A privacy information retrieval method based on NTRU homomorphism outer product

Through the private information retrieval method based on NTRU homomorphic outer product, the problems of complex ciphertext query expansion and high query calculation overhead are solved, efficient query calculation and low communication overhead are achieved, and the throughput of private information retrieval is improved.

CN119323056BActive Publication Date: 2025-10-14ASIAINFO TECH (CHENGDU) INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411529650.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-30
Publication Date
2025-10-14
Estimated Expiration
2044-10-30

AI Technical Summary

Technical Problem

Existing privacy information retrieval protocols have problems such as complex ciphertext query expansion, high query computation overhead, and difficulty in heterogeneous ciphertext conversion. In particular, in schemes such as SealPIR, OnionPIR, and SPIRAL, the ciphertext query vector expansion is complex, the noise growth is large, the homomorphic inner product calculation consumes a large number of polynomials, and heterogeneous ciphertext conversion requires additional communication overhead.

Method used

A privacy information retrieval method based on NTRU homomorphic outer product is adopted. Through polynomial coefficient extraction, NTRU symmetric homomorphic encryption and NTRU homomorphic outer product technology, the complexity of the ciphertext query vector expansion algorithm is reduced, the query calculation efficiency is improved, and the communication volume is reduced.

Benefits of technology

It achieves efficient ciphertext query expansion, reduces query computation overhead and heterogeneous ciphertext conversion complexity, and improves the throughput and computational efficiency of privacy information retrieval.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119323056B_ABST
    Figure CN119323056B_ABST
Patent Text Reader

Abstract

The present invention provides a privacy information retrieval method based on NTRU homomorphic outer product. First, the database is regarded as a v+1-dimensional hypercube. The user User generates the corresponding query tuple (i, j1, j2, ..., j) from the query index idx. v ), compress and encrypt the query tuple to obtain a RLWE ciphertext c as the query query , the ciphertext c query Send it to the server, and the server will query the c based on the ciphertext extension algorithm. query Expanded to v+1 groups of ciphertext CT Ntru , CT NtruGSW,0 , CT NtruGSW,1 ,…,CT NtruGSW,v‑1 , and according to the database hypercube form, use NTRU homomorphic outer product calculation to generate the ciphertext response result c respond , sent to the user User, who uses the NTRU decryption algorithm to recover the result d idx The solution of the present invention realizes the hidden query of database data records, reduces the complexity of the ciphertext query vector expansion algorithm, and improves the throughput and query calculation efficiency of private information retrieval.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of privacy computing, and in particular to a private information retrieval method based on NTRU homomorphic outer product. BACKGROUND

[0002] Private information retrieval (PIR) is a special-purpose cryptographic protocol that allows a client to query a record with index index in the database DB of the server Server index without revealing which record is queried to the database server. Private information retrieval is an important key technology in privacy computing, which can be applied to database privacy query, anonymous information transmission, contact discovery, contact tracking, privacy protection navigation, secure browsing and other scenarios.

[0003] The private information retrieval protocol is mainly divided into information theory secure private information retrieval protocol and computation secure private information retrieval protocol. The computation secure PIR protocol database is stored in a single server and is based on mathematical difficult problems to construct, also known as single server PIR protocol. The fully homomorphic encryption has ciphertext computation capability, which can perform ciphertext computation on the query and database record, and the computation result is also encrypted, which is very suitable for designing computation secure private information retrieval protocol, and can effectively reduce the number of interaction rounds and communication volume. The private information retrieval protocol based on fully homomorphic encryption belongs to computation secure private information retrieval protocol. In 2009, Gentry of Stanford University in the United States proposed the first PIR protocol based on fully homomorphic encryption, which realized sub-linear communication complexity, but the execution efficiency was very low due to bit-by-bit homomorphic computation.

[0004] From 2012 to 2016, the efficiency of fully homomorphic encryption has been greatly improved, especially the BGV, BFV and other schemes based on RLWE mathematical difficult problem have excellent performance, which brings rapid development for the practical design of PIR protocol. In 2016, Melchor et al. designed an efficient and usable private information retrieval protocol XPIR based on RLWE homomorphic encryption scheme, and implemented the protocol based on HElib library. At present, most of the high-efficiency PIR protocols based on fully homomorphic encryption are based on the XPIR protocol framework, but the query request of the XPIR scheme contains a ciphertext vector with the same dimension as the database size, which leads to large communication overhead of inquiry. In 2018, Angel et al. designed a private information retrieval protocol SealPIR with smaller inquiry size based on the BFV homomorphic encryption scheme, which encoded the index index of the inquiry as a monomial x indexThen homomorphic encryption is performed on it to obtain ciphertext queries, and the query size is compressed to 0.36% of the XPIR scheme. In order to shorten the response size, in 2021, Mughees et al. designed a response-efficient single-server private information query protocol OnionPIR under the basic framework of SealPIR, which fully utilizes the outer product of RLWE ciphertext and RGSW ciphertext, has the advantage of small noise growth rate, and makes the parameter setting of the scheme smaller. In 2022, Menon et al. fused two lattice-based homomorphic encryption schemes and designed a fast and high-occupancy single-server private information retrieval protocol cluster, mainly including SPIRAL, SPIRALSTREM and SPIRALPACK schemes. The SPIRAL protocol family uses the matrix Regev scheme and the GSW scheme, and introduces a new type of ciphertext conversion method, while realizing the improvement of the server throughput rate and the response occupancy.

[0005] It can be seen that the mainstream private information retrieval scheme with high efficiency mainly involves key technologies such as ciphertext query compression and expansion technology, homomorphic outer product, and mainly uses RLWE / LWE as a mathematical difficult problem for construction. The existing technical scheme has problems such as complex ciphertext query expansion, large query calculation overhead, and additional auxiliary information required for heterogeneous ciphertext conversion, as follows:

[0006] (1) The ciphertext query expansion is complex. At present, the SealPIR, OnionPIR, SPIRAL and other schemes adopt a coefficient extraction algorithm based on homomorphic calculation, and the ciphertext query vector is obtained by a certain number of loop iterations and expansion. This expansion is relatively complex, and the ciphertext noise grows rapidly.

[0007] (2) The query calculation overhead is large. The homomorphic inner product of OnionPIR, SPIRAL and other schemes is based on RLWE or LWE mathematical difficult problems, and the ciphertext size is large, and the polynomial calculation consumed in the homomorphic calculation process is also large.

[0008] (3) It is difficult to convert heterogeneous ciphertext. When OnionPIR, SPIRAL and other schemes use homomorphic inner product, the query must be converted from BFV / Regev ciphertext to GSW type ciphertext, which requires the private key to be encrypted by the GSW homomorphic encryption scheme, and the ciphertext of the private key is sent to the server, resulting in an increase in communication overhead during query. SUMMARY

[0009] To solve the above problems, the application provides a privacy information retrieval method based on NTRU homomorphic outer product, adopts polynomial coefficient extraction, NTRU symmetric homomorphic encryption, NTRU homomorphic outer product and other technologies, realizes the anonymous query of database data records, reduces the complexity of the ciphertext query vector expansion algorithm, improves the throughput and query calculation efficiency of the privacy information retrieval, and has the characteristics of high calculation efficiency, low communication volume, large data scale and the like.

[0010] The privacy information retrieval method based on NTRU homomorphic outer product provided by the application comprises the following steps:

[0011] Step 1: A user User generates the parameters of the RLWE scheme, the NtruSHE scheme and the NtruGSW scheme according to a security parameter λ by respectively calling the RLWE scheme, the NteuSHE scheme and the NtruGSW scheme. RLWE ←RLWE.Setup(1 λ )、Params NtruSHE ←NtruSHE.Setup(1 λ )、Params NtruGSW ←NtruGSW.Setup(1 λ );

[0012] Step 2: The user User generates a private key s, f and ciphertext conversion keys w and K respectively according to the RLWE scheme, the NtruSHE scheme and the conversion key generation algorithms RlweToNtruKeyGen() and LweToRlweKeyGen(), s←RLWW.KeyGen(Params RLWE )、f←NtruSHE.KeyGen(Params NtruSHE )、w←RlweToNtruKeyGen(s,f,B w )、K←LweToRlweKeyGen(s), and determines parameters v1 and v according to the database scale, and the user User sends the parameters Params RLWE 、Params NtruSHE 、Params NtruGSW , the ciphertext conversion key public keys w and K and the parameters v1 and v to a server Server.

[0013] Step 3: The user User generates a query tuple (i, j1, j2,..., j v )←QueryTupleGen(idx) according to a plaintext query index idx by calling a query tuple generation algorithm.

