A Privacy-Preserving Skyline Query Method and System

Through the additive secret sharing technology, the privacy protection of Skyline query is achieved in the cloud computing environment, and the problem of lack of privacy protection in the existing technology is solved, the security of database content and query results is ensured, and efficient privacy protection is achieved.

CN115186295BActive Publication Date: 2025-07-08HARBIN INST OF TECH SHENZHEN GRADUATE SCHOOL
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210819670.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-13
Publication Date
2025-07-08
Estimated Expiration
2042-07-13

AI Technical Summary

Technical Problem

The lack of privacy protection in the existing technology Skyline query method leads to a high risk of leaking database privacy information in cloud computing environments.

Method used

Adopting additive secret sharing technology, through the collaborative operation of the first computing terminal and the second computing terminal, the original database and query content are encrypted, and database mapping, Skyline tuple acquisition and controlled tuple removal are carried out safely to ensure that the dominant relationship between database content and tuple is not disclosed during the query process.

Benefits of technology

It realizes the privacy protection of Skyline queries in the cloud computing environment, ensures that the database content, query content and query results are not leaked, and protects the confidentiality of the data mode.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115186295B_ABST
    Figure CN115186295B_ABST
Patent Text Reader

Abstract

The present invention discloses a privacy - protected Skyline query method and system. In the method provided by the present invention, lightweight encryption technology is used to encrypt the original database and query content, and secure database mapping, secure Skyline tuple acquisition, and secure elimination of Skyline and dominated tuples can be achieved. During the Skyline query process, the first computing terminal and the second computing terminal do not obtain the original database content, query tuples, and query results, nor do they obtain the dominance relationship between the tuples of the database, realizing an efficient privacy - protected Skyline query.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and particularly to a privacy protection Skyline query method and system. Background Art

[0002] Due to various advantages of cloud computing, more and more enterprises rely on commercial cloud platforms for database management and query. However, the database may contain a large amount of privacy-sensitive information (such as medical records or financial database records), and deploying such database query services in the cloud may bring serious privacy concerns. Therefore, it is urgent to embed privacy protection into such database outsourcing query services to ensure that database information, query content, and query results are not leaked.

[0003] Skyline query is widely used in multi-criteria decision-making systems in different fields, such as website information systems, wireless mobile ad hoc networks, and geographic information systems. Especially when it is very difficult to quantify the weight of each dimension, Skyline query can filter out data in the database that has no advantage in any dimension, reducing the decision-making complexity of users. For a given query point (which can be a tuple), Skyline query aims to retrieve a set of data points (called the Skyline point set), where each data point is a data point that is not dominated by other data points in this multi-dimensional database. However, in the prior art, there is no Skyline query method that can achieve privacy protection.

[0004] Therefore, the prior art still needs to be improved. Summary of the Invention

[0005] In view of the above-mentioned defects of the prior art, the present invention provides a privacy protection Skyline query method and system, aiming to solve the problem that there is no Skyline query method that can achieve privacy protection in the prior art.

[0006] To solve the above technical problems, the technical solutions adopted by the present invention are as follows:

[0007] In the first aspect of the present invention, a privacy protection Skyline query method is provided, and the method includes:

[0008] Based on additive secret sharing, the first computing terminal and the second computing terminal obtain the additive secret sharing share of the mapped database according to the additive secret sharing share of the query tuple held locally and the additive secret sharing share of the original database, where the k-th value in the i-th tuple of the mapped database is the absolute value of the difference between the k-th attribute value of the i-th tuple in the original database and the k-th attribute value of the query tuple;

[0009] The first computing terminal and the second computing terminal obtain an additive secret sharing share of a first comparison result based on additive secret sharing. The first comparison result is a comparison result of the sum of attributes of tuples in the mapping database. The first computing terminal and the second computing terminal obtain an additive secret sharing share of the smallest sum of attributes in the mapping database based on the additive secret sharing share of the first comparison result, where the sum of attributes of a tuple is the sum of each value in the tuple;

[0010] The first computing terminal and the second computing terminal obtain an additive secret sharing share of a Skyline tuple in the mapping database and an additive secret sharing share of a Skyline tuple in the original database according to the first comparison result, and add the additive secret sharing share of the Skyline tuple in the original database to the query result set;

[0011] The first computing terminal and the second computing terminal obtain an additive secret sharing share of a second comparison result between the smallest sum of attributes in the mapping database and a preset maximum value. The first computing terminal and the second computing terminal exchange the additive secret sharing shares of the second comparison result held locally to obtain the plaintext information of the second comparison result;

[0012] If the plaintext information is that the smallest sum of attributes in the mapping database is less than the preset maximum value, the first computing terminal and the second computing terminal respectively obtain an additive secret sharing share of the first identification information and the second identification information of the tuples in the mapping database based on additive secret sharing according to the additive secret sharing share of the Skyline tuple in the mapping database, where the first identification information is used to distinguish a Skyline tuple in the mapping database from other tuples, and the second identification information is used to distinguish the first tuple and the second tuple in the mapping database. The first tuple is a Skyline tuple or a tuple dominated by a Skyline tuple, and the second tuple is neither a Skyline tuple nor a tuple dominated by a Skyline tuple;

[0013] The first computing terminal and the second computing terminal update the additive secret sharing share of the sum of attributes of the tuple dominated by the Skyline tuple and a Skyline tuple in the mapping database based on the additive secret sharing shares of the second identification information and the first identification information held locally, so that the sum of attributes of the tuple dominated by the Skyline tuple and a Skyline tuple in the mapping database is the preset maximum value;

[0014] The first computing terminal and the second computing terminal repeatedly execute the step of obtaining the additive secret sharing shares of the first comparison result based on additive secret sharing until the plaintext information is the smallest attribute in the mapping database and not less than the preset maximum value.

[0015] The privacy-preserving Skyline query method, wherein the first computing terminal and the second computing terminal obtain the additive secret sharing shares of the mapping database based on additive secret sharing according to the additive secret sharing shares of the query tuples held locally and the additive secret sharing shares of the original database, including:

[0016] The first computing terminal and the second computing terminal perform the following operations to obtain a and b the additive secret sharing share of the absolute value of the difference:

[0017] The first computing terminal and the second computing terminal calculate a first difference based on additive secret sharing, such that the first computing terminal holds one additive secret sharing share of the first difference, and the second computing terminal holds the other additive secret sharing share of the second difference, wherein the first difference is a minus b the obtained difference;

[0018] The first computing terminal and the second computing terminal calculate a second difference based on additive secret sharing, such that the first computing terminal holds one additive secret sharing share of the second difference, and the second computing terminal holds the other additive secret sharing share of the second difference, wherein the second difference is b minus a the obtained difference;

[0019] The first computing terminal and the second computing terminal obtain a and b the Boolean additive secret sharing share of the most significant bit of the comparison result bit data, wherein when a < b , a and b the most significant bit of the comparison result is 1, and when a ≥ b, the most significant bit of the comparison result of a and b is 0;

[0020] The first computing terminal and the second computing terminal calculate a first preset formula based on additive secret sharing to obtain a and b the additive secret sharing share of the absolute value of the difference;

[0021] The first preset formula is:

[0022]

[0023] Among them, represents the negation operation. When is the case, , when is the case, ;

[0024] When calculating the first preset formula based on additive secret sharing, the first computing terminal and the second computing terminal perform two rounds of calculations. In the case where the first computing terminal and the second computing terminal respectively hold two Boolean additive secret sharing shares of x, and the first computing terminal and the second computing terminal respectively hold two arithmetic additive secret sharing shares of y, an additive secret sharing share of the product of x and y is obtained;

[0025] Among them, in the first round of calculation, the first computing terminal is the sender and the second computing terminal is the receiver. In the second round of calculation, the first computing terminal is the receiver and the second computing terminal is the sender;

[0026] In each round of calculation, the sender generates a random number , and calculates the message . After that, the sender saves the random number and sends to the receiver. Among them, is the Boolean additive secret sharing share of x locally saved by the sender, and is the arithmetic additive secret sharing share of y locally saved by the sender;

[0027] The receiver determines whether the Boolean additive secret sharing share locally saved is 0. If so, it saves , if not, it saves ;

[0028] After two rounds of calculation, the first computing terminal / the second computing terminal sums the locally generated random number and the saved message to respectively obtain x and y an additive secret sharing share of the product of.

