A Public Key Encryption Method and System Supporting Outsourced Ciphertext Data Equality Testing

By introducing a public key encryption method that supports outsourcing ciphertext data equality testing in the cloud computing environment, using public keys and equality test tokens, the problem that cloud servers cannot judge ciphertext equality is solved, efficient ciphertext retrieval and retrieval is achieved, and data storage and access efficiency is improved.

CN115378666BActive Publication Date: 2025-07-25SHANDONG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210933042.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-04
Publication Date
2025-07-25
Estimated Expiration
2042-08-04

AI Technical Summary

Technical Problem

In a cloud computing environment, after user data is encrypted, the cloud server cannot determine whether the ciphertext is equal, resulting in waste of storage space and increased network communication computing expenses, and it is impossible to effectively search ciphertext.

Method used

The public key encryption method that supports outsourcing ciphertext data equality testing is adopted. By generating public keys and equality testing tokens, cloud servers are allowed to independently complete ciphertext equality testing, including key generation, encryption, decryption and equality detection algorithms, ensuring the security of selecting plaintext attacks.

Benefits of technology

It realizes that cloud servers independently complete ciphertext equality tests, supports ciphertext duplication checking and retrieval, reduces waste of storage space and network communication expenses, and ensures data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115378666B_ABST
    Figure CN115378666B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of encryption technology, and discloses a public key encryption method and system supporting outsourced ciphertext data equality testing. The decryption end generates a public-private key pair and a token, and sends the public key to the encryption end; the encryption end encrypts the plaintext based on the public key to generate a ciphertext, and sends the ciphertext to a cloud server or the decryption end; wherein, different ciphertexts can perform equality testing in combination with the token on the cloud server. The cloud server can independently complete the ciphertext equality testing, which can be used to construct a protocol supporting ciphertext duplicate checking and can also be used for ciphertext retrieval.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of encryption technology, and particularly to a public key encryption method and system supporting outsourced ciphertext data equality testing. Background Art

[0002] The statements in this section merely mention the background art related to the present invention and do not necessarily constitute the prior art.

[0003] In data storage outsourcing services represented by cloud computing, users' private data is stored in cloud servers. This method reduces the overhead of maintaining data storage for users and also brings the convenience of accessing data anytime and anywhere. However, at the same time, since users' data is physically out of the control of users, it also brings serious risks of data security and privacy leakage.

[0004] To protect the confidentiality and privacy of users' data, the users' data can be encrypted before being stored in the cloud server. However, this method brings inconvenience to both the data storage management of the cloud server and the utilization of the users' own data:

[0005] (1) If a user uploads two identical files, due to the security of the encryption algorithm, the server cannot determine whether the ciphertext data is equal. Therefore, the cloud service cannot perform deduplication processing, resulting in wasted storage space.

[0006] (2) When a user needs to retrieve specific data from the cloud server, due to the security of the encryption algorithm, the cloud server cannot determine which ciphertext data meets the user's retrieval conditions and can only send all the ciphertext data to the user. The user decrypts the data to obtain the required data, resulting in huge network communication expenses and computing expenses at the user end. Summary of the Invention

[0007] To solve the deficiencies of the prior art, the present invention provides a public key encryption method and system supporting outsourced ciphertext data equality testing, which can enable the cloud server to independently complete the ciphertext equality test and can be used to construct a protocol supporting ciphertext duplicate checking and ciphertext retrieval.

[0008] In the first aspect, the present invention provides a public key encryption method supporting outsourced ciphertext data equality testing;

[0009] The public key encryption method supporting outsourced ciphertext data equality testing, applied to an encryption end, includes:

[0010] Obtain the plaintext and the public key publicly disclosed by the decryption end;

[0011] Encrypt the plaintext based on the public key to generate a ciphertext, and send the ciphertext to the cloud server or the decryption end;

[0012] Among them, different ciphertexts can perform equality tests with the tokens generated by the cloud server in combination with the decryption end.

[0013] Furthermore, the public key is:

[0014] pk = (G, q, g, h, u, v, H(·));

[0015] where G is a group of order q; q is a prime number; g is a generator of the group G; random numbers x, y ∈ R Z q ; h = g x , u = g y , v = h y ; the cryptographic Hash function H(·): G → Z q .

