A method and system for drone identity anonymization and secure data outsourcing

By constructing an encoding-driven distributed data storage and integrity verification architecture, the security risks in UAV data transmission and storage are resolved, enabling UAV identity anonymization and data security outsourcing, ensuring data integrity and privacy, and making it suitable for the continuous availability and robust recovery of low-altitude UAV systems.

CN121750382BActive Publication Date: 2026-06-02SOUTHWEST PETROLEUM UNIV

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SOUTHWEST PETROLEUM UNIV
Filing Date
2026-03-02
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

Drones face security risks during data transmission and storage, especially issues of identity privacy leakage and data sensitivity. At the same time, existing mechanisms are insufficient to achieve traceability, anonymity, and data integrity verification while protecting privacy.

Method used

By employing erasure coding, identity-based cryptography, homomorphic hash functions, binary search algorithms, uniform sets on finite sets, and blockchain technology, a coding-driven data distribution storage and integrity verification architecture is constructed. Combined with a comprehensive regulatory platform and cloud servers, this enables drone identity anonymization and secure data outsourcing.

Benefits of technology

It achieves continuous availability and robust recovery capabilities for UAV data, reduces the redundancy of traditional multi-cloud, multi-replica storage, ensures data integrity and privacy security, supports continuous availability and robust recovery of low-altitude UAV systems, and has high fault tolerance and low-bandwidth recovery capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121750382B_ABST
    Figure CN121750382B_ABST
Patent Text Reader

Abstract

The application discloses a kind of unmanned plane identity anonymization and safe data outsourcing method and system, method is based on integrated supervision platform and unmanned plane, including system initialization stage, integrated supervision platform generates main private key and public parameter;User anonymous and private key generation stage, unmanned plane registers anonymous identity and obtains user private key;Data preprocessing and outsourcing stage, unmanned plane divides data into block and sub-block and encrypts, generates coding vector using erasure code coding, generates verification label for each coding data block, constructs random distribution table according to the number of cloud server, distributes coding vector and label to multiple cloud server storage.In this way, the unmanned plane identity anonymization and safe data outsourcing method described reduces storage redundancy, ensures that data can be reconstructed when multiple servers fail, and guarantees data availability and robust recovery.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of cyberspace security technology, and in particular to a method and system for anonymizing unmanned aerial vehicle (UAV) identities and outsourcing secure data. Background Technology

[0002] With the acceleration of digitalization and the booming development of the low-altitude economy, Unmanned Aerial Vehicles (UAVs), with their high mobility and high-precision sensors such as visible light cameras, LiDAR, and multispectral / infrared imaging, have become core equipment for low-altitude information sensing and acquisition, widely used in military reconnaissance, geographic mapping, emergency rescue, environmental monitoring, and personal aerial photography. During a single long-duration mission, UAVs can generate terabytes of high-resolution, full-element, multimodal mission data, placing enormous pressure on local storage. Traditional solutions relying on expanding ground servers or building their own data centers suffer from high costs, complex operation and maintenance, and the potential for information silos, making it difficult to support cross-domain collaboration and centralized management. In contrast, cloud storage, with its high scalability, elastic resource scheduling, and professional data management capabilities, provides UAVs with an efficient and persistent solution for massive data storage, supporting remote access, mission backtracking, and subsequent intelligent analysis, and has become a key infrastructure for UAV mission data storage, management, and sharing.

[0003] However, in the complex and open network environment, uploading drone mission data to the cloud also brings significant security risks. Data collected by drones is generally highly sensitive; for example, high-resolution imagery can expose details of critical infrastructure; lidar points and 3D reconstruction models can reveal national topography and building structures; multispectral and infrared remote sensing data can reflect the operational characteristics of energy facilities; and flight logs, trajectories, and control commands contain precise mission area and location parameters. If this data is stolen, analyzed, tampered with, or falsified during transmission or storage, it will seriously threaten trade secrets, public safety, and even national security.