[0014] Step 4: The private key s is input, and a ciphertext query c is generated from the query tuple by calling a ciphertext query generation algorithmquery ← EncQueryGen(s, (i, j1, j2,..., j v )) and sends the ciphertext query c query to the server Server;

[0015] Step 5: After receiving the ciphertext query c query , the server Server extracts N LWE ciphertexts from c query = (c0, c1):

[0016] c LWE,i = (c 0,i , p i (c1)), i = 0, 1,..., N-1

[0017] where N is the dimension of the ring R polynomial, c 0,i represents the coefficient of the ith term of the polynomial c0, p i is a conversion function that can convert a polynomial b = b0+ b1x+... + b N-1 x N-1 into an N-dimensional vector (b i , b i-1 ,..., b0, -b N-1 , -b N-2 ,..., -b i+1 ).

[0018] Then input the conversion key K, w to call the ciphertext conversion algorithm LweToRlwe(), RlweToNtru() in turn, to convert the LWE ciphertext into the RLWE ciphertext, and then further convert it into the NtruSHE ciphertext:

[0019] ct RLWE,i ← LweToRlwe(K, C LWE,i ), i = 0, 1,..., N-1

[0020] C Ntru,i ← RlweToNtru(w, ct RLWE,i ), i = 0, 1,..., N-1;

[0021] Step 6: The server Server divides the N NtruSHE ciphertexts into v+1 groups, and the first group is Convert the ciphertext groups other than the first group into NtruGSW ciphertext groups by calling the algorithm NtruSHEToGSW():

[0022]

[0023] CT NtruGSW,k = (c NtruGSW,k, g-C NtruGSW,k mod q)

[0024] where k = 0, 1, …, v - 1, l = "log B q], g is a tool vector, and q is a ciphertext modulus;

[0025] Step 7: The server Server performs a secure query calculation, first using the first group of ciphertexts CT Ntru Process the first dimension database record, let n represent the number of database data records, for where NtruSHE.MultPlain() is a homomorphic plaintext-ciphertext multiplication, the addition of the summation symbol uses homomorphic addition NtruSHE.Add(), and then using CT NtruGSW,0 , CT NtruGSW,1 , …, CT NtruGSW,v-1 Process the records of the subsequent dimensions of the database, and initialize For k = 0, 1, …, v - 1, iterate in a loop as follows:

[0026] (1) Set num = num / 2;

[0027] (2) For h = 0, 1, …, num - 1, where g is a tool vector, B is a base, represents an NTRU homomorphic outer product operation;

[0028] (3) Take as the calculation result and enter the next round of loop iteration;

[0029] After v iterations are completed, output is the output of the last iteration, and the server Server sends c respond to the user User;

[0030] Step 8: The user receives c respond , inputs the private key f, and decrypts the result d idx according to the NTRU decryption algorithm respond .

[0031] Further, the RLWE scheme in step 1 is an RLWE-based symmetric homomorphic encryption scheme, including:

[0032] System establishment algorithm RLWE.Setup(1 λ ): input security parameter λ, let distribution χ keyrepresenting a distribution of keys, the parameters Params are generated according to a decisional RLWE difficult problem RLWE =(N,q,s,B,l,t,A), such that the solving complexity of the difficult problem is not less than 2 λ , wherein N represents an integer ring the degree of the generating polynomial, q represents a ciphertext modulus, s represents a standard deviation of a discrete Gaussian distribution, B represents a basis of a tool vector, t represents a plaintext modulus,

[0033] Key generation algorithm RLWE.KeyGen(Params RLWE ): input parameters Params RLWE , randomly select s on a ternary {-1,0,1} distribution , and let the key be sk=s e R, wherein

[0034] Encryption algorithm RLWE.Enc(sk,m): input plaintext m e R t , randomly select an element a e R q on a random R q , randomly select e on a discrete Gaussian distribution , calculate and output ciphertext , wherein

[0035] Decryption algorithm RLWE.Dce(sk,ct): input ciphertext ct=(c0,c1) and decryption key sk, calculate and output

[0036] Further, the NtruSHE scheme in step 1 is an NTRU-based symmetric homomorphic encryption scheme, including:

[0037] System establishment algorithm NtruSHE.Setup(1 λ ): input security parameter l, generate parameters Params N,q,σ =(N,q,s,B,l,t,A) according to the decisional NTRU difficult problem Decisional_NTRU NtruSHE , such that the solving complexity of the difficult problem is not less than 2 λ , wherein N represents an integer ring the degree of the generating polynomial, q represents a ciphertext modulus, s represents a standard deviation of a discrete Gaussian distribution, B represents a basis of a tool vector, t represents a plaintext modulus,

[0038] Key generation algorithm NtruSHE.KeyGen(Params NtruSHE ): Input parameters Params NtruSHE , randomly selected Calculate f = t·f′ + 1, determine whether f is reversible, and if not, reselect f′ until f is reversible, and output the key sk = f;

[0039] Encryption algorithm NtruSHE.Enc(sk, m): Input plaintext m∈R t , in the discrete Gaussian distribution Randomly select u from the above, calculate and output the ciphertext ct = u sk -1 +Δ·m mod q;

[0040] Decryption algorithm NtruSHE.Dec(sk, ct): Input ciphertext ct and decryption key sk, calculate and output

[0041] In order to speed up the calculation efficiency of homomorphic multiplication and homomorphic outer product, sometimes it is not necessary to make the ciphertext decryptable. The ciphertext is only used as an intermediate output process. In this case, the following method can be used to encrypt the plaintext:

[0042] Encoding algorithm NtruSHE.Encode(sk,m): Input plaintext m∈R t , in the discrete Gaussian distribution Randomly select u from the above and calculate the ciphertext ct = u sk -1 +m mod q;

[0043] Homomorphic addition NtruSHE.Add(ct0, ct1): input two ciphertexts ct0, ct1∈R q , calculate and output ct Add =ct0+ct1mod q;

[0044] Homomorphic plaintext addition NtruSHE.AddPlain(ct, pt): Input ciphertext ct∈R q and a plaintext pt∈R t , calculate and output ct MultPlain =ct+Δ·pt mod q;

[0045] Homomorphic plaintext multiplication NtruSHE.MultPlain(ct, pt): input ciphertext ct∈R q and a plaintext pt∈R t , calculate and output ct MultPlain =ct·pt mod q.

[0046] Furthermore, the NtruGSW scheme in step 1 is a GSW-type symmetric Boolean homomorphic encryption scheme based on NTRU, including:

[0047] Given a basis B, let Introducing tool vector g and tool matrix G, Definition of g -1 Transformation: For a∈R q , decompose it based on B in a i ∈R B , g T g -1 (a) = a;

[0048] System establishment algorithm NtruGSW.Setup(1 λ ):Input security parameter λ, according to the decision-type NTRU problem Decisional_NTRU N,q,σ , generate parameters Params NtruGSW =(N,q,σ,B,l,t,Δ), ​​so that the complexity of solving the difficult problem is not less than 2 λ ,in

[0049] Key generation algorithm NtruGSW.KeyGen(Params NtruGSW ): Input parameters Params NtruGSW , randomly selected Calculate f = tf′ + 1, determine whether f is reversible, if not, reselect f′ until f is reversible, and set the key sk = f;

[0050] Encryption algorithm NtruGSW.Enc(sk,m): Input plaintext polynomial m∈{0,1}, in l identical discrete Gaussian distributions Randomly select a l-dimensional vector u=(u0,u1,...,u l-1 ), calculate and output the ciphertext c = u f -1 +Δ·m·g;

[0051] Decryption algorithm NtruGSW.Dec(sk, c): Input ciphertext c and private key sk, calculate Get the 0th element of vector m, and you can recover the message m=m[0];

[0052] In order to speed up the calculation efficiency of homomorphic multiplication and homomorphic outer product, sometimes it is not necessary to make the ciphertext decryptable. The ciphertext is only used as an intermediate output process. In this case, the following method can be used to encrypt the plaintext:

[0053] Encoding algorithm NtruGSW.Encode(sk, m): input plaintext polynomial m e {0, 1}, randomly select 1 l-dimensional vector u = (u0, u1,..., ul) from l identical discrete Gaussian distribution l-1 , calculate and output ciphertext c = u · f -1 + mg;

[0054] Homomorphic addition NtruGSW.Add(c0, c1): input two ciphertexts Calculate and output c Add = c0 + c1 mod q, where That is, the Cartesian product of l R q ;

[0055] Homomorphic plaintext addition NtruGSW.AddPlain(c, pt): input ciphertext and a plaintext pt e {0, 1}, calculate and output c AddPlain = c + Δ · pt · g mod q;

[0056] Homomorphic complement operation NtruGSW.comple(c): input ciphertext Calculate and output c comple = g - c mod q.

