Authenticated multi-keyword searchable encryption method, device, system and storage medium
Patent Information
- Application Number
- CN202311295926.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-10-09
- Publication Date
- 2026-09-25
- Estimated Expiration
- 2043-10-09
AI Technical Summary
[0006]有鉴于此,本发明提供了一种认证多关键词可搜索加密方法、装置、系统、计算机设备及存储介质,其在基于认证的公钥可搜索加密的基础上,可以解决现有技术中好奇的发送者可能对陷门的所包含关键词猜测的问题,同时实现灵活的多关键词搜索
[0062]1、本发明实现了一种支持联合关键词搜索的公钥可搜索加密方案,并且方案在构造上不再依靠关键词的位置索引去实现多关键词搜索,使用了n个点构造多项式的方式更灵活地实现多关键词搜索,并且在加密算法保持了较高的效率。
Smart Images

Figure CN117560171B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to an authentication method, apparatus, system, and storage medium with multi-keyword searchable encryption, belonging to the field of information security. Background Technology
[0002] With the rapid development of cloud computing technology, massive amounts of data are stored in the cloud. The cloud environment, with its powerful computing capabilities and ample storage space, has brought tremendous convenience to various industries such as education, healthcare, and the Internet of Things. However, cloud servers may tamper with, delete, or corrupt data, and they are vulnerable to hacker attacks. Data security and privacy have become major concerns. To protect data security and privacy, data owners can encrypt their data before uploading it to cloud servers. However, encrypting data presents a significant challenge for searching. Users wanting to access data in the cloud must download it entirely to their local machine and then decrypt it to find the desired data, which is clearly inefficient. Therefore, exploring efficient file searching in the cloud while maintaining data privacy and security remains a compelling research topic.
[0003] To address the challenge of efficiently searching encrypted files, Boneh et al. proposed the concept of public-key keyword searchable encryption in 2004, cleverly combining keyword search functionality with public-key encryption. In this framework, the sender extracts keywords from the file, encrypts and uploads them to the cloud as an index for the encrypted file. The receiver can use the keywords to generate a trapdoor, and then the cloud server tests whether there is ciphertext matching the trapdoor. If a match is found, the corresponding encrypted file is returned. However, the keyword space used in the real world is limited, which allows adversaries to guess the keywords contained in the document—a phenomenon known as keyword guessing attacks. Specifically, an adversary will try to generate ciphertext using every possible keyword and test it using the provided trapdoor. The adversary can infer which keyword is encapsulated in the trapdoor based on the test results. Therefore, public-key keyword searchable encryption frameworks inevitably face the challenge of keyword guessing from both external and internal adversaries.
[0004] The main reasons why raw public-key searchable encryption is vulnerable to keyword guessing attacks are as follows: first, the channel through which the trapdoor or keyword ciphertext is transmitted is public; second, anyone can generate the ciphertext; and third, anyone can test it. To address this issue, Huang and Li proposed authentication-based public-key searchable encryption, which not only encrypts the keywords but also authenticates the sender and receiver. Specifically, the sender's private key is embedded in the encryption process to authenticate their identity. In this way, even if the keyword ciphertext is transmitted over a public channel, it ensures that only authenticated legitimate senders and receivers can successfully decrypt and search the data, effectively resisting keyword guessing attacks. However, this approach still has vulnerabilities because the designers of authentication-based public-key searchable encryption only considered adversaries within the internal server and external third-party users, neglecting the possibility that curious senders might guess the keywords contained in the receiver's trapdoor, thus compromising the privacy of the trapdoor.
[0005] In addition, the invention patent application with publication number CN108599937A discloses a public key encryption method with multiple searchable keywords, which solves the technical problem of complex ciphertext keyword calculation process in existing public key encryption methods with multiple searchable keywords. However, this technology requires additional position indexes to identify keywords, which limits the flexibility of search when actually matching keywords. Summary of the Invention
[0006] In view of this, the present invention provides a method, apparatus, system, computer device and storage medium for authentication multi-key searchable encryption, which, based on authentication-based public key searchable encryption, can solve the problem in the prior art that curious senders may guess the keywords contained in the trapdoor, while realizing flexible multi-key search.
[0007] The first objective of this invention is to provide an authentication method for multi-keyword searchable encryption.
