Encryption and decryption system and method for vehicle and road cloud collaborative management and medium
By using a vehicle-road-cloud collaborative management encryption and decryption system, and employing equivalence testing to verify the equivalence of ciphertexts, the system solves the problems of high data storage overhead and data leakage in encryption technologies in multi-network converged vehicle networks, improves communication security and efficiency, and achieves fine-grained forward security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- STATE GRID ELECTRIC VEHICLE SERVICE CO LTD
- Filing Date
- 2024-10-12
- Publication Date
- 2026-04-14
AI Technical Summary
In the convergence of multiple networks in vehicle network technology, existing encryption technologies suffer from high data storage overhead and frequent data leaks due to the vulnerability of data transmission channels.
The encryption and decryption system, which adopts vehicle-road-cloud collaborative management, encrypts the initial ciphertext by matching coefficient vectors based on identity identifiers, preset tag sets, and publicly available system parameters on the device side. The ciphertext is then uploaded to the cloud server via the roadside device. The cloud server performs an equivalence test and sends it to the user end for decryption. The equivalence test verifies the equivalence of the ciphertext, reducing the data storage overhead on the device side.
By reducing data storage overhead on the device side, the data communication security and efficiency of the encryption and decryption system are improved, and fine-grained forward security and precise data management are achieved.
Smart Images

Figure CN121865254A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information security technology, specifically to an encryption / decryption system, method, and medium for vehicle-road-cloud collaborative management. Background Technology
[0002] In related technologies, the convergence of multiple networks in vehicle-to-everything (V2X) technology has brought significant benefits to vehicles during operation. However, due to the vulnerability of data transmission channels, data breaches occur frequently. Encryption technology, as a crucial data security measure, has long been highly anticipated by the industry. However, encryption technology still faces challenges such as substantial storage overhead in V2X technology. Summary of the Invention
[0003] To address the problems of existing technologies, this invention proposes an encryption / decryption system, method, and medium for vehicle-road-cloud collaborative management, aiming to reduce data storage overhead.
[0004] The objective of this invention is achieved through the following technical solution:
[0005] On one hand, the present invention provides an encryption / decryption system for vehicle-road-cloud collaborative management, the encryption / decryption system comprising: a cloud server, a user terminal, and a device terminal deployed on the vehicle, wherein:
[0006] The device is used to encrypt the collected environmental information based on the device's identity identifier, the coefficient vector matched by a preset tag set, and publicly available system parameters to obtain initial ciphertext, and then upload the initial ciphertext to the cloud server via the roadside device.
[0007] The cloud server is configured to perform an equivalence test on the initial ciphertext based on the authorization trapdoor sent by the user terminal, and obtain a test result; it is also configured to send the initial ciphertext to the user terminal if the test result is successful.
[0008] The user terminal is configured to initiate an equivalence test request on the initial ciphertext and generate an authorization trapdoor; send the authorization trapdoor to the cloud server; and decrypt the initial ciphertext sent by the cloud server to obtain the environment information.
[0009] Optionally, the device is further configured to employ a set d-order polynomial function. Set the preset label set S = {t1,...,t} d} is converted into a coefficient vector that matches the preset tag set. Where n and z are both preset variables, i represents the i-th coefficient vector, d is the number of labels in the preset label set, and t1,t j ,t dFor the labels in the preset label set, y1,y i ,y n These are the parameters that constitute the coefficient vector.
[0010] Optionally, the user terminal is specifically used to generate the authorization trapdoor based on the user terminal's identity identifier and the user terminal's private key when an equivalence test request is initiated on the initial ciphertext.
[0011] Optionally, the encryption / decryption system further includes: a trusted authorization center;
[0012] The trusted authorization center is used to broadcast the generated system public parameters to the device and the user.
[0013] The trusted authorization center is further configured to, in response to receiving a first registration request sent by the device, generate and send the device's private key to the device based on the device's identity identifier, the system's public parameters, and the master key; wherein the first registration request carries the device's identity identifier;
[0014] The trusted authorization center is further configured to, in response to receiving a second registration request sent by the user terminal, generate and send the user terminal's private key to the user terminal based on the user terminal's identity identifier, the system's public parameters, and the master key; wherein the second registration request carries the user terminal's identity identifier.
[0015] Optionally, the cloud server is further configured to send the initial ciphertext to the user terminal if the test result indicates that the information included in the initial ciphertext and the ciphertext to be tested provided by the user terminal are equal;
[0016] The user terminal is specifically used to decrypt the initial ciphertext based on the system's public parameters, the user terminal's identity identifier, and the user terminal's private key to obtain the environment information.
[0017] Optionally, the cloud server is further configured to determine that the equivalence test result is a failure if the information included in the initial ciphertext and the ciphertext to be tested is not equal, as indicated by the test result.
