Agricultural land data right auditing system based on edge node assistance

The agricultural land data ownership confirmation and auditing system assisted by edge nodes solves the problems of low utilization efficiency and security caused by unclear data ownership, realizes efficient and secure data management and ownership confirmation and auditing, and reduces computing and communication costs.

CN121502785APending Publication Date: 2026-02-10NORTHWEST NORMAL UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511668892.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-14
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

The unclear ownership of agricultural land data leads to low data utilization efficiency, potential conflicts of interest and legal risks. Furthermore, existing technologies incur high communication and computation costs during data transmission and rights confirmation, and the verification process is cumbersome.

Method used

An edge-node-based agricultural land data ownership verification and auditing system is adopted, which includes a key generation module, a hierarchical storage module, a data flow management module, and an ownership verification and auditing module. The system uses a key generation center to generate identity and tag keys, and uses hierarchical storage and edge nodes to assist in data storage and ownership verification and auditing, thereby reducing the complexity of key management and enhancing data security and integrity verification.

Benefits of technology

It improves the efficiency and security of agricultural land data management, reduces computing and communication costs, significantly improves auditing efficiency, enhances data storage security, and resists substitution, replay, and forgery attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121502785A_ABST
    Figure CN121502785A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of agricultural land right confirmation, in particular to an agricultural land data right confirmation auditing system based on edge node assistance. The system comprises a key generation module used for generating a system master key and a system public key, and generating an identity key and a label key corresponding to each entity based on identity information of each entity in a hierarchical storage module; the hierarchical storage module comprises a plurality of entities used for storing land data, and each entity comprises a city-level cloud storage center, a county-level edge node and a rural-level edge node; the data flow management module is used for calling the hierarchical storage module to receive the original land data in response to a data registration operation or an operation right flow operation initiated by a user, and generating a corresponding authentication tag; and the right auditing verification module is used for responding to a right auditing request initiated by the user and executing right auditing operation on the land data. According to the invention, the efficiency of data management in agricultural land data auditing is improved, and the data security is enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of agricultural land ownership confirmation technology, specifically to an agricultural land data ownership confirmation audit system based on edge node assistance. Background Technology

[0002] Currently, the Big Data Development Center of the Ministry of Agriculture and Rural Affairs has initially established a big data "resource pool," aggregating data on approximately 1.107 billion plots of rural contracted land, 960,000 rural collective economic organizations, 900 million members, and 4 million family farms nationwide. Agricultural enterprises have accumulated a wealth of data resources, including land, climate, and crop growth information. However, the ownership of this data is not clearly defined. Due to the lack of clear legal provisions, data ownership is difficult to determine. This not only interferes with the future exercise of holding and management rights but may also lead to inefficient data utilization and potential conflicts of interest. Because of the unclear data ownership, enterprises struggle to reach data-sharing agreements, resulting in severe data silos and hindering the full realization of the data's potential value. Land, as a crucial production factor in agriculture and rural development, necessitates the rational flow of land resources and optimal resource allocation to achieve agricultural development, rural progress, and increased farmer income. Although the management rights of agricultural land data have been initially defined, due to the unique nature of the agricultural industry and the multiple attributes involved, agricultural enterprises lack effective guidance for confirming rights. This may constrain the healthy development of digital agriculture and lead to legal risks for enterprises in data use and management.

[0003] Existing technologies have proposed a data ownership confirmation model for agricultural enterprises based on digital agriculture. In this context, agricultural enterprises have accumulated a large amount of data resources, but due to unclear data ownership and insufficient rights protection, the effective use of data by enterprises is restricted. Even if the data is shown to have unique attributes, such as non-rivalry and non-exclusivity, once the data is generated and enters cyberspace, it may be copied and used infinitely, and the control of the original data owner will be rapidly weakened. Therefore, after the data is traded, its ownership also needs to be transferred through devices such as cloud servers, and how to transfer it has become the focus of current research.

[0004] Existing researchers have proposed a DT-PDP scheme based on bilinear duality, which ensures the security of other data not purchased by the acquiring company, the integrity and privacy of purchased data, and outsources the computability of data transmission to public cloud servers. However, in this scheme, all authenticators corresponding to the transmitted data blocks need to be downloaded from the cloud and converted into valid authenticators. Therefore, the communication and computation costs are proportional to the number of transmitted data blocks. There is also a certificateless cloud storage auditing scheme that supports data ownership transfer. This scheme designs an authenticator conversion method compatible with certificateless signatures. When transferring data ownership, the integrity of the transmitted data can still be verified by converting the authenticator of the previous data owner into a valid authenticator of the new data owner. However, the authenticator conversion process is slightly cumbersome. Summary of the Invention

[0005] To address the problems existing in the prior art, this invention provides an agricultural land data ownership verification and auditing system based on edge nodes. The system includes a key generation module for generating a system master key and a system public key, and generating an identity key and tag key for each entity based on the identity information of each entity in the hierarchical storage module; the hierarchical storage module includes multiple entities for storing land data, including a city-level cloud storage center, county-level edge nodes, and township-level edge nodes; a data flow management module for responding to user-initiated data registration or management right transfer operations, calling the hierarchical storage module to receive raw land data, and generating corresponding authentication tags; and an ownership verification and auditing module for responding to user-initiated ownership verification and auditing requests, performing ownership verification and auditing operations on the land data. This invention not only improves the efficiency of data management in agricultural land data auditing but also enhances data security.

