An end-to-end encrypted file search system without privacy leakage
By using binary hybrid filters and distributed multipoint functions in the end-to-end encrypted file search system, the problem of slow query speed of large-scale data sets in the prior art is solved, and efficient and privacy-free encrypted file search is achieved.
Patent Information
- Application Number
- CN202311076241.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-08-24
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2043-08-24
AI Technical Summary
In the prior art, end-to-end encrypted file search systems are slow to query when facing large-scale data sets, and the search time will increase with the change of the number of keywords stored in the file and the bit error rate.
Adopt an end-to-end encrypted file search system without privacy leakage, store files using binary hybrid filters, and implement file search through distributed multipoint functions (DMPF). The system distributes the encrypted binary hybrid filter to two cloud servers and uses distributed multipoint functions to process the search data. The client device obtains the final search results through XOR operation and decryption.
It improves the search speed when facing large-scale data sets, reduces the search complexity, and does not increase with the increase of bit error rate or the number of query keywords, achieving efficient encrypted file search.
Smart Images

Figure CN117112503B_ABST
Abstract
Description
Technical Field
[0001] The invention belongs to the field of computer technology, and in particular relates to an end-to-end encrypted file search system without privacy leakage. Background Art
[0002] With the popularity of cloud computing technology, more and more users choose to outsource their data to cloud servers. Through cloud servers, users can store files on cloud servers and quickly retrieve data through cloud servers. However, cloud servers have the risk of information leakage, so users cannot fully trust the privacy protection services of cloud servers.
[0003] End-to-end encryption technology provides a solution to the above problems. In end-to-end encryption technology, users encrypt files containing data and upload them to the cloud server. Attackers cannot threaten the privacy of data if they only obtain the encrypted files. However, encrypted files pose a great challenge to the retrieval service of the cloud server.
[0004] In the prior art, in order to realize the retrieval of encrypted files on the cloud server, Dauterman et al. proposed a Dory scheme. The Dory scheme generates a Bloom filter for storing each file and encrypts it with a stream cipher. When the cloud server receives a query request, it uses DPF (distributed point function) to realize the search of the encrypted file.
[0005] However, the Dory solution has the following two defects:
[0006] (1) The search time will increase rapidly as the number of keywords stored in the file increases;
[0007] (2) The search time will increase rapidly as the search bit error rate decreases.
[0008] Due to the above two shortcomings, the query speed of Dory solution is slow when facing large-scale data sets. Summary of the invention
[0009] In order to solve the above problems existing in the prior art, the present invention provides an end-to-end encrypted file search system without privacy leakage.
[0010] The technical problem to be solved by the present invention is achieved through the following technical solutions:
[0011] An end-to-end encrypted file search system without privacy leakage comprises: a client device, a first cloud server and a second cloud server;
[0012] The client device is used to generate a binary hybrid filter for a file uploaded by a user to store the file; encrypt the binary hybrid filter; and send the encrypted binary hybrid filter to the first cloud server and the second cloud server for storage;
[0013] The client device is further used to construct a distributed multi-point function according to at least one query keyword input by a user, wherein the distributed multi-point function is associated with a first sub-function function and a second sub-function function; the first sub-function function is used to generate a pair of keys according to the distributed multi-point function value, and the second sub-function function is used to calculate the distributed multi-point function value according to the key;
[0014] The client device is further configured to generate a first key and a second key using the first sub-function; send the first key to the first cloud server, and send the second key to the second cloud server;
[0015] The first cloud server is configured to search the encrypted binary hybrid filter using the second sub-function according to the first key to obtain first encrypted search data, and return the first encrypted search data to the client device;
[0016] The second cloud server is used to search the encrypted binary hybrid filter using the second sub-function according to the second key to obtain second encrypted search data, and return the second encrypted search data to the client device;
[0017] The client device is further configured to obtain search results according to the first encrypted search data and the second encrypted search data.
