A Searchable Encryption Method, Device, Equipment and Storage Medium

By receiving and processing encrypted documents and index tables on cloud servers, encrypting and re-encrypting using elliptic curve encryption algorithm and user keys, the computing efficiency and structural complexity of existing searchable encryption solutions are solved, and search efficiency and user experience are improved.

CN115134083BActive Publication Date: 2025-05-30CETC CYBERSPACE SECURITY TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202210736578.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-27
Publication Date
2025-05-30
Estimated Expiration
2042-06-27

AI Technical Summary

Technical Problem

The existing multi-write and multi-read searchable encryption scheme has problems with computing efficiency and structural complexity, which cannot meet the adaptation needs of domestic commercial secret applications, and the search efficiency is low.

Method used

The cloud server receives the encrypted documents and pre-security index tables sent by the user, uses the elliptic curve encryption algorithm and the user key to encrypt and re-encrypt, calculates the hash value for comparison, finds matching encrypted document information, and pre-decrypts and decrypts to return to the plain text document.

Benefits of technology

It improves the search efficiency of searchable encryption schemes, avoids bilinear pairing operations, simplifies private key management, flexibly controls user decryption permissions, reduces the cost of user revocation, and supports correlation sorting, improving user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115134083B_ABST
    Figure CN115134083B_ABST
Patent Text Reader

Abstract

The present disclosure relates to a searchable encryption method, apparatus, device, and storage medium. In this solution, a cloud server receives an encrypted document and a pre-security index table sent by a first user, re-encrypts each pre-encrypted keyword to obtain its first hash value, re-encrypts a search trapdoor sent by a second user and obtains its second hash value, compares the second hash value with each first hash value, the cloud server performs pre-decryption on the matching result, and after the second user decrypts it, a target document identifier is obtained. After the cloud server returns the target encrypted document corresponding to the target document identifier to the second user, the second user decrypts it to obtain the plaintext document. It can be seen that when implementing the searchable encryption solution, this solution does not involve bilinear pair operations, improving the search efficiency. In this solution, the private key is divided into two parts of keys, which are used by the cloud server and the second user respectively, and the decryption permissions of each user can be flexibly controlled.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of information security technology, and specifically, to a searchable encryption method, apparatus, device, and storage medium. Background Art

[0002] Searchable encryption technology refers to the realization of search functions under encryption. Multi-user searchable encryption technology well solves the problems of data confidentiality and usability in data sharing. Existing multi-write multi-read searchable encryption schemes are mainly implemented based on proxy re-encryption technology. If the proxy re-encryption technology is constructed based on bilinear pairing, it has the problem of low computational efficiency; if the proxy re-encryption technology is constructed based on international cryptographic algorithms such as RSA or ElGamal, the structure is complex and it cannot meet the adaptation requirements of domestic commercial cryptography applications. Therefore, how to improve the search efficiency of searchable encryption schemes is a problem that needs to be solved by those skilled in the art. Summary of the Invention

[0003] The purpose of the present disclosure is to provide a searchable encryption method, apparatus, device, and storage medium to improve the search efficiency of searchable encryption schemes.

[0004] To achieve the above purpose, the present disclosure provides a searchable encryption method, and the searchable encryption method includes:

[0005] A cloud server receives an encrypted document and a pre-security index table sent by a first user; each item of data in the pre-security index table includes: a pre-encrypted keyword encrypted by the user key of the first user, and encrypted document information encrypted by an elliptic curve encryption algorithm and a public key encryption; the private key of the elliptic curve encryption algorithm includes two parts: a user key and an auxiliary key;

[0006] Re-encrypt each pre-encrypted keyword using the auxiliary key of the first user, and calculate a first hash value of the encryption result; receive a search trapdoor sent by a second user, re-encrypt the search trapdoor using the auxiliary key of the second user, and calculate a second hash value of the re-encryption result; the search trapdoor is encrypted according to a search keyword and the user key of the second user;

[0007] Compare the second hash value with each first hash value to find a matching encrypted target document information, pre-decrypt the encrypted target document information using the auxiliary key of the second user, and send the pre-decryption result to the second user;

[0008] Receive a target document identifier sent by the second user; the target document identifier is obtained by decrypting the pre-decryption result using the user key of the second user;

[0009] Send the target encrypted document corresponding to the target document identifier to the second user so that the second user can decrypt the target encrypted document to obtain the plaintext document.

[0010] To achieve the above object, the present disclosure further provides a searchable encryption device, including:

[0011] A first receiving module, configured to receive an encrypted document and a pre-security index table sent by a first user; each piece of data in the pre-security index table includes: a pre-encrypted keyword generated by encrypting with the user key of the first user, and encrypted document information generated by encrypting with an elliptic curve encryption algorithm and a public key; the private key of the elliptic curve encryption algorithm includes two parts, a user key and an auxiliary key;

[0012] A first re-encryption module, configured to re-encrypt each pre-encrypted keyword with the auxiliary key of the first user, and calculate a first hash value of the encryption result;

[0013] A second receiving module, configured to receive a search trapdoor sent by a second user; the search trapdoor is generated by encrypting according to a search keyword and the user key of the second user;

[0014] A second re-encryption module, configured to re-encrypt the search trapdoor with the auxiliary key of the second user, and calculate a second hash value of the re-encryption result;

[0015] A comparison module, configured to compare the second hash value with each first hash value to find a matching encrypted target document information;

[0016] A pre-decryption module, configured to pre-decrypt the encrypted target document information with the auxiliary key of the second user, and send the pre-decryption result to the second user;

[0017] A third receiving module, configured to receive a target document identifier sent by the second user; the target document identifier is obtained by decrypting the pre-decryption result with the user key of the second user;

[0018] A sending module, configured to send the target encrypted document corresponding to the target document identifier to the second user so that the second user can decrypt the target encrypted document to obtain the plaintext document.

