Method, system and service platform for data aggregation and sharing supporting multi-data owner joint control

By generating individual sharing intention attribute vectors and access control rules through multiple data owners and users registered in the Trusted Center, and using the CP-ABE cryptographic framework for data encryption and aggregation, the problem of data owner self-control and user on-demand access in data sharing is solved, realizing differentiated control and efficient sharing in the data aggregation process.

CN122437689APending Publication Date: 2026-07-21STATE GRID INFORMATION & TELECOMM GRP CO LTD +1

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
STATE GRID INFORMATION & TELECOMM GRP CO LTD
Filing Date
2026-04-23
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

In data sharing scenarios with multiple data owners, it is difficult to simultaneously meet the data owners' need for continuous and controllable management of their own data, as well as the data users' access demands for on-demand and differentiated data acquisition.

Method used

By registering multiple data owners and data users in the Trust Center, an individual sharing intention attribute vector and access control rules are generated. The data is encrypted using the CP-ABE cryptographic framework, and differentiated data is aggregated on the aggregation platform to generate multiple sets of aggregation results, ensuring the data owner's autonomous control and the data user's on-demand access.

Benefits of technology

It achieves differentiated access strategies for data owners during the data aggregation process, ensuring that data owners can effectively control the aggregation conditions and sharing boundaries of their own data, while generating multiple sets of differentiated aggregation results to meet the access needs of data users and avoid information redundancy or insufficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122437689A_ABST
    Figure CN122437689A_ABST
Patent Text Reader

Abstract

The application provides a data aggregation and sharing method, system and service platform supporting multi-data owner joint control, relates to the technical field of data security, and is executed by an aggregation platform and comprises the following steps: receiving ciphertext data packets from multiple data owners, wherein the ciphertext data packets at least include differentiated access strategies set by the data owners independently; screening the ciphertext data packets authorized to the same data user according to the attribute set of the target data user and the differentiated access strategies of the ciphertext data packets, and obtaining multiple sets of aggregation results based on the screening result; and in response to a data access request of the target data user, determining the to-be-used aggregation result in the multiple sets of aggregation results authorized to the target data user according to the attribute set of the target data user, and sending the to-be-used aggregation result to the target data user. The application can meet the management requirement of the data owner for the continuous controllability of the data and the access appeal of the data user for the on-demand and differentiated access.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data security, and in particular to a data aggregation and sharing method, system, and business platform that supports joint control by multiple data owners. Background Technology

[0002] With the rapid growth of electric vehicle ownership and the rapid development of new energy transportation systems, the vehicle-to-grid (V2G) model is increasingly being applied in energy dispatching and charging service systems. A large number of distributed charging piles, charging stations, regional operators, and grid-side platforms are continuously connecting to the system, causing the V2G system to gradually evolve into a complex network structure involving multiple stakeholders operating collaboratively. Against this backdrop, the demand for sharing multi-dimensional power data among participating parties, including charging behavior records, real-time load status, electricity price information, and dispatching strategies, has significantly increased to support key operations such as load forecasting, dispatch optimization, demand response, and transaction settlement.

[0003] With the rapid increase in the number of participants in data sharing, the traditional data sharing model centered on centralized platforms is facing bottlenecks due to the concentrated computing and communication loads. To improve the security and efficiency of data sharing, hierarchical data aggregation under a multi-layered architecture is gradually becoming the mainstream model. This involves aggregating distributed data layer by layer from bottom to top, and then providing the aggregated results to the upper-level platform or data user.

[0004] However, this design focuses on the centralized aggregation and unified processing of data. Once the data is submitted to the centralized aggregation platform, its control is transferred from the data owner to the centralized aggregation platform. As a result, it is difficult to simultaneously meet the data owner's need for continuous and controllable management of its own data, as well as the data user's access demands for on-demand and differentiated data. Summary of the Invention

[0005] To address the shortcomings of existing technologies, this invention provides a data aggregation and sharing method, system, and business platform that supports joint control by multiple data owners. It solves the problem in existing technologies that, in data sharing scenarios involving multiple data owners, it is difficult to simultaneously meet the data owners' need for continuous and controllable management of their own data, as well as the data users' access demands for on-demand and differentiated data acquisition.

[0006] According to an embodiment of the present invention, a first aspect provides a data aggregation and sharing method that supports joint control by multiple data owners, executed by an aggregation platform. The aggregation platform is directed to multiple data owners and multiple data users who have completed entity registration in a trusted center. The data users submit a set of attributes to the trusted center during entity registration for the aggregation platform to retrieve. The method includes: Receive encrypted data packets from multiple data owners; the encrypted data packets include at least the differentiated access policies set by each data owner. The attribute sets of each data user are compared with the differentiated access policies of each encrypted data packet to filter out encrypted data packets authorized to the same data user; when the number of filtering results is greater than a preset threshold, all encrypted data packets authorized to the same data user are aggregated to obtain multiple sets of aggregation results. In response to a data access request from a target data user, the system determines the pending aggregation result authorized to the target data user from among the multiple aggregation results based on the target data user's attribute set, and sends the pending aggregation result to the target data user.

[0007] Optionally, for any target data owner among multiple data owners, the encrypted data packet includes at least an individual sharing intention attribute vector, individual attribute encrypted ciphertext, and individual data to be shared encrypted using a unified encryption key; The generation of the individual attribute encrypted ciphertext includes: The unified encryption key is split into multiple sub-key shares through secret sharing, and the target data owner owns one of the sub-key shares. The target data owner’s subkey share is encrypted using the master public key allocated by the trusted center, and an access control rule is bound to it. The access control rule is used to specify whether each data user can access the subkey share owned by each data owner. The differentiated access strategy for each encrypted data packet is defined by the individual shared intention attribute vector and the access control rules. When comparing the attribute set of each data user with the differentiated access strategy of each encrypted data packet, if the individual shared intention attribute vector of one or more data owners indicates that the same data user has access rights, and the same data user satisfies the access control rules of one or more data owners, then the encrypted data packets of one or more data owners are all authorized to the same data user.