[0018] Optionally, the user terminal is further configured to perform a piercing attack on the user terminal's private key based on the preset tag set to obtain the pierced private key;
[0019] The private key after puncture is a private key that does not have the ability to decrypt the initial ciphertext.
[0020] On the other hand, the present invention also provides an encryption / decryption method for vehicle-road-cloud collaborative management, applied to a cloud server within a vehicle-road-cloud collaborative management encryption / decryption system, the method comprising:
[0021] Receive initial ciphertext uploaded by the roadside device; wherein, the initial ciphertext is obtained by encrypting the collected environmental information by the device deployed on the vehicle based on the device's identity identifier, a coefficient vector matched by a preset tag set, and publicly available system parameters;
[0022] Based on the authorization trapdoor sent by the user terminal, an equivalence test is performed on the initial ciphertext to obtain the test result; wherein, the authorization trapdoor is generated when the user terminal initiates an equivalence test request on the initial ciphertext;
[0023] If the test result is satisfactory, the initial ciphertext is sent to the user terminal so that the user terminal can decrypt the initial ciphertext to obtain the environment information.
[0024] Optionally, the process of obtaining the coefficient vector matched by the preset label set includes: using a set d-order polynomial function. Set the preset label set S = {t1,...,t} d} is converted into the coefficient vector that matches the preset tag set. Where n and z are both preset variables, i represents the i-th coefficient vector, d is the number of labels in the preset label set, and t1,t j ,t d For the labels in the preset label set, y1,y i ,y n These are the parameters that constitute the coefficient vector.
[0025] Furthermore, this application also provides a readable storage medium having an executable program stored thereon, which, when executed, implements the encryption and decryption method for vehicle-road-cloud collaborative management as described in any of the preceding claims.
[0026] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0027] This invention provides an encryption / decryption system for vehicle-road-cloud collaborative management. Within this system, the collected environmental information is first encrypted at the device end based on the device's identity identifier, a coefficient vector matching a preset tag set, and publicly available system parameters, resulting in a constant-length ciphertext, i.e., the initial ciphertext. Then, the user end can verify the initial ciphertext on the cloud server based on an equivalence test. This approach, by using a constant-length ciphertext to reduce data storage overhead at the device end, and by leveraging equivalence testing, improves the communication security and efficiency of data within the encryption / decryption system.
[0028] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit the technical solutions provided in the embodiments of the present invention. Attached Figure Description
[0029] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort, wherein:
[0030] Figure 1 This is a schematic diagram of the composition structure of an encryption and decryption system for vehicle-road-cloud collaborative management provided in an embodiment of the present invention;
[0031] Figure 2 This is a schematic diagram illustrating the interaction between a trusted authorization center and a user terminal and a device terminal during the initialization phase, as provided in an embodiment of the present invention.
[0032] Figure 3 This is a schematic diagram illustrating the interaction between a user terminal and a device terminal with a trusted authorization center during the registration phase, as provided in an embodiment of the present invention.
[0033] Figure 4 This is a schematic diagram illustrating the process of forming initial ciphertext and the interaction between the initial ciphertext on the device and the cloud server, as provided in an embodiment of the present invention.
[0034] Figure 5 A schematic diagram illustrating an information interaction process during the equivalence testing phase, provided in an embodiment of the present invention;
[0035] Figure 6 This is a schematic diagram illustrating the interaction between a user terminal and a cloud server during the acquisition and use of initial ciphertext, as provided in an embodiment of the present invention.
[0036] Figure 7 This is a schematic diagram of information interaction during the private key piercing phase performed by a user terminal, provided in an embodiment of the present invention.
[0037] Figure 8 This invention provides a P-IBEET system model diagram for a fine-grained forward-secure identity-based encryption scheme that supports equivalence testing under multi-network fusion.
[0038] Figure 9 This is a flowchart illustrating an encryption / decryption method for vehicle-road-cloud collaborative management provided in an embodiment of the present invention. Detailed Implementation
[0039] The embodiments of the present invention will be described below with reference to the accompanying drawings and preferred embodiments. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be understood that the preferred embodiments are only for illustrating the present invention and not for limiting the scope of protection of the present invention.
[0040] In the following description, references are made to “some embodiments,” which describe a subset of all possible embodiments. However, it is understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.
[0041] In the following description, the terms "first, second, third" are used merely to distinguish similar objects and do not represent a specific ordering of objects. It is understood that "first, second, third" may be interchanged in a specific order or sequence where permitted, so that the embodiments of the invention described herein can be implemented in an order other than that illustrated or described herein.
[0042] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which embodiments of the invention pertain. The terminology used herein is for descriptive purposes only and is not intended to limit the scope of the invention.
