Keyword private information retrieval method and device based on layered dynamic constant weight code
Through the combination of multi-dimensional hypercube storage units and anti-collision hash functions, combined with hierarchical dynamic constant-privileged code optimization index update, the hash conflict and global reconstruction problems of PIR technology in dynamic databases are solved, and efficient dynamic expansion and query optimization are achieved.
Patent Information
- Application Number
- CN202510768061.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-10
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-06-10
AI Technical Summary
The existing PIR technology has problems such as high hash collision probability, large global reconstruction overhead, high computational complexity, serious waste of storage resources and low query efficiency in dynamic database scenarios, especially in dynamic updates and expansions.
The multi-dimensional hypercube storage unit and the anti-collision hash function are used for data mapping, combined with the layered dynamic constant-privilege code to optimize the index update time complexity, the code length and Hamming weight are determined through the dynamic programming algorithm, the query vector is compressed by a dynamic segmentation algorithm, and the ciphertext expansion complexity is reduced by precalculating the rotation factor.
Significantly reduce the probability of hash collision, avoid global reconstruction, improve storage accuracy and update efficiency, optimize index update time, improve resource utilization efficiency, control noise variance accumulation, and improve query efficiency and system performance.
Smart Images

Figure CN120277104A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information retrieval, and in particular, to a keyword private information retrieval method and device based on a hierarchical dynamic constant weight code. Background Art
[0002] Private Information Retrieval (PIR) is one of the important protocols in the field of cryptography. This technology allows users to retrieve specific data items from a server while ensuring that the server cannot know the specific content of the user's query. This technology can better protect user privacy and has wide application requirements in fields such as medical record query, financial data acquisition, and anonymous network access.
[0003] The PIR technology needs to copy the database to at least two non-colluding servers. In the information-theoretic security framework, to prevent an adversary from snooping on the user's retrieval privacy, the user has to download all the data on the server, which makes the communication complexity as high as . This scheme that relies on a multi-copy storage architecture not only has extremely low communication efficiency but also causes a great waste of storage resources, seriously restricting its practical application. To reduce the communication complexity, the prior art designs a scheme to implement PIR (Comutational PIR, CPIR for short) through two cryptography principles of homomorphic encryption and oblivious transfer. Among them, in the homomorphic encryption scheme, the user encrypts the query index and sends it to the server. The server calculates on the encrypted data and returns the encrypted result. The user then decrypts the encrypted result to obtain the target data. And in the oblivious transfer scheme, the efficiency is further improved by batch oblivious pseudorandom functions. Through cryptography principles, the query volume of PIR can be greatly reduced.
[0004] Although a large amount of query volume has been reduced in CPIR, there are still some problems in the existing private information retrieval schemes based on constant weight codes when dealing with dynamic databases. For example, keywords are usually mapped to one-dimensional or low-dimensional spaces through simple hash functions. When the database scale is large, the hash conflict probability is as high as , which is extremely likely to cause data retrieval ambiguity and lead to the inability to accurately obtain the target data. Moreover, when the database scale expands, the traditional mapping method is difficult to efficiently support dynamic updates, and usually requires a global reconstruction of the mapping structure, resulting in huge computational and storage overheads. The traditional constant weight code construction depends on a global single combination number and cannot achieve incremental expansion in a dynamic update scenario. When the database scale changes, it is necessary to recalculate and replace the entire codebook in full, and the time complexity is as high as , which not only causes storage redundancy but also leads to serious update delays. Current query vector compression methods also fail to fully consider the non-zero bit distribution characteristics of constant weight codes. They use fixed segmentation parameters for compression, which does not match the actual data distribution, resulting in a waste of a large amount of storage and computing resources. In the process of ciphertext expansion, there are limitations in the generation of rotation factors and the control of hierarchical complexity. Existing algorithms dynamically generate rotation factors in each layer of operation, and the computational complexity increases significantly with the increase in the number of hierarchical levels. At the same time, the global modulus switching strategy will cause the accumulation of noise variance, affecting the system performance, possibly leading to decryption failure or result distortion, and reducing the reliability and effectiveness of private information retrieval. These above problems severely restrict the application and development of PIR technology in dynamic database scenarios. Summary of the Invention
[0005] Embodiments of the present application provide a keyword private information retrieval method and apparatus based on hierarchical dynamic constant weight codes. Data is mapped and stored through a multi-dimensional hypercube storage unit and a collision-resistant hash function to reduce hash conflicts and avoid global reconstruction. The time complexity of index update is optimized through hierarchical dynamic constant weight codes to achieve dynamic incremental expansion.
