Multi-log range query on encrypted data

By handling range query token and encrypted index updates on the server side, the problems of low query efficiency and insufficient privacy in encrypted database outsourcing are solved, achieving efficient range queries and data protection.

CN106708921BActive Publication Date: 2025-12-05SAP SE
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN201610911555.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2015-11-12
Filing Date
2016-10-19
Publication Date
2025-12-05
Estimated Expiration
2036-10-19

AI Technical Summary

Technical Problem

Existing encrypted database outsourcing solutions may leak additional information or significantly slow down the search process when handling range queries, failing to effectively protect data privacy and improve search efficiency.

Method used

By receiving a range query token on the server-side computing device, it determines whether the encrypted search index tree list is empty, and encrypts the query results based on the tree list and the range query token, updates the encrypted search index, and uses an interactive protocol to build and refine the encrypted index to accelerate subsequent queries.

Benefits of technology

It achieves a reduction in the average search time for range queries and improves query efficiency while maintaining data privacy, without revealing unqueried encrypted information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN106708921B_ABST
    Figure CN106708921B_ABST
Patent Text Reader

Abstract

Methods, systems, and computer-readable storage media for range querying encrypted data, including acts of receiving a range query token; determining whether a tree list of encrypted search indexes is empty, and whether a range of the token intersects a range specified by the tree list, whether the encrypted search indexes include one or more of the tree list and a point list; if the tree list is non-empty and the range of the token is at least one sub-range of the range specified by the tree list, receiving encrypted query results based on one of the search trees, and if the tree list is empty or the range of the token is not at least one sub-range of the range specified by the tree list, and updating the encrypted search index based on the token, receiving the point list.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] This application relates to querying encrypted data. BACKGROUND

[0002] Encrypting databases in cloud platforms and / or database as a service (DaaS) environments provides data protection (security). In encrypted databases, data (plaintext) can be encrypted on the client side to provide encrypted data (ciphertext) that can be provided to a database for storage. In some examples, a third party provides and maintains the database. That is, the database is outsourced to a third party. For example, a customer encrypts data using one or more encryption keys to provide encrypted data, which the customer sends to a third party for storage in a database.

[0003] Outsourcing databases provides efficient resource management and low maintenance costs for customers, but exposes the outsourced data (customer data) to the service provider (the third party providing the database and its agents). For example, range queries that are protected for privacy enable encrypted data while also enabling testing of the ciphertext. This provides the possibility for a data owner to outsource a data set to a cloud service provider while neither sacrificing privacy nor losing the ability to filter the data. However, current schemes for handling range queries either leak additional information (e.g., the order of the complete data set) or significantly slow down the search process. SUMMARY

[0004] Implementations of the present disclosure include computer-implemented methods for performing multi-log range queries on encrypted data stored in a database on a server. In certain implementations, the acts include receiving, by a server-side computing device, a range query token from a client-side computing device; determining, by the server-side computing device, one or more of whether a tree list of encrypted search indexes is empty and whether a range of the range query token intersects a range accounted for by at least one tree in the tree list, the encrypted search indexes comprising the tree list and a point list; receiving, by the server-side computing device, encrypted query results based on one of the search trees if the tree list is non-empty and the range query token is at least one sub-range of the range accounted for by the tree list, and the point list if the tree list is empty or the range of the range query token is not at least one sub-range of the range accounted for by the tree list; and updating, by the server-side computing device, the encrypted search indexes based on the range query token and a client-server side protocol. Other implementations of this aspect include corresponding systems, apparatus, and computer programs, configured to perform the acts of the methods, which are encoded on computer storage devices.

[0005] These and other implementations can each optionally include one or more of the following features. Updating the encrypted search index includes transmitting, to the client computing device, a refined range query token based at least in part on the range query token and a previously received range query token, receiving, from the client computing device, the refined range token, and updating the encrypted search index based on the refined range token. Updating the encrypted search index includes transmitting, to the client computing device, a root node of a search tree of the tree list and a previously received query corresponding to the search tree, expanding the search tree of the tree list to provide an expanded search tree based at least in part on the root node of the search tree and the previously received query corresponding to the search tree, and providing a new range query token corresponding to the expanded search tree. Updating the encrypted search index includes transmitting, to the client computing device, respective root nodes of a plurality of search trees of the tree list, merging the plurality of search trees of the tree list to provide a merged search tree based at least in part on the respective root nodes of the plurality of search trees, and receiving a revised token corresponding to the merged search tree. Merging the plurality of trees is in response to determining that there is no value gap between the plurality of trees. The actions further include receiving, from the client computing device, the encrypted search index and the ciphertext. The tree list includes at least one search tree based on a previously received range query token.

[0006] The present disclosure also provides a computer-readable storage medium coupled to one or more processors and having instructions stored thereon that, when executed by the one or more processors, cause the one or more processors to perform operations in accordance with implementations of the methods provided herein.

[0007] The present disclosure also provides a system for implementing the methods provided herein. The system includes one or more processors, and a computer-readable storage medium coupled to the one or more processors and having instructions stored thereon that, when executed by the one or more processors, cause the one or more processors to perform operations in accordance with implementations of the methods provided herein.

[0008] It will be appreciated that methods according to the present disclosure can include any combination of the aspects and features described herein. That is, methods according to the present disclosure are not limited to the combination of aspects and features specifically described herein, but include any combination of the aspects and features provided.

[0009] The specifics of one or more implementations of the present disclosure are set forth in the accompanying drawings and description below. Other features and advantages will become apparent from the description and drawings, and from the claims. BRIEF DESCRIPTION OF DRAWINGS

[0010] Figure 1 An example high-level architecture is depicted in accordance with implementations of the present disclosure.

[0011] Figure 2 An example search tree is depicted in accordance with implementations of the present disclosure.

[0012] Figure 3 An example relationship between ranges is described.

[0013] Figure 4 An example process that can be run in accordance with implementations of the present disclosure is depicted.

[0014] Figure 5 is a schematic diagram of a computer system that can be used to perform implementations of the present disclosure.

[0015] The same reference symbols in the various drawings indicate the same elements. DETAILED DESCRIPTION

[0016] Implementations of the present disclosure include computer-implemented methods of performing multi-log range queries on encrypted data stored in a database on a server. More specifically, implementations of the present disclosure enable range queries requested from a client (e.g., a data owner) to be compared on the server side (e.g., the hosted database). In this way, a service provider can use information obtained from ranges of previous queries to speed up the search time of subsequent range queries. In some implementations, values that fall within the range of a query are stored in an interactively constructed search index for subsequent range requests. In some implementations, values that have not been queried before do not leak any information to the cloud service provider and remain completely secure. As discussed in further detail herein, implementations of the present disclosure reduce information leakage while supporting an average multi-log search time.

[0017] Figure 1 An example of a high-level architecture 100 in accordance with implementations of the present disclosure is depicted. The high-level architecture 100 includes a computing device 102 (e.g., a client), a server system 104, and a network 106. In some examples, the computing device 102 can communicate with the server system 104 through the network 106. In some examples, the computing device 102 can communicate with the server system 104 through one or more networks (e.g., including the network 106). In some examples, the computing device 102 can include any appropriate type of computing device, such as a desktop computer, a laptop computer, a handheld computer, a tablet computer, a personal digital assistant (PDA), a cellular telephone, a web appliance, a camera, a smart phone, an enhanced general packet radio service (EGPRS) mobile phone, a media player, a navigation device, an email device, a game console, or any suitable combination of these or other data processing devices.

[0018] In some implementations, the server system 104 includes at least one server device 108 and at least one data store 110. In some implementations, the server device 108 includes one or more processors 112 and one or more memory devices 114. In some implementations, the server device 108 includes one or more servers, such as a web server, an application server, a proxy server, a database server, a file server, a print server, a game server, a media server, a fax server, a directory server, a mail server, a Figure 1Examples of server system 104 are intended to represent a variety of forms of servers, including but not limited to: web servers, application servers, proxy servers, network servers, and / or server pools. In general, server system accepts requests for application services and provides such services to any number of client devices (e.g., computing device 102) over network 106.

