A method, system and storage medium for tokenized fuzzy query of ciphertext data

By homomorphic encryption of plain text documents and keywords and homomorphic operations to realize cryptographic data tokenized fuzzy query, the problem of fuzzy matching and complex system parameters in the existing technology is solved, and query efficiency and data security are improved.

CN116611099BActive Publication Date: 2025-05-23HANGZHOU DBAPPSECURITY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211405025.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-08
Publication Date
2025-05-23
Estimated Expiration
2042-11-08

AI Technical Summary

Technical Problem

In the prior art, the ciphertext data tokenized query method based on integer homomorphic encryption cannot realize keyword fuzzy matching query, and the system parameter settings are complex, resulting in a decrease in retrieval efficiency.

Method used

The ciphertext document is obtained by encrypting the plain text document, and homomorphically encrypting the keywords of the plain text document to obtain the ciphertext keyword vector. The ciphertext keyword and the encrypted query keyword are homomorphically calculated. According to the homomorphic operation results and the index of the set fuzzy query error character upper limit query result, the query result is finally decrypted.

Benefits of technology

The fuzzy matching query of keywords is realized, which reduces the complexity of system parameters, improves query efficiency, and protects data security through homomorphic operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116611099B_ABST
    Figure CN116611099B_ABST
Patent Text Reader

Abstract

The present invention discloses a fuzzy query method, system and storage medium for tokenization of ciphertext data, and the method comprises the following steps: encrypting a plaintext document to obtain a ciphertext document; homomorphically encrypting the keywords of the plaintext document to obtain ciphertext keywords; binding the ciphertext keyword vector to the ciphertext document; obtaining the query keyword and homomorphically encrypting it to obtain the encrypted query keyword; homomorphically computing the ciphertext keyword and the encrypted query keyword; querying the index of the hit result according to the result of the homomorphic computing and the set upper limit of the fuzzy query error characters; decrypting the ciphertext document corresponding to the index to obtain the query result. The present invention solves the problem in the related art that the keyword fuzzy matching query cannot be realized and the retrieval efficiency is reduced due to the system parameters.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of information security technology, and in particular relates to a fuzzy query method, system and storage medium for tokenizing encrypted data. Background Art

[0002] In the current context of big data and cloud computing, various applications and platforms generate more and more personal and corporate data, which also increases the risk of data privacy leakage. Encrypted data query is the basis of various applications and calculations, and query efficiency and query accuracy have become important indicators to limit the application of encrypted data.

[0003] In order to solve the problem of low efficiency and long time consumption of full-text search when searching for ciphertext, a ciphertext data tokenization query method is currently widely used, that is, ciphertext is tokenized into several keywords for binding, and keyword matching query is directly used when searching the document. In the field of ciphertext data tokenization query, homomorphic encryption has also been used as the main technical means in recent years. The ciphertext data tokenization query method currently used based on homomorphic encryption uses integer homomorphic encryption as the technical basis, performs a homomorphic subtraction when matching keywords, and if the result is 0, it is determined to be a match. However, this method has the following shortcomings: (1) Only one homomorphic subtraction is performed, which can only determine whether two keywords are completely matched, and cannot achieve a certain character error tolerance function, and cannot achieve keyword fuzzy matching query; (2) In order to ensure the security of the integer homomorphic encryption system, it is necessary to set several coordinated system parameters and perform a verification process. The parameter setting is complex, the calculation complexity is high, and the search takes a long time.

[0004] In order to realize keyword fuzzy matching query and simplify system parameters, a fuzzy query method, system and storage medium for tokenizing encrypted data are proposed. Summary of the invention

[0005] The embodiments of the present invention provide a fuzzy query method, system and storage medium for tokenizing encrypted data, so as to at least solve the problem in the related art that keyword fuzzy matching query cannot be implemented and the retrieval efficiency is reduced due to system parameters.

[0006] According to one embodiment of the present invention, a fuzzy query method for tokenizing encrypted data is proposed, comprising:

[0007] Encrypt the plaintext document to obtain the ciphertext document;

[0008] Homomorphically encrypting the keywords of the plaintext document to obtain ciphertext keywords; the ciphertext keyword vector is bound to the ciphertext document;

[0009] Obtain query keywords and perform homomorphic encryption to obtain encrypted query keywords;

[0010] Perform homomorphic operations on the ciphertext keywords and the encrypted query keywords;

[0011] The index of the hit result is searched based on the result of the homomorphic operation and the set upper limit of the fuzzy query error characters;

[0012] The query result is obtained by decrypting the ciphertext document corresponding to the index.

[0013] In an exemplary embodiment, encrypting a plaintext document to obtain a ciphertext document comprises the steps of:

[0014] Determine the document to be encrypted, the document owner, and the owner mapping; the document to be encrypted is denoted as D i , i = 1,…,n; document D i The owner is denoted as P f(i) , the number of owners is recorded as m, and f represents the owner mapping;

[0015] Document Owner P 1 ,…,P m Randomly select their own 128-bit symmetric key 1 ,…,key m ;

[0016] The owner uses the SM4 national encryption algorithm to symmetric encrypt all documents and obtain their own ciphertext documents E i =SM4(D i ,key f(i) ).

[0017] In an exemplary embodiment, the step of homomorphically encrypting the keywords of the plaintext document to obtain the ciphertext keywords includes the following steps:

[0018] Document D i There are t(i) keywords in total. Let j = 1, 2, ..., t(i), then the document keyword vector kw is formed. i =(kw i,1 ,…,kw i,j );

[0019] The owner generates a Paillier public-private key pair;

[0020] Encode each document keyword into a string;

[0021] Convert the string into a large integer according to the big endian storage;

[0022] Encrypt the large integer using the Paillier public key to obtain the ciphertext keyword, and combine them to obtain the ciphertext keyword vector e i =(e i,1 ,…,e i,t(i) ); ciphertext keyword vector ei and the corresponding ciphertext document E i Binding.