[0019] To achieve the above object, the present disclosure further provides an electronic device, including:

[0020] A memory, configured to store a computer program;

[0021] A processor, configured to implement the steps of the above searchable encryption method when executing the computer program.

[0022] To achieve the above object, the present disclosure further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the above searchable encryption method are implemented.

[0023] Through the above technical solution, the present disclosure provides a searchable encryption method, apparatus, device and storage medium; in this solution, the cloud server receives the encrypted document and the pre-security index table sent by the first user, and re-encrypts each pre-encrypted keyword to obtain its first hash value; re-encrypts the search trapdoor sent by the second user and obtains its second hash value; compares the second hash value with each first hash value, the cloud server pre-decrypts the matching result, and after decrypting it through the second user, obtains the target document identifier, and the cloud server returns the target encrypted document corresponding to the target document identifier to the second user, and then the second user decrypts it to obtain the plaintext document. It can be seen that when implementing the searchable encryption solution, this solution does not involve bilinear pair operations, improving the search efficiency; this solution divides the private key into two parts of keys for the cloud server and the second user to use respectively, and can flexibly control the decryption permissions of each user. When a user revokes, only the corresponding information needs to be deleted from the authorized user list, and the revocation cost is small, which does not affect other users or the existing ciphertext data. Description of the Drawings

[0024] The drawings are used to provide a further understanding of the present disclosure, and constitute a part of the specification, and are used to explain the present disclosure together with the following specific embodiments, but do not constitute a limitation to the present disclosure. In the drawings:

[0025] Figure 1 It is a schematic diagram of a system structure provided by an embodiment of the present disclosure;

[0026] Figure 2 It is a schematic diagram of the flow of a searchable encryption method provided by an embodiment of the present disclosure;

[0027] Figure 3 It is a schematic diagram of the overall process provided by an embodiment of the present disclosure;

[0028] Figure 4 It is a schematic diagram of the structure of a searchable encryption apparatus provided by an embodiment of the present disclosure;

[0029] Figure 5 It is a block diagram of the structure of a terminal device provided by an embodiment of the present disclosure;

[0030] Figure 6 It is a block diagram of the structure of a server device provided by an embodiment of the present disclosure. Detailed Embodiments

[0031] Next, the technical solutions in the embodiments of the present disclosure will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present disclosure.

[0032] For the sake of easy understanding, the system architecture used in this solution will be described first. Refer to Figure 1 , which is a schematic diagram of a system structure provided for an embodiment of the disclosure. This system mainly includes four entities: a key management center, a first user, a cloud server, and a second user; the key management center is responsible for generating system parameters, system keys, user keys, and their auxiliary keys, and securely distributing the shared key (system key) and the corresponding user key to each user, and distributing the auxiliary keys of each user to the cloud server; the first user is the data owner DO who uploads the document. The data owner is responsible for encrypting the document, generating a pre-security index, and uploading both to the cloud server CS; the cloud server is responsible for storing the encrypted document and pre-security index uploaded by the data owner, as well as storing the auxiliary keys of each user issued by the key management center, and providing re-encryption services, search services, and pre-decryption services for legitimate users; the second user is the legitimate user DU who searches for the document. It is responsible for generating a search trapdoor for the keyword and uploading it to the cloud server, and decrypting the returned search results. This system is applicable to the scenario where multiple legitimate users in a group share data in a cloud storage environment. The data owner encrypts the data and uploads it to the cloud server for storage. After the legitimate user retrieves the search result on the ciphertext and downloads it locally, the cloud server cannot obtain any information about the plaintext data.

[0033] Refer to Figure 2 , which is a schematic flowchart of a searchable encryption method provided by an embodiment of the present disclosure. Through Figure 2 it can be seen that the searchable encryption method includes:

[0034] S101. The cloud server receives the encrypted document and the pre-security index table sent by the first user; each piece of data in the pre-security index table includes: a pre-encrypted keyword encrypted by the user key of the first user, and encrypted document information encrypted by the elliptic curve encryption algorithm and the public key; the private key of the elliptic curve encryption algorithm includes two parts: the user key and the auxiliary key.

[0035] In this embodiment, the cloud server needs to receive the encrypted document and the pre - security index table sent by the first user. When the second user conducts a search, the second user needs to upload a search trapdoor to the cloud server. The cloud server needs to re - encrypt the pre - encrypted keywords and the search trapdoor in the pre - security index table and then calculate the hash value. By comparing the hash values, the cloud server checks whether there is a document that meets the requirements. If so, the corresponding encrypted document is returned to the second user through subsequent operations. The first user is the data owner who uploads the document, and the second user is the legitimate user who searches for the document.