[0019] In some implementations, network 106 can include a large computer network, such as a local area network (LAN), a wide area network (WAN), the Internet, a cellular network, a telephone network (e.g., PSTN), or suitable combinations thereof, connecting any number of communication devices, mobile computing devices, fixed computing devices, and server systems.

[0020] According to implementations of the present disclosure, server system 104 maintains a database (e.g., an encrypted database) that stores encrypted data. In some examples, data (plaintext) is encrypted at computing device 102 (a client) and the encrypted data (ciphertext) is sent to server system 104 over network 106 for storage. In some implementations, and as described herein, server system 104 can be provided by a third-party service provider that stores and provides access to the encrypted data.

[0021] In some implementations, the database is part of a database system that also includes a query execution engine. In some examples, the query execution engine receives a query (e.g., a search token from a client), provides a query plan based on the query, executes the query plan to provide a response (i.e., encrypted data from the database that responds to the query, for example), and sends the response to the client (e.g., from which the query was received). In some examples, the query plan includes one or more operations to be performed on the encrypted data.

[0022] Implementations of the present disclosure are described in the context of an example in which data is outsourced to a cloud service provider (e.g., a database in the cloud). Cloud computing enables a data owner to outsource data while enabling the data owner to access the data using one or more computing devices. For example, a computing device with limited computing power (e.g., a smart phone, relative to a desktop computer) can be used to access a relatively large data set. This is possible by delegating computationally expensive operations (e.g., searches) to the cloud service provider. In some examples, a relatively small subset of data that matches a search query is sent to the client computing device and processed by the client computing device.

[0023] To protect data privacy, the outsourced data is encrypted. For example, the data (plaintext) is encrypted at the client side to provide encrypted data (ciphertext) that is sent to and stored at the server side. In some examples, standard encryption schemes are not suitable for data outsourcing scenarios because they do not enable processing of encrypted data. As a result, the entire encrypted data needs to be transferred to the client computing device and decrypted and processed locally.

[0024] Advanced encryption schemes enable the computing device at the server side (of the cloud service provider) to perform search operations, e.g., such as exact pattern matching and / or range queries on the ciphertext. In some examples, the data owner can encrypt the data and augment the encrypted data with additional information (e.g., a keyword, a timestamp). The data owner transfers the ciphertext to the cloud service provider. Using a key (e.g., an encryption key known only to the data owner), the data owner can create a search token (e.g., for exact pattern matching on a keyword, a range within which the timestamp should fall) that is sent to the cloud service provider. Using such a search token, the cloud service provider can filter the encrypted data for all ciphertexts that match the search token and is able to return the matching ciphertexts to the data owner.

[0025] For practicality, searchable encryption schemes should be efficient and secure. In some examples, the search operation should be possible in sublinear search time, which can be achieved by suitably encrypting the search index. To protect the privacy of the outsourced data, the encrypted data and the encrypted search index should leak as little information as possible. For example, the ciphertexts that are never searched should not reveal any information.

[0026] In view of this, implementations of the present disclosure provide an encrypted search scheme for privacy-protected range queries on encrypted data. According to the present disclosure, and as described in further detail herein, implementations enable a cloud service provider to compare range tokens that have been queried in previous search requests. This enables the cloud service provider to reduce the average search time of its range queries. While the initial search time for a range query is linear in the number of ciphertexts (e.g., files) of the index, subsequent queries can be sped up. For example: in the first, initial search, the cloud service provider learns the result set for the range query; if the range query in the second search request is a sub-range of the range that has already been queried in the first step, then scanning the previously learned result set is sufficient. In this way, the search space of the second query is reduced, which results in a faster search operation. Moreover, as described herein, using this approach for each new range query, the cloud service provider can build and refine an encrypted search index using an interactive protocol between the client and the server. Thus, the encrypted search scheme of the present disclosure enables an average reduced search time. Moreover, the ciphertexts that do not fall in any query range are not included in any access pattern. Thus, using a suitable encryption scheme, the unqueried ciphertexts do not leak any information.

[0027] In some implementations, the properties of the encrypted search scheme for privacy-protected range queries can be summarized in terms of security, efficiency, and modularity. Security is formalized using a simulation-based approach in a non-adaptive model. In some examples, a leakage function is provided that gives an upper bound on the information leaked by the encrypted search scheme of the present disclosure. In terms of efficiency, the encrypted search scheme has amortized polylogarithmic running time. This is achieved by interactively building the search index. In terms of modularity, the encrypted search scheme is built on a black-box interface of functional encryption.

[0028] To further provide context for the implementations of the present disclosure, governing definitions are provided. In some examples, denotes the set of natural numbers, [i, j] denotes i ≤ j and is the set of integers starting at i and including j (i.e., the set {i,..., j}). A (possibly probabilistic) algorithm whose output z is written as: In some examples, λ denotes a security parameter. A function f is said to be negligible if for every positive polynomial p(·) there exists x0such that f(x) < 1 / p(x) for all x > x0. is called negligible (in x). Given a matrix M, M[i] denotes the ith row, and M[i][j] denotes the jth element in the ith row. A message m is provided as a tuple (f, v), where f is an arbitrary file (e.g., a document, an image), and a value point v for indexing. In some examples, each message m has a unique identifier ID(m), and each file f can be accessed by a given associated identifier ID(m). For a range Q = [q(s), q(e)], ID Q can be defined as the set of file identifiers indexed at value v, where v e Q (i.e., ID Q = {ID(m) : m = (f, v) with q (s) ≤ v ≤ q (e)}.

[0029] In some implementations, a secure and efficient range query scheme consists of the following (partially probabilistic) polynomial algorithms: SRQ-Setup, SRQ-Enc, SRQ-IndexFile, SRQ-Token, SRQ-Search. In an initial step, a data owner creates public parameters and a master key for a desired value domain by running SRQ-Setup. In some examples, the public parameters are known to the parties. In a next step, a collection of messages (in the clear) is encrypted by running SRQ-Enc, and indexed at given value points. In some examples, each value point depends on the value domain used in the initial setup. The result of these steps includes an encrypted index and a set of ciphertexts, which are transferred to a file server side (e.g., a cloud service provider) using SRQ-IndexFile. The data owner (who possesses the master key mk) is able to create a range token (for a respective range query) by invoking SRQ-Token. The range token can be sent to the server side so that a respective range query can be run on the encrypted data. In some examples, given a range token, the server can run SRQ-Search to filter all (encrypted and indexed) messages associated with value points falling within the desired range.

[0030] Definition 1: A scheme SRQ for secure range queries includes the following (probabilistic) polynomial time algorithms:

[0031] mk ← SRQ-Setup(l λ , [0, D - 1]): is a probabilistic algorithm that takes as input a security parameter l λ and a value domain [0, D - 1], and outputs a master key mk.

[0032] c ← SRQ-Enc(mk, m): is a probabilistic algorithm that takes as input a master key mk and a message m. The message m is a tuple m = (f, v) of a file f and a value point v e [0, D - 1]. The output is a ciphertext c.

[0033] γ', C' <- SRQ-IndexFile(ID(m), c, γ, C): is a deterministic algorithm that takes the identifier ID(m), the ciphertext c, the search index γ, and the set of ciphertexts C as input. It outputs the updated secure search index γ' and the updated set of ciphertexts C'.

[0034] τ Q <- SRQ-Token(mk, Q): is a probabilistic algorithm that takes the master key mk and the range Q as input and outputs the search token τ for the range Q Q .

[0035] ID Q <- SRQ-Search(τ Q , γ): is a deterministic algorithm that takes the range token τ for the range Q Q and the search index γ as input and outputs the ID Q .