[0008] Optionally, when the number of filtered results exceeds a preset threshold, the data aggregation includes: Based on the encrypted data packets authorized to the same data user, and according to the additive homomorphism of the homomorphic encryption algorithm, the individual data to be shared in all the encrypted data packets authorized to the same data user are aggregated to generate aggregated data to be shared. The individual sharing intention attribute vectors in all encrypted data packets authorized to the same data user are aggregated to generate a joint sharing intention attribute vector; Based on the equivalence or logical equivalence of access control rules, aggregate the individual attribute encrypted ciphertexts in all encrypted data packets authorized to the same data user to generate aggregated attribute encrypted ciphertexts. The joint sharing intention attribute vector, aggregated attribute encrypted ciphertext, and aggregated data to be shared, obtained from the same data user, are used as a set of aggregation results for the multiple sets of aggregation results.

[0009] Optionally, the summary includes: For any data user, if the component corresponding to the data user in the individual sharing intention attribute vector of the encrypted data packet authorized to the data user is 1, then the component corresponding to the data user in the generated joint sharing intention attribute vector is 1; otherwise, it is 0. In this context, a component of an individual data owner's shared willingness attribute vector being 1 indicates that the data owner authorizes the data user corresponding to that component to access their data; a component of a joint shared willingness attribute vector being 1 indicates that the data user is authorized by all data owners and has the right to access all data owners' data.

[0010] Optionally, determining whether there are any pending aggregation results authorized to the target data user among the multiple sets of aggregation results includes: Read the joint sharing intention attribute vector in the aggregation result. If the joint sharing intention attribute vector in any one or more of the aggregation results points to the target data user, then the one or more aggregation results are intermediate aggregation results for the target data user. Read the encrypted ciphertext of the aggregated attributes in the intermediate aggregation result, and extract the access control rules from it. The access control rules include an access matrix and a mapping function. The attribute set of the target data user is associated with the corresponding row vector in the access matrix through the mapping function, and a set of coefficients is calculated. If the linear combination of the coefficients equals the target vector, then the intermediate aggregation result is used as the pending aggregation result, and the pending aggregation result, including the aggregated data to be shared and the encrypted ciphertext of the aggregation attribute, is sent to the target data user.

[0011] The second aspect provides a data aggregation and sharing system that supports joint control by multiple data owners, including a data owner terminal, a user terminal, an aggregation platform, and a trusted center; Multiple data owners on the data owner side and multiple data users on the user side complete entity registration in the trusted center. The trusted center allocates a master public key to the multiple data owners and allocates an attribute private key to each of the multiple data users according to the attribute set submitted during entity registration. For any target data owner among multiple data owners, the data owner performs the following steps: Set differentiated sharing intentions for different data users and generate individual sharing intention attribute vectors; Local data is encrypted using a unified encryption key to generate individual data to be shared. The unified encryption key is split into multiple sub-key shares, and the target data owner has one sub-key share. The sub-key shares are then encrypted using the master public key to generate individual attribute encrypted ciphertext. During encryption, access control rules that specify whether each data user can access each sub-key share are bound to the sub-key share. The individual sharing intention attribute vector, the encrypted ciphertext of the individual attributes, and the individual data to be shared are packaged into a ciphertext data packet and sent to the aggregation platform. The aggregation platform executes the data aggregation and sharing method supporting multi-data owner joint control as described above, aggregates the encrypted data packets, and responds to data access requests sent by any target data user among the multiple data users, sending the aggregation results to be used to the target data user. The target data user, based on its attribute private key, recovers the unified encryption key used to decrypt the aggregated data to be shared based on the aggregated results to be used, thereby obtaining shared data jointly controlled by multiple data owners.

[0012] Optionally, the settings generate individual sharing intention attribute vectors based on the differentiated sharing intentions of different data users, including: Based on its own business objectives, business relationships with each data user, and at least in combination with user credit assessment and data security requirements, the sharing targets and scope for each data user should be dynamically adjusted. The adjustment results are represented in vector form to generate the individual shared willingness attribute vector; The dynamic adjustment responds to changes in one or more of the following: the business objectives, the business relationships with each data user, the user credit assessment, and the data security requirements.

[0013] Optionally, it also includes: Set general sharing preferences; For any data user, if the differentiated sharing intention is not set, the general sharing intention is used to generate an individual sharing intention attribute vector.

[0014] The third aspect provides a business platform based on vehicle-to-network interaction, using the data aggregation and sharing system that supports joint control of multiple data owners as described above; Among them, the data owners on the data owner side include at least one or more of the following: charging piles, charging stations, charging operators, and electric vehicle users; the data users on the user side include at least one or more of the following: charging facility manufacturers, power grid dispatch centers, third-party energy service providers, research institutions, and industry management agencies.

[0015] A fourth aspect provides a computer-readable storage medium storing instructions that, when executed by a processor, configure the processor to perform the data aggregation and sharing method as described above that supports multi-owner joint control.

[0016] Compared with existing technologies, the present invention has the following advantages: The aggregation platform filters the authorized objects of each encrypted data packet, ensuring that the authorized objects of encrypted data packets participating in the same data aggregation process are the same data users. This fully preserves the differentiated access policies set by each data owner during data aggregation. Even if the encrypted data packets are submitted to the centralized platform, the data owner can still effectively control the aggregation conditions and sharing boundaries of their own data. In addition, by setting a preset threshold value, the aggregation operation is only performed when a sufficient number of owners authorize it, thereby generating multiple sets of differentiated aggregation results for different authorized objects. This avoids the information redundancy or insufficiency problems caused by traditional "one-size-fits-all" aggregation and ensures that the aggregation results are only open to data users who meet the authorization conditions. Attached Figure Description

[0017] Figure 1 This is a schematic diagram of the structure of a data aggregation and sharing system that supports joint control by multiple data owners, as described in an embodiment of the present invention. Figure 2 This is a flowchart illustrating the information interaction process between various execution entities in a data aggregation and sharing system that supports joint control of multiple data owners, as described in this embodiment of the invention. Figure 3 This is a flowchart illustrating the execution steps of the data owner in a data aggregation and sharing system that supports joint control by multiple data owners, as described in this embodiment of the invention. Figure 4 This is a flowchart illustrating the execution steps of the aggregation platform in a data aggregation and sharing system that supports joint control by multiple data owners, as described in an embodiment of the present invention. Detailed Implementation

[0018] The technical solutions of the present invention will be further described below with reference to the accompanying drawings and embodiments.