[0006] This invention adopts the following technical solution: an agricultural land data ownership confirmation and auditing system based on edge nodes, comprising: The key generation module is used to generate the system master key and the system public key, and to generate the identity key and tag key corresponding to each entity based on the identity information of each entity in the hierarchical storage module; the identity key includes an identity public key and an identity private key; the tag key includes a tag public key and a tag private key; The hierarchical storage module includes multiple entities for storing land data, including a city-level cloud storage center, county-level edge nodes, and township-level edge nodes. The township-level edge nodes are used to receive raw land data, and the county-level edge nodes are used to store land transfer data of various township-level edge nodes within the same county-level region. The city-level cloud storage center is used to store land transfer data of various county-level edge nodes within the same city-level region. The data transfer management module is used to respond to user-initiated data registration or management rights transfer operations. It calls township-level edge nodes to receive raw land data and generates authentication tags for the raw land data based on the tag keys of the township-level edge nodes. It also calls county-level edge nodes or city-level cloud storage centers to receive land transfer data and generates authentication tags for the land transfer data based on the corresponding tag keys. The land rights confirmation audit verification module is used to respond to user-initiated land rights confirmation audit requests and perform land rights confirmation audit operations on land data. The audit verification module is further configured as a local land rights confirmation unit and a cross-regional land rights confirmation unit. The local land rights confirmation unit generates challenge information based on the land data and sends the challenge information to the county-level edge node to obtain response information. Land rights confirmation audit is performed based on the challenge information, response information, and the tag public key of the county-level edge node. The cross-regional land rights confirmation unit generates an audit conversion value based on the tag private key of the municipal cloud storage center, generates challenge information based on the land data, sends the challenge information to the county-level edge node to obtain response information, and performs land rights confirmation audit based on the audit conversion value and response information.

[0007] Furthermore, the key generation module is used to generate the system master key and the system public key, and to generate an identity key and a tag key corresponding to each entity based on the identity information of each entity in the hierarchical storage module, specifically: The system publicly available parameters are output through the key generation center, including parameters of order [number missing]. Multiplication cyclic group Bilinear pair Group generator and hash function and ;; The key generation center selects the first random number as the system master key, and calculates the system public key based on the master key and the group generator g1; The key generation center selects a second random number and calculates the identity key of the municipal cloud storage center based on the second random number, the identity information of the municipal cloud storage center, and the publicly available system parameters. The key generation center selects a third random number, calculates the master key of the municipal cloud storage center based on the third random number, and calculates the tag key of the municipal cloud storage center based on the master key, the identity key of the municipal cloud storage center, and the publicly available system parameters. The key generation center selects a fourth random number and calculates the identity key of the county-level edge node based on the fourth random number, the identity information of the county-level edge node, and the publicly available parameters of the system. The key center selects the fifth random number as the master key of the county-level edge node, and calculates the tag key of the county-level edge node based on the fifth random number, the identity key of the county-level edge node, and the publicly available system parameters. The key center selects a sixth random number and calculates the identity key of the township-level edge node based on the sixth random number, the identity information of the township-level edge node, and the publicly available parameters of the system. The key center selects the seventh random number as the master key of the township-level edge node, and calculates the tag key of the township-level edge node based on the seventh random number, the identity key of the township-level edge node, and the publicly available system parameters.

[0008] Furthermore, the local land ownership confirmation unit generates challenge information based on land data and sends this challenge information to the county-level edge node to obtain response information; land ownership confirmation audit is performed based on the challenge information, response information, and the tag public key of the county-level edge node, specifically as follows: When a user initiates a land ownership audit request to a county-level edge node, the corresponding land data stored in the county-level edge node is retrieved. The land data is divided into multiple data blocks, and a set number of data blocks are selected to construct a data subset. Generate a corresponding number of challenge random numbers based on the data subset, and generate challenge information based on the data subset and the challenge random numbers; The challenge information is sent to the county-level edge node, and the response information is calculated by the aggregation verifier deployed at the county-level edge node; Bilinear mapping operations are performed based on challenge information, response information, and the public key of the county-level edge node to obtain the rights confirmation audit result.

