Verifiable Privacy-Preserving Retrieval Method and System for Massive Image Data in Cloud Environment

By using orthogonal decomposition and fault-tolerant learning in a cloud environment to generate secure indexes and trap gates, combined with satellite system diagrams and Merkel trees and other technologies, the privacy protection retrieval and result verification problems of massive image data are solved, and efficient and accurate retrieval and powerful result verification capabilities are achieved.

CN117194689BActive Publication Date: 2025-05-30WUHAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311036879.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-08-15
Publication Date
2025-05-30
Estimated Expiration
2043-08-15

AI Technical Summary

Technical Problem

In the cloud environment, the privacy protection of massive image data is faced with the problems of high calculation consumption and difficulty in verifying the search results, especially when the amount of data is large and the integrity of the server is difficult to guarantee.

Method used

The orthogonal decomposition technology and fault-tolerant learning theory are used to generate security indexes and security traps, and the satellite system graph index structure of the ciphertext domain is constructed, and the message verification code is generated through edge server assistance, combining Merkel tree and improved cuckoo hash for search results verification.

Benefits of technology

It realizes efficient and accurate massive image privacy protection retrieval, and effectively verifies the correctness of the search results, reducing the computing burden of data owners and user verification burden.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117194689B_ABST
    Figure CN117194689B_ABST
Patent Text Reader

Abstract

The present invention belongs to the field of information security protection, and particularly relates to a verifiable privacy protection retrieval method and system for massive image data in a cloud environment, which can be used for secure and efficient massive image retrieval and verify the correctness of retrieval results at the same time. By using orthogonal decomposition technology and the theory of fault-tolerant learning problems to generate secure indexes and secure traps, it supports the cloud server to construct an efficient satellite system graph as an index structure for multi-source massive images in the ciphertext domain. In order to support the verification of ciphertext data and reduce the computational burden of data owners, an edge server is used to assist in generating message authentication codes for ciphertexts so that users can verify the correctness of the ciphertexts of retrieval results. Aiming at the problem of retrieval result verification, combining Merkle trees and improved cuckoo hashing supports users to efficiently verify whether the amount of accessed data during the retrieval process by the cloud server and the calculated retrieval results are correct.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of information security protection, and particularly relates to a verifiable privacy protection retrieval method for massive image data in a cloud environment, which can be used for secure and efficient massive image retrieval and verify the correctness of retrieval results at the same time. Background Art

[0002] With the popularization of intelligent devices and the continuous expansion of application fields, more and more data storage and computing requirements pose challenges to terminal devices, prompting users to outsource data to servers and access these data remotely to save local storage costs and maintenance burdens. However, data outsourcing will cause data owners to lose physical control of the data, which may pose a security threat to sensitive data.

[0003] To protect user data privacy, it is generally possible to encrypt the data before transmitting it to the server. Traditional cryptography can prevent data privacy leakage, but the direct encryption method will affect data availability and thus affect data sharing and applications. For example, in a common content-based image retrieval task, it can extract visual features from images, then calculate the distances between image features, and sort according to the similarity between images. Therefore, privacy-preserving image retrieval schemes have been proposed. However, with the growth of data volume, especially when cloud servers aggregate massive amounts of data, the computational cost of using linear retrieval is too high. To reduce the computational overhead and improve efficiency, an appropriate index structure can be used to reduce the amount of data accessed. However, if the data owner constructs the index structure, it will bring a huge computational burden to the data owner and cannot support the cloud server to complete multi-source image retrieval. Therefore, it is necessary for the cloud server to construct an efficient retrieval index structure on the ciphertext.

[0004] In practical applications, the cost of cloud servers storing massive amounts of data will increase with the increase in data volume and storage time. Some of this data may be rarely accessed and used. Due to economic reasons, software errors or hardware failures of devices, or even external attacks, etc., the correct data originally stored in the cloud server may be tampered with, forged, or even lost. During the retrieval process, it is impossible to guarantee that the retrieved data is correct, nor can it guarantee that the server will definitely execute the protocol honestly. It may execute partial calculations or even stop executing the protocol to save costs, and return incorrect or even random retrieval results. Therefore, it is necessary to verify the retrieval results.

[0005] When using an index structure for retrieval, the calculation protocol does not require the server to calculate the distance for each data in the entire database. It is difficult to determine which data the server has accessed, and it is also difficult to determine whether the server's retrieval results are correct. Therefore, it is necessary to study efficient privacy protection retrieval methods and result verification methods for massive images. Summary of the Invention

[0006] The present invention aims to propose a verifiable privacy - preserving retrieval method for massive image data in the cloud environment. By using orthogonal decomposition technology and the theory of fault - tolerant learning problems to generate secure indexes and secure traps, it supports the cloud server to construct a satellite system graph as an index structure for multi - source massive images in the ciphertext domain, so as to complete efficient and accurate retrieval. To support the verification of ciphertext data and reduce the computational burden of data owners, an edge server is used to assist in generating message authentication codes for ciphertexts, so that users can verify the correctness of the ciphertext of the retrieval results. For the problem of verifying retrieval results, combining Merkle trees and improved cuckoo hashing supports users to efficiently verify whether the amount of accessed data and the calculated retrieval results during the retrieval process by the cloud server are correct.

[0007] This solution is divided into an offline phase and an online phase. In the offline phase, the key management center generates various keys and the required hash functions, and distributes them to data owners, edge servers, cloud servers, and authorized users. First, the data owner extracts features from the images, generates secure indexes through methods such as adding noise, scrambling, orthogonal decomposition, and fault - tolerant learning, and sends these secure indexes and encrypted images to the edge server. Subsequently, the edge server generates message authentication codes (MACs) for each ciphertext image and secure index, and uploads the ciphertexts and MAC values to the cloud server. The cloud server uses the corresponding re - encryption key to perform re - encryption on the received secure indexes, and generates a satellite system graph as an index structure on the ciphertexts. In the online phase, after the authorized user applies to the key management center to obtain the key, a secure trap is generated through orthogonal decomposition and fault - tolerant learning and sent to the cloud server. The cloud server performs re - encryption, and then uses the re - encrypted trap to retrieve in the satellite system graph index structure to obtain the retrieval results. To verify the retrieval results, the cloud server generates a Merkle tree to verify the correctness of the ciphertext images and encrypted indexes of the retrieval results, uses improved cuckoo hashing to generate a privacy - protected hash table, which can securely disclose the amount of accessed data and the distance values calculated for each data. Subsequently, the cloud server generates a transformation key corresponding to this retrieval for the user, and sends the transformation key, the root node of the Merkle tree, and the hash table to the user. When verifying, the user first verifies the correctness of the ciphertext images and encrypted indexes through the Merkle tree, and then reconstructs the distance values using the encrypted indexes and the transformation key, and compares the distance results calculated by the server stored in the hash table to further determine whether the retrieval results returned by the cloud server are correct.