[0008] The second objective of this invention is to provide an authentication multi-keyword searchable encryption device.
[0009] The third objective of this invention is to provide an authentication multi-keyword searchable encryption system.
[0010] The fourth object of the present invention is to provide a computer device.
[0011] A fifth objective of this invention is to provide a computer-readable storage medium.
[0012] The first objective of this invention is achieved by adopting the following technical solution:
[0013] A method for authenticating multi-keyword searchable encryption, the method comprising:
[0014] Generate system-wide parameters based on security parameters;
[0015] The system global parameters are sent to the sender, receiver, and server so that the sender, receiver, and server can generate corresponding public-private key pairs based on the system global parameters. The public-private key pair includes public key and private key parameters.
[0016] The receiver's public key is sent to the sender so that the sender can generate a ciphertext message based on the system's global parameters, the sender's private key, the receiver's public key, the set of multiple plaintext keywords input by the sender, and the current system time.
[0017] The sender's public key and the server's public key are sent to the receiver so that the receiver can generate a trapdoor message based on the system's global parameters, the receiver's private key, the sender's public key, the server's public key, the set of multiple plaintext keywords entered by the receiver, and the current system time.
[0018] The encrypted message and the trapdoor message are uploaded to the server, so that the server can match the encrypted message and the trapdoor message with the server's private key. If the match is successful, the matched encrypted message is sent to the receiver for decryption.
[0019] Furthermore, the generation of system global parameters based on security parameters specifically includes:
[0020] Given a security parameter λ and a bilinear group Among them G1 and G T It is a multiplicative cyclic group of order p prime numbers, and g is a generator of the group G1. It satisfies G1×G1→G T The bilinear mapping relationship;
[0021] Selecting l1 as the maximum number of keywords in the ciphertext, we obtain three hash functions H1: H2: {0,1} * →G1, H3:
[0022] Based on the security parameters and hash function, output the system global parameters.
[0023] Furthermore, the step of generating corresponding public-private key pairs based on system global parameters specifically includes:
[0024] Based on the system global parameter gp, generate the sender's public and private key pair (sk). S =α1, ), the recipient's public and private key pair (sk R =α2, ) and the server's public / private key pair (sk V =v,pk V =g v ).
[0025] Furthermore, the process of generating a encrypted message based on system global parameters, the sender's private key, the receiver's public key, a set of multiple plaintext keywords input by the sender, and the current system time specifically includes:
[0026] Select random number
[0027] Generate a set using the current system time t using the 0-encoding algorithm. For each The time-encrypted block is calculated based on the hash function H2 of the system's global parameters and the random number r1.
[0028] For i∈[1,l1], based on the hash function H1 of the system's global parameters and the set of plaintext keywords input by the sender... sender's private key sk S The receiver's public key pk R ,calculate
[0029] Using random numbers r1, r2 and The polynomial f(x) of order l1+1 is established as follows:
[0030]
[0031] Extract the polynomial coefficients as the first part of the ciphertext.
[0032] Based on time ciphertext blocks Part One Cipher Output the encrypted message based on the current system time t.
[0033] Furthermore, the step of generating a trapdoor message based on system global parameters, the receiver's private key, the sender's public key, the server's public key, a set of multiple plaintext keywords input by the receiver, and the current system time specifically includes:
[0034] Select random number
[0035] Generate a set using the current system time t′ using the 1-encoding algorithm. For each Calculate the time trapdoor block based on the hash function H2 of the system global parameters and the random number β
[0036] For j∈[1,l2],i∈[0,l1+1], according to the hash function H1 of the system global parameters and the plaintext keyword set input by the receiver the receiver's private key sk R and the sender's public key pk S , calculate Using h j to calculate
[0037] For i∈[0,l1+1], according to the generator g of the system global parameters, the hash function H3, and the server's public key pk V , random number and the random number β, calculate the first part of the trapdoor and the second part of the trapdoor
[0038] According to the time trapdoor block the first part of the trapdoor TD 1,i , the second part of the trapdoor TD 2,i and the current system time t′, output the trapdoor message TD=({TD t},{TD1},{TD2},l2,t′).