[0019] like Figure 1 As shown, this embodiment of the invention provides a data aggregation and sharing system that supports joint control by multiple data owners, including a data owner terminal, a user terminal, an aggregation platform, and a trusted center. The data owner terminal serves multiple data owners, and the user terminal serves multiple data users.

[0020] It should be noted that in this embodiment of the invention, the trusted center completes initialization, such as holding the master public key and master private key after system parameter settings. The aggregation platform, data users, and data owners complete entity registration at the initialized trusted center. The trusted center then manages keys based on the data used for entity registration at each end, including the master public key allocated to multiple data owners and attribute private keys allocated to each data user based on the attribute sets submitted during entity registration. The aggregation platform also obtains the master public key after completing entity registration at the trusted center, but does not obtain the master private key or any data user's attribute keys, and does not have the ability to decrypt aggregated ciphertext. It is understood that the trusted center can also perform key updates, providing trusted support for the secure operation of the system.

[0021] This invention is applied to real-world scenarios involving multiple data owners. Simply encrypting and aggregating the data ignores the differentiated sharing intentions of different data owners regarding shared objects and scope, and also makes it difficult to support data users in selectively obtaining aggregation results based on business needs. Therefore, Figures 2 to 4 This paper illustrates the sequential steps of information interaction among various executing entities in a data aggregation and sharing system supporting multi-data-owner joint control, as described in an embodiment of the present invention. Through the working principle and execution process of the entire system, it explains how the present invention achieves secure data aggregation and refined sharing under multi-data-owner joint control.

[0022] Please see Figure 2In the data preparation phase, the Trusted Center first sets system parameters and generates and distributes the master public key and private keys for each attribute. Then, the aggregation platform, data users, and data owners register with the Trusted Center entity. In addition, data encryption for each data owner is also included. For example, each data owner collects data according to its own business and independently sets differentiated access policies, i.e., the sharing objects and scope for different data users. These sharing objects and scopes are specifically implemented through two types of parameters: individual sharing intention attribute vectors and access control rules. The former expresses whether a data owner allows a specific data user to access its data, while the latter defines what attribute conditions a data user must meet to decrypt the data. After encrypting the local data, the data owner uploads it to the aggregation platform along with the above two types of parameters to form a encrypted data packet. The individual sharing intention attribute vector and access control rules serve as publicly accessible information that does not require decryption. Unlike traditional solutions that uniformly configure differentiated access policies only after data aggregation is completed, this embodiment of the invention supports a data aggregation and sharing system jointly controlled by multiple data owners. The setting of sharing objects and scopes is completed before data aggregation, integrating differentiated access policies into the entire data encryption and aggregation process. Even when encrypted data packets are submitted to the aggregation platform, the differentiated access policies set by each data owner remain in effect, at least during the data aggregation phase executed by the platform. This includes the platform's ability to differentiate access needs based on the shared objects and scopes preset by each data owner—specifically, individual sharing intention attribute vectors and access control rules—and to generate differentiated aggregation results on demand without decrypting the data content, thus reducing the risk of privacy leaks. The aggregation platform ultimately generates multiple sets of aggregation results for different authorized objects, such as the pending aggregation results authorized to the target data user, providing support for subsequent differentiated data access. In the final data sharing phase, when a data user is within the shared objects and scopes set by one or more data owners, after initiating a data access request to the aggregation platform, the platform will have an aggregation result authorized to that user—the pending aggregation result. The data user can then use their private attribute key to decrypt the pending aggregation result, thereby obtaining data matching their business needs on demand.

[0023] Taking a vehicle-to-grid (V2G) interaction scenario as an example, suppose a charging station operator, as the data owner, sets up sharing objects and scopes for two types of data users: the power grid dispatch center and the trading platform. The operator authorizes the power grid dispatch center to share the total regional load and charging pile availability status, while authorizing the trading platform to share electricity price and electricity consumption information. In existing data aggregation and sharing mechanisms, because data aggregation is performed before configuring differentiated access strategies, only a single aggregation result, such as the total regional load, is usually generated. This results in insufficient information for the power grid dispatch center, while the trading platform receives a large amount of useless information. However, in this embodiment of the invention, because the data owner embeds differentiated sharing objects and scopes, such as individual sharing intention attribute vectors and access control rules, into encrypted data packets before data aggregation, the aggregation platform can generate aggregation results for the power grid dispatch center and for the trading platform respectively, based on these preset constraints. The former includes the total regional load and charging pile availability status, while the latter includes electricity price and electricity consumption information. Therefore, the data aggregation process and multiple aggregation results of the aggregation platform have fine-grained aggregation capabilities that match the differentiated use needs of shared data, ultimately achieving the differentiated sharing goal of the trading platform obtaining electricity price and electricity consumption information on demand, and the power grid dispatch center obtaining regional total load and charging pile availability status on demand.

[0024] To achieve the above process, this embodiment of the invention supports a data aggregation and sharing system jointly controlled by multiple data owners. At the algorithm level, it employs the CP-ABE cryptographic framework, so that encryption and decryption operations involving data owners, data users, and the trusted center are all implemented based on this CP-ABE cryptographic framework. On this basis, the data aggregation of the aggregation platform uses decryptable homomorphic aggregation operations. For example, the trusted center first executes the system initialization algorithm. The algorithm takes a security parameter λ as input and generates a master public key PK and a master private key MSK to be distributed to multiple data owners. The trusted center then uses an attribute key generation algorithm... Taking the master private key MSK and the attribute set S submitted during data user entity registration as input, the output is the attribute private key SK bound to the attribute set S. S This key is then distributed to the corresponding data user. Following this, the unified encryption key shown in step SA2 below is negotiated and generated by each data owner, and used for homomorphic encryption of local data m. Finally, the encryption algorithm is used. , represents the step SA3 below shown for generating encrypted ciphertext of individual attributes, where For access control rules, the final generated encrypted ciphertext representation of individual attributes is as follows: The unified encryption key K is split into N independent subkey shares {k1,k2,...,k}. N}, k iThis represents the share of the subkey held by data owner i.