[0009] Furthermore, the cross-regional land rights confirmation unit generates an audit conversion value based on the tag private key of the municipal cloud storage center, generates challenge information based on land data, and sends the challenge information to the county-level edge node to obtain response information. Land rights confirmation audit is then performed based on the audit conversion value and the response information, specifically as follows: When a user initiates a land ownership confirmation request to the municipal cloud storage center, the county-level edge node for land data storage is determined based on the transfer number submitted by the user. The municipal cloud storage center calls a third-party auditing agency to select the eighth random number and calculates the initial conversion parameters based on the eighth random number; Calculate the first intermediate conversion parameter based on the tag private key of the municipal cloud storage center and the initial conversion parameter; The first intermediate conversion parameter is sent to the county-level edge node, and the second intermediate conversion parameter is calculated based on the tag private key of the county-level edge node and the intermediate conversion parameter. The third-party auditing firm calculates the audit conversion value based on the second intermediate conversion parameter and the tag key of the county-level edge node; The land data stored in the county-level edge nodes is divided into multiple data blocks, and a set number of data blocks are selected to construct a data subset. A number of challenge random numbers are generated based on the number of data blocks in the data subset, and challenge information is generated based on the data subset and the challenge random numbers; The challenge information is sent to the county-level edge node, and the response information is calculated by the aggregation verifier deployed at the county-level edge node; A bilinear mapping operation is performed based on the audit conversion value and the response information to obtain the confirmation audit result.

[0010] The beneficial effects of this invention are as follows: This invention utilizes user identity for key creation, reducing the complexity of key management. Furthermore, by introducing edge nodes, it enhances data security and integrity verification capabilities, effectively resisting substitution, replay attacks, and forgery, thus ensuring data storage security. Simultaneously, the rights confirmation audit process proposed in this invention has significant advantages in terms of computational cost and communication overhead, especially in big data environments, significantly improving audit efficiency and communication efficiency. In summary, this invention provides an effective solution for the secure auditing of agricultural land data, not only improving data management efficiency but also enhancing data security. Attached Figure Description

[0011] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0012] Figure 1 This is a schematic diagram of the structure of an agricultural land data ownership confirmation and auditing system based on edge nodes, according to an embodiment of the present invention. Figure 2 This is a schematic diagram of a three-tiered edge node architecture of township-county-city according to an embodiment of the present invention; Figure 3 This is a model of an agricultural land data transfer system according to an embodiment of the present invention; Figure 4 This is a schematic diagram illustrating the comparison results of computational costs during the label generation stage according to an embodiment of the present invention; Figure 5 This is a schematic diagram illustrating the comparison results of computational costs during the evidence generation stage according to an embodiment of the present invention. Figure 6 This is a schematic diagram illustrating a communication overhead comparison result according to an embodiment of the present invention. Detailed Implementation

[0013] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0014] Before providing a detailed structural description of an edge node-assisted agricultural land data ownership confirmation and auditing system, this invention first describes the entities involved in the system and the flow process of land data, such as... Figure 2 As shown, the entities in the system of this invention adopt a three-level edge node architecture of township-county-city. Meanwhile, Figure 3 An agricultural land data transfer system model according to an embodiment of the present invention is given; from Figure 2 and 3 As can be seen, there are eight entities in this invention's system, including farmers, edge nodes at various levels (which are the data storage nodes managed by the respective management agencies), a municipal cloud data center (which is the data storage node managed by the municipal management agency), a third-party auditing agency (TPA), and a key generation center (KGC). Farmers are landowners who, as users of this system, register their land data at the township-level edge node and can conduct land management rights transactions. The township-level edge nodes corresponding to the township management agencies are responsible for storing the original land data of each farmer and have auditing capabilities for the edge nodes under their jurisdiction. County-level management... The county-level edge nodes corresponding to the agency are responsible for storing land transfer data between farmers at the township level and have the ability to audit the edge nodes under their jurisdiction; the municipal-level cloud data center corresponding to the municipal-level management agency is responsible for storing land transfer data between farmers at the county level; the third-party auditing agency has an employment relationship with the municipal-level cloud data center corresponding to the municipal-level management agency, that is, the municipal-level cloud data center corresponding to the municipal-level management agency can audit the land data stored in the municipal-level cloud data center and its subordinate county-level and township-level edge nodes through the third-party auditing agency; the key generation center is responsible for the initialization of the system of this invention and the creation of identity keys and tag keys for management agencies at all levels.

[0015] In this embodiment of the invention, the original land data stored at the township-level edge nodes is represented as shown in Table 1: Table 1. Schematic diagram of original land data registration This embodiment of the invention further defines land transfer data in the form shown in Table 2: Table 2. Schematic diagram of land transfer data registration in, In the represented flow index, This indicates the number of the municipal-level management agency. This indicates the number of the county-level management agency. The last four digits represent the code of the township-level administrative organization. This indicates the positional number.