[0008] The verifiable privacy - preserving retrieval method for massive image data in the cloud environment provided by the present invention involves a Key Management Center (KMC), a Data Owner (DO), an Authorized User (U), an Edge Server (ES), and a Cloud Server (CS). The specific implementation steps are as follows:

[0009] Step 1, the Key Management Center generates keys and the required hash functions for each participant in the verifiable retrieval system;

[0010] Step 2, the image owner obtains the key from the Key Management Center, then extracts the image features, encrypts the image features to obtain a secure index, and uploads it together with the encrypted image to the Edge Server;

[0011] Step 3, the Edge Server calculates the Message Authentication Code (MAC) of the ciphertext image and the encrypted index according to the received ciphertext data, and then sends the ciphertext and the corresponding MAC value to the Cloud Server;

[0012] Step 4, the Cloud Server re - encrypts all the received secure indexes according to the re - encryption key, and uses each re - encrypted index as a node to generate a satellite system graph index structure in the ciphertext domain;

[0013] Step 5, the authorized user U j obtains the key returned via a secure channel from the Key Management Center, extracts the features of the query image to generate a secure trapdoor T, and then sends it to the Cloud Server;

[0014] Step 6, the Cloud Server re - encrypts the received secure trapdoor T using the corresponding re - encryption key to obtain then calculates the distance between the re - encrypted index and the trapdoor, and searches on the satellite system graph index structure to obtain the retrieval result;

[0015] Step 7, the Cloud Server uses the MAC values of the ciphertext image and the encrypted index of the retrieval result to generate Merkle trees respectively, and obtains the value of the root node. Then, using the improved cuckoo hash, a privacy - protected hash table is generated for the ID information, distance information, and sorting information of the data accessed in this retrieval. Next, the Cloud Server returns the retrieval result and the corresponding verification data;

[0016] Step 8, the authorized user verifies the correctness of the ciphertext image and the encrypted index according to the Merkle tree. After determining that the ciphertext is correct, the encrypted index is used to reconstruct the distance value, and then it is compared with the hash table to verify whether the calculation result of the cloud server for this data is correct. If the retrieval result is confirmed to be correct, the authorized user decrypts the ciphertext image to obtain the retrieved plaintext result.

[0017] Further, the implementation method of step 1 is as follows.

[0018] Step 1.1, the key management center selects an encryption key EncK and a decryption key DecK for the image; generates an orthogonal matrix r represents the dimension of each vector in the orthogonal matrix, and the data range of its vectors is much smaller than the data range of the image features. The orthogonal vectors in are divided into two non-overlapping sets and for feature dimension expansion; a scrambling function Π() is selected to protect the features; an orthogonal matrix is generated for orthogonal decomposition, where d is the feature dimension; an orthogonal matrix i (representing the i-th data owner) or the authorized user U j (representing the j-th user), the KMC will decompose the matrix to obtain TK X and SK X , where X = DO i or U j , TK X is the re-encryption key corresponding to X, and SK X is the index or trapdoor generation key of X, satisfying In addition, the KMC will select a random number γ for generating a secure index and a trapdoor;

[0019] Step 1.2, the KMC selects a random number g > 1 and generates a key Key M for the message authentication code; generates a hash function mht for constructing the Merkle tree; generates w hash functions for determining the position of the retrieved access data in the hash table, and generates a hash function hash to calculate the hash value of the retrieval result;

[0020] Step 1.3, the KMC will send {g, Key M} to the edge server and send to the cloud server. The KMC generates a key i for the data owner DO and generates a key j for the authorized user U

[0021] Furthermore, the implementation of Step 2 is as follows:

[0022] For a certain data owner DO i , whose image set contains n i images Each image feature f l =(f l (1), …, f l (d)) T is d-dimensional;

[0023] Step 2.1, DO i sends a request to the KMC, and the KMC returns a set of keys through a secure channel

[0024] Step 2.2, DO i randomly selects a vector a from i , expands the dimension of the feature f l to obtain f′ l =(f l (1), …, f l (d), a i (1), …, a i (r)) T , and then uses the scrambling function Π() to obtain a vector

[0025] Step 2.3, DO i uses an orthogonal matrix to perform orthogonal decomposition on to obtain orthogonal coefficients

[0026] Step 2.4, DO i selects a random integer noise τ l =[τ l (1), τ l (2), …, τ l (d + r)] T , and the data range of each element of the random noise should be much smaller than the random number γ. Using the theory of fault-tolerant learning, encrypts the orthogonal coefficients y with the key l as shown in formula (1) to obtain the secure index I l ;

[0027]

[0028] Step 2.5, DO iEncrypt the image m using EnCK l , and obtain c l . Upload the ciphertext image and the security index to the edge server.

[0029] Furthermore, the implementation of step 3 is as follows

[0030] The edge server receives the ciphertexts sent by each data owner where n is the number of ciphertexts received by ES;

[0031] Step 3.1, ES uses the ciphertext image c l and the ID value id of this image l to calculate the MAC value σ l ;

[0032] σ l = MAC(Key M , id l ||c l ) (2) Step 3.2, ES calculates the encrypted index for the security index I l and then calculates the MAC value ρ according to formula (3); l ;

[0033]

[0034] Step 3.3, ES sends to the cloud server.

[0035] Furthermore, the implementation of step 4 is as follows

[0036] Step 4.1, The cloud server uses the re-encryption key to re-encrypt all the received security indexes I l and calculates to obtain where DO i represents the data owner to which I l belongs, l ∈ [1, n all , and n all is the number of all security indexes aggregated by the cloud server. Subsequently, the cloud server calculates for each security index, where

[0037] Step 4.2, The cloud server selects the angle for constructing the satellite system diagram as α. For each re-encrypted index it calculates it and for all the remaining indexes in The distance between is added to the list L;

[0038] Step 4.3, Sort the distance values in L, find the closest point L[0], and add it to the set P of neighbor nodes;

[0039] Step 4.4, For all the index nodes in L Calculate the angle between it and each index node in the set P and compare it with α. If this angle is greater than α, add the node to add the set P of neighbor nodes;

[0040] Step 4.5, According to the set P of neighbors of each index node construct the satellite system graph structure G.