[0018] In one embodiment, the client device obtains search results according to the first encrypted search data and the second encrypted search data, including:
[0019] Performing an XOR operation on the first encrypted search data and the second encrypted search data to obtain data to be verified, and decrypting the data to be verified to obtain decrypted data;
[0020] Calculating the fingerprint of the at least one query keyword using a fingerprint function, and calculating the XOR sum of each fingerprint; wherein the fingerprint function is the fingerprint function used in the process of generating the binary hybrid filter;
[0021] Determine whether the XOR sum of the fingerprints matches the data to be verified; if they match, use the decrypted data as the search result.
[0022] In one embodiment, the client device encrypts the binary hybrid filter, including: encrypting the binary hybrid filter using a stream cipher;
[0023] The client device decrypts the data to be verified to obtain decrypted data, including: decrypting the data to be verified using a stream cipher to obtain decrypted data.
[0024] In one embodiment, the client device is further configured to:
[0025] In response to a file update request, a new binary hybrid filter is generated for the updated file, the new binary hybrid filter is encrypted, and the new encrypted binary hybrid filter is sent to the first cloud server and the second cloud server respectively, and the first cloud server and the second cloud server are informed to replace the old encrypted binary hybrid filter with the new encrypted binary hybrid filter.
[0026] In one embodiment, the binary filter includes an N×M index table;
[0027] The client device is also used to generate an XOR homomorphic message authentication code for each element in the index table as the tag of the element after generating the binary hybrid filter; and calculate the XOR and MAC of the tag of each column element in the index table respectively. xor , forming a MAC xor Table; locally store the MAC xor table, and the MAC xor The table is sent to the first cloud server and the second cloud server respectively;
[0028] The first cloud server is further configured to, after obtaining the first encrypted search data, select the first encrypted search data from the MAC according to the position of the first encrypted search data in the encrypted binary filter. xor Determine a MAC in the table xor Value as MAC xor1 ', to encrypt the first search data and MAC xor1 'Return to the client device at the same time;
[0029] The second cloud server is further configured to, after obtaining the second encrypted search data, select the MAC address according to the position of the second encrypted search data in the encrypted binary filter. xor Determine a MAC in the table xor Value as MAC xor2 ', to encrypt the second search data and MAC xor2 'Return to the client device at the same time;
[0030] The client device is further configured to determine whether the first encrypted search data and the second encrypted search data are tampered with according to MAC xor1 ‘ and MAC xor2 ‘.
[0031] In one embodiment, the client device is further configured to generate a new MAC xor table after generating a new binary hybrid filter for the updated file in response to a file update request, so as to send the new encrypted binary hybrid filter and the new MAC xor table to the first cloud server and the second cloud server simultaneously;
[0032] The first cloud server and the second cloud server are further configured to update the old MAC xor table according to the new MAC xor table.
[0033] The end-to-end encrypted file search system without privacy leakage provided by the present invention uses a binary hybrid filter to store files and uses a distributed multi-point function (DMPF) to implement file search. Among them, for the search task of a single query keyword, the search complexity of the present invention is O(3M), while the search complexity of the existing Dory scheme is O(Km), where M is the length of the binary exclusive-or filter, M << m, m is the length of the Bloom filter used in the existing Dory scheme, and K is the number of hash functions in the Bloom filter used in the existing Dory scheme. Since the length of the Bloom filter increases with the decrease of the error rate, the search complexity of the existing Dory scheme increases with the decrease of the error rate, while the length of the binary exclusive-or filter in the present invention does not increase with the decrease of the error rate. Therefore, the search complexity of the present invention does not increase with the decrease of the error rate. For the search task of multiple query keywords, the search complexity of the present invention is O(3M), while the search complexity of the existing Dory scheme is O(QKm), where Q is the number of query keywords. Therefore, the search complexity of the present invention does not increase with the increase of the number of query keywords. In summary, the present invention can improve the search speed in the face of large-scale data sets and achieve efficient search on the basis of protecting data privacy.