[0057] Further, the conversion key generation algorithm RlweToNtruKeyGen() in step 2 is the conversion of RLWE ciphertext to NtruSHE ciphertext, including:

[0058] The form of RLWE ciphertext is Where s is the private key of the RLWE ciphertext, a is randomly and uniformly selected from R q , e is randomly sampled from distribution The plaintext m belongs to R t In order to convert the RLWE ciphertext to the NtruSHE ciphertext, a conversion key w is needed, and the conversion key generation algorithm RlweToNtruKeyGen() is:

[0059] Let f represent the private key of the NtruSHE scheme, B w represents the conversion base;

[0060] Input the private key s of the RLWE ciphertext, the private key f of the NtruSHE scheme, and the conversion base B w , let The conversion key generation algorithm RlweToNtruKeyGen(s, f, B w ) is:

[0061] ​(1) In distribution Randomly select an l w dimensional vector u w ;

[0062] (2) Let l w Dimensional Tools Vector

[0063] (3) Calculate and output the conversion key w = (w0, w1, ..., w l-1 )=u w ·f -1 +s·g w mod q;

[0064] Input RLWE ciphertext ct RLWE And the conversion key w, the conversion algorithm from RLWE ciphertext to NtruSHE ciphertext RlweToNtru(w, c RLWE )for:

[0065] (1) For the RLWE ciphertext component c RLWE,1 Base B w Decomposition in Indicates that the output data is B w Decomposition of the base;

[0066] (2) Calculate and output

[0067] The conversion key generation algorithm LweToRlweKeyGen() in step 2 is a conversion key generation algorithm for LWE ciphertext to RLWE ciphertext, including:

[0068] K←KSKeyGen(s, s′): Randomly select an l-dimensional vector k1 from the distribution Randomly sample an l-dimensional vector e, calculate k0 = -k1·s′+g·s+emod q, and output the conversion key of the RLWE ciphertext

[0069] K←LweToRlweKeyGen(s): Since s is a polynomial, for i=2,3,...,l-1, let s (i) =s(x i ), call K i =KSKeyGen(s, s′), then the conversion key from LWE ciphertext to RLWE ciphertext is K={K2, K3, ..., K l-1}.

[0070] Furthermore, the query tuple generation algorithm in step 3 is specifically as follows:

[0071] Let a database server store a database DB = {d0, d1,..., dn-1} with n records. n-1 Let the privacy information query index be idx, i.e. the query object is didx. idx Let the database be regarded as a hypercube in a v+1 dimensional space i.e. the number of the 1st dimension is The number of the 2nd to v+1th dimensions is 2, and the parameters v and v1 are set according to the database size and specific requirements.

[0072] Let the query index idx e {0, 1,..., n-1}, and the query tuple generation algorithm QueryTupleGen() is:

[0073] (1)

[0074] (2) tmp = idx - i · 2 v :

[0075] (3) For k = 1, 2,..., v, execute:

[0076] ①

[0077] ② tmp = tmp - j k · 2 v-k ;

[0078] Finally, output the query tuple (i, j1, j2,..., j v ), wherein j1, j2,..., j v e {0, 1}.

[0079] Further, the ciphertext query generation algorithm in step 4 is specifically:

[0080] Embed each component of the query tuple (i, j1, j2,..., j v ) into the plaintext polynomial μ(x) = μ0+ μ1x+... + μ N-1 x N-1 , and also embed B h j k , h = 0, 1,..., l-1, k = 1, 2,..., v, and the ciphertext query generation algorithm EncQueryGen() is:

[0081] Input RLWE private key s and query tuple (i, j1, j2,..., j v );

[0082] Output: RLWE ciphertext

[0083] Let μ(x) = Δ · x i ;

[0084] For k = 1, 2, …, v, perform:

[0085]

[0086] Output RLWE ciphertext c query = RLWE.Enc(s, μ(x)).

[0087] Further, the ciphertext query expansion algorithm in step 5 specifically includes:

[0088] Let vector polynomial b = b0+ b1x+ …+ b N-1 x N-1 ∈ R q , whose coefficient vector is (b0, b1, …, b N-1 ), define the transformation ρ i (b) = (b i , b i-1 , …, b0, -b N-1 , -b N-2 , …, -b i+1 ), which is equivalent to reversing the order of the first i consecutive elements of the coefficient vector of the polynomial b and negatively reversing the order of the i+1 to N-1 consecutive elements, outputting an N-1 dimensional vector on R ;

[0089] Let the input be an RLWE ciphertext query c query = RLWE.Enc(s, μ(x)) = (c0, c1) = (-as+e+Δ·μ(x), a), where the plaintext μ(x) = μ0+ μ1x+ …+ μ N-1 x N-1 , the coefficient vector of the key is represented by the vector s, and C 0,i represents the coefficient of the i-th term of the polynomial element c0 on R q , then the LWE ciphertext of the plaintext polynomial coefficient is directly extracted from c RLWE , specifically as follows:

[0090] LWE.Enc(s, μ i ) = (c 0,i , ρ i (c1)), i = 0, 1, …, N-1

[0091] By using the LWE ciphertext to RLWE ciphertext conversion technology, LWE.Enc(s, μ i) to RLWE ciphertext with key s, which requires a conversion key K←LweToRlweKeyGen(s), and the conversion algorithm is LweToRlwe(), then:

[0092] ct RLWE,i ←LweToRlwe(K, LWE.Enc(s, μ i )), i = 0, 1, …, N-1

[0093] ct RLWE,i is an RLWE ciphertext encrypted with coefficients μ i , ct RLWE,i = RLWE.Enc(s, μ i ), i = 0, 1, …, N-1, then call the conversion algorithm RlweToNtru() from RLWE ciphertext to NtruSHE ciphertext with input conversion key w, to generate a set of NtruSHE ciphertexts: C Ntru,i ←RlweToNtru(w, ct RLWE,i ), i = 0, 1, …, N-1, the calculation result ciphertext C Ntru,i is the NtruSHE ciphertext of coefficients μ i ;

[0094] The ciphertext conversion algorithm LweToRlwe() includes:

[0095] ct'←KeySwitch(ct, K): input an RLWE ciphertext conversion key K, calculate and output ciphertext ct' = (c0, 0) + g -1 (c1)·K mod q;

[0096] ct'←EvalAuto(ct, i, K): input an RLWE ciphertext conversion key K = {K2, K3, …, K l-1}, an integer i, calculate and output ct' = KeySwitch(ct, K i );

[0097] ct RLWE ←LweToRlwe(C LWE , K): input an LWE ciphertext where a = (a0, a1, …, a N-1 ), convert a to a polynomial Let the initial ciphertext ct = (b, a), for k = 1, 2, …, log2N, iteratively calculate After the iteration is completed, output

[0098] Further, the algorithm NtruSHEToGSW() in step 6 is to construct NtruGSW ciphertext based on NtruSHE ciphertext, including:

[0099] Let plaintext m be in {0, 1}, input l NtruSHE encryption codes: ct0=NtruSHE.Encode(B 0 , m), ct1=NtruSHE.Encode(B, m), …, ct l-1 =NtruSHE.Encode(B l-1 , m), then the algorithm NtruSHEToGSW() is:

[0100]

[0101] Further, the NTRU homomorphic outer product operation in step 7 is:

[0102]

[0103] Let an NtruSHE ciphertext ct be in R q , which is the encryption of message m0 in {0, 1}, that is, ct=NtruSHE.Enc(sk, m0), an NtruGSW ciphertext , which is the encryption code of message m1 in {0, 1}, that is, c=NtruGSW.Encode(sk, m1), NTRU homomorphic outer product Output an NtruSHE ciphertext, denoted as ct ExPorduct , and it is the encryption of message m0m1 mod t, when m1=0, the noise of ct ExPorduct is irrelevant to ct.