[0039] Further, said matching the ciphertext message with the trapdoor message according to the server's private key specifically comprises:
[0040] Split the ciphertext message CT into and split the trapdoor message TD into ({TD t′},{TD1},{TD2},l2,t′);
[0041] If the system time t<t′, then there exists an element where H2(t′ j )=H2(t i );
[0042] For i∈[0,l1+1], calculate
[0043] For i∈[0,l1+1], calculate
[0044] If there exists then infer that Q∈W, where Q is the keyword set embedded in the trapdoor message and W is the keyword set embedded in the ciphertext message.
[0045] The second objective of this invention is achieved by adopting the following technical solution:
[0046] An authentication multi-keyword searchable encryption device, the device comprising:
[0047] The system global parameter generation module is used to generate system global parameters based on security parameters;
[0048] The public-private key pair generation module is used to send system global parameters to the sender, receiver, and server so that the sender, receiver, and server can generate corresponding public-private key pairs based on the system global parameters. The public-private key pair includes a public key and a private key parameter.
[0049] The encrypted message generation module is used to send the recipient's public key to the sender, so that the sender can generate an encrypted message based on the system global parameters, the sender's private key, the recipient's public key, a set of multiple plaintext keywords input by the sender, and the current system time.
[0050] The trapdoor message generation module is used to send the sender's public key and the server's public key to the receiver, so that the receiver can generate a trapdoor message based on the system global parameters, the receiver's private key, the sender's public key, the server's public key, a set of multiple plaintext keywords input by the receiver, and the current system time.
[0051] The matching module is used to upload ciphertext messages and trapdoor messages to the server, so that the server can match the ciphertext messages and trapdoor messages according to the server's private key. If the match is successful, the matched ciphertext message is sent to the receiver for decryption.
[0052] The third objective of this invention is achieved by adopting the following technical solution:
[0053] An authentication multi-keyword searchable encryption system is provided, the system comprising a sender end, a receiver end, and a server, the server being connected to the sender end and the receiver end respectively;
[0054] The sender end is used to obtain the receiver's public key and the current system time, input multiple plaintext keyword sets, generate ciphertext messages based on system global parameters, the sender's private key, the receiver's public key, multiple plaintext keyword sets and the current system time, and upload the ciphertext messages to the server;
[0055] The receiver is used to obtain the sender's public key and the current system time, input multiple plaintext keyword sets, generate a trapdoor message based on the system global parameters, the receiver's private key, the sender's public key, the server's public key, multiple plaintext keyword sets, and the current system time, and upload the trapdoor message to the server.
[0056] The server is used to match the ciphertext message and the trapdoor message according to the server's private key. If the match is successful, the ciphertext message is sent to the receiver for decryption.
[0057] The fourth objective of this invention is achieved by adopting the following technical solution:
[0058] A computer device includes a processor and a memory for storing a processor-executable program, wherein when the processor executes the program stored in the memory, it implements the above-described authentication multi-keyword searchable encryption method.
[0059] The fifth objective of this invention is achieved by adopting the following technical solution:
[0060] A computer-readable storage medium storing a program that, when executed by a processor, implements the above-described authentication multi-keyword searchable encryption method.
[0061] The present invention has the following advantages over the prior art:
[0062] 1. This invention implements a public-key searchable encryption scheme that supports joint keyword search. The scheme no longer relies on the position index of keywords to achieve multi-keyword search in its construction. Instead, it uses a polynomial construction method with n points to achieve multi-keyword search more flexibly, while maintaining high efficiency in the encryption algorithm.
[0063] 2. This invention effectively resists keyword guessing attacks launched by senders both offline and online. Because a test server is specified during the trapdoor generation process, senders cannot test the intercepted trapdoors, thus limiting offline keyword guessing attacks. Since both the trapdoor generation and ciphertext generation processes incorporate time, the server will successfully match the intercepted trapdoors with the newly generated ciphertext, preventing senders from using the server's capabilities for online keyword guessing.
[0064] 3. This invention sends system-wide parameters to the sender, receiver, and server. The sender, receiver, and server then generate corresponding public-private key pairs based on these parameters. This enables the system to have authentication capabilities and access control functionality based on key negotiation between the users. Furthermore, both the sender and receiver have their own public keys, which can be categorized to some extent, reducing the server's search workload. Attached Figure Description
[0065] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the structures shown in these drawings without creative effort.