[0029] The privacy-preserving Skyline query method described above, where the first computing terminal and the second computing terminal obtain a and b the most significant bit of the bit data of the comparison result of, including:

[0030] The first computing terminal and the second computing terminal convert the additive secret sharing shares of the first difference held locally into bit data, and perform calculations through a parallel prefix adder circuit so that the first computing terminal obtains a and b a Boolean additive secret sharing share of the most significant bit of the bit data of the comparison result, and the second computing terminal obtains a and b another Boolean additive secret sharing share of the most significant bit of the comparison result.

[0031] The privacy-preserving Skyline query method, wherein the first computing terminal and the second computing terminal obtain the additive secret sharing share of the smallest sum of attributes in the mapping database based on the additive secret sharing share of the first comparison result, including:

[0032] The first computing terminal and the second computing terminal obtain a and b the additive secret sharing share of the minimum value between them through the following operations:

[0033] The first computing terminal and the second computing terminal obtain a and b a Boolean additive secret sharing share of the most significant bit of the bit data of the comparison result, wherein when a < b the most significant bit of the comparison result of a and b is 1, and when a ≥ b the most significant bit of the comparison result of a and b is 0;

[0034] The first computing terminal and the second computing terminal respectively obtain two additive secret sharing shares of a first product based on additive secret sharing, and the first computing terminal and the second computing terminal respectively obtain two additive secret sharing shares of a second product based on additive secret sharing, wherein the first product is a and b the product of the most significant bit of the comparison result and a , and the second product a and b the product of the inverted value of the comparison result and b ;

[0035] The first computing terminal and the second computing terminal respectively obtain two additive secret sharing shares of the sum of the first product and the second product as a and bThe additive secret sharing share of the minimum value in

[0036] The privacy-preserving Skyline query method described above, wherein the first computing terminal and the second computing terminal obtain the additive secret sharing share of a Skyline tuple in the mapping database and the additive secret sharing share of a Skyline tuple in the original database according to the first comparison result, including:

[0037] The first computing terminal and the second computing terminal perform the following operations in each iteration:

[0038] Select a tuple in the mapping database as the first tuple, and the first computing terminal and the second computing terminal obtain the boolean additive secret sharing share of the most significant bit of the comparison result of the sum of the attributes corresponding to the current first target tuple and the first tuple;

[0039] The first computing terminal and the second computing terminal respectively obtain two additive secret sharing shares of a third product and two additive secret sharing shares of a fourth product based on additive secret sharing, wherein the third product is the product of the most significant bit of the comparison result of the sum of the attributes corresponding to the current first target tuple and the first tuple and the first target tuple, and the fourth product is the product of the inverted value of the most significant bit of the comparison result of the sum of the attributes corresponding to the current first target tuple and the first tuple and the first tuple;

[0040] The first computing terminal and the second computing terminal respectively obtain two additive secret sharing shares of the sum of the third product and the fourth product as the additive secret sharing share of the updated first target tuple based on additive secret sharing;

[0041] Select a tuple in the original database as the second tuple, and the first computing terminal and the second computing terminal obtain the boolean additive secret sharing share of the most significant bit of the comparison result of the sum of the attributes corresponding to the second tuple and the current second target tuple;

[0042] The first computing terminal and the second computing terminal respectively obtain two additive secret sharing shares of a fifth product and two additive secret sharing shares of a sixth product based on additive secret sharing, wherein the fifth product is the product of the most significant bit of the comparison result of the sum of the attributes corresponding to the current second target tuple and the second tuple and the second target tuple, and the sixth product is the product of the inverted value of the most significant bit of the comparison result of the sum of the attributes corresponding to the current second target tuple and the second tuple and the second tuple;

[0043] The first computing terminal and the second computing terminal respectively obtain two additive secret sharing shares of the sum of the fifth product and the sixth product based on additive secret sharing as the additive secret sharing shares of the updated second target tuple.

[0044] After each tuple in the mapping database / the original database has participated in the above iterative calculation, the first computing terminal and the second computing terminal use the latest additive secret sharing shares of the first target tuple held locally as the additive secret sharing shares of a Skyline tuple in the mapping database, and use the latest additive secret sharing shares of the second target tuple held locally as the additive secret sharing shares of a Skyline tuple in the original database.

[0045] The privacy-preserving Skyline query method, wherein the first computing terminal and the second computing terminal respectively obtain the additive secret sharing shares of the second identification information of the tuples in the mapping database based on additive secret sharing according to the additive secret sharing shares of the Skyline tuples in the mapping database, including:

[0046] For a target tuple in the mapping database, the first computing terminal and the second computing terminal perform the following operations to obtain the second identification information of the target tuple:

[0047] The first computing terminal and the second computing terminal obtain the comparison results of each value of the target tuple and the corresponding value of the latest first target tuple.

[0048] The first computing terminal and the second computing terminal obtain the boolean additive secret sharing share of the exclusive OR operation result of the negated values of all comparison results of each value of the target tuple and the corresponding value of the latest first target tuple as the additive secret sharing share of the second identification information of the target tuple.

[0049] The privacy-preserving Skyline query method, wherein the first computing terminal and the second computing terminal respectively obtain the additive secret sharing shares of the first identification information of the tuples in the mapping database based on additive secret sharing according to the additive secret sharing shares of the Skyline tuples in the mapping database, including:

[0050] For each target tuple in the mapping database, the first computing terminal and the second computing terminal perform the following operations to obtain the first identification information of the target tuple:

[0051] The first computing terminal and the second computing terminal obtain the boolean additive secret sharing share of the comparison result between the minimum attribute sum in the mapping database and the attribute sum of the target tuple;

[0052] The first computing terminal negates the boolean additive secret sharing share of the comparison result between the minimum attribute sum in the mapping database held locally and the attribute sum of the target tuple, to obtain the boolean additive secret sharing share of the third identification information of the target tuple, and the second computing terminal uses the boolean additive secret sharing share of the comparison result between the minimum attribute sum in the mapping database held locally and the attribute sum of the target tuple as the boolean additive secret sharing share of the third identification information of the target tuple;

[0053] The first computing terminal and the second computing terminal obtain the boolean additive secret sharing share of the AND operation result of the negated value of the current marking information and the third identification information, as the boolean additive secret sharing share of the first identification information of the target tuple;

[0054] The first computing terminal and the second computing terminal obtain the XOR operation result of the current marking information and the first identification information of the target tuple to update the marking information for use in the first identification information of the next tuple in the mapping database.

[0055] The privacy-preserving Skyline query method, wherein the first computing terminal and the second computing terminal update the additive secret sharing share of the sum of the attributes of the tuples dominated by the Skyline tuples and a Skyline tuple in the mapping database based on the additive secret sharing shares of the second identification information and the first identification information held locally, so that the sum of the attributes of the tuples dominated by the Skyline tuples and a Skyline tuple in the mapping database is the preset maximum value, including:

[0056] The first computing terminal and the second computing terminal obtain the boolean additive secret sharing share of the elimination flag based on the additive secret sharing shares of the first identification information, the second identification information, and the third identification information held locally, and the elimination flag is used to mark a Skyline tuple and the tuples dominated by the Skyline tuple in the mapping database;

[0057] For each tuple in the mapping database, the first computing terminal and the second computing terminal perform the following operations:

[0058] The first computing terminal and the second computing terminal obtain additive secret sharing shares of a seventh product and an eighth product, where the seventh product is the product of the sum of the attributes of the tuple and the negation value of the elimination flag, and the eighth product is the product of the elimination flag of the tuple and the preset maximum value;

[0059] The first computing terminal and the second computing terminal update the additive secret sharing share of the sum of the attributes of the tuple in the mapping database held this time to the additive secret sharing share of the sum of the seventh product and the eighth product.

[0060] The privacy - protected Skyline query method, wherein the first computing terminal and the second computing terminal obtain a boolean additive secret sharing share of an elimination flag based on the additive secret sharing shares of the first identification information, the second identification information, and the third identification information held locally, including:

[0061] The first computing terminal and the second computing terminal obtain a boolean additive secret sharing share of fourth marker information, where the fourth marker information is the result of the AND operation of the negation values of the second identification information and the third identification information;

[0062] The first computing terminal and the second computing terminal obtain a boolean additive secret sharing share of the exclusive - OR operation result of the first identification information and the fourth identification information as the boolean additive secret sharing share of the elimination flag.

