An image retrieval method, a cloud server, a first device, and a storage medium.
By using encrypted indexes and encrypted role multinomial functions to verify user roles in a cloud environment, the problem of image privacy leakage is solved, the security and privacy of image retrieval are improved, and the burden on devices is reduced.
Patent Information
- Application Number
- CN202410238955.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-01
- Publication Date
- 2026-01-06
- Estimated Expiration
- 2044-03-01
AI Technical Summary
Existing image retrieval methods suffer from image privacy leaks in cloud environments, particularly due to privacy leaks caused by malicious users posing as legitimate users to access the system, as well as privacy leaks caused by uploading plaintext role values. Furthermore, updating the set of legitimate users increases the burden on image owners.
The system employs encrypted indexes, encrypted role polynomial functions, and an encrypted image library. It verifies encrypted role values via a cloud server to determine the legitimacy of user roles and performs image retrieval only after successful verification. This prevents malicious users from accessing the system and avoids uploading plaintext role values.
It effectively prevents malicious users from stealing image privacy, improves the security of image retrieval, reduces the device burden when updating the legitimate user set, and ensures the privacy of user roles and the security of the system.
Smart Images

Figure CN118802277B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of cloud security technology, and in particular to an image retrieval method, a cloud server, a first device, and a storage medium. Background Technology
[0002] Image retrieval technology refers to the technique of searching for images of interest to users within a large-scale image dataset. However, image retrieval tasks consume significant storage and computing resources. With the development of cloud technology, more and more image owners are inclined to upload their images to cloud servers with stronger storage and computing capabilities. In cloud-based image retrieval tasks, image owners upload their image datasets to the cloud, which then performs the image retrieval task and returns the search results to the user.
[0003] However, current privacy-supporting image retrieval technologies typically assume that users are honest and trustworthy. In practice, however, malicious users frequently exist who can impersonate legitimate users to access the system and steal images from owners, leading to privacy breaches. Furthermore, when verifying the legitimacy of a querying user, the user often directly uploads their role value in plaintext to the cloud for verification. This could result in the cloud collecting a set of legitimate users, further exacerbating privacy concerns. Therefore, current image retrieval methods suffer from image privacy breaches, consequently reducing the security of image retrieval. Summary of the Invention
[0004] This application implements a legal provision that provides an image retrieval method, a cloud server, a first device, and a storage medium, which can prevent image privacy leaks and thus improve the security of image retrieval.
[0005] The technical solution of this application embodiment is implemented as follows:
[0006] In a first aspect, embodiments of this application provide an image retrieval method, the method being applied to a cloud server, the method comprising:
[0007] Receive the encrypted index, the first role polynomial function, and the encrypted image library sent by the first device;
[0008] Receive a first image retrieval request sent by a second device; wherein the first image retrieval request carries a first encrypted trapdoor and a first encrypted role value;
[0009] Based on the first encrypted role value and the first role polynomial function, determine whether the first user role corresponding to the first encrypted role value is a first legitimate user role;
[0010] If the first user role is the first legitimate user role, the target image is determined based on the encrypted index, the first encrypted trapdoor, and the encrypted image library, and the target image is sent to the second device.
[0011] Secondly, embodiments of this application provide an image retrieval method, the method being applied to a first device, the method comprising:
[0012] Determine the encrypted user role set based on the set of legitimate user roles corresponding to the image set;
[0013] The first role polynomial function is determined based on the encrypted user role set;
[0014] The first role polynomial function, the encrypted index, and the encrypted image library are sent to the cloud server so that the cloud server can determine the target image based on the first role polynomial function, the encrypted index, and the encrypted image library.
[0015] Thirdly, embodiments of this application provide a cloud server, which includes: a receiving unit, a judging unit, a first determining unit, and a first sending unit.
[0016] The receiving unit is used to receive the encrypted index, the first role polynomial function, and the encrypted image library sent by the first device;
[0017] The receiving unit is further configured to receive a first image retrieval request sent by the second device; wherein the first image retrieval request carries a first encryption trapdoor and a first encryption role value;
[0018] The judgment unit is used to determine whether the first user role corresponding to the first encrypted role value is a first legitimate user role based on the first encrypted role value and the first role polynomial function.
[0019] The first determining unit is configured to determine the target image based on the encrypted index, the first encrypted trapdoor, and the encrypted image library when the first user role is the first legitimate user role;
[0020] The first sending unit is used to send the target image to the second device.