[0004] Beyond the core challenges of multi-cloud integrity verification mentioned above, protecting drone identity privacy is also crucial. If the identity identifiers (such as IP addresses, MAC addresses, and manufacturer serial numbers) exposed by drones during communication are leaked, they could be used for tracking, interference, or even attacks. Identity-Based Cryptography (IBC), with its inherently simplified key management and low communication overhead, is better suited to the highly dynamic, multi-node operation characteristics of drone systems. Simultaneously, in cross-departmental / organizational drone data sharing scenarios, a balance must be struck between privacy protection and accountability: while complete anonymization mechanisms can protect identity privacy, they can easily lead to untraceable malicious behavior. Furthermore, the reliability of TPA (Transportation Permit) depends on privacy breach risk mitigation. Existing mechanisms heavily rely on the complete reliability of TPA. However, TPAs ​​may violate protocols to save computational resources, failing to perform audits or falsifying results; moreover, malicious TPAs ​​can attempt to infer and steal sensitive information contained in drone missions by initiating multiple rounds of audit requests targeting the same objective.

[0005] To address these issues, a security mechanism is needed that can both protect the identity and data privacy of drones and provide traceable anonymity when necessary. Summary of the Invention

[0006] The purpose of this invention is to overcome the shortcomings of the prior art and provide a method and system for anonymizing drone identities and outsourcing secure data. The method is based on erasure coding, identity-based cryptography, homomorphic hash functions, binary search algorithms, uniform (K,N) sets on finite sets, and blockchain technology. The core of the invention is to construct an architecture for encoding-driven distributed data storage, integrity verification, and accurate location and effective recovery of damaged data.

[0007] The objective of this invention is achieved through the following technical solution:

[0008] Firstly, this application discloses a method for anonymizing drone identities and outsourcing security data, based on a comprehensive monitoring platform and a drone, including: a system initialization phase, in which the comprehensive monitoring platform, according to given security parameters... Generate system parameters, including the master private key. In the user anonymization and private key generation stage, the drone generates an anonymous identity and submits registration information to the integrated supervision service platform to obtain the user private key sk corresponding to the anonymous identity; in the data preprocessing and outsourcing stage, the drone uploads the data files to be uploaded. The data is divided into multiple data blocks, each data block is further divided into multiple data sub-blocks, and each data sub-block is encrypted using a symmetric encryption algorithm to obtain ciphertext sub-blocks. The subscript ij represents the j-th sub-block of the i-th data block. Then, the UAV encodes the ciphertext data block using erasure coding to generate multiple encoding vectors. For each encoded data block in the encoding vector, the UAV calculates its corresponding verification tag. The UAV obtains the number of available cloud servers, calculates the amount of encoded data stored on each cloud server, and then constructs an adapted random distribution record table of encoded data to record the encoding vectors and their verification tags corresponding to each cloud server, so as to allocate and transmit the storage data that the UAV needs to store to one of the multiple cloud servers for storage.

[0009] Its beneficial effects are:

[0010] The raw UAV data files are segmented and encoded using erasure coding to generate encoded vectors. For each encoded data block, an identity-based homomorphic hash signature algorithm is used to generate a corresponding verification tag. Then, an adapted random distribution table for the encoded data is designed, and these vectors are evenly distributed and stored across multiple cloud servers. This significantly reduces data storage redundancy in traditional multi-cloud, multi-replica storage models, while ensuring that even in the event of a multi-server failure, the remaining vectors can be used to efficiently reconstruct the complete data and its homomorphic hash signature tag, guaranteeing the continuous availability and robust recovery capability of the low-altitude UAV system data.

[0011] Secondly, this application also discloses a drone identity anonymization and security data outsourcing system, including a drone, a comprehensive regulatory service platform, and multiple cloud servers, for executing the drone identity anonymization and security data outsourcing method. Attached Figure Description

[0012] Figure 1 This describes the communication process between the drone, the integrated regulatory service platform, and the blockchain as described in the embodiments of this application. Detailed Implementation

[0013] The technical solution of the present invention will be clearly and completely described below with reference to the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0014] refer to Figure 1 This application describes a method and system for anonymizing drone identities and outsourcing secure data, according to embodiments of the present application.

[0015] Figure 1The numbers in the figure represent the execution order. According to the embodiments of this application, the drone identity anonymization and security data outsourcing system includes: drones and an integrated supervision service platform (Unmanned Aerial Vehicle Operation Management, UOM). This platform manages drones and unmanned aerial vehicles in an integrated manner, performs secure information exchange, generates user public and private key pairs, and realizes secure outsourcing of collected data.

[0016] According to the system, a method for anonymizing drone identities and outsourcing secure data according to an embodiment of this application is executed through the comprehensive regulatory service platform, which includes: a system initialization phase, a user anonymization and private key generation phase, and a data preprocessing and outsourcing phase.