[0063] In a second aspect of the present invention, a privacy - protected Skyline query system is provided. The system includes a first computing terminal and a second computing terminal, and the first computing terminal and the second computing terminal cooperate to complete the privacy - protected Skyline query method described in any one of the above.

[0064] Compared with the prior art, the present invention provides a privacy - protected Skyline query method and system. In the privacy - protected Skyline query method, lightweight encryption technology is used to encrypt the original database and the query content, and secure database mapping, secure Skyline tuple acquisition, and secure Skyline and dominated tuple elimination can be achieved. During the Skyline query process, the first computing terminal and the second computing terminal do not obtain the original database content, query tuples, and query results, nor do they obtain the domination relationship between the tuples of the database, realizing an efficient privacy - protected Skyline query. BRIEF DESCRIPTION OF THE DRAWINGS

[0065] Figure 1 It is a flowchart of an embodiment of the privacy - protected Skyline query method provided by the present invention;

[0066] Figure 2 Schematic illustration of the Skyline query example Figure 1 ;

[0067] Figure 3 Schematic illustration of the Skyline query example Figure 2 ;

[0068] Figure 4 Schematic illustration of the Skyline query example Figure 3 ;

[0069] Figure 5 Schematic algorithm diagram of the plaintext Skyline query method;

[0070] Figure 6 Schematic diagram of the interaction framework of the parties in the privacy - protected Skyline query method provided by the present invention;

[0071] Figure 7 Schematic diagram of the parallel prefix adder in the embodiment of the privacy - protected Skyline query method provided by the present invention;

[0072] Figure 8 Schematic algorithm diagram of the secure database mapping in the embodiment of the privacy - protected Skyline query method provided by the present invention;

[0073] Figure 9 Schematic algorithm diagram of securely obtaining Skyline tuples in the embodiment of the privacy - protected Skyline query method provided by the present invention;

[0074] Figure 10 Schematic algorithm diagram of securely eliminating Skyline tuples and dominated tuples from the mapped database in the embodiment of the privacy - protected Skyline query method provided by the present invention;

[0075] Figure 11 Schematic diagram of the algorithm of the complete process in the embodiment of the privacy - protected Skyline query method provided by the present invention. Detailed implementation manners

[0076] To make the objectives, technical solutions and effects of the present invention clearer and more definite, the following further elaborates the present invention with reference to the accompanying drawings and by way of examples. It should be understood that the specific examples described herein are only used to explain the present invention and are not used to limit the present invention.

[0077] The present invention provides a privacy - protected Skyline query method, aiming to implement Skyline query in a privacy - protected manner. The method provided by the present invention can be used for privacy - protected Skyline query of encrypted databases outsourced to cloud servers. First, a brief description of Skyline query is given below.

[0078] First, the definition of domination is given. Given a database and a query tuple , where has the same dimension as other tuples in the database. For two tuples and in the database, if and only if for any dimension , it satisfies , and there exists at least one dimension that satisfies , then dominates the vector . Based on the query tuple , the Skyline tuples are those that are not dominated by any other tuples. Suppose a medical institution outsources its medical record database to a cloud server to share their medical records and treatment plans. Figure 2 describes the original database , where each piece of data (i.e., tuple) represents the health index record of a patient, including respiratory rate (R) and heart rate (H). A doctor who does not belong to this institution hopes to retrieve medical records similar to one of his patients ( ) in . For this purpose, the doctor submits a query to the cloud server. After receiving , the cloud server first maps each piece of data in the original database Figure 3 (i.e., ) to a new database , and the mapping function [15,16] used is . Then, the cloud server finds the Skyline point set in , where is not dominated by other data points in . Finally, the returned medical records (i.e., the target Skyline points) are and because can dominate but cannot dominate and dominates Figure 4 . Figure 4Describes the dominance relationship in this example.

[0079] As Figure 5 shown, the Skyline query process in the plaintext domain is as follows:

[0080] Given an original database and a query tuple , the first step is to map the original database based on to a new database (called the mapped database), that is, Figure 5 lines 1-6 in the algorithm. Then for each tuple in this initial mapped database (denoted as ), calculate the sum of all its attributes, that is, Figure 5 lines 7-9 in the algorithm. Then after multiple rounds of executing Figure 5 lines 12-16 in the algorithm, Skyline tuples are successively selected from the mapped database. In the ( ) round, using the current mapped database as the input, select a with the smallest attribute sum from as the Skyline tuple. The tuple in the original database corresponding to is added to the Skyline result. Then, the Skyline tuple and the tuples it dominates will be deleted from , and the deleted mapped database is denoted as , which will be used as the input for the next round. This process is repeated multiple times until the mapped database is empty.

[0081] The problem to be solved by the method provided by the present invention is how to securely perform Skyline queries on an encrypted database. Taking the above application scenario as an example, the result obtained by the method provided by the present invention is that the cloud server with the encrypted database generates an encrypted Skyline query result . In addition to ensuring the security of the data content, it is also necessary to ensure that the data pattern is not leaked. The data pattern includes the dominance relationship between data points in the database, the number of data points dominated by each Skyline point in the database, and the search access pattern, and this information will indirectly leak the data. Among them, the search access pattern includes the search pattern and the access pattern. The search pattern reveals whether a new Skyline query has appeared before, and the access pattern reveals which specific data point in the database is a Skyline point, that is, which data point will appear in the query result.

[0082] To achieve the above effects, additive secret sharing is adopted in the present invention to implement encryption operations. Additive secret sharing is a lightweight encryption technology that can support some secure computations. Given a private data , based on additive secret sharing under the setting of two parties, is divided into two secret sharing shares , and . When , in the field, , this form is called arithmetic sharing. When , in the field, , this form is called boolean sharing. These two shares are separately held by two parties and respectively. Each individual share cannot infer , ensuring the security of subsequent computations. In the following text, and are used to represent arithmetic sharing and boolean sharing respectively. When holding the secret sharing values of two private data and , two parties and can securely perform some basic operations. This patent uses arithmetic sharing to elaborate on the secure computation process. The only difference between boolean sharing and arithmetic sharing is that the addition or subtraction of arithmetic sharing becomes the "exclusive OR " of boolean sharing, and the multiplication of arithmetic sharing becomes the "AND " of boolean sharing. In the following text, for the sake of simplicity in description, for those that are not specifically indicated as boolean additive secret sharing shares but are only called additive secret sharing shares, they are all arithmetic additive secret sharing shares.

[0083] Specifically, the addition or subtraction of two secret sharing values and only needs to be calculated locally by the parties, that is, . The scalar multiplication between a public value and a secret sharing value also only needs to be calculated locally by the parties, that is, . Different from these two operations, the multiplication between two secret sharing values and requires one round of online communication. For example, to calculate , where , parties and need to additionally use a set of pre-prepared secret sharing Beaver triples ( ), where . Each participant first locally computes , , and then publicly discloses its and secret sharing shares to the other party. Then, and respectively locally compute and to obtain the sharing value. For the sake of convenience of expression, it is written as in the following text to represent this multiplication.

[0084] Example 1

[0085] In an embodiment of the present invention, a privacy-preserving Skyline query method is provided. By using lightweight encryption technology to encrypt the database and query content, the encryption process can be completed quickly, while ensuring that the database content, query content, and query results are not leaked, and also ensuring the confidentiality of the data pattern during the query process.

