K-NN query method for medical data based on homomorphic encryption

By adopting homomorphic encryption and Paillier cryptography system in cloud servers, combined with the identity allocation of Lagrangian polynomials, the problems of key security and operation control during medical data k-NN query in cloud servers are solved, and efficient and secure medical data query is achieved.

CN116318662BActive Publication Date: 2025-05-13XIDIAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310084603.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-08
Publication Date
2025-05-13
Estimated Expiration
2043-02-08

AI Technical Summary

Technical Problem

In the prior art, when medical data is queried in a cloud server, it is assumed that the patient is completely trustworthy, and there is a problem that the key is stolen by the attacker, resulting in data insecurity, and the patient's operation after holding the key is uncontrolled.

Method used

A method based on homomorphic encryption is adopted, a public-private key pair is generated using the Paillier cipher system, and an identity identification is assigned to each user through the Lagrangian polynomial to ensure that each user only has its own private key to decrypt the medical data ciphertext it needs.

Benefits of technology

It effectively protects the security of outsourced data, prevents access by non-registered users, and reduces the Euclidean distance ciphertext comparison operation through the idea of ​​priority queues, and reduces the time complexity of the query algorithm.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116318662B_ABST
    Figure CN116318662B_ABST
Patent Text Reader

Abstract

The present invention discloses an efficient and secure k-NN query method for medical data based on homomorphic encryption, which is applied to a cloud server and includes: a cloud computing server generates a required public-private key pair; a cloud storage server receives uploaded ciphertext data and patient data ciphertext; the cloud storage server verifies whether the user terminal is registered; if the user terminal is registered, the cloud storage server and the cloud computing server calculate the Euclidean distance ciphertext between each indicator in each medical data ciphertext and each indicator in the patient data ciphertext; the cloud storage server selects k medical data ciphertexts closest to the user's physical indicators, and sends them to the user terminal after partial decryption. Since each user terminal has its own private key, it can only decrypt the medical data ciphertext required by itself, which is beneficial to protecting the security of outsourced data, and can reject the request service of non-registered users, improve the actual utilization rate of the server, and reduce the time complexity of the query algorithm.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of data processing, and in particular relates to a k-NN query method for medical data based on homomorphic encryption. Background Art

[0002] As an emerging computing paradigm, cloud computing has important applications in the field of electronic medical data query. Although cloud servers have the advantages of flexibility, reliability, and strong storage capacity, the security and privacy of data in the cloud still need to be taken seriously. In fact, cloud servers are not completely trustworthy. When highly sensitive data such as medical data is uploaded directly to the cloud without any processing, serious privacy leakage may occur. Therefore, encrypting the data before uploading becomes an effective means to protect data security.

[0003] As a basic query algorithm for machine learning, the k-NN algorithm aims to find the k pieces of data closest to a given query data in a data set. Considering that ciphertext data is not as transparent as plaintext, how cloud servers can perform secure and efficient k-NN queries on encrypted data has become a topic of continuous research in recent years. In related technologies, when using the k-NN algorithm to query medical data, most k-NN query algorithms assume that the patient is completely trustworthy and has the key to encrypt and decrypt outsourced data, which obviously brings some problems: on the one hand, once the key held by the patient is stolen by an attacker, the ciphertext data of the entire cloud server will be successfully decrypted by the attacker, and the medical data will not be secure; on the other hand, once the patient obtains the key, his subsequent operations will not be controlled by the hospital, that is, hospitals and other medical institutions cannot prevent certain operations of the patient, which will bring great security risks. Summary of the invention

[0004] In order to solve the above problems existing in the prior art, the present invention provides a k-NN query method for medical data based on homomorphic encryption. The technical problem to be solved by the present invention is achieved through the following technical solutions:

[0005] The present invention provides a k-NN query method for medical data based on homomorphic encryption, which is applied to a cloud server, wherein the cloud server includes a cloud computing server and a cloud storage server;

[0006] The method comprises:

[0007] The cloud computing server generates a public-private key pair using the key generation algorithm of the Paillier cryptographic system, generates the ID identity set of the user terminal based on the private key sk and the Lagrange polynomial, and then assigns an identity identifier to each user terminal from the ID identity set;

[0008] The cloud storage server receives the encrypted database uploaded by the user and the encrypted patient data generated based on the patient's physical indicators [q] pk , select random number R to perform Paillier encryption and get the ciphertext C R And based on the patient data ciphertext [q] pk , a random number R and a verification value h generated by the identity identifier, the ciphertext database contains a plurality of medical data ciphertexts;

[0009] The cloud storage server sends the ciphertext C R Send it to the cloud computing server, and verify whether the user terminal is registered according to the first AES ciphertext returned by the cloud computing server;