[0066] Figure 1 This is a structural block diagram of the multi-keyword searchable encryption system for authentication according to Embodiment 1 of the present invention.
[0067] Figure 2 This is a flowchart of the multi-keyword searchable encryption method for authentication according to Embodiment 1 of the present invention.
[0068] Figure 3 This is a structural block diagram of the authentication multi-keyword searchable encryption device of Embodiment 2 of the present invention.
[0069] Figure 4 This is a structural block diagram of the computer device according to Embodiment 3 of the present invention. Detailed Implementation
[0070] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are some embodiments of the present invention, but not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0071] Example 1:
[0072] like Figure 1 As shown, this embodiment provides an authenticated multi-keyword searchable encryption system. The system includes a sender, a receiver, and a server. The server is a cloud server, and both the sender and receiver are user terminals. The server is connected to both the sender and receiver, and can resist sender keyword guessing attacks. The specific implementation process of this authenticated multi-keyword searchable encryption system is as follows:
[0073] (1) System initialization
[0074] Given a security parameter λ and a bilinear group Among them G1 and G T It is a multiplicative cyclic group of order p prime numbers, and g is a generator of the group G1. It satisfies G1×G1→G T The bilinear mapping relationship.
[0075] Selecting l1 as the maximum number of keywords in the ciphertext, we obtain three hash functions H1: H2: {0,1} * →G1, H3:
[0076] Based on the security parameter λ and the hash function, output the system global parameters.
[0077] (2) Generate key
[0078] The sender, receiver, and server generate corresponding public-private key pairs based on the system global parameter gp. Each public-private key pair includes a public key and a private key parameter, i.e., they generate the sender's public-private key pair (sk). S =α1, ), the recipient's public and private key pair (sk R =α2, ) and the server's public / private key pair (sk V =v,pk V =g v ).
[0079] (3) Ciphertext generation
[0080] The ciphertext generation process is completed by the sender, who uses the system's global parameter gp and the sender's private key pk. S =α1, the receiver's public key A set of multiple plaintext keywords input by the sender In addition to the current system time t, a ciphertext message is generated, specifically including:
[0081] Step 1: Select random numbers
[0082] The second step is to generate a set using the current system time t using the 0 encoding algorithm. For each The time-encrypted block is calculated based on the hash function H2 of the system's global parameters and the random number r1.
[0083] Third step: For i∈[1,l1], based on the hash function H1 of the system's global parameters and the set of plaintext keywords input by the sender... sender's private key sk S The receiver's public key pk R ,calculate
[0084] Step 4: Use random numbers r1, r2, and The polynomial f(x) of order l1+1 is established as follows:
[0085]
[0086] Step 5: Extract the polynomial coefficients as the first part of the ciphertext.
[0087] Step 6: Based on the time-encrypted block Part One Cipher Output the encrypted message based on the current system time t.
[0088] (4) Trapdoor generation
[0089] The trapdoor generation process is completed by the receiver, which uses the system's global parameter gp and the receiver's private key sk. R =α2, the sender's public key server public key PK V =g v A set of multiple plaintext keywords input by the receiver And the current system time t′, generate a trapdoor message, specifically including:
[0090] Step 1: Select random numbers
[0091] The second step is to generate a set using the current system time t′ with a 1-encoding algorithm. For each The time trapdoor is calculated based on the hash function H2 and the random number β of the system's global parameters.
[0092] Step 3: For j∈[1,l2], i∈[0,l1+1], based on the hash function H1 of the system's global parameters and the set of plaintext keywords input by the receiver... The recipient's private key sk R PK with the sender's public key S ,calculate Using h j calculate
[0093] Step 4: For i∈[0,l1+1], based on the generator g of the system's global parameters, the hash function H3, and the server's public key pk... V Random numbers Calculate the first part of the trapdoor using a random number β. Second part of the trapdoor
[0094] Step 5: Based on the time trap block Part 1: Trapdoor TD 1,i, Part Two Trapdoor TD 2,i and the current system time t′, output the trapdoor message TD=({TD t},{TD1},{TD2},l2,t′).
