A remote sensing image security retrieval method and system under cloud environment
By constructing encrypted searchable indexes and Merkle trees in a cloud environment, and performing query trap gate generation and authenticity verification of search results, problems such as low retrieval accuracy and insufficient security in remote sensing image security retrieval in cloud environment are solved, and efficient, accurate and secure image retrieval is achieved.
Patent Information
- Application Number
- CN202410938537.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-13
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2044-07-13
AI Technical Summary
The prior art has problems in the security retrieval of remote sensing images in cloud environments with low retrieval accuracy, low retrieval efficiency, insufficient security, poor privacy, difficult to guarantee the legality of data distribution, and difficult to verify the authenticity of search results.
A remote sensing image security retrieval method and system is proposed in the cloud environment. The encrypted searchable index and Merkle tree are constructed by the image owner, and the encrypted image set is uploaded to the cloud server, the query user generates a query trap and sends it to the cloud server, the cloud server performs security retrieval, and the certification agency performs authenticity verification and distribution legality authentication on the search results.
It realizes efficient and accurate remote sensing image security retrieval in a cloud environment, ensures the security and privacy of image content, controls the legality of data distribution, curbs forgery and tampering, and provides verifiable and credible search results.
Smart Images

Figure CN118733816B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of spatial data security, and specifically relates to a remote sensing image security retrieval method and system in a cloud environment. Background Art
[0002] With the continuous maturity of earth observation technology, remote sensing images are also growing rapidly, especially with the support of distributed storage and high-performance parallel computing, which further promotes the arrival of the era of remote sensing big data. Faced with the dynamically growing remote sensing image data storage, management and application problems, cloud computing with the characteristics of rapid scalability, large scale and low cost has become a potential solution. With the rapid development and popularization of the Internet, it is also facing the threat of information security. Remote sensing images containing important information need to be encrypted to protect their confidentiality before outsourcing to the cloud. However, secure image retrieval needs to strike a balance between searchability and confidentiality. There are generally problems such as low retrieval accuracy and low retrieval efficiency, which cannot meet the requirements of large-scale image retrieval in cloud environments. At the same time, "semi-honest" cloud servers, malicious external attackers and query users will engage in activities such as leaking and falsifying data content for profit, which poses a serious threat to secure image retrieval.
[0003] Through the summary of the prior art, it is found that there are at least the following technical problems:
[0004] 1) When multiple data owners are involved, the remote sensing images held by different data owners are limited and have large differences, making it difficult to support large-scale training and ensure that the extracted features have the same feature space. In addition, the high-dimensional features obtained by deep learning require large storage and computing costs.
[0005] 2) Existing methods consider using technologies such as homomorphic encryption and secure multi-party computing to encrypt image features. However, for remote sensing images with large data volumes and rich content, it is difficult to balance the efficiency, accuracy, and security of secure image retrieval.
[0006] 3) Existing methods consider using watermarking technology to track the data distributed by query users. In this process, the reversibility and separability of image encryption and watermark embedding are rarely considered, which makes it difficult to ensure the high fidelity requirements of remote sensing images and the flexibility requirements of multi-task remote sensing image retrieval.
[0007] 4) Existing methods define cloud servers as honest, but cloud servers in actual applications are "semi-honest" and may engage in activities such as forging and tampering with data content, returning untrue remote sensing images, which in turn has a serious negative impact on tasks such as ground detection and investigation. Summary of the invention
[0008] The present invention aims at solving the problems of efficiency and accuracy of image retrieval, security of image content, privacy of retrieval process, legality of data distribution, authenticity of retrieval results and so on in the existing secure image retrieval technology, and proposes a remote sensing image secure retrieval method and system in a cloud environment. The method is used for the image owner to upload the encrypted image and encrypted searchable index to the cloud server, the query user generates a query trap and sends it to the cloud server, the cloud server performs a secure retrieval after receiving the query request, and the certification body verifies the authenticity of the retrieval results and certifies the legality of distribution, so as to obtain secure and efficient retrieval performance and true retrieval results.
