Verifiable Multimodal Spatiotemporal Data Index Structure and Spatiotemporal Range Query Verification Method

By using Z order encoding, prefix encoding and Bloom filters to build a verifiable hybrid index tree in spatiotemporal data query, the problem of unverified query results caused by incomplete trust in cloud service providers is solved, and efficient and verifiable spatiotemporal range query is achieved.

CN117194418BActive Publication Date: 2025-06-20XIDIAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311074991.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-08-24
Publication Date
2025-06-20
Estimated Expiration
2043-08-24

AI Technical Summary

Technical Problem

The incomplete trustworthy characteristics of cloud service providers lead to the insecurity, accuracy and completeness of spatiotemporal data query results, and it is difficult for the existing technology to achieve efficient and verifiable spatiotemporal range query.

Method used

Z order encoding and prefix encoding combined with Bloom filters are used to build a verifiable hybrid index tree based on B-Tree, generate a plaintext tree and send it to a cloud service provider. Users reconstruct the query path locally and verify the root node signature to determine the integrity and accuracy of the query results.

Benefits of technology

It realizes spatiotemporal data query with sublinear search complexity, improves search efficiency, ensures the integrity, correctness and completeness of query results, and solves the problem of incomplete credibility of cloud service providers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117194418B_ABST
    Figure CN117194418B_ABST
Patent Text Reader

Abstract

The present invention provides a verifiable multi-modal spatio-temporal data index structure and a spatio-temporal range query verification method, which are divided into a plaintext database generation stage, a query stage, and a verification stage. In the plaintext database generation stage, a plaintext tree with verifiable query results is constructed. During the establishment of the plaintext tree, the tags, cumulative values, and digests of each node are calculated as verification information; and the leaf nodes in the plaintext tree additionally have time information, and there is a Bloom filter for the information of each node after each node, and then they are uploaded to the cloud service provider together as node attributes. In the query stage, the cloud service provider queries the hybrid index tree to obtain the query results. In the verification stage, the query user reconstructs the query path locally and compares whether the root node signatures are consistent to determine the integrity of the query results, and determines the accuracy of the query results by verifying the query results again. The present invention can achieve sub-linear search complexity for search queries, greatly improving the search efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security, and particularly relates to a verifiable multi-modal spatio-temporal data index structure and a spatio-temporal range query verification method. Background Art

[0002] Due to the characteristics of data scale and service real-time requirements of spatio-temporal data query services, spatio-temporal data is usually outsourced to cloud service providers for storage, management and query services. Its typical application scenarios are as Figure 1 shown, including three entities: data owners, cloud service providers, and query users. Because cloud service providers are not fully trusted and the characteristics of the separation of data ownership and control rights in cloud services, cloud-outsourced spatio-temporal data query services face security threats such as unverifiable query results, incomplete, incorrect, and imperfect query results.

[0003] Most of the existing verifiable query work focuses on the integrity and completeness of query results. Liu et al. used RSA accumulators to generate proofs for search results, but the cost is huge computational overhead. Wan et al. used homomorphic MAC technology to authenticate each indicator and verify the correctness of the calculation of the relevant score. Tang et al. proposed a tree-based authenticated index structure based on MHT. Zhang et al. proposed to use blockchain technology to perform certificateless public verification of data integrity without the need for a central authority. For verification that takes both completeness and integrity into account, Xu et al. combined MHT with Multiset accumulators, but it only supports retrieval in plaintext settings, and its integrity verification is invalid. Malicious cloud service providers may forge the accumulated value of the index and thus not return the corresponding documents that meet the search query. Liu et al. used RSA accumulators to authenticate the index structure, which has high computational overhead and is not suitable for tree-based index structures. Shao et al. used keyed hash message authentication codes and radix trees to support effective verifiable fuzzy multi-keyword search. However, none of the above schemes can achieve IND-SCPA security. For the integrity verification method of query results provided by untrusted cloud service providers, most of the existing research focuses on outsourced databases. There are two typical approaches: supporting general queries using circuit-based verifiable computing techniques and supporting specific queries using authenticated data. The approach based on verifiable computing can support arbitrary computing tasks, but its computational overhead is usually large; in addition, this approach requires cumbersome preprocessing steps because the data and query programs need to be hard-coded into the proving key and verification key. To solve this problem, Ben-Sasson et al. developed a variant of SNARKs in which the preprocessing steps only depend on the upper limit size of the database and the query program. Recently, Zhang et al. proposed a vSQL system that uses an interactive protocol to support verifiable SQL queries. However, it is limited to relational databases with fixed schemas. Two types of structures are commonly used as ADS: digital signatures and MHTs. Digital signatures authenticate the content of digital messages based on asymmetric encryption. To support verifiable queries, it requires each data record to be signed, so it cannot be extended to large data sets. On the other hand, MHTs are built on a hierarchical tree. Each entry in a leaf node is assigned a hash digest of the data record, and each entry in an internal node is assigned a digest derived from a child node. The data owner signs the root summary of the MHT, which can be used to verify any subset of the data record. Dauterman et al. proposed an encrypted time series database Waldo in a three-party honest majority model based on Function Secret Sharing (FSS). Waldo requires three non-collusive servers, which is difficult to implement in practical applications.