[0023] In an exemplary embodiment, the owner generates a Paillier public-private key pair, comprising the steps of:

[0024] Document Owner P 1 ,…,P m Each of them selects a random 1024-bit large prime number p i and q i , calculate the modulus n i =p i ·q i ;

[0025] Let g i =n i +1,λ i =(p i -1)·(q i -1), calculate μ i =λ i -1 mod n i ;

[0026] Calculate owner P i The Paillier public key held is pk i =(n i ,g i ), the private key is sk i =(λ i ,μ i ).

[0027] In an exemplary embodiment, the step of obtaining a query keyword and performing homomorphic encryption to obtain an encrypted query keyword includes the following steps:

[0028] Query Party P s Enter a plaintext keyword kw as the query keyword;

[0029] Encode the query keywords into strings;

[0030] Convert the string into a large integer according to the big endian storage;

[0031] The large integer is encrypted using the Paillier public key to obtain the encrypted query keyword e_kw.

[0032] In an exemplary embodiment, the homomorphic operation of the ciphertext keyword and the encrypted query keyword includes any one or more combinations of homomorphic subtraction of the ciphertext keyword and the encrypted query keyword, bit-by-bit homomorphic addition of the ciphertext keyword and the encrypted query keyword, bit-by-bit homomorphic division of the ciphertext keyword and the encrypted query keyword, or bit-by-bit homomorphic multiplication of the ciphertext keyword and the encrypted query keyword.

[0033] In an exemplary embodiment, the index of querying hit results based on the result of homomorphic operation and the set upper limit of fuzzy query error characters comprises the steps of:

[0034] Decrypt the result of the homomorphic operation using the Paillier private key to obtain a large integer, denoted as dec i,j , i=1,2,…,n, j=1,2,…,t(i);

[0035] Decode the decrypted large integer into a string and calculate the string length, Hamming weight in character form, and the proportion of repeated characters;

[0036] Calculate the value x based on the length of the string and / or the Hamming weight of the character form and / or the weight of the repeated characters i,j ;

[0037] If the homomorphic labeled value x i,j If the number of characters is less than or equal to the upper limit of the fuzzy query error, the current index (i, j) is considered to be a hit index; otherwise, the current index (i, j) is considered to have no hit result.

[0038] When all indexes do not have a hit result, it is determined that the query content is not in the current document or the set fuzzy query error character limit is increased and the above steps are repeated.

[0039] In an exemplary embodiment, the step of decrypting the ciphertext document corresponding to the index to obtain the query result comprises the following steps:

[0040] Combine all the i values ​​in the hit index into an increasing index vector index = (index 1 ,…,index h );

[0041] For k = 1, 2, ..., h, all index k The corresponding ciphertext document E k Return to the query user;

[0042] Decrypt the ciphertext document to obtain the plaintext document D k , which is the query result.

[0043] A computer-readable storage medium stores a computer program for electronic data exchange, wherein the computer program enables a computer to execute the above method.

[0044] According to another embodiment of the present invention, a fuzzy query system for tokenizing encrypted data is provided, comprising:

[0045] processor;

[0046] Memory;

[0047] as well as

[0048] One or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the processor, the programs causing the computer to perform the above method.

[0049] The advantages of the ciphertext data tokenization fuzzy query method, system and storage medium of the present invention are:

[0050] (1) The ciphertext keyword vector is bound to the ciphertext document, and the query is performed by matching the query keyword with the document keyword. Compared with the traditional technical solution of full-text retrieval of documents based on query keywords, this can effectively narrow the search scope, reduce the search complexity, and improve the query efficiency.

[0051] (2) Based on the homomorphic operation of the ciphertext keyword and the encrypted query keyword and the set fuzzy query error character upper limit query hit result index, compared with the traditional technical solution of only performing one homomorphic subtraction to determine whether the encrypted keyword matches, it can effectively achieve a certain character error tolerance function and fuzzy matching of keywords, thereby improving query efficiency.

[0052] (3) Compared with the traditional technical solution of searching documents based on plaintext keywords, searching ciphertext documents based on encrypted keywords can effectively protect the original data of the document and the query information, thereby improving data security.

[0053] (4) Fuzzy matching of keywords is achieved through encoding and decoding analysis between character strings and large integers. Compared with the traditional technical solution that requires setting several coordinated system parameters for verification, it can effectively reduce parameter complexity and improve query efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0054] Figure 1 It is a flow chart of a fuzzy query method for tokenizing encrypted data according to an embodiment of the present invention;

[0055] Figure 2 is a flowchart of sub-step S01 of an embodiment of the present invention;

[0056] Figure 3 is a flowchart of sub-step S02 of an embodiment of the present invention;

[0057] Figure 4 is a flowchart of sub-step S022 of an embodiment of the present invention;

[0058] Figure 5 is a flowchart of sub-step S03 of an embodiment of the present invention;

[0059] Figure 6 is a flowchart of sub-step S05 of an embodiment of the present invention;

[0060] Figure 7 is a flowchart of sub-step S06 of an embodiment of the present invention;

[0061] Figure 8 It is a schematic diagram of the structure of a fuzzy query system for tokenizing encrypted data according to an embodiment of the present invention. DETAILED DESCRIPTION

[0062] The present invention is described in detail below in conjunction with specific embodiments. The following embodiments will help those skilled in the art to further understand the invention, but are not intended to limit the present invention in any form. It should be noted that, for those of ordinary skill in the art, several changes and improvements can be made without departing from the concept of the present invention. These all belong to the protection scope of the present invention.

[0063] In order to limit the data size, only the case where the modulus n=p*q in Paillier encryption is 128 bits is used for illustration. In actual processes, a larger security parameter should be used.