[0041] Furthermore, the implementation of Step 5 is as follows.

[0042] For the authorized user U j , the feature of its query image is fq;

[0043] Step 5.1, U j sends a request to the KMC and subsequently obtains the set of keys returned by the KMC

[0044] Step 5.2, U j randomly selects a vector a from j , expands the dimension of the feature fq to obtain fq′=(fq(1),…,fq(d),a j (1),…,a j (r)) T , and then uses the scrambling function Π() to obtain the vector

[0045] Step 5.3, U j uses the orthogonal matrix to perform orthogonal decomposition on to obtain the orthogonal coefficients p=(p(1),…,p(d+r)) T ;

[0046] Step 5.4, U j selects random integer noises τj = [τ j (1),τ j (2),…,τ j (d+r)] T , and the selection range of each element of the random noise should be much smaller than the random number γ. Using the key Encrypt the orthogonal coefficient p as shown in formula (4) to obtain the security trapdoor T, and send T to the cloud server for retrieval.

[0047]

[0048] Furthermore, the implementation of step 6 is as follows.

[0049] Step 6.1, the cloud server uses the re-encryption key to re-encrypt the security trapdoor T of the authorized user U j to obtain

[0050] Step 6.2, the cloud server calculates the distance dist between the index node and the re-encrypted trapdoor on the satellite system graph structure as shown in formula (5), and uses the retrieval method of the satellite system graph structure to iteratively access the neighbors of the index node and the neighbors of its neighbors to obtain k retrieval results that are very close to the re-encrypted trapdoor, and the corresponding ID values are

[0051]

[0052] Furthermore, the implementation of step 7 is as follows.

[0053] The cloud server generates verification data according to the retrieval results and the nodes accessed during the retrieval;

[0054] Step 7.1, generate a Merkle tree based on the MAC values of the ciphertext images of the k retrieval results to obtain the value root C ;

[0055] Step 7.2, generate a Merkle tree for the MAC values of the encrypted indexes of the k retrieval results to obtain the value root I ;

[0056] Step 7.3, for the data accessed by the CS during the retrieval process, the corresponding sorting value can be obtained according to the distance values recorded during the retrieval process where v is the number of accessed data. The cloud server selects a random number θ for this query to protect the retrieval distance;

[0057] Step 7.4, the CS first sets a hash table. Suppose there are B buckets and each bucket has X slots. Subsequently, borrowing the idea of cuckoo hashing, use a set of hash functions For each accessed data, use its sorting value sort i , calculate its storage location in the hash table Subsequently, when looking up the location, if the position of H 1 (sort i ) is empty, store the hash value in this position. If this position is not empty, instead of using the method of cuckoo hashing to kick out the existing data, look up the next hash position H 2 (sort i ), and so on, until an empty position is found. If all positions in the first slot are already occupied with data, start looking up one by one in the second slot, and so on, until an empty position is found to store the hash value of the data. Store the hash values of all accessed data in the hash table to obtain the hash table which can disclose the computational amount of the cloud server during the retrieval process without leaking the privacy information of the accessed data during the retrieval;

[0058] Step 7.5, CS generates a transformation key for the retrieval result where DO i represents the data owner to which the result data belongs;

[0059] Step 7.6, CS sends the retrieval result, proof data, and transformation key to the authorized user U j .

[0060] Furthermore, the implementation method of step 8 is as follows

[0061] The authorized user U j after receiving the data, respectively verifies the correctness of the ciphertext and the correctness of the cloud server distance calculation result;

[0062] Step 8.1, U j uses Key M to calculate the MAC values of the received image ciphertext and the encrypted index , as shown in formula (6);

[0063]

[0064] Step 8.2, U j uses and mht to construct a Merkle tree, obtaining the values of two root nodes root′ C , root′ I . Subsequently, U j compares the received root node values root C , rootI With the calculated root node root′ C , root′ I , if the root node values are the same, it indicates that the ciphertext image and the encryption index are both correct, and proceed to the next verification; otherwise, reject the retrieval result.

[0065] Step 8.3, after determining that the encryption index is correct, U j uses the received key to transform the trapdoor T and obtain Subsequently, for each returned result, U j reconstructs the distance value as shown in formula (7) to obtain the distance Next, U j calculates the hash value

[0066]

[0067] Step 8.4, U j uses the hash function to calculate the storage location of each returned result in the hash table If the data at a certain location among these locations is the same as the j calculated hash value by U, it indicates that the cloud server's calculation of this data is correct. Verify each data in the retrieval result to confirm that the cloud server's distance calculation for the returned k results is correct. For multiple data, it is also possible to judge whether the sort given by the cloud server is correct according to the l sorting;

[0068] Step 8.5, in addition to the returned result data, if U j wants to verify other accessed data, it can send the sort x to the cloud server, and the cloud server will return Subsequently, U j can use ρ x to verify whether the encryption index is correct according to Step 8.1. After confirmation, verify whether the cloud server's distance calculation result for this data is correct according to Step 8.3 and Step 8.4, and it is possible to judge whether the distance values of these data are smaller than the distance values of the retrieval result;

[0069] Step 8.6, after the authorized user confirms that the ciphertext image of the retrieval result is correct, and the server's calculation result and sorting for the data are also correct, then U j uses DecK to decrypt the image ciphertext to obtain the corresponding plaintext retrieval result.