[0043] Vehicle-to-everything (V2X) technology, integrating vehicles, sensors, and infrastructure with powerful analytics and processing capabilities, significantly optimizes the on-road experience for drivers. In a V2X environment, vehicles and nearby infrastructure form a self-organizing network to easily acquire real-time road traffic data. Among related technologies, the onboard unit (OBU) mounted on the vehicle can exchange information with roadside units (RSUs) installed along the roadside. After collecting sufficient information about the vehicle and the road, the RSU transmits the data to a cloud server platform associated with the traffic control center, enabling the center to authorize further actions. Simultaneously, the cloud server platform can identify and categorize the collected information to manage vehicle information more effectively without compromising efficiency.
[0044] However, despite the significant benefits that converged vehicle-to-everything (V2X) technology brings to vehicles during operation, data breaches frequently occur due to the vulnerability of data transmission channels. Encryption technology, as a crucial data security measure, has long been highly anticipated by the industry. However, traditional encryption methods suffer from a significant drawback: without the private key, the appropriate data structure used for statistical purposes cannot be guaranteed. Furthermore, if data is maliciously obtained by a third party during encryption, key leakage could compromise the confidentiality of all previously encrypted communications and recorded sessions. In addition, to achieve compatibility between data confidentiality and classification, the current industry practice is to use public-key signature schemes with equality checks. In this scheme, encryption and signing operations are performed simultaneously, thus achieving message confidentiality and authentication. However, this scheme still faces the same challenges as Public Key Infrastructure (PKI), namely, the potential for significant storage and computational overhead.
[0045] To address the aforementioned issues, embodiments of the present invention provide an encryption / decryption system, method, and medium for vehicle-road-cloud collaborative management.
[0046] Example 1
[0047] Please see Figure 1 The diagram shown is a structural representation of an encryption / decryption system for vehicle-road-cloud collaborative management according to an embodiment of the present invention. The encryption / decryption system 100 includes: a cloud server 102, a user terminal 103, and a device terminal 101 deployed on a vehicle.
[0048] The device terminal 101 is used to encrypt the collected environmental information based on the identity identifier of the device terminal 101, the coefficient vector matched by the preset tag set, and the publicly available parameters of the system to obtain an initial ciphertext, and then upload the initial ciphertext to the cloud server terminal 102 through the roadside device terminal.
[0049] The cloud server 102 is used to perform an equivalence test on the initial ciphertext based on the authorization trapdoor sent by the user terminal 103, and obtain a test result; it is also used to send the initial ciphertext to the user terminal 103 if the test result is successful.
[0050] The user terminal 103 is used to initiate an equivalence test request on the initial ciphertext and generate an authorization trapdoor; send the authorization trapdoor to the cloud server 102; and also to decrypt the initial ciphertext sent by the cloud server 102 to obtain the environment information.
[0051] In some embodiments of the present invention, the device 101 deployed on the vehicle may be the vehicle's OBU, and the vehicle may be any vehicle traveling on the road and in a vehicle-to-everything (V2X) environment.
[0052] In some embodiments of the present invention, device 101 can sense environmental information of the vehicle's environment through internal sensing elements (sensors), including but not limited to: the vehicle's own driving data, the vehicle's location information, and image information of the vehicle's environment. It then uses relevant algorithms to encrypt the collected (sensed) environmental information to form initial ciphertext, which is then sent to cloud server 102 for storage via a roadside unit (RSU). Here, device 101 and / or cloud server 102 can also process the initial ciphertext accordingly when encountering other related requests; for example, the initial ciphertext can be temporarily stored within the RSU.
[0053] In some embodiments of the present invention, device 101 runs a corresponding encryption algorithm to encrypt the environment information, such as running the algorithm P-IBEET.Encrypt(params,M,ID,t1,...,t d Encryption environment information; wherein, the encryption environment information M of the encryption algorithm may involve the following parameters: system public parameter params, device 101's identity identifier ID, and a set of tags S = {t1,...,t...} d}
[0054] In some embodiments of this application, before the encryption / decryption system 100, where the device 101 is located, sends the initial ciphertext to the cloud server 102 via the roadside device, it needs to complete the following operations using its internal related devices: initialization operation and system member registration phase. Here, the encryption / decryption system 100 may further include: a trusted authorization center 104, which correspondingly completes the aforementioned initialization operation and system member registration operation, i.e.:
[0055] The trusted authorization center 104 is used to broadcast the generated system public parameters to the device terminal 101 and the user terminal 103.
[0056] The trusted authorization center 104 is further configured to, in response to receiving a first registration request sent by the device terminal 101, generate and send the private key of the device terminal 101 to the device terminal 101 based on the identity identifier of the device terminal 101, the system public parameters and the master key; wherein, the first registration request carries the identity identifier of the device terminal 101;
[0057] The trusted authorization center 104 is further configured to, in response to receiving a second registration request sent by the user terminal 103, generate and send the private key of the user terminal 103 to the user terminal 103 based on the identity identifier of the user terminal 103, the system public parameters and the master key; wherein the second registration request carries the identity identifier of the user terminal 103.