[0006] In a first aspect, embodiments of the present application provide a keyword private information retrieval method based on hierarchical dynamic constant weight codes. The method includes: Construct a multi-dimensional hypercube storage unit and a collision-resistant hash function on the server side. Use the collision-resistant hash function to map the key-value pair of each data keyword in the database to be retrieved to a unique position in the hypercube storage unit, and map the coordinates of each data in the hypercube storage unit to a unique coordinate constant weight code in a hierarchical mapping manner. The client obtains the key of the data keyword to be retrieved, uses the collision-resistant hash function to map the key of the data to be retrieved to a multi-dimensional indication vector, maps each dimension indication vector in the multi-dimensional indication vector to an indication constant weight code in a hierarchical mapping manner, compresses each indication constant weight code into multiple query polynomials, performs homomorphic encryption on each query polynomial to obtain ciphertext polynomials, combines all the ciphertext polynomials to obtain a query vector, and sends the query vector to the server. The server expands the query vector to obtain an extended query vector, performs equality detection on the coordinate constant weight code in the hypercube storage unit and the extended query vector to obtain a selection vector, performs an ordered homomorphic dot product operation on the selection vector to obtain a query result, and returns the query result to the client. The client performs homomorphic decryption on the query result to obtain the value of the data keyword to be retrieved, and obtains the corresponding data to be retrieved with the key-value pair of the data keyword to be retrieved.
[0007] Second aspect, an embodiment of the present application provides a keyword private information retrieval method based on hierarchical dynamic constant weight codes, including: Obtain the key of the keyword of the data to be retrieved, use a collision-resistant hash function to map the key of the data to be retrieved into a multi-dimensional indication vector, map the indication vector of each dimension in the multi-dimensional indication vector into an indication constant weight code in a hierarchical mapping manner, compress each indication constant weight code into multiple query polynomials, perform homomorphic encryption on each query polynomial to obtain ciphertext polynomials, combine all the ciphertext polynomials to obtain a query vector, and send the query vector to the server; wherein a multi-dimensional hypercube storage unit for mapping the database to be retrieved is constructed in the server, and each key-value pair of the data keyword in the database to be retrieved is mapped to a unique position in the hypercube storage unit, and the coordinates of each data in the hypercube storage unit are mapped to a unique coordinate constant weight code; Obtain the query result of the server, perform homomorphic decryption on the query result to obtain the value of the keyword of the data to be retrieved, and obtain the corresponding data to be retrieved based on the key-value pair of the keyword of the data to be retrieved.
[0008] Third aspect, an embodiment of the present application provides a keyword private information retrieval method based on hierarchical dynamic constant weight codes, including: Construct a multi-dimensional hypercube storage unit for mapping the database to be retrieved, wherein each key-value pair of the data keyword in the database to be retrieved is mapped to a unique position in the hypercube storage unit, and the coordinates of each data in the hypercube storage unit are mapped to a unique coordinate constant weight code; Obtain a query vector for mapping the keyword of the data to be detected from the client, expand the query vector to obtain an extended query vector, perform equality detection on the coordinate constant weight code in the hypercube storage unit and the extended query vector to obtain a selection vector, perform an ordered homomorphic dot product operation on the selection vector to obtain a query result, and return the query result to the client, wherein the query vector is obtained by mapping the key of the data to be retrieved into a multi-dimensional indication vector, mapping the indication vector of each dimension in the multi-dimensional indication vector into an indication constant weight code in a hierarchical mapping manner, compressing each indication constant weight code into multiple query polynomials, and performing homomorphic encryption on each query polynomial to obtain ciphertext polynomials, and combining all the ciphertext polynomials to obtain a query vector.
[0009] Fourth aspect, an embodiment of the present application provides an electronic device, including a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to run the computer program to execute a keyword private information retrieval method based on hierarchical dynamic constant weight codes.
[0010] The main contributions and innovations of the present invention are as follows: The embodiments of the present application use multi-dimensional hypercube storage units and collision-resistant hash functions to process data keyword key-value pairs in a hierarchical mapping manner, which can greatly reduce the probability of hash collisions, avoid the overhead of global reconstruction, and improve storage accuracy and update efficiency. In the construction of constant-weight codes in the embodiments of the present application, the code length and Hamming weight are determined by setting relevant rules, and the time complexity of index update is optimized by means of the dynamic programming algorithm to achieve dynamic incremental expansion. When compressing query vectors in the embodiments of the present application, a dynamic segmentation algorithm is adopted, and various factors are comprehensively considered to determine the number of segments, etc., to improve resource utilization efficiency. In the ciphertext expansion stage of the embodiments of the present application, the time complexity is reduced by pre-computing rotation factors, and the modulus switching strategy is optimized, thereby effectively controlling the accumulation of noise variance.