[0036] It should be noted that before the cloud server in this solution receives the encrypted document and the pre - security index table sent by the first user, it needs to generate system parameters, a system key, a user key for each user, and an auxiliary key for each user through a key management center. Among them, the system key includes: the key of the pseudo - random permutation function, the public key and private key of the elliptic curve encryption algorithm. The key management center sends the key of the pseudo - random permutation function, the user key corresponding to each user, and the public key of the elliptic curve encryption algorithm to the corresponding user through a secure channel; and sends the identification information of each user and the corresponding auxiliary key to the cloud server through a secure channel, so that the cloud server stores the identification information of each user and the corresponding auxiliary key in the authorized user list.

[0037] Specifically, in this solution, it is first necessary to agree that the keyword set of the documents input into the system is predefined, that is, the document set contains N documents, and each document is: F i =(P i , KW i ), where P i is the document plaintext, and KW i is the document keyword set. Assume that the set composed of the keywords of all documents contains M different keywords, and is denoted as

[0038] The key management center first needs to establish a system, generate system parameters, a system key, user keys, and auxiliary keys. The system parameters include: a collision - resistant hash function H, a pseudo - random permutation function f, and elliptic curve system parameters. The elliptic curve system parameters specifically include the order q of the finite field F q , and define two elements a, b ∈ F q of the equation of the elliptic curve E(F q ); the base point G=(x q , y G )(G≠O) on E(F G ), where x G and y G are in F qTwo elements in; the order n of G and other optional items (such as the cofactor h of n, etc.). The key management center discloses the system parameters (q, a, b, G, n, h, H, f). The key management center generates the system key K = (s, d o , P o ) according to the security parameters. Among them, s is the key of the pseudo-random permutation function, which is used to encrypt keywords and generate the key for the search trapdoor, and is used together with the pseudo-random permutation function f; (d o , P o ) is a pair of public and private keys of the elliptic curve encryption algorithm. The public key is P o , and the private key is d o , P o = [d o G ∈ E(F q ).

[0039] For an authorized legitimate user, if the legitimate user is user i with the identification information UID i , the key management center can randomly select the corresponding auxiliary key d i1 and the user key d i2 , and d i1 , d i2 ∈ [1, n - 1], such that d i1 + d i2 = d o (mod n); and, if user i is the data owner: the first user, the key management center needs to send (S, d i2 , P o ) to user i through a secure channel so that user i can encrypt each document information with the public key P o , and encrypt the search keyword with s and d i2 ; correspondingly, if there is a user v with the identification information UID v , and user v is the second user searching for documents, the auxiliary key selected by the key management center for user v is d v1 , and the user key is d v2 , and the relationship between the auxiliary key d v1 and the user key d v2 is the same as the relationship between d i1 and d i2 above, which will not be specifically elaborated here; after the key management center sends s, d v2 to the second user, the second user generates a search trapdoor with s and d v2 , and decrypts the pre-decrypted document information with d v2 ; the key management center also needs to send (UID i , d i1 ) and (UID v , dv1 ) It is sent to the cloud server through a secure channel so that the cloud server can store it in the authorized user list, indicating that both user i and user v are legitimate users. When searching for data, the auxiliary key of the corresponding user can be pre-decrypted.

[0040] It can be understood that when revoking a target user in this solution, the cloud server only needs to delete the corresponding identification information and the corresponding auxiliary key of the target user from the authorized user list. For example, when revoking user j, only (UID j , d j1 ) needs to be deleted from the authorized user list. In this way, when user j searches for a document, the cloud server cannot find the corresponding (UID j , d j1 ) in the authorized user list, and user j can be determined as an illegal user. At this time, there is no need to perform subsequent pre-decryption and other operations, and a prompt message is sent to user j, indicating that user j has no permission to obtain the corresponding document. It can be seen that when performing the user revocation operation in this way, the process of this solution is simple, does not involve adjusting the password scheme, improves the search efficiency, and reduces the revocation cost.

[0041] Furthermore, the first user in this solution specifically generates an encrypted document and a pre-secure index table in the following way, and sends the obtained encrypted document and pre-secure index table to the cloud server for storage.

[0042] 1. The first user assigns a corresponding document identifier and a symmetric encryption key to each document in the document set, and encrypts the corresponding document with the symmetric encryption key to generate an encrypted document;

[0043] Specifically, for each document F in this solution's document set, the data owner needs to assign a document identifier FID i to it, and generate a symmetric encryption key k i , and run the symmetric encryption algorithm SKE (Secret Key Encryption) to encrypt the document F i to obtain an encrypted document. i

[0044] 2. The first user searches for the document information of several associated documents containing each keyword; the document information includes: the document identifier of the associated document, the symmetric encryption key of the associated document, and the relevance score of each keyword to the associated document; uses a pseudo-random permutation function and the corresponding key, as well as the user key of the first user to encrypt each keyword, generating a pre-encrypted keyword for each item of data in the pre-secure index table; uses the elliptic curve encryption algorithm and the public key to encrypt the document information of several associated documents corresponding to each keyword, generating the encrypted document information for each item of data in the pre-secure index table.