[0010] If the user has registered, the cloud storage server uses the Paillier algorithm to encrypt the selected random number r to generate ciphertext X1, and generates ciphertext X2 based on the random number r and ciphertext X1; after receiving the ciphertext X calculated by the cloud computing server, the patient data ciphertext [q] is calculated based on the ciphertext X1 and ciphertext X. pk The Euclidean distance ciphertext between each indicator in the ciphertext of each medical data;

[0011] After the cloud storage server randomly selects k Euclidean distance ciphertexts from multiple Euclidean distance ciphertexts and stores them in the priority queue, it calculates the intermediate value based on the randomly selected s and sends the intermediate value to the cloud computing server;

[0012] The cloud computing server decrypts the intermediate value using the private key sk, and sets a first identifier t according to the obtained plaintext length;

[0013] The cloud storage server adjusts the priority queue based on the second AES ciphertext to obtain the smallest k Euclidean distance ciphertexts among the multiple Euclidean distance ciphertexts, wherein the second AES ciphertext is obtained by encrypting the first identifier t by the cloud storage server;

[0014] The cloud storage server obtains the k medical data ciphertexts corresponding to the k smallest Euclidean distance ciphertexts, decrypts them and sends them to the user. The cloud computing server generates a public-private key pair using the key generation algorithm of the Paillier cryptographic system, and generates the ID identity set of the user based on the private key sk and the Lagrange polynomial, and then assigns an identity to each user from the ID identity set;

[0015] The cloud storage server receives the encrypted database uploaded by the user and the encrypted patient data generated based on the patient's physical indicators [q] pk , select random number R to perform Paillier encryption and get the ciphertext C R And based on the patient data ciphertext [q] pk, a random number R and a verification value h generated by the identity identifier, the ciphertext database contains a plurality of medical data ciphertexts;

[0016] The cloud storage server sends the ciphertext C R Send it to the cloud computing server, and verify whether the user terminal is registered according to the first AES ciphertext returned by the cloud computing server;

[0017] If the user has registered, the cloud storage server uses the Paillier algorithm to encrypt the selected random number r to generate ciphertext X1, and generates ciphertext X2 based on the random number r and ciphertext X1; after receiving the ciphertext X calculated by the cloud computing server, the patient data ciphertext [q] is calculated based on the ciphertext X1 and ciphertext X. pk The Euclidean distance ciphertext between each indicator in the ciphertext of each medical data;

[0018] After the cloud storage server randomly selects k Euclidean distance ciphertexts from multiple Euclidean distance ciphertexts and stores them in the priority queue, it calculates the intermediate value based on the randomly selected s and sends the intermediate value to the cloud computing server;

[0019] The cloud computing server decrypts the intermediate value using the private key sk, and sets a first identifier t according to the obtained plaintext length;

[0020] The cloud storage server adjusts the priority queue based on the second AES ciphertext to obtain the smallest k Euclidean distance ciphertexts among the multiple Euclidean distance ciphertexts, wherein the second AES ciphertext is obtained by encrypting the first identifier t by the cloud storage server;

[0021] The cloud storage server obtains the k medical data ciphertexts corresponding to the k smallest Euclidean distance ciphertexts, decrypts them and sends them to the user end.

[0022] In one embodiment of the present invention, after the cloud computing server generates a public-private key pair using a key generation algorithm of the Paillier cryptographic system and generates an ID identity set of the user terminal based on the private key sk and the Lagrange polynomial, and after the step of assigning an identity identifier to each user terminal from the ID identity set, the step further includes:

[0023] The cloud computing server calculates the first key sk according to the identity identifier ID and the second key sk Δ ;in,

[0024]

[0025] In the formula, f(·) is the a-1 order Lagrangian polynomial generated by the cloud computing server, a represents a preset constant, w i 、w jRespectively represent the i-th random number and the j-th random number, x i represents the identity of the i-th user, and n represents the number of index items of the patient data ciphertext and each medical data ciphertext.

[0026] In one embodiment of the present invention, the cloud storage server sends the ciphertext C R The step of sending the first AES ciphertext to the cloud computing server and verifying whether the user terminal is registered according to the first AES ciphertext returned by the cloud computing server includes:

[0027] The cloud storage server sends the ciphertext C R Send to cloud computing server;

[0028] The cloud computing server processes the ciphertext C R After decryption, a random number R is obtained, and after the random number R is encrypted using the AES symmetric encryption algorithm, the obtained first AES ciphertext is sent to the cloud storage server;

[0029] The cloud storage server decrypts the first AES ciphertext to obtain a random number R, performs XOR processing on the random number R and the ciphertext q, and then uses a hash function to calculate a hash value of the first XOR processing result;

[0030] The cloud storage server performs XOR processing on the hash value and the verification value h, and compares the identity identifier of the user terminal with the obtained second XOR processing result; if the identity identifier of the user terminal is equal to the second XOR processing result, the user terminal is registered; otherwise, the user terminal is not registered.