[0011] Details of one or more embodiments of the present application are set forth in the following drawings and description to make other features, objects, and advantages of the present application more concise and understandable. Brief Description of the Drawings
[0012] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments and descriptions thereof of the present application are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings: Figure 1 is a flowchart of a keyword private information retrieval method based on hierarchical dynamic constant-weight codes according to an embodiment of the present application; Figure 2 is a schematic hardware structure diagram of an electronic device according to an embodiment of the present application. Detailed Embodiments
[0013] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with one or more embodiments of this specification. On the contrary, they are merely examples of devices and methods consistent with some aspects of one or more embodiments of this specification as detailed in the appended claims.
[0014] It should be noted that: in other embodiments, the steps of the corresponding methods are not necessarily executed in the order shown and described in this specification. In some other embodiments, the steps included in the method may be more or less than those described in this specification. In addition, a single step described in this specification may be decomposed into multiple steps for description in other embodiments; and multiple steps described in this specification may also be combined into a single step for description in other embodiments.
[0015] Embodiment 1 The embodiment of the present application provides a keyword private information retrieval method based on a hierarchical dynamic constant weight code. Data mapping storage is performed through a multi-dimensional hypercube storage unit and a collision-resistant hash function to reduce hash conflicts and avoid global reconstruction. The time complexity of index update is optimized through the hierarchical dynamic constant weight code to achieve dynamic incremental expansion. Specifically, referring to Figure 1 , the method includes: Construct a multi-dimensional hypercube storage unit and a collision-resistant hash function on the server side. Use the collision-resistant hash function to map the key-value pair of each data keyword in the database to be retrieved to a unique position in the hypercube storage unit, and map the coordinates of each data in the hypercube storage unit to a unique coordinate constant weight code in a hierarchical mapping manner; The client obtains the key of the data keyword to be retrieved, uses the collision-resistant hash function to map the key of the data to be retrieved to a multi-dimensional indication vector, maps each dimension indication vector in the multi-dimensional indication vector to an indication constant weight code in a hierarchical mapping manner, compresses each indication constant weight code into multiple query polynomials, performs homomorphic encryption on each query polynomial to obtain a ciphertext polynomial, combines all the ciphertext polynomials to obtain a query vector, and sends the query vector to the server; The server expands the query vector to obtain an extended query vector, performs equality detection on the coordinate constant weight code in the hypercube storage unit and the extended query vector to obtain a selection vector, performs an ordered homomorphic dot product operation on the selection vector to obtain a query result, and returns the query result to the client; The client performs homomorphic decryption on the query result to obtain the value of the data keyword to be retrieved, and obtains the corresponding data to be retrieved with the key-value pair of the data keyword to be retrieved.
[0016] In some specific embodiments, the BLAKE3 algorithm is used as the collision-resistant hash function. Through the collision-resistant hash function, it can be ensured that each data keyword in the database to be retrieved is uniquely mapped to a unique position in the multi-dimensional hypercube storage unit, thereby avoiding hash conflicts.
[0017] Exemplarily, using the collision-resistant hash function can reduce the hash conflict probability from to negligible , while avoiding the global reconstruction overhead.
[0018] In the step of "using the collision-resistant hash function to map the key-value pair of each data keyword in the database to be retrieved to the hypercube storage unit", use the collision-resistant hash function to calculate the coordinate value of the key of each data keyword under each dimension of the hypercube storage unit, obtain the coordinate position of each data keyword based on the coordinate value under each dimension, and store the key-value pair of each data keyword at the corresponding coordinate position in the cube storage unit.
[0019] Specifically, the size of each dimension of the hypercube storage unit in this solution is different. Exemplarily, the dimension of the hypercube storage unit is , and the sizes of each dimension are successively , 2 ,...,z . Then, for the key-value pair of the data keyword in the database to be detected , the calculation formula for the coordinate value of k in each dimension of the hypercube storage unit is as follows:
[0020] Wherein, represents the dimension of the hypercube storage unit, represents string concatenation, is the key corresponding to the data keyword, is the total dimension of the hypercube storage unit, is the coordinate value of the key corresponding to the data keyword in dimension i, and BLAKE3 is a collision-resistant hash function.
[0021] That is to say, if there exist any two different keys , the hash values BLAKE( ) and BLAKE( ) obtained through the collision-resistant hash function BLAKE3 will not be mapped to the same position, that is, there is no possibility of hash collision in practice.
[0022] In the step of "mapping the coordinates of each data in the hypercube storage unit to coordinate constant-weight codes in a hierarchical mapping manner", the server sets the corresponding code length and Hamming weight as constant-weight parameters for each dimension of the hypercube storage unit, and converts the coordinate value of the key of each data keyword in the corresponding dimension of the hypercube storage unit into a first constant-weight code based on the constant-weight parameters of each dimension of the hypercube storage unit, and integrates the first constant-weight codes of each dimension to obtain the coordinate constant-weight code.
[0023] Furthermore, the server sets the objective function and constraint formula for the code length and Hamming weight, and sets the corresponding code length and Hamming weight for each dimension of the hypercube storage unit based on the objective function and constraint conditions.