[0045] Specifically, when generating the pre - security index table in this solution, first, an inverted index table of "keyword - document" needs to be established for the document set, and then the inverted index table is encrypted to obtain the pre - security index table. When establishing the inverted index structure, for each keyword w j , find t documents that contain w j . In this embodiment, the t documents that contain the keyword w j are called associated documents corresponding to the keyword w j . Then, the document information ID of each associated document is determined j . The keyword w j is combined with the document information of the corresponding associated documents to establish an inverted index table with M rows. The data in the j - th row is: The document information of each associated document includes: the document identifier of the associated document, the symmetric encryption key of the associated document, and the correlation score between the keyword and the associated document. For example, if the first associated document of the keyword w j is , then the document information of the associated document is: And so on, the document information of the associated documents corresponding to each keyword w j can be obtained.

[0046] In this embodiment, the TF×IDF algorithm (Term Frequency Inversedocumentffequency, a common weighting technique used in information retrieval and data mining) can be used to calculate the correlation score Score between the keyword and each associated document. Considering that for a single keyword, the IDF of different documents is a constant value, Score in this solution only takes TF. For example: where is the frequency of w j appearing in .

[0047] After obtaining the inverted index table in this solution, it needs to be encrypted to obtain a pre - security index table with M rows. The data in the j - th row is: In this solution, specifically, the pseudo - random permutation function f and its key, as well as the user key of the first user, are used to encrypt each keyword to obtain C * (w j ), that is: C * (w j ) = [f s (w j ) + d i2 G; Then, the elliptic curve encryption algorithm and the public key P are usedo Encrypt each document information. For example, the ciphertext of the document information is:

[0048]

[0049] S102. Re-encrypt each pre-encrypted keyword using the auxiliary key of the first user, and calculate the first hash value of the encryption result; receive the search trapdoor sent by the second user, re-encrypt the search trapdoor using the auxiliary key of the second user, and calculate the second hash value of the re-encryption result; the search trapdoor is encrypted and generated according to the search keyword and the user key of the second user.

[0050] In this embodiment, after the cloud service center receives the encrypted document and the pre-secure index table sent by the first user, it is also necessary to re-encrypt the pre-encrypted keyword in the pre-secure index table using the auxiliary key of the first user. For example, if the first user is user i, the cloud service center needs to use the auxiliary key d i1 The re-encryption result is obtained: C(w j ) = C * (w j ) + [d i1 G = [f s (w j ) + d o G = (x j , y j ); then calculate the first hash value H(x j ) of the re-encryption result C(w j ||y j ). The first hash value will replace the pre-encrypted keyword and be stored in the pre-secure index table. If each pre-encrypted keyword in the pre-secure index table is replaced with the corresponding first hash value, then this pre-secure index table can be called a secure index table. Correspondingly, the j-th item of data in the secure index table is:

[0051] It should be noted that the search trapdoor in this solution is encrypted and generated by the second user using the pseudo-random permutation function and the corresponding key, as well as the user key of the second user. For example, when user v needs to query keyword w, the calculated search trapdoor is specifically: T w * = [f s (w) + d v2 G, and send it to the cloud server. After the cloud server receives the search trapdoor T w * sent by user v, it can query the authorized user list using the identity identifier UID v of user v, obtain the auxiliary key d v1 of user v, and re-encrypt the search trapdoor to get: T w = Tw * +[d v1 G = [f s (w) + d o G = (x, y), and use the hash function to calculate the second hash value H(x||y) of the re-encrypted result.

[0052] S103. Compare the second hash value with each first hash value, search for the encrypted target document information that matches, pre-decrypt the encrypted target document information using the auxiliary key of the second user, and send the pre-decryption result to the second user;

[0053] In this embodiment, when the cloud server searches according to the search trapdoor, it needs to traverse the security index table, and compare the second hash value H(x||y) of the user's search trapdoor with the first hash value H(x j ) of each keyword ciphertext C(w j ||y j ). If, after traversing, no first hash value identical to the second hash value is found in the security index table, it means that no matching document is found and the search fails. Then, the output stops, and a prompt message indicating that no matching document is found is sent to the second user; if a first hash value identical to the second hash value is found in the security index table, it means that the matching is successful. For example, if H(x||y) and the first hash value H(x j ||y j ) are successfully compared, then search for each encrypted target document information corresponding to the first hash value H(x j ||y j ), and pre-decrypt the ciphertext of each encrypted target document information according to the auxiliary key d v1 of the second user to obtain the pre-decryption result. It should be noted that the pre-decryption process is related to the specific algorithm. If the SM2 encryption algorithm is used, the ciphertext is in the form of C = C 1 ||C 2 ||C 3 . The cloud server calculates the point P 1 = [d v1 C 1 , and returns P 1 and the pre-decrypted target document information to the user v.

[0054] S104. Receive the target document identifier sent by the second user; the target document identifier is obtained by decrypting the pre-decryption result using the user key of the second user;

[0055] In this embodiment, after the second user receives the pre-decryption result, the second user uses the user key of the second user to decrypt the pre-decryption result to obtain a decrypted document identifier, a symmetric encryption key corresponding to each decrypted document identifier, and a relevance score corresponding to each decrypted document identifier; sorts the relevance scores corresponding to each decrypted document identifier in descending order, and uses the first predetermined number of decrypted document identifiers in the sorting result as the target document identifiers.