[0095] (5) Matching Test
[0096] The matching test process is completed by the server. According to the server's private key sk V =v, the ciphertext message and the trapdoor message TD=({TD t},{TD1},{TD2},l2,t′) are matched, which specifically includes:
[0097] Step 1: Split the ciphertext message CT into and split the trapdoor message TD into ({TD t′},{TD1},{TD2},l2,t′);
[0098] Step 2: If the system time t<t′, there exists an element where H2(t′ j )=H2(t i ); otherwise, return 0 directly;
[0099] Step 3: For i∈[0,l1+1], calculate
[0100] Step 4: For i∈[0,l1+1], calculate
[0101] Step 5: If there exists then infer Q∈W, where Q is the keyword set embedded in the trapdoor message and W is the keyword set embedded in the ciphertext message; in this case, the matching is successful, return 1; otherwise, return 0.
[0102] If the matching is successful, send the successfully matched ciphertext message to the receiver for decryption.
[0103] As shown in Figure 2 , this embodiment provides an authenticated multi-keyword searchable encryption method, which is mainly implemented through the above steps (1) to (5), and the specific description is as follows:
[0104] S201: Generate global system parameters according to security parameters.
[0105] S202: Send the global system parameters to the sender, the receiver and the server, so that the sender, the receiver and the server generate corresponding public-private key pairs according to the global system parameters.
[0106] S203. Send the receiver's public key to the sender so that the sender can generate a ciphertext message based on the system global parameters, the sender's private key, the receiver's public key, the set of multiple plaintext keywords input by the sender, and the current system time.
[0107] S204. Send the sender's public key and the server's public key to the receiver so that the receiver can generate a trapdoor message based on the system global parameters, the receiver's private key, the sender's public key, the server's public key, the set of multiple plaintext keywords input by the receiver, and the current system time.
[0108] S205. Upload the ciphertext message and the trapdoor message to the server so that the server can match the ciphertext message and the trapdoor message according to the server's private key. If the match is successful, the ciphertext message that has been matched is sent to the receiver for decryption.
[0109] It should be noted that although the method operations of the above embodiments are described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. On the contrary, the order of execution of the described steps may be changed. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.
[0110] Example 2:
[0111] like Figure 3 As shown, this embodiment provides an authentication multi-keyword searchable encryption device, which includes an acquisition module 301, a ciphertext generation module 302, a key generation module 303, an authorization trapdoor generation module 304, and a search module 305. The specific functions of each module are as follows:
[0112] The system global parameter generation module 301 is used to generate system global parameters based on security parameters;
[0113] The public-private key pair generation module 302 is used to send system global parameters to the sender, receiver and server so that the sender, receiver and server can generate corresponding public-private key pairs according to the system global parameters. The public-private key pair includes a public key and a private key parameter.
[0114] The encrypted message generation module 303 is used to send the receiver's public key to the sender so that the sender can generate an encrypted message based on the system global parameters, the sender's private key, the receiver's public key, the set of multiple plaintext keywords input by the sender, and the current system time.
[0115] The trapdoor message generation module 304 is used to send the sender's public key and the server's public key to the receiver so that the receiver can generate a trapdoor message based on the system global parameters, the receiver's private key, the sender's public key, the server's public key, the set of multiple plaintext keywords input by the receiver, and the current system time.
[0116] The matching module 305 is used to upload the ciphertext message and the trapdoor message to the server, so that the server can match the ciphertext message and the trapdoor message according to the server's private key. If the match is successful, the successfully matched ciphertext message is sent to the receiver for decryption.
[0117] It should be noted that the device provided in the above embodiments is only an example of the division of the above functional modules. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure can be divided into different functional modules to complete all or part of the functions described above.
[0118] Example 3:
[0119] This embodiment provides a computer device, such as... Figure 4 As shown, the processor 402, memory, input device 403, display device 404, and network interface 405 are connected via system bus 401. The processor provides computing and control capabilities. The memory includes a non-volatile storage medium 406 and internal memory 407. The non-volatile storage medium 406 stores the operating system, computer programs, and database. The internal memory 407 provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. When the processor 402 executes the computer programs stored in the memory, it implements the authentication multi-keyword searchable encryption method of Embodiment 1 described above, as follows:
[0120] Generate system-wide parameters based on security parameters;
[0121] The system global parameters are sent to the sender, receiver, and server so that the sender, receiver, and server can generate corresponding public-private key pairs based on the system global parameters. The public-private key pair includes public key and private key parameters.