[0024] Specifically, the formula of the objective function is expressed as follows:
[0025] Wherein, is the code length of the th layer in the th dimension, is the number of layers of the th dimension of the hypercube storage unit.
[0026] Specifically, the formula representation of the constraint conditions is as follows: :
[0027] Wherein, is the current dimension, j is the current layer number, is the total number of layers of the hypercube storage unit in the dimension, is the dimension, and the layer code length, is the dimension, and the layer Hamming weight, is to cover a given database scale on the premise of satisfying the total Hamming weight conservation .
[0028] Specifically, under the objective function and constraint conditions, the server estimates all possible combination numbers through the dynamic programming method and stores them in the lookup table to accelerate subsequent queries. Under each dimension of the hypercube storage unit, different code lengths and Hamming weights are traversed, and the Hamming weight is selected from small to large during the traversal until the constraint conditions are met to determine the code length and Hamming weight of each dimension.
[0029] Specifically, obtain the coordinate values of the key of each data keyword under each dimension of the hypercube storage unit , and then calculate the first constant weight value based on the code length and Hamming weight under the corresponding dimension, and integrate the first constant weight codes under each dimension to obtain the coordinate constant weight code.
[0030] Specifically, under the total Hamming weight conservation constraint of the hierarchical mapping scheme in this solution, the number of hierarchical levels , code length and Hamming weight are adaptively selected through the dynamic programming algorithm, and the index update time complexity is reduced from to , significantly reducing the combination number scale.
[0031] In some embodiments, since the database to be detected is updated in real time, if a new data keyword is added to the current database to be detected, and the dimension capacity of the current hypercube storage unit cannot store the data content in the database to be retrieved due to the addition of the new data keyword, the dimension of the hypercube is expanded, and the new keyword is mapped to the expanded dimension of the hypercube storage unit. The formula representation is as follows: 。
[0032] Among them, is the coordinate position of the new data in the hypercube, is the dimension size of the hypercube storage unit after dimension expansion.
[0033] That is to say, for the original data keywords in the database to be detected, the retrieval is still based on the original dimensions of the hypercube, while for the new data, the detection is carried out with the expanded dimensions of the hypercube storage unit, without global reconstruction.
[0034] Specifically, for any dimension in the hypercube storage unit, on the premise of ensuring that the code length and Hamming weight of dimension remain unchanged, replace the content of the th dimension to adapt to the dynamic update of the database to be detected.
[0035] In some specific embodiments, the specific implementation of the client mapping the key of the data to be retrieved to a multi-dimensional indication vector is the same as that of the server using a collision-resistant hash function to map the key-value pair of each data keyword in the database to be retrieved to the hypercube storage unit, which will not be elaborated here. Similarly, the specific implementation of the client mapping the indication vector of each dimension to an indication constant weight code in a hierarchical mapping manner is the same as the processing method of the first constant weight code above, and will not be elaborated either.
[0036] Embodiment 2 The embodiment of the present application provides a keyword private information retrieval method based on hierarchical dynamic constant weight codes, including: Obtain the key of the data keyword to be retrieved, use a collision-resistant hash function to map the key of the data to be retrieved to a multi-dimensional indication vector, map the indication vector of each dimension in the multi-dimensional indication vector to an indication constant weight code in a hierarchical mapping manner, compress each indication constant weight code into multiple query polynomials and perform homomorphic encryption on each query polynomial to obtain ciphertext polynomials, combine all the ciphertext polynomials to obtain a query vector, and send the query vector to the server; wherein a multi-dimensional hypercube storage unit for mapping the database to be retrieved is constructed in the server, and the key-value pair of each data keyword in the database to be retrieved is mapped to a unique position in the hypercube storage unit, and the coordinate of each data in the hypercube storage unit is mapped to a unique coordinate constant weight code; Obtain the query result of the server, perform homomorphic decryption on the query result to obtain the value of the data keyword to be retrieved, and obtain the corresponding data to be retrieved with the key-value pair of the data keyword to be retrieved.
[0037] In some embodiments, a dynamic segmentation algorithm is set, and each indication constant weight code is segmented based on the dynamic segmentation algorithm into segments, and a query polynomial is constructed for each segment respectively to obtain a plurality of query polynomials. The formula of the dynamic segmentation algorithm is as follows:
[0038]
[0039] Wherein, is the number of segments, is the total length of the indication constant weight code, is the compression constant, is the influence weight of the number of segments on the computational complexity, is the influence weight of the size of each segment on the memory occupation, is the influence weight of the distribution characteristics of the constant weight code on the computational efficiency, represents the indication constant weight code the variance of the non-zero bit distribution in.
[0040] Specifically, in practical applications, is used to measure the sparsity of data. That is to say, according to the above formula, if is evenly distributed, then the value will become larger. If is unevenly distributed, then the value needs to be reduced to adapt to local sparsity.