[0017] Specifically, during the system initialization phase, the integrated monitoring platform, based on given security parameters... Generate system parameters, including the master private key. In the user anonymization and private key generation phase, the drone generates an anonymous identity and submits registration information to the integrated regulatory service platform to obtain the user private key sk corresponding to the anonymous identity; in the data preprocessing and outsourcing phase, the drone uploads the data files to be uploaded. The data is divided into multiple data blocks, each data block is further divided into multiple data sub-blocks, and each data sub-block is encrypted using a symmetric encryption algorithm to obtain ciphertext sub-blocks. The subscript ij represents the j-th sub-block of the i-th data block. Then, the UAV encodes the ciphertext data block using erasure coding to generate multiple encoding vectors. For each encoded data block in the encoding vector, the UAV calculates its corresponding verification tag. The UAV obtains the number of available cloud servers, calculates the amount of encoded data stored on each cloud server, and then constructs an adapted random distribution record table of encoded data to record the encoding vectors and their verification tags corresponding to each cloud server, so as to allocate and transmit the storage data that the UAV needs to store to one of the multiple cloud servers for storage.

[0018] Next, each stage will be explained in detail.

[0019] System initialization phase: Given a security parameter The integrated regulatory service platform operates on an initialization algorithm to generate system parameters, including the system master private key. And public parameters. The specific steps are as follows:

[0020] set up and All are large prime numbers of order. Multiplication cyclic group, yes The generator. The integrated regulatory service platform defines a bilinear pair: Select random value ,and As the system's master and private keys And calculate its corresponding public key. , ,in It is a model Remainder ring.

[0021] The integrated regulatory service platform has selected six secure, collision-resistant hash functions: the first hash function The second hash function The third hash function The fourth hash function ,in The fifth hash function is used for the set of natural numbers. The sixth hash function ,in For safety parameters The determined bit length of the hash function output, and the seventh hash function. .

[0022] The integrated regulatory service platform selects a pseudo-random function. and a pseudo-random generator .

[0023] The integrated regulatory service platform sets up and publishes system parameters. and securely store the master private key. .

[0024] User anonymity and private key generation phase: Assuming each drone has a unique and authentic identity. The drone first generates an anonymous identity and sends it to the integrated regulatory service platform for registration. The integrated regulatory service platform then calculates the user's private key sk. The specific steps are as follows:

[0025] Set an initial login password for the drone. And select a random value And calculate the first user's public key and user anonymity ,in Anonymous identity information The validity period. Finally, the drone submits user registration information to the integrated regulatory service platform via a secure channel. ,in The session key, generated by the drone, is used to ensure the confidentiality of communication during subsequent interactions. This is a timestamp used to indicate when the registration information was generated.

[0026] When the registration information sent by the drone is received Then, the integrated regulatory service platform first uses the master private key. To restore the drone's identity and reset its login password to .

[0027] The integrated regulatory service platform selects a random value. And calculate the second user's public key. and its users' private keys Finally, the integrated regulatory service platform transmits the binary data via a secure channel. Send to the drone.

[0028] When receiving binary data from the comprehensive regulatory service platform Then, the drone verifies the validity of the user's private key sk using the following equation:

[0029] If the above verification equation holds true, the drone will receive the binary tuple. Otherwise, the drone rejects the binary pair. The integrated regulatory service platform was required to regenerate the user's private key sk and the second user's public key. .

[0030] Data preprocessing and outsourcing stage: Given a data file The drone performs the following algorithm steps to achieve secure data outsourcing.

[0031] For each data file to be uploaded Its file name is The drone first cut it into One data block. Each data block The subscript i represents the i-th data block, which is further divided into Data sub-blocks The subscript ij represents the j-th sub-block of the i-th data block. For each data sub-block... The drone chooses a secure symmetric encryption algorithm. To encrypt it, in order to generate ciphertext sub-blocks. ,in Represents a symmetric encryption algorithm A security key. Therefore, the data file Encrypted into ciphertext , It is by Individual Model The data space composed of elements.

[0032] The drone selects an encoding matrix ,in The total number of vectors generated after encoding is given, and the codeword matrix is ​​calculated as follows: , where each encoded vector For each coded data block The drone selects a random value. And calculate its corresponding verification label:

[0033]

[0034] For random values The hash mapping value, The tags generated for the drone based on coded data sub-blocks, random values, and private keys are used for subsequent integrity verification. Therefore, each coded vector... The verification tag is:

[0035] .