[0016] Furthermore, the ciphertext is:

[0017] c = (c1, c2, c3)

[0018] where c1 = h r ; c2 = u r ·g H(m) ; c3 = v r ·h H(m) ·m; the plaintext m ∈ G; the random number r ∈ R Z q ; G is a group of order q; q is a prime number; g is a generator of the group G; random numbers x, y ∈ R Z q ; h = g x , u = g y , v = h y ; the cryptographic Hash function H(·): G → Z q .

[0019] Furthermore, the plaintext obtained by decrypting the ciphertext at the decryption end is:

[0020]

[0021] where c2 and c3 come from the ciphertext, the random number x ∈ R Z q , and q is a prime number.

[0022] Furthermore, the specific method of the equality test is: based on two ciphertexts c = (c1, c2, c3) and c' = (c1', c2', c3'), verify whether it holds. If it holds, it means that the plaintexts corresponding to the ciphertexts c and c' are equal; where c1, c2, c3 are all components of the ciphertext c; c1', c2', c3' are all components of the ciphertext c'; the random number y ∈R Z q , where q is a prime number.

[0023] In a second aspect, the present invention provides a public key encryption method that supports outsourcing ciphertext data equality testing;

[0024] The public key encryption method that supports outsourcing ciphertext data equality testing, applied to the decryption end, includes:

[0025] Generating a public-private key pair and a token, and sending the public key to the encryption end so that the encryption end encrypts the plaintext to generate ciphertext;

[0026] Based on the private key, decrypting the ciphertext to obtain the plaintext;

[0027] Among them, different ciphertexts can be subjected to equality testing in combination with the token by the cloud server.

[0028] In a third aspect, the present invention provides a public key encryption method that supports outsourcing ciphertext data equality testing;

[0029] The public key encryption method that supports outsourcing ciphertext data equality testing includes:

[0030] The decryption end generates a public-private key pair and a token, and sends the public key to the encryption end;

[0031] The encryption end encrypts the plaintext based on the public key to generate ciphertext, and sends the ciphertext to the cloud server or the decryption end;

[0032] Among them, different ciphertexts can be subjected to equality testing in combination with the token by the cloud server.

[0033] In a fourth aspect, the present invention provides a public key encryption system that supports outsourcing ciphertext data equality testing;

[0034] The public key encryption system that supports outsourcing ciphertext data equality testing includes an encryption end and a decryption end;

[0035] The decryption end is used to generate a public-private key pair and a token, and send the public key to the encryption end;

[0036] The encryption end is used to encrypt the plaintext based on the public key to generate ciphertext, and send the ciphertext to the cloud server or the decryption end;

[0037] Among them, different ciphertexts can be subjected to equality testing in combination with the token by the cloud server.

[0038] In a fifth aspect, the present invention provides an electronic device, including:

[0039] A memory for non-temporarily storing computer-readable instructions; and

[0040] A processor for running the computer-readable instructions,

[0041] wherein, when the computer-readable instructions are run by the processor, the method described in the first aspect or the second aspect above is executed.

[0042] In a sixth aspect, the present invention also provides a storage medium that non-temporarily stores computer-readable instructions, wherein when the non-temporary computer-readable instructions are executed by a computer, instructions for executing the method described in the first aspect or the second aspect are executed.

[0043] Compared with the prior art, the beneficial effects of the present invention are:

[0044] The public key encryption method of the present invention that supports outsourcing ciphertext data equality testing has the security of chosen-plaintext attack, and the server can independently complete the ciphertext equality test, which can be used to construct a protocol that supports ciphertext duplicate checking and can also be used for ciphertext retrieval. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] The specification drawings forming a part of this application are used to provide a further understanding of this application. The schematic embodiments of this application and their descriptions are used to explain this application and do not constitute an improper limitation to this application.

[0046] Figure 1 It is a flowchart of the public key encryption method that supports outsourcing ciphertext data equality testing described in the first embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0047] It should be noted that the following detailed descriptions are all exemplary and are intended to provide further descriptions of this application. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this application belongs.

[0048] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to this application. As used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. In addition, it should be understood that when the terms "include" and / or "comprise" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.