[0104] Private information retrieval is an important key technology in privacy computing, which can protect the query behavior of users and prevent the service library from mastering the query results of users, and has become an indispensable technology in the privacy computing platform, and has wide application value, and the present application aims at the problems of complex ciphertext query expansion, large query calculation overhead, and difficult heterogeneous ciphertext conversion existing in the private information retrieval protocol, and proposes a private information retrieval method based on NTRU homomorphic outer product, which mainly adopts a coefficient direct extraction method to extract LWE encryption of each coefficient of the plaintext polynomial from the RLWE ciphertext, realizes more efficient ciphertext query expansion, and adopts NTRU symmetric homomorphic encryption and NTRU homomorphic outer product to perform query calculation in a secret state, reduces the memory space consumption, and improves the query calculation efficiency, and the present application first regards a database with a size of n as a hypercube with a size of v+1 dimensions, that is a hypercube with a size of v+1 dimensions, the size of the first dimension is The size of the remaining dimension is 2, wherein v1 is generally set to 128, and the user User generates a corresponding query tuple (i, j1, j2,..., j v ), and the query tuple is compressed, encoded and encrypted to obtain an RLWE ciphertext c query as an inquiry. query The ciphertext c query is sent to the server Server, and the server Server expands the ciphertext c Ntru into v+1 groups of NtruSHE ciphertexts based on the ciphertext inquiry expansion algorithm, further calls the NtruSHEToGSW algorithm, and converts into CT NtruGSW,0 , CT NtruGSW,1 ,..., and CT NtruGSW,v-1 , and according to the database hypercube form, adopts NTRU homomorphic outer product calculation to generate a ciphertext response result c respond , which is sent to the user User, and the user recovers the result d idx by using the NTRU decryption algorithm. The privacy information retrieval protocol method provided by the application has the beneficial technical effects that the communication overhead is small, the response calculation time is short, and the application has the following beneficial technical effects:

[0105] (1) The ciphertext query expansion is simple, and the SealPIR, OnionPIR and SPIRAL schemes adopt a coefficient extraction algorithm based on homomorphic calculation, which is complex and has large ciphertext noise growth. The application directly extracts LWE ciphertext from RLWE ciphertext, realizes coefficient ciphertext extraction with basically no calculation overhead, and combines a ciphertext conversion method to form an efficient ciphertext expansion algorithm.

[0106] (2) The query calculation overhead is small. When calculating the homomorphic inner product, the ciphertexts of the OnionPIR and SPIRAL schemes are two polynomial ring elements. The ciphertext of the application is one polynomial ring element, which reduces the memory space and the polynomial multiplication operation time.

[0107] (3) The heterogeneous ciphertext conversion is simple and efficient. When the OnionPIR and SPIRAL schemes adopt the homomorphic inner product, the GSW ciphertext of the private key needs to be sent to the server, which increases the communication overhead during the query, and the homomorphic outer product is needed to realize the conversion of the BFV ciphertext to the GSW ciphertext. The application does not need the GSW ciphertext of the private key, but directly expresses a group of NTRU ciphertexts as a GSW ciphertext. This conversion has no calculation overhead and is very efficient. BRIEF DESCRIPTION OF DRAWINGS

[0108] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0109] Figure 1 1 is a flowchart of a method for private information retrieval based on NTRU homomorphic outer product provided by an embodiment of the present invention;

[0110] Figure 2 This is a general architecture diagram of a private information retrieval based on NTRU homomorphic outer product provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0111] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0112] First, the relevant symbols of the present invention are explained as follows:

[0113] This paper uses italic bold lowercase letters to represent vectors (e.g., u, v) and italic bold uppercase letters to represent matrices (e.g., A, B). represents the ring of integers, represents the set of natural numbers; for positive integers Let [n] denote the set {1, 2, ..., n}; for positive integers make represents the residue class of integers modulo q; for integers and a≤b, let [a, b] denote the set {a, a+1, ..., b}; let λ denote the security parameter, and the symbol poly(λ) denotes that for a positive integer The asymptotic function O(λ c ), the symbol negl(λ) means that for all positive integers The asymptotic function o(λ -c ).

[0114] When A is a set, x←A means randomly selecting an element x from the set A; when χ is a probability distribution, x←χ means randomly sampling an element x from the distribution χ; when f is a function, x←f means the output of the function f.

[0115] N is a positive integer, and N is a power of 2, then x N +1 is a 2N order cyclotomic polynomial, then the integral ring is a cyclotomic polynomial ring; any element a on R can be regarded as a unique sum of polynomials with degree less than N and a multiple of x N +1; for convenience, we directly use the polynomial to represent the element on R, and the coefficient vector is (a0, a1,..., a N-1 ); for any integer , the quotient ring

[0116] The discrete Gaussian distribution is a probability distribution on the integer ring , for real number σ, c>0, first define the Gaussian function Therefore, for the entire integer ring , there is Then the discrete Gaussian distribution with standard deviation σ and mean c is a distribution, and the probability function is Its symbolic representation is χ σ,c , if c=0, then χ σ , represents the distribution on , and each component is a χ σ distribution.

[0117] The privacy information retrieval method based on NTRU homomorphism outer product provided by the application first regards the database as a (v+1) -dimensional hypercube, and the user User generates a corresponding query tuple (i, j1, j2,..., j v ) from the query index idx, and compresses and encrypts the query tuple to obtain an RLWE ciphertext c query as a query, sends the ciphertext c query to the server Server, and the server Server expands the ciphertext query expansion algorithm to expand the ciphertext c query into v+1 groups of ciphertexts CT Ntru , CT NtruGSW,0 , CT NtruGSW,1 ,..., and CT NtruGSW,v-1 , and adopts NTRU homomorphism outer product calculation according to the hypercube form of the database to generate a ciphertext response result c respond , and sends it to the user User, and the user adopts the NTRU decryption algorithm to restore the result d idx . Specifically, it comprises:

[0118] There are two participating entities in the method: a user User and a server Server. The server Server has a database DB = {d0, d1,..., dn} of size n. The user wants to query a record d n-1 in the database. idx The method includes the following steps. Figure 1

[0119] Step 1: The user User generates parameters of RLWE scheme, NtruSHE scheme and NtruGSW scheme according to a security parameter λ by calling RLWE scheme, NtruSHE scheme and NtruGSW scheme respectively: Params RLWE ← RLWE. Setup (1 λ ), Params NtruSHE ← NtruSHE. Setup (1 λ ), and Params NtruGSW ← NtruGSW. Setup (1 λ ). The consistency of the underlying algebraic structure is required, that is, the same algebraic structure is used in the three schemes.

[0120] Step 2: The user User generates a private key s, a private key f and ciphertext conversion keys w and K according to RLWE scheme, NtruSHE scheme and conversion key generation algorithms RlweToNtruKeyGen(), LweToRlweKeyGen(): s ← RLWE. KeyGen (Params RLWE ), f ← NtruSHE. KeyGen (Params NtruSHE ), w ← RlweToNtruKeyGen (s, f, B w ), K ← LweToRlweKeyGen (s), and parameters v1 and v are determined according to the size of the database. The user User sends the parameters Params RLWE , Params NtruSHE , Params NtruGSW , ciphertext conversion key public keys w and K, and parameters v1 and v to the server Server.

[0121] Step 3: The user User generates a query tuple (i, j1, j2,..., j v ) according to the plaintext query idx by calling a query tuple generation algorithm QueryTupleGen (idx).

[0122] Step 4: The private key s is inputted, and a ciphertext challenge c is generated from the query tuple by calling a ciphertext challenge generation algorithm CiphertextChallengeGen.​query ← EncQueryGen(s, (i, j1, j2,..., j v )) and sends the ciphertext query c query to the server Server.

[0123] Step 5: After receiving the ciphertext query c query , the server Server extracts N LWE ciphertexts from c query = (c0, c1):

[0124] c LWE,i = (c 0,i , p i (c1)), i = 0, 1,..., N-1

[0125] where N is the dimension of the ring R polynomial, c 0,i represents the coefficient of the ith term of the polynomial c0, p i is a conversion function that can convert a polynomial b = b0+ b1x+... + b N-1 x N-1 into an N-dimensional vector (b i , b i-1 ,..., b0, -b N-1 , -b N-2 ,..., -b i+1 ).

[0126] Then input the conversion key K, w to call the ciphertext conversion algorithm LweToRlwe(), RlweToNtru() in turn to convert the LWE ciphertext into the RLWE ciphertext, and then further convert it into the NtruSHE ciphertext:

[0127] ct RLWE,i ← LweToRlwe(K, C LW E, i ) , i = 0, 1,..., N-1

[0128] C Ntru,i ← RlweToNtru(w, ct RLWE,i ), i = 0, 1,..., N-1;

[0129] Step 6: The server Server divides the N NtruSHE ciphertexts into v+1 groups, and the first group is Convert the ciphertext groups other than the first group into NtruGSW ciphertext groups by calling the algorithm NtruSHEToGSW():

[0130]

[0131] CT NtruGSW,k= (c NtruGSW,k , g - c NtruGSW,k mod q)

[0132] where k = 0, 1, …, v - 1, g is a tool vector, and q is a ciphertext modulus.