[0086] As Figure 6 shown, in the system structure applicable to the method provided in this embodiment, there are three types of entities: data owners, clients, and cloud servers. The data owner can be an organization (for example, a medical institution), and they own the database and want to provide Skyline query services to clients (such as doctors in a hospital). Considering the benefits of using cloud computing, the data owner intends to store the database on the cloud server, and then the cloud server provides Skyline query services for the client. Considering the privacy and security of the data, in this cloud service, the security of the database , query tuple and the query result must be guaranteed. In order to be compatible with the working paradigm of additive secret sharing, the cloud computing part in the method provided in this embodiment is divided into two cloud servers (denoted as and ), i.e., two cloud servers perform collaborative computing as two computing terminals, and these cloud servers can be hosted by independent cloud service providers in practice. The method provided in this embodiment realizes an efficient privacy-preserving Skyline query on an encrypted cloud database. In this system, the data owner and the client are regarded as two trusted parties, and the two cloud servers, i.e., the two computing terminals, are semi-trusted and non-collusive. Among them, semi-trusted means that each cloud server honestly executes the method provided in this embodiment, but may attempt to obtain privacy information during the execution of the query. Non-collusive means that the two cloud servers will not communicate information to jointly speculate on the content of the privacy data. By performing Skyline queries through the method provided in this embodiment, it is possible to prevent the cloud servers from obtaining (i) the content of the database the content of the query tuple the content of the query and the result of the query , (ii) the dominance relationship between database tuples, (iii) the number of tuples dominated by each Skyline tuple in the database, and (iv) the search access pattern. The search pattern reveals whether a new Skyline query has been submitted before, and the access pattern reveals which database tuples are Skyline tuples.

[0087] In the initialization phase, the data owner uses arithmetic additive secret sharing to fully encrypt each tuple in the original database and generates . Then, the data owner sends the secret sharing shares and to the two computing terminals and respectively. Subsequently, in the online query phase, the client first encrypts its Skyline query tuple through arithmetic sharing and sends the secret sharing shares and to the first computing terminal and the second computing terminal respectively. For the convenience of description, this patent will use to represent the computing terminals and subsequently. After receiving the encrypted query , performs a secure Skyline query securely on according to the protocol designed in this patent.

[0088] To enable to perform a secure Skyline query, the present invention decomposes the entire process into the following modules and realizes the Skyline query through corresponding customized security components. The specific introduction of the modules is as follows:

[0089] Secure database mapping secMap. Given an encrypted database and a query , the present invention provides secMap to securely map the encrypted original database to an encrypted mapped database based on for subsequent privacy-preserving Skyline tuple acquisition.

[0090] Secure Skyline tuple acquisition secFetch. Based on the current encrypted mapped database, the present invention provides secFetch to allow securely obtaining Skyline tuples from the current mapped database without knowing which tuple in its corresponding . At the same time, secFetch allows securely obtaining from the original database the corresponding Skyline tuples without knowing which tuple in its corresponding and adding them to the encrypted Skyline result set .

[0091] Secure Skyline and dominated tuple elimination secElim. Given and , the present invention provides secElim to securely eliminate and the tuples dominated by , and ensure not knowing which tuples they are in and the number of tuples dominated by .

[0092] As Figure 1 shown, the method includes the steps of:

[0093] S100. The first computing terminal and the second computing terminal obtain the additive secret sharing share of the mapped database based on additive secret sharing according to the additive secret sharing shares of the query tuples and the original database held locally, where the k-th value in the i-th tuple in the mapped database is the absolute value of the difference between the k-th attribute value of the i-th tuple in the original database and the k-th attribute value of the query tuple.

[0094] The first computing terminal and the second computing terminal cooperate to perform operations in the secret sharing domain to achieve secure database mapping, and obtain the additive secret sharing shares of the mapped database. In this specification, the first computing terminal and the second computing terminal obtaining the additive secret sharing shares of a certain data means that the first computing terminal and the second computing terminal each obtain an additive secret sharing share of this data.

[0095] It can be seen from the plaintext algorithm of the Skyline query that to securely obtain the additive secret sharing shares of the mapped database, it is necessary to obtain the absolute value of the difference between each value in each tuple of the original database and the corresponding value of the query tuple. The first computing terminal and the second computing terminal obtain the additive secret sharing shares of the mapped database based on additive secret sharing, according to the additive secret sharing shares of the query tuple and the additive secret sharing shares of the original database held locally, including:

[0096] The first computing terminal and the second computing terminal perform the following operations to obtain a and b the additive secret sharing share of the absolute value of the difference:

[0097] The first computing terminal and the second computing terminal calculate a first difference based on additive secret sharing, so that the first computing terminal holds an additive secret sharing share of the first difference, and the second computing terminal holds another additive secret sharing share of the second difference, where the first difference is a minus b the obtained difference;

[0098] The first computing terminal and the second computing terminal calculate a second difference based on additive secret sharing, so that the first computing terminal holds an additive secret sharing share of the second difference, and the second computing terminal holds another additive secret sharing share of the second difference, where the second difference is b minus a the obtained difference;

[0099] The first computing terminal and the second computing terminal obtain a and b the Boolean additive secret sharing share of the most significant bit of the bit data of the comparison result, where when a < b , a and b the most significant bit of the comparison result is 1, and when a ≥ b, the most significant bit of the comparison result of a and b is 0;

[0100] The first computing terminal and the second computing terminal calculate a first preset formula based on additive secret sharing to obtain a and b the additive secret sharing share of the absolute value of the difference;

[0101] The first preset formula is:

[0102]

[0103] where represents the negation operation. When , , when , ;

[0104] When calculating the first preset formula based on additive secret sharing, the first computing terminal and the second computing terminal perform two rounds of calculations. When the first computing terminal and the second computing terminal respectively hold x two Boolean additive secret sharing shares, and the first computing terminal and the second computing terminal respectively hold y two arithmetic additive secret sharing shares, obtain x and y the additive secret sharing share of the product;

[0105] Among them, in the first round of calculation, the first computing terminal is the sender, and the second computing terminal is the receiver. In the second round of calculation, the first computing terminal is the receiver, and the second computing terminal is the sender;

[0106] In each round of calculation, the sender generates a random number , and calculates the message . After that, the sender saves the random number and sends to the receiver, where is the Boolean additive secret sharing share of x locally saved by the sender, and is the arithmetic additive secret sharing share of y locally saved by the sender;

[0107] The receiver determines whether the locally saved Boolean additive secret sharing share is 0. If so, it saves , if not, it saves ;

[0108] After two rounds of calculation, the first computing terminal / the second computing terminal sums the locally generated random number and the saved message to respectively obtain x and yAn additive secret sharing share of the product.

[0109] Specifically, the method provided in this embodiment calculates the absolute value of the difference between two values based on a first preset formula. To calculate this formula, it is necessary to securely implement the negation operation and obtain a and b comparison value . In the secret sharing domain, the negation operation only requires one of the parties in to locally negate the boolean secret sharing share it holds. Regarding how to securely calculate , the method provided in this embodiment, after obtaining the two's complement representation of , uses the most significant bit (MSB) of to obtain . This MSB can be represented by . If , then , otherwise . The extraction of the MSB in the secret sharing domain can be implemented by a secure parallel prefix adder (PPA), which only requires basic exclusive OR and AND operations in the secret sharing domain. Figure 7 Describes an 8-bit PPA structure for MSB extraction. Based on the PPA, the present invention designs a secure protocol for MSB extraction, denoted as SecExt, which allows two servers to use and secret sharing to calculate the secret sharing of the MSB of , that is, . That is to say, the first computing terminal and the second computing terminal obtain a and b the boolean additive secret sharing share of the most significant bit of the comparison result of the bit data, including:

[0110] The first computing terminal and the second computing terminal convert the additive secret sharing share of the first difference held locally into bit data, and perform calculations through a parallel prefix addition circuit so that the first computing terminal obtains a and b a boolean additive secret sharing share of the most significant bit of the comparison result of the bit data, and the second computing terminal obtains a and b another boolean additive secret sharing share of the most significant bit of the comparison result.

[0111] Note that the output of SecExt is a boolean shared value, but according to the first preset formula, the present invention needs to calculate as the result. Therefore, it is necessary to consider how to calculate (i.e., ) and the product between. That is to say, given the boolean secret sharing value and the arithmetic secret sharing value , it is necessary to calculate . The method provided in this embodiment processes the multiplication between the values in different secret sharing domains according to the following steps:

[0112] 1) Generate a random number , and then construct two values: , and then send and to .

[0113] 2) According to its own secret sharing share to select the corresponding , that is, when , select , when , select . After that, saves , saves .

[0114] 3) For the secret sharing share , as the sender and then as the receiver, repeat steps 1) and 2).

[0115] Finally, and can obtain the secret sharing value of . Use MultiBA to represent this secret sharing multiplication, that is . Similarly, MultiBA can also be used for the secret sharing multiplication of a boolean shared value and an arithmetic shared vector , that is , where is a vector. Based on the above security operations, the present invention designs a secure database mapping module secMap, and the detailed content is shown in Algorithm 2 as shown in Figure 8 .