[0031] In one embodiment of the present invention, if the user terminal has registered, the cloud storage server generates ciphertext X1 and ciphertext X2 based on the random number r, and after receiving the ciphertext X calculated by the cloud computing server, calculates the patient data ciphertext [q] according to the ciphertext X1 and the ciphertext X. pk The steps of calculating the Euclidean distance between each indicator in the ciphertext of each medical data include:

[0032] The cloud storage server uses the Paillier algorithm to encrypt the selected random number r and generate the ciphertext X1, where [p l,n' ] pk represents the n'th index in the ciphertext of the lth medical data in the ciphertext database D, [q n' ] pk represents the n'th index in the patient data ciphertext, n'=1,2…,n, n represents the number of index items in the patient data ciphertext and each medical data ciphertext, [·] pk Indicates encryption using the public key pk, and N represents the modulus of the Paillier algorithm;

[0033] The cloud storage server generates ciphertext X2 based on the random number r and ciphertext X1, and sends the ciphertext X2 to the cloud computing server, where X2 = X1 · [r] pk ;

[0034] The cloud computing server decrypts the ciphertext X2 to obtain the plaintext p l,n' -q n' +r, calculate the plaintext p l,n' -q n' +r squared and encrypted into ciphertext X and sent to the cloud storage server;

[0035] The cloud storage server calculates the patient data ciphertext [q] according to the following formula based on the ciphertext X1 and ciphertext X: pk The Euclidean distance ciphertext between each indicator in the ciphertext of each medical data:

[0036]

[0037] Where N represents the modulus of the Paillier algorithm, [r 2 ] pk Indicates using pk to encrypt r 2 The obtained ciphertext, d, is the Euclidean distance ciphertext between the n'th index in the patient data ciphertext and the n'th index in the lth medical data ciphertext.

[0038] In one embodiment of the present invention, the cloud storage server randomly selects k Euclidean distance ciphertexts from a plurality of Euclidean distance ciphertexts and stores them in a priority queue, calculates an intermediate value based on the randomly selected s, and sends the intermediate value to the cloud computing server, comprising:

[0039] The cloud storage server randomly selects k Euclidean distance ciphertexts from the calculated multiple Euclidean distance ciphertexts, and stores the k Euclidean distance ciphertexts and their index values ​​into a priority queue;

[0040] The cloud storage server randomly selects s=0 or s=1 and selects a random number u that satisfies After that, the intermediate value [l'] is calculated according to the value of s pk ; If s = 1, then If s = 0, then p l represents the medical data corresponding to the ciphertext with the smallest Euclidean distance in the priority queue, p v represents the medical data corresponding to any Euclidean distance ciphertext that is not stored in the priority queue, q represents the patient data, Indicates bit length;

[0041] The cloud storage server will store the intermediate value [l'] pk Send to cloud computing server.

[0042] In one embodiment of the present invention, the cloud computing server decrypts the intermediate value using the private key sk, and sets the first identifier t according to the obtained plaintext length, including:

[0043] The cloud computing server uses the private key sk to decrypt the intermediate value [l'] pk , if the decrypted plaintext l' satisfies: Then the first flag t=1 is set; otherwise, the first flag t=0 is set.

[0044] In one embodiment of the present invention, the cloud storage server adjusts the priority queue based on the second AES ciphertext to obtain the smallest k Euclidean distance ciphertexts among the multiple Euclidean distance ciphertexts, including:

[0045] When s≠t, it means Then discard p l And p v Deposit p l The k smallest Euclidean distance ciphertexts among the multiple Euclidean distance ciphertexts are obtained at the position in the priority queue.

[0046] In one embodiment of the present invention, the cloud storage server obtains k pieces of medical data ciphertexts corresponding to the k smallest Euclidean distance ciphertexts, decrypts them and sends them to the user end, including:

[0047] The cloud storage server obtains various indicators of the k medical data ciphertexts corresponding to the k smallest Euclidean distance ciphertexts And using the first key sk ID Decrypt to obtain the medical data ciphertext required by the user in,

[0048] The cloud storage server encrypts the medical data required by the user and the second key sk Δ Sent to the user end so that the user end uses the second key sk Δ right Decrypt it and get the required medical data plaintext.

[0049] Compared with the prior art, the present invention has the following beneficial effects:

[0050] The embodiment of the present invention provides a k-NN method for medical data based on homomorphic encryption. By integrating the private key of the Paillier algorithm into the constant term of the Lagrange interpolation polynomial, each user terminal has its own private key and can only decrypt the medical data ciphertext required by itself, which is conducive to protecting the security of outsourced data. In addition, the present invention assigns a unique identity to each user terminal, verifies whether the user terminal is registered by comparing the verification value h with the identity, and can reject the service request of non-registered users, thereby improving the actual utilization rate of the server.