[0058] In some embodiments of the present invention, the trusted authorization center 104 is a trusted authority center, and its running algorithm is P-IBEET.Setup(1 k d) Generate the master key MSK and system public parameters params. Here, k is a security parameter, and d is the maximum number of tags embedded in the initial ciphertext. Subsequently, the system public parameters params can be broadcast from the encryption / decryption system 100 to the user terminal 103 and device terminal 101 within the encryption / decryption system 100. For example... Figure 2 The diagram illustrates the interaction between the Trusted Authorization Center and the client and device during the initialization phase.
[0059] In some embodiments of the present invention, the algorithm Setup(1) k ,d) takes the security parameter k and the maximum number of tags d embedded in the subsequently generated ciphertext as input.
[0060] First, the algorithm Setup(1 k d) Generate a bilinear mapping e: G×G→G T ; where G and G T Let G and G represent two multiplicative cyclic groups of prime order p, respectively, and g be the generator of group G.
[0061] Secondly, define three hash functions: H0:{0,1} * →G, and H2:G T →G; where l1 and l2 are groups Z respectively. p and the bit length of the elements in G, and from group Z P Four elements υ, α, β, ω are randomly selected from the given information. R Z p and random selection Where n is the independent variable.
[0062] Then, calculate V = g υ W = g ω , Δ=e(g,g) α And Γ=e(g,g) β and set And t0 is selected as the initial label. Here, t0 is set to distinguish it from the labels used in the subsequent puncture algorithm, and t0 will not be used again in subsequent regular operations. Based on this, [the following is a separate section:] t0 is set.
[0063] Finally, the output params = (g, (e, G, G) T ),V,W,{U i} i∈[1,n] ,Δ,Γ,H0,H1,H2) and MSK=(α,β).
[0064] In some embodiments of the present invention, after receiving the publicly disclosed system parameters params, both the user terminal 103 and the device terminal 101 can identify themselves by their own identifiers ID∈{0,1}. * A registration application is submitted to the trusted authorization center 104. If approved, the user can join the encryption / decryption system 100 as a registered member. Simultaneously, after joining the encryption / decryption system 100, both the user terminal 103 and the device terminal 101 will generate an initial private key SK0 for the registered member using the algorithm P-IBEET.Key-Extract(ID,params,MSK). Figure 3 The diagram illustrates the interaction between the user and the device during the registration phase and the trusted authorization center.
[0065] Here, the input to the algorithm Key-Extract(ID, params, MSK) includes: ID ∈ {0, 1} * , params and MSK, and calculate h ID =H0(ID)∈G. Then, the algorithm randomly selects two elements r. id ,r f ∈ R Z p And calculate the following formulas (1) and (2) to obtain the two parts of the parameters that constitute the initial private key SK0: sk0 and in:
[0066]
[0067] Here, let and Thus, by using the algorithm Key-Extract(ID,params,MSK), multiple parameters constituting sk0 are generated through formulas (1) and (2) and the parameters involved in the initialization phase: t0, and its components Multiple parameters: t0; thus obtaining the initial private key of user terminal 103 and / or device terminal 101.
[0068] In some embodiments of this application, the algorithm Encrypt(params,M,ID,t1,...,t) d The inputs are: the user's ID, plaintext (i.e., the environmental information M(MSG) involved in this invention), the system's public parameters params, and a tag set S = {t1,...,t}. d}∈Z p \{t0}.
[0069] In some embodiments of the present invention, the preset tag set can be S = {t1,...,t}. d}, that is, S={t1,...,t d}∈Z p \{t0}, the coefficient vector is Here, a d-order polynomial function can be used. Set the preset label set S = {t1,...,t} d} is converted into a coefficient vector that matches the preset tag set. Where n and z are both preset variables, i represents the i-th coefficient vector, d is the number of labels in the preset label set, and t1,t j ,t d For the labels in the preset label set, y1,y i ,y n These are the parameters that constitute the coefficient vector. It can also be specified that when d+1 < n, the coefficient y... d+1 ,...,y n All are set to 0.
[0070] Additionally, when t i ∈{t1,...,t d}, then F S [z] = 0, that is Subsequently, the algorithm randomly selects an element s∈ R Z p And calculate the following formula (3) to obtain the initial ciphertext CT. Here, let Therefore, the initial ciphertext CT can be further encrypted using the following parameters: M s ·H2(Γ s ), g s , Composition. (See here for reference.) Figure 4 The diagram illustrates the process of forming the initial ciphertext and its interaction between the device and the cloud server.