[0070] The present invention also provides a verifiable privacy - protected retrieval system for massive image data in a cloud environment, including the following modules:

[0071] A key and hash function generation module, which is used for the key management center to generate keys and the required hash functions for each participant in the verifiable retrieval system;

[0072] A secure index generation module, which is used for the image owner to obtain a key from the key management center, then extract image features, encrypt the image features to obtain a secure index, and upload it to the edge server together with the encrypted image;

[0073] A MAC calculation module, which is used for the edge server to calculate the message authentication code MAC of the ciphertext image and the encrypted index according to the received ciphertext data, and then send the ciphertext and the corresponding MAC value to the cloud server;

[0074] A re - encryption and index structure generation module, which is used for the cloud server to re - encrypt all the received secure indexes according to the re - encryption key, and use each re - encrypted index as a node to generate a satellite system graph index structure in the ciphertext domain;

[0075] A secure trapdoor generation module, which is used for the authorized user U j to obtain the key returned via a secure channel from the key management center, extract the features of the query image to generate a secure trapdoor T, and then send it to the cloud server;

[0076] A retrieval result acquisition module, which is used for the cloud server to re - encrypt the received secure trapdoor T using the corresponding re - encryption key to obtain then calculate the distance between the re - encrypted index and the trapdoor, and search in the satellite system graph index structure to obtain the retrieval result;

[0077] A verification data acquisition module, which is used for the cloud server to generate Merkle trees using the MAC values of the ciphertext image and the encrypted index of the retrieval result respectively to obtain the values of the root nodes; then use Cuckoo hashing to generate a privacy - protected hash table for the ID information, distance information, and sorting information of the data accessed in this retrieval; then, the cloud server returns the retrieval result and the corresponding verification data;

[0078] A plaintext result acquisition module, which is used for the authorized user to verify the correctness of the ciphertext image and the encrypted index according to the Merkle tree. After determining that the ciphertext is correct, use the encrypted index to reconstruct the distance value, and then compare and verify it with the hash table to confirm whether the calculation result of the cloud server for this data is correct; if it is confirmed that the retrieval result is correct, the authorized user decrypts the ciphertext image to obtain the retrieved plaintext result.

[0079] Compared with the prior art, the advantages and beneficial effects of the present invention are as follows: The present invention proposes a verifiable privacy-preserving retrieval method for massive image data in a cloud environment. This method can support efficient and high-precision privacy-preserving image retrieval, and at the same time can efficiently verify the retrieval results. It adaptively improves the retrieval method based on orthogonal decomposition and fault-tolerant learning, supports the efficient and secure construction of satellite system graph structures in the ciphertext domain, and provides efficient retrieval of massive data. At the same time, by combining the Merkle tree with the improved cuckoo hash, it verifies the workload of the server while completing the verification of the retrieved ciphertext images and distance calculation results, and does not impose a huge verification calculation burden on users. BRIEF DESCRIPTION OF THE DRAWINGS

[0080] Figure 1 FIG. is a general schematic diagram of the secure retrieval method according to an embodiment of the present invention.

[0081] Figure 2 FIG. is a graph of experimental results according to an embodiment of the present invention, where (a) is a graph of the change in retrieval accuracy, and (b) is a schematic diagram of the time consumed during the retrieval process. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0082] In order to make the objectives, technical solutions, and advantages of the present invention clearer, the following further describes the embodiments of the present invention in detail with reference to the accompanying drawings.

[0083] As Figure 1 shown, the embodiment of the present invention provides a verifiable privacy-preserving retrieval method for massive image data in a cloud environment, including the following steps:

[0084] Step 1: The key management center generates keys and the required hash functions for each participant in the verifiable retrieval system.

[0085] Step 1.1, the key management center selects an encryption key EncK and a decryption key DecK for the image; generates an orthogonal matrix r represents the dimension of each vector in the orthogonal matrix, and the data range of its vectors is much smaller than the data range of the image features. Divide the orthogonal vectors in into two non-overlapping sets and for feature dimension expansion; select a scrambling function Π() to protect the features; generate an orthogonal matrix for orthogonal decomposition, where d is the feature dimension; generate an orthogonal matrix for generating a secure index and a trapdoor. Subsequently, for any data owner DO i (representing the i-th data owner) or authorized user U j (representing the j-th user) in the retrieval system, the KMC will decompose the matrix S to obtain TK X and SK X, where X = DO i or U j , TK X is the re - encryption key corresponding to X, SK X is the index of X or the trapdoor generation key, satisfying In addition, KMC will select a random number γ for generating secure indexes and trapdoors;

[0086] Step 1.2, KMC selects a random number g > 1 and generates the key Key for the message authentication code M ; generates the hash function mht for constructing the Merkle tree; generates w hash functions for determining the position of the retrieved access data in the hash table, and generates a hash function hash to calculate the hash value of the retrieval result;

[0087] Step 1.3, KMC will send {g, Key M} to the edge server and send to the cloud server. KMC generates keys i for the data owner DO and generates keys j for the authorized user U

[0088] Step 2: The image owner obtains the key from the key management center, then extracts the image features, encrypts the image features to obtain a secure index, and uploads them to the edge server together with the encrypted image. Taking DO i as an example, its image set contains n i images Each image feature f l =(f l (1),…,f l (d)) T is d - dimensional.

[0089] Step 2.1, DO i sends a request to KMC, and KMC returns the key set through a secure channel

[0090] Step 2.2, DO i randomly selects a vector a from i and expands the dimension of the feature f l to obtain f′ l =(f l (1),…,f l (d),a i (1),…,a i (r)) T , and then uses the scrambling function Π() on the expanded feature f′l Process it to obtain a vector

[0091] Step 2.3, DO i Use an orthogonal matrix to Complete orthogonal decomposition to obtain orthogonal coefficients

[0092] Step 2.4, DO i Select a random integer noise τ l = [τ l (1), τ l (2), …, τ l (d + r)] T , and the selection range of each element of the random noise should be much smaller than the random number γ. Using the theory of fault-tolerant learning, encrypt the orthogonal coefficient y with the key l , as shown in Formula (1), to obtain the secure index I l ;

[0093]

[0094] Step 2.5, DO i Use EncK to encrypt the image m l , to obtain c l . Upload the ciphertext image and the secure index to the edge server.

[0095] Step 3: The edge server calculates the message authentication code (MAC) of the ciphertext image and the encrypted index based on the ciphertexts received from each data owner , and then sends the ciphertext and the corresponding MAC value to the cloud server, where n is the number of ciphertexts received by the ES.

[0096] Step 3.1, The ES calculates the MAC value σ l using the ciphertext image c l and the ID value id of this image l ;

[0097]

[0098] Step 3.2, The ES calculates the encrypted index l for the secure index I and then calculates the MAC value ρ l according to Formula (3);

[0099]

[0100] Step 3.3, ES sends to the cloud server.