[0056] Specifically, after user v receives the pre-decryption result, user v uses the user key d v2 to continue decrypting the pre-decryption result. The obtained decrypted document information includes: a decrypted document identifier, a symmetric encryption key corresponding to each decrypted document identifier, and a relevance score corresponding to each decrypted document identifier. If the SM2 encryption algorithm is adopted, user i calculates the point P 2 = P 1 + [d v2 C 1 = (x 2 , y 2 ), and then continues to complete the subsequent decryption steps to obtain the plaintext document information. Moreover, when determining the target document identifiers, user v can sort the relevance scores corresponding to each decrypted document identifier from largest to smallest in descending order, and use the first k document identifiers as the target document identifiers and return them to the cloud server.

[0057] S105. Send the target encrypted document corresponding to the target document identifier to the second user so that the second user can decrypt the target encrypted document to obtain the plaintext document.

[0058] In this embodiment, after the cloud server receives the target document identifiers sent by the second user, the cloud server needs to send the corresponding target encrypted document to the second user according to the corresponding relationship between each document identifier and the encrypted document. After the second user receives the target encrypted document sent by the cloud server, the second user uses the symmetric encryption key corresponding to the target encrypted document to decrypt the target encrypted document to generate a plaintext document. When decrypting, the symmetric encryption algorithm SKE specifically needs to be run for decryption to obtain the plaintext document set.

[0059] See Figure 3, The overall process schematic diagram provided by the embodiments of the present disclosure. The key management center KMC executes the system establishment and key generation steps, authorizes users, and sends the identification information, auxiliary key, and elliptic curve parameters of each user to the cloud server CS through a secure channel, and sends the elliptic curve parameters, pseudo-random permutation function and key, public key of the elliptic curve encryption algorithm, and corresponding user key to each legitimate user DU through a secure channel. User i assigns identifiers to all documents, encrypts the document set using a symmetric algorithm, calculates the relevance score between keywords and documents to construct document information, establishes an inverted index, pre-encrypts the keywords and document information to generate a pre-security index table, and sends the encrypted documents and the pre-security index table to the cloud server CS. The cloud server generates a security index using the auxiliary key of user i. When user v searches, calculates the search trapdoor and sends it to the cloud server. The cloud server re-encrypts the search trapdoor using the auxiliary key of user v, retrieves the security index list, finds the corresponding encrypted document information ciphertext, and sends the pre-decryption result to user v after pre-decrypting. User v continues to decrypt the pre-decryption result to obtain the plaintext of the document information, sorts it and obtains the first k document identifiers and sends them to the cloud server. The cloud server returns the corresponding k document ciphers to the legitimate user according to the first k document identifiers. User v decrypts using the symmetric algorithm to obtain the plaintext set of the documents.

[0060] This solution uses the elliptic curve encryption algorithm on the basis of Searchable Symmetric Encryption (SSE) to encrypt the symmetric encryption key of the encrypted document. This method of using the elliptic curve encryption algorithm instead of proxy re-encryption to protect the encryption key of the document does not involve bilinear pair operations, improves the overall efficiency of the system, and has good adaptability in commercial cryptography applications; this solution also splits the decryption private key of the elliptic curve encryption algorithm into two parts, which are respectively mastered by the user and the cloud server, so that each user has a different user key, thus flexibly controlling the decryption permissions of multiple users, and each user has its own independent key, and there is no mutual influence between users. At the same time, the generation processes of the security index and the search trapdoor are both completed by the user and the cloud server in cooperation using the user key and the auxiliary key, thus effectively controlling the write permission and search permission of the user; the user revocation cost of this solution is small, and only the identification information and auxiliary key of the corresponding user need to be deleted from the authorized user list, which does not affect other users or the existing ciphertext data; this solution also has the function of sorting the search results by relevance, so that users can independently select several results to output according to the relevance, improving the user experience.

[0061] See Figure 4 , A schematic structural diagram of a searchable encryption device provided by the embodiments of the present disclosure. This device is applied to a cloud server and includes:

[0062] The first receiving module 11 is configured to receive an encrypted document and a pre - security index table sent by a first user; each piece of data in the pre - security index table includes: a pre - encrypted keyword generated by encrypting with the user key of the first user, and encrypted document information generated by encrypting with an elliptic curve encryption algorithm and a public key; the private key of the elliptic curve encryption algorithm includes two parts: a user key and an auxiliary key.

[0063] The first re - encryption module 12 is configured to re - encrypt each pre - encrypted keyword with the auxiliary key of the first user, and calculate the first hash value of the encryption result.

[0064] The second receiving module 13 is configured to receive a search trapdoor sent by a second user; the search trapdoor is generated by encrypting according to a search keyword and the user key of the second user.

[0065] The second re - encryption module 14 is configured to re - encrypt the search trapdoor with the auxiliary key of the second user, and calculate the second hash value of the re - encryption result.

[0066] The comparison module 15 is configured to compare the second hash value with each first hash value to find the matching encrypted target document information.