[0122] The receiver's public key is sent to the sender so that the sender can generate a ciphertext message based on the system's global parameters, the sender's private key, the receiver's public key, the set of multiple plaintext keywords input by the sender, and the current system time.
[0123] The sender's public key and the server's public key are sent to the receiver so that the receiver can generate a trapdoor message based on the system's global parameters, the receiver's private key, the sender's public key, the server's public key, the set of multiple plaintext keywords entered by the receiver, and the current system time.
[0124] The encrypted message and the trapdoor message are uploaded to the server, so that the server can match the encrypted message and the trapdoor message with the server's private key. If the match is successful, the matched encrypted message is sent to the receiver for decryption.
[0125] Example 4:
[0126] This embodiment provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it implements the multi-keyword searchable encryption method of Embodiment 1 above, as follows:
[0127] Generate system-wide parameters based on security parameters;
[0128] The system global parameters are sent to the sender, receiver, and server so that the sender, receiver, and server can generate corresponding public-private key pairs based on the system global parameters. The public-private key pair includes public key and private key parameters.
[0129] The receiver's public key is sent to the sender so that the sender can generate a ciphertext message based on the system's global parameters, the sender's private key, the receiver's public key, the set of multiple plaintext keywords input by the sender, and the current system time.
[0130] The sender's public key and the server's public key are sent to the receiver so that the receiver can generate a trapdoor message based on the system's global parameters, the receiver's private key, the sender's public key, the server's public key, the set of multiple plaintext keywords entered by the receiver, and the current system time.
[0131] The encrypted message and the trapdoor message are uploaded to the server, so that the server can match the encrypted message and the trapdoor message with the server's private key. If the match is successful, the matched encrypted message is sent to the receiver for decryption.
[0132] The computer-readable storage medium of this embodiment may be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof.
[0133] In summary, this invention implements a public-key searchable encryption scheme that supports joint keyword search. The scheme no longer relies on keyword position indexes for multi-keyword search; instead, it uses an n-point polynomial construction method for more flexible multi-keyword search, while maintaining high efficiency in the encryption algorithm. Furthermore, this invention effectively resists keyword guessing attacks launched by senders both offline and online. Because a test server is specified during the trapdoor generation process, senders cannot test the intercepted trapdoors, thus limiting offline keyword guessing attacks. Since both the trapdoor generation and ciphertext generation processes incorporate time, the server successfully matches the intercepted trapdoors with the newly generated ciphertext, preventing senders from using the server's capabilities for online keyword guessing. In addition, this invention sends system global parameters to the sender, receiver, and server, who then generate corresponding public-private key pairs based on these parameters. This enables the system to have authentication capabilities, and access control functionality is achieved based on key negotiation between the users. Moreover, both the sender and receiver have their own public keys, which can be categorized to some extent, reducing the server's search workload.
[0134] The above description is merely a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope disclosed in the present invention, based on the technical solution and inventive concept of the present invention, shall fall within the scope of protection of the present invention.
Claims
1. A multi-keyword searchable encryption authentication method, characterized in that, The method includes: Generate system-wide parameters based on security parameters; The system global parameters are sent to the sender, receiver, and server so that the sender, receiver, and server can generate corresponding public-private key pairs based on the system global parameters. The public-private key pair includes public key and private key parameters. The receiver's public key is sent to the sender so that the sender can generate a ciphertext message based on the system's global parameters, the sender's private key, the receiver's public key, the set of multiple plaintext keywords input by the sender, and the current system time. The sender's public key and the server's public key are sent to the receiver so that the receiver can generate a trapdoor message based on the system's global parameters, the receiver's private key, the sender's public key, the server's public key, the set of multiple plaintext keywords entered by the receiver, and the current system time. The encrypted message and the trapdoor message are uploaded to the server so that the server can match the encrypted message and the trapdoor message with the server's private key. If the match is successful, the matched encrypted message is sent to the receiver for decryption. The process of generating global system parameters based on security parameters specifically includes: Input security parameter λ, given a bilinear group PG = ( , , , , p), where and It is a multiplicative cyclic group of order p prime numbers. It is a group A generator, It is to satisfy × → The bilinear mapping relationship; Selected To find the maximum number of keywords in the ciphertext, we obtain three hash functions H1: {0, 1}. * → H2: {0, 1} * → H3: → ; Based on the security parameters and hash function, output the system global parameter gp = ( , , g, , p, H1, H2, H3, ); The step of generating corresponding public-private key pairs based on system global parameters specifically includes: Based on the system global parameter gp, generate the sender's public and private key pairs respectively. = , = ), the recipient's public and private key pair ( = , = ) and the server's public and private key pair ( = v, = ); The process of generating a encrypted message based on system global parameters, the sender's private key, the receiver's public key, a set of multiple plaintext keywords input by the sender, and the current system time specifically includes: Select random number , ; Generate a set using the current system time t using the 0-encoding algorithm. ={ … For each Based on the hash function of the system's global parameters and random numbers The time-ciphertext block is calculated. = ; For i [1, ], based on the hash function H1 of the system's global parameters and the set of plaintext keywords W input by the sender. … }, the sender's private key The recipient's public key ,calculate =H1( , ); Use random numbers , as well as … ,Establish + 1st order polynomial f( )as follows: f(x) = ( - ) + = + …+ ; Extract the polynomial coefficients as the first part of the ciphertext. = { … }; Based on time ciphertext blocks Part 1 Ciphertext Given the current system time t, output the encrypted message CT= ).
