A Method for Label Range Query Supporting Encrypted Road Network Graphs
By constructing encrypted indexes and obfuscating keyword hash tables, using distributed decryption schemes and symmetric encryption algorithms, the problem of privacy leakage and low efficiency of label range query of road network diagrams in the Internet of Vehicles is solved, and efficient privacy protection and query efficiency are achieved.
Patent Information
- Application Number
- CN202210562457.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-05-23
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2042-05-23
AI Technical Summary
The prior art cannot effectively protect the tag range query method of road network maps in the Internet of Vehicles, resulting in data privacy leakage and user privacy threats, and the query efficiency is inefficient.
Using Paillier-based distributed decryption scheme and symmetric encryption algorithm, an encryption index and obfuscating keyword hash table are constructed, a key is generated and distributed, and the user generates an encryption query token. The cloud server collaborates on query requests and returns the ciphertext results.
It realizes privacy protection for data owners and users, improves the efficiency of tag range query, and avoids performance losses caused by complex cryptographic primitives.
Smart Images

Figure CN115186276B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method for querying the range of vehicle networking tags, specifically to a method for querying the range of tags supporting an encrypted road network graph in vehicle networking, belonging to the technical fields of vehicle networking and privacy protection. Background Art
[0002] In the big data era, in addition to unstructured data represented by text data, structured data represented by graph data has also attracted more and more attention.
[0003] In the vehicle networking scenario, the road network graph is a typical graph data. The points in the road network graph represent certain entities in the real road (such as restaurants, gas stations, etc.), the edges in the graph represent whether there is a road connection between two points, and the weights on the edges represent the lengths of the roads between two points.
[0004] In the road network graph, as a typical query method, the tag range query aims to query the set of all points that meet specific tags and are less than a given threshold away from the current location. For example, if a user's current location is point A and all gas stations within 500 meters need to be queried, then the tag range query corresponding to this user is (A, 500, "gas station").
[0005] With the development of cloud storage and cloud computing technologies, more and more data owners of road network graphs will outsource their data to third-party cloud servers, which store the data and respond to users' data query requests. Although this method of outsourcing storage and computing reduces the costs of data owners, it also brings serious problems of privacy information leakage. From the perspective of data owners, once the owned graph data is leaked, the data may be sold to others, causing huge economic losses to the data owners. From the perspective of users, once the users' query information is leaked, attackers can infer users' preferences, living habits and other privacy information based on this information, seriously threatening users' privacy and security.
[0006] Currently, although some researchers have proposed some query methods supporting encrypted road network graphs, these methods only support query methods such as the shortest distance query of graphs and do not support tag range queries. In addition, existing technologies are more based on complex cryptographic primitives such as secure multi-party computation, oblivious transfer, and oblivious storage, seriously affecting the query efficiency. Summary of the Invention
[0007] The purpose of the present invention is to address the defects and deficiencies existing in the prior art. To solve the technical problem of privacy leakage in the method for querying the range of tags based on road network graphs in vehicle networking, a method for querying the range of tags supporting an encrypted road network graph is creatively proposed.
[0008] The innovation points of the present invention are as follows: First, based on the query characteristics of users in label range queries, a range query index for road network diagrams with high query efficiency is constructed. Second, cryptographic primitives such as a distributed decryption scheme based on Paillier are used to encrypt the range query index and the user's query request, protecting the data privacy of the data owner and the query privacy of the user.
[0009] The present invention is implemented by the following technical solutions.
[0010] A method for label range query supporting encrypted road network diagrams includes the following steps:
[0011] Step 1: The data owner generates keys and distributes them.
[0012] In this method, the data owner first needs to generate a series of keys required for data encryption and query. The data owner has road network diagram data.
[0013] The road network diagram data is represented as G=(V, E), where V represents the set of vertices of the road network diagram, and E represents the set of edges of the road network diagram. Each point in V has a corresponding keyword, and the set of keywords is W.