[0064] A fuzzy query method for ciphertext data tokenization according to an embodiment of the present invention is shown in the flowchart as follows: Figure 1 As shown, the steps include:

[0065] Step S01, encrypting a plaintext document to obtain a ciphertext document;

[0066] Step S02: homomorphically encrypt the keywords of the plaintext document to obtain ciphertext keywords; the ciphertext keyword vector is bound to the ciphertext document;

[0067] Step S03: Obtain query keywords and perform homomorphic encryption to obtain encrypted query keywords;

[0068] Step S04, performing homomorphic operation on the ciphertext keyword and the encrypted query keyword;

[0069] Step S05, querying the index of the hit result according to the result of the homomorphic operation and the set upper limit of fuzzy query error characters;

[0070] Step S06: decrypt the ciphertext document corresponding to the index to obtain the query result;

[0071] In an exemplary embodiment, the step S01, the flow chart is as follows Figure 2 As shown, including:

[0072] Step S011, determine the document to be encrypted, the document owner, and the owner mapping; the document to be encrypted is denoted as D i , i = 1,…,n; document D i The owner is denoted as P f(i) , the number of owners is recorded as m, and f represents the owner mapping;

[0073] Step S012: Document owner P 1 ,…,P m Randomly select their own 128-bit symmetric key 1 ,…,key m ;

[0074] Step S013: The owner uses the SM4 national encryption algorithm to symmetric encrypt all documents to obtain their own ciphertext documents E i =SM4(D i ,key f(i) ).

[0075] In an exemplary embodiment, the step S02, the flow chart is as follows Figure 3 As shown, including:

[0076] Step S021, document D i There are t(i) keywords in total. Let j = 1, 2, ..., t(i), then the document keyword vector kw is formed. i =(kw i,1 ,…,kw i,j );

[0077] Step S022: The owner generates a Paillier public-private key pair;

[0078] Step S023, encoding each document keyword into a character string;

[0079] Step S024, convert the string into a large integer according to big-endian storage;

[0080] Step S025: Encrypt the large integer using the Paillier public key to obtain the ciphertext keyword, and combine them to obtain the ciphertext keyword vector e i =(e i,1 ,…,e i,t(i) ); ciphertext keyword vector e i and the corresponding ciphertext document E i Binding.

[0081] In this embodiment, for each keyword vector kw i=(kw i,1 ,…,kw i,t(i) ), owner P f(i) First, all the keywords kw i,j Encode it into a string (English keywords use ASCII encoding, Chinese and English keywords use UTF-8 encoding), and then convert the string into a large integer m according to big-endian storage i,j , and then m i,j Use the corresponding Paillier public key pk f(i) =(n f(i) ,g f(i) ) is used for encryption, that is, a random number r is selected from (0,n) such that r and n f(i) Coprime, calculate the ciphertext e i,j =(g i ^m i,j )·(r^n f(i) )modn f(i) 2 , combined to get the ciphertext keyword vector e i =(e i,1 ,…,e i,t(i) ); Document owner P 1 ,…,P m Each Paillier private key sk i =(λ i ,μ i ) is sent to the trusted third party TTP. All encrypted ciphertext documents E 1 ,…,E n Bind the corresponding ciphertext keyword vector e respectively 1 ,…,e n ; All (E i ,e i ) by the respective document owners P f(i) Upload to the cloud server CS for storage. Assuming that the binding keyword of a document contains "study", its ASCII encoding sequence is [0x73, 0x74, 0x75, 0x64, 0x79] = [115, 116, 117, 100, 121], then its corresponding integer is 115*256 4 +116*256 3 +117*256 2 +100*256+121*1=495875089529, after the plaintext integer of the keyword "study" is encrypted with Paillier homomorphic encryption, the ciphertext c is 10466677566082097841346274930611661006726825124756550423643142937441876048613.

[0082] In an exemplary embodiment, the step S022, the flow chart is as follows Figure 4 As shown, including:

[0083] Step S0221: Document owner P 1 ,…,P m Each of them selects a random 1024-bit large prime number p i and q i , calculate the modulus n i =p i ·q i ;

[0084] Step S0222: Set g i =n i +1,λ i =(p i -1)·(q i -1), calculate μ i =λ i -1 mod n i ;

[0085] Step S0223, calculate the owner P i The Paillier public key held is pk i =(n i ,g i ), the private key is sk i =(λ i ,μ i ).

[0086] In this embodiment, the Paillier encryption parameters are set as follows: p=11619517902018857773, q=15587091809923183721;

[0087] pk:n=p*q=181114492325813952330076163888047913333,

[0088] sk:λ=(p-1)*(q-1)=181114492325813952302869554176105871840,

[0089] μ=λ -1 mod n=40706810928253159587952660581436296775.

[0090] In an exemplary embodiment, the step S03, the flow chart is as follows Figure 5 As shown, including:

[0091] Step S031: Query Party P s Enter a plaintext keyword kw as the query keyword;

[0092] Step S032, encoding the query keyword into a character string;

[0093] Step S033, convert the string into a large integer according to big-endian storage;

[0094] Step S034: Encrypt the large integer using the Paillier public key to obtain the encrypted query keyword e_kw.

[0095] In this embodiment, the querying party P s Enter a plaintext keyword kw as the query keyword, query method P s First, encode the plaintext keyword into a string (the full English keyword is encoded in ASCII, and the Chinese and English keywords are encoded in UTF-8), and then convert the string into a large integer m according to the big endian storage. s , and then m s Use the Paillier public key pk s =(n s ,g s ) s Encryption is performed, that is, in the interval (0,n s ) selects a random number r that satisfies r and n s Coprime, calculate the ciphertext e_kw = (g s ^m s )·(r^n s )modn s 2 , and finally the encrypted query keyword e_kw and public key pk s =(n s ,g s )Submit to the cloud server CS.