[0036] To determine the number of cloud servers available in the system Then, the drone first calculated the amount of coded data stored on each cloud server. The codeword matrix follows. Construct an adapted table of randomly distributed encoded data records. It is used to record the encoding vector and its verification label corresponding to each cloud server.

[0037] In some examples, a record table can be randomly distributed based on the coded data. Leaf nodes Then, based on the Merkel hash tree structure, the drones proceed in logical order on each cloud server. Calculate the hash root And thus obtain hash sub-roots Based on Merkel hash tree structure and hash sub-roots The drone can calculate the root hash value. Drone settings auxiliary metadata and generate a blockchain transaction. , For file tags.

[0038] Meanwhile, the drone is set to store data. And send it to the cloud server. , Let be the verification label for the i-th encoded vector.

[0039] Upon receiving stored data After that, cloud server Recalculate the hash root And retrieve blockchain transactions from the blockchain. To obtain the hash subroot .

[0040] Subsequently, cloud server Check the equation:

[0041] Check if they are equal. If not, store the data. Storage was denied. Otherwise, the cloud server... Check its correctness using the following formula: .in If the equation for checking correctness holds true, the cloud server... Preserve stored data The cloud server will store the data; otherwise, it will refuse to store the data. .

[0042] As in the aforementioned embodiments, after the blockchain deployment is completed, the integrated regulatory service platform, drones, and server clusters join the blockchain network and obtain a unique blockchain address. , and .

[0043] Furthermore, the integrated regulatory service platform UOM in this application embodiment deploys the following smart contracts on the blockchain: challenge contract. Validate the contract and positioning contracts .

[0044] Therefore, based on the foregoing embodiments, a blockchain-based multi-cloud data integrity verification method according to the embodiments of this application is implemented through a smart contract deployed on the blockchain. The smart contract is responsible for performing integrity verification on drone data stored on multiple cloud servers without downloading the full data. The method includes three stages: an audit challenge generation stage, a response proof generation stage, and a response proof verification stage.

[0045] Specifically, if the verification result determined in the response proof verification phase is a failure, the following actions are taken:

[0046] A location contract deployed on the blockchain is used to locate faulty cloud servers. The set of multiple cloud servers is subjected to integrity verification based on the predetermined verification algorithm until all faulty cloud servers with incomplete stored data are located. A faulty cloud server location entry is set through the location contract, and a transaction is provided to the blockchain. The located faulty cloud servers are used to locate damaged coded data blocks. After the faulty cloud server listens to the blockchain to obtain the transaction it provides, it performs fragment verification on the local storage of the faulty cloud server to determine the specific damaged coded data blocks.

[0047] The method will now be explained in detail.

[0048] Audit challenge generation phase: This phase is initiated by the first smart contract deployed on the blockchain. The specific steps for execution are as follows:

[0049] First Smart Contract Based on the current state of the blockchain and the block height, obtain the header hash value of the latest block. Extract the previous ones in reverse order. The block header hash. First smart contract. Calculate the audit challenge seed key 1:

[0050]

[0051] And Audit Challenge Seed Key 2:

[0052] .

[0053] First Smart Contract Output Audit Challenges:

[0054]

[0055] in and These respectively represent the audit objectives The number of challenged encoded vectors and data blocks. Furthermore, to generate a challenge index for the encoded vectors, the first smart contract... Call the pseudo-random generator ,index ,in This is a counter variable used in the challenge index generation process to distinguish different challenge indexes generated in the same audit round. .

[0056] This generates a challenge index set for the encoded vectors. for:

[0057] ,in Indicates cloud server The set of indices of the encoded vectors that need to be challenged. Finally, the first smart contract. Record table based on random distribution of coded data Set up audit sub-challenges and generate a blockchain transaction. As the first transaction.

[0058] Response proof generation phase: This phase is handled by each cloud server. Perform the steps separately, as follows:

[0059] After listening to blockchain transactions After that, cloud server Obtaining the audit sub-challenge And retrieve the corresponding stored data. After that, the cloud server Computation in the Coding Challenge Data Vector Index Set The index of the encoded data block below , Similarly, a counter variable is used to represent the data block challenge index generation process, distinguishing different data block challenge indexes generated in the same audit round. .