[0041] Furthermore, the formula for constructing each segment into a query polynomial is as follows:
[0042] Wherein, is the current segment , is the dimension of the indication constant weight code, is the compression parameter, is the indication constant weight code, is the dimension of the hypercube storage unit, is the number of indication constant weight codes in the current dimension.
[0043] Furthermore, the modulus for constructing the query polynomial is dynamically determined based on the current noise level and computational requirements. The modulus refers to the ciphertext modulus of homomorphic encryption, which is used to define the coefficient range of the ciphertext polynomial. When the ciphertext modulus is larger, the computational accuracy is higher, but at the same time, the calculation is more complex and the noise grows faster. Therefore, after encryption here, using the modulus conversion technology, a smaller ciphertext modulus can be selected to reduce the computational complexity and the speed of noise growth.
[0044] Specifically, in the polynomial construction stage, a larger modulus is used to ensure computational accuracy. However, a larger modulus also brings higher computational complexity and the risk of noise growth. Therefore, gradually switch to a smaller modulus , to reduce the complexity of subsequent calculations and control the growth of noise. The formula for modulus switching is as follows:
[0045] where is the modulus reduction factor at the stage, which is dynamically determined according to the current noise level and computational requirements.
[0046] In some embodiments, the BFV homomorphic encryption algorithm is used to encrypt each query polynomial and output it with the smallest modulus , which can not only reduce the computational complexity but also control the growth of noise, ensuring the security and integrity of the encryption result.
[0047] In some specific embodiments, the ciphertext polynomials corresponding to all multi-dimensional indicator vectors are combined to obtain a query vector.
[0048] In the step of "extending the query vector to obtain an extended query vector", calculate and store the rotation factor for each dimension of the hypercube storage unit, initialize the number of segments and create a global ciphertext set. Load each ciphertext polynomial in the query vector into a temporary array in turn, and extend each ciphertext polynomial in the temporary array one by one, and save the extension result to the global ciphertext set. When the extension of all ciphertext polynomials is completed, output the global ciphertext set to obtain the extended query vector.
[0049] Specifically, the global ciphertext set is initially an empty set. First, pre-calculate and store the rotation factor for each dimension , where , and initialize the number of blocks . The outer loop processes each block in turn , load the current ciphertext polynomial into the temporary array . In the hierarchical loop, the parameter increases from 0 to . Each layer corresponds to expanding the number of blocks to . For each layer , the block operation loops through the index , extracts the current block and performs modulus reduction . Subsequently, use the pre-stored factor Calculate the rotation term and the shift block , and update the block value through linear combination: and , ensuring the independence of the extended block.
[0050] Specifically, by pre-computing and storing the rotation factors for each dimension, the time complexity can be reduced from to .
[0051] In some specific embodiments, equality detection is completed by finding the coordinate constant weight code of each item in the corresponding extended query vector under each dimension of the hypercube storage unit. The formula for equality detection is as follows:
[0052] where is the coordinate constant weight code in ciphertext form, is the item in the extended query vector under the dimension.
[0053] That is to say, the extended query vector is subjected to equality detection with the hypercube coordinate constant weight code of the corresponding dimension through the above formula, and a selection vector will be generated in each dimension, where only one of them is 1 and the others are 0.
[0054] In the step of "performing an ordered homomorphic dot product operation on the selection vector to obtain a query result", the hypercube storage unit is used as the plaintext database. The items in different dimensions of the selection vector are successively subjected to homomorphic dot product with the plaintext database to obtain an intermediate database, and then the intermediate database is subjected to homomorphic dot product with the selection vector to obtain a new intermediate database until the intermediate database only contains the query result corresponding to the selection vector. Among them, the plaintext database / intermediate database is reshaped before each round of homomorphic dot product.
[0055] That is to say, in this solution, the items in different dimensions of the selection vector are subjected to homomorphic dot product with the plaintext database / intermediate database, so as to gradually screen out the target items that meet the conditions.
[0056] Specifically, the formula for performing an ordered homomorphic dot product operation on the selection vector to obtain a query result is as follows:
[0057] where the dot product starts with the ciphertext form of the selection vector and the plaintext database to generate the intermediate database , subsequently, for each step i, the selection vector is dot - producted with the reshaped form of the intermediate database obtained in the previous step to form a new intermediate database , and the plaintext database has a size of . In each step, the intermediate database is reshaped into a new two - dimensional matrix before participating in the dot - product, and its size is .
[0058] In some specific embodiments, the key of the BFV homomorphic encryption is used to decrypt the query result to obtain the key - value pair of the keyword of the data to be retrieved, and the corresponding data is obtained with the key - value pair of the keyword.