[0016] Based on the above description, this invention proposes an agricultural land data ownership confirmation and auditing system based on edge node assistance, the structural diagram of which is shown below. Figure 1 As shown, the system includes a key generation module, a hierarchical storage module, a data flow management module, and a rights confirmation and auditing verification module; among which: The key generation module is used to generate the system master key and system public key, and to generate the identity key and tag key corresponding to each entity based on the identity information of each entity in the hierarchical storage module; In this embodiment of the invention, the identity key includes an identity public key and an identity private key; the tag key includes a tag public key and a tag private key; In one specific embodiment of the present invention, the key generation module adopts a Key Generation Center (KGC), and its process for generating the system master key and system public key is as follows: By choosing the order Two multiplication cyclic groups , Meanwhile, a computable bilinear pair is defined. , making , and select and Let G1 be the group generator of the multiplicative cyclic group, and then a first random number be randomly selected. As the system master key, among which... Representing a finite field The multiplicative group in the middle; and based on the master key and the group generator. The system public key is calculated and represented as follows: Then, the key generation center selects two hash functions. , Output the system's publicly available parameters based on the above information. .

[0017] The key generation module further generates an identity key and tag key for each entity based on the identity information of each entity in the hierarchical storage module, as follows: Based on the identity information of the municipal cloud storage center The key generation center randomly selects a second random number. Then, its identity public key is calculated based on the second random number and the system public key. Then, based on the second random number, the publicly available system parameters, and the identity information of the municipal cloud storage center, its private key is calculated, as follows: Thus, the identity key is obtained by combining the identity public key and the identity private key. The identity key is sent to the municipal cloud storage center, which then verifies the private key. The validity of the test is verified as follows: .

[0018] The key generation center further selects a third random number. The master key of the municipal cloud storage center is used as the key, and then its tag public key is calculated based on the master key, system public parameters, and the municipal cloud storage center's identity private key. Then, based on the master key, the identity key of the municipal cloud storage center, and the publicly available system parameters, the tag private key of the municipal cloud storage center is calculated, as follows: Once the calculation is complete, the tag key for the municipal cloud storage center can be obtained. It is then sent to the municipal cloud storage center for verification. The verification process is as follows: This verification process utilizes the one-way property of the discrete logarithm problem to verify the consistency between the generated tag key and the publicly available system parameters and identity key. Through this verification, the municipal cloud storage center can confirm that the received tag key is legitimate and valid, preventing it from being forged or replaced.

[0019] In one specific embodiment of the present invention, the key generation center selects a fourth random number. Simultaneously, obtain the identity information of county-level edge nodes. The identity public key is calculated based on the fourth random number and the system's public parameters, and is expressed as follows: The identity private key is calculated based on the fourth random number, identity information, and publicly available system parameters, and is expressed as follows: Thus, the identity key of the county-level edge node is obtained. Then, send it to the county-level agency for verification.

[0020] The key generation center further selects a fifth random number. The master key of the county-level edge node is used as the key, and then the tag public key of the county-level edge node is calculated based on the master key, the identity key, and the system's public parameters, as follows: The tag private key is calculated based on the fifth random number, the identity key of the county-level edge node, and the publicly available system parameters, and is expressed as: Thus, the tag key of the county-level edge node is obtained. Then, send it to the county-level agency for verification.

[0021] In one specific embodiment of the present invention, the key center selects a sixth random number. Simultaneously, obtain the identity information of township-level edge nodes. The identity public key is calculated based on the sixth random number and the system's public parameters, and is expressed as follows: The identity private key is calculated based on the sixth random parameter, the identity information of the township-level edge node, and the publicly available system parameters, and is expressed as follows: Thus, the identity key of the township-level edge node is obtained. The identity key of the township-level edge node is sent to the county-level edge node for verification.

[0022] The key center further selects a seventh random number. As the master key for the township-level edge node, the tag public key for the township-level edge node is calculated based on the seventh random number and the system's public parameters, and is represented as follows: The private key of the label for the township-level edge node is calculated based on the seventh random number, the identity key of the township-level edge node, and the publicly available system parameters, and is expressed as follows: Once the calculation is complete, the tag key for the township-level edge node can be obtained. It is then sent to the county-level edge node for verification.

[0023] It should be noted that the verification method for identity keys and tag keys by county-level edge nodes in this embodiment of the invention is the same as the verification method of city-level cloud storage centers, and this embodiment of the invention will not provide further limitations.