[0025] To achieve the fine-grained autonomous control that data owners have over their own data during the data preparation and data aggregation phases, as described above, and as a concrete implementation of the differentiated access strategy, such as... Figure 2 and Figure 3 As shown, for any target data owner among multiple data owners, the data owner performs the following steps: SA1. Set differentiated sharing intentions for different data users and generate individual sharing intention attribute vectors; SA2. Encrypt local data using a unified encryption key to generate individual data to be shared. The unified encryption key is split into multiple sub-key shares, and the target data owner has one sub-key share. Then, the sub-key shares are encrypted using the master public key to generate individual attribute encrypted ciphertext. During encryption, access control rules that specify whether each data user can access each sub-key share are bound to the sub-key share. SA3. Package the individual sharing intention attribute vector, the encrypted individual attribute, and the individual data to be shared into an encrypted data packet and send it to the aggregation platform.

[0026] In this embodiment of the invention, the differentiated sharing intentions of different data users can be set according to multiple dimensions such as the data owner's business needs, trust assessment, and security policies, and represented by a vector, and dynamically updated according to real-time status or external feedback. In one embodiment, the detailed implementation steps of step SA1 above include: Based on its own business objectives, business relationships with each data user, and at least in combination with user credit assessment and data security requirements, the sharing targets and scope for each data user should be dynamically adjusted. The adjustment results are represented in vector form to generate the individual shared willingness attribute vector; The dynamic adjustment responds to changes in one or more of the following: the business objectives, the business relationships with each data user, the user credit assessment, and the data security requirements.

[0027] Taking the vehicle-to-grid (V2G) interaction business scenario as an example, the charging station operator i is the data owner i, and the data owner i's initial setting for the individual sharing willingness vector of different data users is set to... In this shared willingness vector, each dimension corresponds to a type of data. That is, the element value of each vector element indicates whether the data owner i allows the data user j to access its m-th data. For example, the charging station operator i allows the power grid dispatch center (j=1) to share the total regional load (m=1) and the charging pile status (m=2). Therefore, the vector elements... For load aggregators (j=2), shared vehicle type distribution (m=1) and SOC information (m=2) are allowed; therefore, vector elements... The trading platform (j=3) allows shared electricity prices (m=1) and electricity consumption (m=2), therefore, the vector elements... One day, charging station operator i detected a risk of data misuse by a load aggregator, resulting in a significant drop in its reputation assessment. Therefore, it dynamically adjusted its individual sharing willingness vector, changing the original distribution of allowed vehicle types to only allow sharing to the aggregated total number, while keeping other data users unchanged. The vector elements... The above adjustments are reflected in real time in the individual sharing willingness attribute vector of charging station operator i towards load aggregator. In this system, the values ​​of vector elements are dynamically updated as credit assessments and business relationships change, ensuring that the data owner can always control the scope of data sharing according to the latest wishes, thus guaranteeing the rationality and security of data flow.

[0028] Considering that in practical applications, data owners may face situations where they have not yet established clear business relationships with some data users or where the access needs of certain data users do not require fine-grained differentiation, in this embodiment of the invention, the data owner can also pre-set a set of default sharing rules, such as general sharing intentions, to cover data users who have not separately configured differentiated intentions. Based on this, step SA1 above may also include the following steps: Set a general sharing intention; if any data user has not set the differentiated sharing intention, then use the general sharing intention to generate an individual sharing intention attribute vector.

[0029] Steps SA1 and SA2 above illustrate the data preparation stage. The target data owner divides the encryption operation performed by the data owner into two stages. In the first stage, the data is encrypted with a unified key to ensure that the ciphertext structure is consistent and can be aggregated. In the second stage, the subkey share is protected with CP-ABE to ensure that only entities that meet the rules can recover the complete key and then decrypt the data.

[0030] This embodiment of the invention also explains the role and implementation principle of the unified encryption key and subkey share through the process of determining the unified encryption key and generating subkey shares in the encryption operation shown in step SA2: First, each data owner determines the secret value k of the unified encryption key. Then, the secret value k is split into multiple subkey shares k using a random polynomial. iEach data owner's subkey share is a specific value derived mathematically from the secret value k. Therefore, when any data owner owns a share, it means they possess a necessary part derived from the secret value k for recovering the unified encryption key K. Only when a sufficient number of shares are combined can the secret value k be recovered to reconstruct the complete unified encryption key K. Therefore, in the following embodiments, a preset threshold value can be set as the number of subkey shares used to obtain the unified encryption key.

[0031] In step SA1 above, each data owner independently and dynamically sets an individual sharing intention attribute vector to express their differentiated authorization intentions to different data users; in step SA2, the data owner uses a unified encryption key K to encrypt local data to generate individual data to be shared, and uses the master public key PK to encrypt the subkey share k held by themselves. i This generates encrypted ciphertext containing individual attributes. The subkey share k... i Bound to access control rules, the master public key (PK) corresponds to the attribute private key (SKS) assigned to the data user, and this access control rule is essentially an attribute-based linear secret sharing scheme. Based on the above design, when data aggregation is performed on the aggregation platform and when data users decrypt the data based on the aggregation results, controllable constraints can be achieved on data decryption permissions and usage scope, ensuring that access to aggregated data is limited by the joint authorization and attribute policies of multiple data owners.

[0032] Step SA3 above illustrates the data that the aggregation platform can obtain. In specific applications, the individual sharing willingness attribute vector is represented as follows: ; represent the encrypted ciphertext of individual attributes as Where i represents any data owner, k i A represents the share of a subkey held by any data owner. i Indicates access control rules, A i =(M i , ρ i M i Let M represent the access matrix of l*n. i This is used to split the secret value k of the unified encryption key K into n secret shares, and further generate multiple subkey shares k. i ;ρ i Represents the mapping function, mapping function ρ i Used to access matrix M i Each row is associated with an attribute label; individual data to be shared is represented as local data m encrypted with a unified encryption key K. m iThis represents local data encrypted by data owner i using a unified encryption key K. The mathematical representation above better illustrates the mathematical guarantees of ciphertext structure consistency and aggregability conditions, the joint determination mechanism of sharing intention, and the threshold mechanism in the following data aggregation phase; as well as the verification process of attributes satisfying access control policies, the decryption permission control under the dual constraints of the joint sharing intention attribute vector and access control rules, and the on-demand acquisition of differentiated aggregation results in the following data sharing phase.