2. The multi-keyword searchable encryption method for authentication according to claim 1, characterized in that, The process of generating a trapdoor message based on system global parameters, the receiver's private key, the sender's public key, the server's public key, a set of multiple plaintext keywords input by the receiver, and the current system time specifically includes: Select random number … ; Set the current system time Generate a set using the 1-encoding algorithm. ={ … For each Based on the hash function of the system's global parameters and random numbers The time trap block was calculated. = ; For j [1, ], i [0, ], based on the system's global parameters hash function H1 and the receiver's plaintext keyword set Q={ … }, the recipient's private key and the sender's public key ,calculate =H1( , ),use calculate = ; For i [0, ], based on the generator of system global parameters Hash function H3, server's public key Random numbers … and random numbers Calculate the first part of the trapdoor = Second part of the trapdoor = ; According to the time trap Part One: Trap Door Part Two: Trap Door and current system time Output trapdoor message TD=({ },{ },{ }, , ).
3. The multi-keyword searchable encryption method for authentication according to claim 2, characterized in that, The step of matching the ciphertext message and the trapdoor message based on the server's private key specifically includes: The encrypted message CT is divided into ( ), and divide the trapdoor message TD into ({ },{ },{ }, , ); If system time t < Then there exists an element = , = ,in = ; For i [0, ],calculate ; For i [0, ],calculate ; If it exists ( ) = ( If Q is inferred, then... W, where Q is the set of keywords embedded in the trapdoor message, and W is the set of keywords embedded in the ciphertext message.
4. A multi-keyword searchable encryption device for authentication, characterized in that, The device includes: The system global parameter generation module is used to generate system global parameters based on security parameters; The public-private key pair generation module is used to send system global parameters to the sender, receiver, and server so that the sender, receiver, and server can generate corresponding public-private key pairs based on the system global parameters. The public-private key pair includes a public key and a private key parameter. The encrypted message generation module is used to send the recipient's public key to the sender, so that the sender can generate an encrypted message based on the system global parameters, the sender's private key, the recipient's public key, a set of multiple plaintext keywords input by the sender, and the current system time. The trapdoor message generation module is used to send the sender's public key and the server's public key to the receiver, so that the receiver can generate a trapdoor message based on the system global parameters, the receiver's private key, the sender's public key, the server's public key, a set of multiple plaintext keywords input by the receiver, and the current system time. The matching module is used to upload ciphertext messages and trapdoor messages to the server, so that the server can match the ciphertext messages and trapdoor messages according to the server's private key. If the match is successful, the ciphertext message that has been matched is sent to the receiver for decryption. The process of generating global system parameters based on security parameters specifically includes: Input security parameter λ, given a bilinear group PG = ( , , , , p), where and It is a multiplicative cyclic group of order p prime numbers. It is a group A generator, It is to satisfy × → The bilinear mapping relationship; Selected To find the maximum number of keywords in the ciphertext, we obtain three hash functions H1: {0, 1}. * → H2: {0, 1} * → H3: → ; Based on the security parameters and hash function, output the system global parameter gp = ( , , g, , p, H1, H2, H3, ); The step of generating corresponding public-private key pairs based on system global parameters specifically includes: Based on the system global parameter gp, generate the sender's public and private key pairs respectively. = , = ), the recipient's public and private key pair ( = , = ) and the server's public and private key pair ( = v, = ); The process of generating a encrypted message based on system global parameters, the sender's private key, the receiver's public key, a set of multiple plaintext keywords input by the sender, and the current system time specifically includes: Select random number , ; Generate a set using the current system time t using the 0-encoding algorithm. ={ … For each Based on the hash function of the system's global parameters and random numbers The time-ciphertext block is calculated. = ; For i [1, ], based on the hash function H1 of the system's global parameters and the set of plaintext keywords W input by the sender. … }, the sender's private key The recipient's public key ,calculate =H1( , ); Use random numbers , as well as … ,Establish + 1st order polynomial f( )as follows: f(x) = ( - ) + = + …+ ; Extract the polynomial coefficients as the first part of the ciphertext. = { … }; Based on time ciphertext blocks Part 1 Ciphertext Given the current system time t, output the encrypted message CT= ).