[0096] Assume that the query user mistakenly inputs "study" as "stupy" when entering the query keyword, then its ASCII encoding sequence is [0x73, 0x74, 0x75, 0x70, 0x79] = [115, 116, 117, 112, 121], and its corresponding integer is 115*256 4 +116*256 3 +117*256 2+112*256+121*1=495875092601, after the plaintext integer of "stupy" is encrypted with Paillier homomorphic encryption, its ciphertext c1 is 23503081489681165980693543610881487048821301820938356728967450826599302370111.

[0097] In an exemplary embodiment, the homomorphic operation of the ciphertext keyword and the encrypted query keyword includes any one or more combinations of homomorphic subtraction of the ciphertext keyword and the encrypted query keyword, bit-by-bit homomorphic addition of the ciphertext keyword and the encrypted query keyword, bit-by-bit homomorphic division of the ciphertext keyword and the encrypted query keyword, or bit-by-bit homomorphic multiplication of the ciphertext keyword and the encrypted query keyword.

[0098] In an exemplary embodiment, the homomorphic operation of the ciphertext keyword and the encrypted query keyword is to perform homomorphic subtraction on the ciphertext keyword and the encrypted query keyword, that is, the ciphertext keyword and the encrypted query keyword are each treated as a ciphertext as a whole and subjected to homomorphic subtraction operation to obtain a ciphertext result.

[0099] In this embodiment, the cloud server CS receives the encrypted query keyword e_kw; for i=1,2,…,n, j=1,2,…,t(i), the cloud server uses the public key pk s Each e i,j Perform Paillier homomorphic subtraction with e_kw to obtain each operation result comp i,j =e i,j ·e_kw -1 mod n s 2 The cloud server performs a homomorphic subtraction operation on the ciphertext c1 and c, and the resulting ciphertext calculation result is 15444467313106524019706917936052847004074838611255731507759884248482973589018.

[0100] In another exemplary embodiment, performing homomorphic operation on the ciphertext keyword and the encrypted query keyword is performing bit-by-bit homomorphic addition on the ciphertext keyword and the encrypted query keyword, including:

[0101] Encrypt each byte of the ciphertext keyword and the query keyword bit by bit, and perform homomorphic addition operation on the ciphertext of each corresponding byte of the two keywords;

[0102] The ciphertext of each byte after the bit-by-bit homomorphic addition operation is divided by 2, and then the obtained ciphertext is homomorphically subtracted from the overall ciphertext of the ciphertext keyword to obtain the ciphertext result.

[0103] In another exemplary embodiment, performing homomorphic operation on the ciphertext keyword and the encrypted query keyword is performing bit-by-bit homomorphic division on the ciphertext keyword and the encrypted query keyword, including:

[0104] Encrypt each byte of the ciphertext keyword and the query keyword bit by bit, and perform homomorphic division operation on the ciphertext of each corresponding byte of the two keywords;

[0105] Subtract 1 from the ciphertext of each byte after the bit-by-bit homomorphic division operation to obtain the ciphertext result.

[0106] In another exemplary embodiment, performing homomorphic operation on the ciphertext keyword and the encrypted query keyword is performing bit-by-bit homomorphic multiplication on the ciphertext keyword and the encrypted query keyword, including:

[0107] Encrypt each byte of the ciphertext keyword and the query keyword bit by bit, and perform homomorphic multiplication on the ciphertext of each corresponding byte of the two keywords;

[0108] Calculate the square root of the ciphertext of each byte after the bit-by-bit homomorphic multiplication operation, and then perform a homomorphic subtraction operation on the obtained ciphertext and the overall ciphertext of the ciphertext keyword to obtain the ciphertext result.

[0109] In another exemplary embodiment, the homomorphic operation of the ciphertext keyword and the encrypted query keyword is a combination of homomorphic subtraction and bitwise homomorphic division of the ciphertext keyword and the encrypted query keyword, including:

[0110] Performing homomorphic subtraction operation on the ciphertext keyword and the encrypted query keyword as the ciphertext as a whole to obtain a first ciphertext result;

[0111] Perform homomorphic division on the ciphertext of each corresponding byte of the two keywords, and then subtract 1 from the ciphertext of each byte after the bit-by-bit homomorphic division to obtain the second ciphertext result;

[0112] The first ciphertext result and the second ciphertext result are homomorphically subtracted to obtain the final ciphertext result.

[0113] In another exemplary embodiment, the performing homomorphic operation on the ciphertext keyword and the encrypted query keyword is a combination of performing homomorphic subtraction and bitwise homomorphic addition on the ciphertext keyword and the encrypted query keyword, including:

[0114] Performing homomorphic subtraction operation on the ciphertext keyword and the encrypted query keyword as the ciphertext as a whole to obtain a first ciphertext result;

[0115] Perform homomorphic addition operation on the ciphertext of each corresponding byte of the two keywords, divide the ciphertext of each byte after the bit-by-bit homomorphic addition operation by 2, and then perform homomorphic subtraction operation on the obtained ciphertext and the overall ciphertext of the ciphertext keyword to obtain the second ciphertext result;

[0116] The first ciphertext result and the second ciphertext result are homomorphically subtracted to obtain the final ciphertext result.

[0117] In another exemplary embodiment, the performing homomorphic operation on the ciphertext keyword and the encrypted query keyword is a combination of performing homomorphic subtraction and bitwise homomorphic multiplication on the ciphertext keyword and the encrypted query keyword, including:

[0118] Performing homomorphic subtraction operation on the ciphertext keyword and the encrypted query keyword as the ciphertext as a whole to obtain a first ciphertext result;

[0119] Perform homomorphic multiplication on the ciphertext of each corresponding byte of the two keywords, calculate the square root of the ciphertext of each byte after the bit-by-bit homomorphic multiplication, and then perform homomorphic subtraction on the obtained ciphertext and the overall ciphertext of the ciphertext keyword to obtain the second ciphertext result;

[0120] The first ciphertext result and the second ciphertext result are homomorphically subtracted to obtain the final ciphertext result.