[0034] The following will further describe the present invention in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] Figure 1 is an interaction schematic diagram of an end-to-end encrypted file search system without privacy leakage provided by an embodiment of the present invention;
[0036] Figure 2 is a schematic diagram of an index table in an embodiment of the present invention;
[0037] Figure 3 is a comparison result of the server query time between the embodiment of the present invention and the existing Dory solution as the bit error rate changes;
[0038] Figure 4 is a comparison result of the client query time between the embodiment of the present invention and the existing Dory solution as the bit error rate changes;
[0039] Figure 5 is a comparison result of the server query time between the embodiment of the present invention and the existing Dory solution as the number of documents changes;
[0040] Figure 6 is a comparison result of the client query time between the embodiment of the present invention and the existing Dory solution as the number of documents changes;
[0041] Figure 7 is a comparison result of the server query time between the embodiment of the present invention and the existing Dory solution as the number of keywords changes;
[0042] Figure 8 This is a comparison result of the client query time between the embodiment of the present invention and the existing Dory solution as the number of keywords changes. DETAILED DESCRIPTION
[0043] The present invention is further described in detail below with reference to specific embodiments, but the embodiments of the present invention are not limited thereto.
[0044] In order to achieve efficient search on the basis of protecting data privacy, the embodiment of the present invention provides an end-to-end encrypted file search system without privacy leakage, such as Figure 1 As shown, the system includes: a client device, a first cloud server and a second cloud server. In the system, users can choose to upload files containing data to two servers in the cloud, and the two servers will store and search data for users respectively, and there is no privacy leakage in the process. The working method adopted by the system to achieve this effect is described in detail below.
[0045] The client device is used to generate a binary hybrid filter for a file uploaded by a user to store the file; encrypt the binary hybrid filter; and send the encrypted binary hybrid filter to the first cloud server and the second cloud server for storage;
[0046] Specifically, suppose a user uploads N files, each of which consists of at most n keywords and is stored in the form of a binary hybrid filter. To this end, the client device needs to initialize a binary hybrid filter, specifying its maximum number of keywords to be n and a bit error rate of Then, a fingerprint function F is constructed based on the bit error rate, which realizes the mapping from a single keyword to an n-bit integer. Finally, an array H with a length of 1.23n is initialized. After setting the parameters of the binary hybrid filter, for each file S input by the user i , the client device will S i , array H and fingerprint function F are input into the binary hybrid filter construction algorithm (BFF.build) and BFF.build is run to obtain an array B with a length of m = 1.125n i and B i The three associated hashes h0, h1, h2; among them, array B i Each position of can hold a k-bit integer, and array B i Divided into 3 segments. Array B of multiple files i Can form a Figure 2 The client device then converts the array B of each file into an N×m index table. i After encryption, it is sent to the first cloud server and the second cloud server for storage.
[0047] It is understandable that in order to save data storage overhead and query overhead, the most commonly used file storage method is to use Bloom filters and cuckoo filters. XOR filters are faster and smaller than Bloom filters and cuckoo filters, and are within 23% of the theoretical lower limit in storage space. In particular, the binary hybrid filter used in the embodiment of the present invention is within 13% of the storage lower limit, and the construction speed of the binary hybrid filter is more than twice that of the XOR filter.
[0048] The client device is also used to construct a distributed multi-point function based on at least one query keyword input by the user, and the distributed multi-point function is associated with a first sub-function function (DMPF.Gen) and a second sub-function function (DMPF.Eval); the first sub-function function is used to generate a pair of keys based on the distributed multi-point function value, and the second sub-function function is used to calculate the distributed multi-point function value based on the key.
[0049] The distributed multi-point function (DMPF) is a DMPF constructed by PRP (pseudo random permutation) hashing, and the distributed multi-point function can be expressed as:
[0050]
[0051] Where x represents the input parameter of the distributed multi-point function f(x), is a set of query keywords, which contains Q words, h jThe hash function produced when generating the binary hybrid filter for the client device.