[0014] Specifically, Step 1 may include the following steps:
[0015] Step 1.1: The data owner randomly generates two keys K0 and K;
[0016] Step 1.2: Adopt a public key encryption scheme with distributed decryption, abbreviated as the PCDD scheme, to generate a strong private key and m+1 public-private key pairs, where m represents the number of users;
[0017] Step 1.3: Send K0, K, and the i-th public-private key pair to user i through a secure channel; use the (m+1)-th public-private key pair as the public-private key pair for its own use, and secretly save K0, K, and the private key;
[0018] Step 1.4: Use the strong private key splitting algorithm of the PCDD scheme to split the strong private key into two partial private keys; send all m+1 public keys generated in Step 1.2 and the first partial private key obtained by splitting in Step 1.3 to cloud server A through a secure channel, and send m+1 public keys and the second partial private key to cloud server B through a secure channel;
[0019] Among them, cloud server A and cloud server B are two independent cloud servers provided by different cloud service providers. Therefore, there is no collusion behavior between these two servers.
[0020] Step 2: The data owner encrypts the road network diagram.
[0021] In an actual vehicle networking scenario, when a user performs a tag range query, the set range threshold is usually not too large. For example, the user is more inclined to search for "gas stations within 1000 meters" rather than "gas stations within 5000 meters".
[0022] Based on the above query characteristics, in order to further improve the query efficiency, this method pre - sets a maximum value of the range threshold (e.g., 1000 meters) based on the road network graph data, and generates a range index RI; then, uses cryptographic primitives to encrypt the generated range index;
[0023] When the user performs a query, as long as the set range threshold is less than the maximum value of the threshold set by the system, the tag range query result can be obtained efficiently.
[0024] Specifically, step 2 may include the following steps:
[0025] Step 2.1: Initialize an empty encrypted index and a confusion keyword hash table with a value of 0;
[0026] Step 2.2: For each vertex in the vertex set V of the road network graph data G, find all vertices whose distance from this vertex does not exceed the given maximum threshold value (e.g., 1000 meters), and construct the query range index RI;
[0027] Step 2.3: Use the vertex set V and the keyword set W to generate the corresponding keyword dictionary D. The keyword dictionary D gives which keyword in the keyword set W each vertex in V corresponds to.
[0028] Step 2.4: Generate the encrypted index.
[0029] For each vertex v ∈ V in the vertex set V, generate an encrypted range index item associated with this vertex v, and add it to the encrypted index.
[0030] Specifically, step 2.4 may include the following steps:
[0031] Step 2.4.1: Encrypt the vertex v using the symmetric encryption algorithm, and the key is the key K0 generated in step 1.1 to obtain the encrypted vertex;
[0032] Step 2.4.2: Encrypt each range index item associated with the vertex v in the query range index RI. Each range index item includes the intermediate vertex u and the distance d between u and v.
[0033] Specifically, step 2.4.2 includes the following steps:
[0034] Step 2.4.2.1: Encrypt the intermediate vertex u using a symmetric encryption algorithm with the key K0 generated in Step 1.1 to obtain the encrypted intermediate vertex;
[0035] Step 2.4.2.2: Encrypt the distance d using the encryption algorithm in the PCDD scheme with the public key of the data owner generated in Step 1.1 to obtain the encrypted distance;
[0036] Step 2.4.2.3: Take the encrypted intermediate vertex and the encrypted distance as encrypted range index entries and add them to the encrypted index.
[0037] Step 2.5: Generate a hash table of obfuscated keywords.
[0038] For each keyword in the keyword set W, set the index entry associated with the keyword in the hash table of obfuscated keywords to 1.
[0039] Specifically, Step 2.5 may include the following steps:
[0040] Step 2.5.1: Use the keyword and the key K generated in Step 1.1 to calculate the first index key and the second index key;
[0041] Step 2.5.2: For each vertex associated with the keyword in the dictionary D, generate an obfuscated keyword index and set the value corresponding to the index in the hash table of obfuscated keywords to 1.
[0042] Specifically, Step 2.5.2 may include the following steps:
[0043] Step 2.5.2.1: Encrypt the vertex using a symmetric encryption algorithm with the key K0 generated in Step 1.1 to obtain the encrypted vertex;
[0044] Step 2.5.2.2: Generate a first index using the first index key and the encrypted vertex, and generate a second index using the second index key and the encrypted vertex;
[0045] Step 2.5.3.3: Set the values corresponding to the first index and the second index in the hash table of obfuscated keywords to 1.