[0049] Term Explanation:

[0050] Public key encryption method: includes: key generation algorithm, encryption algorithm, and decryption algorithm.

[0051] Key generation algorithm: The decryption end (which can be the client of any user, such as Alice) generates its own public and private key pair by running the key generation algorithm: public key pkA and the private key sk A , where pk A is public and can be obtained by anyone, while sk A is kept secret and only known to the encrypting party (Alice) herself.

[0052] Encryption algorithm: If the encrypting party (which can be the client of any user, such as Bob) wants to encrypt and send a message m to the decrypting party (Alice), it uses the publicly available public key pk of the decrypting party A to encrypt m, obtaining the ciphertext c, and then sends the ciphertext to the decrypting party.

[0053] Decryption algorithm: After the decrypting party (Alice) obtains the ciphertext c, it uses the private key sk A known only to itself to decrypt and obtain the plaintext

[0054] For public key encryption methods, to satisfy the security against chosen plaintext attack, the encryption algorithm must be a probabilistic algorithm. Generally speaking, for the same plaintext m, the ciphertexts obtained from the first encryption and the second encryption are different. Due to this characteristic, the server stores ciphertexts, and they are random ciphertexts. Therefore, the server has no way to determine whether the plaintexts corresponding to two ciphertexts are the same. So, duplicate removal and retrieval cannot be completed by the server itself.

[0055] Embodiment 1

[0056] This embodiment provides a public key encryption method that supports outsourced ciphertext data equality testing. Based on the traditional public key encryption scheme, it adds a ciphertext equality test token and a ciphertext equality detection algorithm. The participating party holding the ciphertext equality test token can use the ciphertext equality detection algorithm to determine whether the plaintexts corresponding to two ciphertexts are equal. During this equality detection process, the specific information of the plaintext is not leaked.

[0057] The public key encryption method that supports outsourced ciphertext data equality testing provided in this embodiment is based on the Decision Diffie - Hellman (DDH) assumption, as Figure 1 shown, and specifically includes the following steps:

[0058] Step 1: Key generation algorithm Gen(1 k ): In response to the input of the encrypting party's ciphertext, the decrypting party inputs a security parameter k and outputs a key triple (pk, sk, etoken), where pk is the public key, sk is the private key, and etoken is the equality test token. It can be denoted as (pk, sk, etoken) ← Gen(1 k ).

[0059] The decryption end (i.e., the client of any user, such as Alice) generates its own public and private key pair pk A , sk A , where pk A is public and can be obtained by anyone, and sk A is confidential and only known to the decryption end itself. In addition, a ciphertext equality test token etoken is also generated. This token is not public. The decryption end secretly sends the token to whomever it wants to have the ability to perform ciphertext equality tests, such as a cloud server.

[0060] Specifically, for the input security parameter k of the key generation algorithm Gen(1 k ), a q-order group G is selected, where q is a prime number, ||q|| = k, and g is a generator of the group G. A cryptographic Hash function H(·): G → Z q is selected, and x, y ∈ R Z q are uniformly and randomly selected. Calculate h = g x , u = g y , v = h y . Then the public key pk = (G, q, g, h, u, v, H(·)), the private key sk = x, and the equality test token etoken = y. Among them, ∈ R is a whole, a specific symbol commonly used in cryptographic algorithms. x ∈ R Z q means randomly selecting an element x from the set Z q , and y ∈ R Z q means randomly selecting an element y from the set Z q ; ||q|| refers to the order of q, specifically the number of bits in the binary form of q, that is, the bit length of q; q cannot be too small, otherwise q can be found by brute force, so it is required that the length of q is at least k; Z q is the residue class modulo q. Simply understood, the set of integers can be divided into numbers that leave a remainder of 0 when divided by q (the integer subset, denoted by [0]), numbers that leave a remainder of 1 when divided by q ([1]),..., numbers that leave a remainder of q - 1 when divided by q ([q - 1]).

[0061] Step 2, Encryption algorithm Enc pk (m): The encryption end inputs the public key pk and the plaintext m, and outputs the ciphertext c. Denote it as c ← Enc pk (m).