[0052] DMPF.Gen is the t-point function value of f(x) and 1 λ is a function of the algorithm input and output (k0, k1), where k0 and k1 are a pair of keys. (α i ,β i ) represents a pair of input and output of f(x), for x = α i , f(α i )=β i , and for x≠α i , f(x) = 0. λ is the preset security parameter. Each word corresponds to 3 point function values, and the 3 point function values corresponding to different words may be repeated, so t is less than or equal to
[0053] DMPF.Eval is based on the key k b as well as is a function whose input and output are m f(x) values, b∈{0,1}; where represents the input domain of f(x), x1,...,x m for There are m of them.
[0054] In addition, for the specific algorithm content of DMPF.Gen and DMPF.Eval, reference may be made to the prior art introduction of DMPF, which will not be elaborated in the embodiment of the present invention.
[0055] The client device is further used to generate a first key and a second key using the first sub-function; send the first key to the first cloud server, and send the second key to the second cloud server;
[0056] Specifically, the client device generates a first key k0 and a second key k1 by running DMPF.Gen.
[0057] The first cloud server is configured to search the encrypted binary hybrid filter using the second sub-function according to the first key to obtain first encrypted search data, and return the first encrypted search data to the client device;
[0058] Specifically, the first cloud server inputs the key k0 and each column of the index table into DMPF.Eval, obtains the operation result of each column by running DMPF.Eval, and then calculates The encrypted search data is returned to the client device as first encrypted search data; wherein h is the column index of the index table. B(h) represents the data in the hth column of the index table, and DMPF.Eval(k0,h) represents the calculation result of DMPF.Eval.
[0059] The second cloud server is used to search the encrypted binary hybrid filter using the second sub-function according to the second key to obtain second encrypted search data, and return the second encrypted search data to the client device;
[0060] Specifically, the second cloud server inputs the key k1 and each column of the index table into DMPF.Eval, obtains the calculation result of each column by running DMPF.Eval, and then calculates returning to the client device as second encrypted search data;
[0061] in,
[0062] The client device is also used to obtain search results based on the first encrypted search data and the second encrypted search data.
[0063] Specifically, the client device performs an XOR operation on the first encrypted search data and the second encrypted search data, that is, calculates After obtaining the data to be verified f′, the data to be verified is decrypted to obtain the decrypted data; then the client device uses the fingerprint function to calculate the fingerprint of at least one query keyword input by the user, and calculates the XOR sum of each fingerprint, that is, calculates Here, the fingerprint function is the fingerprint function used by the client device in the process of generating a binary hybrid filter; then, the client device determines whether the XOR sum of each fingerprint matches the data to be verified f′, that is, whether the two are equal; if they match, the corresponding file is added to the search results.
[0064] The end-to-end encrypted file search system without privacy leakage provided by the present invention uses a binary hybrid filter to store files and a distributed multi-point function (DMPF) to implement file search. Among them, for the search task of a single query keyword, the search complexity of the present invention is O(3M), while the search complexity of the existing Dory scheme is O(Km), where M is the length of the binary exclusive-or filter, M << m, m is the length of the Bloom filter used in the existing Dory scheme, and K is the number of hash functions in the Bloom filter used in the existing Dory scheme. Since the length of the Bloom filter increases with the decrease of the error rate, the search complexity of the existing Dory scheme increases with the decrease of the error rate, while the length of the binary exclusive-or filter in the present invention does not increase with the decrease of the error rate. Therefore, the search complexity of the present invention does not increase with the decrease of the error rate. For the search task of multiple query keywords, the search complexity of the present invention is O(3M), while the search complexity of the existing Dory scheme is O(QKm), where Q is the number of query keywords. Therefore, the search complexity of the present invention does not increase with the increase of the number of query keywords. In summary, the present invention can improve the search speed in the face of large-scale data sets and achieve efficient search on the basis of protecting data privacy.
[0065] In one embodiment, the client device encrypting the binary hybrid filter may include: encrypting the binary hybrid filter using a stream cipher; correspondingly, the client device decrypting the data to be verified includes: decrypting the data to be verified using a stream cipher.