[0071]
[0072] In some embodiments of the present invention, the cloud server 102 may receive an authorization trapdoor sent by the user terminal 103. This authorization trapdoor is generated by the user terminal 103 initiating an equivalence test request on the initial ciphertext. That is:
[0073] Specifically, the user terminal 103 is used to generate the authorization trapdoor based on the identity identifier of the user terminal 103 and the private key of the user terminal 103 when an equivalence test request is initiated on the initial ciphertext.
[0074] Here, after receiving the authorization trap, cloud server 102 can perform the following operations:
[0075] The cloud server 102 is further configured to send the initial ciphertext to the user terminal 103 if the information contained in the initial ciphertext and the ciphertext to be tested provided by the user terminal 103 are equal, as indicated by the test result. Correspondingly, the user terminal 103 is specifically configured to decrypt the initial ciphertext based on the system public parameters, the user terminal's identity identifier, and the user terminal 103's private key to obtain the environment information.
[0076] The cloud server 102 is further configured to determine that the equivalence test result is a failure when the information included in the initial ciphertext and the ciphertext to be tested are not equal, as indicated by the test result.
[0077] In some embodiments of the present invention, the equivalence test may be described with reference to the following:
[0078] The client 103 in the encryption / decryption system 100 can, according to its own needs (such as initiating an equivalence test request for the initial ciphertext), obtain its identity identifier ID∈{0,1}. * And the private key SK that I currently possess i Run the relevant trapdoor generation algorithm P-IBEET.TrapdoorGen(ID,SK) i A authorization trapdoor is generated and sent to the cloud server 102. Correspondingly, upon receiving the authorization trapdoor, the cloud server 102 inputs the selected trapdoor and ciphertext information into the algorithm P-IBEET.Test(TD1,TD2,CT1,CT2) and runs the algorithm. It then determines whether the ciphertext to be tested and the initial ciphertext (i.e., CT1 and CT2 in the algorithm, assuming the initial ciphertext is CT1 and the ciphertext to be tested is CT2) provided by the user terminal 103 originate from the same plaintext. If they match, the initial ciphertext CT1 is sent to the user terminal 103 to perform relevant decryption operations to obtain environment information; otherwise, the operation is terminated. (The text continues with further details about the cloud server 102 and its operation.) Figure 5 The diagram shown illustrates the information exchange process during the equivalence testing phase.
[0079] Among them, the algorithm TrapdoorGen(ID,SK) i The input is: the user's ID and private key SK. i .
[0080] Here, and Correspondingly, the authorized trapdoor TD (including TD1 and TD2) can be set as shown in formula (4):
[0081] TD = (T) (1) ,T (2) ,T (3) ,T (4) ,T (5) ) formula (4);
[0082] Among them, the authorization parameter that constitutes the authorization trapdoor TD is: T (1) T (2) T (3) T (4) T (5) They can be set as shown in the following formula (5):
[0083]
[0084] The algorithm Test(TD1,TD2,CT1,CT2) takes two ciphertexts as input: CT1 and CT2, and two authorized trapdoors: TD1 and TD2. Let... The two authorized traps unfold separately: The corresponding algorithm Test(TD1,TD2,CT1,CT2) can be used to convert and perform equivalence tests on CT1, CT2, TD1, and TD2 to obtain the following formulas (6) to (9):
[0085]
[0086] Wherein: Γ TD1 ,Γ TD2 All of these are test expressions used in the algorithm Test(TD1,TD2,CT1,CT2) for equivalence testing. After multiple parameter transformations, they can be used as equivalence test parameters. and This is expressed. Similarly, the equivalence test parameters X1 and X2 can be expressed using the parameters corresponding to the plaintext. and To express oneself.
[0087] Therefore, the equation is confirmed. If the condition is met, then the two plaintexts contained in the two ciphertexts CT1 and CT2 are considered to be equal, i.e., M1 = M2 (here, the plaintext contained in CT1 is taken as M1 and the plaintext contained in CT2 is taken as M2).
[0088] Following the description above, client 103 is specifically used to base its configuration on the system's publicly available parameters params, the client's identity identifier ID, and the client's private key SK. i The initial ciphertext CT is decrypted to obtain the environmental information.
[0089] In some embodiments of the present invention, after receiving the initial ciphertext returned by the cloud server 102, the user terminal 103 can run the decryption algorithm P-IBEET.Decrypt(params,ID,SK). i The initial ciphertext CT is decrypted to obtain the required plaintext information, i.e., the environment information. For example... Figure 6 The diagram illustrates the interaction between the user terminal and the cloud server during the acquisition and use of the initial ciphertext.
[0090] The algorithm Decrypt(params, ID, SK) i Inputs to CT: System public parameters params, user's identity ID, and private key SK i And the initial encrypted CT.