[0101] Step 4: The cloud server re-encrypts all the received secure indexes according to the re-encryption key, and takes each re-encrypted index as a node to generate the satellite system graph index structure in the ciphertext domain.

[0102] Step 4.1, the cloud server uses the re-encryption key to re-encrypt all the received secure indexes and calculates to obtain where DO i represents the data owner to which I l belongs, and n all is the number of all the secure indexes aggregated by the cloud server. Subsequently, the cloud server calculates for each secure index, where

[0103] Step 4.2, the cloud server selects the angle for constructing the satellite system graph as α. For each re-encrypted index it calculates the distance between it and all the remaining indexes in and adds it to the list L of ;

[0104] Step 4.3, sort the distance values in L, find the closest point L[0], and add it to the neighbor node set P of ;

[0105] Step 4.4, for each index node in L calculate the angle between it and each index node in the set P and compare it with α. If this angle is greater than α, add the node to the neighbor node set P of ;

[0106] Step 4.5, construct the satellite system graph structure G according to the neighbor set P of each index node ;

[0107] Step 5: The authorized user U j obtains the key returned via the secure channel from the key management center, then extracts the feature fq of the query image to generate a secure trapdoor T, and then sends it to the cloud server.

[0108] Step 5.1, U j sends a request to the KMC and then obtains the key set returned by the KMC

[0109] Step 5.2, U j Randomly select vector a from j , expand the dimension of feature fq to obtain fq′ = (fq(1), …, fq(d), a j (1), …, a j (r)) T , and then use the scrambling function Π() to obtain vector

[0110] Step 5.3, U j Use the orthogonal matrix to perform orthogonal decomposition on to obtain the orthogonal coefficients p = (p(1), …, p(d + r)) T ;

[0111] Step 5.4, U j Select a random integer noise τ j = [τ j (1), τ j (2), …, τ j (d + r)] T , and the selection range of each element of the random noise should be much smaller than the random number γ. Use the secret key to encrypt the orthogonal coefficients p, as shown in formula (4), to obtain the secure trapdoor T, and send T to the cloud server for retrieval.

[0112]

[0113] Step 6: The cloud server uses the corresponding re - encryption key to re - encrypt the received secure trapdoor T to obtain Subsequently, calculate the distance between the re - encrypted index and the trapdoor, and search on the satellite system graph index structure to obtain the retrieval result.

[0114] Step 6.1, The cloud server uses the re - encryption key to re - encrypt the secure trapdoor T of the authorized user U j to obtain

[0115] Step 6.2, The cloud server calculates the distance dist between the index node and the re - encrypted trapdoor on the satellite system graph structure, as shown in formula (5). Using the retrieval method of the satellite system graph structure, iteratively access the neighbors of the index node and the neighbors of its neighbors to obtain k retrieval results that are very close to the re - encrypted trapdoor, and the corresponding ID values are

[0116]

[0117] Step 7: The cloud server generates Merkle trees using the MAC values of the encrypted images of the retrieval results and the MAC values of the encrypted indexes respectively, and obtains the value of the root node. Subsequently, using the improved cuckoo hash, a privacy-preserving hash table is generated for the ID information, calculated distance information, and sorting information of all data accessed in this retrieval. Then, the cloud server returns the retrieval results and the corresponding verification information.

[0118] Step 7.1, Generate a Merkle tree according to the MAC values of the encrypted images of the k retrieval results to obtain the value of the root node root ; C ;

[0119] Step 7.2, Generate a Merkle tree for the MAC values of the encrypted indexes of the k retrieval results to obtain the value of the root node root ; I ;

[0120] Step 7.3, For the data accessed by the CS during the retrieval process, according to the distance values recorded during the retrieval process the corresponding sorting values can be obtained where v is the number of accessed data. The cloud server selects a random number θ for this query to protect the retrieval distance;

[0121] Step 7.4, The CS first sets a hash table. Suppose there are B buckets and each bucket has X slots. Subsequently, drawing on the idea of cuckoo hash, a set of hash functions For each accessed data, use its sorting value sort i to calculate its storage position in the hash table Subsequently, when looking up the position, if the position of H 1 (sort i ) in the first slot is empty, store the hash value in this position. If the position is not empty, instead of using the method of cuckoo hash to kick out the existing data, look for the next hash position H 2 (sort i ), and so on until an empty position is found. If all positions in the first slot are already occupied, start looking one by one in the second slot, and so on until an empty position is found to store the hash value of this data. Store the hash values of all accessed data in the hash table to obtain the hash table It can disclose the computing amount of the cloud server during the retrieval process without disclosing the privacy information of the data accessed during the retrieval;

[0122] Step 7.5, CS generates a transformation key for the retrieval result where DO i represents the data owner to which the result data belongs;

[0123] Step 7.6, CS sends the retrieval result, proof data, and transformation key to the authorized user U j .

[0124] Step 8: After receiving the data, the authorized user U j verifies the correctness of the ciphertext image and the encrypted index according to the Merkle tree. After determining that the ciphertext is correct, the encrypted index is used to reconstruct the distance value, and then it is compared and verified with the hash table to confirm whether the calculation result of the cloud server for this data is correct. If the retrieval result is confirmed to be correct, the authorized user decrypts the ciphertext image to obtain the retrieved plaintext result.

[0125] Step 8.1, U j uses Key M to calculate the MAC values of the received image ciphertext and the encrypted index as shown in formula (6);

[0126]

[0127] Step 8.2, U j uses and mht to construct a Merkle tree, obtaining the values of two root nodes root′ C , root′ I . Subsequently, U j compares the received root node values root C , root I with the calculated root node root′ C , root′ I . If the root node values are the same, it indicates that the ciphertext image and the encrypted index are both correct, and the next verification is performed. Otherwise, the retrieval result is rejected;

[0128] Step 8.3, after determining that the encrypted index is correct, U j uses the received key to transform the trapdoor T, obtaining . Subsequently, for each returned result, U j reconstructs the distance value as shown in formula (7), obtaining the distance Next, U j Calculate the hash value

[0129]

[0130] Step 8.4, U j Use the hash function Calculate the storage location of each return result in the hash table If the data at a certain location among these locations is the same as the hash value calculated by U j It indicates that the cloud server's calculation of this data is correct. Verify each data in the retrieval result to confirm that the cloud server's distance calculation for the returned k results is correct. For multiple data, it can also be based on The sorting to determine whether the sort given by the cloud server l Is correct;

[0131] Step 8.5, in addition to the returned result data, if U j Wants to verify other accessed data, it can send the sorting sort x To the cloud server, and the cloud server will return Subsequently, U j Can use ρ x To verify the encrypted index according to Step 8.1 Whether it is correct. After confirmation, verify whether the cloud server's distance calculation result for this data is correct according to Step 8.3 and Step 8.4, and it can be judged whether the distance values of these data are smaller than the distance values of the retrieval result;

[0132] Step 8.6, the authorized user confirms that the ciphertext image of the retrieval result is correct, the server's calculation result and sorting of the data are also correct, and then U j Uses DecK to decrypt the image ciphertext To obtain the corresponding plaintext retrieval result.