[0059] Embodiment III The present application also proposes a keyword private information retrieval method based on a hierarchical dynamic constant - weight code, including: Constructing a multi - dimensional hypercube storage unit that maps the database to be retrieved, where each key - value pair of data keywords in the hyper - database to be retrieved is mapped to a unique position in the hypercube storage unit, and the coordinates of each data in the hypercube storage unit are mapped to a unique coordinate constant - weight code; Obtaining a query vector that maps the data keyword to be detected from the client, expanding the query vector to obtain an extended query vector, performing an equality detection on the coordinate constant - weight code in the hypercube storage unit and the extended query vector to obtain a selection vector. Performing an ordered homomorphic dot - product operation on the selection vector to obtain a query result, and returning the query result to the client, where the query vector maps the key of the data to be retrieved to a multi - dimensional indication vector, and in a hierarchical mapping manner, each dimension indication vector in the multi - dimensional indication vector is mapped to an indication constant - weight code, each indication constant - weight code is compressed into multiple query polynomials, and the ciphertext polynomials obtained by homomorphically encrypting each query polynomial are combined to obtain the query vector.
[0060] Embodiment IV This embodiment also provides an electronic device, referring to Figure 2 , including a memory 404 and a processor 402. The memory 404 stores a computer program, and the processor 402 is configured to run the computer program to execute the steps in any one of the above - mentioned method embodiments.
[0061] Specifically, the above - mentioned processor 402 may include a central processing unit (CPU), or an application - specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application.
[0062] Among them, the memory 404 may include a mass memory 404 for data or instructions. By way of example and not limitation, the memory 404 may include a hard disk drive (HDD), a floppy disk drive, a solid state drive (SSD), a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive, or a combination of two or more of these. In a suitable case, the memory 404 may include removable or non-removable (or fixed) media. In a suitable case, the memory 404 may be inside or outside the data processing device. In a particular embodiment, the memory 404 is a non-volatile memory. In a particular embodiment, the memory 404 includes a read-only memory (ROM) and a random access memory (RAM). In a suitable case, the ROM may be a mask-programmed ROM, a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), an electrically alterable ROM (EAROM), or a flash memory, or a combination of two or more of these. In a suitable case, the RAM may be a static random access memory (SRAM) or a dynamic random access memory (DRAM), where the DRAM may be a fast page mode dynamic random access memory (FPMDRAM), an extended date out dynamic random access memory (EDODRAM), a synchronous dynamic random access memory (SDRAM), etc.
[0063] The memory 404 can be used to store or cache various data files required for processing and / or communication, as well as possible computer program instructions executed by the processor 402.
[0064] The processor 402 reads and executes the computer program instructions stored in the memory 404 to implement any one of the above-described keyword private information retrieval methods based on hierarchical dynamic constant weight codes.
[0065] Optionally, the above electronic device may further include a transmission device 406 and an input / output device 408. Among them, the transmission device 406 is connected to the above processor 402, and the input / output device 408 is connected to the above processor 402.
[0066] The transmission device 406 can be used to receive or send data via a network. Specific examples of the above network may include a wired or wireless network provided by a communication provider of the electronic device. In one example, the transmission device includes a network adapter (Network Interface Controller, abbreviated as NIC), which can be connected to other network devices through a base station and thus communicate with the Internet. In one example, the transmission device 406 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0067] The input / output device 408 is used to input or output information. In this embodiment, the input information can be a hypercube storage unit, a constant weight code, etc., and the output information can be a keyword of data to be retrieved, etc.
[0068] Optionally, in this embodiment, the above processor 402 can be set to execute the following steps through a computer program: Construct a multi-dimensional hypercube storage unit and a collision-resistant hash function on the server side, use the collision-resistant hash function to map the key-value pair of each data keyword in the database to be retrieved to a unique position in the hypercube storage unit, and map the coordinates of each data in the hypercube storage unit to a unique coordinate constant weight code in a hierarchical mapping manner; The client obtains the key of the data keyword to be retrieved, uses the collision-resistant hash function to map the key of the data to be retrieved to a multi-dimensional indication vector, maps each dimension indication vector in the multi-dimensional indication vector to an indication constant weight code in a hierarchical mapping manner, compresses each indication constant weight code into a plurality of query polynomials, performs homomorphic encryption on each query polynomial to obtain a ciphertext polynomial, combines all the ciphertext polynomials to obtain a query vector, and sends the query vector to the server; The server extends the query vector to obtain an extended query vector, performs an equality detection on the coordinate constant weight codes in the hypercube storage unit and the extended query vector to obtain a selection vector, performs an ordered homomorphic dot product operation on the selection vector to obtain a query result, and returns the query result to the client; The client performs homomorphic decryption on the query result to obtain the value of the keyword of the data to be retrieved, and obtains the corresponding data to be retrieved according to the key-value pair of the keyword of the data to be retrieved.