[0024] The hierarchical storage module includes multiple entities for storing land data, including a city-level cloud storage center, county-level edge nodes, and township-level edge nodes. The township-level edge nodes are used to receive raw land data, while the county-level edge nodes are used to store land transfer data from various township-level edge nodes within the same county-level region. The city-level cloud storage center is used to store land transfer data from various county-level edge nodes within the same city-level region. The data transfer management module is used to respond to user-initiated data registration or management rights transfer operations. It calls township-level edge nodes to receive raw land data and generates authentication tags for the raw land data based on the tag keys of the township-level edge nodes. It also calls county-level edge nodes or city-level cloud storage centers to receive land transfer data and generates authentication tags for the land transfer data based on the corresponding tag keys. In this embodiment of the invention, the user first uploads their original land data to a township-level edge node for storage. During storage, this embodiment of the invention divides the original land data into corresponding data types. A file of data blocks , A unique identifier for the original data file, where , Indicates the first Each data block is then processed, and the township-level edge node uses its label private key to create an authentication label for the raw land data. ,in This is the number of the township-level edge node. A unique identifier for the original land data, and a set of authentication tags is set. Then, the township-level edge node right Store it.

[0025] In a specific embodiment of the present invention, two examples of data flow are further provided as follows: When User A and User B are located in different townships within the same county, they submit a data transfer request to their shared county-level edge node. After successful negotiation, the county-level edge node saves the transfer information as new data. Subsequently, the county-level edge node uses its tag private key to transfer the data. The certification label is created as follows: Then, county-level edge nodes right Store it.

[0026] When user A and user B are located in different county-level areas within the same city, they submit a data transfer request to their shared city-level cloud storage center. The city-level cloud storage center saves the transfer information from both parties as new data. Subsequently, the city-level cloud storage center uses its tag private key to process the transferred data. Creating certification labels Then, county-level cloud storage center right Store it.

[0027] The land rights confirmation audit verification module is used to respond to user-initiated land rights confirmation audit requests and perform land rights confirmation audit operations on land data. The audit verification module is further configured as a local land rights confirmation unit and a cross-regional land rights confirmation unit. The local land rights confirmation unit generates challenge information based on the land data and sends the challenge information to the county-level edge node to obtain response information. Land rights confirmation audit is performed based on the challenge information, response information, and the tag public key of the county-level edge node. The cross-regional land rights confirmation unit generates an audit conversion value based on the tag private key of the municipal cloud storage center, generates challenge information based on the land data, sends the challenge information to the county-level edge node to obtain response information, and performs land rights confirmation audit based on the audit conversion value and response information.

[0028] In one specific embodiment of the present invention, if there is a land transfer dispute between users in different townships within the same county-level region, the users submit a land rights confirmation and traceability application to the county-level edge node. The county-level edge node, by checking the transfer number, finds that the land transfer data is stored in its corresponding edge node, and then calls the local land rights confirmation unit to perform land rights confirmation audit. The specific steps are as follows: When a user initiates a land ownership audit request to the county-level edge node, the corresponding land data stored in the county-level edge node is retrieved; this land data is divided into multiple data blocks, and the blocks containing... A subset of data blocks The county-level edge node generates a challenge random number for each data block in the data subset. This generates challenge information. ,in, It is the sequence number of the selected data block, and the challenge information is sent to the county-level edge node. After receiving the challenge information, the county-level edge node first calculates two corresponding aggregate validators. and ,in, This represents the response of the first aggregate validator. This means taking the power of the corresponding challenge random number for the authentication label of each data block, and then multiplying all the results together; This represents the response of the second aggregate validator. This represents a weighted sum of each data block and its challenge random number, thus yielding the overall response information. Based on the challenge information, response information, and the tag public key of the county-level edge node, a bilinear mapping operation is performed, represented as: If the equation of the bilinear mapping operation holds, it proves that the county-level edge node has correctly and completely stored the land transfer data. The county-level edge node then resolves disputes between farmers based on the land transfer data it stores, thereby obtaining the land ownership audit results.

[0029] In one specific embodiment of the present invention, when a user has a dispute over land transfer and provides the transfer number of their land transfer data to the municipal cloud storage center to initiate a land ownership confirmation audit request, the cross-regional land ownership confirmation unit is invoked to conduct the land ownership confirmation audit, as follows: When a user initiates a land ownership confirmation request to the municipal cloud storage center, the land transfer data provided by the user is assigned a transfer number. The municipal cloud storage center determines the data storage location for the land transfer information to the county-level agency based on the transfer number. Managed edge nodes The municipal cloud storage center then sends a land transfer data access notification to the county-level edge node and sends an audit conversion value calculation application to the third-party auditing agency. Specifically, the third-party auditing agency selects the eighth random number. And calculate the initial transformation parameters. It is then sent to the municipal cloud storage center, which then calculates the first intermediate transformation parameters based on its tag private key. It is then sent to the county-level edge node, which then calculates the second intermediate transformation parameter based on its tag private key. After that, the county-level edge nodes will Send to a third-party auditing firm to calculate the audit conversion value , is represented as: Cross-regional audits are conducted using this audit conversion value; The third-party auditing firm further acquires land data stored in county-level edge nodes and divides it into multiple data blocks, selecting a set number of data blocks to construct a data subset; it generates corresponding response information by performing the same steps as the local land ownership unit; the third-party auditing firm first calculates the changed aggregate validator based on the response information and audit transformation value, represented as: Then, a bilinear mapping operation is performed based on the audit conversion value and the response information, expressed as: If the bilinear mapping operation expression holds true, the third-party auditing agency outputs TRUE; otherwise, it outputs FALSE and returns the audit result to the municipal cloud storage center. After the municipal cloud storage center completes the above operations during the land rights confirmation process, if the third-party auditing agency returns FALSE, it proves that the data integrity has been compromised. The center then records the damage and reports it. If the third-party auditing agency returns TRUE, the municipal agency can access the stored corresponding land transfer data and handle land management disputes between farmers based on the land transfer information, thus obtaining the land rights confirmation audit result.