[0062] The encrypting party (which can be the client of any user, such as Bob) wants to encrypt and send a message m to the decrypting party Alice. Then, the encrypting party Bob uses the publicly available public key pk of the decrypting party Alice A , encrypts m to obtain the ciphertext c. Here, the ciphertext c can be sent to the decrypting party Alice or uploaded to the cloud server.

[0063] Specifically, the encryption algorithm Enc pk (m) takes the public key pk = (G, q, g, h, u, v, H(·)) and the plaintext m ∈ G, and uniformly and randomly selects r ∈ R Z q , and calculates

[0064] c1 = h r

[0065] c2 = u r ·g H(m)

[0066] c3 = v r ·h H(m) ·m

[0067] Then the ciphertext c = (c1, c2, c3).

[0068] Step 3, decryption algorithm Dec sk (c): The decrypting party inputs the private key sk and the ciphertext c, and outputs the plaintext m. Denote it as m := Dec sk (c).

[0069] After the decrypting party Alice obtains the ciphertext c, it uses the private key sk known only to herself A , decrypts the ciphertext to obtain the plaintext

[0070] Specifically, the decryption algorithm Dec sk (c): Inputs the private key sk = x and the ciphertext c = (c1, c2, c3), and calculates

[0071]

[0072] Step 4, ciphertext equality test algorithm EqT etoken (c, c′): The cloud server inputs the token etoken for equality test and two ciphertexts c, c′, and outputs a bit b. If the plaintexts corresponding to the ciphertexts c, c′ are equal, then b = 1; otherwise, b = 0. Denote it as b := EqT etoken (c, c′).

[0073] Ciphertext equality test algorithm EqT etoken(c, c′): The token etoken for input equality test and two ciphertexts c = (c1, c2, c3), c′ = (c1′, c2′, c3′) are verified Whether it holds. If it holds, it means the plaintexts corresponding to the ciphertexts c and c′ are equal, and output 1; otherwise, output 0.

[0074] In this embodiment, the encryption end and the decryption end can be the same client.

[0075] There are two application scenarios for the ciphertext equality test algorithm:

[0076] (1) Retrieval scenario: The decryption end or the encryption end (which can be any client, such as Alice or someone else, like Bob) wants to retrieve a certain file (for example, the file "Ode to the Willow") from the cloud server. The public key pk of the decryption end Alice can be used A to encrypt the file "Ode to the Willow" to obtain a ciphertext c′, and send it to the cloud server. The cloud server uses etoken to perform the ciphertext equality test on each ciphertext it stores, respectively, with c′, and sends the equal results back to the user. After the decryption end Alice gets the results, it can decrypt. After the encryption end Bob gets the results, it cannot directly decrypt and needs to request the decryption end Alice to decrypt.

[0077] (2) Duplicate removal scenario: Several encryption ends (for example, users Bob, Carl, and even the decryption end Alice herself) use the public key pk of the decryption end Alice A to encrypt a batch of files (for example, a batch of Tang poems), obtain a series of ciphertexts, and store them on the cloud server. The cloud server can use etoken to run the ciphertext equality test algorithm to determine whether there are duplicates among these ciphertexts. If there are duplicates, only one copy can be stored.

[0078] Verification of decryption correctness:

[0079]

[0080] Verification of ciphertext equality test correctness:

[0081] Let c be the ciphertext of m, then c = (c1, c2, c3) = (h r , u r ·g H(m) , v r ·h H(m) ·m)

[0082] Let c′ be the ciphertext of m′’, then c′ = (c1′, c2′, c3′) = (h r′ , u r′ ·g H(m′) , v r′ ·hH(m′) ·m′)

[0083] while

[0084]

[0085] Therefore, if m = m′, then holds, and the algorithm outputs 1,

[0086] otherwise it does not hold, and the algorithm outputs 0.

[0087] The public - key encryption method of the present invention has the security against chosen - plaintext attack, and the server can independently complete the ciphertext equality test, which can be used to construct a protocol supporting ciphertext duplicate checking and ciphertext retrieval.