[0046] Step 2.6: The data owner sends the encrypted index and the hash table of obfuscated keywords to Cloud Server A.
[0047] Step 3: The user generates a label range query token.
[0048] The user generates a label range query request q, q = (s, w, θ), where s represents the source vertex where the user is currently located, w represents the keyword to be queried, θ is the range threshold, and θ is not greater than the maximum value of the allowed query threshold.
[0049] After that, the user encrypts and obfuscates the query request using the secret key obtained from the data owner to obtain a query token in ciphertext form.
[0050] Specifically, step 3 may include the following steps:
[0051] Step 3.1: Encrypt the source vertex s using a symmetric encryption algorithm with the secret key K0 generated in step 1.1 to obtain the encrypted source vertex.
[0052] Step 3.2: Calculate the first index key and the second index key using the keyword w and the secret key K generated in step 1.1.
[0053] Step 3.3: Encrypt the range threshold θ using the encryption algorithm in the PCDD scheme with the public key of the user sent by the data owner in step 1.3 to obtain the encrypted range threshold.
[0054] Step 3.4: Take the "encrypted source vertex, first index key, second index key, encrypted range threshold" as the query token and send it to cloud server A.
[0055] Step 4: The cloud server responds to the query request and returns the query result in ciphertext form.
[0056] When receiving the user's query token, the two cloud servers A and B cooperate to perform a label range query operation based on the encrypted road network graph and return the query result in ciphertext form to the user.
[0057] Specifically, step 4 may include the following steps:
[0058] Step 4.1: Cloud server A initializes a candidate set and parses the query token into: encrypted source vertex, first index key, second index key, encrypted range threshold.
[0059] Step 4.2: Cloud server A queries all the encrypted index entries associated with the encrypted source vertex from the encrypted index uploaded by the data owner in step 2.6 and filters out all the points associated with the keyword. Each encrypted index entry contains an encrypted associated vertex and an encrypted distance.
[0060] Specifically, step 4.2 may include the following steps:
[0061] Step 4.2.1: Generate the first index using the first index key obtained in step 4.1 and the encrypted associated vertex; generate the second index using the second index key obtained in step 4.1 and the encrypted associated vertex.
[0062] Step 4.2.2: Based on the obfuscated keyword hash table uploaded by the data owner in Step 2.6, Cloud Server A determines whether the values corresponding to the first index and the second index in the hash table are both 1.
[0063] If both are 1, add this encrypted index item to the candidate set; otherwise, traverse the next encrypted index item and repeat Step 4.2 until all encrypted index items have been traversed.
[0064] Step 4.3: Cloud Server A and Cloud Server B jointly execute a ciphertext-based range filtering algorithm to remove the results with a distance greater than the range threshold from the candidate set, update the ciphertexts in the candidate set, and shuffle the order of the encrypted index items in the candidate set to obtain a query result set in ciphertext form.
[0065] Step 4.4: Cloud Server A returns the query result set to the user via the roadside unit.
[0066] Step 5: The user recovers the query results in plaintext form.
[0067] When receiving the query result set sent by Cloud Server A, the user decrypts the query results to recover the query results in plaintext form.
[0068] Beneficial Effects
[0069] Compared with the prior art, the present invention has the following advantages:
[0070] 1. Strong privacy protection. The method of the present invention uses cryptographic primitives such as symmetric encryption and the PCDD scheme to encrypt the road network graph in plaintext form and encrypt and obfuscate the label range query request in plaintext form. Compared with the existing plaintext-based road network graph label range query schemes in the vehicle networking, the present invention realizes the data privacy protection of the data owner of the road network graph and the query privacy protection of the user.