[0051] Furthermore, during the query process on the user side, the present invention adopts the idea of ​​priority queue to temporarily store k Euclidean distance ciphertexts, and dynamically adjusts the order of elements in the queue by comparing the remaining Euclidean distance ciphertexts with the smallest Euclidean distance ciphertext in the priority queue, thereby effectively reducing repeated Euclidean distance ciphertext comparison operations between the cloud computing server and the cloud storage server, and reducing the time complexity of the query algorithm.

[0052] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] Figure 1 It is a flow chart of a k-NN query method for medical data based on homomorphic encryption provided by an embodiment of the present invention;

[0054] Figure 2 It is a schematic diagram of a k-NN query method for medical data based on homomorphic encryption provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0055] The present invention is further described in detail below with reference to specific embodiments, but the embodiments of the present invention are not limited thereto.

[0056] Figure 1 is a flow chart of a k-NN query method for medical data based on homomorphic encryption provided by an embodiment of the present invention. Figure 2 FIG. 1 is a schematic diagram of a k-NN query method for medical data based on homomorphic encryption provided by an embodiment of the present invention. Figure 1-2 As shown, an embodiment of the present invention provides a k-NN query method for medical data based on homomorphic encryption, which is applied to a cloud server, and the cloud server includes a cloud computing server and a cloud storage server;

[0057] The above methods include:

[0058] S1. The cloud computing server generates a public-private key pair using the key generation algorithm of the Paillier cryptographic system, generates the ID identity set of the user terminal based on the private key sk and the Lagrange polynomial, and then assigns an identity to each user terminal from the ID identity set;

[0059] S2, the cloud storage server receives the ciphertext database uploaded by the user, and the patient data ciphertext generated based on the patient's physical indicators [q] pk , select random number R to perform Paillier encryption and get the ciphertext C R And based on the patient data ciphertext [q] pk , a verification value h generated by a random number R and an identity identifier, the ciphertext database contains multiple medical data ciphertexts;

[0060] S3, the cloud storage server sends the ciphertext C R Send it to the cloud computing server, and verify whether the user terminal is registered according to the first AES ciphertext returned by the cloud computing server;

[0061] S4. If the user has registered, the cloud storage server uses the Paillier algorithm to encrypt the selected random number r to generate ciphertext X1, and generates ciphertext X2 based on the random number r and ciphertext X1; after receiving the ciphertext X calculated by the cloud computing server, the patient data ciphertext [q] is calculated based on the ciphertext X1 and ciphertext X. pk The Euclidean distance ciphertext between each indicator in the ciphertext of each medical data;

[0062] S5, the cloud storage server randomly selects k Euclidean distance ciphertexts from the calculated multiple Euclidean distance ciphertexts and stores them in the priority queue, calculates the intermediate value based on the randomly selected s, and sends the intermediate value to the cloud computing server;

[0063] S6. The cloud computing server decrypts the intermediate value using the private key sk and sets a first identifier t according to the obtained plaintext length;

[0064] S7. The cloud storage server adjusts the priority queue based on the second AES ciphertext to obtain the smallest k Euclidean distance ciphertexts among the multiple Euclidean distance ciphertexts, where the second AES ciphertext is obtained by encrypting the first identifier t by the cloud storage server;

[0065] S8. The cloud storage server obtains the k medical data ciphertexts corresponding to the k smallest Euclidean distance ciphertexts, decrypts them and sends them to the user end.

[0066] Optionally, after the cloud computing server generates a public-private key pair using a key generation algorithm of the Paillier cryptographic system, and generates an ID identity set of the user terminal based on the private key sk and the Lagrange polynomial, and then assigns an identity identifier to each user terminal from the ID identity set, the method further includes:

[0067] The cloud computing server calculates the first key sk according to the identity ID and the second key sk Δ ;in,

[0068]

[0069] In the formula, f(·) is a Lagrangian polynomial of order a - 1 generated by the cloud computing server, a represents a preset constant, w i , w j represent the i-th random number and the j-th random number respectively, x i represents the identity identifier of the i-th client, and n represents the number of index items of the patient data ciphertext and each medical data ciphertext.

[0070] Specifically, in the above step S1, the cloud computing server uses the key generation algorithm of the Paillier cryptosystem to generate a public-private key pair {pk, sk}, where pk represents the public key and sk represents the private key. The cloud computing server selects a random number δ (δ≡0 mod sk, δ≡1 mod n 2 ) to generate a Lagrangian polynomial of order a - 1 f(x) = δ + A1x + A2x 2 +,..., A a-1 x a-1 , selects a - 1 + t (t < a) points from the polynomial f(x), where t points are used as the ID identity set of the client {(x i , f(x i )} i∈(1,...,t) , and the remaining a - 1 points form a set {(w i , f(w i )} i∈(1,...,a-1) .