[0091] Here, let the initial ciphertext CT be expanded as follows: private key SK i Expanding, we get (sk′0, sk1, ..., sk i-1 ,sk i And set the following conditions: and in, It can be given by a set of labels S = {t1,...,t} d The d-th order polynomial function F S [z] is calculated. If the private key SK i All labels t∈{t1,...,t d},but Therefore If the expression Z does not exist, the decryption algorithm terminates and outputs ⊥ to indicate decryption failure. Conversely, if the expression Z does exist, the decryption expression Z can be calculated. τ And the corresponding parameter Δ, namely the following formulas (10) and (11):
[0092]
[0093] Where τ=0,...,i, corresponding to, as well as All are algorithms Decrypt(params, ID, SK) i The decryption parameters in CT).
[0094] Subsequently, the algorithm Decrypt(params, ID, SK) i ,CT) Determine whether the following formulas (12) and (13) are true:
[0095] g s =ct (2) Formula (12);
[0096]
[0097] If both formulas (12) and (13) are true, then by calculation Environmental information M and s can be obtained.
[0098] In some embodiments of the present invention, a private key piercing stage can be further performed. The purpose of this stage is to revoke the decryption capabilities of some user terminals 103 for specific information, thereby achieving precise forward security and preventing malicious actors from damaging the encryption / decryption system 100. Specifically, the user terminal 103 is also used to pierce its private key based on the preset tag set to obtain the pierced private key.
[0099] The private key after puncture is a private key that does not have the ability to decrypt the initial ciphertext.
[0100] In some embodiments of the present invention, the legitimate data user in the encryption / decryption system 100, i.e., the user terminal 103, can access the tag t related to the initial ciphertext CT. i and the private key SK that has not yet been punctured i-1 Input puncture algorithm P-IBEET.Puncture(SK) i-1 ,t i In order to obtain the new private key SK after the puncture. i .like Figure 7 The diagram illustrates the information exchange during the private key piercing phase performed by the user.
[0101] Among them, the algorithm Puncture(SK) i-1 ,t i The inputs are: the user's ID (identity identifier) and private key SK. i-1 and the tag t i ∈{0,1} * \{t0}. Here, we define... Send the private key SK from user terminal 103 i-1 Expand as Then they each launched sk i-1 =(sk′0,sk1,...,sk i-1 )as well as Randomly select three elements λ j ,r j,0 ,r j,1 ∈ R Z p And calculate sk i =(sk′0,sk1,...,sk i-1 ,sk i The multiple parameters sk′0 and sk in ) i That is, refer to formulas (14) and (15):
[0102]
[0103] Based on this, we can obtain the user's ID (103) and the corresponding private key after the stab. Among them, sk i =(sk′0,sk1,...,sk i-1 ,sk i ); where the multiple parameter components constituting sk′0 are: as well as Correspondingly, sk constitutes i The multiple parameter parts are: V rj,1 , and t i .
[0104] Based on the above description, in the vehicle-road-cloud collaborative management encryption and decryption system 100, which includes: device 101, user 103, cloud server 102, and trusted authorization center 104, the following stages can be executed sequentially, as can be found in the references below. Figure 8 The diagram shown is a P-IBEET system model diagram in a fine-grained forward-secure identity-based encryption scheme under multi-network convergence that supports equivalence testing. Here, user terminal 103 includes multiple data users as an example.
[0105] S1 Initialization Phase: The trusted authorization center 104 runs the P-IBEET.Setup(1) algorithm. k d) Generate the master key MSK and the system public parameter params, and broadcast the system public parameter params to the user terminal 103 and device terminal 101 in the encryption / decryption system 100.
[0106] During the S2 system member registration phase: After receiving the publicly available system parameters params, both user terminal 103 and device terminal 101 can register their identities using their own identifiers ID∈{0,1}. * A registration application is submitted to the Trusted Authorization Center 104. If approved, the member can join the encryption / decryption system 100 as a registered member. Upon joining the encryption / decryption system 100, PKC will generate an initial private key SK0 for the registered member using the algorithm P-IBEET.Key-Extract(ID,params,MSK), and send it to the user terminal 103 and the device terminal 101.
[0107] S3 Information Collection and Transmission Phase: Device 101 runs the corresponding encryption algorithm to encrypt the environmental information, such as running the algorithm P-IBEET.Encrypt(params,M,ID,t1,...,t d Encrypt the environment information, obtain the initial ciphertext CT, and send it to the cloud server 102.
[0108] S4 Equivalence Testing Phase: User terminal 103 can, according to its own needs, base its identity identifier ID∈{0,1} * And the private key SK that I currently possess i Run the relevant trapdoor generation algorithm P-IBEET.TrapdoorGen(ID,SK) i A authorization trapdoor is generated and sent to the cloud server 102. Correspondingly, upon receiving the authorization trapdoor, the cloud server 102 inputs the selected trapdoor and ciphertext information into the algorithm P-IBEET.Test(TD1,TD2,CT1,CT2) and runs the algorithm. It then determines whether the ciphertext to be tested and the initial ciphertext (i.e., CT1 and CT2 in the corresponding algorithm, assuming the initial ciphertext is CT1 and the ciphertext to be tested is CT2) provided by the user client 103 originate from the same plaintext. If they match, the initial ciphertext CT1 is returned to the user client 103; otherwise, the operation is terminated.