[0133] On the other hand, the embodiment of the present invention also provides a verifiable privacy protection retrieval system for massive image data in the cloud environment, including the following modules:

[0134] Key and hash function generation module, used for the key management center to generate keys and the required hash functions for each participant in the verifiable retrieval system;

[0135] Secure index generation module, used for the image owner to obtain the key from the key management center, then extract the image features, encrypt the image features to obtain a secure index, and upload it to the edge server together with the encrypted image;

[0136] The MAC calculation module is used for the edge server to calculate the message authentication code MAC of the ciphertext image and the encrypted index based on the received ciphertext data, and then send the ciphertext and the corresponding MAC value to the cloud server;

[0137] The re-encryption and index structure generation module is used for the cloud server to re-encrypt all the received secure indexes according to the re-encryption key, and take each re-encrypted index as a node to generate a satellite system diagram index structure in the ciphertext domain;

[0138] The secure trapdoor generation module is used for the authorized user U j to obtain the key returned via the secure channel from the key management center, extract the features of the query image to generate a secure trapdoor T, and then send it to the cloud server;

[0139] The retrieval result acquisition module is used for the cloud server to re-encrypt the received secure trapdoor T using the corresponding re-encryption key to obtain subsequently calculate the distance between the re-encrypted index and the trapdoor, and search on the satellite system diagram index structure to obtain the retrieval result;

[0140] The verification data acquisition module is used for the cloud server to generate Merkle trees respectively using the MAC value of the ciphertext image and the MAC value of the encrypted index of the retrieval result to obtain the value of the root node; then use Cuckoo hash to generate a privacy-protected hash table for the ID information, distance information, and sorting information of the data accessed in this retrieval; then, the cloud server returns the retrieval result and the corresponding verification data;

[0141] The plaintext result acquisition module is used for the authorized user to verify the correctness of the ciphertext image and the encrypted index according to the Merkle tree. After determining that the ciphertext is correct, use the encrypted index to reconstruct the distance value, and then compare and verify it with the hash table to confirm whether the calculation result of the cloud server for this data is correct; if it is confirmed that the retrieval result is correct, the authorized user decrypts the ciphertext image to obtain the retrieved plaintext result.

[0142] The above content is the specific implementation manner of the present invention. In order to further verify the performance of the method, the retrieval accuracy, retrieval time, and verification time of the present invention are tested on the Corel10k dataset, and compared with the SVMIS scheme, Vpsl scheme, and VFIRM scheme. The Corel10k dataset contains 10,000 images, the feature dimension of each image extracted by the neural network is d = 100, and the size of each image is 192 * 128.

[0143] When generating the secure index and trapdoor, parameters r = 100, γ = 1000, and α = 45° are selected. Taking the result obtained by linearly retrieving the plaintext features as a benchmark and using precision@k to measure the retrieval accuracy, it can be obtained that when the k value increases from 10 to 300, the change in retrieval accuracy is as shown in Figure 2 (a). The retrieval accuracy of the present invention is very close to the result of linear retrieval and hardly fluctuates as the number k of retrieval results increases.

[0144] The time consumed during the retrieval process is as shown in Figure 2 (b). The present invention uses the satellite system diagram as the index structure, greatly reducing the time consumption of retrieval. As the number of returned images increases, the retrieval time gradually increases and tends to be flat, significantly lower than other solutions.

[0145] The verification phase includes the verification of the correctness of the returned images and the verification of the distance values calculated by the cloud service. Table 1 shows the time required for the present invention and other solutions that support the verification of image correctness to generate the relevant verification data on the cloud server and for the user to perform the verification. Whether it is the process of generating the verification data or the process of the user verifying the correctness of the images, the time required by the present invention is the lowest, with very high efficiency.

[0146] Table 1. Image correctness verification time (ms)

[0147]

[0148] Table 2 shows the time required for the present invention and other solutions that support the verification of the distance calculated by the cloud server during the process of generating the proof data and for the user to perform the verification. The present invention does not generate an excessive computational burden during the verification process and can efficiently verify the distance values calculated by the cloud server.

[0149] Table 2. Cloud service calculated distance value verification time (ms)

[0150]

[0151] The above content is a further detailed description of the present invention in combination with the best implementation solutions. It cannot be determined that the specific implementation of the present invention is limited only to these descriptions. Those skilled in the art should understand that various modifications can be made in details without departing from the scope defined by the appended claims, and all should be regarded as belonging to the protection scope of the present invention.

Claims

1. A verifiable privacy - protected retrieval method for massive image data in a cloud environment, characterized in that, it includes the following steps: Step 1, the key management center generates keys and required hash functions for each participant in the verifiable retrieval system; Step 2, the image owner obtains keys from the key management center, then extracts image features, encrypts the image features to obtain a secure index, and uploads the encrypted image and the secure index to the edge server together; Step 3, the edge server calculates the message authentication code MAC of the encrypted image and the encrypted index according to the received ciphertext data, and then sends the ciphertext and the corresponding MAC value to the cloud server; Step 4, the cloud server re-encrypts all the received security indexes according to the re-encryption key, and takes each re-encrypted index as a node to generate a satellite system graph index structure in the ciphertext domain; Step 5, authorize user U j Obtain the key returned via the secure channel from the key management center, extract the features of the query image to generate a security trapdoor T, and then send it to the cloud server; Step 6, the cloud server uses the corresponding re-encryption key to re-encrypt the received security trapdoor T, and obtains Subsequently, calculate the distance between the re-encrypted index and the trapdoor, and search on the satellite system diagram index structure to obtain the retrieval result; Step 7, the cloud server uses the MAC value of the encrypted image of the retrieval result and the MAC value of the encrypted index to generate Merkle trees respectively, and obtains the root node values; Subsequently, use Cuckoo hash to generate a privacy - protected hash table for the ID information, distance information, and sorting information of the data accessed in this retrieval; then, the cloud server returns the retrieval result and the corresponding verification data; Step 8, the authorized user verifies the correctness of the encrypted image and the encrypted index according to the Merkle tree. After determining that the ciphertext is correct, use the encrypted index to reconstruct the distance value, and then compare it with the hash table to verify whether the calculation result of the cloud server for this data is correct; if it is confirmed that the retrieval result is correct, the authorized user decrypts the encrypted image to obtain the plaintext result of the retrieval.