[0033] Based on steps SA1 to SA3 above, this embodiment of the invention constructs an individual sharing intention attribute vector to characterize the differentiated sharing intentions of each data owner towards different data users. On the one hand, this supports data owners in constraining the sharing objects and scope of their data, enabling them to exercise fine-grained autonomous control over their own data. On the other hand, it allows the aggregation platform to provide matching, decryptable aggregation results based on the authorization differences of data users. At the data encryption level, each data owner uses a unified encryption key to encrypt the individual data to be shared, ensuring that the generated ciphertext maintains consistency in mathematical structure and encryption parameters, thus laying the foundation for subsequent aggregateable operations. Simultaneously, regarding the allocation of control over the encryption key, this embodiment of the invention divides the encryption key into multiple sub-key shares. Each data owner holds one sub-key share, and each data owner uses the master public key to encrypt each sub-key share, forming individual attribute encrypted ciphertext. When generating the individual attribute encrypted ciphertext, the sub-key shares held by the data owner are also bound to access control rules. Thus, the access control rules apply to the sub-key shares collaboratively generated by multiple data owners. In practical applications, data users can directly obtain the rules without decryption. Based on this, the aforementioned individual sharing intention attribute vector, individual attribute encrypted ciphertext, and individual data to be shared enable the aggregation platform to perform decryptable aggregation operations on these ciphertexts without disrupting the access structure, thereby providing a foundation for the efficient aggregation and differentiated sharing of multi-owner data.

[0034] Based on the individual sharing intention attribute vectors, individual attribute encrypted ciphertexts, and individual data to be shared provided by the data owners, the aggregation platform performs data aggregation in the data aggregation stage according to the joint authorization constraints expressed by the individual sharing intention attribute vectors and access control rules. Thus, upon receiving a data access request from a data user, it can perform decryptable homomorphic aggregation operations on these ciphertext data packets without disrupting the access structure. This enables the generation of differentiated aggregation results under the joint authorization constraints of multiple data owners, completing the entire closed loop from data owner self-control to data user on-demand access.

[0035] like Figure 2 and Figure 4As shown, this embodiment of the invention also provides a data aggregation and sharing method supporting joint control by multiple data owners, illustrating the detailed steps of the aggregation platform in performing data aggregation and access verification. According to the data aggregation and sharing system supporting joint control by multiple data owners in the above embodiments, the aggregation platform is oriented towards multiple data owners and multiple data users who have completed entity registration in a trusted center. When a data user registers an entity, they submit an attribute set to the trusted center for the aggregation platform to retrieve. Based on this, the steps performed by the aggregation platform include, but are not limited to: SB1. Receive encrypted data packets from multiple data owners; the encrypted data packets include at least the differentiated access policies set by each data owner. SB2. Compare the attribute sets of each data user with the differentiated access policies of each encrypted data packet to filter out encrypted data packets authorized to the same data user; when the number of filtering results is greater than a preset threshold, aggregate all encrypted data packets authorized to the same data user to obtain multiple sets of aggregation results. SB3. In response to the data access request of the target data user, determine the pending aggregation result authorized to the target data user from the multiple sets of aggregation results based on the attribute set of the target data user, and send the pending aggregation result to the target data user.

[0036] Regarding step SB1 above, the above embodiment has shown the differentiated access strategy set by the data owner when generating the encrypted data packet locally. This strategy, implemented through two types of parameters—individual sharing intention attribute vector and access control rules—specifically targets the sharing objects and scope for different data users. This differentiated access strategy both restricts the access permissions of each data user and achieves fine-grained, controllable sharing dominance over their own data. For how to set this strategy, refer to steps SA1 to SA3 above. For ease of description, it is shown here that: for any target data owner among multiple data owners, the encrypted data packet includes at least an individual sharing intention attribute vector, individual attribute encrypted ciphertext, and individual data to be shared encrypted using a unified encryption key. The generation of the individual attribute encrypted ciphertext includes: The unified encryption key is split into multiple sub-key shares through secret sharing, and the target data owner owns one of the sub-key shares. The target data owner's subkey share is encrypted using the master public key allocated by the trusted center, and an access control rule is bound to it. The access control rule is used to specify whether each data user can access the subkey share owned by each data owner.

[0037] In this embodiment of the invention, the consistency of the encrypted structure and the conditions for aggregation during the data aggregation stage include: (1) each data owner explicitly allows the same data user to access the data in their individual shared intention attribute vector; (2) the access control rules of the attribute-encrypted ciphertexts are the same or logically equivalent; and (3) the number of ciphertext data packets participating in the aggregation reaches a preset threshold. Therefore, when the ciphertext data packets simultaneously meet the above three conditions, the aggregation platform performs data aggregation, and the data users corresponding to the ciphertext data packets participating in the same aggregation process are the same. Therefore, firstly, step SB2 uses the encrypted data packets shown in step SB1 as the basic data and makes a preliminary determination based on the combined authorization conditions of the first and second filtering conditions. That is, the differentiated access strategy of each encrypted data packet is jointly defined by the individual shared intention attribute vector and the access control rules. Therefore, when comparing the attribute set of each data user with the differentiated access strategy of each encrypted data packet, if the individual shared intention attribute vector of one or more data owners indicates that the same data user has access rights, and the same data user satisfies the access control rules of one or more data owners, then the encrypted data packets of one or more data owners are all authorized to the same data user.

[0038] It should be noted that in the encrypted data packet authorized to the same data user, the individual shared intention attribute vector indicates that the same data user has the right to access the data owner that provides the individual shared intention attribute vector, and the access control rules bound to the individual attribute encrypted ciphertext all allow the same data user to access it.