[0071] 2. Efficient query. According to the characteristics of label range queries for road traffic networks in the vehicle networking scenario, the method of the present invention constructs an efficient range query index and an obfuscated keyword hash table for the road network graph data, realizing efficient label range queries for encrypted road network graphs. Compared with graph privacy protection schemes based on complex cryptographic primitives such as secure multi-party computation, oblivious transfer, and oblivious storage, this scheme realizes efficient queries. Description of the Drawings
[0072] Figure 1 It is a flow schematic diagram of the method of the present invention. Detailed Embodiments
[0073] The present invention will be further described in detail below with reference to the drawings and embodiments.
[0074] Embodiment
[0075] As Figure 1 shown, a method for querying label ranges supporting an encrypted road network graph includes the following steps:
[0076] Step 1: The data owner generates keys and distributes them.
[0077] The data owner first needs to generate a series of keys required for data encryption and query. Here, the data owner has road network graph data, where a graph data can be expressed as G = (V, E), where V represents the set of vertices of the road network graph, and E represents the set of edges of the road network graph. Each point in V has a corresponding keyword, and the set of keywords is W.
[0078] Specifically, it includes the following steps:
[0079] Step 1.1: Randomly generate two keys K0 and K, with a length of 256 bits.
[0080] Step 1.2: Use the public key encryption technology with distributed decryption (hereinafter referred to as the PCDD scheme, which can be referred to in the literature "A Privacy-Preserving Outsourced Functional Computation Framework Across Large-Scale Multiple Encrypted Domains") to generate a strong private key SK and m + 1 public-private key pairs (pk0, sk0), (pk1, sk1),..., (pk m , sk m ), where m is the number of users, pk m represents the public key of the mth user, and sk m represents the private key of the mth user.
[0081] Step 1.3: Send K0, K, and the public-private key pair (pk i , sk i ) of user i to user i through a secure channel, use (pk0, sk0) as the public-private key pair for its own use, and secretly save K0, K, and the private key.
[0082] Step 1.4: Use the strong private key splitting algorithm PCDD.SKeyS of the PCDD scheme to split the strong private key into two partial private keys SK 1 , SK 2 = PCDD.SKeyS(SK). Send pk0, pk1,..., pk m and SK 1 to the cloud server S A, send pk0, pk1, …, pk m and SK 2 to the cloud server S through a secure channel B . The cloud server S here A and the cloud server S B are two independent cloud servers provided by different cloud service providers. Therefore, there is no collusion behavior between these two servers.
[0083] Step 2: The data owner encrypts the road network graph.
[0084] Based on the characteristics of label range queries for road traffic networks in the vehicle networking scenario, to further improve the query efficiency, this method pre - defines a maximum value of the range threshold (e.g., 1000 meters) based on the road network graph data, generates a range index RI, and then encrypts the generated range index using cryptographic primitives. When a user executes a query, as long as the set range threshold is less than the maximum value of the system - set threshold, the label range query result can be obtained efficiently.
[0085] Specifically, it includes the following steps:
[0086] Step 2.1: Initialize an empty encrypted index EI and a confusion keyword hash table H with a value of 0.
[0087] Step 2.2: For each vertex v ∈ V in the vertex set V, find all vertices within a distance not exceeding the given maximum threshold value θ max (e.g., 1000 meters), and construct the query range index RI.
[0088] Step 2.3: Generate the corresponding keyword dictionary D using the vertex set V and the keyword set W. The keyword dictionary gives which keyword in the keyword set W each vertex in V corresponds to.
[0089] Step 2.4: Generate the encrypted index EI. For each vertex v ∈ V in V, generate an encrypted range index item associated with this vertex and add it to the encrypted index.
[0090] Specifically, it includes the following steps:
[0091] Step 2.4.1: Encrypt v using the AES symmetric encryption algorithm AES.Enc with the key K0 generated in Step 1.1 to obtain the encrypted vertex E v = AES.Enc(K0, v).
[0092] Step 2.4.2: Encrypt each range index entry associated with vertex v in the query range index RI. Each such range index entry (u, d) includes the intermediate vertex u and the distance d between u and v.
[0093] Specifically, it includes the following steps:
[0094] Step 2.4.2.1: Encrypt u using the symmetric encryption algorithm with the key K0 generated in Step 1.1 to obtain the encrypted intermediate vertex E u = AES.Enc(K0, u).