[0030] In another embodiment of the present invention, to verify the correctness of the local rights confirmation unit in the present invention, the embodiment of the present invention provides an example of the situation when a county-level edge node audits data. When the edge node correctly stores the data, it should be as follows: To verify the correctness of cross-regional rights confirmation units, this embodiment of the invention provides the situation when a municipal cloud storage center audits data from county-level edge nodes. When edge nodes correctly store data, the following should be observed: In another specific embodiment of the present invention, the security of the system proposed in this invention is further demonstrated from four aspects: storage security, prevention of replay attacks, prevention of forgery attacks, and prevention of substitution attacks, as detailed below: Storage security refers to the inability to generate proofs that can be verified by third-party auditing agencies or edge nodes at all levels if land data is not fully stored by the edge nodes or cloud data center CDC in the scheme. This scheme verifies its storage security based on the difficulty of calculating the discrete logarithm problem (DLP) and the Diffie-Hellman problem (CDH) in multiplicative cyclic groups. The principle is that if an attacker (the city-level cloud storage center in this invention) can generate proofs that pass integrity verification without storing the complete original user data, it indicates that the malicious cloud data center has the ability to solve the CDH or DLP problem, that is, the cloud storage center can win in polynomial time. For specific analysis, please refer to the relevant content recorded in the prior art. Through analysis, it can be seen that due to the difficulty of the CDH and DLP problems, the malicious cloud storage center cannot generate proofs that pass auditing without storing the complete user data. In other words, the system proposed in this invention can meet the storage security requirements.

[0031] A replay attack refers to a situation where a cloud storage center cannot pass the verification of a third-party auditing agency using previous audit proofs. Each time a challenge message is generated, the third-party auditing agency randomly selects 'a' data blocks to generate a random number. For each challenge message, the cloud storage center must calculate the proof response information based on the random number. These challenge messages all guarantee the randomness of the challenge, thereby proving that the system proposed in this invention can resist replay attacks.

[0032] Anti-forgery attack refers to the analysis of the storage correctness portion. If the cloud storage center does not fully store the user's original data, it has no way to forge a valid certificate that can be audited by a third-party auditing agency. Other external malicious attackers cannot even forge valid certificates. Therefore, the system of this invention supports anti-forgery attacks.

[0033] The substitution attack prevention mechanism refers to the scenario where a cloud data center attempts to replace a corrupted or incompletely stored data block with the k-th unchallenged data block to generate proof that passes an integrity audit. Upon receiving a challenge from a third-party auditing agency, the cloud storage center calculates the corresponding response and returns it to the agency. If the response passes the data integrity verification, the substitution attack succeeds; otherwise, it fails. According to the algorithm construction in this invention system, each block has its own unique identifier, preventing the cloud storage center from generating a valid proof that passes an integrity audit through a substitution attack. Therefore, this invention system possesses the security against substitution attacks.

[0034] In another specific embodiment of the present invention, the performance of the system is analyzed in depth through numerical analysis and experimental evaluation to verify its efficiency and practicality. To ensure the consistency of the experiments, the embodiment of the present invention selects the BN128 curve as the basis. The experiment is conducted on the Ubuntu 22.04 platform, using a 12th Gen Intel(R) Core(TM) i7-12700H 2.30 GHz processor and 16.0 GB of RAM. The solution code uses Python language, as follows: The present invention embodiment selects The sizes of the elements in the multiplication cyclic group are 160 bits and 256 bits, respectively. and In each challenge message from the third-party auditing firm, the number of data blocks selected is [number missing]. For comparison, this invention selects existing scheme 1 and existing scheme 2 as comparative schemes for embodiments of this invention. In the numerical analysis and comparison of computational costs, the computational costs of tag generation, evidence generation, and third-party audit verification stages will be considered respectively. Embodiments of this invention define some key operations and their corresponding time costs, as shown in Table 3: Table 3 Definitions related to performance analysis In the system proposed in this invention, each level of entity generates authentication tags for the data blocks it manages, with an overhead of [missing information]. During the response generation phase, the overhead that edge nodes need to bear is To assist third-party audit firms in generating response information, the overhead for third-party audit firms during the challenge generation and verification phases is = .