[0036] In some implementations, an order-preserving encryption scheme can be used. For example:

[0037] OPE = (OPE-Setup, OPE-Enc, OPE-Dec), where

[0038]

[0039] This example OPE scheme can be used to establish an encrypted search index. For example, at each message m = (f, v), the value point v is encrypted using OPE-Enc and associated with the message identifier ID(m). All index entries with the form c i = (OPE-Enc(v i ), ID(m i )) are sorted according to their first element. For a search query on the range [q (s) , q (e) ], the range token is realized as the tuple τ Q = (OPE-Enc(q (s) ), OPE-Enc(q (e) )). Given τ Q to a server storing the search index, the server is able to obtain the set {(OPE-Enc(v i ), ID(m i )): OPE-Enc(q (s) ≤ OPE-Emc(v i ) ≤ OPE-Enc(q (e) in logarithmic time by running a binary search.However, even points that are indexed but not queried can be compared to all other indexed (queried and not queried) points.

[0040] In another example method of hiding the order-related information of all points that are not queried before hiding, a range predicate encryption (RPE) can be used. An example RPE scheme includes the following example algorithms:

[0041] k←RPE-Setup(1 λ , [0, D-1]) outputs a key k on input a security parameter 1 λ and a domain range [0, D-1].

[0042] c←RPE-Enc(k, v) outputs a ciphertext c on input a key k and an attribute value v.

[0043] tk Q ←RPE-Token(k, Q) outputs a range token tk Q on input a key k and a range Q.

[0044] {0, 1}←RPE-Dec(tk Q , c) outputs 1 if v e Q, and 0 otherwise, on input a range token tk Q and a ciphertext c = RPE-Enc(k, v).

[0045] Given the example RPE scheme, a scheme for range queries can be provided with linear running time (with respect to the number of index elements). That is, all attributes encrypted using RPE-ENC are added to a point list For each range query for a range Q, a token τ Q is created by the data owner holding the master key using RPE-Token, which is sent to the server. The server can provide the ID Q by adding all entries c e P with RPE-Dec(tk Q , c) = 1. In some examples, all entries are checked. Thus, the running time is linear with respect to the number of all index files (ciphertexts).

[0046] In some implementations, the index is searched in a way that improves the average search speed (e.g., all index messages are arranged). Furthermore, the index structure is designed to leak as little information as possible. For all ciphertexts, the following example security game can be used to define security.

[0047] Definition 2: RP is a scheme for range predicate encryption. The following security game between an attacker and a challenger includes:

[0048] Initialization: Submit two values that it wishes to be challenged on

[0049] Setup: The challenger generates a secret key MK by running RPE-Setup(1 λ , [0, D - 1]).

[0050] Query Phase 1: Adaptively issue queries, where each query is one of two types:

[0051] (a) Token Query: On the ith query, the prover submits a value v = (vi, vi+1,..., vj) that satisfies the condition or (v0∈ Q i ∧ v1∈ Q i ) for some i < j < D. The challenger generates a token by running and outputs

[0052] (b) Ciphertext Query: On the ith query, the prover submits a value point z = (z0, z1,..., zj) for some j < D. i The challenger encrypts the value point z by running RPE-Enc(mk, z i ) and returns the output. i

[0053] Challenge: The challenger flips a coin b← {0, 1} and outputs RPE-Enc(mk, v b ).

[0054] Query Phase 2: Adaptively issue further queries with the same restrictions as in Query Phase 1.

[0055] Guess: Output a guess b' for b.

[0056] In some examples, the RPE has selective secure ciphertext privacy if for all probabilistic polynomial time attackers

[0057] where ε is negligible in λ

[0058] holds, then the RPE has selective secure ciphertext privacy.

[0059] Definition 3: An RPE is a scheme for range predicate encryption. The following exemplary security game between an attacker and a challenger includes:

[0060] Initialization: Submit two values that it wishes to be challenged on ​

[0061] Setup: The challenger generates a secret key mk by running RPE-Setup(l λ , [0, D - 1]).

[0062] Query Phase 1: Adaptively issue queries, where each query is one of two types:

[0063] (a) Token Query: At the i-th query, submit The challenger generates a token and outputs by running

[0064] (b) Ciphertext Query: At the i-th query, submit a value point z i such that z i ∈ R0∧ z i ∈ R1or The challenger encrypts the value point z i and returns the output by running RPE-Enc(mk, z i ).

[0065] Challenge: The challenger flips a coin b←{0,1} and outputs RPE-Token(mk, R b ).

[0066] Query Phase 2: Adaptively further issue queries with the same restrictions as in Query Phase 1.

[0067] Guess: Output a guess b' for b.

[0068] In some examples, RPE has selective secure plaintext privacy if for all probabilistic polynomial time attackers running the secure game

[0069] where ε is negligible in λ.

[0070] holds, then RPE has selective secure plaintext privacy.

[0071] Given such an RPE scheme, a scheme for range queries with linear running time (relative to the number of indexed elements) can be provided. That is, all attributes encrypted using RPE-Enc are added to a list of points For each range query over a range Q, a token τ Q is created by the data owner holding the master key using RPE-Token. Given this token, the server can create a range query over the range Q by adding all the points with RPE-Dec(tk Qc) = 1, create ID Q Since all entries are checked, the running time is linear with respect to the number of all index files (ciphertexts).

[0072] In some examples, to improve the average search speed, all index messages are arranged in a suitable index structure. Furthermore, the index structure is designed to leak as little information as possible. Given a secure and efficient range query scheme SRQ, the encryption operations are extended in such a way that it is possible to encrypt the file f indexed at value point v. As a result, the secure game for plaintext privacy is slightly modified to provide the following:

[0073] Definition 4: SRQ scheme is a secure and efficient range query scheme. The exemplary security game between the following attacker and the challenger includes:

[0074] Initialization: Submit two values v0, v1∈[0, D-1] that it wishes to be challenged.

[0075] Setup: The challenger generates a secret key mk by running SRQ-Setup(1 λ , [0, D-1]).

[0076] Query phase 1: Adaptively issue queries, where each query is one of two types:

[0077] (a) Token query: At the i-th query, submit a token that satisfies the condition or (v0∈Q i ∧ v1∈Q i ) both. The challenger generates a token by running and outputs

[0078] (b) Ciphertext query: At the i-th query, submit a value point z i and a file f i . The challenger encrypts f i indexed at z i by running SRQ-Enc(mk, (f i , z i )) and returns the output.

[0079] Challenge: Submit two files f0, f1 of the same size. The challenger flips a random coin b←{0, 1} and outputs SRQ-Enc(mk, (f b , v b )).

[0080] Query phase 2: Adaptively further issue queries with the same restrictions as in query phase 1.

[0081] Guess: Output a guess b' for b.

[0082] In some examples, if for all probabilistic polynomial time adversaries running the secure game

[0083] where ε is negligible in λ.

[0084] holds, then RPE has selective secure clear private.

[0085] With respect to predicate privacy, implementations of the present disclosure use properties given directly from RPE predicate privacy. Using these definitions and results of properties, security definitions for the SRQ scheme of the present disclosure can be provided. In some examples, security properties are defined using definitions based on leakage.

[0086] Definition 5: Given a scheme for secure range queries SRQ = (SR-Setup, SR-En, SRQ-IndexFile, SRQ-Token, SR-Search) and a security parameter λ The following adversary Simulator and leakage function Probability experiment:

[0087] The challenger runs SRQ-Setup(1 λ , [0, D-1]) to generate a master key and an empty search index γ. First the adversary sends an f-tuple of messages M = (m1,..., mf f ) (where m i = (f i , v i ), v i ∈ [0, D-1] and for all i ∈ {0,..., f), f i is a file) and a q-tuple of queries Q = {Q1,..., Qq q ) (where for all i ∈ {1,..., q}, Q ) to the challenger. The challenger sends an f-tuple C = (SRQ-Enc(mk, m1),..., SRQ-Enc(mk, mf f )) and a search token TK = (SRQ-Token(mk, Q1),..., (SRQ-Token(mk, Qq q) of the q-tuple together to the adversary. Finally, Return the bit b output by the experiment.

[0088] The simulator sets up the internal environment for the domain [0, D - 1]. The adversary sends a message M = (m1,..., m f ) of f-tuples (where m i = (f i , v i ), v i ∈ [0, D - 1], and for all i ∈ {0,..., f}, f i is the file) and a q-tuple Q = (Q1,..., Q q ) (for all i ∈ {1,..., q}, ) and assumes that the simulator leaks appropriately for the message tuples and for the query tuples The simulator returns the f-tuple and the q-tuple to the adversary. Finally, Return the bit b output by the experiment.