[0121] In another exemplary embodiment, the performing homomorphic operation on the ciphertext keyword and the encrypted query keyword is a combination of performing bitwise homomorphic division and bitwise homomorphic addition on the ciphertext keyword and the encrypted query keyword, including:

[0122] Perform homomorphic division on the ciphertext of each corresponding byte of the two keywords, and then subtract 1 from the ciphertext of each byte after the bit-by-bit homomorphic division to obtain the first ciphertext result;

[0123] Perform homomorphic addition operation on the ciphertext of each corresponding byte of the two keywords, divide the ciphertext of each byte after the bit-by-bit homomorphic addition operation by 2, and then perform homomorphic subtraction operation on the obtained ciphertext and the overall ciphertext of the ciphertext keyword to obtain the second ciphertext result;

[0124] The first ciphertext result and the second ciphertext result are homomorphically subtracted to obtain the final ciphertext result.

[0125] In another exemplary embodiment, the performing homomorphic operation on the ciphertext keyword and the encrypted query keyword is a combination of performing bit-by-bit homomorphic division and bit-by-bit homomorphic multiplication on the ciphertext keyword and the encrypted query keyword, including:

[0126] Perform homomorphic division on the ciphertext of each corresponding byte of the two keywords, and then subtract 1 from the ciphertext of each byte after the bit-by-bit homomorphic division to obtain the first ciphertext result;

[0127] Perform homomorphic multiplication on the ciphertext of each corresponding byte of the two keywords, calculate the square root of the ciphertext of each byte after the bit-by-bit homomorphic multiplication, and then perform homomorphic subtraction on the obtained ciphertext and the overall ciphertext of the ciphertext keyword to obtain the second ciphertext result;

[0128] The first ciphertext result and the second ciphertext result are homomorphically subtracted to obtain the final ciphertext result.

[0129] In another exemplary embodiment, performing homomorphic operation on the ciphertext keyword and the encrypted query keyword is a combination of bit-by-bit homomorphic addition and bit-by-bit homomorphic multiplication on the ciphertext keyword and the encrypted query keyword, including:

[0130] Perform homomorphic addition operation on the ciphertext of each corresponding byte of the two keywords, divide the ciphertext of each byte after the bit-by-bit homomorphic addition operation by 2, and then perform homomorphic subtraction operation on the obtained ciphertext and the overall ciphertext of the ciphertext keyword to obtain the first ciphertext result;

[0131] Perform homomorphic multiplication on the ciphertext of each corresponding byte of the two keywords, calculate the square root of the ciphertext of each byte after the bit-by-bit homomorphic multiplication, and then perform homomorphic subtraction on the obtained ciphertext and the overall ciphertext of the ciphertext keyword to obtain the second ciphertext result;

[0132] The first ciphertext result and the second ciphertext result are homomorphically subtracted to obtain the final ciphertext result.

[0133] In another exemplary embodiment, the performing homomorphic operation on the ciphertext keyword and the encrypted query keyword is a combination of performing homomorphic subtraction, bitwise homomorphic division, and bitwise homomorphic addition on the ciphertext keyword and the encrypted query keyword, including:

[0134] Performing homomorphic subtraction operation on the ciphertext keyword and the encrypted query keyword as the ciphertext as a whole to obtain a first ciphertext result;

[0135] Perform homomorphic division on the ciphertext of each corresponding byte of the two keywords, and then subtract 1 from the ciphertext of each byte after the bit-by-bit homomorphic division to obtain the second ciphertext result;

[0136] Perform homomorphic addition operation on the ciphertext of each corresponding byte of the two keywords, divide the ciphertext of each byte after the bit-by-bit homomorphic addition operation by 2, and then perform homomorphic subtraction operation on the obtained ciphertext and the overall ciphertext of the ciphertext keyword to obtain the third ciphertext result;

[0137] The first ciphertext result, the second ciphertext result and the third ciphertext result are subjected to homomorphic subtraction operation to obtain the final ciphertext result.

[0138] In another exemplary embodiment, the homomorphic operation of the ciphertext keyword and the encrypted query keyword is a combination of homomorphic subtraction, bitwise homomorphic division, and bitwise homomorphic multiplication of the ciphertext keyword and the encrypted query keyword, including:

[0139] Performing homomorphic subtraction operation on the ciphertext keyword and the encrypted query keyword as the ciphertext as a whole to obtain a first ciphertext result;

[0140] Perform homomorphic division on the ciphertext of each corresponding byte of the two keywords, and then subtract 1 from the ciphertext of each byte after the bit-by-bit homomorphic division to obtain the second ciphertext result;

[0141] Perform homomorphic multiplication on the ciphertext of each corresponding byte of the two keywords, calculate the square root of the ciphertext of each byte after the bit-by-bit homomorphic multiplication, and then perform homomorphic subtraction on the obtained ciphertext and the overall ciphertext of the ciphertext keyword to obtain the third ciphertext result;

[0142] The first ciphertext result, the second ciphertext result and the third ciphertext result are subjected to homomorphic subtraction operation to obtain the final ciphertext result.