[0066] In one embodiment, the end-to-end encrypted file search system without privacy leakage provided by the embodiments of the present invention also supports file update. At this time, the client device is further configured to: in response to a file update request, generate a new binary hybrid filter for the updated file, encrypt the new binary hybrid filter, and send the new encrypted binary hybrid filter to the first cloud server and the second cloud server, and at the same time inform the first cloud server and the second cloud server to replace the old encrypted binary hybrid filter with the new encrypted binary hybrid filter. Correspondingly, after receiving the new encrypted binary hybrid filter, the first cloud server and the second cloud server replace the old encrypted binary hybrid filter with it.
[0067] In one embodiment, in the file storage stage, the client device is further configured to, after generating the binary hybrid filter, generate an exclusive-or homomorphic message authentication code for each element in its index table as the tag of the element; calculate the exclusive-or sum and MAC of the tags of each column of elements in the index table xor , to obtain the MAC xor table, and this MAC xorThe table has only one row of data; the client device stores MAC locally xor table, and MAC xor The tables are sent to the first cloud server and the second cloud server respectively.
[0068] The first cloud server is further configured to, after obtaining the first encrypted search data, obtain the first encrypted search data from the MAC according to the position of the first encrypted search data in the encrypted binary filter. xor Determine a MAC in the table xor Value as MAC xor1 ', to first encrypt the search data and MAC xor1 'Return to the client device at the same time;
[0069] Specifically, the first cloud server first calculates In this way, the position of the first encrypted search data in the encrypted binary filter is known, that is, if the first encrypted search data is in the hth column, then MAC xor The hth element in the table MACxor(h) gives Assign a value. If the first encrypted search data is not in the hth column, assign Assign 0; then, the first cloud server calculates Returned to the client device.
[0070] The second cloud server is further used to obtain the second encrypted search data, and then obtain the second encrypted search data from the MAC according to the position of the second encrypted search data in the encrypted binary filter. xor Determine a MAC in the table xor Value as MAC xor2 ', to encrypt the second search data and MAC xor2 ' and returned to the client device at the same time.
[0071] Specifically, the second cloud server first calculates In this way, the position of the second encrypted search data in the encrypted binary filter is known, that is, if the second encrypted search data is in the hth column, then MAC xor The hth element in the table MACxor(h) gives If the second encrypted search data is not in the hth column, then Assign 0; then, the second cloud server calculates Returned to the client device.
[0072] Client devices are also used to xor1 ' and MAC xor2 'Determine whether the first encrypted search data and the second encrypted search data have been tampered with.
[0073] Specifically, the client device uses hash functions h0(x), h1(x), h2(x) to calculate The columns mapped to, and then calculate the tag XOR sum corresponding to these columns, and compare it with Compare, if they are equal, it means the data has not been tampered with, otherwise it means the data has been tampered with.
[0074] It is understandable that in practice there may be malicious attackers in the system, who may modify the data returned by the server to the client through active attacks. In order to resist malicious attackers, the existing Dory scheme uses a message authentication code (Mac) to generate a tag for each element in the index table. When the server returns the selected column data, it also returns its corresponding tag. After getting the responses from the two servers, the client can check whether the tag of each element is correct. However, the universal MAC used in the Dory scheme cannot be used in the embodiments of the present invention. This is because the f′ obtained by the client device in the present invention is the XOR sum of multiple column elements after decryption. If a universal MAC is used, the tag returned by the server is also the XOR sum of multiple tags. For a general Mac, Therefore, the embodiment of the present invention uses a Mac with XOR homomorphism. xor Constructing MAC xor Table, client devices can use MAC xor The table is used to verify the correctness of the result, thereby resisting malicious attacks. In addition, the MAC stored by the client device and the server in the present invention xor The table is a single-row table, which reduces the storage overhead of client devices and servers.
[0075] In the above mentioned MAC xor Based on the embodiment of the table, the end-to-end encrypted file search system without privacy leakage provided by the embodiment of the present invention also supports file update.