[0089] In some examples, if there exists a probabilistic polynomial-time simulator such that for all probabilistic polynomial-time algorithms , the advantage

[0090]

[0091] is negligible in λ, then the SRQ scheme is secure against non-adaptive range selection attacks. -secure against non-adaptive range selection attacks.

[0092] According to implementations of the present disclosure, a server uses information obtained from previous range queries to reduce the number of files for performing future queries. In this way, search time is reduced. For further discussion, it can be assumed that this server (cloud service provider) learns the range token τ Q and its result set ID Q after performing a scan over the entire set of indexed messages. Given a new range token τ R with , scanning the result set ID Q (i.e., a subset of the entire set of indexed values) is sufficient to obtain ID R . Furthermore, the server can compute the relative complement of R in Q (i.e., ID Q / Rthe result set of the query. This information can also be used to respond to queries more quickly in the future.

[0093] In some implementations, to improve average search speed, all indexed messages are arranged in a search index in a suitable way, and the search index is efficiently updatable. Moreover, the structure of the search index is designed to leak as little information as possible. According to implementations of the present disclosure, the search index is organized into multiple components:

[0094] 1. A list of trees, denoted by , is a list of search trees, each covering a contiguous and searched range. This enables the server to answer range queries for subranges of already queried ranges in logarithmic time.

[0095] 2. A list of points, denoted by , is a linear list of all indexed points. This enables the server to answer all range queries that are neither a subrange of a queried range nor searched before by checking all elements that fall within the query range have linear running time.

[0096] In the list of trees , an encrypted (one-dimensional) R-tree is stored. In some examples, the R-tree Γ completely covers the contiguous range. Each internal node contains up to t entries. Figure 2 An example tree 200 is depicted, where t = 3, the covered range is [1-31] and the index information A,..., H. In some examples, each entry has the form (p, R), where R is a range and p is a pointer to another node (either an internal node or a leaf) that covers that range. Accordingly, the pointer p points to a subtree. In some examples, Γ[p] denotes the subtree of Γ pointed to by p. For simplicity, if the covered range of Γ is a subset of S, then for a range S, and vice versa

[0097] Moreover, for any two entries (pi, Ri) and (p2, R2) of the same node, (i.e., the ranges in one node do not overlap) holds. For each entry (p, R), the subtree rooted at the node pointed to by p covers the range R (i.e., Γ[p] = R). Moreover, all leaves consist of up to t entries, and each entry has the form (obj, R), where R is a range and obj is a pointer to a list of all files indexed at value v e R (i.e., obj points to IDs R ) at value v e R). Given a range Q = [q (s) , q (e) ], the server holds a superset of the range Q (i.e., Q e Γ) and a list of all points in Γ that fall within Q. The server answers the query by returning the union of the list of points and the list of IDs pointed to by the list of points. The server of the tree Γ can compute the ID of a node in logarithmic time (with respect to the number of nodes) by using Algorithm 1 Q :

[0098]

[0099] Algorithm 1 : Tree search for range query (SearchForRange)

[0100] In some examples, the only two operations needed for such a range query are as follows: first, check whether the start point q (s) and end point q (e) of Q fall into the range R (i.e., if R and Q intersect), and second, check whether the range Q is a subrange of R. In some examples, this functionality is provided by the modified RPE scheme. Thus, a range query can also be answered by the search tree that includes the ranges encrypted by the modified RPE scheme. In some examples, the range token of the range Q created by the RPE-Token must be augmented by the encryption restriction points (i.e., the start point and the end point) encrypted using the RPE-Enc.

[0101] In some examples, to add a new value to an existing tree, the correct leaf and entry must be identified. That is, the entry that contains the range in which the new value falls. In some examples, this can be done by using Algorithm 2:

[0102]

[0103] Algorithm 2 : Search entry for a specific value (SearchEntry)

[0104] In some implementations, with the encrypted index structure, the SRQ scheme can be defined as follows. Given an RPE scheme including algorithms RPE-Setup, RPE-Enc, RPE-Token, RPE-Dec, an (IND-CPA) secure encryption scheme Π1 = (Gen IND-C , Enc IND-C , Dec IND-CPA ) and a second encryption scheme Π2 = (Gen, Enc, Dec), the SRQ scheme can be provided as follows:

[0105] mk, γ ← SRQ-Setup(1 λ , [0, D-1]), using k1 ← RPE-Setup(1 λ , [0, D-1]) and k2 ← Gen IND-CPA (1 λ ) and k3 ← Gen(1 λ) ; set mk = (k1, k2, k3). Output the master key mk.

[0106] c <- SRQ-Enc(mk, m) : On input master key mk = (k1, k2, k3) and message m = (f, v), perform the following operations:

[0107] - encrypt c1 <- RPE-Enc(k1, v).

[0108] - encrypt c2 <- Enc IND - C(k2, f).

[0109] Output c = (c1, c2).

[0110] γ, C <- SRQ-IndexFile((ID(m i ), c i ) i e [1, n]) : Initialize empty search index γ containing empty list of points , empty tree list and empty set of ciphertexts C. For each i e [1, n], parse c i = (c i1 , c i2 ) and add (ID(m i ), c i2 ) to C. Furthermore, add the tuple (ID(m i ), c i1 ) to the list of points Output C and γ.

[0111] t Q <- SRQ-Token(mk, Q) : On input master key mk = (k1, k2, k3) and range Q = [q (s) , q (e) ], use RPE-Enc to encrypt and Furthermore, create the range token tk Q = RPE-Token(k1, Q). In addition, encrypt Q to c Q = Enc(k3, Q) to enable the client to decrypt the range token. Output as the range token.

[0112] ID Q <- SRQ-Search(t Q , γ), for a range Q and index γ, given the range token check all index trees in if they cover the queried values completely or partially. Initialize the list of trees that fall completely in the query range Q Then the boundary points and are executed the following:

[0113] (a) Check if there is a tree including and If so, obtain ID Q by calling Algorithm 1 and set Γ (s) = Γ (e) = Γ i

[0114] (b) Otherwise, check if there is a tree partially covering the query range. In more detail, set the tree using Otherwise Γ (s) = ⊥. Do the same for and Γ (e)

[0115] (c) Otherwise set Γ (s) = Γ (e) = ⊥.

[0116] If case 1 does not occur, scan all the ciphertexts and store in the result set ID Q if and only if r i = 1. To maintain logarithmic search time for future queries that are sub-ranges of ranges that have already been queried, call the interactive procedure (as described above). Output ID Q as the result.

[0117] Using the above algorithm, one can outsource encrypted data and support range queries. For example, in the initial step, the data owner creates the master key and defines the possible value domain by calling SRQ-Setup. The data owner encrypts the files by calling SRQ-Enc, where each file is associated with a value point and indexed at this point. The encrypted files are transferred to the server and added to the search index by calling SRQ-IndexFile. In some examples, the files (e.g., encrypted files) can be deleted at the client. The data owner, who holds the master key, can create a range search token by calling SRQ-Token. In some examples, the server can compare different range tokens without knowing the master key. More specifically, the server can check the following example properties: and

[0118] 1. R and Q intersect if or if​​​​​

[0119] 2. R is a subrange of Q, if and

[0120] 3. The ranges are equal if R is a subrange of Q and Q is a subrange of R.

[0121] Figure 3 It describes the example relationships between the ranges.

[0122] In some implementations, the receiving range Q = [q (s) q (e) ] range token The server can search for all files associated with values ​​falling within the range Q using SRQ-Search. In the initial steps, the server searches each tree... Check whether the tree covers a subrange of Q or intersects with the range Q. For example, it contains any tree Γ. i All entries in the root node Compare with the range Q, where if all ranges If Γ is a subrange of Q, then i Covering sub-ranges; and if at least one range R exists j If it intersects with the range Q, then Γ i Intersects with Q. Create a list of all trees that cover the subrange of Q. In some examples, a partial intersection of the index search tree and the query range is calculated. In some examples, Γ (s) It includes coverage (Right now Make ) scope The number. If no such tree is found, then set Γ. (s) =⊥. For the end value of encryption. Executing the same will result in a tree Otherwise Γ (e) =⊥.