[0133] Step 7: The server Server performs a secure query computation, first using the first group of ciphertexts CT Ntru processes the first dimension database record, let n represent the number of database data records, for where NtruSHE.MultPlain() is a homomorphic plaintext-ciphertext multiplication, the addition of the summation symbol uses a homomorphic addition NtruSHE.Add(), and then using CT NtruGSW,0 , CT NtruGSW,1 , …, CT NtruGSW,v-1 processes the database record of the subsequent dimensions, and initializes For k = 0, 1, …, v - 1, the loop iteration is run as follows:

[0134] (1) Set num = num / 2;

[0135] (2) For h = 0, 1, …, num - 1, where g is a tool vector, B is a base, represents an NTRU homomorphic outer product operation;

[0136] (3) Take as the calculation result and enter the next round of loop iteration;

[0137] After v iterations are completed, output is the output of the last iteration, and the server Server sends c respond to the user User.

[0138] Step 8: The user receives c respond , inputs the private key f, and decrypts the result d idx according to the NTRU decryption algorithm. respond

[0139] This method is divided into four stages: steps 1 and 2 are the system establishment stage, steps 3 and 4 are the query generation stage, steps 5 to 7 are the response calculation stage, and step 8 is the result acquisition stage.

[0140] Further, the NTRU difficulty problem assumption is:

[0141] ​NTRU sampling: randomly choose f and g on distribution χ σ NTRU q (f) is invertible, take f as secret information, compute h = g f -1 , get NTRU N,q,σ (f) sampling h.

[0142] Search NTRU problem Search_NTRU N,q,σ : Let integers N > 0, q > 0, let real number σ > 0, randomly choose as an element on R, and f is invertible on R q , take f as secret information, randomly choose as an element on R, given h = g f -1 mod q, solve f.

[0143] Decisional NTRU problem Decisional_ntru N,q,σ : Let integers N > 0, q > 0, let real number σ > 0, randomly choose as an element on R, and f is invertible on R q , take f as secret information, randomly choose as an element on R, h = g f -1 mod q forms a probability distribution NTRU N,q,σ (f), distinguish NTRU N,q,σ (f) and random uniform distribution u <- R q .

[0144] RLWE difficult problem hypothesis is:

[0145] RLWE sampling: randomly choose an element s on distribution χ key , take s as secret information, randomly choose a polynomial a on R q , randomly choose an error e on discrete Gaussian distribution , compute b = as + e, then get RLWE N,q,σ (s) sampling (a, b).

[0146] Search RLWE problem Search_RLWE N,q,σ : According to k RLWE N,q,σ (s) samplings (a i , b i = a i s + e i ), i = 1, 2,..., k, solve the secret s.

[0147] Decisional_RLWE N,q,σ : distinguish the distribution (a, b = as + e) from the uniform distribution U(R q x R q ).

[0148] According to the research of scholars, solving Search_NTRU N,q,σ problem and Decisional_NTRU N,q,σ problem, and Search_RLWE N,q,σ and Decisional_RLWE N,q,σ is computationally difficult.

[0149] Further, the RLWE scheme in step 1 is a symmetric homomorphic encryption scheme based on RLWE, including:

[0150] System establishment algorithm RLWE.Setup(1 λ ): input security parameter λ, let the distribution χ key represent the distribution of the key, generate the parameter Params RLWE = (N, q, σ, B, l, t, Δ) according to the decision RLWE difficult problem, so that the solving complexity of the difficult problem is not less than 2 λ , wherein N represents the degree of the integral ring generating polynomial, q represents the ciphertext modulus, σ represents the standard deviation of the discrete Gaussian distribution, B represents the basis of the tool vector, t represents the plaintext modulus,

[0151] Key generation algorithm RLWE.KeyGen(Params RLWE ): input parameter Params RLWE , randomly select s on the ternary {-1, 0, 1} distribution , and let the key be sk = s ∈ R, wherein

[0152] Encryption algorithm RLWE.Eec(sk, m): input plaintext m ∈ R t , randomly select an element a ← R q on R q , randomly select e on the discrete Gaussian distribution , calculate and output the ciphertext wherein

[0153] Decryption algorithm RLWE.Dec(sk, ct): input ciphertext ct = (c0, c1) and decryption key sk, calculate and output .

[0154] Furthermore, the NtruSHE scheme in step 1 is a symmetric homomorphic encryption scheme based on NTRU, including:

[0155] System establishment algorithm NtruSHE.Setup(1 λ ):Input security parameter λ, according to the decision-type NTRU problem Decisional_NTRU N,q,σ , generate parameters Params HtruSHE =(N,q,σ,B,l,t,Δ), ​​so that the complexity of solving the difficult problem is not less than 2 λ , where N represents an entire ring The degree of the generating polynomial, q represents the ciphertext modulus, σ represents the standard deviation of the discrete Gaussian distribution, B represents the basis of the tool vector, t represents the plaintext modulus,

[0156] Key generation algorithm NtruSHE.KeyGen(Params NtruSHE ): Input parameters Params NtruSHE , randomly selected Calculate f = t·f′ + 1, determine whether f is reversible, and if not, reselect f′ until f is reversible, and output the key sk = f;

[0157] Encryption algorithm NtruSHE.Enc(sk, m): Input plaintext m∈R t , in the discrete Gaussian distribution Randomly select u from the above, calculate and output the ciphertext ct = u sk -1 +Δ·m mod q;

[0158] Decryption algorithm NtruSHE.Dec(sk, ct): Input ciphertext ct and decryption key sk, calculate and output

[0159] In order to speed up the calculation efficiency of homomorphic multiplication and homomorphic outer product, sometimes it is not necessary to make the ciphertext decryptable. The ciphertext is only used as an intermediate output process. In this case, the following method can be used to encrypt the plaintext:

[0160] Encoding algorithm NtruSHE.Encode(sk,m): Input plaintext m∈R t , in the discrete Gaussian distribution Randomly select u from the above and calculate the ciphertext ct = u sk -1 +m mod q;

[0161] Homomorphic addition NtruSHE.Add(ct0, ct1): input two ciphertexts ct0, ct1 e R q , compute and output ct Add = ct0+ ct1 mod q.

[0162] Homomorphic plain-ciphertext addition NtruSHE.AddPlain(ct, pt): input a ciphertext ct e R q and a plaintext pt e R t , compute and output ct MultPlain = ct+ D pt mod q.

[0163] Homomorphic plain-ciphertext multiplication NtruSHE.MultPlain(ct, pt): input a ciphertext ct e R q and a plaintext pt e R t , compute and output ct MultPlain = ct pt mod q.

[0164] Further, the NtruGSW scheme in step 1 is an NTRU-based GSW-type symmetric Boolean homomorphic encryption scheme, comprising:

[0165] Given a basis B, let introduce a tool vector g and a tool matrix G, define g -1 transform: for a e R q , perform decomposition with B as the basis where a i e R B , g T g -1 (a) = a;

[0166] System establishment algorithm NtruGSW.Setup(1 λ ): input a security parameter l, according to the decisional NTRU difficult problem Decisional_NTRU N,q,σ , generate parameters Params NtruGSW = (N, q, s, B, l, t, D) such that the solution complexity of the difficult problem is not less than 2 λ , wherein

[0167] Key generation algorithm NtruGSW.KeyGen(Params NtruGSW ): input parameters Params NtruGSW , randomly select Compute f = tf' + 1, determine if f is invertible, if not, reselect f', until f is invertible, let the key sk = f;

[0168] Encryption algorithm NtruGSW.Enc(sk, m): input plaintext polynomial m e {0, 1}, randomly select an l-dimensional vector u = (u0, u1,..., u from the same discrete Gaussian distribution l-1 , compute and output ciphertext c = u · f -1 + Δ · mg;

[0169] Decryption algorithm NtruGSW.Dec(sk, c): input ciphertext c and private key sk, compute Get the 0th element of the vector m, and you can recover the message m = m[0];

[0170] In order to speed up the homomorphic multiplication and homomorphic outer product calculation efficiency, sometimes it is not necessary to have decryptability of ciphertext, but only to take the ciphertext as an intermediate output process, at this time the following method can be used to encrypt the plaintext:

[0171] Encoding algorithm NtruGSW.Encode(sk, m): input plaintext polynomial m e {0, 1}, randomly select an l-dimensional vector u = (u0, u1,..., u from the same discrete Gaussian distribution l-1 , compute and output ciphertext c = u · f -1 + mg;

[0172] Homomorphic addition NtriGSW.Add(c0, c1): input two ciphertexts Compute and output c Add = c0 + c1 mod q, where is the Cartesian product of l R q ;

[0173] Homomorphic plaintext addition NtruGSW.AddPlain(c, pt): input ciphertext and a plaintext pt e {0, 1}, compute and output c AddPlain = c + Δ · pt · g mod q;

[0174] Homomorphic complement operation NtruGSW.comple(c): input ciphertext Compute and output c comple = g - c mod q.