[0067] The pre - decryption module 16 is configured to pre - decrypt the encrypted target document information with the auxiliary key of the second user, and send the pre - decryption result to the second user.

[0068] The third receiving module 17 is configured to receive a target document identifier sent by the second user; the target document identifier is obtained by decrypting the pre - decryption result with the user key of the second user.

[0069] The sending module 18 is configured to send the target encrypted document corresponding to the target document identifier to the second user, so that the second user decrypts the target encrypted document to obtain a plain - text document.

[0070] In an embodiment of the present disclosure, the searchable encryption device further includes:

[0071] The deletion module is configured to, when revoking a target user, the cloud server deletes the identification information corresponding to the target user and the corresponding auxiliary key from the authorized user list.

[0072] An embodiment of the present disclosure further provides a searchable encryption system, and the searchable encryption method includes:

[0073] The first user is used to send an encrypted document and a pre - security index table to the cloud server; each piece of data in the pre - security index table includes: a pre - encrypted keyword generated by encrypting with the user key of the first user, and encrypted document information generated by the elliptic curve encryption algorithm and public key encryption; the private key of the elliptic curve encryption algorithm includes two parts: the user key and the auxiliary key.

[0074] The second user is used to send a search trapdoor to the cloud server; the search trapdoor is generated by encrypting according to the search keyword and the user key of the second user; receive the pre - decryption result sent by the cloud server, decrypt the pre - decryption result using the user key of the second user to obtain the target document identifier; receive the target encrypted document sent by the cloud server, and decrypt the target encrypted document to obtain the plain - text document.

[0075] The cloud server is used to receive the encrypted document and the pre - security index table sent by the first user; re - encrypt each pre - encrypted keyword using the auxiliary key of the first user, and calculate the first hash value of the encryption result; receive the search trapdoor sent by the second user, re - encrypt the search trapdoor using the auxiliary key of the second user, and calculate the second hash value of the re - encryption result; compare the second hash value with each first hash value to find the matching encrypted target document information, pre - decrypt the encrypted target document information using the auxiliary key of the second user, and send the pre - decryption result to the second user; receive the target document identifier sent by the second user, and send the target encrypted document corresponding to the target document identifier to the second user.

[0076] In the embodiment of the present disclosure, the first user is specifically used for: assigning corresponding document identifiers and symmetric encryption keys to each document in the document set, and encrypting the corresponding document with the symmetric encryption key to generate an encrypted document; finding the document information of several associated documents containing each keyword; the document information includes: the document identifier of the associated document, the symmetric encryption key of the associated document, and the relevance score of each keyword and the associated document; using the pseudo - random permutation function and the corresponding key, as well as the user key of the first user to encrypt each keyword, generating the pre - encrypted keyword of each piece of data in the pre - security index table; using the elliptic curve encryption algorithm and public key to encrypt the document information of several associated documents corresponding to each keyword, generating the encrypted document information of each piece of data in the pre - security index table.

[0077] In the embodiment of the present disclosure, the second user is specifically used for: encrypting the search keyword using the pseudo - random permutation function and the corresponding key, as well as the user key of the second user to generate.

[0078] In the embodiments of the present disclosure, the searchable encryption system further includes:

[0079] A key management center, configured to generate system parameters, a system key, a user key for each user, and an auxiliary key for each user; wherein, the system key includes: a key of a pseudo-random permutation function, a public key and a private key of an elliptic curve encryption algorithm; sending the key of the pseudo-random permutation function, the user key corresponding to each user, and the public key of the elliptic curve encryption algorithm to the corresponding user through a secure channel; sending the identification information of each user and the corresponding auxiliary key to the cloud server through a secure channel, so that the cloud server stores the identification information of each user and the corresponding auxiliary key in an authorized user list.

[0080] In the embodiments of the present disclosure, the cloud server is further configured to: when revoking a target user, delete the identification information and the corresponding auxiliary key corresponding to the target user from the authorized user list.

[0081] In the embodiments of the present disclosure, the second user is specifically configured to: receive a pre-decryption result, and decrypt the pre-decryption result by using the user key of the second user to obtain a decrypted document identifier, a symmetric encryption key corresponding to each decrypted document identifier, and a relevance score corresponding to each decrypted document identifier; perform a descending order arrangement on the relevance scores corresponding to each decrypted document identifier, and use the first predetermined number of decrypted document identifiers in the sorting result as target document identifiers.

[0082] In the embodiments of the present disclosure, the second user is specifically configured to: receive the target encrypted document sent by the cloud server, and decrypt the target encrypted document by using the symmetric encryption key corresponding to the target encrypted document to generate a plaintext document.

[0083] The embodiments of the present disclosure also disclose an electronic device, which includes: a memory, configured to store a computer program; a processor, configured to implement the steps of the searchable encryption method described in the above method embodiments when executing the computer program.

[0084] Specifically, when the electronic device executes the operations performed by the first user or the second user, the electronic device may specifically be a terminal device, such as: a mobile phone, a computer, and other terminals. Refer to Figure 5 , a structural block diagram of a terminal device 20 provided by the embodiments of the present disclosure. As Figure 5 shown, the terminal device 20 may include: a processor 21, a memory 22. The terminal device 20 may further include one or more of a multimedia component 23, an input / output (I / O) interface 24, and a communication component 25.