[0004] The incomplete trustworthiness of cloud service providers leads to the inability to guarantee the integrity, correctness, and completeness of query results. With the popularization of cloud services, low-cost and highly flexible data cloud outsourcing has become increasingly common. However, cloud service providers are generally regarded as untrusted entities and may disclose the privacy of outsourced data. In applications, due to factors such as economic factors, hardware failures, and hacker attacks, during the execution of data queries, malicious cloud service providers may only perform partial searches or retrieve tampered data sets, returning incomplete or incorrect query results; to save computing costs, cloud service providers may randomly select several pieces of data to impersonate query results, thus affecting the integrity and completeness of query results. Therefore, how to design a verifiable spatio-temporal range query system to achieve the verification of the integrity, correctness, and completeness of query results is a key issue in improving the usability of query results and enhancing the practical application value of the system. Summary of the Invention

[0005] To solve the above problems existing in the prior art, the present invention provides a verifiable multi-modal spatio-temporal data index structure and a spatio-temporal range query verification method. The technical problems to be solved by the present invention are realized through the following technical solutions:

[0006] The present invention provides a verifiable multi-modal spatio-temporal data index structure and a spatio-temporal range query verification method, including: a plaintext database generation stage, a query stage, and a verification stage;

[0007] In the plaintext database generation stage: the data owner obtains the original data set and encodes each original data in the original data set to obtain a Zorder encoding; each Zorder encoding is prefixed encoded to obtain verification data; according to the different situations of leaf nodes and non-leaf nodes in the tree structure, the attributes of leaf nodes and non-leaf nodes are set according to the verification data to obtain a plaintext tree; the plaintext tree is used as the plaintext database, and the plaintext database is sent to the cloud service provider;

[0008] In the query stage: the cloud service provider receives a query request; generates a query token according to the query request, and uses the query token to search downward from the root node in the plaintext database to obtain a query result and auxiliary verification information;

[0009] In the verification stage: the query user uses the auxiliary verification information to check whether the query result meets the spatio-temporal search range, and determines whether the query result meets the accuracy requirements and integrity requirements by comparing the root attribute of the reconstructed minimum plaintext tree with the root attribute of the original plaintext tree.

[0010] Advantageous Effects:

[0011] The present invention provides a verifiable multi-modal spatio-temporal data index structure and a spatio-temporal range query verification method, which are divided into a plaintext database generation stage, a query stage, and a verification stage. In the plaintext database generation stage, a plaintext tree with verifiable query results is constructed. During the establishment of the plaintext tree, the tags, cumulative values, and digests of each node are calculated as verification information; the leaf nodes in the plaintext tree additionally have time information, and there is a Bloom filter for the information of each node after each node, and then they are uploaded to the cloud service provider together as node attributes. In the query stage, the cloud service provider queries the hybrid index tree to obtain the query results. In the verification stage, the query user reconstructs the query path locally and compares whether the root node signatures are consistent to determine the integrity of the query results, and determines the accuracy of the query results by verifying the query results again. The present invention can achieve sub-linear search complexity for search queries, greatly improving the search efficiency. The present invention realizes high-efficiency and low-latency queries of spatio-temporal data, and realizes the verifiability of query results, solving the problem that cloud service providers are not completely trustworthy. Finally, an efficient and verifiable spatio-temporal range query system is formed, promoting the application of spatio-temporal data query services in fields such as target population recommendation, logistics distribution, and urban services.

[0012] The following will further elaborate on the present invention in conjunction with the accompanying drawings and embodiments. Description of the Drawings

[0013] Figure 1 is a schematic diagram of a typical application scenario and security threats of spatio-temporal data query services in the prior art;

[0014] Figure 2 is a flowchart for generating VRBH-Tree provided by the present invention;

[0015] Figure 3 is a schematic diagram of the prefix coding form of Z order coding provided by the present invention;

[0016] Figure 4 is a schematic diagram of the generation of VRBH-Tree nodes provided by the present invention;

[0017] Figure 5 is a schematic diagram of an example of VRBH-Tree provided by the present invention;

[0018] Figure 6 is a schematic diagram of the query process of DB provided by the present invention;

[0019] Figure 7 is a schematic diagram of VRBH-Tree query provided by the present invention;

[0020] Figure 8 is a schematic diagram of the comparison of query times between the present invention and existing solutions. Detailed Embodiments

[0021] The present invention will be further described in detail below in conjunction with specific embodiments, but the implementation manners of the present invention are not limited thereto.