[0175] Further, the conversion key generation algorithm RlweToNtruKeyGen() in step 2 is the conversion from RLWE ciphertext to NtruSHE ciphertext, including:

[0176] The form of the RLWE ciphertext is where s is the private key of the RLWE ciphertext, a is randomly and uniformly selected from R q , and e is randomly sampled from the distribution The plaintext m belongs to R t In order to convert the RLWE ciphertext into the NtruSHE ciphertext, a conversion key w is needed, and the conversion key generation algorithm RlweToNtruKeyGen() is:

[0177] Let f represent the private key of the NtruSHE scheme, and B w represents the conversion base;

[0178] Input the private key s of the RLWE ciphertext, the private key f of the NtruSHE scheme, and the conversion base B w Let The conversion key generation algorithm RlweToNtruKeyGen(s, f, B w ) is:

[0179] (1) Randomly select an l w dimensional vector u w from the distribution

[0180] (2) Let an l w dimensional tool vector

[0181] (3) Calculate and output the conversion key w = (w0, w1, …, w l-1 ) = u w · f -1 + s· g w mod q;

[0182] Input the RLWE ciphertext ct RLWE and the conversion key w, and the conversion algorithm RlweToNtru(w, c RLWE ) from the RLWE ciphertext to the NtruSHE ciphertext is:

[0183] (1) Decompose the RLWE ciphertext component c RLWE,1 with the base B w , where represents the decomposition of the output data in base B w ;

[0184] (2) Calculate and output ​​

[0185] The conversion key generation algorithm LweToRlweKeyGen() in step 2 is a conversion key generation algorithm for LWE ciphertext to RLWE ciphertext, including:

[0186] K←KSKeyGen(s, s′): Randomly select an l-dimensional vector k1 from the distribution Randomly sample an l-dimensional vector e, calculate k0 = -k1·s′+g·s+e mod q, and output the conversion key of the RLWE ciphertext

[0187] K←LweToRlweKeyGen(s): Since s is a polynomial, for i=2,3,...,l-1, let s (i) =s(x i ), call K i =KSKeyGen(s, s′), then the conversion key from LWE ciphertext to RLWE ciphertext is K={K2, K3, ..., K l-1}.

[0188] Furthermore, the query tuple generation algorithm in step 3 is specifically as follows:

[0189] The database server stores a database DB with n records = {d0, d1, ..., d n-1}, let the private information query index be idx, that is, the query object be d idx , consider the database as a hypercube in v+1 dimensional space That is, the scale of the first dimension is The scale of the 2nd to v+1th dimension is 2, and the parameters v and v1 are set according to the database scale and specific needs;

[0190] Let the query index idx∈{0, 1, ..., n-1}, which can be converted into a query tuple (i, j1, j2, ..., j v ),in j1, j2, ..., j v ∈{0, 1}. The query tuple generation algorithm QueryTupleGen() can be called to generate the query tuple. The query tuple generation algorithm is:

[0191]

[0192] Furthermore, the ciphertext query generation algorithm in step 4 is specifically:

[0193] The query tuple (i, j1, j2, ..., j veach component of the plaintext polynomial μ(x) = μ 0 + μ 1 x + … + μ N-1 x N-1 In order to adapt to the encryption form of the Ntru GSW scheme, B h j k , h = 0, 1, …, l-1, k = 1, 2, …, v, for this purpose, the present application gives ciphertext query generation algorithm WncQueryGen():

[0194]

[0195]

[0196] The present application claims

[0197] Further, the ciphertext query expansion algorithm in step 5 specifically includes:

[0198] Let the vector polynomial b = b 0 + b 1 x + … + b N-1 x N-1 ∈ R q , the coefficient vector of which is (b 0, b 1, …, b N-1 ), define the transformation ρ i (b) = (b i , b i-1 , …, b 0, -b N-1 -b N-2 , …, -b i+1 ), which is equivalent to reversing the order of the first i consecutive elements of the coefficient vector of the polynomial b and reversing the order of the i+1 to N-1 consecutive elements, output an N-1-dimensional vector on ;

[0199] Let the input be an RLWE ciphertext query c query = RLWE.Enc(s, μ(x)) = (c 0, c 1 ) = (-as + e + Δ μ(x), a), where the plaintext μ(x) = μ 0 + μ 1 x + … + μ N-1 x N-1 , the coefficient vector of the key is represented by the vector s, c 0,i represents the coefficient of the i-th term of the polynomial element c 0 on the ring R q , then the LWE ciphertext of the plaintext polynomial coefficient is directly extracted from c RLWE , specifically as follows:

[0200] LWE.Enc(s, μ i ) = (c 0,i , ρ i (c 1 )), i = 0, 1, …, N-1

[0201] By using the LWE ciphertext to RLWE ciphertext conversion technique, LWE.Enc(s, μ i ) is converted into RLWE ciphertext with key s, which requires conversion key K

[0202] ct RLWR,i ←LweToRlwe(K, LWE.Enc(s, μ i )), i = 0, 1,..., N-1

[0203] ct RLWE,i is an RLWE ciphertext encrypted with the coefficient μ i , ct RLWE,i = RLWE.Enc(s, μ i ), i = 0, 1,..., N-1, then call the conversion algorithm RlweToNtru() from RLWE ciphertext to NtruSHE ciphertext, input conversion key w, generate a set of NtruSHE ciphertexts: c Ntru,i ←RlweToNtru(w, ct RLWE,i ), i = 0, 1,..., N-1, the calculation result ciphertext c Ntru,i is the NtruSHE ciphertext of the coefficient μ i ;

[0204] The ciphertext conversion algorithm LweToRlwe() includes:

[0205] ct' <- KeySwitch(ct, K): input an RLWE ciphertext conversion key K, calculate and output ciphertext ct' = (c0, 0) + g -1 (c1) · K mod q;

[0206] ct' <- EvalAuto(ct, i, K): input an RLWE ciphertext conversion key K = {K2, K3,..., K l-1}, an integer i, calculate and output ct' = KeySwitch(ct, K i );

[0207] ct RLWE ←LweToRlwe(c LWE , K): input an LWE ciphertext where a = (a0, a1,..., a N-1 ), convert a to polynomial Let initial ciphertext ct = (b, a), for k = 1, 2,..., log2N, iteratively calculate After iteration, output

[0208] Further, the algorithm NtruSHEToGSW() in step 6 is to construct NtruGSW ciphertext based on NtruSHE ciphertext group, including:

[0209] Let plaintext m ∈ {0, 1}, input l NtruSHE encryption codes: ct0 = NtruSHE.Encode(B 0 , m), ct1 = NtruSHE.Encode(B, m),..., ct l-1 = NtruSHE.Encode(B l-1 , m), the present application can construct the l NtruSHE encryption codes into 1 NtruGSW ciphertext, which is zero overhead, very direct, let the construction algorithm be NtruSHEToGSW(), the specific form is:

[0210]

[0211] Further, the NTRU homomorphic outer product operation in step 7 includes:

[0212] Let a NtruSHE ciphertext ct ∈ R q is the encryption of message m0 ∈ {0, 1}, that is, ct = NtruSHE.Enc(sk, m0), a NtruGSW ciphertext is the encryption code of message m1 ∈ {0, 1}, that is, c = NtruGSW.Encode(sk, m1), the decryption keys corresponding to the two ciphertexts are the same, both are f, define the operator to represent the NTRU homomorphic outer product operation:

[0213]

[0214] NTRU homomorphic outer product Output a NtruSHE ciphertext, set as ct ExPorduct , and it is the encryption of message m0m1 mod t, the noise growth rate brought by the homomorphic outer product operation is a non-symmetrical linear, especially when m1 = 0, the noise of ct ExPorduct is irrelevant to ct.

[0215] Figure 2The overall framework of the privacy information retrieval based on the NTRU homomorphism outer product provided by the present application is shown in the figure, and the user side includes query tuple generation and plaintext encoding, RLWE encryption, NTRU decryption and the like, so as to generate a ciphertext query and decrypt to obtain a response result; the server side includes an expansion algorithm, NTRU ciphertext group to NtruGSW ciphertext group conversion, database plaintext and ciphertext multiplication, homomorphic outer product and the like, so as to generate a ciphertext response.

[0216] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, but not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for part or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application.