[0039] Then, step SB2 above uses the number of encrypted data packets authorized to the same data user as the base data and performs further filtering with the third filtering condition, that is: data aggregation is performed when the number of filtering results is greater than a preset threshold.

[0040] It should be noted that the threshold value is set based on the inherent requirements of the secret sharing mechanism: only when a sufficient number of shares are combined can the secret value be recovered to reconstruct the complete unified encryption key. Therefore, the aggregation platform uses a preset threshold value t as the final condition for ciphertext aggregation, which essentially ensures at the operational level that the aggregation group contains valid authorized ciphertext from no fewer than t data owners.

[0041] At the algorithm level, the aggregation platform of this embodiment of the invention implements data aggregation based on homomorphic encryption algorithm. Therefore, the data aggregation in step SB2 above when the number of filtered results is greater than a preset threshold includes obtaining a joint sharing intention attribute vector based on individual sharing intention attribute vectors, obtaining aggregated data to be shared based on individual data to be shared, and obtaining aggregated attribute encrypted ciphertext based on individual attribute encrypted ciphertext. The detailed implementation steps include: Based on the encrypted data packets authorized to the same data user, and according to the additive homomorphism of the homomorphic encryption algorithm, the individual data to be shared in all the encrypted data packets authorized to the same data user are aggregated to generate aggregated data to be shared. The individual sharing intention attribute vectors in all encrypted data packets authorized to the same data user are aggregated to generate a joint sharing intention attribute vector; Based on the equivalence or logical equivalence of access control rules, aggregate the individual attribute encrypted ciphertexts in all encrypted data packets authorized to the same data user to generate aggregated attribute encrypted ciphertexts. The joint sharing intention attribute vector, aggregated attribute encrypted ciphertext, and aggregated data to be shared, obtained from the same data user, are used as a set of aggregation results for the multiple sets of aggregation results.

[0042] In one embodiment, the aggregation includes: For any data user, if the component corresponding to the data user in the individual sharing intention attribute vector of the encrypted data packet authorized to the data user is 1, then the component corresponding to the data user in the generated joint sharing intention attribute vector is 1; otherwise, it is 0. In this context, a component of an individual data owner's shared willingness attribute vector being 1 indicates that the data owner authorizes the data user corresponding to that component to access their data; a component of a joint shared willingness attribute vector being 1 indicates that the data user is authorized by all data owners, that is, has the right to access the data of all data owners.

[0043] Based on the individual sharing intention attribute vector, individual attribute encrypted ciphertext, and mathematical representation of the individual data to be shared provided in the above embodiments, the mathematical representation of the joint sharing intention attribute vector can be: , where u=1,2,3,...,i, This represents the individual sharing intention vector based on all data owners. The statistical analysis of voting results regarding whether data user j has authorized access to the m-th data set is performed only when all data owners vote that a data user can authorize access to the aggregated data; only then will the component for that data user in the joint sharing intention attribute vector be 1. The mathematical representation of the aggregated data to be shared can be C. agg =∑C mi , where C mi This represents individual data to be shared. The mathematical representation of aggregated attribute encrypted ciphertext can be... Among them, CT ABE This represents the encrypted ciphertext of individual attributes. The mathematical representation of the aggregation result is then: .

[0044] Different aggregation results are differentiated in terms of access control policies and federated sharing intention constraints. Therefore, for a data user making a data access request, a usable aggregation result can only be obtained if the user has sufficient access permissions to the encrypted data packets provided by each data owner. Therefore, step SB3 above is used to determine whether there is a usable aggregation result authorized to the target data user among the multiple sets of aggregation results. The verification includes: for any aggregation result, whether the data user has access permissions, decryption permissions, and the scope of the data user's permissions. Specific implementation methods include: Read the joint sharing intention attribute vector in the aggregation result. If the joint sharing intention attribute vector in any one or more of the aggregation results points to the target data user, then the one or more aggregation results are intermediate aggregation results for the target data user. Read the encrypted ciphertext of the aggregated attributes in the intermediate aggregation result, and extract the access control rules from it. The access control rules include an access matrix and a mapping function. The attribute set of the target data user is associated with the corresponding row vector in the access matrix through the mapping function, and a set of coefficients is calculated. If the linear combination of the coefficients equals the target vector, then the intermediate aggregation result is used as the pending aggregation result, and the pending aggregation result, including the aggregated data to be shared and the encrypted ciphertext of the aggregation attribute, is sent to the target data user.

[0045] Therefore, the target data user shown in step SB3 above is a verified data user in a data aggregation and sharing system that supports multi-data-owner joint control. Based on... Figure 2 The entire process and execution are illustrated. In the final data sharing stage, the target data user can use the attribute private key allocated by the trusted center based on the attribute set to recover the unified encryption key used to decrypt the aggregated data to be shared based on the aggregated results, thereby obtaining shared data jointly controlled by multiple data owners.

[0046] Understandably, in the above steps, if none of the multiple aggregation results contain an intermediate aggregation result pointing to the target data user, the joint sharing intention verification fails, the data user cannot obtain the aggregated ciphertext, and the decryption process terminates directly. If the target data user's attribute set does not meet the access control policy defined in the aggregated attribute encrypted ciphertext, the subsequent CP-ABE decryption will fail, and the target data user will still be unable to recover the encryption key and obtain the shared data jointly controlled by multiple data owners.

[0047] Based on steps SB1 to SB3 above, the aggregation platform, acting as a hub for data flow, can fully preserve the differentiated access strategies independently set by each data owner when receiving and processing encrypted data packets embedded with individual sharing intention attribute vectors and access control rules. Even if the data is submitted to a centralized platform, the data owner can still effectively control the aggregation conditions and sharing boundaries of their own data through preset sharing objects and scopes. On this basis, the aggregation platform generates joint authorization decisions based on the sharing intentions of each data owner through joint authorization judgment and threshold filtering mechanisms. It only performs aggregation operations under the premise of obtaining authorization from a sufficient number of owners and consistent access control rules, thereby generating multiple sets of differentiated aggregation results for different authorized objects. This avoids the information redundancy or insufficiency problems caused by traditional "one-size-fits-all" aggregation and ensures that the aggregation results are only open to data users who meet the authorization conditions. At the same time, since the access control rules, individual sharing intention vectors, and joint sharing intention vectors are all information that can be obtained without decryption, the aggregation platform can complete the above aggregation and filtering process without decrypting the data content or destroying the access structure, effectively ensuring the privacy and security of the data throughout its entire lifecycle. Therefore, the embodiments of the present invention support a data aggregation and sharing method jointly controlled by multiple data owners, which enables the aggregation platform to undertake the core functions of data aggregation and distribution while respecting and implementing the personalized authorization requirements of multiple data owners, and enabling data users to obtain the aggregation results on demand and accurately. Ultimately, under a centralized architecture, the collaborative goal of "data controllability, flexible sharing, and privacy protection" is achieved.