[0009] In order to achieve the above object, the present invention adopts the following technical solution:
[0010] A remote sensing image security retrieval method and system in a cloud environment, comprising:
[0011] S1. The image owner constructs an encrypted searchable index and Merkle tree for the outsourced image, encrypts the image set, transmits the encrypted image set and encrypted searchable index to the cloud server, and transmits the Merkle tree to the certification authority;
[0012] S2, the query user extracts and encrypts the features of the query image in the same way, generates a query trap, and then transmits it to the cloud server. After the search results are returned, the query user verifies the authenticity of the search results through the certification agency;
[0013] S3, the cloud server stores the outsourced images and encrypted searchable index of the image owner, retrieves the encrypted images according to the query trapdoor provided by the query user, returns the top-k encrypted images with similar structures to the query image, and then embeds the specific watermark generated by the certification authority for each user into the retrieved encrypted images;
[0014] S4. The certification body performs two tasks: user authentication and retrieval result correctness verification. User authentication controls the illegal distribution of retrieved images by generating a specific watermark for each user, and the retrieval result correctness verification is implemented through the Merkle tree.
[0015] Preferably, in S1, the encrypted searchable index is constructed as follows:
[0016] S21. Use the pre-trained CNN model to extract the feature vector of each image;
[0017] S22, converting the high-dimensional feature vector into a low-dimensional binary code according to the spectral rotation hashing technique, and performing K-means++ clustering;
[0018] S23. After dimension reduction and clustering, the feature vector is expanded and split into two parts, and the two parts obtained by splitting are encrypted respectively according to two random matrices.
[0019] Preferably, in S1 and S3, the image set encryption and watermark embedding method is as follows:
[0020] S31, marking prediction errors and rearranging pixels to free up space for watermark embedding;
[0021] S32, a pseudo-random matrix is generated by a pseudo-random generator, and the current pixel is binarized and then XOR-encrypted bit by bit;
[0022] S33, extracting the starting position information for data embedding in each image according to the data hider, and then embedding the watermark into the space vacated by the encrypted image in the form of pixel replacement after the starting position.
[0023] Preferably, in S2, the query trapdoor is generated by expanding the query vector and splitting it into two parts, and then encrypting the two parts obtained by the splitting according to two random matrices respectively, where the two random matrices here are inverse vectors of the two random matrices in S23.
[0024] Preferably, in S4, the authentication agency authenticates the authenticity of the search result as follows:
[0025] S51, the certification authority returns all neighboring nodes on the path from the root node to the leaf node of the image to be verified as evidence according to the Merkle tree of the image set;
[0026] S52. Construct a new Merkle tree based on the image to be verified and its evidence, and compare the root hash value of the new Merkle tree with that of the original Merkle tree.
[0027] Preferably, in S4, the certification body tracks the distribution data:
[0028] S61, the image owner finds a suspicious image and sends the copy and the original image to the certification agency;
[0029] S62. The authentication agency finds the reserved space for embedding the user authentication watermark by extracting the starting position mark, and extracts the embedded watermark information.
[0030] A remote sensing image security retrieval method and system in a cloud environment, comprising:
[0031] The retrieval index generation and encryption module is used by the image owner to extract low-dimensional image features and encrypt feature vectors, form encrypted feature vectors, and send them to the cloud server;
[0032] Image encryption and watermark embedding module, used for image encryption in reserved space and watermark embedding for tracking distribution data. The encrypted image is sent to the cloud server, and the cloud server embeds a watermark containing the identity information of the query user;
[0033] A query vector generation and encryption module is used to query the user to extract image features and encrypt the query vector, form an encrypted query vector, and send it to the cloud server;
[0034] The retrieval module is used to calculate the Euclidean distance between the encrypted feature vector and the encrypted query vector, and return the top-k encrypted images in ascending order;
[0035] The authenticity verification module of the retrieval results is used to prevent malicious cloud servers and external attackers from forging and tampering with image content;
[0036] The data distribution legitimacy verification module is used to track the distributed data and control the leakage of retrieval results by malicious query users.
[0037] Compared with the prior art, the present invention has the following beneficial technical effects:
[0038] The extracted features of the pre-trained CNN model transfer learning are used and the dimension reduction is performed according to the spectral rotation hash, so that the features of different source images can be retrieved with high precision and high efficiency based on the same feature space. The image features are encrypted according to the modified tuple of ASPE to generate a secure encrypted searchable index to achieve privacy protection for feature operations. In addition, the reversibility and separability of image encryption and watermark embedding meet the high fidelity requirements of high-precision remote sensing images and the flexibility requirements of secure image retrieval, thereby effectively controlling and tracking the illegal distribution of retrieved images. By constructing a Merkle tree to authenticate the authenticity of the retrieval results, the behavior of forging and tampering with data content is curbed. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.