Claims

1. A privacy information retrieval protocol method based on NTRU homomorphic outer product, characterized in that: The method comprises: Step 1: User User calls the RLWE scheme, NtruSHE scheme and NtruGSW scheme respectively according to the security parameter λ, and generates the parameters of the RLWE scheme, NtruSHE scheme and NtruGSW scheme: Params RLWE ←RLWE.Setup(1 λ ), Params NtruSHE ←NtruSHE.Setup(1 λ ), Params NtruGSW ←NtruGSW.Setup(1 λ ); Step 2: User generates private keys s, f and ciphertext conversion keys w, K according to the RLWE scheme, NtruSHE scheme and conversion key generation algorithms RlweToNtruKeyGen() and LweToRlweKeyGen(), s←RLWE.KeyGen(Params RLWE )、f←NtruSHE.KeyGen(Params NtruSHE ), w←RlweToNtruKeyGen(s,f,B w ), K←LweToRlweKeyGen(s), and determine the parameters v1 and v according to the database size, and the user User will set the parameters Params RLWE 、Params NtruSHE 、Params NtruGSW , the ciphertext conversion key public key w, K, and parameters v1 and v are sent to the server Server, where v is the database dimension parameter, v1 is the scale parameter of the first dimension, B w Indicates conversion base; Step 3: User User calls the query tuple generation algorithm based on the plaintext query index idx to generate the query tuple (i, j1, j2, ..., j v )←QueryTupleGen(idx); Step 4: Input the private key s and call the ciphertext query generation algorithm to generate the ciphertext query c from the query tuple query ←EncQueryGen(s,(i,j1,j2,…,j v )), and ask c for the ciphertext query Send to the server; Step 5: The server receives the ciphertext query c query Afterwards, from c query =(c0,c1) to extract N LWE ciphertexts: c LwE,i =(c 0,i ,ρ i (c1)),i=0,1,…,N-1 Where c1 is the ciphertext, N is the dimension of the ring R polynomial, and c 0,i represents the coefficient of the i-th term of the polynomial c0, ρ i It is a conversion function that can convert the polynomial b=b0+b1x+…+b N-1 x N-1 Convert to an N-dimensional vector (b i ,b i-1 ,…,b0,-b N-1 ,-b N-2 ,…,-b i+1 ); Then input the conversion keys K and w and call the ciphertext conversion algorithms LweToRlwe() and RlweToNtru() in turn to convert the LWE ciphertext into RLWE ciphertext, and then further convert it into NtruSHE ciphertext: ct RLWE,i ←LweToRlwe(K,c LWE,i ),i=0,1,…,N-1 c Ntru,i ←RlweToNtru(w,ct RLWE,i ),i=0,1,…,N-1; Step 6: The server divides the N NtruSHE ciphertexts into v+1 groups, the first group is Convert ciphertext groups other than group 1 to NtruGSW ciphertext groups by calling the algorithm NtruSHEToGSW(): CT NtruGSW,k =(c NtruGSW,k ,g-c NtruGSW,k mod q) Where k = 1, 2, ..., v, g is the tool vector, q is the ciphertext modulus; Step 7: The server performs the secret query calculation, first using the first set of ciphertext CT Ntru Process the first dimension database records, let n represent the number of database data records, for Among them, NtruSHE.MultPlain() is the homomorphic plaintext and ciphertext multiplication, and the addition of the sum symbol adopts the homomorphic addition NtruSHE.Add(), and then CT NtruGSW,0 ,CT NtruGSW,1 ,…,CT NtruGSW,v-1 Process the records of subsequent dimensions of the database and initialize For k = 1, 2, ..., v, the loop iterates as follows: (1) Set num = num / 2; (2) For h = 0, 1, ..., num-1, Among them, g is the tool vector, B is the base, represents the NTRU homomorphic outer product operation, represents a ciphertext polynomial ring, That is, 1 R q The Cartesian direct product of (3) As a result of the calculation, it enters the next round of loop iteration; After completing v iterations, output Is the output of the last iteration, the server will c respond Send to user User; Step 8: User receives c respond , input the private key f, and decrypt the result d according to the NTRU decryption algorithm idx ←NtruSHE.Dec(f,c respond ).

2. The method according to claim 1, characterized in that The RLWE scheme in step 1 is a symmetric homomorphic encryption scheme based on RLWE, including: System establishment algorithm RLWE.Setup(1 λ ): Input security parameter λ, let distribution χ key Represents the distribution of the key, and generates parameters Params based on the decision-type RLWE problem RLWE =(N,q,σ,B,l,t,Δ), ​​so that the complexity of solving difficult problems is not less than 2 λ , where N represents an entire ring The degree of the generating polynomial, q represents the ciphertext modulus, σ represents the standard deviation of the discrete Gaussian distribution, B represents the basis of the tool vector, t represents the plaintext modulus, Key generation algorithm RLWE.KeyGen(Params RLWE ): Input parameters Params RLWE , in the ternary {-1,0,1} distribution Randomly select s from the above, let the key be sk=s∈R, where Encryption algorithm RLWE.Enc(sk,m): Input plaintext m∈R t , in random R q Randomly select an element a←R q , in the discrete Gaussian distribution Randomly select e from above, calculate and output the ciphertext in Decryption algorithm RLWE.Dec(sk,ct): Input ciphertext ct = (c0, c1) and decryption key sk, calculate and output 3. The method according to claim 1, characterized in that The NtruSHE scheme in step 1 is a symmetric homomorphic encryption scheme based on NTRU, including: System establishment algorithm NtruSHE.Setup(1 λ ):Input security parameter λ, according to the decision-type NTRU problem Decisional_NTRU N,q,σ , generate parameters Params NtruSHE =(N,q,σ,B,l,t,Δ), ​​so that the complexity of solving difficult problems is not less than 2 λ , where N represents an entire ring The degree of the generating polynomial, q represents the ciphertext modulus, σ represents the standard deviation of the discrete Gaussian distribution, B represents the basis of the tool vector, t represents the plaintext modulus, Key generation algorithm NtruSHE.KeyGen(Params NtruSHE ): Input parameters Params NtruSHE , randomly selected Calculate f = t·f′ + 1, determine whether f is reversible, and if not, reselect f′ until f is reversible, and output the key sk = f; Encryption algorithm NtruSHE.Enc(sk,m): Input plaintext m∈R t , in the discrete Gaussian distribution Randomly select u from the above, calculate and output the ciphertext ct = u sk -1 +Δ·m mod q; Decryption algorithm NtruSHE.Dec(sk,ct): Input ciphertext ct and decryption key sk, calculate and output In order to speed up the computation of homomorphic multiplication and homomorphic outer product, sometimes the ciphertext does not need to be decryptable and is only used as an intermediate output process. In this case, the following method is used to encrypt the plaintext: Encoding algorithm NtruSHE.Encode(sk,m): Input plaintext m∈R t , in the discrete Gaussian distribution Randomly select u from the above and calculate the ciphertext ct = u sk -1 +m mod q; Homomorphic addition NtruSHE.Add(ct0,ct1): Input two ciphertexts ct0, ct1∈R q , calculate and output ct Add =ct0+ct1mod q; Homomorphic plaintext addition NtruSHE.AddPlain(ct,pt): Input ciphertext ct∈R q and a plaintext pt∈R t , calculate and output ct MultPlaim =ct+Δ·pt mod q; Homomorphic plaintext multiplication NtruSHE.MultPlain(ct,pt): input ciphertext ct∈R q and a plaintext pt∈R t , calculate and output ct MultPlain =ct·pt mod q.

4. The method according to claim 1, wherein The NtruGSW scheme in step 1 is a GSW-type symmetric Boolean homomorphic encryption scheme based on NTRU, including: Given a basis B, let Introduce the tool vector g, Definition of g -1 Transformation: For a∈R q , decompose it based on B in a i ∈R B , g T g -1 (a) = a; System establishment algorithm NtruGSW.Setup(1 λ ):Input security parameter λ, according to the decision-type NTRU problem Decisional_NTRU N,q,σ , generate parameters Params NtruGSW =(N,q,σ,B,l,t,Δ), ​​so that the complexity of solving difficult problems is not less than 2 λ ,in Key generation algorithm NtruGSW.KeyGen(Params NtruGSW ): Input parameters Params NtruGSW , randomly selected Calculate f = tf′ + 1, determine whether f is reversible, if not, reselect f′ until f is reversible, and set the key sk = f; Encryption algorithm NtruGSW.Enc(sk,m): Input plaintext polynomial m∈{0,1}, in l identical discrete Gaussian distributions Randomly select a l-dimensional vector u=(u0,u1,…,u l-1 ), calculate and output the ciphertext c = u·f -1 +Δ·m·g; Decryption algorithm NtruGSW.Dec(sk,c): Input ciphertext c and private key sk, calculate Get the 0th element of vector m and restore the message m=m[0]; In order to speed up the computation of homomorphic multiplication and homomorphic outer product, sometimes the ciphertext does not need to be decryptable and is only used as an intermediate output process. In this case, the following method is used to encrypt the plaintext: Encoding algorithm NtruGSW.Encode(sk,m): Input plaintext polynomial m∈{0,1}, in l identical discrete Gaussian distributions Randomly select a l-dimensional vector u=(u0,u1,…,u l-1 ), calculate and output the ciphertext c = u·f -1 +m·g; Homomorphic addition NtruGSW.Add(c0,c1): input two ciphertexts Calculate and output c Add =c0+c1modq, where That is, 1 R q The Cartesian direct product of Homomorphic plaintext addition NtruGSW.AddPlain(c,pt): input ciphertext And a plaintext pt∈{0,1}, calculate and output c AddPlain =c+Δ·pt·g mod q; Homomorphic complement operation NtruGSW.comple(c): input ciphertext Calculate and output c comple =g-cmodq.