[0035] In the existing scheme 1, the overhead required for an edge node to generate authentication labels for s data blocks is... During the response generation phase, this solution requires The overhead at this stage, involving numerous bilinear mapping operations and exponentiation, results in a significant cost for the solution. The cost of third-party auditing during the validation phase is also substantial. .

[0036] In the existing Scheme 2, the computational cost for a user to generate authentication tags for s data blocks is: During the response generation phase, the required computational overhead is... For the verification phase conducted by a third-party auditing firm, the computational cost is... .

[0037] In this embodiment of the invention, 20 simulation experiments were conducted and the average value was calculated to evaluate the performance difference between the present invention and existing solutions. Figure 4 and Figure 5 The advantages and disadvantages of the present invention compared to existing solutions can be seen from this; for example... Figure 4 As shown, during the data tagging stage, the computational cost of this scheme is slightly better than that of the existing scheme two, but significantly better than that of the existing scheme one; REF _Ref196386249 \h \* MERGEFORMAT Figure 5 The comparison of evidence generation computation costs is presented, and the proposed solution is significantly superior to the proposed solution. Although both proposed solutions and proposed solution one use random sampling techniques, resulting in little difference in cost, the proposed solution still demonstrates higher efficiency on the TPA side. In the TPA verification stage, since proposed solution one lacks an audit ownership transfer mechanism, it is only compared with proposed solution two. Although neither proposed solution nor proposed solution two requires re-downloading data blocks to create tags, the proposed solution has a significant advantage over proposed solution two in terms of the interaction overhead between TPA and the user. In summary, the proposed solution has the lowest computational cost in all aspects.

[0038] In another specific embodiment of the present invention, a comparative analysis of the communication overhead is further performed between the present invention and existing solutions one and two. The comparison of communication overhead is divided into three parts: the communication overhead between nodeCDC and TPA audit conversion value, the challenge information initiated by TPA to the edge node or CDC, and the response information returned by the edge node or CDC to TPA. The curve used is based on a 256-bit field, where the multiplication cyclic group... The length is 256 bits, the length of each data block index is set to 16 bits, and the random number, signature length, and hash length are all set to 160 bits. Specific overhead data is shown in Table 4. Figure 6 As shown.

[0039] Table 4 Comparison Results of Communication Overhead Calculation In this invention, the communication overhead for calculating the audit transition value between the CDC and TPA is: Then, the communication overhead for TPA to send audit challenges to edge nodes is... bits, and the communication overhead during the process of the CDC sending the audit certificate to the TPA is... bits.

[0040] In the existing Option 1, TPA initiates an audit challenge to the CDC, with a communication overhead of [missing information]. bits, ultimately The transmission overhead for sending audit certification to TPA is bits.

[0041] In the existing Scheme 2, the cost of calculating the conversion value is The communication overhead for TPA to challenge CDC is The computational overhead of CDC sending proof to TPA is basically the same as that of the present invention, which is bits. bits.

[0042] Based on the above analysis, the present invention mainly compares with the existing solution 1 in terms of communication overhead. When the edge node transmits data to the CDC, the communication overhead of this solution is significantly better than that of the existing solution 1. To more intuitively demonstrate the comparison of communication overhead between this solution and the existing solution 1, in... Figure 6 The relevant data is presented in the document, from Figure 6 As can be seen, with the assistance of edge nodes, the present invention significantly reduces communication overhead during the integrity audit process. Although the overhead of the present invention is slightly less than that of the existing solution 1 in the stage where the CDC sends the audit certificate to the TPA, the advantages of the present invention in other stages are not negligible. Therefore, in practical applications, especially in the audit scenario of big data agricultural land data, the present invention can significantly improve communication efficiency.

[0043] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. An agricultural land data ownership confirmation and auditing system based on edge nodes, characterized in that, include: The key generation module is used to generate the system master key and the system public key, and to generate the identity key and tag key corresponding to each entity based on the identity information of each entity in the hierarchical storage module; the identity key includes an identity public key and an identity private key; the tag key includes a tag public key and a tag private key; The hierarchical storage module includes multiple entities for storing land data, including a city-level cloud storage center, county-level edge nodes, and township-level edge nodes. The township-level edge nodes are used to receive raw land data, and the county-level edge nodes are used to store land transfer data of various township-level edge nodes within the same county-level region. The city-level cloud storage center is used to store land transfer data of various county-level edge nodes within the same city-level region. The data transfer management module is used to respond to user-initiated data registration or management rights transfer operations. It calls township-level edge nodes to receive raw land data and generates authentication tags for the raw land data based on the tag keys of the township-level edge nodes. It also calls county-level edge nodes or city-level cloud storage centers to receive land transfer data and generates authentication tags for the land transfer data based on the corresponding tag keys. The land rights confirmation audit verification module is used to respond to user-initiated land rights confirmation audit requests and perform land rights confirmation audit operations on land data. The audit verification module is further configured as a local land rights confirmation unit and a cross-regional land rights confirmation unit. The local land rights confirmation unit generates challenge information based on the land data and sends the challenge information to the county-level edge node to obtain response information. Land rights confirmation audit is performed based on the challenge information, response information, and the tag public key of the county-level edge node. The cross-regional land rights confirmation unit generates an audit conversion value based on the tag private key of the municipal cloud storage center, generates challenge information based on the land data, sends the challenge information to the county-level edge node to obtain response information, and performs land rights confirmation audit based on the audit conversion value and response information.