[0088] Embodiment 2

[0089] This embodiment provides a public - key encryption method supporting the equality test of outsourced ciphertext data, which is applied to the encryption side and includes the following steps:

[0090] Obtain the plaintext and the public key publicly disclosed by the decryption side;

[0091] Encrypt the plaintext based on the public key to generate a ciphertext, and send the ciphertext to the cloud server or the decryption side;

[0092] Among them, different ciphertexts can perform an equality test in combination with the tokens generated by the decryption side on the cloud server.

[0093] Among them, the public key is:

[0094] pk = (G, q, g, h, u, v, H(·));

[0095] Among them, G is a group of order q; q is a prime number; g is a generator of the group G; random numbers x, y ∈ R Z q ; h = g x , u = g y , v = h y ; the cryptographic Hash function H(·): G → Z q .

[0096] Among them, the ciphertext is:

[0097] c = (c1, c2, c3)

[0098] Among them, c1 = h r ; c2 = u r ·g H(m) ; c3 = v r ·h H(m) ·m; the plaintext m ∈ G; the random number r ∈R Z q ; G is a group of order q; q is a prime number; g is a generator of the group G; random numbers x, y ∈ R Z q ; h = g x , u = g y , v = h y ; cryptographic Hash function H(·): G → Z q .

[0099] Among them, the plaintext obtained by decrypting the ciphertext at the decryption end is:

[0100]

[0101] Among them, c2 and c3 come from the ciphertext, and the random number x ∈ R Z q , q is a prime number.

[0102] Among them, the specific method of the equality test is: based on two ciphertexts c = (c1, c2, c3) and c' = (c1', c2', c3'), verify whether it holds. If it holds, it means that the plaintexts corresponding to the ciphertexts c and c' are equal; among them, c1, c2, c3 are all components of the ciphertext c; c1', c2', c3' are all components of the ciphertext c'; random number y ∈ R Z q , q is a prime number.

[0103] The detailed method is the same as the method provided in Embodiment 1 and will not be elaborated here.

[0104] Embodiment 3

[0105] This embodiment provides a public key encryption method supporting outsourcing ciphertext data equality test, which is applied to the decryption end and includes:

[0106] Generating a public-private key pair and a token, and sending the public key to the encryption end so that the encryption end encrypts the plaintext to generate a ciphertext;

[0107] Based on the private key, decrypting the ciphertext to obtain the plaintext;

[0108] Among them, different ciphertexts can perform an equality test in combination with the token generated by the decryption end on the cloud server.

[0109] Among them, the public key is:

[0110] pk = (G, q, g, h, u, v, H(·));

[0111] Among them, G is a group of order q; q is a prime number; g is a generator of the group G; random numbers x, y ∈ R Zq ; h = g x , u = g y , v = h y ; Cryptographic Hash function H(·): G → Z q .

[0112] Among them, the ciphertext is:

[0113] c = (c1, c2, c3)

[0114] Among them, c1 = h r ; c2 = u r .g H(m) ; c3 = v r ·h H(m) ·m; The plaintext m ∈ G; The random number r ∈ R Z q ; G is a group of order q; q is a prime number; g is a generator of the group G; The random numbers x, y ∈ R Z q ; h = g x , u = g y , v = h y ; Cryptographic Hash function H(·): G → Z q .

[0115] Among them, the plaintext obtained by decryption is:

[0116]

[0117] Among them, c2 and c3 come from the ciphertext, and the random number x ∈ R Z q , q is a prime number.

[0118] Among them, the specific method of the equality test is: Based on two ciphertexts c = (c1, c2, c3) and c' = (c1', c2', c3'), verify Whether it holds. If it holds, it means that the plaintexts corresponding to the ciphertexts c and c' are equal; Among them, c1, c2, c3 are all components of the ciphertext c; c1', c2', c3' are all components of the ciphertext c'; The random number y ∈ R Z q , q is a prime number.

[0119] The detailed method is the same as the method provided in Embodiment 1 and will not be elaborated here.

[0120] Embodiment 4

[0121] This embodiment provides a public key encryption system that supports outsourcing the equality test of ciphertext data;

[0122] A public key encryption system that supports outsourcing ciphertext data equality testing, including an encryption end and a decryption end;

[0123] The decryption end is used to generate a public-private key pair and a token, and send the public key to the encryption end;

[0124] The encryption end is used to encrypt the plaintext based on the public key, generate ciphertext, and send the ciphertext to the cloud server or the decryption end;

[0125] Among them, different ciphertexts can perform equality testing in the cloud server in combination with the token.