[0109] S5 Information Acquisition and Utilization Phase: After receiving the initial ciphertext returned by the cloud server 102, the user terminal 103 can run the decryption algorithm P-IBEET.Decrypt(params,ID,SK). i The initial ciphertext CT is decrypted to obtain the plaintext information needed, i.e., the environment information.
[0110] S6 Private Key Piercing Phase: Client 103 can access the tags related to the initial ciphertext CT. i and the private key SK that has not yet been punctured i-1 Input puncture algorithm P-IBEET.Puncture(SK) i-1,t i In order to obtain the new private key SK after the puncture. i .
[0111] Based on the above description, the vehicle-road-cloud collaborative management encryption and decryption system provided by this invention first encrypts the collected environmental information at the device end based on: the device's identity identifier, a coefficient vector matching a preset tag set, and publicly available system parameters, to obtain a constant-length ciphertext, i.e., the initial ciphertext. Then, the user end can verify the initial ciphertext on the cloud server based on an equivalence test. In this way, based on a constant-length ciphertext to reduce the data storage overhead at the device end, and with the help of an equivalence test, the communication security and efficiency of data within the encryption and decryption system can be improved.
[0112] Building upon this foundation, embodiments of the present invention also provide a fine-grained forward security scheme for multi-network convergence that supports equivalence testing. This scheme allows user clients to autonomously update their private keys, providing not only fine-grained forward security for data, i.e., environmental information, but also maintaining necessary equivalence testing functionality, enabling user clients to verify that different ciphertexts originate from the same plaintext.
[0113] Example 2:
[0114] Based on the same inventive concept, this invention also provides an encryption / decryption method for vehicle-road-cloud collaborative management, applied to the cloud server within the encryption / decryption system of vehicle-road-cloud collaborative management. Please refer to [link to relevant documentation]. Figure 9 The diagram shown is a flowchart illustrating an encryption / decryption method for vehicle-road-cloud collaborative management provided in an embodiment of the present invention. The following is a summary of the process. Figure 9 The encryption and decryption method is explained below:
[0115] Step 901: Receive the initial ciphertext uploaded by the roadside device; wherein, the initial ciphertext is obtained by encrypting the collected environmental information by the device deployed on the vehicle based on the device's identity identifier, a coefficient vector matching a preset tag set, and publicly available system parameters;
[0116] Step 902: Based on the authorization trapdoor sent by the user terminal, perform an equivalence test on the initial ciphertext to obtain the test result; wherein, the authorization trapdoor is generated when the user terminal initiates an equivalence test request on the initial ciphertext;
[0117] Step 903: If the test result is passed, the initial ciphertext is sent to the user terminal so that the user terminal can decrypt the initial ciphertext to obtain the environment information.
[0118] In some embodiments of the present invention, the process of obtaining the coefficient vector of the preset tag set matching includes: using a set d-order polynomial function. Set the preset label set S = {t1,...,t} d} is converted into the coefficient vector that matches the preset tag set. Where n and z are both preset variables, i represents the i-th coefficient vector, d is the number of labels in the preset label set, and t1,t j ,t d For the labels in the preset label set, y1,y i ,y n These are the parameters that constitute the coefficient vector.
[0119] It should be noted that the description of the encryption / decryption method for vehicle-road-cloud collaborative management is similar to the description of the encryption / decryption system embodiment for vehicle-road-cloud collaborative management described above, and has similar beneficial effects to the system embodiment. For technical details not disclosed in the method embodiment of this invention, please refer to the description of the system embodiment of this invention for understanding.
[0120] Example 3:
[0121] Based on the same inventive concept, this invention also provides a readable storage medium, specifically an electronic device readable storage medium (Memory). This readable storage medium is a memory device within an electronic device used to store programs and data. It is understood that the storage medium here can include both built-in storage media within the electronic device and extended storage media supported by the electronic device. The storage medium provides storage space, which stores the terminal's operating system. Furthermore, this storage space also stores one or more instructions suitable for loading and execution by a processor. These instructions can be one or more executable programs (including program code). It should be noted that the storage medium here can be high-speed RAM or non-volatile memory, such as at least one disk storage device. The processor loads and executes one or more instructions stored in the storage medium to implement the encryption and decryption methods of the vehicle-road-cloud collaborative management described in the above embodiments.
[0122] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0123] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0124] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0125] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0126] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the specific implementation of the present invention. Any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.