[0048] Based on the joint sharing intention attribute vector, aggregate attribute encrypted ciphertext, and mathematical representation of the aggregated data to be shared provided in the above embodiments, the complete decryption process after the target data user obtains the pending aggregation result includes: the target data user receiving the pending aggregation result sent by the aggregation platform, which contains the aggregated data to be shared C. agg and aggregate attribute encryption ciphertext The target data user first decrypts the aggregated attribute encrypted ciphertext using their attribute private key SKS. Since this aggregated attribute encrypted ciphertext is composed of individual attribute encrypted ciphertexts from multiple data owners, and the target data user's attribute set S has been verified through access control rules, the target data user can extract the corresponding subkey share k from each individual attribute encrypted ciphertext. i In detail, for each individual attribute encrypted ciphertext, the target data user accesses the access matrix M based on their attribute set S. i The corresponding row vector and mapping function ρ i A set of coefficients {wx} is calculated such that a linear combination of these row vectors equals the target vector, thereby recovering the secret value k, and further obtaining the subkey share k owned by the data owner. iWhen the number of subkey shares successfully obtained by the target data user reaches a preset threshold, the unified encryption key K can be recovered through the secret sharing reconstruction algorithm. Finally, the target data user uses the unified encryption key K to aggregate the data C to be shared. agg Performing a decryption operation yields shared data jointly controlled by multiple data owners, thereby enabling on-demand and controllable data sharing.

[0049] In practical applications, assume there are two data owners: charging station A and charging station B, who each upload encrypted data packets targeting the power grid dispatch center to the aggregation platform. In the individual sharing intention attribute vector of charging station A, the component corresponding to the power grid dispatch center is 1, and the same component is also 1 in charging station B. Therefore, in the joint sharing intention attribute vector generated by the aggregation platform, the component corresponding to the power grid dispatch center is 1, indicating that the data user is authorized by all data owners and has the right to access all data. At this point, the aggregation platform uses the intermediate aggregation result pointed to by this joint sharing intention attribute vector as a candidate.

[0050] Next, the aggregation platform verifies the access rights of the power grid dispatch center using the encrypted ciphertext of the aggregated attribute associated with the intermediate aggregation result. Assume that the encrypted ciphertext of the aggregated attribute is composed of two encrypted ciphertexts of individual attributes, and each individual attribute encrypted ciphertext is bound to an access control rule, A. i =(M i , ρ i Taking the access control rules of charging station A as an example, let its access matrix M be... A for: M A =[1 0,1 1]; Mapping function ρ A The first row of the matrix is ​​associated with the attribute "Dispatch Center", and the second row is associated with the attribute "Regional Management". The attribute set S of the power grid dispatch center is S = {Dispatch Center, Regional Management}. The system first filters out the rows whose attribute labels belong to S, namely the first and second rows. Then it checks whether there exists a set of coefficients {w1, w2} such that the linear combination of these two row vectors equals the target vector (1, 0). Calculation shows that setting w1 = 1 and w2 = 0 satisfies 1 × (1, 0) + 0 × (1, 1) = (1, 0). Therefore, the attribute set of the power grid dispatch center satisfies the access structure of charging station A. Similarly, if its attribute set also satisfies the access structure of charging station B, then the access control rule bound to the aggregated attribute encrypted ciphertext passes the verification. At this point, the intermediate aggregation result is officially determined as the aggregation result to be used, and the aggregation platform sends the aggregated data to be shared and the aggregated attribute encrypted ciphertext to the power grid dispatch center.

[0051] On the other hand, embodiments of the present invention also provide a business platform based on vehicle-to-grid interaction, using the data aggregation and sharing system supporting joint control of multiple data owners as shown in the above embodiments; wherein, the data owners on the data owner side include at least one or more of charging piles, charging stations, charging operators, and electric vehicle users; the data users on the user side include at least one or more of charging facility manufacturers, power grid dispatch centers, third-party energy service providers, research institutions, and industry management agencies.

[0052] In another aspect, embodiments of the present invention also provide a computer-readable storage medium storing instructions that, when executed by a processor, configure the processor to perform the data aggregation and sharing method supporting multi-data-owner joint control as described in the above embodiments.

[0053] It should be noted that, in the context of the embodiments of the present invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0054] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.

Claims

1. A data aggregation and sharing method supporting joint control by multiple data owners, characterized in that, The aggregation platform is executed by multiple data owners and multiple data users who have completed entity registration in the Trusted Center. When registering an entity, the data user submits a set of attributes to the Trusted Center for the aggregation platform to retrieve. The method includes: Receive encrypted data packets from multiple data owners; the encrypted data packets include at least the differentiated access policies set by each data owner. The attribute sets of each data user are compared with the differentiated access policies of each encrypted data packet to filter out encrypted data packets authorized to the same data user; when the number of filtering results is greater than a preset threshold, all encrypted data packets authorized to the same data user are aggregated to obtain multiple sets of aggregation results. In response to a data access request from a target data user, the system determines the pending aggregation result authorized to the target data user from among the multiple aggregation results based on the target data user's attribute set, and sends the pending aggregation result to the target data user.