2. The verifiable privacy - protected retrieval method for massive image data in a cloud environment according to claim 1, characterized in that: The implementation method of Step 1 is as follows; Step 1.1, the key management center selects an encryption key EncK and a decryption key DecK for the image; generate an orthogonal matrix r represents the dimension of each vector in the orthogonal matrix, and the data range of its vectors is much smaller than the data range of the image features. Divide the orthogonal vectors in into two non - overlapping sets and for feature dimension expansion; Select the scrambling function Π() to protect features; generate an orthogonal matrix For orthogonal decomposition, where d is the feature dimension; Generate an orthogonal matrix for generating a secure index and a trapdoor; subsequently, for any data owner DO i or authorized user U j , where DO i represents the i-th data owner and U j represents the j-th user, the KMC will decompose the matrix to obtain TK X and SK X , where X = DO i or U j , TK X is the re-encryption key corresponding to X, and SK X is the index or trapdoor generation key of X, satisfying In addition, the KMC will select a random number γ for generating a secure index and a trapdoor; Step 1.2, KMC selects a random number g > 1 and generates a key Key for the message authentication code M ; generates a hash function mht for constructing the Merkle tree; Generate w hash functions For determining the position of the retrieved access data in the hash table, generate a hash function hash to calculate the hash value of the retrieval result; Step 1.3, KMC will send {g,Key M} to the edge server and send to the cloud server; KMC generates a key i for the data owner DO and generates a key j for the authorized user U 3. The verifiable privacy - protected retrieval method for massive image data in a cloud environment according to claim 1, characterized in that: The implementation method of Step 2 is as follows, For a certain data owner DO i , whose image set contains n i images Each image feature f l =(f l (1), …, f l (d)) T is d-dimensional; Step 2.1, DO i Send a request to the KMC, and the KMC returns a set of keys through a secure channel Step 2.2, DO i Randomly select a vector a from i to perform dimensional expansion on the feature f l to obtain f' l =(f l (1), …, f l (d), a i (1), …, a i (r)) T , and then use the scrambling function Π() to obtain a vector Step 2.3, DO i Use an orthogonal matrix to perform orthogonal decomposition to obtain orthogonal coefficients Step 2.4, DO i Select a random integer noise τ l = [τ l (1), τ l (2), …, τ l (d + r)] T , the data range of each element of the random noise should be much smaller than the random number γ. Using the theory of fault-tolerant learning, encrypt the orthogonal coefficient y with the key l , as shown in formula (1), to obtain the secure index I l ; Step 2.5, DO i Use EncK to encrypt the image m l to obtain c l and upload the encrypted image along with the security index to the edge server.

4. The verifiable privacy - protected retrieval method for massive image data in a cloud environment according to claim 1, characterized in that: The implementation method of Step 3 is as follows, The edge server receives the ciphertexts sent by each data owner where n is the number of ciphertexts received by the ES; Step 3.1, ES calculates the MAC value σ l of the ciphertext image c l using the ciphertext image c l and the ID value id l of this image; σ l = MAC(Dey M , id l ||c l ) (2) Step 3.2, ES is the security index I l Calculate the encrypted index Subsequently, calculate the MAC value ρ according to formula (3) l ; Step 3.3, ES will send it to the cloud server.

5. The verifiable privacy - protected retrieval method for massive image data in a cloud environment according to claim 3, characterized in that: The implementation method of Step 4 is as follows, Step 4.1, the cloud server uses the re-encryption key to re-encrypt all the received secure indexes I l and calculates to obtain where DO i represents the data owner to which I l belongs, l ∈ [1, n all , and n all is the number of all the secure indexes aggregated by the cloud server; subsequently, the cloud server calculates for each secure index, where Step 4.2, the cloud server selects the angle for constructing the satellite system diagram as α, and for each re-encrypted index calculate it and all the remaining indexes in the distance between them, and add it to the list L of Step 4.3, sort the distance values in L, find the point L[0] with the closest distance, and add it to the set P of neighbor nodes; Step 4.4, for all the index nodes in L calculate the angle between it and each index node in the set P and compare its size with α. If this angle is greater than α, then add the node to the neighbor node set P of add ; Step 4.5, according to the neighbor set P of each index node to construct the satellite system graph structure G.

6. The verifiable privacy - protected retrieval method for massive image data in a cloud environment according to claim 1, characterized in that: The implementation method of Step 5 is as follows, For authorized user U j , the feature of the query image is fq; Step 5.1, U j Send a request to the KMC and subsequently obtain the set of keys returned by the KMC Step 5.2, U j Randomly select vector a from j , expand the dimension of the feature fq to obtain fq′ = (fq(1), …, fq(d), a j (1), …, a j (r)) T , and then use the scrambling function Π() to obtain the vector Step 5.3, U j Use an orthogonal matrix to perform orthogonal decomposition to obtain orthogonal coefficients p = (p(1), …, p(d + r)) T ; Step 5.4, U j Select a random integer noise τ j = [τ j (1), τ j (2), …, τ j (d + r)] T , the selection range of each element of the random noise should be much smaller than the random number γ, and use the key to encrypt the orthogonal coefficient p, as shown in formula (4), to obtain the security trapdoor T, and send T to the cloud server for retrieval:

7. The verifiable privacy - protected retrieval method for massive image data in a cloud environment according to claim 1, characterized in that: The implementation method of Step 6 is as follows, Step 6.1, the cloud server uses the re-encryption key to re-encrypt the security trapdoor T of the authorized user U j and obtains Step 6.2, the cloud server calculates the distance dist between the index node and the re-encryption trapdoor on the satellite system graph structure, as shown in formula (5). Using the retrieval method of the satellite system graph structure, iteratively access the neighbors of the index node and the neighbor nodes of its neighbors to obtain k retrieval results that are very close to the re-encryption trapdoor, and the corresponding ID values are used, and iteratively access the neighbors of the index node and the neighbor nodes of its neighbors to obtain k retrieval results that are very close to the re-encryption trapdoor, and the corresponding ID values are 8. The verifiable privacy - protected retrieval method for massive image data in a cloud environment according to claim 1, characterized in that: The implementation method of Step 7 is as follows, The cloud server generates verification data according to the retrieval result and the nodes accessed during the retrieval; Step 7.1, generate a Merkle tree based on the MAC values of the ciphertext images of the k retrieval results to obtain the value root of the root node C ;​ Step 7.2, the encrypted index MAC values of the k retrieval results Generate a Merkle tree Obtain the value root of the root node I ; Step 7.3, for the data accessed by CS during the retrieval process, according to the distance values recorded during the retrieval process the corresponding sorting values can be obtained where v is the number of accessed data; the cloud server selects a random number θ for this query to protect the retrieval distance; Step 7.

4. The CS first sets up a hash table. Suppose there are B buckets and each bucket has X slots. Subsequently, drawing on the idea of cuckoo hashing, a set of hash functions is used For each accessed data, its sorting value sort is used i to calculate its storage position in the hash table Subsequently, when looking up the position, if the position of H 1 (sort i ) in the first slot is empty, the hash value is stored in this position; if the position is not empty, instead of using the method of cuckoo hashing to kick out the existing data, the next hash position H 2 (sort i ) is looked up, and so on, until an empty position is found; if all positions in the first slot are already occupied by data, the second slot is searched one by one, and so on, until an empty position is found to store the hash value of the data; the hash values of all accessed data are stored in the hash table to obtain the hash table which can expose the computational amount of the cloud server during the retrieval process without revealing the privacy information of the accessed data during the retrieval; Step 7.5, CS generates a transformation key for the retrieval result where DO i represents the data owner to which the result data belongs; Step 7.6, the CS sends the retrieval result, the proof data, and the transformation key to the authorized user U j .

9. The verifiable privacy - protected retrieval method for massive image data in a cloud environment according to claim 1, characterized in that: The implementation method of Step 8 is as follows, Authorized user U j After receiving the data, verify the correctness of the ciphertext and the correctness of the cloud server distance calculation result respectively; Step 8.1, U j Use Key M to calculate the MAC values of the received image ciphertext and the encrypted index as shown in formula (6); Step 8.2, U j Use and mht to construct a Merkle tree, obtaining the values root′ C , root′ I; Subsequently, U j compares the received root node value root C , root I with the calculated root node root′ C , root′ I . If the root node values are the same, it indicates that the ciphertext image and the encrypted index are both correct, and the next verification is performed; otherwise, the retrieval result is rejected. Step 8.3, determine the encrypted index After being correct, U j Use the received key Transform the trapdoor T to obtain Subsequently, for each returned result, U j Reconstruct the distance value as shown in formula (7) to obtain the distance Then, U j Calculate the hash value Step 8.4, U j Use a hash function Calculate the storage location of each return result in the hash table If the data at a certain location among these locations is the same as the hash value calculated by U j It indicates that the cloud server's calculation of this data is correct. Verify each data in the retrieval result to confirm that the cloud server's distance calculation for the returned k results is correct; for multiple data, then according to The sorting of judge whether the sort given by the cloud server l Is correct; Step 8.5, except for the returned result data, if U j wants to verify other accessed data, send the sorting sort x to the cloud server, and the cloud server will return Subsequently, U j uses ρ x , and according to Step 8.1, verifies whether the encrypted index is correct. After confirmation, according to Step 8.3 and Step 8.4, verify whether the distance calculation result of the cloud server for this data is correct, and determine whether the distance values of these data are smaller than the distance value of the retrieval result; Step 8.6, the authorized user confirms that the ciphertext image of the retrieval result is correct, and the server's calculation result and sorting of the data are also correct. Subsequently, U j Use DecK to decrypt the image ciphertext Obtain the corresponding plaintext retrieval result.

10. A verifiable privacy - protected retrieval system for massive image data in a cloud environment, characterized in that, it includes the following modules: A key and hash function generation module, which is used for the key management center to generate keys and required hash functions for each participant in the verifiable retrieval system; A security index generation module, which is used for the image owner to obtain a key from the key management center, then extract image features, encrypt the image features to obtain a security index, and upload it together with the encrypted image to the edge server; A MAC calculation module, which is used for the edge server to calculate the message authentication code MAC of the ciphertext image and the encrypted index according to the received ciphertext data, and then send the ciphertext and the corresponding MAC value to the cloud server; The re-encryption and index structure generation module is used for the cloud server to re-encrypt all received secure indexes according to the re-encryption key, and generate a satellite system graph index structure for the ciphertext domain with each re-encrypted index as a node; A security trapdoor generation module, used for authorized user U j obtains the key returned via a secure channel from the key management center, extracts the features of the query image to generate a security trapdoor T, and then sends it to the cloud server; The retrieval result acquisition module is used for the cloud server to re-encrypt the received security trapdoor T using the corresponding re-encryption key, and obtain Subsequently, calculate the distance between the re-encrypted index and the trapdoor, and search on the satellite system diagram index structure to obtain the retrieval result; A verification data acquisition module, which is used for the cloud server to generate Merkle trees using the MAC values of the ciphertext image and the encrypted index of the retrieval result respectively to obtain the values of the root nodes; Subsequently, use Cuckoo hashing to generate a privacy-protected hash table for the ID information, distance information, and sorting information of the data already accessed in this retrieval; then, the cloud server returns the retrieval result and the corresponding verification data; A plaintext result acquisition module, which is used for the authorized user to verify the correctness of the ciphertext image and the encrypted index according to the Merkle tree. After determining that the ciphertext is correct, use the encrypted index to reconstruct the distance value, and then compare and verify it with the hash table to confirm whether the calculation result of the cloud server for this data is correct; if it is confirmed that the retrieval result is correct, the authorized user decrypts the ciphertext image to obtain the retrieved plaintext result.

Citation Information

Patent Citations

  • Image security retrieval method based on secret sharing in cloud environment

    CN111541679A

  • Multi-source image security retrieval method suitable for marginal environment

    CN114996722A