[0021] Fourthly, embodiments of this application provide a cloud server, the cloud server comprising: a first processor and a first memory; wherein,
[0022] The first memory is used to store computer programs that can run on the processor;
[0023] The first processor is configured to execute the image retrieval method as described above when running the computer program.
[0024] Fifthly, embodiments of this application provide a first device, the first device comprising: a second determining unit and a second sending unit.
[0025] The second determining unit is used to determine the encrypted user role set based on the legitimate user role set;
[0026] The second determining unit is further configured to determine a first role polynomial function based on the encrypted user role set;
[0027] The second sending unit is used to send the first role polynomial function, the encrypted index, and the encrypted image library to the cloud server, so that the cloud server can determine the target image based on the first role polynomial function, the encrypted index, and the encrypted image library.
[0028] Sixthly, embodiments of this application provide a first device, the first device comprising: a second processor and a second memory; wherein,
[0029] The second memory is used to store computer programs that can run on the processor;
[0030] The second processor is configured to execute the image retrieval method described above when running the computer program.
[0031] In a seventh aspect, embodiments of this application provide a computer-readable storage medium, characterized in that the storage medium stores computer program code, which, when executed by a computer, implements the image retrieval method described above.
[0032] Eighthly, a computer program product includes a computer program, characterized in that, when executed by a processor, the computer program implements the image retrieval method as described above.
[0033] This application provides an image retrieval method, a cloud server, a first device, and a storage medium. The cloud server receives an encrypted index, a first role polynomial function, and an encrypted image library sent by the first device; it also receives a first image retrieval request sent by a second device. The first image retrieval request carries a first encrypted trapdoor and a first encrypted role value. Based on the first encrypted role value and the first role polynomial function, the cloud server determines whether the first user role corresponding to the first encrypted role value is a first legitimate user role. If the first user role is the first legitimate user role, the cloud server determines a target image based on the encrypted index, the first encrypted trapdoor, and the encrypted image library, and sends the target image to the second device. The first device determines an encrypted user role set based on the set of legitimate user roles corresponding to the image set; it determines a first role polynomial function based on the encrypted user role set; and it sends the first role polynomial function, the encrypted index, and the encrypted image library to the cloud server, so that the cloud server determines the target image based on the first role polynomial function, the encrypted index, and the encrypted image library. Therefore, the role value received by the cloud server is the first encrypted role value, not the plaintext role value, thus avoiding the privacy leakage problem that may be caused by uploading plaintext roles. Furthermore, this application proposes a lightweight access control strategy, which can verify the identity information of the first user role corresponding to the first encrypted role value. The cloud server can determine whether the first user role corresponding to the first encrypted role value is a first legitimate user role based on the first encrypted role value and the first role polynomial function. If the first user role is verified to be a first legitimate user role, the target image can be determined based on the encrypted index, the first encrypted trapdoor, and the encrypted image library. This can prevent malicious users from accessing the system, further avoid the image privacy leakage problem, and thus improve the security of image retrieval. Attached Figure Description
[0034] Figure 1 This is a schematic diagram of the image retrieval method proposed in the embodiments of this application. Figure 1 ;
[0035] Figure 2 This is a schematic diagram of the image retrieval method proposed in the embodiments of this application. Figure 2 ;
[0036] Figure 3 This is a schematic diagram of the image retrieval method proposed in the embodiments of this application. Figure 3 ;
[0037] Figure 4 This is a schematic diagram of the image retrieval system model proposed in the embodiments of this application;
[0038] Figure 5 This is a schematic diagram of the image retrieval method proposed in the embodiments of this application. Figure 4 ;
[0039] Figure 6 This is a schematic diagram of the cloud server structure proposed in the embodiments of this application. Figure 1 ;
[0040] Figure 7 This is a schematic diagram of the cloud server structure proposed in the embodiments of this application. Figure 2 ;
[0041] Figure 8 This is a schematic diagram of the composition structure of the first device proposed in the embodiments of this application. Figure 1 ;
[0042] Figure 9 This is a schematic diagram of the composition structure of the first device proposed in the embodiments of this application. Figure 2 . Detailed Implementation
[0043] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are only for explaining the relevant application and not for limiting the application. Furthermore, it should be noted that, for ease of description, only the parts related to the relevant application are shown in the accompanying drawings.