[0085] Among them, the processor 21 is used to control the overall operation of the terminal device 20 to complete all or part of the steps of the above-mentioned first user or second user performing operations. The memory 20 is used to store various types of data to support the operation of the terminal device 20. These data may include, for example, instructions for any application or method operating on the terminal device 20, as well as application-related data, such as contact data, received and sent messages, pictures, audio, video, and so on. The memory 22 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random Access Memory (SRAM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Erasable Programmable Read-Only Memory (EPROM), Programmable Read-Only Memory (PROM), Read-Only Memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk. The multimedia component 23 may include a screen and an audio component. Among them, the screen may be a touch screen, and the audio component is used to output and / or input audio signals. For example, the audio component may include a microphone, and the microphone is used to receive external audio signals. The received audio signals may be further stored in the memory 22 or sent through the communication component 25. The audio component also includes at least one speaker for outputting audio signals. The I / O interface 24 provides an interface between the processor 21 and other interface modules, and the above-mentioned other interface modules may be a keyboard, a mouse, buttons, etc. These buttons may be virtual buttons or physical buttons. The communication component 25 is used for wired or wireless communication between the terminal device 20 and other devices. Wireless communication, such as Wi-Fi, Bluetooth, Near Field Communication (NFC), 2G, 3G or 4G, or a combination of one or more of them. Therefore, the corresponding communication component 25 may include: a Wi-Fi module, a Bluetooth module, and an NFC module.

[0086] In an exemplary embodiment, the terminal device 20 may be implemented by one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components, and is used to execute the searchable encryption method performed by the first user or the second user.

[0087] Specifically, when the electronic device executes the operations performed by the cloud server, the electronic device may specifically be a server. Refer to Figure 6 , a structural block diagram of a server device 30 provided by an embodiment of the present disclosure. As Figure 6 shown, the server device 30 includes a processor 31, the number of which may be one or more, and a memory 32 for storing computer programs executable by the processor 31. The computer programs stored in the memory 32 may include one or more modules each corresponding to a set of instructions. In addition, the processor 31 may be configured to execute the computer program to perform the searchable encryption method performed by the above-mentioned cloud server.

[0088] In addition, the server device 30 may further include a power supply component 33 and a communication component 34. The power supply component 33 may be configured to perform power management of the server device 30, and the communication component 34 may be configured to implement communication of the server device 30, for example, wired or wireless communication. In addition, the server device 30 may further include an input / output (I / O) interface 35. The server device 30 may operate based on an operating system stored in the memory 32, such as Windows ServerTM, Mac OS XTM, UnixTM, LinuxTM, and so on.

[0089] In another exemplary embodiment, a computer-readable storage medium including program instructions is further provided. When the program instructions are executed by a processor, the steps of the above-mentioned searchable encryption method are implemented. The storage medium may include: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs.

[0090] Regarding the devices, systems, equipment, and storage in the above embodiments, the specific ways in which they perform operations have been described in detail in the embodiments related to the method, and will not be elaborated here.

[0091] The preferred embodiments of the present disclosure have been described in detail above with reference to the accompanying drawings. However, the present disclosure is not limited to the specific details in the above embodiments. Within the scope of the technical concept of the present disclosure, various simple modifications can be made to the technical solutions of the present disclosure, and these simple modifications all fall within the protection scope of the present disclosure.

[0092] In addition, it should be noted that, among the various specific technical features described in the above specific embodiments, without conflict, they can be combined in any appropriate way. To avoid unnecessary repetition, the present disclosure will not separately describe various possible combination methods.

[0093] Furthermore, any combination can be made between various different embodiments of the present disclosure, as long as it does not violate the idea of the present disclosure, and it should also be regarded as the content disclosed by the present disclosure.

Claims

1. A searchable encryption method, characterized in that, the searchable encryption method includes: The cloud server receives an encrypted document and a pre - security index table sent by a first user; each item of data in the pre - security index table includes: a pre - encrypted keyword generated by encrypting with the user key of the first user, and encrypted document information generated by elliptic curve encryption algorithm and public - key encryption; the private key of the elliptic curve encryption algorithm includes two parts: the user key and the auxiliary key; the auxiliary key is sent to the cloud server by the key management center through a secure channel; Wherein, the generation method of the encrypted document and the pre - security index table includes: the first user assigns a corresponding document identifier and a symmetric encryption key to each document in the document set, and encrypts the corresponding document with the symmetric encryption key to generate an encrypted document; the first user searches for the document information of several associated documents containing each keyword; the document information includes: the document identifier of the associated document, the symmetric encryption key of the associated document, and the relevance score of each keyword to the associated document; uses a pseudo - random permutation function and the corresponding key, as well as the user key of the first user to encrypt each keyword to generate the pre - encrypted keyword of each item of data in the pre - security index table; uses the elliptic curve encryption algorithm and public - key to encrypt the document information of several associated documents corresponding to each keyword to generate the encrypted document information of each item of data in the pre - security index table; Re - encrypts each pre - encrypted keyword with the auxiliary key of the first user and calculates the first hash value of the encryption result; receives a search trapdoor sent by a second user, re - encrypts the search trapdoor with the auxiliary key of the second user and calculates the second hash value of the re - encryption result; the search trapdoor is encrypted according to the search keyword and the user key of the second user; Compares the second hash value with each first hash value, searches for the encrypted target document information that matches, pre - decrypts the encrypted target document information with the auxiliary key of the second user, and sends the pre - decryption result to the second user; Receives the target document identifier sent by the second user; the target document identifier is obtained by decrypting the pre - decryption result with the user key of the second user; Sends the target encrypted document corresponding to the target document identifier to the second user, so that the second user decrypts the target encrypted document to obtain the plain - text document.