[0040] Figure 1 A schematic diagram of the overall framework of a remote sensing image security retrieval method and system in a cloud environment provided by the present invention. DETAILED DESCRIPTION
[0041] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only partial embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0042] See attached Figure 1 The embodiment of the present invention discloses a remote sensing image security retrieval method and system in a cloud environment, comprising the following steps:
[0043] Step 1: The key generation center generates the keys required for the encryption algorithm.
[0044] Generate a key using the key generation algorithm:
[0045] First, a binary vector G and two reversible matrices M1 and M2 are randomly generated. Next, for the image owner, four reversible matrices are randomly generated. Among them A θ1,1 ·A θ1,2 =M1,B θ1,1 ·B θ1,2 =M2. For the query user, 4 reversible matrices are randomly generated in K is a set of real numbers encoded in n bits. I,i Represents the key required to encrypt an image using a stream cipher;
[0046] Step 2: Image owner builds an encrypted searchable index.
[0047] Step 1: The image owner is extracted from the image set according to the CNN model and a set of feature vectors are obtained by spectral rotation hashing. And according to k-means++ Clustering
[0048] Step 2: For each eigenvector f t , 1≤t≤n, first in f t Add ||f t || 2 Expand it to (d+1) dimensions.
[0049] Step 3: When the binary vector G is equal to 0, let f t,a =f t,b =f t , otherwise f t,a +f t,b =f t , f t Divide into ft,a and f t,b Two vectors. Then according to the random matrix A θ1,1 , B θ1,1 Each expanded eigenvector f t Encrypted to f t ′=(f t, a A θ1,1 , f t,b B θ1,1 ).
[0050] Step 4: Similarly, set the cluster center c s Encrypted into c′ s , 1≤s≤k. Get the encrypted feature vector and encrypted cluster centers
[0051] Step 3: The image owner encrypts the image set.
[0052] The image owner performs prediction error marking, pixel rearrangement and image encryption in sequence. The encryption algorithm is stream cipher encryption, that is, a pseudo-random matrix R of size m×n is first generated by a pseudo-random generator, and then the current pixels x(i, j) and r(i, j) are binarized into x k (i, j) and r k (i, j), and then XOR encryption is performed bit by bit. Next, the image owner extracts the starting position information for data embedding in each image, and then embeds the watermark containing copyright information into the space reserved for the encrypted image in the form of pixel replacement after the starting position. Finally, a set of encrypted images marked with copyright information is generated. For details of this ciphertext domain watermark embedding algorithm, please refer to the literature "Reversible data hiding in encrypted imagesbased on pixel prediction and multi-MSB planes rearrangement" (Signa1Processing 187(2021):108146).
[0053] Step 4: Image owner builds the Merkle tree.
[0054] First, the image owner performs a i,t And its ID are hashed to get the leaf node N i,t =h(m′ i,t ||ID(m′ i,t )). Then, the internal nodes and root nodes are obtained in turn according to the calculated leaf nodes, and then the Merkle tree is generated.
[0055] Step 5: Query the user to generate a query trapdoor.
[0056] Step 1: The query user will extract the feature vector f in the query image in the same way q .
[0057] Step 2: f q Multiply it by (-2) and add 1 to the end of the vector to get a (d+1)-dimensional query vector.
[0058] Step 3: When the binary vector G is equal to 0, let f q,a =f q,b =f q , otherwise f q,a +f q,b =f q , f q Divide into f q,a and f q,b Two vectors.
[0059] Step 4: According to the random matrix A θ2,1 , B θ2,1 Each expanded eigenvector f q Encrypted Where γ is a random positive integer used to ensure the randomness and security of the query trapdoor.
[0060] Step 6: The cloud server retrieves the image set and returns the retrieval results to the query user.
[0061] Step 1: According to A θ1,2 , B θ1,2 Each encrypted feature vector f t 'Convert to Right now
[0062] Step 2: According to A θ2,2 , B θ2,2 The query trapdoor f′ q Convert to Right now
[0063] Step 3: Cloud server based on index vector and query vector Calculate f t With f q Euclidean distance between HD t ,Right now , return the top-k encrypted images sorted by distance.
