Page 412 - 《软件学报》2026年第2期
P. 412
李鲍 等: 基于 TEE 安全高效的细粒度统计分析与可验证数据聚合方案 891
6 总 结
本文设计并提出了一种基于 TEE 安全高效的细粒度统计分析与可验证数据聚合方案. 通过优化 BGN 同态加
密的参数, 设计了一种 ODMT-BGN 算法, 此算法在相同大小的安全参数下能提供更高的安全强度并扩展了消息
空间, 保障了数据的机密性; 其次, 本方案依托于 TEE 实现了多种明文数据的统计分析方法, 不仅保证了数据分析
过程的安全性, 还明显提高了统计分析的效率. 此外, 研究中心仅进行一次解密就可以得到方差、期望等统计分析
结果, 降低了研究中心的计算代价; 最后, 构建了一种依托身份的聚合签名与验证方法, 从而维护了数据传输和存
储过程中的完整性, 也通过批量认证降低了认证成本, 并实现了医疗数据的访问控制, 满足了研究中心细粒度统计
分析的需求. 特别地, 随着数据拥有者和边缘服务器数量的增加, 研究中心能够以近乎恒定的计算开销完成统计结
果的验证和解密. 在后续研究中, 将进一步扩展该方案的分析方法种类, 优化 TEE 中的最小算子达到更高的计算
安全性, 并探讨方案在去中心化场景中的应用可行性.
References
[1] Zhang YQ, Wang XF, Liu XF, Liu L. Survey on cloud computing security. Ruan Jian Xue Bao/Journal of Software, 2016, 27(6):
1328–1348 (in Chinese with English abstract). http://www.jos.org.cn/1000-9825/5004.htm [doi: 10.13328/j.cnki.jos.005004]
[2] Feng DG, Zhang M, Zhang Y, Xu Z. Study on cloud computing security. Ruan Jian Xue Bao/Journal of Software, 2011, 22(1): 71–83 (in
Chinese with English abstract). http://www.jos.org.cn/1000-9825/3958.htm [doi: 10.3724/SP.J.1001.2011.03958]
[3] Botta A, De Donato W, Persico V, Pescapé A. Integration of cloud computing and Internet of Things: A survey. Future Generation
Computer Systems, 2016, 56: 684–700. [doi: 10.1016/j.future.2015.09.021]
[4] Marinescu DC. Cloud Computing: Theory and Practice. 3rd ed., Amsterdam: Elsevier, 2022. [doi: 10.1016/C2020-0-02233-4]
[5] Catarinucci L, De Donno D, Mainetti L, Palano L, Patrono L, Stefanizzi ML, Tarricone L. An IoT-aware architecture for smart healthcare
systems. IEEE Internet of Things Journal, 2015, 2(6): 515–526. [doi: 10.1109/JIOT.2015.2417684]
[6] Mohamad Noor MB, Hassan WH. Current research on Internet of Things (IoT) security: A survey. Computer Networks, 2019, 148:
283–294. [doi: 10.1016/j.comnet.2018.11.025]
[7] Bansal M, Nanda M, Husain MN. Security and privacy aspects for Internet of Things (IoT). In: Proc. of the 6th Int’l Conf. on Inventive
Computation Technologies (ICICT). Coimbatore: IEEE, 2021. 199–204. [doi: 10.1109/ICICT50816.2021.9358665]
[8] Chen DY, Zhao H. Data security and privacy protection issues in cloud computing. In: Proc. of the 2012 Int’l Conf. on Computer Science
and Electronics Engineering. Hangzhou: IEEE, 2012. 647–651. [doi: 10.1109/ICCSEE.2012.193]
[9] Choudhury T, Gupta A, Pradhan S, Kumar P, Rathore YS. Privacy and security of cloud-based Internet of Things (IoT). In: Proc. of the
3rd Int’l Conf. on Computational Intelligence and Networks (CINE). Odisha: IEEE, 2017. 40–45. [doi: 10.1109/CINE.2017.28]
[10] Qiu J, Tian ZH, Du CL, Zuo Q, Su S, Fang BX. A survey on access control in the age of Internet of Things. IEEE Internet of Things
Journal, 2020, 7(6): 4682–4696. [doi: 10.1109/JIOT.2020.2969326]
[11] Goldwasser S, Micali S, Rivest RL. A digital signature scheme secure against adaptive chosen-message attacks. SIAM Journal on
Computing, 1988, 17(2): 281–308. [doi: 10.1137/0217017]
[12] Xiong H, Bao YY, Nie XY, Asoor YI. Server-aided attribute-based signature supporting expressive access structures for industrial
Internet of Things. IEEE Trans. on Industrial Informatics, 2020, 16(2): 1013–1023. [doi: 10.1109/TII.2019.2921516]
[13] Hu CQ, Pu YW, Yang FH, Zhao RF, Alrawais A, Xiang T. Secure and efficient data collection and storage of IoT in smart ocean. IEEE
Internet of Things Journal, 2020, 7(10): 9980–9994. [doi: 10.1109/JIOT.2020.2988733]
[14] Ducas L, Kiltz E, Lepoint T, Lyubashevsky V, Schwabe P, Seiler G, Stehlé D. Crystals-Dilithium: A lattice-based digital signature
scheme. IACR Trans. on Cryptographic Hardware and Embedded Systems, 2018, 2018(1): 238–268. [doi: 10.13154/tches.v2018.i1.238-
268]
[15] Hamdi M, Pirbhulal S, Abie H. A homomorphic digital signature scheme for the Internet of Things. 2022. [doi: 10.20944/preprints202202.
0238.v1]
[16] Zhao YQ, Yang XY, Feng Q, Yu Y. Anonymous credential protocol based on SM2 digital signature. Ruan Jian Xue Bao/Journal of
Software, 2024, 35(7): 3469–3481 (in Chinese with English abstract). http://www.jos.org.cn/1000-9825/6929.htm [doi: 10.13328/j.cnki.
jos.006929]
[17] Boneh D, Goh EJ, Nissim K. Evaluating 2-DNF formulas on ciphertexts. In: Proc. of the 2nd Theory of Cryptography Conf. on Theory of
Cryptography. Cambridge: Springer, 2005. 325–341. [doi: 10.1007/978-3-540-30576-7_18]