[0116] Please refer to again Figure 1, the method provided in this embodiment further includes the steps:

[0117] S200. The first computing terminal and the second computing terminal obtain the additive secret sharing shares of the first comparison result based on additive secret sharing. The first comparison result is the comparison result of the sum of the attributes of the tuples in the mapping database. The first computing terminal and the second computing terminal obtain the additive secret sharing shares of the smallest sum of attributes in the mapping database based on the additive secret sharing shares of the first comparison result, where the sum of the attributes of a tuple is the sum of each value in the tuple;

[0118] S300. The first computing terminal and the second computing terminal obtain the additive secret sharing shares of a Skyline tuple in the mapping database and the additive secret sharing shares of a Skyline tuple in the original database according to the first comparison result, and add the additive secret sharing shares of the Skyline tuple in the original database to the query result set.

[0119] After mapping the encrypted database based on to , it is necessary to securely obtain the Skyline tuple from , and obtain the corresponding tuple from . This problem can be simplified to a single execution. Next, it is introduced how to securely obtain a from securely, and how to obtain the corresponding from . .

[0120] According to the plaintext Skyline query process described in Algorithm 1, secure Skyline search first requires summing all the attributes of each tuple . This summation operation is naturally supported in the secret sharing domain, that is:

[0121]

[0122] where represents the sum of the attributes of tuple . Based on this sum of attributes, the method provided in this embodiment designs a secFetch module, enabling to securely obtain the Skyline tuple from securely, and from the Skyline tuple, and from ​Obtained from corresponding . Because is the tuple with the smallest sum of attributes in, so the first challenge to be solved in the secure Skyline tuple acquisition in the secret sharing domain is how to make securely obtain the minimum value from a secret shared set without knowing the specific value obtained and which tuple it corresponds to.

[0123] Specifically, the first computing terminal and the second computing terminal obtain the additive secret sharing share of the smallest sum of attributes in the mapping database based on the additive secret sharing share of the first comparison result, including:

[0124] The first computing terminal and the second computing terminal obtain through the following operations a and b the additive secret sharing share of the minimum value between:

[0125] The first computing terminal and the second computing terminal obtain a and b the boolean additive secret sharing share of the most significant bit of the bit data of the comparison result of, where when a < b , a and b the most significant bit of the comparison result of is 1, when a ≥ b , a and b the most significant bit of the comparison result of is 0;

[0126] The first computing terminal and the second computing terminal respectively obtain two additive secret sharing shares of the first product based on additive secret sharing, and the first computing terminal and the second computing terminal respectively obtain two additive secret sharing shares of the second product based on additive secret sharing, where the first product is a and b the product of the most significant bit of the comparison result of and a , and the second product a and b the product of the negated value of the comparison result of and b ;

[0127] The first computing terminal and the second computing terminal respectively obtain two additive secret sharing shares of the sum of the first product and the second product based on additive secret sharing as a and b the additive secret sharing share of the minimum value in.

[0128] Obviously, finding the minimum number among several numbers essentially requires comparing these numbers and then performing exchanges based on the comparison results. Suppose and have and 's secret sharing values and want to obtain the minimum value. First, use the above SecExt function to obtain and 's comparison result , that is . Then, and 's minimum value can be safely retrieved through the following formula:

[0129]

[0130] where . Based on this, this patent can obtain the minimum attribute sum from . When safely exchanging two attribute sums based on the secret sharing comparison result, it is also possible to perform and 's secure exchange of two associated secret sharing tuples, so as to safely obtain the corresponding Skyline tuple from and as well as obtain the corresponding Skyline tuple from .

[0131] That is to say, the first computing terminal and the second computing terminal obtain an additive secret sharing share of a Skyline tuple in the mapping database and an additive secret sharing share of a Skyline tuple in the original database according to the first comparison result, including:

[0132] The first computing terminal and the second computing terminal perform the following operations in each iteration:

[0133] Select a tuple in the mapping database as the first tuple. The first computing terminal and the second computing terminal obtain the boolean additive secret sharing share of the most significant bit of the comparison result between the current first target tuple and the attribute sum corresponding to the first tuple;

[0134] The first computing terminal and the second computing terminal respectively obtain two additive secret sharing shares of a third product and two additive secret sharing shares of a fourth product based on additive secret sharing, where the third product is the product of the most significant bit of the comparison result between the current first target tuple and the sum of attributes corresponding to the first tuple and the first target tuple, and the fourth product is the product of the first tuple and the negation value of the most significant bit of the comparison result between the current first target tuple and the sum of attributes corresponding to the first tuple;

[0135] The first computing terminal and the second computing terminal respectively obtain two additive secret sharing shares of the sum of the third product and the fourth product as the additive secret sharing shares of the updated first target tuple based on additive secret sharing;

[0136] Select a tuple in the original database as the second tuple, and the first computing terminal and the second computing terminal obtain the boolean additive secret sharing share of the most significant bit of the comparison result between the second tuple and the sum of attributes corresponding to the current second target tuple;

[0137] The first computing terminal and the second computing terminal respectively obtain two additive secret sharing shares of a fifth product and two additive secret sharing shares of a sixth product based on additive secret sharing, where the fifth product is the product of the most significant bit of the comparison result between the current second target tuple and the sum of attributes corresponding to the second tuple and the second target tuple, and the sixth product is the product of the second tuple and the negation value of the most significant bit of the comparison result between the current second target tuple and the sum of attributes corresponding to the second tuple;

[0138] The first computing terminal and the second computing terminal respectively obtain two additive secret sharing shares of the sum of the fifth product and the sixth product as the additive secret sharing shares of the updated second target tuple based on additive secret sharing;

[0139] After each tuple in the mapping database / the original database has participated in the above iterative calculation, the first computing terminal and the second computing terminal use the latest additive secret sharing shares of the first target tuple held locally as the additive secret sharing shares of a Skyline tuple in the mapping database, and use the latest additive secret sharing shares of the second target tuple held locally as the additive secret sharing shares of a Skyline tuple in the original database.

[0140] In as Figure 9The process of obtaining secure Skyline tuples is introduced in Algorithm 3 shown above. Note that when implementing Algorithm 3, the divide-and-conquer technique can also be used to improve the performance of secure minimum value calculation. For example, for a vector composed of four numbers the minimum value can be calculated through , where and can be calculated in parallel, thus saving the number of communication rounds.

[0141] The first computing terminal and the second computing terminal add the additive secret sharing shares of a Skyline tuple in the obtained original database to the query result set. So far, it has been introduced how to securely obtain encrypted Skyline tuples from the encrypted mapping database . It is worth noting that through the above steps, although the first computing terminal and the second computing terminal obtain the additive secret sharing shares of the minimum attribute sum, they do not know which tuple's attribute sum it is specifically, nor do they know whether there are multiple tuples with the minimum attribute sum. Although they obtain the additive secret sharing share of a Skyline tuple, they also do not know which tuple it is specifically. Subsequently, it is necessary to make securely delete and those tuples dominated by , while ensuring that does not know which tuples in the database these are, thereby hiding the access pattern and domination relationship.

[0142] According to the plaintext algorithm of the Skyline query, after each Skyline tuple in the original database is obtained, the corresponding tuple in the mapping database needs to be deleted. In this embodiment, in order to achieve secure deletion and those tuples dominated by , while ensuring that does not know which tuples in the database these are, the method provided in this embodiment sets multiple identification information to identify the tuples that need to be deleted, and updates the attribute sum corresponding to the tuples that need to be deleted to a preset maximum value. In this way, these tuples will not be determined as Skyline tuples and will not be added to the query result. That is to say, the method provided in this embodiment further includes the steps:

[0143] The S400, the first computing terminal, and the second computing terminal obtain the additive secret sharing share of the smallest attribute sum in the mapping database and the second comparison result with the preset maximum value. The first computing terminal and the second computing terminal exchange the additive secret sharing shares of the second comparison result held locally to obtain the plaintext information of the second comparison result;

[0144] S500. If the plaintext information indicates that the smallest attribute sum in the mapping database is less than the preset maximum value, the first computing terminal and the second computing terminal respectively obtain the additive secret sharing shares of the first identification information and the second identification information of the tuples in the mapping database based on additive secret sharing according to the additive secret sharing shares of the Skyline tuples in the mapping database, where the first identification information is used to distinguish one Skyline tuple in the mapping database from other tuples, the second identification information is used to distinguish the first tuple and the second tuple in the mapping database, the first tuple is a Skyline tuple or a tuple dominated by a Skyline tuple, and the second tuple is neither a Skyline tuple nor a tuple dominated by a Skyline tuple;

[0145] S600. The first computing terminal and the second computing terminal update the additive secret sharing shares of the attribute sums of the tuples dominated by the Skyline tuples and a Skyline tuple in the mapping database based on the additive secret sharing shares of the second identification information and the first identification information held locally, so that the attribute sums of the tuples dominated by the Skyline tuples and a Skyline tuple in the mapping database are the preset maximum value.