[0022] The present invention uses Z order coding, prefix coding combined with a Bloom filter, constructs a hybrid index tree with verifiable query results based on a B-Tree, and realizes large-scale spatio-temporal intersection queries; during the establishment of the hierarchical index tree structure, the labels, cumulative values, and digests of each node are calculated and uploaded to the cloud server together, and only the signature of the root node digest is saved locally; after receiving the query results, the query user reconstructs the query path on the cloud server side locally and calculates the signature of the root node digest value of the query path. If it is consistent with the signature of the root node digest of the original hierarchical index tree, the verification is passed, otherwise it indicates that the query results fail the verification.

[0023] Combined Figures 2 to 7 , the present invention provides a verifiable multi-modal spatio-temporal data index structure and a spatio-temporal range query verification method, including: a plaintext database generation stage, a query stage, and a verification stage;

[0024] In the plaintext database generation stage: the data owner obtains the original data set and encodes each original data in the original data set to obtain Zorder coding; each Zorder coding is subjected to prefix coding to obtain verification data; according to the different situations of leaf nodes and non-leaf nodes in the tree structure, the attributes of leaf nodes and non-leaf nodes are set according to the verification data to obtain a plaintext tree; the plaintext tree is used as the plaintext database and the plaintext database is sent to the cloud service provider;

[0025] Among them, the step of obtaining verification data by subjecting each original data to prefix coding includes: using the prefix coding membership coding method to convert the Zorder coding of each original data and the preset geometric range into the prefix coding form to obtain verification data.

[0026] The step of setting the attributes of leaf nodes and non-leaf nodes according to the verification data according to the different situations of leaf nodes and non-leaf nodes in the tree structure of the present invention to obtain a plaintext tree includes:

[0027] Insert the verification data and the time data included in the original data into the Bloom filter as the attributes of the leaf nodes;

[0028] Insert the verification data into the Bloom filter as the attributes of the non-leaf nodes;

[0029] Establish a plaintext tree in the order of giving priority to spatial data and in the way of establishing a quadtree;

[0030] Among them, the original data is two-dimensional data, including time data and spatial data, and the verification data is one-dimensional data, only including spatial data.

[0031] Due to the large scale of the epidemiological investigation dataset, the search efficiency of a search structure with a time complexity of O(n) is slow. Therefore, a data structure with a sublinear search time complexity is proposed based on the B-Tree: to achieve sublinear search complexity and be able to verify the integrity and completeness of query results, the present invention organizes the encoded data objects into a tree structure called the Verifiable Range Query Bloom filter Hierarchical Tree (VRBH-Tree). In the VRBH-Tree, the present invention stores the original data on the leaf nodes, which are individual spatio-temporal nodes. If a user in the database has N different spatio-temporal nodes, then N original data are created for this user and stored on N different leaf nodes. For non-leaf nodes, they are defined as a range that can accommodate at most M child nodes (the child may be a point, but may also be a range). To implement the search function, the present invention sets all the nodes on the VRBH-Tree as Bloom filters after prefix encoding, converting the two-dimensional query into an existence detection problem, so that it can be easily determined whether an object contains all the query keywords, that is, to judge whether a single node belongs to a certain range.

[0032] As Figure 3 shown, the key to using a Bloom filter to implement range queries lies in how to determine whether a spatial point belongs to a certain geometric range, so as to determine whether the target data is included in the set to be searched. To solve this problem, first, the Z order encoding with excellent locality is used. According to the spatial positions of the data items, all the data items are encoded by a "Z" - shaped arrangement, mapping the data points in the two-dimensional space to a one-dimensional number line, and enabling points with close one-dimensional encodings not to be too far apart in the two-dimensional space. After obtaining the Z order encodings of the data items, the present invention uses the prefix encoding membership verification scheme to convert the Z order encodings of the data items and a specific geometric range into prefix encoding forms for subsequent retrieval.

[0033] In Figure 3 Figure a, after calculating the Z order encoding for the nodes O1O2O3O4, the corresponding encodings mapped to the one-dimensional number line are 7, 27, 42, and 37 respectively. The prefix encoding is shown in Figure b. The spatio-temporal ranges R1 and R2 are also converted into the corresponding encodings. The nodes belonging to the spatial ranges R1 and R2 are found through the prefix encoding existence detection, and the matching process of the time data is carried out in the same way.