2. The data aggregation and sharing method supporting multi-data-owner joint control as described in claim 1, characterized in that, For any target data owner among multiple data owners, the encrypted data packet includes at least an individual sharing intention attribute vector, individual attribute encrypted ciphertext, and individual data to be shared encrypted using a unified encryption key; The generation of the individual attribute encrypted ciphertext includes: The unified encryption key is split into multiple sub-key shares through secret sharing, and the target data owner owns one of the sub-key shares. The target data owner’s subkey share is encrypted using the master public key allocated by the trusted center, and an access control rule is bound to it. The access control rule is used to specify whether each data user can access the subkey share owned by each data owner. The differentiated access strategy for each encrypted data packet is defined by the individual shared intention attribute vector and the access control rules. When comparing the attribute set of each data user with the differentiated access strategy of each encrypted data packet, if the individual shared intention attribute vector of one or more data owners indicates that the same data user has access rights, and the same data user satisfies the access control rules of one or more data owners, then the encrypted data packets of one or more data owners are all authorized to the same data user.

3. The data aggregation and sharing method supporting multi-data-owner joint control as described in claim 2, characterized in that, When the number of filtered results exceeds a preset threshold, the data aggregation includes: Based on the encrypted data packets authorized to the same data user, and according to the additive homomorphism of the homomorphic encryption algorithm, the individual data to be shared in all the encrypted data packets authorized to the same data user are aggregated to generate aggregated data to be shared. The individual sharing intention attribute vectors in all encrypted data packets authorized to the same data user are aggregated to generate a joint sharing intention attribute vector; Based on the equivalence or logical equivalence of access control rules, aggregate the individual attribute encrypted ciphertexts in all encrypted data packets authorized to the same data user to generate aggregated attribute encrypted ciphertexts. The joint sharing intention attribute vector, aggregated attribute encrypted ciphertext, and aggregated data to be shared, obtained from the same data user, are used as a set of aggregation results for the multiple sets of aggregation results.

4. The data aggregation and sharing method supporting multi-data-owner joint control as described in claim 3, characterized in that, The summary includes: For any data user, if the component corresponding to the data user in the individual sharing intention attribute vector of the encrypted data packet authorized to the data user is 1, then the component corresponding to the data user in the generated joint sharing intention attribute vector is 1; otherwise, it is 0. In this context, a component of an individual data owner's shared willingness attribute vector being 1 indicates that the data owner authorizes the data user corresponding to that component to access their data; a component of a joint shared willingness attribute vector being 1 indicates that the data user is authorized by all data owners and has the right to access all data owners' data.

5. The data aggregation and sharing method supporting multi-data-owner joint control as described in claim 3, characterized in that, Determining whether any of the multiple aggregation results contain pending aggregation results authorized to the target data user includes: Read the joint sharing intention attribute vector in the aggregation result. If the joint sharing intention attribute vector in any one or more of the aggregation results points to the target data user, then the one or more aggregation results are intermediate aggregation results for the target data user. Read the encrypted ciphertext of the aggregated attributes in the intermediate aggregation result, and extract the access control rules from it. The access control rules include an access matrix and a mapping function. The attribute set of the target data user is associated with the corresponding row vector in the access matrix through the mapping function, and a set of coefficients is calculated. If the linear combination of the coefficients equals the target vector, then the intermediate aggregation result is used as the pending aggregation result, and the pending aggregation result, including the aggregated data to be shared and the encrypted ciphertext of the aggregation attribute, is sent to the target data user.

6. A data aggregation and sharing system supporting joint control by multiple data owners, characterized in that, This includes the data owner's end, the user's end, the aggregation platform, and the trust center; Multiple data owners on the data owner side and multiple data users on the user side complete entity registration in the trusted center. The trusted center allocates a master public key to the multiple data owners and allocates an attribute private key to each of the multiple data users according to the attribute set submitted during entity registration. For any target data owner among multiple data owners, the data owner performs the following steps: Set differentiated sharing intentions for different data users and generate individual sharing intention attribute vectors; Local data is encrypted using a unified encryption key to generate individual data to be shared. The unified encryption key is split into multiple sub-key shares, and the target data owner has one sub-key share. The sub-key shares are then encrypted using the master public key to generate individual attribute encrypted ciphertext. During encryption, access control rules that specify whether each data user can access each sub-key share are bound to the sub-key share. The individual sharing intention attribute vector, the encrypted ciphertext of the individual attributes, and the individual data to be shared are packaged into a ciphertext data packet and sent to the aggregation platform. The aggregation platform executes the data aggregation and sharing method supporting multi-data owner joint control as described in any one of claims 1 to 5, performs data aggregation on the encrypted data packet, and responds to a data access request sent by any target data user among the multiple data users, sending the aggregation result to be used to the target data user. The target data user, based on its attribute private key, recovers the unified encryption key used to decrypt the aggregated data to be shared based on the aggregated results to be used, thereby obtaining shared data jointly controlled by multiple data owners.

7. The data aggregation and sharing system supporting multi-data-owner joint control as described in claim 6, characterized in that, The settings are designed to address the differentiated sharing intentions of different data users, generating individual sharing intention attribute vectors, including: Based on its own business objectives, business relationships with each data user, and at least in combination with user credit assessment and data security requirements, the sharing targets and scope for each data user should be dynamically adjusted. The adjustment results are represented in vector form to generate the individual shared willingness attribute vector; The dynamic adjustment responds to changes in one or more of the following: the business objectives, the business relationships with each data user, the user credit assessment, and the data security requirements.

8. The data aggregation and sharing system supporting multi-data-owner joint control as described in claim 6 or 7, characterized in that, Also includes: Set general sharing preferences; For any data user, if the differentiated sharing intention is not set, the general sharing intention is used to generate an individual sharing intention attribute vector.

9. A business platform based on vehicle-to-everything (V2X) interaction, characterized in that, Use the data aggregation and sharing system that supports joint control of multiple data owners as described in any one of claims 6 to 8; Among them, the data owners on the data owner side include at least one or more of the following: charging piles, charging stations, charging operators, and electric vehicle users; the data users on the user side include at least one or more of the following: charging facility manufacturers, power grid dispatch centers, third-party energy service providers, research institutions, and industry management agencies.

10. A computer-readable storage medium storing instructions thereon, characterized in that, When executed by a processor, the instructions cause the processor to be configured to perform the data aggregation and sharing method supporting multi-owner joint control as described in any one of claims 1 to 5.