[0060] Indexing each coded data block cloud server Calculate the corresponding weights for it. , Subsequently, the cloud server Calculate combined encoded data blocks , ,in cloud server The stored challenged encoded data blocks are aggregated with corresponding verification tags. ,in:

[0061] ;in It is a value with the hash value of the random value corresponding to the challenged coded data block as the base and the corresponding weight as the exponent.

[0062] ;in It is a value with the label corresponding to the challenged coded data block as the base and the corresponding weight as the exponent.

[0063] In the above two equations, It is a large prime number. The multiplicative cyclic group.

[0064] Finally, cloud servers Generate response proof And generate a transaction on the blockchain. As a second transaction, it is stored in the block.

[0065] Response Proof Verification Phase: This phase is handled by verification contracts deployed on the blockchain. The specific steps for execution are as follows:

[0066] Verify the contract within the specified time frame. All second transactions were detected. And obtain the response proof. Subsequently, the contract was verified. Recalculate the data vector index set in the coding challenge The index of the encoded data block below and their weights:

[0067] ,in Validate the contract Examine outsourced storage data using the following batch verification equation. Completeness:

[0068] in If the integrity calculation equation holds, then verify the contract. Output "True" if the audit result is true; otherwise, output "False".

[0069] Validate Contract Create an audit log entry and generate a blockchain transaction. ,in The timestamp representing the output of the audit results.

[0070] The applicant further considered that existing data integrity verification mechanisms suffer from the problem of vague location of damaged data. When an audit fails, existing solutions can typically only locate the problematic cloud server, lacking the ability to accurately pinpoint the specific damaged data blocks, greatly increasing the difficulty and cost of data repair. In other words, when coded data is corrupted, data recovery is required. However, in a distributed storage system, data recovery presupposes the accurate location of the faulty cloud server and the coded data blocks it stores.

[0071] Therefore, based on the foregoing embodiments, this application also provides a blockchain-based multi-cloud data error location method, which mainly includes two stages: a damaged data accurate location stage and a damaged data recovery stage.

[0072] Accurate location of damaged data stage: This stage consists of locating the faulty cloud server and the damaged coded data block.

[0073] Error location on cloud server: When the audit result is "False", the location contract deployed on the blockchain... Triggered to initiate the location of the faulty cloud server. Location contract. Initialize a candidate index set and an empty set The empty set Cloud server used to collect detected errors Indexes, and use management stacks. To manage the subset of indexes to be inspected. For each from the management stack The collection that pops up ,if Then its index is directly used as the error cloud server. Add to collection Middle, otherwise Divided into two approximately equal subsets and Each subset must pass through the aforementioned equation:

[0074]

[0075] Perform integrity verification. If verification fails, locate the contract. Push it into the management stack This process is pending further recursive subdivision and integrity verification. It is repeated iteratively until all erroneous cloud server indexes are included in the set. In the middle. Finally, the positioning contract. Set up an entry for locating the faulty cloud server:

[0076] and provide a transaction to the blockchain. .

[0077] Location of damaged encoded data blocks: When an off-chain cloud server malfunctions... Transaction detected Then, the location of the damaged coded data block is initiated. Error occurred on the cloud server. First, the audit target (i.e., the target object) is retrieved. Data stored in and define a finite set Then, the cloud server encountered an error. Initialize another empty collection This is to record the complete encoded vector of the data. Simultaneously, a counter is set up. To track sets For each set Error in cloud server The verification tags are aggregated and calculated to generate a combined coded data block. ,in The error occurred in the encoded data vector index of the cloud server.

[0078] and aggregate signature: ( , ),in The hash value of the random value corresponding to the erroneous encoded data block. The labels corresponding to the erroneous encoded data blocks are used, and integrity verification is performed using the following batch verification equation:

[0079] ,in The coded data block in the erroneous cloud server, where H is the seventh hash function, specifically a secure, collision-resistant hash function. .

[0080] If the above verification equation holds, in the set All indexes were added In the middle, and the counter Add one; otherwise, set There are damaged encoding vectors, and they are marked and Unchanged. Until all sets After all verifications were completed, an error occurred on the cloud server. Based on the properties of uniform (K, N) sets on a finite set, the damaged encoding vector is determined and output. .

[0081] Damaged data recovery phase: This phase is handled by the cloud server. With the erroneous cloud server The joint execution involves the following steps:

[0082] Error cloud server Send a data recovery request to the help cloud server ,in This indicates the established help agreement. Upon receiving a data recovery request... Then, it helps the cloud server retrieve stored data and sends recovery metadata. Error cloud server .