[0069] It should be noted that the specific examples in this embodiment can refer to the examples described in the above embodiments and optional implementation manners, and will not be elaborated here.
[0070] Generally, various embodiments can be implemented in hardware or dedicated circuits, software, logic, or any combination thereof. Some aspects of the present invention can be implemented in hardware, while other aspects can be implemented by firmware or software executed by a controller, a microprocessor, or other computing devices, but the present invention is not limited thereto. Although various aspects of the present invention can be shown and described as block diagrams, flowcharts, or using some other graphical representation, it should be understood that, as a non-limiting example, the blocks, devices, systems, techniques, or methods described herein can be implemented in hardware, software, firmware, dedicated circuits or logic, general hardware or a controller, or other computing devices, or some combination thereof.
[0071] Embodiments of the present invention can be implemented by computer software, which can be executed by a data processor of a mobile device, such as in a processor entity, or can be implemented by hardware, or can be implemented by a combination of software and hardware. A computer software or program (also referred to as a program product), including software routines, applets, and / or macros, can be stored in any device-readable data storage medium, and they include program instructions for performing specific tasks. The computer program product can include one or more computer-executable components configured to execute embodiments when the program runs. One or more computer-executable components can be at least one software code or a part thereof. Additionally, in this regard, it should be noted that any box in the logical flow, as Figure 2 shown, can represent a program step, or an interconnected logical circuit, box, and function, or a combination of a program step and a logical circuit, box, and function. The software can be stored on physical media such as memory chips or storage blocks implemented within a processor, magnetic media such as hard disks or floppy disks, and optical media such as, for example, DVDs and their data variants, CDs. The physical media are non-transitory media.
[0072] Those skilled in the art should understand that the technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as within the scope described in this specification.
[0073] The above embodiments only express several implementation manners of the present application, and the description thereof is relatively specific and detailed, but it should not be construed as a limitation on the scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. A keyword private information retrieval method based on a hierarchical dynamic constant weight code, characterized in that It includes the following steps: Construct a multi-dimensional hypercube storage unit and a collision-resistant hash function on the server side. Use the collision-resistant hash function to map the key-value pairs of each data keyword in the database to be retrieved to a unique position in the hypercube storage unit, and map the coordinates of each data in the hypercube storage unit to a unique coordinate constant weight code in a hierarchical mapping manner; The client obtains the key of the data keyword to be retrieved, uses the collision-resistant hash function to map the key of the data to be retrieved to a multi-dimensional indication vector, maps the indication vector of each dimension in the multi-dimensional indication vector to an indication constant weight code in a hierarchical mapping manner, compresses each indication constant weight code into multiple query polynomials, performs homomorphic encryption on each query polynomial to obtain a ciphertext polynomial, combines all the ciphertext polynomials to obtain a query vector, and sends the query vector to the server; The server expands the query vector to obtain an extended query vector, performs equality detection on the coordinate constant weight code in the hypercube storage unit and the extended query vector to obtain a selection vector, performs an ordered homomorphic dot product operation on the selection vector to obtain a query result, and returns the query result to the client; The client performs homomorphic decryption on the query result to obtain the value of the data keyword to be retrieved, and obtains the corresponding data to be retrieved according to the key-value pair of the data keyword to be retrieved.
2. The keyword private information retrieval method based on a hierarchical dynamic constant weight code according to claim 1, wherein In the step of "using the collision-resistant hash function to map the key-value pairs of each data keyword in the database to be retrieved to a unique position in the hypercube storage unit", use the collision-resistant hash function to calculate the coordinate value of the key of each data keyword under each dimension of the hypercube storage unit, obtain the coordinate position of each data keyword based on the coordinate value under each dimension, and store the key-value pair of each data keyword in the corresponding coordinate position of the cube storage unit.
3. A keyword private information retrieval method based on a hierarchical dynamic constant weight code according to claim 1, characterized in that In the step of "mapping the coordinates of each data in the hypercube storage unit to a coordinate constant weight code in a hierarchical mapping manner", the server sets the corresponding code length and Hamming weight for each dimension of the hypercube storage unit as constant weight parameters, and converts the coordinate value of the key of each data keyword under the corresponding dimension of the hypercube storage unit to a first constant weight code based on the constant weight parameters under each dimension of the hypercube storage unit, and integrates the first constant weight codes under each dimension to obtain the coordinate constant weight code.
4. The keyword private information retrieval method based on a hierarchical dynamic constant weight code according to claim 3, wherein The server sets the objective function and constraint formula for the code length and Hamming weight, and sets the corresponding code length and Hamming weight for each dimension of the hypercube storage unit based on the objective function and constraint conditions. The formula of the objective function is as follows: ; Among them, is the code length of the layer in the dimension, is the number of layers of the dimension of the hypercube storage unit; The formula representation of the above-mentioned constraint conditions is as follows, :[[]]END]] Among them, is the current dimension, is the current layer number, is the total number of layers of the hypercube storage unit in the dimension, is the dimension, and is the code length of the layer in the dimension, is the Hamming weight of the layer in the dimension, and covers a given database scale on the premise of satisfying the conservation of the total Hamming weight.