[0076] Specifically, the client device is further configured to generate a new MAC after generating a new binary hybrid filter for the updated file in response to the file update request. xor Table (generated as above) to mix the new encrypted binary filter and the new MAC xor The table is sent to the first cloud server and the second cloud server at the same time;
[0077] Correspondingly, the first cloud server and the second cloud server are also used to xor Table for old MAC xor The table is updated. The specific update method is to calculate the new and old MAC xor The XOR of the table, the calculation result is the updated MAC xorsurface.
[0078] The beneficial effects of the embodiments of the present invention are further illustrated below using actual test data.
[0079] During the experiment, the Enron data set was used for testing. The reason for choosing the Enron incident data set is that Enron's email database contains 500,000 emails between 150 former Enron employees, mainly senior managers. This is also the only large-scale public real email database. The present invention is compared with the Dory solution in terms of bit error rate, number of files, and number of query keywords.
[0080] (1) Bit Error Rate Comparison
[0081] Under the condition that the number of query keywords is 6 and the number of documents is 514324, the query time of the client device and the query time of the server are tested when the bit error rate changes. The test results are as follows: Figure 3 , Figure 4 As shown. It can be seen that with the increase of the bit error rate, the Dory solution uses a Bloom filter to store files, and the increase of the bit error rate leads to an increase in the length of the Bloom filter, and the number of operations of the DPF.eval() function increases accordingly, which ultimately leads to a rapid increase in the query time of the server and the client. In the present invention, the increase in the bit error rate does not lead to an increase in the length of the array, so the overall trend tends to be stable. In addition, it can be seen that the query time in the present invention is much shorter than the query time of the Dory solution.
[0082] (2) Comparison of file quantity
[0083] Under the condition of bit error rate (1 / 2)^24 and the number of query keywords is 6, when the number of files changes, the query time of the client device and the server changes as follows Figure 5 and Figure 6 Although the increase in the number of files in both the Dory solution and the present invention will lead to an increase in query time, the query time of the present invention is still much shorter than that of the Dory solution.
[0084] (3) Comparison of the number of query keywords
[0085] Under the conditions of bit error rate (1 / 2)^24 and the number of documents 514324, when the number of files changes, the query time of the client device and the server changes as follows Figure 7 and Figure 8 As shown. Since the present invention adopts DMPF, it can cope with the secret sharing of multi-point functions, so the increase in the number of keywords does not affect the change of query time. It can be seen from the figure that the query time of the present invention on both the client and the server tends to be stable, and the query time of the present invention is also much lower than that of the Dory solution.
[0086] It should be noted that the terms "first", "second", etc. are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present disclosure described herein can be implemented in an order other than those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present disclosure. Instead, they are merely examples of devices and methods consistent with some aspects of the present disclosure.
[0087] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" etc. means that the specific features or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine different embodiments or examples described in this specification.
[0088] Although the present application is described herein in conjunction with various embodiments, in the process of implementing the claimed application, those skilled in the art can understand and implement other changes to the disclosed embodiments by viewing the drawings and the disclosed content. In the description of the present invention, the term "comprising" does not exclude other components or steps, "one" or "an" does not exclude multiple situations, and the meaning of "multiple" is two or more, unless otherwise clearly and specifically limited. In addition, certain measures are recorded in different embodiments, but this does not mean that these measures cannot be combined to produce good results.
[0089] The above contents are further detailed descriptions of the present invention in combination with specific preferred embodiments, and it cannot be determined that the specific implementation of the present invention is limited to these descriptions. For ordinary technicians in the technical field to which the present invention belongs, several simple deductions or substitutions can be made without departing from the concept of the present invention, which should be regarded as falling within the scope of protection of the present invention.