[0095] Step 2.4.2.2: Encrypt d using the encryption algorithm PCDD.Enc in the PCDD scheme with the public key pk0 of the data owner generated in Step 1.2 to obtain the encrypted distance D uv = PCDD.Enc(pk0, d).
[0096] Step 2.4.2.3: Take (E u , D) as the encrypted range index entry and add it to the encrypted index EL.
[0097] Step 2.5: Generate the obfuscated keyword hash table H. For each keyword w ∈ W in W, set the index entry associated with the keyword in H to 1.
[0098] Specifically, it includes the following steps:
[0099] Step 2.5.1: Use the keyword and the key K generated in Step 1.1 to calculate the first index key I w = F(K, w || 0) and the second index key K w = F(K, w || 1). Here, F is a secure pseudo-random function that takes as input a 256-bit key and a string of arbitrary length and outputs a 256-bit string, and || is the string concatenation operation.
[0100] Step 2.5.2: For each vertex u′ associated with the keyword in the dictionary D, generate the obfuscated keyword index and set the value corresponding to the index in H to 1. Specifically, it includes the following steps:
[0101] Step 2.5.2.1: Encrypt the vertex using the symmetric encryption algorithm with the key K0 generated in Step 1.1 to obtain the encrypted vertex E u′ = AES.Enc(K0, u′).
[0102] Step 2.5.2.2: Generate the first index h1 = F(I w , E u′ ) and the second index h1 = F(Kw , E u′ ).
[0103] Step 2.5.3.3: Set H[h1] = 1, H[h2] = 1.
[0104] Step 2.6: The data owner sends the encrypted index EI and the obfuscated keyword hash table H to the cloud server S A .
[0105] Step 3: The user generates a tag range query token.
[0106] The user generates a tag range query request q = (s, w, θ), where s represents the source vertex where the user is currently located, w represents the keyword to be queried, and θ is the range threshold, and θ is not greater than the maximum value of the allowed query threshold.
[0107] After that, the user encrypts and obfuscates the query request using the key obtained from the data owner to obtain the query token in ciphertext form.
[0108] Specifically, it includes the following steps:
[0109] Step 3.1: Encrypt s using the symmetric encryption algorithm, and the key is the key K0 generated in Step 1.1 to obtain the encrypted source vertex E s = AES.Enc(K0, s).
[0110] Step 3.2: Use the keyword w and the key K generated in Step 1.1 to calculate the first index key I w = F(K, w||0) and the second index key K w = F(K, w||1), where F is the pseudo-random function defined in Step 2.5.1.
[0111] Step 3.3: Encrypt θ using the encryption algorithm PCDD.Enc in the PCDD scheme, and the key is the public key pk0 of the user sent by the data owner in Step 1.2 to obtain the encrypted range threshold Θ = PCDD.Enc(pk0, θ).
[0112] Step 3.4: Take (E s , I w , K w , Θ) as the query token and send it to the cloud server S through the roadside unit A .
[0113] The roadside unit here is one of the infrastructures in the vehicle-to-everything network. In the present invention, it only plays the role of data forwarding.
[0114] Step 4: The cloud server responds to the query request and returns the query result in ciphertext form.
[0115] After receiving the query token from the user, the two cloud servers cooperate to perform a label range query operation based on the encrypted road network graph, and return the query result in ciphertext form to the user.
[0116] Specifically, it includes the following steps:
[0117] Step 4.1: Cloud server S A Initializes a candidate set tmp, and parses the query token into: (1) the encrypted source vertex E s , (2) the first index key I w , (3) the second index key K w , (4) the encrypted range threshold Θ.
[0118] Step 4.2: Cloud server S A Queries all the encrypted index entries associated with E from the encrypted index EI uploaded by the data owner in Step 2.6, and filters out all the points associated with the keyword. Each encrypted index entry (E s , D t ) contains an encrypted associated vertex E st and an encrypted distance D t . st .
[0119] Specifically, it includes the following steps:
[0120] Step 4.2.1: Use I w and E t to generate the first index h1, h1 = F(I w , E t ). Use K w and E t to generate the second index h2, h2 = F(K w , E t ), where F is the pseudo-random function defined in Step 2.5.1.