5. A keyword private information retrieval method based on a hierarchical dynamic constant weight code, characterized in that, It includes the following steps: Obtain the key of the keyword of the data to be retrieved, use a collision-resistant hash function to map the key of the data to be retrieved into a multi-dimensional indication vector, map the indication vector of each dimension in the multi-dimensional indication vector into an indication constant weight code in a hierarchical mapping manner, compress each indication constant weight code into multiple query polynomials, and perform homomorphic encryption on each query polynomial to obtain ciphertext polynomials. Combine all the ciphertext polynomials to obtain a query vector, and send the query vector to the server. Among them, a multi-dimensional hypercube storage unit that maps the database to be retrieved is constructed in the server. The key-value pair of each data keyword in the database to be retrieved is mapped to a unique position in the hypercube storage unit, and the coordinates of each data in the hypercube storage unit are mapped to a unique coordinate constant weight code. Obtain the query result of the server, perform homomorphic decryption on the query result to obtain the value of the keyword of the data to be retrieved, and obtain the corresponding data to be retrieved according to the key-value pair of the keyword of the data to be retrieved.
6. The keyword private information retrieval method based on a hierarchical dynamic constant weight code according to claim 5, characterized in that Set a dynamic segmentation algorithm. Based on the dynamic segmentation algorithm, each indication constant weight code is segmented into S segments, and multiple query polynomials are constructed for each segment respectively. The formula of the dynamic segmentation algorithm is as follows: ; ; Among them, is the number of segments, is the total length of the indicating constant weight code, is the compression constant, is the influence weight of the number of segments on the computational complexity, is the influence weight of the size of each segment on the memory occupancy, is the influence weight of the distribution characteristic of the constant weight code on the computational efficiency, represents the indicating constant weight code and is the variance of the non-zero bit distribution in it.
7. A keyword private information retrieval method based on a hierarchical dynamic constant weight code according to claim 6, characterized in that, The formula for constructing each segment into a query polynomial is as follows: ; Among them, is the current segment , is the dimension indicating the constant weight code, is the compression parameter, is the indication of the constant weight code, is the dimension of the hypercube storage unit, is the number of constant weight codes indicated in the current dimension.
8. A keyword private information retrieval method based on a hierarchical dynamic constant weight code according to claim 5, characterized in that, In the step of "extending the query vector to obtain an extended query vector", calculate and store the rotation factor of each dimension of the hypercube storage unit, initialize the number of segments and create a global ciphertext set. Load each ciphertext polynomial in the query vector into a temporary array in turn, and extend each ciphertext polynomial in the temporary array one by one, and save the extension result to the global ciphertext set. When the extension of all ciphertext polynomials is completed, output the global ciphertext set to obtain the extended query vector.
9. A keyword private information retrieval method based on a hierarchical dynamic constant weight code, characterized in that, Include the following steps: Construct a multi-dimensional hypercube storage unit that maps the database to be retrieved, where the key-value pair of each data keyword in the database to be retrieved is mapped to a unique position in the hypercube storage unit, and the coordinates of each data in the hypercube storage unit are mapped to a unique coordinate constant weight code. Obtain the query vector that maps the keyword of the data to be detected from the client, extend the query vector to obtain an extended query vector, perform equality detection on the coordinate constant weight code in the hypercube storage unit and the extended query vector to obtain a selection vector, perform an ordered homomorphic dot product operation on the selection vector to obtain a query result, and return the query result to the client. Among them, the query vector is obtained by mapping the key of the data to be retrieved into a multi-dimensional indication vector, mapping the indication vector of each dimension in the multi-dimensional indication vector into an indication constant weight code in a hierarchical mapping manner, compressing each indication constant weight code into multiple query polynomials, and performing homomorphic encryption on each query polynomial to obtain ciphertext polynomials, and combining all the ciphertext polynomials to obtain a query vector.
10. An electronic device, comprising a memory and a processor, characterized in that, A computer program is stored in the memory, and the processor is configured to run the computer program to execute a method for keyword private information retrieval based on a hierarchical dynamic constant weight code according to any one of claims 1-4, or a method for keyword private information retrieval based on a hierarchical dynamic constant weight code according to any one of claims 5-8, or a method for keyword private information retrieval based on a hierarchical dynamic constant weight code according to claim 9.
Citation Information
Patent Citations
Anonymous search system suitable for large-scale multi-valued mapping database
CN119622787A
Homomorphic keyword privacy information retrieval method and system based on polynomial link
CN119918088A
Batch privacy information retrieval method and device
WO2024239204A1