[0146] The following introduces how to securely locate the Skyline tuples and the tuples they dominate from , specifically based on the following premises: 1) Each attribute value of the Skyline tuples in the current round is equal to the corresponding attribute value found in secFetch; 2) Each attribute value of the dominated tuples is greater than or equal to the corresponding attribute value in . Premise 1 can be subsumed into premise 2, so only premise 2 needs to be judged by comparison. The method provided in this embodiment defines an encrypted (binary) flag for each tuple as the second identification information to (secretly) identify Whether it is a Skyline tuple or a dominated tuple. The first computing terminal and the second computing terminal respectively obtain the additive secret sharing shares of the second identification information of the tuples in the mapping database based on additive secret sharing according to the additive secret sharing shares of the Skyline tuples in the mapping database, including:

[0147] For a target tuple in the mapping database, the first computing terminal and the second computing terminal perform the following operations to obtain the second identification information of the target tuple:

[0148] The first computing terminal and the second computing terminal obtain the negation value of the comparison result of each value of the target tuple and the corresponding value of the latest first target tuple;

[0149] The first computing terminal and the second computing terminal obtain the boolean additive secret sharing share of the exclusive OR operation result of the negation values of all comparison results of each value of the target tuple and the corresponding value of the latest first target tuple as the additive secret sharing share of the second identification information of the target tuple.

[0150] Specifically, First, securely compare and for each attribute:

[0151]

[0152] Then, summarize the encrypted comparison results into through the following formula:

[0153]

[0154] where, indicates that is a Skyline tuple or a dominated tuple, indicates that is neither a Skyline tuple nor a dominated tuple. The above process corresponds to Figure 10 lines 3 - 6 of algorithm 4 shown in. However, note that there may be multiple tuples in that are exactly the same as the Skyline tuple , but only one of them needs to be eliminated in this round because the rest are also Skyline tuples in subsequent rounds (to be added to the query result ). Deleting all of them now will lead to a decrease in query accuracy because the Skyline tuple that should have appeared in the query result is deleted. Therefore, cannot be directly based on Simply (in a secure manner) eliminate the tuples.

[0155] In the method provided in this embodiment, it is allowed to only securely mark the first-occurring Skyline tuple and then eliminate the Skyline tuple based on this mark. Specifically, for each tuple define an encrypted (binary) mark as the first identification information to indicate whether it is the desired (first) Skyline tuple . Then, through Figure 10 lines 7 - 9 of Algorithm 4 shown in securely calculate the for each

[0156] The first computing terminal and the second computing terminal respectively obtain the additive secret sharing shares of the first identification information of the tuples in the mapping database based on additive secret sharing, including:

[0157] For each target tuple in the mapping database, the first computing terminal and the second computing terminal perform the following operations to obtain the first identification information of the target tuple:

[0158] The first computing terminal and the second computing terminal obtain the Boolean additive secret sharing share of the comparison result between the minimum attribute in the mapping database and the sum of attributes of the target tuple;

[0159] The first computing terminal negates the Boolean additive secret sharing share of the comparison result between the minimum attribute in the mapping database held locally and the sum of attributes of the target tuple to obtain the Boolean additive secret sharing share of the third identification information of the target tuple, and the second computing terminal takes the Boolean additive secret sharing share of the comparison result between the minimum attribute in the mapping database held locally and the sum of attributes of the target tuple as the Boolean additive secret sharing share of the third identification information of the target tuple;

[0160] The first computing terminal and the second computing terminal obtain the Boolean additive secret sharing share of the AND operation result of the negated value of the current mark information and the third identification information as the Boolean additive secret sharing share of the first identification information of the target tuple;

[0161] The first computing terminal and the second computing terminal obtain the exclusive OR operation result of the current marked information and the first identification information of the target tuple to update the marked information for the first identification information of the next tuple in the mapping database.

[0162] Specifically, in each round, determine the first identification information of a tuple in the mapping database. In each round, first, securely compare and ( is the attribute sum of the current round ) :

[0163]

[0164] where then means . Note that is the minimum value in (based on Algorithm 3), so means . Although the attribute sum of is equal to , there may be more than one value in equal to , so only means may be a Skyline tuple . Therefore, the present invention provides a clever security design such that is set only when the first tuple satisfying is encountered. The specific operation is as follows:

[0165]

[0166]

[0167] where represents that the tuple is the first required Skyline tuple .

[0168] The correctness analysis is as follows. At the beginning . When the first appears, securely set , and will remain equal to in the next loop. Because , in the next loop such that will not set the tags of other tuples to .

[0169] The first computing terminal and the second computing terminal update the additive secret sharing shares of the sum of the attributes of the tuples dominated by the Skyline tuple and a Skyline tuple in the mapping database based on the additive secret sharing shares of the second identification information and the first identification information held locally, so that the sum of the attributes of the tuples dominated by the Skyline tuple and a Skyline tuple in the mapping database is the preset maximum value, including:

[0170] The first computing terminal and the second computing terminal obtain the boolean additive secret sharing share of the elimination flag based on the additive secret sharing shares of the first identification information, the second identification information, and the third identification information held locally, where the elimination flag is used to mark a Skyline tuple and the tuples dominated by the Skyline tuple in the mapping database;

[0171] For each tuple in the mapping database, the first computing terminal and the second computing terminal perform the following operations:

[0172] The first computing terminal and the second computing terminal obtain the additive secret sharing shares of the seventh product and the eighth product, where the seventh product is the product of the sum of the attributes of the tuple and the negation value of the elimination flag, and the eighth product is the product of the elimination flag of the tuple and the preset maximum value;

[0173] The first computing terminal and the second computing terminal update the additive secret sharing share of the sum of the attributes of the tuple in the mapping database held this time to the additive secret sharing share of the sum of the seventh product and the eighth product.

[0174] The first computing terminal and the second computing terminal obtain the boolean additive secret sharing share of the elimination flag based on the additive secret sharing shares of the first identification information, the second identification information, and the third identification information held locally, including:

[0175] The first computing terminal and the second computing terminal obtain the boolean additive secret sharing share of the fourth marking information, where the fourth marking information is the result of the AND operation of the negation values of the second identification information and the third identification information;

[0176] The first computing terminal and the second computing terminal obtain the boolean additive secret sharing share of the exclusive OR operation result of the first identification information and the fourth identification information as the boolean additive secret sharing share of the elimination flag.

[0177] Specifically, after marking the skyline tuple, Should be securely marked The method provided in this embodiment is to eliminate the tuples that are dominated by Defines an encrypted (binary) tag , to indicate Whether it is Then, For each Compute safely :

[0178]

[0179] in and It can be calculated by the method provided above. When is a Dominated tuple. =1 means is a The dominant tuple or ,but Excluded Therefore, correctness can be guaranteed.

[0180] Through the above design, Can be used Safely mark the skyline tuple by Safely mark the Skyline tuple Therefore, It is safe to determine the tuple by Whether it needs to be deleted:

[0181]

[0182] For the elimination mark, when The tuples need to be eliminated. A simple way to do this is to let Directly expose each tuple However, this simple approach will leak the dominance relationship and which tuple is the skyline tuple, which violates the security requirement of protecting the access mode. Therefore, the present invention proposes a protocol that can achieve secure tuple elimination. Specifically, the protocol allows Safely tuple of Set to a preset system-wide maximum value , to mark it as in such a way that the tuple has been "eliminated". If , it means that the tuple does not need to be eliminated and needs to be kept unchanged. This design specifically enables to perform the following calculations:

[0183]

[0184] It should be noted that since the preset maximum value is public information and can be made to be saved in plain text , therefore and the multiplication between them does not require online communication. By setting it can prevent from selecting (or ) as a Skyline tuple, thus ensuring the accuracy of the Skyline query.