[0034] Nodes at the same depth in the plaintext tree have the same Bloom filter length, and nodes at different depths have different Bloom filter lengths. In the plaintext database generation stage of the present invention: verification information is generated for each node in the plaintext tree; the verification information includes a digest and an accumulation value; a signature is generated for the verification information of the root node.

[0035] The present invention uses Z - order encoding to map a two - dimensional coordinate space into one - dimensional data, and uses prefix encoding combined with Bloom filters to represent node spatio - temporal data. At the same time, in order to prevent the Bloom filter lengths of each node on the VRBH - Tree from being too large, resulting in wasted storage space and an increase in the average query time complexity, it is stipulated that: only leaf nodes contain Bloom filters in both the space and time dimensions, and all other non - leaf nodes only contain Bloom filters for the spatial range. The nodes of the VRBH - Tree and its generation process can be represented as Figure 4 the form shown.

[0036] The number of prefix encodings stored in the Bloom filter of the parent node in the VRBH - Tree is always less than the number of prefix encodings stored in the child node. If the same length m is set for the Bloom filters of all nodes, if m is too small, then the Bloom filters in the lower layers of the tree will have a high false positive rate; if m is too large, it will consume a lot of memory space, which usually leads to unacceptable storage consumption. Therefore, the present invention stipulates that in a VRBH - Tree, nodes at the same depth have the same Bloom filter length, and nodes at different depths have different Bloom filter lengths. In order to keep the false positive rate less than one - thousandth, the present invention sets the relationship between m and the number of elements a in the Bloom filter:

[0037] m≈14·a.

[0038] To verify the integrity and completeness of the query results, the following preparations are required in the present invention. Given a security parameter λ, first execute KGen to obtain the key pair {pk, sk} for result verification, that is:

[0039]

[0040] pk←g u .

[0041] Then generate a public key and a private key {K pub ,K pri} for digital signature. Next, DO randomly generates a traditional collision - resistant hash function H1:{0,1} * →{0,1} η . Finally, DO outputs the public parameter set PP = {pk, K pub ,H1}, and the private key set SK = {sk, Kpri , HK}。

[0042] In the design of this algorithm, the present invention will convert the original DB into a node queue and define a flag variable flag to indicate whether the establishment of the VRBH-Tree is completed. And during the establishment process, data required for verifying the integrity and completeness of the query results is generated for each node. Each node in the tree structure stores the data c of the minimum prefix set of the spatio-temporal data of its child nodes, the label Tag (the prefix encoding of the node), and the Bloom filter B carrying the prefix encoding. Among them, the B of the parent node is obtained by merging the Bs of all child nodes; the Tag of the parent node is the minimum prefix set of the Tags of all child nodes. To implement the query result verification function, the present invention adds verification information {d, acc} to each node of the VRBH-Tree, where the digest d = H1(node.c || node.B || node.acc), and the accumulative value acc = Acc(node.Tag, sk), thereby generating the VRBH-Tree and uploading it to the CS. For the root node root, root.Tag is the intersection of the labels of all other nodes. Thus, d root can represent the state of the entire VRBH-Tree at this time. Use the digital signature function to sign it to obtain Sig as the signature of the entire tree structure. The detailed VRBH-Tree establishment algorithm is shown in Algorithm 1.

[0043]

[0044] In the loop, if the value of flag is true, then perform the generation of the tree-building node: take the first element of the node, and determine whether it and the k - 1 elements following it in the node queue satisfy the condition of being under the same parent node. If satisfied, generate the parent node Node* and add it to the node queue and update flag. If the value of flag is true, it means that the establishment of the VRBH-Tree is completed, and return the entity of this VRBH-Tree. The specific implementation of the function Acc is as follows: For the set T i ,

[0045] Since there are two variables of time and space during the retrieval process, in order to prevent too many non-leaf nodes with only one child from appearing on the VRBH-Tree due to the difference of only one variable, it is stipulated that only leaf nodes contain Bloom filters in both the space and time dimensions, and all other non-leaf nodes only contain Bloom filters in the space range, that is, the tracing logic is to first complete the matching in the space dimension, and then perform the time matching on the child nodes that have completed the matching. The process of setting the Bloom filter for a subset of leaves V = {s1, s2... s n} (s is an element in the set) is as follows:

[0046] 1) The Bloom filter is initialized as an m-bit binary vector B

[0047] 2) Select t independent hash functions {H i} 1≤i≤t , where the range of each hash function is [1, m].

[0048] 3) For any element s ∈ V, all bits with indices {H i (s)} 1≤i≤t are set to 1; to check whether the element q exists, check whether all bits with indices {H i (q)} 1≤i≤t in B are all 1. If so, q is very likely to exist in the set V.