[0044] Image retrieval technology refers to the technique of searching for images of interest to users within a large-scale image database. However, image retrieval tasks consume significant storage and computing resources. With the development of cloud technology, more and more image owners tend to upload their images to cloud servers with stronger storage and computing capabilities. In cloud-based image retrieval tasks, image owners upload image datasets to the cloud, which then performs the image retrieval task and returns the results to the user. However, while cloud servers are considered "honest and curious," they may analyze stored images to learn more information, potentially leading to privacy breaches. Furthermore, malicious users could impersonate legitimate users, also resulting in privacy leaks. Therefore, it is necessary to research privacy-supporting image retrieval schemes based on access control.
[0045] The patent titled "A Secure Image Retrieval Method for Large-Scale Images in a Cloud Environment" discloses a secure image retrieval method for large-scale images in a cloud environment. Image owners generate an encrypted image library and secure index locally and outsource them to a cloud server. The cloud server can return the most similar image to the queried image without decryption during retrieval. This method combines the bag-of-words model and the minimum hash principle, achieving high efficiency in large-scale secure image retrieval. However, this scheme directly assumes that the user is completely trustworthy and does not consider the possibility of malicious users stealing image privacy. The patent titled "A Secure Image Retrieval Method Based on Secret Sharing in a Cloud Environment" discloses a secure image retrieval scheme based on Shamir secret sharing in a cloud environment. In the offline stage, an image index is generated using secret sharing technology and outsourced to multiple cloud servers along with an encrypted image library. In the query stage, the user generates image trapdoors and sends them to multiple cloud servers. Through data interaction between the multiple servers, the search results of interest to the user are returned. This method improves upon a secure multi-party computation method, enabling secure image retrieval in a multi-cloud server environment without exposing the true Euclidean distance of the images. However, the original intention of this method was to achieve secure image retrieval across multiple servers, without considering the possibility of malicious users, and therefore it cannot identify malicious users.
[0046] Current image retrieval methods have the following problems: (1) Privacy-supporting image retrieval technologies usually assume that users are honest and trustworthy, but in actual applications, there are often malicious users who will pretend to be legitimate users to access the system and steal images from image owners, thus leading to privacy leaks; (2) When verifying whether a query user is a legitimate user, the query user usually uploads the plaintext role value to the cloud for verification. The cloud may collect a set of legitimate users, leading to privacy leaks; (3) When the set of legitimate users is updated, that is, when the set of legitimate users is added or reduced, the image owner usually needs to regenerate the role polynomial and upload it to the cloud, which increases the burden on the image owner.
[0047] To address the issue of image privacy leakage and consequently decreased security in current image retrieval methods, this application provides an image retrieval method, a cloud server, a first device, and a storage medium. The cloud server receives an encrypted index, a first role polynomial function, and an encrypted image library from the first device; it also receives a first image retrieval request from a second device. The first image retrieval request carries a first encrypted trapdoor and a first encrypted role value. Based on the first encrypted role value and the first role polynomial function, the cloud server determines whether the first user role corresponding to the first encrypted role value is a first legitimate user role. If the first user role is a first legitimate user role, the cloud server determines a target image based on the encrypted index, the first encrypted trapdoor, and the encrypted image library, and sends the target image to the second device. The first device determines an encrypted user role set based on the set of legitimate user roles corresponding to the image set; it determines a first role polynomial function based on the encrypted user role set; and it sends the first role polynomial function, the encrypted index, and the encrypted image library to the cloud server, enabling the cloud server to determine the target image based on the first role polynomial function, the encrypted index, and the encrypted image library. Therefore, the role value received by the cloud server is the first encrypted role value, not the plaintext role value, thus avoiding the privacy leakage problem that may be caused by uploading plaintext roles. Furthermore, this application proposes a lightweight access control strategy, which can verify the identity information of the first user role corresponding to the first encrypted role value. The cloud server can determine whether the first user role corresponding to the first encrypted role value is a first legitimate user role based on the first encrypted role value and the first role polynomial function. If the first user role is verified to be a first legitimate user role, the target image can be determined based on the encrypted index, the first encrypted trapdoor, and the encrypted image library. This can prevent malicious users from accessing the system, further avoid the image privacy leakage problem, and thus improve the security of image retrieval.