2. The agricultural land data ownership confirmation and auditing system based on edge nodes as described in claim 1, characterized in that: The key generation module is used to generate the system master key and the system public key, and to generate an identity key and a tag key for each entity based on the identity information of each entity in the hierarchical storage module, specifically: The system publicly available parameters are output through the key generation center, including parameters of order [number missing]. Multiplication cyclic group Bilinear pair Group generator and hash function and ; The key generation center selects the first random number as the system master key, and calculates the system public key based on the master key and the group generator g1; The key generation center selects a second random number and calculates the identity key of the municipal cloud storage center based on the second random number, the identity information of the municipal cloud storage center, and the publicly available system parameters. The key generation center selects a third random number, calculates the master key of the municipal cloud storage center based on the third random number, and calculates the tag key of the municipal cloud storage center based on the master key, the identity key of the municipal cloud storage center, and the publicly available system parameters. The key generation center selects a fourth random number and calculates the identity key of the county-level edge node based on the fourth random number, the identity information of the county-level edge node, and the publicly available parameters of the system. The key center selects the fifth random number as the master key of the county-level edge node, and calculates the tag key of the county-level edge node based on the fifth random number, the identity key of the county-level edge node, and the publicly available system parameters. The key center selects a sixth random number and calculates the identity key of the township-level edge node based on the sixth random number, the identity information of the township-level edge node, and the publicly available parameters of the system. The key center selects the seventh random number as the master key of the township-level edge node, and calculates the tag key of the township-level edge node based on the seventh random number, the identity key of the township-level edge node, and the publicly available system parameters.

3. The agricultural land data ownership confirmation and auditing system based on edge nodes as described in claim 1, characterized in that: The local land ownership confirmation unit generates challenge information based on land data and sends this challenge information to the county-level edge node to obtain response information; it then performs land ownership confirmation audit based on the challenge information, response information, and the county-level edge node's tag public key, specifically: When a user initiates a land ownership audit request to a county-level edge node, the corresponding land data stored in the county-level edge node is retrieved. The land data is divided into multiple data blocks, and a set number of data blocks are selected to construct a data subset. Generate a corresponding number of challenge random numbers based on the data subset, and generate challenge information based on the data subset and the challenge random numbers; The challenge information is sent to the county-level edge node, and the response information is calculated by the aggregation verifier deployed at the county-level edge node; Bilinear mapping operations are performed based on challenge information, response information, and the public key of the county-level edge node to obtain the rights confirmation audit result.

4. The agricultural land data ownership confirmation and auditing system based on edge nodes as described in claim 1, characterized in that: The cross-regional land ownership confirmation unit generates an audit conversion value based on the tag private key of the municipal cloud storage center, generates challenge information based on land data, and sends the challenge information to the county-level edge node to obtain response information. Land ownership confirmation audit is then performed based on the audit conversion value and the response information, specifically as follows: When a user initiates a land ownership confirmation request to the municipal cloud storage center, the county-level edge node for land data storage is determined based on the transfer number submitted by the user. The municipal cloud storage center selects the eighth random number and calculates the initial conversion parameters based on the eighth random number; Calculate the first intermediate conversion parameter based on the tag private key of the municipal cloud storage center and the initial conversion parameter; The first intermediate conversion parameter is sent to the county-level edge node, and the second intermediate conversion parameter is calculated based on the tag private key of the county-level edge node and the intermediate conversion parameter. The third-party auditing firm calculates the audit conversion value based on the second intermediate conversion parameters and the tag key of the county-level edge node; The land data stored in the county-level edge nodes is divided into multiple data blocks, and a set number of data blocks are selected to construct a data subset. A number of challenge random numbers are generated based on the number of data blocks in the data subset, and challenge information is generated based on the data subset and the challenge random numbers; The challenge information is sent to the county-level edge node, and the response information is calculated by the aggregation verifier deployed at the county-level edge node; A bilinear mapping operation is performed based on the audit conversion value and the response information to obtain the confirmation audit result.