[0049] An example of a VRBH-Tree is as Figure 5 shown. After obtaining the spatio-temporal data of the user, the two-dimensional spatial data is converted into one-dimensional spatial data using Z order encoding. The one-dimensional spatial data and one-dimensional time data are used to generate prefix codes. Then, a VRBH-Tree is built in the way of giving priority to spatial data and in the way of building a quadtree. It should be noted that only the set of the minimum prefix codes covering the ranges of all child nodes is stored in the parent node, without saving the specific information of the child nodes, so as to reduce the data length of the parent node. When the number of child nodes of the parent node reaches the maximum value, the parent node is split into four new nodes, and the original child nodes are attached to the new nodes according to the spatial information. At the same time, the evidence used for result verification is calculated for each node and stored in the nodes of the tree. After forming the basic tree structure, Bloom filters are generated for each node respectively to obtain the final VRBH-Tree.

[0050] As Figure 5 shown, for the data points 1, 2, 3, 4 storing spatio-temporal data and Bloom filters, the accumulated values acc are calculated respectively first. When storing the Bloom filters of the prefix codes of spatio-temporal data in the merging nodes, the accumulated value acc father = ∏(acc child ) of the parent node is calculated at the same time until the root node. For each node, a one-way collision-resistant hash function is used for calculation to obtain d i = H1(c i || B i || acc i ). For the digest d root of the root node, a signature algorithm is used. Thus, the signature Sig of the entire database is obtained.

[0051] In the query phase: The cloud service provider receives a query request; generates a query token according to the query request, and uses the query token to search downward from the root node in the plaintext database to obtain a query result and auxiliary verification information;

[0052] The query process of the DB is as Figure 6 shown. After receiving the spatio-temporal traceability request from the web server, the server first processes the parameters to generate a token (Token) corresponding to the traceability parameters. The system uses this token to search in the database (DB) to obtain a set of results and returns them to the web page.

[0053] As an optional implementation manner of the present invention, the generating a query token according to the query request and using the query token to search downward from the root node in the plaintext database to obtain a query result and auxiliary verification information includes:

[0054] Obtain the spatio-temporal query range included in the query request, and generate a query prefix according to the spatio-temporal query range; the spatio-temporal query range includes a time query range and a space query range;

[0055] Use the query prefix and the Bloom filter within the time query range to establish a query token;

[0056] As an optional implementation manner of the present invention, the using the query prefix and the Bloom filter within the time query range to establish a query token includes:

[0057] Convert all possible spatial data within the space query range into Zorder codes, and convert the Zorder codes into first prefix codes;

[0058] Convert all possible time data within the time query range into second prefix codes;

[0059] Form a first prefix code set from the first prefix codes, and form a second prefix code set from the second prefix codes;

[0060] Use the first prefix code set and the second prefix code set as the query prefix;

[0061] Determine the query prefix as the query token.

[0062] To prevent the Bloom filters of each node on the VRBH-Tree from being too long, resulting in wasted storage space and an increase in the average query time complexity, the present invention generates Tokens for each layer of nodes in the tree structure. Given a search query Q = {R Q ,C Q}, the TokGen algorithm generates a search token TQ For the j-th layer in the VRBH-Tree, according to the query range R Q Generate a query prefix and use the hash function HK j Build a Bloom filter that contains the query prefix and all the times in the time query range C Q , that is, the search token T Q . The database (DB) query token generation and spatio-temporal query algorithms are shown in Algorithm 2 and Algorithm 3.

[0063]

[0064] To achieve complete and comprehensive query of the query results, given the private key set SK and the spatio-temporal query Q, QU first converts the spatial data in Q into Z-order encoding, and then converts the spatio-temporal data into prefix encoding Tag Q ={t1,…,t q}, where q is the number of query ranges in Q. The prefix encoding set is used as the query token TK = {t′1,…,t′ q}.

[0065] Use the query token to search from the root node downwards on the plaintext tree to record the search path from the root node to the leaf node;

[0066] Query the nodes of each search path according to the query token to determine the nodes that meet the query conditions to obtain the query results and the nodes that do not meet the query conditions to obtain the mismatch information;

[0067] Among them, the query condition is: there is an intersection between the spatial query range in the node attribute and the spatial query range corresponding to the query request.

[0068] As an optional implementation manner of the present invention, the querying the nodes of each search path according to the query token to determine the nodes that meet the query conditions to obtain the query results and the nodes that do not meet the query conditions to obtain the mismatch information includes:

[0069] For the non-leaf nodes on each search path, if the non-leaf node meets the query condition, record the digest of the non-leaf node; otherwise, calculate the disjoint proof of the non-leaf node and record the mismatch information of the non-leaf node;

[0070] For the leaf nodes on each search path, if the leaf node meets the query condition, add the digest of the leaf node to the query result set; otherwise, calculate the disjoint proof of the leaf node and record the mismatch information of the leaf node.