[0123] For a given range token τ Q Multiple scenarios are possible. Each scenario leads to a different behavior of SQR-UpdateIndex as described in this article. Example scenarios include:

[0124] 1. A tree covers the complete query range Q, that is, Γ (s) =Γ (e) ,so If this is the case, then the server does not need the entire list of points. Perform a search, but search by Γ(s) The indexed value points are sufficient. This is done by Algorithm 1 described above. SQR-UpdateIndex refines the index's ranges by using the new information obtained from the current range query.

[0125] 2. The current range query and the previous query range have no intersection, so, Γ (s) = Γ (e) = 0 and If this is the case, the server knows nothing about the current range query. As a result, the server has to scan all the points searched in the point list SQR-UpdateIndex creates a new search tree which is added to the tree list of the covering range query

[0126] 3. The query range is only partially covered by the indexed search trees. Or Γ (s) = 0 or Γ (e) = 0. If this is the case, the server cannot know whether there are values in the point list that fall in Q but are not covered by Γ (s) resp. Γ (e) . As a result, the server scans all the points indexed in the point list SQR-UpdateIndex extends one tree of the partially covering range query (i.e., the tree that is not 0).

[0127] 4. The values fall in different trees, i.e., c (s) ∈ Γ (s) , c (e) ∈ Γ (e) where Γ (s) = Γ (e) . If this is the case, the server cannot be sure that there is no non-indexed gap between the two trees (i.e., there can be values in that fall neither in Γ (s) nor in Γ (e) but in the range Q). As a result, the server scans all the points indexed in the point list SQR-UpdateIndex merges the two trees Γ (s) and Γ (e) since the gap can be closed by the current range query.

[0128] From a high-level perspective, the new range token contains some new information for the server, such as the result set ID Q of this new range token. This newly obtained information is implicit in the search and access patterns and can be used by the server to update the encrypted search index for future queries. As described above, given a Four different updates can occur, in which the server needs to either refine a tree, create a new tree, extend a tree, or merge trees. In addition, trees that are completely covered by Q (i.e., contained in are composed using a combination of tree extensions and tree merges.

[0129] Since operations can necessitate the creation of new scope tokens for encrypted trees, and such creation is only possible when there is a master key, these updates are interactive protocols between the server and the data owner. In the continuing discussion, operations performed at the client are denoted as @C. This can be necessary because operations must be performed on plaintext, or it is necessary to create new scope tokens.

[0130] Because operations add new entries to one or more existing trees, these operations can include a balancing step as discussed in Algorithm 3 herein to ensure that each node is later smaller than the threshold T. Again, rebalancing trees forces the creation of new scope tokens, so it is also provided as an interactive protocol.

[0131]

[0132] Algorithm 3: Rebalance Tree

[0133] For refining a tree, the server sends the new scope token and the previous scope tokens that intersect with this new token to the data owner to request assistance. The data owner decrypts the scope tokens, creates (at most) four disjoint, but more refined, scopes, and sends back the tokens generated by SRQ- Token. The server can replace the old scope tokens with the new, more refined tokens, and the indexed file list is split according to these new tokens. Algorithm 4 provides a formal description. Because this replacement increases the number of entries in the nodes, the server runs Rebalance Tree.

[0134]

[0135] Algorithm 4: Refine Tree

[0136] In some implementations, if Γ (s) = Γ (e) = 0 and is empty, the server creates a new tree. In some examples, the server creates a new encrypted tree Γ with entries and index entry ID Q . This tree Γ is added to the list of trees

[0137] In some implementations, if the new range token intersects with the tree portion (i.e., the range token intersects with the tree), but at least one limit point of the new query's range does not intersect, then the tree is extended. In some examples, extending the tree is initiated by the server sending the newly learned range token and the root node to the data owner. The data owner decrypts all ranges to reconstruct the entire range currently covered by this tree. New range tokens for the gaps between the range covered by the tree and the boundary points of the new range token that fall outside the tree's range are created and added to the tree's leaves. In addition, the tree's internal nodes (up to the root) are updated. That is, the index range of all internal nodes is replaced by the extended version. Algorithm 5 provides a formal description. In some examples, because at least one leaf gets a new entry, the resulting tree is rebalanced after the tree extension.

[0138]

[0139] Algorithm 5: ExtendTree

[0140] In some implementations, if they both intersect with the new query range, then the two trees are merged. In some examples, there should be no value gaps between the two trees. In some implementations, the end point covered by one tree is directly followed by the start point covered by the other tree. This can be achieved by using tree extension as discussed above. In some examples, to merge the trees in logarithmic time, the trees In some implementations, if they both intersect with the new query range, then the two trees are merged. In some examples, there should be no value gaps between the two trees. In some implementations, the end point covered by one tree is directly followed by the start point covered by the other tree. This can be achieved by using tree extension as discussed above. In some examples, to merge the trees in logarithmic time, the trees

[0141]

[0142] Algorithm 6: MergeTrees

[0143] In some implementations, if the new query range token has been queried, then the tree extension and tree merge can be combined. In some examples, all the roots, Γ (s) , Γ (e) and the newly queried range token τ Q are sent to the client. The client decrypts all the roots and gets the ranges R i covered by Γ i = [r i (s) , r i (e) ], in their range start points r i (s)Ordering. The client chooses two trees Γ j to be merged j+1 In some examples, it can be assumed that Γ j has the greater height. Thus, Γ j is extended to cover Γ Next, Γ j and Γ j+1 can be merged using algorithm 6, and the number of distinct trees is reduced by one. This is repeated until there is exactly one search tree covering the entire range being queried.

[0144] Implementations of the present disclosure are described in more detail herein with reference to example runtimes (e.g., runs). At the beginning of an example runtime, it is assumed that no multiple query ranges have occurred so far. As a result, each token contains new information that the server can use to update the index γ. Given a universe of D elements and n index items, there are different contiguous ranges that can be queried. In some examples, after D 2 different queries, all possible ranges have been queried and γ includes exactly one tree that contains all possible ranges.

[0145] In this state, any repeated range query can be answered in logarithmic time. However, repeated queries can cause problems assuming that the search index γ contains exactly one tree before the repeated queries. In addition, these repeated queries do not contain new information, so the server cannot update the index γ. As a result, there is a search pattern that results in linear search time: first, O(n) different, non-contiguous ranges are queried and indexed (e.g., n different queries - each of size 1). Now, these ranges are repeatedly queried - on average, half of all index queries are examined before an answer is provided.

[0146] According to implementations of the present disclosure, a cache is used for ranges that have already been queried. In this way, search time is reduced in such cases. In some examples, using a hash table keyed by a deterministic range identifier (e.g., Π2= (Gen, Enc, Dec) is a deterministic encryption that is part of each search token), search time for repeated range queries is reduced to constant time O(1).

[0147] The runtime of a search operation is the sum of the actual search time t s and the update time t u The height of a tree is bounded by log(D) and the size of an operation on a predicate-encrypted ciphertext is also O(log(D)). Thus, merging two trees, extending a tree, refining a tree, or rebalancing a tree can be done in O(log2 (D)) complete, and r trees can be in O(r log 2 (D)) merge. Moreover, because any update operation adds at least one new boundary element, there can be at most n trees. As a result, the expected update time is bounded by t u = O(n log 2 (D)).

[0148] In some implementations, the search time depends on the new query range Q (i.e., if the new query range Q is completely covered by exactly one tree). The probability of such an event is denoted by If this is the case, the search can be performed in O(log 2 (D)), because searching one tree is enough to learn the result set. Otherwise, the entire point list is scanned and possibly updated, resulting in a search time of O(n log 2 (D)). As a result, the expected search time can be provided as:

[0149]

[0150] In some examples, at any time when the range is not completely covered by a single tree, at least one element from D is added to the search tree. As a result, the size of the set Γ i is increased by at least 1. Thus, at most n search complexities of O(n log 2 (D) are performed. The maximum total time spent on these searches is n n log 2 (D). In some examples, this event can be amortized by the event In some examples, x is the total number of searches until the amortization occurs, where:

[0151]

[0152] According to implementations of the present disclosure, after n 2 searches, on average, a polylogarithmic search time can be achieved.