[0121] Step 4.2.2: Cloud server S A Based on the obfuscated keyword hash table H uploaded by the data owner in Step 2.6, determines whether both H[h1] = 1 and H[h2] = 1 hold. If both hold, add the encrypted index entry (E t , D st ) to the candidate set tmp. Otherwise, traverse the next encrypted index entry, and repeat Step 4.2 until all encrypted index entries are traversed.
[0122] Step 4.3: Cloud server S A and cloud server S BCooperatively execute the ciphertext-based range filtering algorithm, remove the results with distances greater than the range threshold from the candidate set, update the ciphertexts in the candidate set, and shuffle the order of the encrypted index items in the candidate set to obtain a query result set in ciphertext form.
[0123] Specifically, it includes the following steps:
[0124] Step 4.3.1: For each tag item (E tmp , D tmp ) ∈ tmp, S A Calculate the intermediate result, where E tmp and D tmp represent the encrypted vertex and encrypted distance in the traversed tag item respectively.
[0125] Specifically, it includes the following steps:
[0126] Step 4.3.1.1: Initialize an intermediate result set list.
[0127] Step 4.3.1.2: Generate three random numbers r1, r2 in ciphertext form and satisfy 0 ≤ r3 < r2 < N / d max , where is the set of all non-negative integers less than N, N is a parameter in the PCDD scheme, and d max represents the maximum distance.
[0128] Then, calculate the intermediate value R3 = PCDD.Enc(pk i , r3).
[0129] After that, calculate the perturbed distance and the perturbed threshold using the random numbers and the intermediate value, where · represents the multiplication operation, and pk0 and pk i are the public key of the data owner and the public key of the user sent by the data owner to S A in Step 1.4 respectively.
[0130] Step 4.3.1.3: Use the partial private key SK A sent by the data owner to S 1 in Step 1.4, execute the partial decryption algorithm PCDD.PDec in PCDD, and obtain the partially decrypted distance D′ (1) = PCDD.PDec(D′, SK 1 ) and the threshold Θ′ (1) = PCDD.PDec(Θ′, SK 1 ).
[0131] Step 4.3.1.4: Use pk i to re-encrypt E, obtaining the re-encrypted result E' = PCDD.Enc(pk i , E).
[0132] Step 4.3.1.5: Add (E', D', Θ', D' (1) , Θ' (1) ) to list.
[0133] Step 4.3.2: S A Send list to S B .
[0134] Step 4.3.3: S B Judge whether the distance value corresponding to each entry (E', D', Θ', D' (1) , Θ' (1) ) in list is less than the threshold. After updating the ciphertext vertex information corresponding to the entries that meet the conditions, add them to the query result list Res.
[0135] Specifically: It includes the following steps:
[0136] Step 4.3.3.1: Use the partial private key SK B sent by the data owner to S in Step 1.4 2 , execute the partial decryption algorithm PCDD.PDec in PCDD to obtain the partially decrypted distance D' (2) = PCDD.PDec(D', SK 2 ) and the threshold Θ' (2) = PCDD.PDec(Θ', SK 2 ). Then execute the distributed decryption algorithm PCDD.DDec in PCDD to obtain the fully decrypted distance d' = PCDD.DDec(D' (1) , D' (2) ) and the threshold θ' = PCDD.DDec(Θ' (1) , Θ' (2) ). At this time, the decrypted distance d' and threshold θ' are perturbed in Step 4.3.1.2, so the original distance d and threshold θ will not be leaked to the cloud server.
[0137] Step 4.3.3.2: Judge whether d' ≤ θ' holds. If it is less than the threshold, use the ciphertext update algorithm PCDD.CR in PCDD to re-encrypt E', obtaining the re-encrypted ciphertext vertex information E'' = PCDD.CR(pk i , E'), and add it to Res.
[0138] Step 4.3.4: SB Randomly shuffle the elements in Res, and send the shuffled query result list Res′ to S A .
[0139] Step 4.4: Cloud server S A Return the query result set Res′ to the user through the roadside unit.