5. The method according to claim 3, characterized in that The conversion key generation algorithm RlweToNtruKeyGen() in step 2 converts RLWE ciphertext to NtruSHE ciphertext, including: The RLWE ciphertext is in the form of Where s is the private key of the RLWE ciphertext, and a is randomly and uniformly selected from R q , e random sampling from the distribution Plaintext m belongs to R t In order to convert RLWE ciphertext into NtruSHE ciphertext, a conversion key w is required. The conversion key generation algorithm RlweToNtruKeyGen() is: Let f denote the private key of the NtruSHE scheme, B w Indicates conversion base; Input the private key s of the RLWE ciphertext, the private key f of the NtruSHE scheme, and the conversion basis B w ,make Conversion key generation algorithm RlweToNtruKeyGen(s,f,B w )for: (1) In distribution Randomly select an l w dimensional vector u w ; (2) Let l w Dimensional Tools Vector (3) Calculate and output the conversion key w=(w0,w1,…,w l-1 )=u w ·f -1 +s·g w mod q; Input RLWE ciphertext ct RLWE And the conversion key w, the conversion algorithm from RLWE ciphertext to NtruSHE ciphertext RlweToNtru(w,c RLWE )for: (1) For the RLWE ciphertext component c RLWE,1 Base B w Decomposition in Indicates that the output data is B w Decomposition of the base; (2) Calculate and output The conversion key generation algorithm LweToRlweKeyGen() in step 2 is a conversion key generation algorithm for LWE ciphertext to RLWE ciphertext, including: K←KSKeyGen(s,s′): Randomly select an l-dimensional vector k1 from the distribution Randomly sample an l-dimensional vector e, calculate k0 = -k1·s′+g·s+e mod q, and output the conversion key of the RLWE ciphertext K←LweToRlweKeyGen(s): Since s is a polynomial, for i'=2,3,…,l-1, let s (i′) =s(x i′ ), call K i '=KSKeyGen(s,s′), then the conversion key from LWE ciphertext to RLWE ciphertext is K={K2,K3,…,K l-1 }.

6. The method according to claim 1, characterized in that The query tuple generation algorithm in step 3 is as follows: The database server stores a database with n records DB={d0,d1,...,d n-1 }, let the private information query index be idx, that is, the query object be d idx , consider the database as a hypercube in v+1 dimensional space2 v1 ×2×2×…×2, that is, the number of the first dimension is The number of dimensions from 2 to v+1 is 2, and the parameters v and v1 are set according to the database size and specific needs; Assume that the query index idx∈{0,1,…,n-1}, then the query tuple generation algorithm QueryTupleGen() is: (1) (2)tmp=idx-i·2 v ; (3) For k = 1, 2, ..., v, execute: ① ②tmp=tmp-j k ·2 v-k ; Finally, the query tuple (i, j1, j2, ..., j v ),in j1,j2,…,j v ∈{0,1}.

7. The method according to claim 2, characterized in that The ciphertext query generation algorithm in step 4 is specifically: The query tuple (i,j1,j2,…,j v ) is embedded into the plaintext polynomial μ(x)=μ0+μ1x+…+μ N-1 x N-1 In the h j k , h'=0,1,…,l-1, k=1,2,…,v, the ciphertext query generation algorithm EncQueryGen() is: Input RLWE private key s and query tuple (i, j1, j2, ..., j v ); Output: RLWE ciphertext Let μ(x) = Δ x i ; For k = 1, 2, ..., v, execute: Output RLWE ciphertext c query =RLWE.Enc(s,μ(x)).

8. The method according to claim 5, characterized in that The ciphertext conversion algorithm in the ciphertext query expansion algorithm in step 5 specifically includes: Let the vector polynomial b = b0 + b1x + ... + b N-1 x N-1 ∈R q , whose coefficient vector is (b0,b1,…,b N-1 ), define the transformation ρ i (b)=(b i ,b i-1 ,…,b0,-b N-1 ,-b N-2 ,…,-b i+1 ), which is equivalent to reversely flipping the 0th to ith consecutive elements of the coefficient vector of the polynomial b, and reversely flipping the i+1th to N-1th consecutive elements, and outputting a N-1 dimensional vector on ; Let the input be an RLWE ciphertext query c query =RLWE.Enc(s,μ(x))=(c0,c1)=(-as+e+Δ·μ(x),a), where plaintext μ(x)=μ0+μ1x+…+μ N-1 x N-1 , using vector s * Represents the coefficient vector of the key, c 0,i Represents R q The coefficient of the i-th degree term of the polynomial element c0 on the ring, and then directly from c RLWE Extract the LWE ciphertext of the plaintext polynomial coefficients as follows: LWE.Enc(s * ,m i )=(c 0,i ,r i (c1)),i=0,1,…,N-1 By using LWE ciphertext to RLWE ciphertext conversion technology, LWE.Enc(s * ,μ i ) is converted to RLWE ciphertext with key s. This conversion requires the conversion key K←LweToRlweKeyGen(s). Let the conversion algorithm be LweToRlwe(), then: ct RLWE,i ←LweToRlwe(K,LWE.Enc(s * ,μ i )),i=0,1,…,N-1 ct RLWE,i is a pair of coefficients μ i Encrypted RLWE ciphertext, ct RLWE,i =RLWE.Enc(s,μ i ), i = 0, 1, ..., N-1, then call the RLWE ciphertext to NtruSHE ciphertext conversion algorithm RlweToNtru(), input the conversion key w, and generate a set of NtruSHE ciphertext: c Ntru,i ←RlweToNtru(w,ct RLWE,i ), i=0,1,…,N-1, the calculated ciphertext c Ntru,i is the coefficient μ i NtruSHE ciphertext; The ciphertext conversion algorithm LweToRlwe() includes: ct′←KeySwitch(ct,K): Input an RLWE ciphertext Convert the key K, calculate and output the ciphertext ct′=(c0,0)+g -1 (c1)·K mod q; ct′←EvalAuto(ct,i,K): Input an RLWE ciphertext Conversion key K={K2,K3,…,K l-1 }, an integer i, calculate and output ct′=KeySwitch(ct,K i ); ct RLWE ←LweToRlwe(c LwE ,K): Input a LWE ciphertext where a=(a0,a1,…,a N-1 ), convert a into a polynomial Let the initial ciphertext ct = (b, a), for k = 1, 2, ..., log2N, iteratively calculate After the iteration is completed, output 9. The method according to claim 3, characterized in that The algorithm NtruSHEToGSW() in step 6 constructs the NtruGSW ciphertext based on the NtruSHE ciphertext group, including: Let plaintext m∈{0,1}, input l NtruSHE encryption codes: ct0=NtruSHE.Encode(B 0 ,m),ct1=NtruSHE.Encode(B,m),…,ct l-1 =NtruSHE.Encode(B l-1 ,m), then the algorithm NtruSHEToGSW() is:

10. The method according to claim 3 or 4, characterized in that The NTRU homomorphic outer product operation in step 7 is: Let an NtruSHE ciphertext ct∈R q is the encryption of message m0∈{0,1}, i.e. ct=NtruSHE.Enc(sk,m0), an NtruGSW ciphertext It is the encrypted code of message m1∈{0,1}, that is, c=NtruGSW.Encode(sk,m1), NTRU homomorphic outer product Output an NtruSHE ciphertext, set as ct ExPorduct , and is the encryption of message m0m1 mod t, when m1=0, ct ExPorduc The noise has nothing to do with ct.

Citation Information

Patent Citations

  • Method and system for sequencing ciphertexts orienting to homomorphic encryption

    CN103401871A

  • Anti-quantum ciphertext equivalent test public key encryption method and system based on lattice

    CN118400197A