5. A multi-keyword searchable encrypted authentication system, characterized in that, The system includes a sender, a receiver, and a server, with the server connected to both the sender and the receiver. The sender end is used to obtain the receiver's public key and the current system time, input multiple plaintext keyword sets, generate ciphertext messages based on system global parameters, the sender's private key, the receiver's public key, multiple plaintext keyword sets and the current system time, and upload the ciphertext messages to the server; The receiver is used to obtain the sender's public key and the current system time, input multiple plaintext keyword sets, generate a trapdoor message based on the system global parameters, the receiver's private key, the sender's public key, the server's public key, multiple plaintext keyword sets, and the current system time, and upload the trapdoor message to the server. The server is used to match the ciphertext message and the trapdoor message according to the server's private key. If the match is successful, the ciphertext message is sent to the receiver for decryption. The process of generating global system parameters based on security parameters specifically includes: Input security parameter λ, given a bilinear group PG = ( , , , , p), where and It is a multiplicative cyclic group of order p prime numbers. It is a group A generator, It is to satisfy × → The bilinear mapping relationship; Selected To find the maximum number of keywords in the ciphertext, we obtain three hash functions H1: {0, 1}. * → H2: {0, 1} * → H3: → ; Based on the security parameters and hash function, output the system global parameter gp = ( , , g, , p, H1, H2, H3, ); The step of generating corresponding public-private key pairs based on system global parameters specifically includes: Based on the system global parameter gp, generate the sender's public and private key pairs respectively. = , = ), the recipient's public and private key pair ( = , = ) and the server's public and private key pair ( = v, = ); The process of generating a encrypted message based on system global parameters, the sender's private key, the receiver's public key, a set of multiple plaintext keywords input by the sender, and the current system time specifically includes: Select random number , ; Generate a set using the current system time t using the 0-encoding algorithm. ={ … For each Based on the hash function of the system's global parameters and random numbers The time-ciphertext block is calculated. = ; For i [1, ], based on the hash function H1 of the system's global parameters and the set of plaintext keywords W input by the sender. … }, the sender's private key The recipient's public key ,calculate =H1( , ); Use random numbers , as well as … ,Establish + 1st order polynomial f( )as follows: f(x) = ( - ) + = + …+ ; Extract the polynomial coefficients as the first part of the ciphertext. = { … }; Based on time ciphertext blocks Part 1 Ciphertext Given the current system time t, output the encrypted message CT= ).
6. A computer device, characterized in that, The method includes a processor and a memory for storing a processor-executable program, characterized in that, when the processor executes the program stored in the memory, it implements the authentication multi-keyword searchable encryption method according to any one of claims 1-3.
7. A computer-readable storage medium storing a program, characterized in that, When the program is executed by the processor, it implements the authentication multi-keyword searchable encryption method according to any one of claims 1-3.
Citation Information
Patent Citations
Public key encryption method capable of searching multiple keywords
CN108599937A
Public key authentication searchable encryption method and system based on trusted execution environment
CN115314284A
Secure channel-free public key authentication searchable encryption method with multi-keyword search function and related device
CN115333811A