2. The searchable encryption method according to claim 1, characterized in that, the search trapdoor is generated by the second user using a pseudo - random permutation function and the corresponding key, as well as the user key of the second user to encrypt the search keyword.

3. The searchable encryption method according to claim 1, characterized in that, before the cloud server receives the encrypted document and the pre - security index table sent by the first user, it further includes: The key management center generates system parameters, a system key, a user key for each user, and an auxiliary key for each user; wherein, the system key includes: a key of a pseudo-random permutation function, a public key and a private key of an elliptic curve encryption algorithm. The key management center sends the key of the pseudo-random permutation function, the user key corresponding to each user, and the public key of the elliptic curve encryption algorithm to the corresponding user through a secure channel; and sends the identification information of each user and the corresponding auxiliary key to the cloud server through a secure channel, so that the cloud server stores the identification information of each user and the corresponding auxiliary key in an authorized user list.

4. The searchable encryption method according to claim 3, characterized in that the searchable encryption method further includes: When revoking a target user, the cloud server deletes the identification information and the corresponding auxiliary key of the target user from the authorized user list.

5. The searchable encryption method according to any one of claims 1 to 4, characterized in that the method for generating the target document identifier includes: The second user receives the pre-decryption result, and decrypts the pre-decryption result by using the user key of the second user to obtain a decrypted document identifier, a symmetric encryption key corresponding to each decrypted document identifier, and a relevance score corresponding to each decrypted document identifier. Arrange the relevance scores corresponding to each decrypted document identifier in descending order, and use the first predetermined number of decrypted document identifiers in the sorting result as the target document identifier.

6. The searchable encryption method according to claim 5, characterized in that the method for generating the plaintext document includes: Receiving the target encrypted document sent by the cloud server, and decrypting the target encrypted document by using the symmetric encryption key corresponding to the target encrypted document to generate a plaintext document.

7. A searchable encryption device, characterized in that applied to a cloud server, including: A first receiving module, configured to receive an encrypted document and a pre-secure index table sent by a first user; each item of data in the pre-secure index table includes: a pre-encrypted keyword encrypted by using the user key of the first user, and encrypted document information encrypted by using the elliptic curve encryption algorithm and the public key; the private key of the elliptic curve encryption algorithm includes two parts, namely a user key and an auxiliary key; the auxiliary key is sent by the key management center to the cloud server through a secure channel. Among them, the method for generating the encrypted document and the pre - security index table includes: the first user assigns corresponding document identifiers and symmetric encryption keys to each document in the document set, and encrypts the corresponding document with the symmetric encryption key to generate an encrypted document; the first user searches for the document information of several associated documents containing each keyword; the document information includes: the document identifier of the associated document, the symmetric encryption key of the associated document, and the relevance score of each keyword to the associated document; uses a pseudo - random permutation function and the corresponding key, as well as the user key of the first user to encrypt each keyword, generating a pre - encrypted keyword for each item of data in the pre - security index table; uses the elliptic curve encryption algorithm and the public key to encrypt the document information of several associated documents corresponding to each keyword, generating the encrypted document information for each item of data in the pre - security index table. The first re - encryption module is used to re - encrypt each pre - encrypted keyword with the auxiliary key of the first user and calculate the first hash value of the encryption result. The second receiving module is used to receive the search trapdoor sent by the second user; the search trapdoor is encrypted and generated according to the search keyword and the user key of the second user. The second re - encryption module is used to re - encrypt the search trapdoor with the auxiliary key of the second user and calculate the second hash value of the re - encryption result. The comparison module is used to compare the second hash value with each first hash value to find the matching encrypted target document information. The pre - decryption module is used to pre - decrypt the encrypted target document information with the auxiliary key of the second user and send the pre - decryption result to the second user. The third receiving module is used to receive the target document identifier sent by the second user; the target document identifier is obtained by decrypting the pre - decryption result with the user key of the second user. The sending module is used to send the target encrypted document corresponding to the target document identifier to the second user, so that the second user can decrypt the target encrypted document to obtain the plain - text document.

8. An electronic device Characterized in that It includes: A memory for storing a computer program; A processor for implementing the steps of the searchable encryption method according to any one of claims 1 to 6 when executing the computer program.

9. A computer - readable storage medium Characterized in that The computer - readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the steps of the searchable encryption method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Agent re-encryption scheme based on keyword research

    CN105743888A

  • Encrypted file retrieval method and system, terminal equipment and storage medium

    CN108038128A

  • Encrypted data retrieval and sharing method and system, medium, equipment and application

    CN112632598A

  • Searching method and device based on elliptic curve cryptography, equipment and storage medium

    CN115134084A