[0064] Step 4: After the cloud server obtains the top-k encrypted images, it embeds the watermark containing the query user's identity information into them and sends these encrypted images containing the user authentication watermark information to the query user.
[0065] Step 7: The certification body verifies the authenticity of the search results.
[0066] Step 1: The authentication agency finds the reserved space for embedding the user authentication watermark by extracting the starting position mark, and extracts the embedded watermark containing the query user identity information, thereby obtaining an encrypted image without the user authentication watermark.
[0067] Step 2: Encrypt image m′ for top-k i,n , the certification authority generates evidence π based on the Merkle tree i,n .
[0068] Step 3: First, perform hash calculation on the encrypted image to obtain the leaf node N i,n =h(m′ i,n ||ID(m′ i,n )), then based on the evidence π i,n Build a Merkle tree and get the hash value N' of the root node root Finally, verify that N′ root With N root Are they equal, where N root is the hash value of the root node of the Merkle tree. If they are equal, it means that the encrypted image m′ i,n is correct, otherwise it means that the encrypted image has been tampered with.
[0069] Step 8: Query the user to decrypt the retrieved image.
[0070] Query the user's key K I,i For the encrypted image m′ i,n Then, the auxiliary information before the start position mark is extracted to obtain the ignored bit, threshold T, label list and compressed position map. After decompressing the position map, all original pixel values can be restored according to the auxiliary information, the label and predicted value of each pixel, and thus the original image m can be restored losslessly. i,n .
[0071] Step 9: Watermark extraction.
[0072] There are two types of watermark extraction, one for copyright protection and the other for user authentication. The former is done by the image owner, extracting the embedded copyright information watermark to achieve copyright protection of the image set. The latter is done by the certification authority, extracting the embedded user authentication watermark to authenticate the legitimacy of the identity of the suspicious object. The reserved space for embedding the user authentication watermark is found by extracting the starting position mark, and the embedded watermark information is extracted.
[0073] Compared with the prior art, the present invention has the following advantages:
[0074] First, in order to improve the accuracy and efficiency of image retrieval while keeping the image features extracted by different image owners in the same feature space, the proposed scheme uses CNN transfer learning to extract the feature vector of each image before image encryption, and then converts the high-dimensional feature vector into a low-dimensional binary code based on the spectral rotation hashing technique, and performs K-means++ clustering to divide it into meaningful clusters, maintaining high retrieval accuracy while reducing storage and communication costs.
[0075] Second, each cluster center is encrypted according to the modified tuple encryption algorithm of ASPE to generate a secure encrypted searchable index to achieve privacy protection for feature operations.
[0076] Third, the prediction error is marked and the pixels are rearranged before the image is encrypted, and the auxiliary information required to fully restore the image is stored in it, which ensures the reversibility of the watermark embedding in the ciphertext domain. The prediction error is marked using the statistical characteristics of the Laplace distribution to free up more space for watermark embedding. It is worth noting that watermark extraction and image restoration are independent of each other, which improves the flexibility of secure image retrieval and privacy protection.
[0077] Fourth, a Merkle tree is constructed based on the encrypted image set to curb the forgery and tampering of image content, and to support verifiable and reliable Top-k retrieval results in the presence of malicious cloud servers and external attackers.
[0078] In this specification, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part.
[0079] The above description of the disclosed embodiments enables one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A remote sensing image security retrieval method in a cloud environment, characterized in that: include: S1. The image owner uses the pre-trained CNN model to extract the features of the outsourced image, and generates an encrypted searchable index based on spectral rotation hashing and ASPE, then performs prediction error marking and pixel rearrangement to free up watermark embedding space, and finally encrypts the image set and constructs a Merkle tree. The encrypted image set and encrypted searchable index are transmitted to the cloud server, and the Merkle tree is transmitted to the certification authority; S2, the query user uses the pre-trained CNN model to extract the features of the query image, and generates a query trapdoor based on spectral rotation hashing dimensionality reduction and ASPE, and then transmits it to the cloud server. After the retrieval results are returned, the query user verifies the authenticity of the search results through the certification agency; S3, the cloud server stores the outsourced images and encrypted searchable index of the image owner, retrieves the encrypted images according to the query trapdoor provided by the query user, returns the top-k encrypted images with similar structures to the query image, and then embeds the specific watermark generated by the certification authority for each user in the watermark embedding space reserved for the top-k encrypted images; S4. The certification authority performs two tasks: user authentication and retrieval result correctness verification. User authentication is achieved by extracting and comparing specific watermark information in suspicious images, and retrieval result correctness verification is achieved by reconstructing the Merkle tree and comparing the root hash stored by the image owner.