[0153] The security of the SRQ scheme of the present disclosure is described in detail with respect to the security of encrypting files using SRQ-Enc, and the security of tokenized queries using SRQ-Token. The following example theorems are provided:

[0154] Theorem 1: If the scheme RPE = (RPE-Setup, RPE-Enc, RPE-Tok, RPE-Dec) used has selectively protected the plaintext privacy, and Π1 = (Gen IND-CPA , Enc IND-CPA , Dec IND-CPAIf ) is an IND-CPA security encryption scheme, then the SRQ scheme of this invention has selectively protected the privacy of plaintext.

[0155] Proof: The above-mentioned safe game (Definition 4) has been modified. To display the original game and the modified game The computation is indistinguishable. The modified game is as follows: the challenger does not perform the only step as in the original game, which is the challenge step. Instead, in the modified safe game, the challenger responds with c = (c1, c2), where c1 = RPE - Enc(mk1, v b )and Provided attacker Used in and Distinguisors between Leaking IND-CPA security. Obtain two values ​​v0 and v1 and create a key mk1 = ROE-Setup(1 λ All token queries for [0, D-1] are performed by Answer directly using RPE-Token and mk1. For all encrypted queries (z) sent by the distinguisher... i f i ), It requires its encrypted oracle to f i c2 is performed (Enc IND-CPA Encryption, create c1 = RPE - Enc(mk1, z) i ), and send c = (c1, c2) to For the challenges (t0, f0) and (t1, f1) sent by the distinguisher, Flip b←{0, 1}, create c1 = RPE-Enc(mk1, t b And submit to Facebook and The challenger in the IND-CPA game flips bit b*←{0,1} and sends it back to c. * If b * =0 then c * =ENc IND-CPA (mk2, f) b And if b * =1 Send (c1, c * )to If b * =0 The view and If b is the same as b * =1 then the view and Thus, due to the IND-CPA of Π, the probability that and can be ignored.

[0156] The attacker can only provide the range predicate on the encrypted plaintext privacy of the RPE scheme used The RPE scheme used wins the game with probability ε. Obtains two values v0, vi output by and creates the key mk2 = Gen IND-CPA (1 λ ). Hopes to be challenged on these values v0, vi and thus outputs them to the challenger and sends the answer. In the query phase, forwards all token queries to its own challenger. For all ciphertext queries (z i , f i ), creates c2 = Enc IND-CPA (mk2, f i ), and asks its own challenger for c1 = RPE-Enc(mk1, z i ), and sends back c = (c1, c2). In the challenge using files f0, f1, asks its own challenger for the challenge (i.e., the challenger flips the coin b * and sends c * = RPE-Enc(mk1, v b ) to creates and sends the tuple to The guess b output by is also returned by It is clear that the probability of winning the range predicate game is the same as winning , which can be ignored. Thus, the advantage of winning can also be ignored.

[0157] Before providing a security proof value according to Definition 5, the example leakage function is defined as follows:

[0158]

[0159]

[0160] where RR(Q) is a q x q range relation matrix, each element of which is in the set Here, the element in the ith row and jth column indicates the relation of the ranges Q i and Q j given in queries i and j. denotes no intersection, = denotes that the two ranges are identical, and ∩ denotes an intersection but no range is a sub-range of the other. denotes that the range Q i is a subset of Q j but has no common bound point, denotes a subset relation with one common bound point, and the inverse denotes that the range Q i is a superset of Q j , i.e., if is in position (i, j), then is in position (j, i).

[0161] In Definition 4 above, the challenger accepts only challenges v0, vi that both occur in the same subset of access patterns. For example, if the file f i indexed under v i is in then, for i e {0, 1} and all token queries, f 1-i indexed under v 1-i is also in . Otherwise, it would be trivial for the attacker to win the security game.

[0162] In some examples, these restrictions are removed by giving the simulator access to this information in the form of access patterns and range relation matrices. This can be used to show the security of the running of a real protocol, where the implementation of the restrictions of the security game cannot be guaranteed. On the other hand, given two sequences of range tokens with the same range relation matrix (for their ranges), no attacker can distinguish between the sequences of range tokens.

[0163] Theorem 2: Given an SRQ with selective security of the plaintext and selective security of the predicate built on an RPE scheme, a domain [0, D - 1] with and RR(Q) = RR(R), two sequences of queries (Q1,..., Q n ) = Q = R = (R1,..., R n ), for any mk < SRQ-Se(1 λ , [0, D - 1]), TK Q= (SRQ-Toke(mk, q1),..., SRQ-Toke(mk, q n )) and TK R = (SRQ-Toke(mk, r1),..., SRQ-Toke(mk, r n )) are provided as:

[0164]

[0165] For any distinguisher the probability of success is negligible.

[0166] Proof: Using ε ∏ to denote the probability of an attacker breaking the IND-CPA secure encryption scheme used, ε1 to denote the probability of an attacker winning the RPE plaintext privacy game, and ε2 as the probability of an attacker winning the RPE predicate privacy game. Given negligible ε Π , ε1 and ε2, the range can be extended, shrunk and moved such that any attacker has negligible probability of distinguishing the token τ Q from the token where is an extended, shrunk or moved version of Q.

[0167] First, given a range token one can extend the range Q to the range as long as there exists another range R whose token τ R is known. However one can assume that no such range R exists in the first place. A series of games can be provided to show that any attacker has negligible probability of distinguishing the two games.

[0168] In the original token τ Q is given.

[0169] In the new encryption is used in place of c Q . An attacker may have a probability ε ∏ of distinguishing from

[0170] In the new RPE token is used in place of tk Q . Note that, and It still holds true. Therefore, the attacker... It is possible to distinguish them with probability ε2. and

[0171] exist Mobile Encryption q (e) Limitations use replace attacker It is possible to distinguish them with probability ε1. and

[0172] exist Afterwards, a valid token was provided. For new range Put them together, attackers The probability that these tokens can be distinguished is:

[0173]

[0174] As long as there exists a token τ that does not exist R Other known ranges R, where but Shrink range Q to range This can be accomplished in a similar way. In some examples, interchange... and As a result, the attacker Can distinguish token τ Q and tokens used for shrinking the range The probability is:

[0175]

[0176] Combining these techniques, as long as there are no other ranges R, r (s) >q (s) But r (s) <(q) (s) +x)(otherwise, this range R must have been moved before), then the range Q = [q (s) q (e) [Can be moved to a new range] First, expand Q to the range Q′=[q (s) q (e) +x], then shrink Q′ to the range

[0177] Without loss of generality, we can assume With the largest limiting point Extensions for Q itokens to the ranges of R tokens (using the techniques described above). This technique is repeated for all ranges in descending order of their end points, and the sequence of ranges Q is modified to a sequence of extended ranges Q' that have the same end points as R. All ranges in the sequence of extended ranges Q' are contracted to be the same as the sequence of ranges R. As shown previously, the attacker can have a probability of distinguishing each of these extension and contraction modifications, which is negligible. Thus, the combination of many modifications of the polynomial is still negligible.

[0178] Given this theorem, the security of the SRQ scheme of the present disclosure can be more formally defined using the leakage based on Definition 5 provided above.

[0179] Theorem 3: If the SRQ scheme has selective security based on an RPE scheme with selective security predicate privacy, and π1 is an IND-CPA secure encryption scheme, then the SRQ scheme is secure against non-adaptive chosen range attacks.

[0180] Proof: A PPT simulator is provided that can convince any PPT adversary A that the leakage from Definition 5 and The advantage of the experiment is negligible. To this end, the SRQ scheme can be described as using leakage and Setting up the environment and simulating range tokens and ciphertexts

[0181] Setup Environment: Internally run SRQ-Setup(l λ , [0, D-1]) and receive the master key mk.