[0071] Form the query results of each query path into a query result set;

[0072] Generate auxiliary verification information based on the query result set, and send the query result and the auxiliary verification information to the service provider.

[0073] For the j-th layer in the VRBH-Tree, it uses Query to check the prefix encoding saved in each node BF. If, during the query process, any BF matches a certain node, it continues to search its child nodes; otherwise, it stops searching this subtree. When reaching the leaf node, it uses Query to check the prefix encoding saved in BF. If the result is "true", it adds the data point to the result set R. The specific algorithm process is as shown in Algorithm 4. During the search process, it only needs to traverse the VRBH-Tree from the root node. When traversing the child nodes downward, it only continues to query the subtrees that meet the query conditions. The resulting search space is dynamically pruned, greatly reducing the complexity of retrieval.

[0074]

[0075] Meanwhile, during the search process, relevant evidence for query result verification needs to be saved. During the query process, the present invention saves the deep search path from the root node to the leaf node, denoted as verify-tree. For the non-leaf node Node at the j-th layer in the path j , if it meets the query conditions, then record {Node j .c, Node j .B, Node j .acc}; otherwise, calculate the disjoint proof π = MSA.PDisjoint(Node j .c, Tag Q , pk):

[0076]

[0077] where, Q1, Q 2 satisfy: P(T1)Q1 + P(T2)Q2 = 1.

[0078] And record {Node j .d, Node j .π, Node j .acc} in this unmatched node; for the leaf node Node at the k-th layer k , if it meets the query conditions, then add it to the query result set R and record {Node k .B, Node k .acc}; otherwise, record {Node k .d, Node k .π, Node kAfter the query algorithm finishes execution, CS sends the query result set R and the auxiliary verification information AP to QU, where AP = {node.d, node.acc, π, node.Tag, Sig}.

[0079] The schematic diagram of the VRBH-Tree query is as Figure 7 shown as follows:

[0080] As Figure 7 , in a VRBH-Tree with only a three-layer structure, taking the spatial query range {8, [12 - 15]} and the temporal query range [6 - 7] as examples, the query process on the VRBH-Tree is demonstrated. According to the search range, the prefix code sets of the spatial query range and the temporal query range are respectively generated at each level as the Tokens for subsequent queries, and then these Tokens are used to query the corresponding levels in the DB. In Figure 7 , for the first match: the N4 child node of the root node is successfully matched, and the remaining child nodes are pruned. The digest, cumulative value, mismatch flag, and mismatch proof of the pruned nodes are recorded. For the second match: the child of N4, the leaf node O5 is pruned and its digest, cumulative value, mismatch flag, and mismatch proof are recorded. The leaf node O6 is the query result and is added to the result set.

[0081] In addition to the query result set, the auxiliary verification information AP is obtained, which consists of the cumulative value of each node on the search path, the digest, cumulative value, mismatch flag, and mismatch proof of each node not on the search path, and the root signature Sig of the root node, that is, AP = {node.d, node.acc, node.π, node.T, Sig}.

[0082] In the verification stage: the query user uses the auxiliary verification information to check whether the query result meets the spatio-temporal search range, and determines whether the query result meets the accuracy requirement and the integrity requirement by comparing the root attribute of the reconstructed minimum plaintext tree with the root attribute of the original plaintext tree.

[0083] As an optional implementation manner of the present invention, the query user uses the auxiliary verification information to check whether the query result meets the spatio-temporal search range, and determines whether the query result meets the accuracy requirement and the integrity requirement by comparing the root attribute of the reconstructed minimum plaintext tree with the root attribute of the original plaintext tree, including:

[0084] The query user re-verifies the nodes that do not meet the query conditions on each query path by using the auxiliary verification information to confirm the correctness of the query result;

[0085] Query the user's query path for nodes that do not meet the query conditions. Reconstruct this query path based on the relationships between the nodes and the summaries of the nodes, and use the reconstructed query path as the minimum authentication tree.

[0086] The user compares the summary of the root node of the minimum authentication tree with the summary of the original root node on the plaintext tree to determine the integrity of the query result.