Claims
1. An end-to-end encrypted file search system without privacy leakage, characterized in that: include: A client device, a first cloud server, and a second cloud server; The client device is used to generate a binary hybrid filter for the file uploaded by the user to store the file; Encrypting the binary hybrid filter; sending the encrypted binary hybrid filter to the first cloud server and the second cloud server for storage; The client device is further used to construct a distributed multi-point function according to at least one query keyword input by a user, wherein the distributed multi-point function is associated with a first sub-function function and a second sub-function function; the first sub-function function is used to generate a pair of keys according to the distributed multi-point function value, and the second sub-function function is used to calculate the distributed multi-point function value according to the key; The client device is further configured to generate a first key and a second key using the first sub-function; send the first key to the first cloud server, and send the second key to the second cloud server; The first cloud server is configured to search the encrypted binary hybrid filter using the second sub-function according to the first key to obtain first encrypted search data, and return the first encrypted search data to the client device; The second cloud server is used to search the encrypted binary hybrid filter using the second sub-function according to the second key to obtain second encrypted search data, and return the second encrypted search data to the client device; The client device is further configured to obtain search results according to the first encrypted search data and the second encrypted search data.
2. The end-to-end encrypted file search system without privacy leakage according to claim 1, characterized in that: The client device obtains search results according to the first encrypted search data and the second encrypted search data, including: Performing an XOR operation on the first encrypted search data and the second encrypted search data to obtain data to be verified, and decrypting the data to be verified to obtain decrypted data; Calculating the fingerprint of the at least one query keyword using a fingerprint function, and calculating the XOR sum of each fingerprint; wherein the fingerprint function is the fingerprint function used in the process of generating the binary hybrid filter; Determine whether the XOR sum of the fingerprints matches the data to be verified; if they match, use the decrypted data as the search result.
3. The end-to-end encrypted file search system without privacy leakage according to claim 2, characterized in that: The client device encrypts the binary hybrid filter, including: encrypting the binary hybrid filter using a stream cipher; The client device decrypts the data to be verified to obtain decrypted data, including: decrypting the data to be verified using a stream cipher to obtain decrypted data.
4. The end-to-end encrypted file search system without privacy leakage according to claim 1, characterized in that: The client device is further used for: In response to a file update request, a new binary hybrid filter is generated for the updated file, the new binary hybrid filter is encrypted, and the new encrypted binary hybrid filter is sent to the first cloud server and the second cloud server respectively, and the first cloud server and the second cloud server are informed to replace the old encrypted binary hybrid filter with the new encrypted binary hybrid filter.
5. The end-to-end encrypted file search system without privacy leakage according to claim 1, characterized in that: The binary filter includes an N×M index table; The client device is further configured to generate an XOR-homomorphic message authentication code for each element in the index table as a tag of the element after generating the binary hybrid filter; Calculate the XOR and MAC of the tag of each column element in the index table respectively xor , forming a MAC xor table; in Locally store the MAC xor table, and the MAC xor The table is sent to the first cloud server and the second cloud server respectively; The first cloud server is further configured to, after obtaining the first encrypted search data, select the first encrypted search data from the MAC according to the position of the first encrypted search data in the encrypted binary filter. xor Determine a MAC in the table xor Value as MAC xor1 ', to encrypt the first search data and MAC xor1 'Return to the client device at the same time; The second cloud server is further configured to, after obtaining the second encrypted search data, select the MAC address according to the position of the second encrypted search data in the encrypted binary filter. xor Determine a MAC in the table xor Value as MAC xor2 ', to encrypt the second search data and MAC xor2 'Return to the client device at the same time; The client device is also used to xor1 ' and MAC xor2 'Determine whether the first encrypted search data and the second encrypted search data have been tampered with.
6. The end-to-end encrypted file search system without privacy leakage according to claim 5, characterized in that: The client device is further configured to generate a new MAC after generating a new binary hybrid filter for the updated file in response to the file update request. xor Table to combine the new encrypted binary mix filter and the new MAC xor The table is sent to the first cloud server and the second cloud server at the same time; The first cloud server and the second cloud server are also used to xor Table for old MAC xor The table is updated.
Citation Information
Patent Citations
Privacy protection intersection calculation method and device based on large-scale data set in asymmetric mode
CN115333789A
Fuzzy keyword searchable encryption method and system with privacy protection
CN115495792A