[0182] Simulate Extract the cluster of ranges that form one large uniform range. Algorithm 7 provides a formal description.

[0183]

[0184] Algorithm 7: Extract cluster of ranges

[0185] In the implementations described herein each cluster is a separate R-tree. For each cluster, simulate ranges that have the same range relation matrix as the actual given range relation matrix RR(Q). In more detail, for each cluster, the simulator Transform the range relation matrix RR(Q) to the solved linear procedure. Each relation is expressed as an inequality. Do this for all clusters. Obtained with Simulation range Now set up This is indistinguishable from Theorem 2. Note that, given a range token... Able to recover the simulated range Because the component includes a plain IND-CPA encrypted value that can be decrypted.

[0186] simulation simulator Create a leaf set L. More specifically, ID is partitioned into a set L consisting of disjoint sets. Q L and ID Q Overwrite the same value. two sets and It was divided into For each simulated leaf L i ∈L, simulator Storage includes L i The indexes for all range queries are used as the result set: Given a simulated set of leaves L, Can simulate ciphertext as follows: Iterate through all tuples (ID(f)) i ), len(f i )))and:

[0187] If there is a simulation with ID(f) i )∈L j L j ∈L, Set randomly selected simulation value points Set now And add tuples arrive or

[0188] Otherwise, there is no simulation with ID(f) i )∈L j leaves L j ∈L, the encrypted file does not match any query range. Then Use random values ​​outside the simulation range: set up Emulator settings And increase arrive

[0189] Due to the IND-CPA security of ∏1, the selective security of plaintext privacy of SRQ, and Theorem 2, Distinguish between C and those generated by S The probability is negligible.

[0190] It is possible from a given leak Simulated range query simulator Able to use these tokens The simulator simulates all update protocols. Because the simulator... Decrypt range token It is possible, so Within the range of simulation Run all update queries on it. Note that these update protocols do not contain new information, but all information has already been provided by [the relevant authority / organization]. and cover.

[0191] Figure 4 Example process 400 is depicted, which can be executed according to an implementation of this disclosure. In some examples, example process 400 may be provided as one or more computer-executable programs running on one or more computing devices. In some implementations, example process 400 is run to perform a range query on encrypted data according to an implementation of this disclosure.

[0192] Receive a range query token (402). For example, a server-side computing device receives a range query token from a client-side computing device. In some examples, the range query token is encrypted. Determine if the tree list is empty (404). In some examples, an encrypted search index stored on the server side includes a tree list and a point list. In some examples, the tree list is empty if it does not contain at least one search tree. In some examples, the search tree is associated with a range that has already been searched (e.g., a range obtained from a previously submitted range query token). In some examples, the point list includes a list of index points of ciphertext that will be searched based on the received query (e.g., a range query). If the tree list is empty, the encrypted query result is determined based on the point list (406). For example, the server-side computing device queries encrypted data (ciphertext) based on the index points provided in the point list to provide an encrypted query result (e.g., a range).

[0193] If the tree list is non-empty, it is determined whether the range query token corresponds to a previously submitted range query token of a search tree in the tree list (410). In some examples, the range query token is determined to correspond to a range query token of a search tree in the tree list if the range query token is a sub-range of, or equal to, a previously submitted range query token of the search tree in the tree list. In some examples, the range query token is determined not to correspond to a range of a search tree in the tree list if the range query token and the previously submitted range query token of the search tree in the tree list are disjoint, the range query token only partially intersects the previously submitted range query token of the search tree in the tree list, or the value of the range query token corresponds to values of multiple search trees in the tree list.

[0194] If it is determined that the range query token does not correspond to a range of a search tree in the tree list, the encrypted query result is determined based on the point list (406). If it is determined that the range query token does not correspond to a range of a search tree in the tree list, the encrypted query result is determined based on the search tree (412). For example, the encrypted query result is based on the value points indexed by the search tree.

[0195] The encrypted search index is updated (414). In some examples, the encrypted search index is updated based on the range query token and the client-server protocol. In some examples, the encrypted search index is updated by adding a search tree to the tree list, refining a search tree (e.g., Algorithm 4), expanding a search tree (e.g., Algorithm 5), merging search trees (e.g., Algorithm 6), and / or rebalancing a search tree (Algorithm 3). The encrypted query result is returned (416). For example, the server-side computing device sends the encrypted query result to the client-side computing device.

[0196] Referring now to Figure 5 A schematic diagram of an example computing system 500 is provided. The system 500 can be used for the described operations associated with the implementations described herein. For example, the system 500 can comprise any or all of the server components discussed herein. The system 500 includes a processor 510, a memory 520, a storage device 530, and an input / output device 540. The components 510, 520, 530, 540 are interconnected using a system bus 550. The processor 510 is capable of processing instructions for execution within the system 500. In one implementation, the processor 510 is a single-threaded processor. In another implementation, the processor 510 is a multi-threaded processor. The processor 510 is capable of processing instructions stored in the memory 520 or on the storage device 530 to display graphical information for a user interface on the input / output device 540.

[0197] Memory 520 stores information within system 500. In one implementation, memory 520 is a computer readable medium. In one implementation, memory 520 is a volatile memory unit. In another implementation, memory 520 is a non-volatile memory unit. Storage 530 can provide mass storage for system 500. In one implementation, storage 530 is a computer readable medium. In various implementations, storage 530 can be a floppy disk device, a hard disk device, an optical disk device, or a tape device. Input / output 540 provides input / output operations for system 500. In one implementation, input / output 540 includes a keyboard and / or pointing device. In another implementation, input / output 540 includes a display unit for displaying graphical user interfaces.

[0198] The described features can be implemented in digital electronic circuitry, or in computer hardware, firmware, software, or in combinations of them. The apparatus can be implemented as a computer program product, i.e., a tangible computer-readable medium having stored thereon the computer program, by a programmable processing device executing the program; and method steps can be performed by a programmable processing device executing the instructions program steps to operate on input data and generate output. The described features can be implemented advantageously in one or more computer programs that are executable on a programmable system including at least one programmable processing device coupled to receive data and instructions from, and to transmit data and instructions to, a data storage system, at least one input device, and at least one output device. A computer program is a set of instructions that can be used directly or indirectly in a computer to perform a certain activity or bring about a certain result. Computer programs can be written in any form of programming language, including compiled or interpreted languages, and they can be deployed in any form, including as a stand-alone program or as a module, component, subroutine, or other unit suitable for use in a computing environment.

[0199] Suitable processors for the execution of a program of instructions include, by way of example, both general and special purpose microprocessors, and the processors of any kind of computer system or other programmable data processing apparatus. Generally, a processor will receive instructions and data from a read-only memory or a random access memory or both. The elements of a computer can include a processor for executing instructions and one or more memory devices for storing instructions and data. Generally, a computer also can include, or be operatively coupled to receive data from or transfer data to, or both, one or more mass storage devices for storing data files; such devices include magnetic disks, such as internal hard disks and removable disks; magneto-optical disks; and optical disks. Storage devices suitable for tangibly embodying computer program instructions and data include all forms of non-volatile memory, including by way of example semiconductor memory devices, such as EPROM, EEPROM, and flash memory devices; magnetic disks such as internal hard disks and removable disks; magneto-optical disks; and CD-ROM and DVD-ROM disks. The processor and the memory can be supplemented by, or incorporated in, ASICs (application-specific integrated circuits).

[0200] To provide for interaction with a user, the features can be implemented on a computer having a display device such as a CRT (cathode ray tube) or LCD (liquid crystal display) monitor for displaying information to the user and a keyboard and a pointing device such as a mouse or a trackball by which the user can provide input to the computer.

[0201] The features can be implemented in a computer system that includes a back- end component, such as a data server, or that includes a middleware component, such as an application server or an Internet server, or that includes a front-end component, such as a client computer having a graphical user interface or an Internet browser, or any combination of them. The components of the system can be connected by any form or medium of digital data communication such as a communication network. Examples of communication networks include a LAN, a WAN, and the computers and networks forming the Internet.