[0087] Using the auxiliary verification information AP, first run VDisjoint to check whether the points not in the query result do not meet the spatio-temporal range query Q, then reconstruct the minimum authentication tree verify-tree, and its root summary d′ root with the original tree root summary d root for comparison to verify the correctness and integrity of the search result. In Figure 7 , first calculate equation (a) to prove that points 1, 2, and 5 are not within the spatio-temporal range p, thus determining that points 1, 2, and 5 do not match the spatio-temporal query range Q. Decrypt the signature Sig using the corresponding public key to obtain the original root summary d root , that is Finally, calculate equation (b) to obtain the root summary d′ root and compare it with d root . If d root ==d′ root then the query result is correct and complete.

[0088]

[0089]

[0090] Among them, the specific implementation of the VDisjoint function in equation (a) is as follows:

[0091]

[0092] The present invention constructs a verifiable spatio-temporal range index tree. The non-leaf nodes contain spatially encoded information after Zorder encoding and prefix encoding, and the leaf nodes additionally have temporal information. There is a Bloom filter for the information of each node to achieve sub-linear search complexity for search queries, greatly improving the search efficiency. At the same time, the integrity, correctness, and completeness of the query results can be verified. To prevent the server from deceiving the user by skipping certain nodes during the query, if the query token matches the current node during the query, the search continues; if not, a disjoint proof needs to be generated additionally. After the entire query process, all disjoint proofs are sent to the user together with other information. The user uses the Verify algorithm locally to verify these disjoint proofs. If the return value of the verification algorithm is true, it can be proved that the search process is running normally. If the return value of the verification algorithm is false, it means that the server omitted some nodes that should have been matched during the search process.

[0093] The solution proposed by the present invention can be implemented using the JAVA programming language, with the security parameter λ = 128. The maximum capacity of the deepest non-leaf node of the VRBH-Tree in v-SKSE is set to 16. The size of the Bloom filter is set to m = 256, t = 14, so that the false positive rate is f ≤ (1 - e (-14×16) / 256 ) 14 ≈4.2×10 -7 。

[0094] Compared with the Dauterman and Waldo schemes, Dauterman proposed the encrypted time-series database Waldo in the three-party honest majority model using Function Secret Sharing (FSS). Waldo supports multi-predicate filtering such as time, space, and text, and is the only currently existing encrypted database that supports verifiable queries for multi-modal spatio-temporal data. Waldo requires three non-colluding servers, which is difficult to achieve in practical applications.

[0095] See Figure 8 , the query latency of the present invention and existing schemes is compared on a simulated dataset. The dataset size N ranges from 2×10 10 to 1×10 20 . It can be seen that the present system is very efficient and is comparable to the fastest multi-cloud scheme Waldo in terms of a single cloud server.

[0096] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the present invention, "a plurality of" means two or more unless otherwise specifically defined.

[0097] Although the present application has been described in conjunction with various embodiments herein, however, in the process of implementing the claimed present application, those skilled in the art can understand and realize other variations of the disclosed embodiments by viewing the accompanying drawings, the disclosure content, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "one" does not exclude a plurality of cases.

[0098] The above content is a further detailed description of the present invention in conjunction with specific preferred embodiments, and it cannot be determined that the specific implementation of the present invention is only limited to these descriptions. For those of ordinary skill in the technical field to which the present invention pertains, without departing from the concept of the present invention, several simple deductions or substitutions can be made, and all should be regarded as belonging to the protection scope of the present invention.

Claims

1. A verifiable multi-modal spatio-temporal data index structure and a spatio-temporal range query verification method, characterized in that, Including: The plaintext database generation phase, the query phase, and the verification phase; In the plaintext database generation phase: The data owner obtains the original dataset and encodes each original data in the original dataset to obtain the Zorder encoding; Each Zorder encoding is prefixed encoded to obtain the verification data; According to the different situations of leaf nodes and non-leaf nodes in the tree structure, the attributes of leaf nodes and non-leaf nodes are set according to the verification data to obtain the plaintext tree; The plaintext tree is used as the plaintext database, and the plaintext database is sent to the cloud service provider; In the query phase: The cloud service provider receives the query request; Generates a query token according to the query request and uses the query token to search from the root node in the plaintext database from bottom to top to obtain the query result and the auxiliary verification information; In the verification phase: The query user uses the auxiliary verification information to check whether the query result meets the spatio-temporal search range, and determines whether the query result meets the accuracy requirements and integrity requirements by comparing the root attribute of the reconstructed minimum plaintext tree with the root attribute of the original plaintext tree.

2. The verifiable multi-modal spatio-temporal data index structure and the spatio-temporal range query verification method according to claim 1, characterized in that, The setting of the attributes of leaf nodes and non-leaf nodes according to the verification data according to the different situations of leaf nodes and non-leaf nodes in the tree structure to obtain the plaintext tree includes: Inserting the verification data and the time data included in the original data into the Bloom filter as the attribute of the leaf node; Inserting the verification data into the Bloom filter as the attribute of the non-leaf node; Establishing the plaintext tree in the order of spatial data first and in the way of establishing a quadtree; Among them, the original data is two-dimensional data, including time data and spatial data, and the verification data is one-dimensional data, only including spatial data.