[0071] Furthermore, the cloud computing server can allocate a unique identity representation x i for each querying client from the ID identity set {(x i , f(x i∈(1,...,t) )} i , and perform the following calculations:

[0072]

[0073] It should be noted that in the k-NN differential selection method of medical data based on homomorphic encryption provided by the present invention, the ciphertext database D can be obtained by a medical institution such as a hospital encrypting the medical database using the public key pk. Among them, each medical data ciphertext in the ciphertext database D can be expressed in the form of a vector: [p l pk = {[p l,1 pk , [p l,2 pk ,..., [p l,n pk ​​​​}, n is the dimension of each medical data ciphertext, that is, the number of indicator items contained in each medical data ciphertext.

[0074] In addition, the patient's physical indicators can also be encrypted by the user and uploaded to the cloud storage server. For example, the user uses the public key pk to encrypt his own physical indicators and obtain the patient data ciphertext [q] pk , the patient data ciphertext is n-dimensional, that is, it contains n indicators. Then, the user selects a random number R and performs Paillier encryption to obtain the ciphertext C R , and then the patient data ciphertext [q] pk After XOR operation with random number R, it is put into hash function H(x) to get hash value, and finally combined with identity x i XOR is performed to obtain the verification value h. The user terminal sends the patient data ciphertext [q] pk 、Ciphertext C R And the verification value h is uploaded to the cloud storage server.

[0075] In the above step S3, the cloud storage server sends the ciphertext C R The step of sending the first AES ciphertext to the cloud computing server and verifying whether the user terminal is registered according to the first AES ciphertext returned by the cloud computing server includes:

[0076] S301, the cloud storage server sends the ciphertext C R Send to cloud computing server;

[0077] S302, the cloud computing server processes the ciphertext C R After decryption, a random number R is obtained, and after the random number R is encrypted using the AES symmetric encryption algorithm, the obtained first AES ciphertext is sent to the cloud storage server;

[0078] S303, the cloud storage server decrypts the first AES ciphertext to obtain a random number R, performs XOR processing on the random number R and the ciphertext q, and then uses a hash function to calculate a hash value of the first XOR processing result;

[0079] S304, the cloud storage server performs XOR processing on the hash value and the verification value h, and compares the identity identifier of the user terminal with the obtained second XOR processing result; if the identity identifier of the user terminal is equal to the second XOR processing result, the user terminal is registered; otherwise, the user terminal is not registered.

[0080] Specifically, the cloud storage server will ciphertext C RAfter sending it to the cloud computing server, the cloud computing server decrypts it to obtain a random number R, and encrypts the random number R using the AES symmetric encryption algorithm. The cloud storage server further sends the encrypted first AES ciphertext to the cloud storage server. The cloud storage server decrypts the first AES ciphertext to obtain a random number R, performs XOR processing on the random number R and the ciphertext q, and then uses the hash function to calculate the hash value of the first hash processing result, and then performs XOR processing on it and the verification value h to obtain a second XOR processing result.

[0081] Optionally, if the second hash processing result is the same as the user's identity x i If the second hash processing result is the same as the user's identity x, it means that the user has registered and can provide query services for it later; otherwise, if the second hash processing result is the same as the user's identity x i If they are different, it means that the client is not registered, and the server will refuse service.

[0082] In the above step S4, if the user terminal has registered, the cloud storage server generates ciphertext X1 and ciphertext X2 based on the random number r, and after receiving the ciphertext X calculated by the cloud computing server, calculates the patient data ciphertext [q] according to the ciphertext X1 and ciphertext X. pk The steps of calculating the Euclidean distance between each indicator in the ciphertext of each medical data include:

[0083] S401, the cloud storage server uses the Paillier algorithm to encrypt the selected random number r to generate a ciphertext X1, where [p l,n' ] pk represents the n'th index in the ciphertext of the lth medical data in the ciphertext database D, [q n' ] pk represents the n'th index in the patient data ciphertext, n'=1,2…,n, n represents the number of index items in the patient data ciphertext and each medical data ciphertext, [·] pk Indicates encryption using the public key pk, and N represents the modulus of the Paillier algorithm;

[0084] S402: The cloud storage server generates a ciphertext X2 based on the random number r and the ciphertext X1, and sends the ciphertext X2 to the cloud computing server, where X2=[p l,n' -q n' +r] pk ;

[0085] S403, the cloud computing server decrypts the ciphertext X2 to obtain the plaintext p l,n' -q n' +r, calculate the plaintext p l,n' -q n' +r squared and encrypted into ciphertext X and sent to the cloud storage server;

[0086] S404, the cloud storage server calculates the patient data ciphertext [q] according to the ciphertext X1 and the ciphertext X according to the following formula: pk The Euclidean distance ciphertext between each indicator in the ciphertext of each medical data:

[0087]

[0088] In the formula, [r 2 ] pk Indicates using pk to encrypt r 2 The obtained ciphertext, d, is the Euclidean distance ciphertext between the n'th index in the patient data ciphertext and the n'th index in the l'th medical data ciphertext.

