Page 396 - 《软件学报》2026年第2期
P. 396
软件学报 ISSN 1000-9825, CODEN RUXUEW E-mail: jos@iscas.ac.cn
2026,37(2):875−893 [doi: 10.13328/j.cnki.jos.007426] [CSTR: 32375.14.jos.007426] http://www.jos.org.cn
©中国科学院软件研究所版权所有. Tel: +86-10-62562563
*
基于 TEE 安全高效的细粒度统计分析与可验证数据聚合方案
李 鲍, 周福才, 王 强, 冯 达
(东北大学 软件学院, 辽宁 沈阳 110169)
通信作者: 周福才, E-mail: fczhou@mail.neu.edu.cn
摘 要: 随着物联网的快速发展, 越来越多智能终端设备采集大量患者的医疗数据进行辅助医疗, 具有十分重要的
医疗研究价值. 然而, 这些医疗数据通常涉及患者的敏感信息, 且医疗数据在聚合和传输过程中可能面临数据篡改
和未经授权访问等安全问题. 为了解决上述安全与隐私问题, 同时支持医疗数据的细粒度的聚合统计分析, 提出了
基于 TEE (trusted execution environment) 安全高效细粒度统计分析与可验证数据聚合方案. 该方案对 m 与 m 双消
2
息类型 BGN 同态加密算法进行了改进, 并结合了数字签名等技术, 确保了医疗数据的机密性和完整性. 采用了一
种可验证的聚合签名算法, 实现了医疗密文数据的批量验证, 降低了认证成本. 通过将医疗密文数据复杂的统计分
析过程转换成为 TEE 内的统计分析过程, 提高了医疗数据的统计分析的效率, 同时也降低了计算代价. 采用边缘服
务器对研究中心进行授权访问的机制, 实现了医疗数据的细粒度统计分析. 在性能分析方面, 该方案在统计分析侧
和数据拥有者侧的计算开销方面具有明显优势.
关键词: 聚合签名; BGN 同态加密; 可信执行环境 (TEE); 统计分析; Intel SGX; 访问控制
中图法分类号: TP309
中文引用格式: 李鲍, 周福才, 王强, 冯达. 基于TEE安全高效的细粒度统计分析与可验证数据聚合方案. 软件学报, 2026, 37(2):
875–893. http://www.jos.org.cn/1000-9825/7426.htm
英文引用格式: Li B, Zhou FC, Wang Q, Feng D. Secure and Efficient Fine-grained Statistical Analysis and Verifiable Data
Aggregation Scheme Based on TEE. Ruan Jian Xue Bao/Journal of Software, 2026, 37(2): 875–893 (in Chinese). http://www.jos.org.cn/
1000-9825/7426.htm
Secure and Efficient Fine-grained Statistical Analysis and Verifiable Data Aggregation Scheme
Based on TEE
LI Bao, ZHOU Fu-Cai, WANG Qiang, FENG Da
(Software College, Northeastern University, Shenyang 110169, China)
Abstract: With the rapid development of the Internet of Things (IoT), a growing number of smart terminal devices collect large volumes
of patient medical data to support healthcare applications, offering considerable value for medical research. However, such data typically
involve sensitive patient information and may face security risks such as tampering and unauthorized access during aggregation and
transmission. To address these security and privacy concerns while enabling fine-grained statistical analysis, this study proposes a secure
and efficient statistical analysis and verifiable data aggregation scheme based on trusted execution environments (TEE). The proposed
2
scheme improves the m and m dual-message BGN homomorphic encryption algorithm and integrates digital signatures to ensure data
confidentiality and integrity. A verifiable aggregate signature algorithm is introduced to enable batch validation of encrypted data, thus
reducing authentication overhead. By shifting the complex statistical analysis of ciphertext data into the TEE, the scheme enhances
computational efficiency while reducing processing costs. Moreover, fine-grained statistical analysis is achieved through an access control
mechanism based on edge servers that authorize research center access. Performance evaluations indicate that the proposed scheme
significantly reduces computational overhead on both the statistical analysis and data owner sides.
* 基金项目: 国家自然科学基金 (62072090, 62202090, 62173101); 中央高校基本科研业务费专项资金 (N2417006); 辽宁省博士科研基金
(2022-BS-077); 辽宁网络安全执法协同创新中心课题 (XTCX2024-015)
收稿时间: 2024-01-26; 修改时间: 2024-11-19; 采用时间: 2025-03-10; jos 在线出版时间: 2025-10-29
CNKI 网络首发时间: 2025-10-31