[0126] The detailed processes of each component have been introduced in Embodiment 1.

[0127] Embodiment 5

[0128] This embodiment also provides an electronic device, including: one or more processors, one or more memories, and one or more computer programs; wherein, the processor is connected to the memory, and the above one or more computer programs are stored in the memory. When the electronic device runs, the processor executes the one or more computer programs stored in the memory, so that the electronic device executes the method described in Embodiment 2 or Embodiment 3 above.

[0129] It should be understood that in this embodiment, the processor may be a central processing unit CPU, and the processor may also be other general-purpose processors, digital signal processors DSP, application-specific integrated circuits ASIC, off-the-shelf programmable gate arrays FPGA or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0130] The memory may include a read-only memory and a random access memory, and provide instructions and data to the processor. A part of the memory may also include a non-volatile random memory. For example, the memory may also store information about the device type.

[0131] In the implementation process, each step of the above method can be completed by the integrated logic circuit in the hardware of the processor or the instructions in the form of software.

[0132] The method in Embodiment 2 or Embodiment 3 can be directly embodied as being executed by the hardware processor, or completed by the combination of the hardware and software modules in the processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above method. To avoid repetition, it will not be described in detail here.

[0133] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in conjunction with this embodiment can be implemented by electronic hardware or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.

[0134] Embodiment Six

[0135] This embodiment also provides a computer-readable storage medium for storing computer instructions. When the computer instructions are executed by a processor, the methods described in Embodiment Two or Embodiment Three are completed.

[0136] The above are only the preferred embodiments of the present application and are not used to limit the present application. For those skilled in the art, the present application can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.

Claims

1. A public key encryption method supporting outsourced ciphertext data equality testing, characterized in that, Applied to the encryption end, including: Obtain the plaintext and the public key publicly disclosed by the decryption end; the public key is: pk = (G, q, g, h, u, v, H(·)); where G is a group of order q; q is a prime number; g is a generator of the group G; random numbers x, y ∈ R Z q ; h = g x , u = g y , v = h y ; the cryptographic Hash function H(·): G → Z q ; Encrypt the plaintext based on the public key to generate the ciphertext and send the ciphertext to the cloud server or the decryption end; the ciphertext is: c = (c1, c2, c3); where, c1 = h r ; c2 = u r ·g H(m) ; c3 = v r ·h H(m) ·m; the plaintext m ∈ G; the random number r ∈ R Z q ; the plaintext obtained by decrypting the ciphertext at the decryption end is: where, c2 and c3 are from the ciphertext, the random number x ∈ R Z q , q is a prime number; Among them, different ciphertexts can perform equality tests when the token etoken = y generated by the cloud server in combination with the decryption end; the specific method of the equality test is as follows: Based on two ciphertexts c = (c1, c2, c3) and c' = (c1', c2', c3'), verify Whether it holds. If it holds, it means that the plaintexts corresponding to the ciphertexts c and c' are equal; where c1, c2, and c3 are all components of the ciphertext c; c1', c2', and c3' are all components of the ciphertext c'.

2. A public key encryption method for supporting the outsourcing of ciphertext data equality testing, characterized in that, Applied to the decryption end, including: Generate a public-private key pair and a token, and send the public key to the encryption end so that the encryption end encrypts the plaintext to generate a ciphertext; the public key is: pk = (G, q, g, h, u, v, H(·)); where G is a group of order q; q is a prime number; g is a generator of the group G; random numbers x, y ∈ R Z q ; h = g x , u = g y , v = h y ; the cryptographic Hash function H(·): G → Z q ; the ciphertext is: c = (c1, c2, c3); where, c1 = h r ; c2 = u r ·g H(m) ; c3 = v r ·h H(m) ·m; the plaintext m ∈ G; random number r ∈ R Z q ; Decrypt the ciphertext based on the private key to obtain the plaintext; the plaintext obtained by decrypting the ciphertext at the decryption end is: where c2 and c3 are from the ciphertext, and the random number x ∈ R Z q , and q is a prime number; Among them, different ciphertexts can perform an equality test in the cloud server in combination with the token etoken = y; the specific method of the equality test is as follows: based on two ciphertexts c = (c1, c2, c3) and c' = (c1', c2', c3'), verify whether it holds. If it holds, it means that the plaintexts corresponding to the ciphertexts c and c' are equal; among them, c1, c2, and c3 are all components of the ciphertext c; c1', c2', and c3' are all components of the ciphertext c'.