[0143] In another exemplary embodiment, the performing homomorphic operation on the ciphertext keyword and the encrypted query keyword is a combination of performing homomorphic subtraction, bitwise homomorphic addition, and bitwise homomorphic multiplication on the ciphertext keyword and the encrypted query keyword, including:

[0144] Performing homomorphic subtraction operation on the ciphertext keyword and the encrypted query keyword as the ciphertext as a whole to obtain a first ciphertext result;

[0145] Perform homomorphic addition operation on the ciphertext of each corresponding byte of the two keywords, divide the ciphertext of each byte after the bit-by-bit homomorphic addition operation by 2, and then perform homomorphic subtraction operation on the obtained ciphertext and the overall ciphertext of the ciphertext keyword to obtain the second ciphertext result;

[0146] Perform homomorphic multiplication on the ciphertext of each corresponding byte of the two keywords, calculate the square root of the ciphertext of each byte after the bit-by-bit homomorphic multiplication, and then perform homomorphic subtraction on the obtained ciphertext and the overall ciphertext of the ciphertext keyword to obtain the third ciphertext result;

[0147] The first ciphertext result, the second ciphertext result and the third ciphertext result are subjected to homomorphic subtraction operation to obtain the final ciphertext result.

[0148] In another exemplary embodiment, the homomorphic operation of the ciphertext keyword and the encrypted query keyword is a combination of bit-by-bit homomorphic division, bit-by-bit homomorphic addition, and bit-by-bit homomorphic multiplication of the ciphertext keyword and the encrypted query keyword, including:

[0149] Perform homomorphic division on the ciphertext of each corresponding byte of the two keywords, and then subtract 1 from the ciphertext of each byte after the bit-by-bit homomorphic division to obtain the first ciphertext result;

[0150] Perform homomorphic addition operation on the ciphertext of each corresponding byte of the two keywords, divide the ciphertext of each byte after the bit-by-bit homomorphic addition operation by 2, and then perform homomorphic subtraction operation on the obtained ciphertext and the overall ciphertext of the ciphertext keyword to obtain the second ciphertext result;

[0151] Perform homomorphic multiplication on the ciphertext of each corresponding byte of the two keywords, calculate the square root of the ciphertext of each byte after the bit-by-bit homomorphic multiplication, and then perform homomorphic subtraction on the obtained ciphertext and the overall ciphertext of the ciphertext keyword to obtain the third ciphertext result;

[0152] The first ciphertext result, the second ciphertext result and the third ciphertext result are subjected to homomorphic subtraction operation to obtain the final ciphertext result.

[0153] In another exemplary embodiment, the homomorphic operation of the ciphertext keyword and the encrypted query keyword is a combination of homomorphic subtraction and bitwise homomorphic division and bitwise homomorphic addition and bitwise homomorphic multiplication of the ciphertext keyword and the encrypted query keyword, including:

[0154] Performing homomorphic subtraction operation on the ciphertext keyword and the encrypted query keyword as the ciphertext as a whole to obtain a first ciphertext result;

[0155] Perform homomorphic division on the ciphertext of each corresponding byte of the two keywords, and then subtract 1 from the ciphertext of each byte after the bit-by-bit homomorphic division to obtain the second ciphertext result;

[0156] Perform homomorphic addition operation on the ciphertext of each corresponding byte of the two keywords, divide the ciphertext of each byte after the bit-by-bit homomorphic addition operation by 2, and then perform homomorphic subtraction operation on the obtained ciphertext and the overall ciphertext of the ciphertext keyword to obtain the third ciphertext result;

[0157] Performing homomorphic multiplication operation on the ciphertext of each corresponding byte of the two keywords, calculating the square root of the ciphertext of each byte after the bit-by-bit homomorphic multiplication operation, and then performing homomorphic subtraction operation on the obtained ciphertext and the overall ciphertext of the ciphertext keyword to obtain a fourth ciphertext result;

[0158] The first ciphertext result, the second ciphertext result, the third ciphertext result and the fourth ciphertext result are subjected to homomorphic subtraction operation to obtain a final ciphertext result.

[0159] In an exemplary embodiment, the step S05, the flow chart is as follows Figure 6 As shown, including:

[0160] Step S051: Decrypt the result of the homomorphic operation according to the Paillier private key to obtain a large integer, denoted as dec i,j , i=1,2,…,n, j=1,2,…,t(i);

[0161] Step S052, decoding the decrypted large integer into a character string and calculating the length of the character string, the Hamming weight in character form, and the proportion of repeated characters;

[0162] Step S053: Calculate the homomorphic indicator value x according to the string length and / or the Hamming weight in the character form and / or the repeated character ratio. i,j ;

[0163] Step S054: If the homomorphic indicator value x i,j If the number of characters is less than or equal to the upper limit of the fuzzy query error, the current index (i, j) is considered to be a hit index; otherwise, the current index (i, j) is considered to have no hit result.

[0164] Step S055: When all indexes do not have a hit result, it is determined that the query content is not in the current document or the set upper limit of fuzzy query error characters is increased and the above steps are repeated.

[0165] In this embodiment, the cloud server CS will comp all the results i,j Sent to a trusted third party TTP; the trusted third party TTP executes all results comp based on all Paillier private keys i,j Decryption of , that is, calculating dec i,j =(comp i,j ^λ f(i) modn f(i) 2 -1) / n f(i) ·μ f(i) modn f(i) 2 ;

[0166] The trusted third party TTP is responsible for the decryption result large integer dec i,j Decode it into a string (English keywords use ASCII encoding, Chinese and English keywords use UTF-8 encoding), and find out the string length len i,j , whose Hamming weight in character form is hw i,j (i.e. the number of characters that are not 0), and the proportion of repeated characters re i,j (i.e. the ratio of the number of character categories to the total number of characters).

[0167] In an exemplary embodiment, the homomorphic indicator value x is calculated according to the string length and / or the Hamming weight in the character form and / or the repeated character ratio. i,j, which is: calculating the homomorphic label value according to the positive correlation between the string length and the homomorphic label value, calculating the homomorphic label value according to the positive correlation between the Hamming weight in character form and the homomorphic label value, calculating the homomorphic label value according to the positive correlation between the repeated character ratio and the homomorphic label value, calculating the homomorphic label value according to the positive correlation between the string length and the Hamming weight in character form and the homomorphic label value, calculating the homomorphic label value according to the positive correlation between the string length and the repeated character ratio and the homomorphic label value, calculating the homomorphic label value according to the positive correlation between the Hamming weight in character form and the repeated character ratio and the homomorphic label value, calculating the homomorphic label value according to the positive correlation between the string length, the Hamming weight in character form and the repeated character ratio and the homomorphic label value. The homomorphic label value is represented by the variable x. i,j is represented by.