[0083] When the number of received recovery metadata reaches After the above, the cloud server encountered an error. From the encoding matrix Extract the corresponding submatrix The encrypted data file is recovered through the following calculations. : Ultimately, the cloud server malfunctioned. calculate To replace the erroneous encoding vector .

[0084] Based on the foregoing embodiments, for further explanation, the derivation process of some of the aforementioned formulas is provided.

[0085] The equation for checking correctness in the above embodiments is:

[0086]

[0087] The derivation process for using cloud server CS to verify the correctness of outsourced data sent by drones is as follows:

[0088]

[0089] The equation for calculating integrity in the foregoing embodiments is as follows:

[0090]

[0091] Used for the second smart contract The derivation process for verifying the integrity of outsourced data in cloud server CS storage is as follows:

[0092] in .

[0093] Therefore, this application implements an identity-based homomorphic hash signature algorithm to aggregate verification tags and data returned by different servers in a multi-cloud environment under a unified structure, making the verification equation linearly composable. This structure avoids the high communication and computational overhead caused by block-by-block signature verification in traditional solutions, and realizes a lightweight auditing process of off-chain aggregation and on-chain consistency verification. This solution significantly reduces computational complexity in multi-node, multi-block auditing scenarios, making it more suitable for the continuous outsourced storage and rapid verification needs of TB-level data from low-altitude UAVs.

[0094] In summary, this application implements a three-layer progressive error location mechanism to accurately locate faulty servers and corrupted data blocks. To address the difficulty of accurately locating damaged blocks in existing multi-cloud systems, a three-layer location mechanism of "server detection—subset determination—block-level verification" is constructed. The verification contract can automatically recursively divide the index space when auditing fails and perform batch verification on the partitions, effectively isolating the faulty server. The faulty node gradually shrinks the search space based on a uniform (K,N) set and combined signatures to accurately locate the corrupted encoded data block. This structured location method significantly reduces recovery costs and substantially improves system diagnostic efficiency.

[0095] This invention employs Reed-Solomon erasure coding to encode the raw UAV data, ensuring that all shards are evenly distributed across multiple cloud servers, significantly reducing the overhead of traditional replica-based redundant storage. In the event of cloud server failure or data corruption, the method helps the cloud server recover the lost original data blocks and their homomorphic tags based on the encoding matrix, achieving data regeneration without relying on centralized components. This method offers advantages such as high fault tolerance, high stability, and low-bandwidth recovery, meeting the long-term storage and robustness requirements of UAV data.

[0096] To avoid the risk of information leakage due to the exposure of drone identities, this invention employs an identity-based key exchange and symmetric encryption mechanism to achieve conditional anonymity for users. In normal business operations, cloud servers and auditors cannot obtain the true identity of the drone, ensuring mission privacy and security. In the event of abuse or malicious behavior, the integrated monitoring service platform can trace the identity of the corresponding user, achieving a balance between anonymity and accountability.

[0097] Compared to traditional multi-cloud auditing, which relies on cloud agents or third-party auditors and is prone to trust bottlenecks and forgery risks, this application utilizes blockchain smart contracts to solidify the entire audit process on the chain, making the audit process open, transparent, automated, and tamper-proof. All results are traceable and require no local computing resources from the user, demonstrating outstanding practical feasibility and credibility in resource-constrained scenarios such as drones.

[0098] The above description is merely a preferred embodiment of the present invention. It should be understood that the present invention is not limited to the forms disclosed herein and should not be construed as excluding other embodiments. It can be used in various other combinations, modifications, and environments, and can be altered within the scope of the concept described herein through the above teachings or related technologies or knowledge. Modifications and variations made by those skilled in the art that do not depart from the spirit and scope of the present invention should be within the protection scope of the appended claims.