Claims
1. An encryption / decryption system for vehicle-road-cloud collaborative management, characterized in that, The encryption / decryption system includes: a cloud server, a user terminal, and a device terminal deployed on the vehicle, wherein: The device is used to encrypt the collected environmental information based on the device's identity identifier, the coefficient vector matched by a preset tag set, and publicly available system parameters to obtain initial ciphertext, and then upload the initial ciphertext to the cloud server via the roadside device. The cloud server is configured to perform an equivalence test on the initial ciphertext based on the authorization trapdoor sent by the user terminal, and obtain a test result; it is also configured to send the initial ciphertext to the user terminal if the test result is successful. The user terminal is configured to initiate an equivalence test request on the initial ciphertext and generate an authorization trapdoor; send the authorization trapdoor to the cloud server; and decrypt the initial ciphertext sent by the cloud server to obtain the environment information.
2. The system according to claim 1, characterized in that, The device is also used to employ a set d-order polynomial function. Set the preset label set S = {t1,...,t} d } is converted into the coefficient vector that matches the preset tag set. Where n and z are both preset variables, i represents the i-th coefficient vector, d is the number of labels in the preset label set, and t1,t j ,t d For the labels in the preset label set, y1,y i ,y n These are the parameters that constitute the coefficient vector.
3. The system according to claim 1 or 2, characterized in that, Specifically, the user terminal is used to generate the authorization trapdoor based on the user terminal's identity identifier and the user terminal's private key when an equivalence test request is initiated on the initial ciphertext.
4. The system according to any one of claims 1 to 3, characterized in that, The encryption / decryption system also includes: a trusted authorization center; The trusted authorization center is used to broadcast the generated system public parameters to the device and the user. The trusted authorization center is further configured to, in response to receiving a first registration request sent by the device, generate and send the device's private key to the device based on the device's identity identifier, the system's public parameters, and the master key; wherein the first registration request carries the device's identity identifier; The trusted authorization center is further configured to, in response to receiving a second registration request sent by the user terminal, generate and send the user terminal's private key to the user terminal based on the user terminal's identity identifier, the system's public parameters, and the master key; wherein the second registration request carries the user terminal's identity identifier.
5. The system according to claim 1, characterized in that, The cloud server is also used to send the initial ciphertext to the user terminal if the information included in the initial ciphertext and the ciphertext to be tested provided by the user terminal are equal, as indicated by the test result. The user terminal is specifically used to decrypt the initial ciphertext based on the system's public parameters, the user terminal's identity identifier, and the user terminal's private key to obtain the environment information.
6. The system according to claim 5, characterized in that, The cloud server is also used to determine that the equivalence test result is a failure when the test result indicates that the information included in the initial ciphertext and the ciphertext to be tested are not equal.
7. The system according to claim 5, characterized in that, The user terminal is also used to perform a piercing attack on the private key of the user terminal based on the preset tag set to obtain the pierced private key. The private key after puncture is a private key that does not have the ability to decrypt the initial ciphertext.
8. An encryption / decryption method for vehicle-road-cloud collaborative management, characterized in that, A cloud server-side application within an encryption / decryption system for vehicle-road-cloud collaborative management, the method comprising: Receive initial ciphertext uploaded by the roadside device; wherein, the initial ciphertext is obtained by encrypting the collected environmental information by the device deployed on the vehicle based on the device's identity identifier, a coefficient vector matched by a preset tag set, and publicly available system parameters; Based on the authorization trapdoor sent by the user terminal, an equivalence test is performed on the initial ciphertext to obtain the test result; wherein, the authorization trapdoor is generated when the user terminal initiates an equivalence test request on the initial ciphertext; If the test result is satisfactory, the initial ciphertext is sent to the user terminal so that the user terminal can decrypt the initial ciphertext to obtain the environment information.
9. The method according to claim 8, characterized in that, The process of obtaining the coefficient vector matched by the preset tag set includes: Using a d-order polynomial function Set the preset label set S = {t1,...,t} d } is converted into the coefficient vector that matches the preset tag set. Where n and z are both preset variables, i represents the i-th coefficient vector, d is the number of labels in the preset label set, and t1,t j ,t d For the labels in the preset label set, y1,y i ,y n These are the parameters that constitute the coefficient vector.
10. A readable storage medium, characterized in that, It contains an executable program, which, when executed, implements the encryption and decryption method for vehicle-road-cloud collaborative management as described in any one of claims 8 and 9.
Citation Information
Patent Citations
A structured encryption method and system for performing an equivalence test based on a cloud service platform
CN109902501A
Searchable encryption method and system capable of flexibly replacing ciphertexts, and computer equipment
CN113626484A
Identity-based puncturable encryption method supporting equality testing
CN114095161A
Method and device for processing heterogeneous communication data between vehicles, equipment and storage medium
CN117715033A