[0140] Step 5: The user restores the query result in plaintext form.
[0141] After receiving the query result set sent by cloud server A, the user decrypts the query result to restore the query result in plaintext form. Specifically, the user executes the decryption algorithm PCDD.Dec in PCDD to decrypt the vertex information E″ in the query result list, and obtains the decrypted result E′ = PCDD.Dec(sk, E″), where sk is the private key sent by the data owner to the user in step 1.4. Then, execute the AES decryption algorithm to decrypt E′ again to restore the query result E in plaintext form, where K0 is the key sent by the data owner to the user in step 1.4, and AES.Dec is the AES decryption algorithm.
[0142] To illustrate the content and implementation method of the present invention, the above specific embodiments are given in this specification. However, those skilled in the art should understand that the present invention is not limited to the above best implementation manner, and anyone can obtain other various forms of products under the inspiration of the present invention. However, no matter what changes are made in its shape or structure, as long as it has the same or similar technical solutions as this application, it falls within the protection scope of the present invention.
Claims
1. A method for querying label ranges that supports encrypted road network diagrams, characterized in that, It includes the following steps: Step 1: The data owner generates keys and distributes them; The data owner has the road network graph data, which is represented as G = (V, E). V represents the vertex set of the road network graph, and E represents the edge set of the road network graph. Each point in V has a corresponding keyword, and the set of keywords is W; Step 1.1: The data owner randomly generates two keys K0 and K; Step 1.2: Adopt a public key encryption scheme with distributed decryption, abbreviated as the PCDD scheme, to generate a strong private key and m + 1 public-private key pairs, where m represents the number of users; Step 1.3: Send K0, K, and the i-th public-private key pair to user i through a secure channel; use the (m + 1)-th public-private key pair as the public-private key pair for its own use, and secretly save K0, K, and the private key; Step 1.4: Use the strong private key splitting algorithm of the PCDD scheme to split the strong private key into two partial private keys; send all m + 1 public keys generated in Step 1.2 and the first partial private key obtained by splitting in Step 1.3 to cloud server A through a secure channel, and send m + 1 public keys and the second partial private key to cloud server B through a secure channel; among them, cloud server A and cloud server B are two independent cloud servers; Step 2: The data owner encrypts the road network graph; A maximum value of a range threshold is given in advance to generate a range index RI; then, use cryptographic primitives to encrypt the generated range index; when the user executes a query, as long as the range threshold set by it is less than the maximum value of the threshold set by the system; Step 2.1: Initialize an empty encrypted index and a confused keyword hash table with a value of 0; Step 2.2: For each vertex in the vertex set V of the road network graph data G, find all vertices whose distance from this vertex does not exceed the given maximum threshold value, and construct a range index RI; Step 2.3: Use the vertex set V and the keyword set W to generate a corresponding keyword dictionary D; the keyword dictionary D shows which keyword in the keyword set W each vertex in V corresponds to; Step 2.4: Generate an encrypted index; For each vertex v ∈ V in the vertex set V, generate an encrypted range index item associated with this vertex v, and add it to the encrypted index; Step 2.5: Generate a confused keyword hash table; For each keyword in the keyword set W, set the index item associated with this keyword in the confused keyword hash table to 1; Step 2.6: The data owner sends the encrypted index and the confused keyword hash table to cloud server A; Step 3: The user generates a label range query token; The user generates a label range query request q, q = (s, w, θ), where s represents the source vertex where the user is currently located, w represents the keyword to be queried, θ is the range threshold, and θ is not greater than the maximum allowed query threshold value; then, the user encrypts and confuses the query request using the key obtained from the data owner to obtain a query token in ciphertext form; Step 4: The cloud server responds to the query request and returns a query result in ciphertext form; After receiving the query token from the user, two cloud servers A and B cooperate to perform a label range query operation based on the encrypted road network graph, and return the query results in ciphertext form to the user; Step 5: The user recovers the query results in plaintext form; When receiving the query result set sent by cloud server A, the user decrypts the query results to recover the query results in plaintext form.