3. The verifiable multi-modal spatio-temporal data index structure and the spatio-temporal range query verification method according to claim 1, characterized in that, The obtaining of the verification data by prefix encoding each original data includes: Using the prefix encoding membership encoding method to convert the Zorder encoding of each original data and the preset geometric range into the prefix encoding form to obtain the verification data.

4. The verifiable multi-modal spatio-temporal data index structure and the spatio-temporal range query verification method according to claim 1, characterized in that, In the plaintext tree, nodes at the same depth have the same Bloom filter length, and nodes at different depths have different Bloom filter lengths.

5. The verifiable multi-modal spatio-temporal data index structure and the spatio-temporal range query verification method according to claim 1, characterized in that, The verifiable multi-modal spatio-temporal data index structure and the spatio-temporal range query verification method further include: In the plaintext database generation phase: Generating verification information for each node in the plaintext tree; Among them, the verification information includes a digest and an accumulation value; Generating a signature for the verification information of the root node.

6. The verifiable multi-modal spatio-temporal data index structure and the spatio-temporal range query verification method according to claim 5, characterized in that, The generating of the query token according to the query request and using the query token to search from the root node in the plaintext database from bottom to top to obtain the query result and the auxiliary verification information includes: Obtaining the spatio-temporal query range included in the query request and generating a query prefix according to the spatio-temporal query range; The spatio-temporal query range includes a time query range and a spatial query range; Using the query prefix and the Bloom filter in the time query range to establish a query token; Using the query token to search from the root node in the plaintext tree from bottom to top to record the search path from the root node to the leaf node; Query the nodes of each search path according to the query token to determine the nodes that meet the query conditions to obtain query results and the nodes that do not meet the query conditions to obtain mismatch information; Form a query result set from the query results of each query path; Generate auxiliary verification information according to the query result set, and send the query results and the auxiliary verification information to the service provider.

7. The verifiable multi-modal spatio-temporal data index structure and the spatio-temporal range query verification method according to claim 6, characterized in that, The establishing the query token by using the query prefix and the Bloom filter within the time query range includes: Convert all possible spatial data within the spatial query range into Zorder codes, and convert the Zorder codes into first prefix codes; Convert all possible time data within the time query range into second prefix codes; Form a first prefix code set from the first prefix codes, and form a second prefix code set from the second prefix codes; Use the first prefix code set and the second prefix code set as the query prefix; Determine the query prefix as the query token.

8. The verifiable multi-modal spatio-temporal data index structure and spatio-temporal range query verification method according to claim 6, characterized in that, The querying the nodes of each search path according to the query token to determine the nodes that meet the query conditions to obtain query results and the nodes that do not meet the query conditions to obtain mismatch information includes: For non-leaf nodes on each search path, if the non-leaf node meets the query conditions, record the summary of the non-leaf node; otherwise, calculate the disjoint proof of the non-leaf node and record the mismatch information of the non-leaf node; For leaf nodes on each search path, if the leaf node meets the query conditions, add the summary of the leaf node to the query result set; otherwise, calculate the disjoint proof of the leaf node and record the mismatch information of the leaf node.

9. The verifiable multi-modal spatio-temporal data index structure and spatio-temporal range query verification method according to claim 6, characterized in that, The query condition is that there is an intersection between the spatial query range in the node attributes and the spatial query range corresponding to the query request.

10. The verifiable multi-modal spatio-temporal data index structure and spatio-temporal range query verification method according to claim 7, characterized in that, The query user uses the auxiliary verification information to check whether the query results meet the spatio-temporal search range, and determines whether the query results meet the accuracy requirements and integrity requirements by comparing the root attributes of the reconstructed minimum plaintext tree with the root attributes of the original plaintext tree, including: The query user re-verifies the nodes that do not meet the query conditions on each query path by using the auxiliary verification information to confirm the correctness of the query results; For query paths with nodes that do not meet the query conditions, the query user reconstructs the query path according to the relationships between the nodes and the summaries of the nodes, and uses the reconstructed query path as the minimum authentication tree; The query user compares whether the summary of the root node of the minimum authentication tree is consistent with the summary of the original root node on the plaintext tree to determine the integrity of the query results.

Citation Information

Patent Citations

  • Efficient verifiable multi-keyword sequencing searchable encryption method supporting preference search and logic search

    CN108388807A

  • Verifiable range query method based on ciphertext spatio-temporal data

    CN111274247A