[0089] Specifically, the cloud storage server selects a random number r and uses the homomorphic characteristics of the Paillier algorithm to perform ciphertext operations to obtain the ciphertext X1:

[0090]

[0091] Then calculate the ciphertext X2 based on the random number r and the ciphertext X1:

[0092] X2=X1·[r] pk =[p l,n' -q n' +r] pk

[0093] The cloud storage server sends the ciphertext X2 to the cloud computing server, and the cloud computing server decrypts the ciphertext X2 to obtain the plaintext p l,n' -q n' +r, and then calculate the plaintext p i,1 -q1+r squared and encrypted into ciphertext X, the cloud computing server sends the ciphertext X to the cloud storage server.

[0094] Furthermore, the cloud storage server calculates the N-1th power of the ciphertext of the square of the random number r, then calculates the N-2rth power of the ciphertext X1, and finally performs the Euclidean distance calculation between the ciphertexts:

[0095]

[0096] Through the continuous interaction between the cloud computing server and the cloud storage server, the ciphertext of each medical data can be obtained. l ] pk Each indicator and patient data ciphertext [q] pk The Euclidean distance between each indicator in the ciphertext.

[0097] In the above step S5, the cloud storage server randomly selects k Euclidean distance ciphertexts from the multiple Euclidean distance ciphertexts and stores them in the priority queue, calculates the intermediate value based on the randomly selected s, and sends the intermediate value to the cloud computing server, including:

[0098] S501, the cloud storage server randomly selects k Euclidean distance ciphertexts from the calculated multiple Euclidean distance ciphertexts, and stores the k Euclidean distance ciphertexts and their index values ​​into a priority queue;

[0099] S502: The cloud storage server randomly selects s=0 or s=1 and selects a random number u that satisfies After that, the intermediate value [l'] is calculated according to the value of s pk ; If s = 1, then If s = 0, then p l represents the medical data corresponding to the ciphertext with the smallest Euclidean distance in the priority queue, p v represents the medical data corresponding to any Euclidean distance ciphertext that is not stored in the priority queue, q represents the patient data, Indicates bit length;

[0100] S503, the cloud storage server sends the intermediate value [l'] pk Send to cloud computing server.

[0101] Specifically, the cloud computing server uses the private key sk to decrypt the intermediate value and sets the first identifier t according to the obtained plaintext length, including:

[0102] The cloud computing server uses the private key sk to decrypt the intermediate value [l'] pk , if the decrypted plaintext l' satisfies: Then the first flag t=1 is set; otherwise, the first flag t=0 is set.

[0103] The cloud computing server uses the private key sk to decrypt. If the decrypted plaintext length meets The first identifier t=1 is set, otherwise, t=0 is set, and t is encrypted using AES to generate a second AES ciphertext and sent to the cloud storage server.

[0104] In the above step S7, the cloud storage server adjusts the priority queue based on the second AES ciphertext to obtain the k smallest Euclidean distance ciphertexts among the multiple Euclidean distance ciphertexts, including:

[0105] When s≠t, it means Then discard p l And p v Deposit p l The position in the priority queue obtains the k smallest Euclidean distance ciphertexts among multiple Euclidean distance ciphertexts.

[0106] Furthermore, the cloud storage server decrypts the second AES ciphertext. If s=t, then If s≠t, then The cloud storage server can adjust the position of the elements in the priority queue according to the comparison result. Specifically, if the medical data p corresponding to the Euclidean distance ciphertext not stored in the priority queue is v The medical data p corresponding to the ciphertext with the smallest Euclidean distance from q is smaller than that in the priority queue l , then p v Deposit p l The position in the priority array. After traversing the remaining Euclidean distance ciphertexts not stored in the priority array in this way, the k medical data ciphertexts closest to q can be obtained.

[0107] In the above step S8, the cloud storage server obtains k medical data ciphertexts corresponding to the k smallest Euclidean distance ciphertexts, decrypts them and sends them to the user end, including:

[0108] The cloud storage server obtains the various indicators of the k medical data ciphertexts corresponding to the k smallest Euclidean distance ciphertexts And using the first key sk ID Decrypt to obtain the medical data ciphertext required by the user in,

[0109] The cloud storage server encrypts the medical data required by the user and the second key sk Δ Sent to the user end so that the user end uses the second key sk Δ right Decrypt it and get the required medical data plaintext.

[0110] Compared with the prior art, the present invention has the following beneficial effects:

[0111] The embodiment of the present invention provides a k-NN method for medical data based on homomorphic encryption. By integrating the private key of the Paillier algorithm into the constant term of the Lagrange interpolation polynomial, each user terminal has its own private key and can only decrypt the medical data ciphertext required by itself, which is conducive to protecting the security of outsourced data. In addition, the present invention assigns a unique identity to each user terminal, verifies whether the user terminal is registered by comparing the verification value h with the identity, and can reject the service request of non-registered users, thereby improving the actual utilization rate of the server.