[0185] As Figure 1 shown, the method provided in this embodiment further includes the steps:

[0186] S700. The first computing terminal and the second computing terminal repeatedly execute the step of obtaining the additive secret sharing share of the first comparison result based on additive secret sharing until the plaintext information is the smallest attribute sum in the mapping database and not less than the preset maximum value.

[0187] In order to let decide whether to terminate the secure search process without leaking other information, the method provided by the present invention realizes securely comparing the smallest attribute sum in the mapping database with the preset maximum value by letting calculate the flag bit:

[0188]

[0189] Through the above formula, the first computing terminal and the second computing terminal can obtain the Boolean additive secret sharing share of the flag bit , and then the first computing terminal and the second computing terminal exchange the Boolean additive secret sharing shares of the flag bit, that is, make public. When , it indicates that the smallest value in is . At this time, can know that all the values in have been deleted, thus stopping the secure search process.

[0190] The complete process algorithm of the privacy - protected skyline query method provided by this embodiment is as Figure 11 shown.

[0191] In summary, this embodiment provides a privacy - protected Skyline query method. In this method, lightweight encryption technology is used to encrypt the original database and the query content, and secure database mapping, secure Skyline tuple acquisition, and secure Skyline and dominated tuple elimination can be achieved. During the Skyline query process, the first computing terminal and the second computing terminal will not obtain the original database content, query tuples, and query results, nor will they obtain the domination relationship between the tuples of the database, realizing an efficient privacy - protected Skyline query.

[0192] It should be understood that although the steps in the flowchart given in the accompanying drawings of the present invention are shown in sequence according to the arrows, these steps do not necessarily have to be executed in the order indicated by the arrows. Unless there is a clear indication in this article, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, at least some of the steps in the flowchart may include multiple sub - steps or multiple stages. These sub - steps or stages do not necessarily have to be completed at the same time, but can be executed at different times, and the execution order of these sub - steps or stages does not necessarily have to be sequential, but can be executed alternately or in turn with at least a part of other steps or sub - steps or stages of other steps.

[0193] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided by the present invention can include non-volatile and / or volatile memories. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or an external cache. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.

[0194] Embodiment 2

[0195] Based on the above embodiments, the present invention also correspondingly provides a privacy-protected Skyline query system. The system includes a first computing terminal and a second computing terminal, and the first computing terminal and the second computing terminal are used to cooperatively execute the relevant steps in the privacy-protected Skyline query method in Embodiment 1.

[0196] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features. These modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention. The user information obtained has obtained the consent of the user and complies with the provisions of relevant laws and policies.

Claims

1. A privacy-preserving Skyline query method, characterized in that, The method includes: The first computing terminal and the second computing terminal obtain the additive secret sharing share of the mapped database based on additive secret sharing, according to the additive secret sharing shares of the query tuples held locally and the additive secret sharing shares of the original database, where the k-th value in the i-th tuple in the mapped database is the absolute value of the difference between the k-th attribute value of the i-th tuple in the original database and the k-th attribute value of the query tuple; The first computing terminal and the second computing terminal obtain the additive secret sharing share of the first comparison result based on additive secret sharing, where the first comparison result is the comparison result of the sum of attributes of the tuples in the mapped database, and the first computing terminal and the second computing terminal obtain the additive secret sharing share of the minimum sum of attributes in the mapped database based on the additive secret sharing share of the first comparison result, where the sum of attributes of a tuple is the sum of each value in the tuple; The first computing terminal and the second computing terminal obtain the additive secret sharing share of a Skyline tuple in the mapped database and the additive secret sharing share of a Skyline tuple in the original database according to the first comparison result, and add the additive secret sharing share of the Skyline tuple in the original database to the query result set; The first computing terminal and the second computing terminal obtain the additive secret sharing share of the second comparison result between the minimum sum of attributes in the mapped database and a preset maximum value, and the first computing terminal and the second computing terminal exchange the additive secret sharing shares of the second comparison result held locally to obtain the plaintext information of the second comparison result; If the plaintext information is that the minimum sum of attributes in the mapped database is less than the preset maximum value, the first computing terminal and the second computing terminal obtain the additive secret sharing shares of the first identification information and the second identification information of the tuples in the mapped database based on additive secret sharing according to the additive secret sharing share of the Skyline tuple in the mapped database, where the first identification information is used to distinguish a Skyline tuple in the mapped database from other tuples, and the second identification information is used to distinguish the first tuple and the second tuple in the mapped database, the first tuple is a Skyline tuple or a tuple dominated by a Skyline tuple, and the second tuple is neither a Skyline tuple nor a tuple dominated by a Skyline tuple; The first computing terminal and the second computing terminal update the additive secret sharing shares of the sum of attributes of the tuples dominated by the Skyline tuple and a Skyline tuple in the mapped database based on the additive secret sharing shares of the second identification information and the first identification information held locally, so that the sum of attributes of the tuples dominated by the Skyline tuple and a Skyline tuple in the mapped database is the preset maximum value; The first computing terminal and the second computing terminal repeatedly execute the step of obtaining the additive secret sharing shares of the first comparison result based on additive secret sharing until the plaintext information is the smallest attribute in the mapping database and not less than the preset maximum value.

2. The privacy protection Skyline query method according to claim 1, wherein The first computing terminal and the second computing terminal obtain the additive secret sharing shares of the mapping database based on additive secret sharing according to the additive secret sharing shares of the query tuple held locally and the additive secret sharing shares of the original database, including: The first computing terminal and the second computing terminal perform the following operations to obtain a and b the additive secret sharing share of the absolute value of the difference: The first computing terminal and the second computing terminal calculate a first difference based on additive secret sharing, such that the first computing terminal holds an additive secret sharing share of the first difference, and the second computing terminal holds another additive secret sharing share of the second difference, where the first difference is a minus b the obtained difference; The first computing terminal and the second computing terminal calculate a second difference based on additive secret sharing, such that the first computing terminal holds one additive secret sharing share of the second difference, and the second computing terminal holds the other additive secret sharing share of the second difference, where the second difference is b minus a the resulting difference; The first computing terminal and the second computing terminal obtain a and b a Boolean additive secret sharing share of the most significant bit of the bit data of the comparison result, where when a < b the most significant bit of the comparison result of a and b is 1, and when a ≥ b, the most significant bit of the comparison result of a and b is 0; The first computing terminal and the second computing terminal calculate a first preset formula based on additive secret sharing to obtain a and b an additive secret sharing share of the absolute value of the difference; The first preset formula is: Among them, represents the negation operation. When happens, , and when happens, ; When calculating the first preset formula based on additive secret sharing, the first computing terminal and the second computing terminal perform two rounds of calculations. When the first computing terminal and the second computing terminal respectively hold x two Boolean additive secret sharing shares, and the first computing terminal and the second computing terminal respectively hold two arithmetic additive secret sharing shares of y, obtain x and y the additive secret sharing share of the product; Wherein, in the first round of calculation, the first computing terminal serves as the sender, and the second computing terminal serves as the receiver; in the second round of calculation, the first computing terminal serves as the receiver, and the second computing terminal serves as the sender. In each round of calculation, the sender generates a random number , and calculates the message . After that, the sender saves the random number and sends to the receiver, where is the Boolean additive secret sharing share of x locally saved by the sender, and is the arithmetic additive secret sharing share of y locally saved by the sender; The recipient determines whether the boolean additive secret sharing share stored locally is 0. If so, it stores , if not, it stores ; After two rounds of calculation, the first computing terminal or the second computing terminal sums the locally generated random number and the saved message to obtain respectively x and y an additive secret sharing share of the product of 3. The privacy-preserving Skyline query method according to claim 2, characterized in that, The first computing terminal and the second computing terminal obtain a and b the Boolean additive secret sharing share of the most significant bit of the bit data of the comparison result, including: The first computing terminal and the second computing terminal convert the additive secret sharing share of the first difference held locally into bit data, and perform calculations through a parallel prefix adder circuit so that the first computing terminal obtains a and b a Boolean additive secret sharing share of the most significant bit of the bit data of the comparison result of, and the second computing terminal obtains a and b another Boolean additive secret sharing share of the most significant bit of the comparison result of.