3. A public key encryption method that supports outsourcing the equality test of ciphertext data, characterized in that, Including: The decryption end generates a public-private key pair and a token, and sends the public key to the encryption end; the public key is: pk = (G, q, g, h, u, v, H(·)); where G is a group of order q; q is a prime number; g is a generator of the group G; random numbers x, y ∈ R Z q ; h = g x , u = g y , v = h y ; the cryptographic Hash function H(·): G → Z q ; The encryption end encrypts the plaintext based on the public key to generate the ciphertext and sends the ciphertext to the cloud server or the decryption end; the ciphertext is: c = (c1, c2, c3); where, c1 = h r ; c2 = u r ·g H(m) ; c3 = v r ·h H(m) ·m; the plaintext m ∈ G; the random number r ∈ R Z q ; the plaintext obtained by decrypting the ciphertext at the decryption end is: where, c2 and c3 are from the ciphertext, the random number x ∈ R Z q , q is a prime number; Among them, different ciphertexts can perform an equality test in the cloud server in combination with the token etoken = y; the specific method of the equality test is: based on two ciphertexts c = (c1, c2, c3) and c' = (c1', c2', c3'), verify whether it holds. If it holds, it means that the plaintexts corresponding to the ciphertexts c and c' are equal; among them, c1, c2, and c3 are all components of the ciphertext c; c1', c2', and c3' are all components of the ciphertext c'.

4. A public key encryption system that supports the outsourcing of ciphertext data equality testing, characterized in that, Including an encryption end and a decryption end; The decryption end is used to generate a public-private key pair and a token, and send the public key to the encryption end; the public key is: pk = (G, q, g, h, u, v, H(·)); where G is a group of order q; q is a prime number; g is a generator of the group G; random numbers x, y ∈ R Z q ; h = g x ^x y ^y y ; the cryptographic Hash function H(·): G → Z q ; Note: In the original Chinese text, there are some missing exponents in the expressions of h, u, and v. I have added them according to the common form of such cryptographic key expressions in English translations. If this is not in line with your intention, please let me know. The encryption end is used to encrypt the plaintext based on the public key, generate the ciphertext, and send the ciphertext to the cloud server or the decryption end; the ciphertext is: c = (c1, c2, c3); where, c1 = h r ; c2 = u r ·g H(m) ; c3 = v r ·h H(m) ·m; the plaintext m ∈ G; the random number r ∈ R Z q ; the plaintext obtained by decrypting the ciphertext at the decryption end is: where, c2 and c3 are from the ciphertext, the random number x ∈ R Z q , q is a prime number; Among them, different ciphertexts can perform equality tests in the cloud server in combination with the token etoken = y; the specific method of the equality test is as follows: based on two ciphertexts c = (c1, c2, c3) and c' = (c1', c2', c3'), verify Whether it holds. If it holds, it means that the plaintexts corresponding to the ciphertexts c and c' are equal; among them, c1, c2, and c3 are all components of the ciphertext c; c1', c2', and c3' are all components of the ciphertext c'.

5. An electronic device, characterized in that it includes: A memory for non-temporarily storing computer-readable instructions; And A processor for running the computer-readable instructions, wherein, when the computer-readable instructions are run by the processor, the method described in any one of claims 1 or 2 above is executed.

6. A storage medium, characterized in that it non-temporarily stores computer-readable instructions, wherein, When the non-temporary computer-readable instructions are executed by a computer, instructions for executing the method described in any one of claims 1 or 2.

Citation Information

Patent Citations

  • Method for supporting synchronization ciphertext comparison of backup server

    CN109246098A

  • Efficient public key encryption method supporting differential equality test

    CN113992397A