[0112] Furthermore, during the query process on the user side, the present invention adopts the idea of ​​priority queue to temporarily store k Euclidean distance ciphertexts, and dynamically adjusts the order of elements in the queue by comparing the remaining Euclidean distance ciphertexts with the smallest Euclidean distance ciphertext in the priority queue, thereby effectively reducing repeated Euclidean distance ciphertext comparison operations between the cloud computing server and the cloud storage server, and reducing the time complexity of the query algorithm.

[0113] In the description of the present invention, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features. In the description of the present invention, the meaning of "plurality" is two or more, unless otherwise clearly and specifically defined.

[0114] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine different embodiments or examples described in this specification.

[0115] The above contents are further detailed descriptions of the present invention in combination with specific preferred embodiments, and it cannot be determined that the specific implementation of the present invention is limited to these descriptions. For ordinary technicians in the technical field to which the present invention belongs, several simple deductions or substitutions can be made without departing from the concept of the present invention, which should be regarded as falling within the protection scope of the present invention.

Claims

1. A k-NN query method for medical data based on homomorphic encryption, characterized in that: Applied to a cloud server, the cloud server includes a cloud computing server and a cloud storage server; The method comprises: The cloud computing server generates a public-private key pair using the key generation algorithm of the Paillier cryptographic system, generates the ID identity set of the user terminal based on the private key sk and the Lagrange polynomial, and then assigns an identity identifier to each user terminal from the ID identity set; The cloud storage server receives the encrypted database uploaded by the user and the encrypted patient data generated based on the patient's physical indicators [q] pk , select random number R to perform Paillier encryption and get the ciphertext C R And based on the patient data ciphertext [q] pk , a random number R and a verification value h generated by the identity identifier, the ciphertext database contains a plurality of medical data ciphertexts; The cloud storage server sends the ciphertext C R Send it to the cloud computing server, and verify whether the user terminal is registered according to the first AES ciphertext returned by the cloud computing server; If the user has registered, the cloud storage server uses the Paillier algorithm to encrypt the selected random number r to generate ciphertext X1, and generates ciphertext X2 based on the random number r and ciphertext X1; after receiving the ciphertext X calculated by the cloud computing server, the patient data ciphertext [q] is calculated based on the ciphertext X1 and ciphertext X. pk The Euclidean distance ciphertext between each indicator in the ciphertext of each medical data; After the cloud storage server randomly selects k Euclidean distance ciphertexts from multiple Euclidean distance ciphertexts and stores them in the priority queue, it calculates the intermediate value based on the randomly selected s and sends the intermediate value to the cloud computing server; The cloud computing server decrypts the intermediate value using the private key sk, and sets a first identifier t according to the obtained plaintext length; The cloud storage server adjusts the priority queue based on the second AES ciphertext to obtain the smallest k Euclidean distance ciphertexts among the multiple Euclidean distance ciphertexts, wherein the second AES ciphertext is obtained by encrypting the first identifier t by the cloud storage server; The cloud storage server obtains the k medical data ciphertexts corresponding to the k smallest Euclidean distance ciphertexts, decrypts them and sends them to the user end.

2. The k-NN query method for medical data based on homomorphic encryption according to claim 1 is characterized in that: The cloud computing server generates a public-private key pair using a key generation algorithm of the Paillier cryptographic system, generates an ID identity set of the user terminal based on the private key sk and the Lagrange polynomial, and after the step of assigning an identity identifier to each user terminal from the ID identity set, further includes: The cloud computing server calculates the first key sk according to the identity identifier ID and the second key sk Δ ;in, In the formula, f(·) is the a-1 order Lagrangian polynomial generated by the cloud computing server, a represents a preset constant, w i 、w j Respectively represent the i-th random number and the j-th random number, x i represents the identity of the i-th user, and n represents the number of index items of the patient data ciphertext and each medical data ciphertext.

3. The k-NN query method for medical data based on homomorphic encryption according to claim 1, characterized in that: The cloud storage server sends the ciphertext C R The step of sending the first AES ciphertext to the cloud computing server and verifying whether the user terminal is registered according to the first AES ciphertext returned by the cloud computing server includes: The cloud storage server sends the ciphertext C R Send to cloud computing server; The cloud computing server processes the ciphertext C R After decryption, a random number R is obtained, and after the random number R is encrypted using the AES symmetric encryption algorithm, the obtained first AES ciphertext is sent to the cloud storage server; The cloud storage server decrypts the first AES ciphertext to obtain a random number R, performs XOR processing on the random number R and the ciphertext q, and then uses a hash function to calculate a hash value of the first XOR processing result; The cloud storage server performs XOR processing on the hash value and the verification value h, and compares the identity identifier of the user terminal with the obtained second XOR processing result; if the identity identifier of the user terminal is equal to the second XOR processing result, the user terminal is registered; otherwise, the user terminal is not registered.