[0202] The computer system can include clients and servers. A client and server are generally remote from each other and typically interact through a network, such as the described one. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other.

[0203] Also, the logic flows depicted in the figures do not require the particular order shown, or sequential order, to achieve desirable results. In addition, other steps can be provided, or steps can be eliminated, from the described flow, and other components can be added to, or removed from, the described systems. Accordingly, other implementations are within the scope of the following claims.

[0204] Many implementations of the disclosure have been described. However, it will be understood that various modifications can be made without departing from the spirit and scope of the disclosure. Therefore, other implementations are within the scope of the following claims.

Claims

1. A computer-implemented method for performing range queries on encrypted data, the method being executed by a server-side computing device, and comprising: The server-side computing device receives the range query token from the client-side computing device. The server-side computing device determines one or more of the following: whether the tree list of the encrypted search index is empty, and whether the range of the range query token intersects with the range of at least one tree in the tree list, the at least one tree covering the range that has been searched, the encrypted search index including a tree list and a point list, the point list including one or more pointers, each pointer pointing to a node of a subtree within the encrypted search index and one of the query result sets; The server-side computing device receives an encrypted query result based on a search tree if the tree list is not empty and the range of the range query token is at least one subrange of the range that the tree list is responsible for; and if the tree list is empty or the range of the range query token is not at least one subrange of the range that the tree list is responsible for, it receives a pointer to a point list, wherein the tree list includes at least one search tree based on the previously received range query token. as well as In response to receiving the range query token, the server-side computing device updates the encrypted search index based on the range query token to change the tree list to indicate that the range of the range query token has been searched, and one of the ranges of at least one index. The update includes performing a client-server protocol that includes actions performed by the server-side computing device and actions performed by the client-side computing device on plaintext data provided by encrypted data received from the server-side computing device, and using a master key held by the client-side computing device.

2. The method as described in claim 1, wherein, Updating the encrypted search index includes refining the search tree of the tree list based at least in part on sending a range query token and a previously received range query token to the client computing device, and receiving a refined range token from the client computing device, the encrypted search index being updated based on the refined range token.

3. The method as described in claim 1, wherein, Updating the encrypted search index includes expanding the search tree of the tree list to the client computing device, at least in part, based on the root node of the search tree and the previously received queries corresponding to the search tree, to provide an expanded search tree, thereby providing a new range query token corresponding to the expanded search tree.

4. The method of claim 1, wherein, Updating the encrypted search index includes, at least in part, sending the corresponding root nodes of the plurality of search trees to the client computing device, merging the plurality of search trees in the tree list to provide a merged search tree, and receiving a token corresponding to the revision of the merged search tree.

5. The method of claim 4, wherein, The multiple trees respond to determining that there are no value gaps between the multiple trees and merge them.

6. The method of claim 1, further comprising receiving an encrypted search index and ciphertext from the client computing device.

7. A non-transitory computer-readable storage medium coupled to one or more processors and having stored thereon, which, when executed by the one or more processors, causes the one or more processors to execute instructions for performing a range query on encrypted data, the operation comprising: The server-side computing device receives the range query token from the client-side computing device. The server-side computing device determines one or more of the following: whether the tree list of the encrypted search index is empty, and whether the range of the range query token intersects with the range of at least one tree in the tree list, the at least one tree covering the range that has been searched, the encrypted search index including a tree list and a point list, the point list including one or more pointers, each pointer pointing to a node of a subtree within the encrypted search index and one of the query result sets; The server-side computing device receives an encrypted query result based on a search tree if the tree list is not empty and the range of the range query token is at least one subrange of the range that the tree list is responsible for; and receives a pointer to a point list if the tree list is empty or the range of the range query token is not at least one subrange of the range that the tree list is responsible for, wherein the tree list includes at least one search tree based on the previously received range query token. as well as In response to receiving the range query token, the server-side computing device updates the encrypted search index based on the range query token to change the tree list to indicate that the range of the range query token has been searched, and one of the ranges of at least one index. The update includes performing a client-server protocol that includes actions performed by the server-side computing device and actions performed by the client-side computing device on plaintext data provided by encrypted data received from the server-side computing device, and using a master key held by the client-side computing device.

8. The computer-readable storage medium of claim 7, wherein, Updating the encrypted search index includes refining the search tree of the tree list based at least in part on sending a range query token and a previously received range query token to the client computing device, and receiving a refined range token from the client computing device, the encrypted search index being updated based on the refined range token.

9. The computer-readable storage medium of claim 7, wherein, Updating the encrypted search index includes at least in part expanding the search tree of the tree list to provide an expanded search tree based on the root node of the search tree and the previously received query corresponding to the search tree to the client computing device, thereby providing a new range query token corresponding to the expanded search tree.

10. The computer-readable storage medium of claim 7, wherein, Updating the encrypted search index includes, at least in part, sending the corresponding root nodes of the plurality of search trees to the client computing device, merging the plurality of search trees in the tree list to provide a merged search tree, and receiving a token corresponding to the revision of the merged search tree.

11. The computer-readable storage medium of claim 10, wherein, The multiple trees respond to determining that there are no value gaps between the multiple trees and merge them.

12. The computer-readable storage medium of claim 7, wherein the operation further comprises: Receive encrypted search index and ciphertext from the client computing device.

13. A system for performing range queries on encrypted data, comprising: Server-side computing device; as well as A computer-readable storage medium coupled to a server-side computing device and having instructions stored thereon that, when executed by the server-side computing device, cause the server-side computing device to execute an operation for performing a range query on encrypted data, the operation including: Receive a range query token from the client computing device; Determine one or more of the following: whether the tree list of the encrypted search index is empty, and whether the range of the range query token intersects with the range of at least one tree in the tree list, the at least one tree covering the range that has been searched, the encrypted search index comprising a tree list and a point list, the point list comprising one or more pointers, each pointer pointing to a node of a subtree within the encrypted search index and one of the query result sets; If the tree list is not empty and the range of the range query token is at least one subrange of the range covered by the tree list, then an encrypted query result is received based on a search tree; and if the tree list is empty or the range of the range query token is not at least one subrange of the range covered by the tree list, then a pointer to a point list is received, wherein the tree list includes at least one search tree based on the previously received range query token; and In response to receiving the range query token, the server-side computing device updates the encrypted search index based on the range query token to change the tree list to indicate that the range of the range query token has been searched, and one of the ranges of at least one index. The update includes performing a client-server protocol that includes actions performed by the server-side computing device and actions performed by the client-side computing device on plaintext data provided by encrypted data received from the server-side computing device, and using a master key held by the client-side computing device.

14. The system of claim 13, wherein, Updating the encrypted search index includes refining the search tree of the tree list based at least in part on sending a range query token and a previously received range query token to the client computing device, and receiving a refined range token from the client computing device, the encrypted search index being updated based on the refined range token.

15. The system of claim 13, wherein, Updating the encrypted search index includes expanding the search tree of the tree list to the client computing device, at least in part, based on the root node of the search tree and the previously received queries corresponding to the search tree, to provide an expanded search tree, thereby providing a new range query token corresponding to the expanded search tree.

16. The system of claim 13, wherein, Updating the encrypted search index includes, at least in part, merging multiple search trees in the tree list to provide a merged search tree by sending the corresponding root nodes of the multiple search trees to the client computing device, and receiving a token corresponding to the revision of the merged search tree.

17. The system of claim 16, wherein, The multiple trees respond to determining that there are no value gaps between the multiple trees and merge them.

18. The system of claim 13, wherein the operation further includes: Receive encrypted search index and ciphertext from the client computing device.

Citation Information

Patent Citations

  • Cipher searching method based on cloud document system

    CN104408177A

  • Symmetrical searchable encryption method for supporting result high-efficiency sequencing in hybrid cloud storage

    CN104765848A

  • Method and system for dynamically partitioning very large database indices on write-once tables

    EP2199935A2

  • Dynamic symmetric searchable encryption

    US20130046974A1

  • Range-Based Queries for Searchable Symmetric Encryption

    US20130262852A1