2. According to the method for secure retrieval of remote sensing images in a cloud environment as described in claim 1, it is characterized in that: In S1, the encrypted searchable index is constructed as follows: S21. Use the pre-trained CNN model to extract the feature vector of each image; S22, converting the high-dimensional feature vector into a low-dimensional binary code according to the spectral rotation hashing technique, and performing K-means++ clustering; S23. After dimension reduction and clustering, the feature vector is expanded and split into two parts, and then the two parts are encrypted according to two random matrices.
3. According to the method for secure retrieval of remote sensing images in a cloud environment as described in claim 1, it is characterized in that: In S1 and S3, the image sets are encrypted and watermarked: S31, marking prediction errors and rearranging pixels to free up space for watermark embedding; S32, a pseudo-random matrix is generated by a pseudo-random generator, and the current pixel is binarized and then XOR-encrypted bit by bit; S33, extracting the starting position information for data embedding in each image, and then embedding the watermark into the space vacated by the encrypted image in the form of pixel replacement after the starting position.
4. According to the method for secure retrieval of remote sensing images in a cloud environment as described in claim 2, it is characterized in that: In S2, the query trapdoor is generated by expanding the query vector and splitting it into two parts, and then encrypting the two parts obtained by splitting according to two random matrices respectively. The two random matrices here are inverse vectors of the two random matrices in S23.
5. The method for secure retrieval of remote sensing images in a cloud environment according to claim 1, characterized in that: In S4, the authentication agency authenticates the authenticity of the search result as follows: S51, the certification authority returns all neighboring nodes on the path from the root node to the leaf node of the image to be verified as evidence according to the Merkle tree of the image set; S52. Construct a new Merkle tree based on the image to be verified and its evidence, and compare the root hash value of the new Merkle tree with that of the original Merkle tree.
6. The method for secure retrieval of remote sensing images in a cloud environment according to claim 1, characterized in that: In S4, the certification authority tracks the distribution data: S61, the image owner finds a suspicious image and sends the copy and the original image to the certification agency; S62. The authentication agency finds the reserved space for embedding the user authentication watermark by extracting the starting position mark, and extracts the embedded watermark information.
7. A remote sensing image security retrieval system in a cloud environment, characterized in that: The remote sensing image security retrieval system under cloud environment comprises: a retrieval index generation and encryption module, an image encryption and watermark embedding module, a retrieval module, a retrieval result authenticity verification module, and a data distribution legitimacy verification module; the remote sensing image security retrieval system under cloud environment executes a remote sensing image security retrieval method under cloud environment as described in any one of claims 1 to 6; Among them, the retrieval index generation and encryption module is used for the image owner to extract low-dimensional image features according to the CNN model and spectral rotation hash and encrypt the feature vector using ASPE to form an encrypted searchable index and send it to the cloud server; the image encryption and watermark embedding module is used for the image owner to encrypt the image according to the prediction error mark and the pixel rearrangement reserved space, and the cloud server embeds a watermark containing the query user's identity information for data tracing; the query vector generation and encryption module is used for the query user to extract image features according to the CNN model and spectral rotation hash and encrypt the query vector using ASPE to form an encrypted query vector and send it to the cloud server; the retrieval module is used to calculate the Euclidean distance between the encrypted feature vector and the encrypted query vector, and return the top-k encrypted images in ascending order; the authenticity verification module of the retrieval result is used to curb the forgery and tampering of the image content by malicious cloud servers and external attackers by constructing a Merkle tree; the legitimacy verification module of data distribution is used to track the distributed data through digital watermarks to control the leakage of retrieval results by malicious query users.
Citation Information
Patent Citations
Efficient cryptograph image retrieval method capable of supporting privacy protection under cloud environment
CN107480163A
Verifiable encrypted image retrieval method supporting dynamic updating
CN113569280A