[0168] In Table A, A1 - A7 represent different implementation manners for calculating the homomorphic label value. The method described in any item in Table A is used to calculate the homomorphic label value of a certain string. For the sake of easy expression, the homomorphic label value of this string is represented by the variable x, the length of this string is represented by l, the Hamming weight in character form is represented by w, and the repeated character ratio is represented by r.

[0169] Table A Different implementation manners for calculating the homomorphic label value

[0170]

[0171]

[0172]

[0173]

[0174]

[0175]

[0176] In this embodiment, the upper limit of fuzzy query error characters X = 3 set in advance, and the homomorphic label value x of the decrypted string is calculated according to any item in Table A. i,j (For example, A7) < X, then it is determined that according to the properties of homomorphic encryption, the current index (i, j) is the index of the hit result.

[0177] In an exemplary embodiment, if the homomorphic label value x of the decrypted string is calculated according to any item in Table A. i,j is greater than the set upper limit of fuzzy query error characters X, then it is determined that the current index (i, j) does not hit the result. Traverse all indexes. When all indexes do not hit the result, it is determined that the query content is not in the current document.

[0178] In an exemplary embodiment, if no hit result is found after traversing all indexes, the set upper limit X of fuzzy query error characters is increased and the above steps are repeated.

[0179] The trusted third party performs homomorphic decryption on the ciphertext calculation result of the previous step and obtains a decryption result of 3072. It is then represented in base 256. Assuming that the upper limit of the uniform length of characters is 15, since 3072 = 12*256, the decoded sequence obtained is [0,0,0,0,0,0,0,0,0,0,0,0,0,12,0]. Its Hamming weight (i.e., the number of characters that are not 0) is 1. From this result, it can be seen that the encoding difference between the submitted query keyword "stupy" and the original keyword "study" is 3072, and there is only a difference of 12 = 'p'-'d' in the second to last character, that is, there is only one position character between the two keywords that is incorrect, and the characters in the other positions are correct. Use the calculation method described in A2 in Table A to calculate the homomorphic indication value x = o4·w o5 +o6=1·1+0=1, the upper limit of fuzzy query error characters is X=3, x=1<3, so the trusted third party determines that the current index is the index of the hit result.

[0180] In an exemplary embodiment, the step S06, the flow chart is as follows Figure 7 As shown, the steps include:

[0181] Step S061: combine the i values ​​in all hit indexes into an increasing index vector index=(index 1 ,…,index h );

[0182] Step S062: for k=1, 2, ..., h, all index k The corresponding ciphertext document E k Return to the query user;

[0183] Step S063: Decrypt the ciphertext document to obtain the plaintext document D k , which is the query result.

[0184] In this embodiment, the trusted third party combines all i values ​​in the hit index into an increasing index vector index=(index 1 ,…,index h ) and sends it back to the cloud server CS.

[0185] For k = 1, 2, ..., h, the cloud server CS will all index k The corresponding ciphertext document E k Return to the query user P s .

[0186] For k = 1, 2, ..., h, if f(k) = s, then the document is for the query user P s All, User P s Using a symmetric key s For E i Perform symmetric decryption to obtain the plaintext document D k =SM4(E k ,key s ) to complete the query.

[0187] A fuzzy query system for tokenizing encrypted data according to an embodiment of the present invention is shown in the structural diagram as follows: Figure 8 As shown, including:

[0188] processor;

[0189] Memory;

[0190] as well as

[0191] One or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the processor, the programs causing the computer to perform the above method.

[0192] Of course, those skilled in the art should realize that the above embodiments are only used to illustrate the present invention, and are not intended to limit the present invention. As long as they are within the scope of the present invention, any changes or modifications to the above embodiments will fall within the protection scope of the present invention.