Claims

1. A method for anonymizing drone identities and outsourcing secure data, characterized in that, Based on a comprehensive monitoring platform and drones, including: During the system initialization phase, the integrated monitoring platform performs operations based on given security parameters. Generate system parameters, including the master private key. and public parameters; During the user anonymity and private key generation phase, the drone generates an anonymous identity and submits registration information to the integrated monitoring service platform to obtain the user's private key sk corresponding to the anonymous identity. The drone generating an anonymous identity and submitting registration information to the integrated monitoring platform includes: the drone setting an initial login password and selecting a random value, combined with the drone's identity identifier. With validity period Calculate and generate the anonymous identity and the first user's public key The drone will contain the aforementioned anonymous identity. First user public key The registration information, including the initial login password, is sent to the integrated regulatory service platform; the integrated regulatory service platform uses its master private key. The registration information is processed to recover the drone's true identity, and a corresponding user private key sk and a second user public key are calculated and generated for this anonymous identity. The integrated monitoring service platform transmits the user's private key sk and the second user's public key through a secure channel. As a pair Send to the drone; During the data preprocessing and outsourcing stage, the drone will upload the data files to be uploaded. The data is divided into multiple data blocks, each data block is further divided into multiple data sub-blocks, and each data sub-block is encrypted using a symmetric encryption algorithm to obtain ciphertext sub-blocks. The subscript ij represents the j-th sub-block of the i-th data block; Then, the UAV uses erasure coding to encode the ciphertext data blocks, generating multiple encoding vectors. For each encoded data block in the encoding vector, the UAV calculates its corresponding verification tag, including: the UAV selects an encoding matrix. ,in The number of data blocks, Given the total number of encoded data blocks, the codeword matrix is ​​calculated as follows: ;in, It is a data file Encrypted ciphertext , It is by Individual Model The data space composed of elements It is a data sub-block; the codeword matrix Includes the encoded vectors, based on each encoded vector Each coded data block in The drone selects a random value. , It is a model Find the remaining class rings and calculate their corresponding verification labels: In the formula, For random values The hash mapping value, The title is a homomorphic authentication tag generated by the drone based on coded data sub-blocks, random values, and a private key. H is the seventh hash function, and Title is the filename. The drone obtains the number of available cloud servers, calculates the amount of encoded data stored on each cloud server, and then constructs an adapted random distribution record table of encoded data to record the encoding vector and its verification label corresponding to each cloud server, so as to allocate and transmit the storage data that the drone needs to store to one of the multiple cloud servers for storage.

2. The method for anonymizing drone identities and outsourcing secure data according to claim 1, characterized in that, After receiving the user's private key sk and the second user's public key, the drone verifies the validity of the user's private key sk using the following equation: In the formula, The system's master public key, For the third hash function, It is a generator of a cyclic group; If the above verification equation holds true, the drone will receive the binary tuple. Otherwise, the drone rejects the binary pair. The system requests the integrated regulatory service platform to regenerate the user's private key sk and the second user's public key. .

3. The method for anonymizing drone identities and outsourcing secure data according to claim 1, characterized in that, Before storing the data, the method further includes: The drone constructs a Merkel hash tree and calculates hash roots at each cloud server in logical order to obtain several hash sub-roots; The drone is configured with auxiliary metadata to generate a blockchain transaction that includes the root hash value and file metadata.

4. The method for anonymizing drone identities and outsourcing secure data according to claim 3, characterized in that, After receiving the stored data, the cloud server recalculates the hash root and retrieves the blockchain transactions from the blockchain to obtain the hash root; then, the cloud server checks whether its recalculated hash root is equal to the hash root retrieved from the blockchain transactions. If they are not equal, the stored data is rejected; otherwise, the cloud server will store the data after verifying its correctness.

5. The method for anonymizing drone identities and outsourcing secure data according to claim 4, characterized in that, The process of storing data after the cloud server checks its correctness includes the following formula: In the formula, , The amount of encoded data stored for each cloud server, y is the number of data sub-blocks, and H is the seventh hash function; If the equation for checking correctness is true, the cloud server retains and stores the data; otherwise, the cloud server refuses to store the data.

6. The method for anonymizing drone identities and outsourcing secure data according to claim 1, characterized in that, The drone's stored data is: in, Let be the verification label for the i-th encoded vector. The amount of encoded data stored for each cloud server; The stored data is sent to the cloud server. , , This refers to the number of cloud servers.

7. The method for anonymizing drone identities and outsourcing secure data according to claim 1, characterized in that, It also includes challenge contracts, verification contracts, and location contracts deployed on the blockchain.

8. A drone identity anonymization and secure data outsourcing system, characterized in that, It includes drones, an integrated monitoring service platform, and multiple cloud servers for executing the drone identity anonymization and security data outsourcing method as described in any one of claims 1-7.