4. The k-NN query method for medical data based on homomorphic encryption according to claim 3 is characterized in that: If the user terminal has registered, the cloud storage server generates ciphertext X1 and ciphertext X2 based on the random number r, and after receiving the ciphertext X calculated by the cloud computing server, calculates the patient data ciphertext [q] according to the ciphertext X1 and ciphertext X. pk The steps of calculating the Euclidean distance between each indicator in the ciphertext of each medical data include: The cloud storage server uses the Paillier algorithm to encrypt the selected random number r and generate the ciphertext X1, where [p l,n' ] pk represents the n'th index in the ciphertext of the lth medical data in the ciphertext database D, [q n' ] pk represents the n'th index in the patient data ciphertext, n'=1,2…,n, n represents the number of index items in the patient data ciphertext and each medical data ciphertext, [·] pk Indicates encryption using the public key pk, and N represents the modulus of the Paillier algorithm; The cloud storage server generates ciphertext X2 based on the random number r and ciphertext X1, and sends the ciphertext X2 to the cloud computing server, where X2 = X1 · [r] pk ; The cloud computing server decrypts the ciphertext X2 to obtain the plaintext p l,n' -q n' +r, calculate the plaintext p l,n' -q n' +r squared and encrypted into ciphertext X and sent to the cloud storage server; The cloud storage server calculates the patient data ciphertext [q] according to the following formula based on the ciphertext X1 and ciphertext X: pk The Euclidean distance ciphertext between each indicator in the ciphertext of each medical data: Where N represents the modulus of the Paillier algorithm, [r 2 ] pk Indicates using pk to encrypt r 2 The obtained ciphertext, d, is the Euclidean distance ciphertext between the n'th index in the patient data ciphertext and the n'th index in the lth medical data ciphertext.

5. The k-NN query method for medical data based on homomorphic encryption according to claim 4 is characterized in that: The cloud storage server randomly selects k Euclidean distance ciphertexts from a plurality of Euclidean distance ciphertexts and stores them in a priority queue, calculates an intermediate value based on the randomly selected s, and sends the intermediate value to the cloud computing server, including: The cloud storage server randomly selects k Euclidean distance ciphertexts from the calculated multiple Euclidean distance ciphertexts, and stores the k Euclidean distance ciphertexts and their index values ​​into a priority queue; After the cloud storage server randomly selects s = 0 or s = 1 and selects a random number u satisfying l(u) < l(N) / 4, it calculates the intermediate value [l'] according to the value of s pk ; where, if s = 1, then If s = 0, then p l represents the medical data corresponding to the ciphertext of the smallest Euclidean distance in the priority queue, p v represents the medical data corresponding to any ciphertext of Euclidean distance not stored in the priority queue, q represents patient data, and l(·) represents the bit length; The cloud storage server will store the intermediate value [l'] pk Send to cloud computing server.

6. The k-NN query method for medical data based on homomorphic encryption according to claim 5 is characterized in that: The cloud computing server decrypts the intermediate value using the private key sk, and sets the first identifier t according to the obtained plaintext length, including: The cloud computing server decrypts the intermediate value [l'] using the private key sk pk , if the plaintext l' obtained by decryption satisfies: l(l') < l(N) / 2, then set the first identifier t = 1; otherwise, set the first identifier t = 0.

7. The k-NN query method for medical data based on homomorphic encryption according to claim 6 is characterized in that: The cloud storage server adjusts the priority queue based on the second AES ciphertext to obtain the smallest k Euclidean distance ciphertexts among the multiple Euclidean distance ciphertexts, including: When s≠t, it means Then discard p l And p v Deposit p l The k smallest Euclidean distance ciphertexts among the multiple Euclidean distance ciphertexts are obtained at the position in the priority queue.

8. The k-NN query method for medical data based on homomorphic encryption according to claim 2, characterized in that: The cloud storage server obtains k medical data ciphertexts corresponding to the k smallest Euclidean distance ciphertexts, decrypts them and sends them to the user end, including: The cloud storage server obtains various indicators of the k medical data ciphertexts corresponding to the k smallest Euclidean distance ciphertexts And using the first key sk ID Decrypt to obtain the medical data ciphertext required by the user in, The cloud storage server encrypts the medical data required by the user and the second key sk Δ Sent to the user end so that the user end uses the second key sk Δ right Decrypt it and get the required medical data plaintext.

Citation Information

Patent Citations

  • Cloud medical data monitoring system and monitoring method with efficient privacy protection function

    CN106650205A

  • Privacy protection K-NN (Kth Nearest Neighbor) classification method based on vector homomorphic encryption

    CN106790069A