Claims

1. A fuzzy query method for tokenization of ciphertext data, It is characterized in that include: Encrypt the plaintext document to obtain the ciphertext document; Perform homomorphic encryption on the keywords of the plaintext document to obtain the ciphertext keywords; The ciphertext keyword vector is bound to the ciphertext document; Obtain query keywords and perform homomorphic encryption to obtain encrypted query keywords; Perform homomorphic operations on the ciphertext keywords and the encrypted query keywords; The index of the hit result is searched based on the result of the homomorphic operation and the set upper limit of the fuzzy query error characters; The method of querying the index of the hit result according to the result of the homomorphic operation and the set upper limit of the fuzzy query error characters comprises the steps of: Decrypt the result of the homomorphic operation using the Paillier private key to obtain a large integer, denoted as dec i,j , i = 1, 2, ..., n, j = 1, 2, ..., t(i); decode the decrypted large integer into a string and calculate the string length, the Hamming weight in character form and the proportion of repeated characters; calculate the homomorphic label value x according to the string length and / or the Hamming weight in character form and / or the proportion of repeated characters i,j ; If the homomorphic labeled value x i,j If the number of characters is less than or equal to the upper limit of the fuzzy query error, the current index (i, j) is considered to be a hit index; otherwise, the current index (i, j) is considered to have no hit result. When all indexes do not have a hit result, it is determined that the query content is not in the current document or the upper limit of fuzzy query error characters is increased and the above steps are repeated; The homomorphic indicator value x is calculated according to the string length and / or the Hamming weight in the character form and / or the repeated character ratio i,j , is: According to the positive correlation between the string length l and the homomorphic label value, the homomorphic label value x = o1 l is calculated o2 +o3, where o1, o2, and o3 are the calculation coefficients obtained by prior training, or the homomorphic label value x=o4·w is calculated based on the positive correlation between the Hamming weight w in the character form and the homomorphic label value o5 +o6, where o4, o5, and o6 are the calculation coefficients obtained by prior training, or the homomorphic label value x = o7·r is calculated based on the positive correlation between the repeated character ratio r and the homomorphic label value o8 +o9, where o7, o8, and o9 are the calculation coefficients obtained by prior training, or the homomorphic label value x=o10·l is calculated based on the positive correlation between the string length l and the Hamming weight w in character form and the homomorphic label value o11 +o12·w o13 Or x = o14·l o15 ·w o16 +o17, where o10, o11, o12, o13, o14, o15, o16, and o17 are calculation coefficients obtained by prior training, or the homomorphic label value x=o18·l is calculated based on the positive correlation between the string length l and the repeated character ratio r and the homomorphic label value o19 +o20·r o21 Or x = o22·l o23 ·r o24 +o25, where o18, o19, o20, o21, o22, o23, o24, and o25 are calculation coefficients obtained by prior training, or the homomorphic label value x=o26·w is calculated based on the positive correlation between the Hamming weight w in the character form and the repeated character ratio r and the homomorphic label value o27 +o28·r o29 Or x = o30·w o31 ·r o32 +o33, where o26, o27, o28, o29, o30, o31, o32, and o33 are calculation coefficients obtained by prior training, or the homomorphic label value x=o34·l is calculated based on the positive correlation between the string length l, the Hamming weight w in character form, the repeated character ratio r, and the homomorphic label value. o35 +o36·w o37 +o38·r o39 Or x = o40·l o41 ·w o42 ·r o43 +o44, where o34, o35, o36, o37, o38, o39, o40, o41, o42, o43, and o44 are calculated coefficients obtained through prior training; The query result is obtained by decrypting the ciphertext document corresponding to the index.

2. The fuzzy query method for tokenizing encrypted data according to claim 1, It is characterized in that The method of encrypting a plaintext document to obtain a ciphertext document comprises the following steps: Determine the document to be encrypted, the document owner and the owner mapping; the document to be encrypted is denoted as D i , i = 1,…,n; document D i The owner is denoted as P f(i) , the number of owners is recorded as m, and f represents the owner mapping; Document Owner P 1 ,…,P m Randomly select their own 128-bit symmetric key 1 ,…,key m ; The owner uses the SM4 national encryption algorithm to symmetric encrypt all documents and obtain their own ciphertext documents E i =SM4(D i ,key f(i) ).

3. The fuzzy query method for tokenizing encrypted data according to claim 2, It is characterized in that The step of homomorphically encrypting the keywords of the plaintext document to obtain the ciphertext keywords comprises the following steps: Document D i There are t(i) keywords in total. Let j = 1, 2, ..., t(i), then the document keyword vector kw is formed. i =(kw i,1 ,…,kw i,j ); The owner generates a Paillier public-private key pair; Encode each document keyword into a string; Convert the string into a large integer according to the big endian storage; Encrypt the large integer using the Paillier public key to obtain the ciphertext keyword, and combine them to obtain the ciphertext keyword vector e i =(e i,1 ,…,e i,t(i) ); ciphertext keyword vector e i and the corresponding ciphertext document E i Binding.

4. The fuzzy query method for tokenizing encrypted data according to claim 3, It is characterized in that The owner generates a Paillier public-private key pair, including the steps of: Document Owner P 1 ,…,P m Each of them selects a random 1024-bit large prime number p i and q i , calculate the modulus n i =p i ·q i ; Let g i =n i +1,λ i =(p i -1)·(q i -1), calculate μ i =λ i -1 mod n i ; Calculate owner P i The Paillier public key held is pk i =(n i ,g i ), the private key is sk i =(λ i ,μ i ).

5. The fuzzy query method for tokenizing encrypted data according to claim 4, It is characterized in that The method of obtaining a query keyword and performing homomorphic encryption to obtain an encrypted query keyword comprises the following steps: Querying Party P s Input a plaintext keyword kw as the query keyword; Encode the query keywords into strings; Convert the string into a large integer according to the big endian storage; The large integer is encrypted using the Paillier public key to obtain the encrypted query keyword e_kw.

6. The fuzzy query method for tokenizing encrypted data according to claim 1, It is characterized in that The homomorphic operation of the ciphertext keyword and the encrypted query keyword includes any one or more combinations of homomorphic subtraction of the ciphertext keyword and the encrypted query keyword, bit-by-bit homomorphic addition of the ciphertext keyword and the encrypted query keyword, bit-by-bit homomorphic division of the ciphertext keyword and the encrypted query keyword, or bit-by-bit homomorphic multiplication of the ciphertext keyword and the encrypted query keyword.

7. The fuzzy query method for tokenizing encrypted data according to claim 1, It is characterized in that The step of decrypting the ciphertext document corresponding to the index to obtain the query result comprises the following steps: Combine all the i values ​​in the hit index into an increasing index vector index = (index 1 ,…,index h ); For k = 1, 2, ..., h, all index k The corresponding ciphertext document E k Return to the query user; Decrypt the ciphertext document to obtain the plaintext document D k , which is the query result.

8. A computer-readable storage medium storing a computer program for electronic data exchange, in, The computer program enables a computer to execute the method according to any one of claims 1 to 7.

9. A fuzzy query system for tokenized encrypted data. Features include: processor; Memory; as well as One or more programs, wherein the one or more programs are stored in a memory and configured to be executed by the processor, the programs causing the computer to execute the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Searchable encryption method based on wildcard character in cloud storage safety

    CN107256248A

  • Data query method and device, and medium

    CN113656648A