2. The method for querying the label range of a road network diagram supporting encryption as claimed in claim 1, wherein, Step 2.4 includes the following steps: Step 2.4.1: Encrypt the vertex v using a symmetric encryption algorithm with the key K0 generated in Step 1.1 to obtain the encrypted vertex; Step 2.4.2: Encrypt each range index item associated with the vertex v in the range index RI; each range index item includes the intermediate vertex u and the distance d between u and v.
3. The method for querying label range of an encrypted road network graph according to claim 2, wherein, Step 2.4.2 includes the following steps: Step 2.4.2.1: Encrypt the intermediate vertex u using a symmetric encryption algorithm with the key K0 generated in Step 1.1 to obtain the encrypted intermediate vertex; Step 2.4.2.2: Encrypt the distance d using the encryption algorithm in the PCDD scheme with the public key of the data owner generated in Step 1.1 to obtain the encrypted distance; Step 2.4.2.3: Use the encrypted intermediate vertex and the encrypted distance as the encrypted range index item and add it to the encrypted index.
4. The method for querying label range of a road network graph supporting encryption as claimed in claim 1, wherein Step 2.5 includes the following steps: Step 2.5.1: Use the keyword and the key K generated in Step 1.3 to calculate the first index key and the second index key; Step 2.5.2: Generate a confused keyword index for each vertex associated with the keyword in the dictionary D, and set the value corresponding to the index in the confused keyword hash table to 1.
5. The method for querying the label range of a road network diagram supporting encryption as claimed in claim 4, wherein, Step 2.5.2 includes the following steps: Step 2.5.2.1: Encrypt the vertex using a symmetric encryption algorithm with the key K0 generated in Step 1.1 to obtain the encrypted vertex; Step 2.5.2.2: Generate the first index using the first index key and the encrypted vertex, and generate the second index using the second index key and the encrypted vertex; Step 2.5.3.3: Set the values corresponding to the first index and the second index in the confused keyword hash table to 1.
6. The method for querying label range of a road network graph supporting encryption as claimed in claim 4, wherein, Step 3 includes the following steps: Step 3.1: Encrypt the source vertex s using a symmetric encryption algorithm with the key K0 generated in Step 1.1 to obtain the encrypted source vertex; Step 3.2: Use the keyword w and the key K generated in Step 1.1 to calculate the first index key and the second index key; Step 3.3: Encrypt the range threshold θ using the encryption algorithm in the PCDD scheme with the public key of the user sent by the data owner in Step 1.3 to obtain the encrypted range threshold; Step 3.4: Use "the encrypted source vertex, the first index key, the second index key, the encrypted range threshold" as the query token and send it to cloud server A.
7. The method for querying label ranges of a road network graph supporting encryption according to claim 4, wherein, Step 4 includes the following steps: Step 4.1: Cloud server A initializes a candidate set and parses the query token into: the encrypted source vertex, the first index key, the second index key, the encrypted range threshold; Step 4.2: Cloud server A queries all the encrypted index entries associated with the encrypted source vertices from the encrypted index uploaded by the data owner in Step 2.6, and filters out all the points associated with the keyword; each encrypted index entry contains an encrypted associated vertex and an encrypted distance.
8. The method for querying label ranges of an encrypted road network graph according to claim 7, wherein Step 4.2 includes the following steps: Step 4.2.1: Generate a first index using the first index key obtained in Step 4.1 and the encrypted associated vertex; generate a second index using the second index key obtained in Step 4.1 and the encrypted associated vertex; Step 4.2.2: Cloud server A determines whether the values corresponding to the first index and the second index in the hash table are both 1 based on the obfuscated keyword hash table uploaded by the data owner in Step 2.6; If both are 1, add the encrypted index entry to the candidate set, otherwise traverse the next encrypted index entry, and repeat Step 4.2 until all encrypted index entries are traversed; Step 4.3: Cloud server A and cloud server B jointly execute a ciphertext-based range filtering algorithm, remove the results with distances greater than the range threshold from the candidate set, update the ciphertexts in the candidate set, and shuffle the order of the encrypted index entries in the candidate set to obtain a query result set in ciphertext form; Step 4.4: Cloud server A returns the query result set to the user through the roadside unit.