4. The privacy-preserving Skyline query method according to claim 2, characterized in that, The first computing terminal and the second computing terminal obtain the additive secret sharing shares of the smallest attribute sum in the mapping database based on the additive secret sharing shares of the first comparison result, including: The first computing terminal and the second computing terminal obtain through the following operations a and b the additive secret sharing share of the minimum value between: The first computing terminal and the second computing terminal obtain a and b the most significant bit of the bit data of the comparison result of a < b When a and b the most significant bit of the comparison result is 1, and when a ≥ b When a and b the most significant bit of the comparison result is 0; The first computing terminal and the second computing terminal respectively obtain two additive secret sharing shares of a first product based on additive secret sharing. The first computing terminal and the second computing terminal respectively obtain two additive secret sharing shares of a second product based on additive secret sharing, where the first product is a and b the most significant bit of the comparison result of a multiplied by a and b the negated value of the comparison result of b multiplied by The first computing terminal and the second computing terminal respectively obtain two additive secret sharing shares of the sum of the first product and the second product based on additive secret sharing as a and b the additive secret sharing share of the minimum value in 5. The privacy protection Skyline query method according to claim 4, characterized in that, The first computing terminal and the second computing terminal obtain the additive secret sharing shares of a Skyline tuple in the mapping database and the additive secret sharing shares of a Skyline tuple in the original database according to the first comparison result, including: The first computing terminal and the second computing terminal perform the following operations in each iteration: Select a tuple in the mapping database as the first tuple, and the first computing terminal and the second computing terminal obtain the Boolean additive secret sharing share of the most significant bit of the comparison result of the current first target tuple and the attribute sum corresponding to the first tuple; The first computing terminal and the second computing terminal respectively obtain two additive secret sharing shares of a third product and two additive secret sharing shares of a fourth product based on additive secret sharing, where the third product is the product of the most significant bit of the comparison result of the current first target tuple and the attribute sum corresponding to the first tuple and the first target tuple, and the fourth product is the product of the inverted value of the most significant bit of the comparison result of the current first target tuple and the attribute sum corresponding to the first tuple and the first tuple; The first computing terminal and the second computing terminal respectively obtain two additive secret sharing shares of the sum of the third product and the fourth product as the additive secret sharing shares of the updated first target tuple based on additive secret sharing; Select a tuple in the original database as the second tuple, and the first computing terminal and the second computing terminal obtain the Boolean additive secret sharing share of the most significant bit of the comparison result of the second tuple and the attribute sum corresponding to the current second target tuple; The first computing terminal and the second computing terminal respectively obtain two additive secret sharing shares of a fifth product and two additive secret sharing shares of a sixth product based on additive secret sharing, where the fifth product is the product of the highest bit of the comparison result between the current second target tuple and the sum of attributes corresponding to the second tuple and the second target tuple, and the sixth product is the product of the inverted value of the highest bit of the comparison result between the current second target tuple and the sum of attributes corresponding to the second tuple and the second tuple; The first computing terminal and the second computing terminal respectively obtain two additive secret sharing shares of the sum of the fifth product and the sixth product as the additive secret sharing shares of the updated second target tuple based on additive secret sharing; After each tuple in the mapping database or the original database has participated in the above iterative calculation, the first computing terminal and the second computing terminal use the additive secret sharing shares of the latest first target tuple held locally as the additive secret sharing shares of a Skyline tuple in the mapping database, and use the additive secret sharing shares of the latest second target tuple held locally as the additive secret sharing shares of a Skyline tuple in the original database.

6. The privacy-preserving Skyline query method according to claim 5, wherein The first computing terminal and the second computing terminal respectively obtain the additive secret sharing shares of the second identification information of the tuples in the mapping database based on the additive secret sharing shares of the Skyline tuples in the mapping database, including: For the target tuple in the mapping database, the first computing terminal and the second computing terminal perform the following operations to obtain the second identification information of the target tuple: The first computing terminal and the second computing terminal obtain the comparison results of each value of the target tuple and the corresponding value of the latest first target tuple; The first computing terminal and the second computing terminal obtain the Boolean additive secret sharing share of the exclusive OR operation result of the inverted values of all comparison results of each value of the target tuple and the corresponding value of the latest first target tuple as the additive secret sharing share of the second identification information of the target tuple.

7. The privacy-preserving Skyline query method according to claim 5, characterized in that, The first computing terminal and the second computing terminal respectively obtain the additive secret sharing shares of the first identification information of the tuples in the mapping database based on the additive secret sharing shares of the Skyline tuples in the mapping database, including: For each target tuple in the mapping database, the first computing terminal and the second computing terminal perform the following operations to obtain the first identification information of the target tuple: The first computing terminal and the second computing terminal obtain the Boolean additive secret sharing share of the comparison result between the minimum sum of attributes in the mapping database and the sum of attributes of the target tuple; The first computing terminal negates the Boolean additive secret sharing share of the comparison result between the minimum attribute sum in the mapping database held locally and the attribute sum of the target tuple, to obtain the Boolean additive secret sharing share of the third identification information of the target tuple, and the second computing terminal uses the Boolean additive secret sharing share of the comparison result between the minimum attribute sum in the mapping database held locally and the attribute sum of the target tuple as the Boolean additive secret sharing share of the third identification information of the target tuple; The first computing terminal and the second computing terminal obtain the Boolean additive secret sharing share of the AND operation result of the negated value of the current marking information and the third identification information, as the Boolean additive secret sharing share of the first identification information of the target tuple; The first computing terminal and the second computing terminal obtain the XOR operation result of the current marking information and the first identification information of the target tuple to update the marking information for use in the first identification information of the next tuple in the mapping database.

8. The privacy-preserving Skyline query method according to claim 7, characterized in that, The first computing terminal and the second computing terminal update the additive secret sharing share of the sum of the attributes of the tuples dominated by the Skyline tuple and a Skyline tuple in the mapping database based on the additive secret sharing shares of the second identification information and the first identification information held locally, so that the sum of the attributes of the tuples dominated by the Skyline tuple and a Skyline tuple in the mapping database is the preset maximum value, including: The first computing terminal and the second computing terminal obtain the Boolean additive secret sharing share of the elimination flag based on the additive secret sharing shares of the first identification information, the second identification information, and the third identification information held locally, and the elimination flag is used to mark a Skyline tuple and the tuples dominated by the Skyline tuple in the mapping database; For each tuple in the mapping database, the first computing terminal and the second computing terminal perform the following operations: The first computing terminal and the second computing terminal obtain the additive secret sharing share of the seventh product and the eighth product, where the seventh product is the product of the sum of the attributes of the tuple and the negated value of the elimination flag, and the eighth product is the product of the elimination flag of the tuple and the preset maximum value; The first computing terminal and the second computing terminal update the additive secret sharing share of the sum of the attributes of the tuple in the mapping database held this time to the additive secret sharing share of the sum of the seventh product and the eighth product.

9. The privacy-preserving Skyline query method according to claim 8, wherein The first computing terminal and the second computing terminal obtain the Boolean additive secret sharing share of the elimination flag based on the additive secret sharing shares of the first identification information, the second identification information, and the third identification information held locally, including: The first computing terminal and the second computing terminal obtain the Boolean additive secret sharing share of the fourth identification information, where the fourth identification information is the AND operation result of the second identification information and the negated value of the third identification information; The first computing terminal and the second computing terminal obtain the Boolean additive secret sharing share of the exclusive OR operation result of the first identification information and the fourth identification information as the Boolean additive secret sharing share of the elimination flag.

10. A privacy-preserving Skyline query system, characterized in that, The system includes a first computing terminal and a second computing terminal; the first computing terminal and the second computing terminal cooperate to complete the privacy-preserving Skyline query method according to any one of claims 1-9.

Citation Information

Patent Citations

  • Dynamic Skyline inquiry device based on cloud computing

    CN106599189A

  • Method for inquiring privacy protection skyline on vertical distribution data set

    CN107967431A