[0048] The technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings.
[0049] Example 1
[0050] This application provides an image retrieval method applied to a cloud server. Figure 1 This is a schematic diagram of the image retrieval method proposed in the embodiments of this application. Figure 1 ,like Figure 1 As shown, an image retrieval method may include the following steps:
[0051] Step 101: Receive the encrypted index, the first role polynomial function, and the encrypted image library sent by the first device.
[0052] In embodiments of this application, the cloud server can receive an encrypted index, a first role polynomial function, and an encrypted image library sent by the first device.
[0053] It should be noted that, in the embodiments of this application, the first device may be the physical device corresponding to the image owner, and this application does not specifically limit the type of the first device.
[0054] It should be noted that, in the embodiments of this application, the first role polynomial function can be represented by the following formula (1).
[0055]
[0056] Where f(v) represents the first-role polynomial function, The root of the function is represented by v, and the user's role is represented by c. i Indicates v i The coefficient.
[0057] It should be noted that, in the embodiments of this application, the encryption index can be represented by the following formula (2).
[0058]
[0059] Among them, ||f i || 2 =f i,1 2 +f i,2 2 +...+f i,n 2 , indicating f i The Euclidean normal form, c1, c2, ..., c m Let f be the coefficients of the role-based polynomial function. i,1 ,f i,2 ,...,f i,l Image m representing the image library i The corresponding feature vector, where i represents the image's index in the image database and l represents the feature dimension.
[0060] It should be noted that, in the embodiments of this application, the encrypted image library can be obtained by encrypting based on an image encryption algorithm. The image encryption algorithm can be an Advanced Encryption Standard (AES) algorithm. This application does not specifically limit the type of image encryption algorithm.
[0061] Step 102: Receive the first image retrieval request sent by the second device; wherein the first image retrieval request carries a first encryption trapdoor and a first encryption role value.
[0062] In embodiments of this application, the cloud server can receive an encrypted index, a first role polynomial function, and an encrypted image library sent by a first device, and can also receive a first image retrieval request sent by a second device; wherein, the first image retrieval request carries a first encrypted trapdoor and a first encrypted role value.
[0063] It should be noted that in the embodiments of this application, the second device may be a user device, and this application does not specifically limit the type of the second device.
[0064] It should be noted that, in the embodiments of this application, the encryption trapdoor can be represented by the following formula (3).
[0065]
[0066] Where v represents the role of the querying user, β, α are random positive numbers, and q1, q2, ..., q l Represents the query image q i The corresponding feature vector, where l represents the dimension of the feature.
[0067] It should be noted that, in the embodiments of this application, the first encrypted role value can be obtained by encrypting the user's role. For example, the user's role v can be encrypted to generate the first encrypted role value g. v .
[0068] Step 103: Determine whether the first user role corresponding to the first encrypted role value is the first legitimate user role based on the first encrypted role value and the first role polynomial function.
[0069] In the embodiments of this application, after receiving the encrypted index, the first role polynomial function, and the encrypted image library sent by the first device; and the first image retrieval request sent by the second device; wherein the first image retrieval request carries the first encrypted trapdoor and the first encrypted role value, the cloud server can determine whether the first user role corresponding to the first encrypted role value is the first legitimate user role based on the first encrypted role value and the first role polynomial function.
[0070] It should be noted that, in the embodiments of this application, when the cloud server determines whether the first user role corresponding to the first encrypted role value is a first legitimate user role based on the first encrypted role value and the first role polynomial function, it can input the first encrypted role value into the first role polynomial function to obtain an output value; if the output value is a first preset value, the first user role is determined to be a first legitimate user role; if the output value is not the first preset value, the first user role is determined not to be a first legitimate user role.
[0071] It should be noted that in the embodiments of this application, the first preset value can be 0, and this application does not specifically limit the size of the first preset value.
[0072] For example, in an embodiment of this application, it is assumed that the value of the first encryption role is... The first encrypted role value is input into the first role polynomial function, i.e., the above formula (1), to obtain the output value; if the output value is 0, the first user role is determined to be the first legal user role; if the output value is not 0, the first user role is determined to be the first legal user role.
[0073] In other words, in the embodiments of this application, the cloud server can verify the user role. If the user role belongs to a legitimate user, the image retrieval operation is allowed to continue; if the user is not a legitimate user, the image retrieval operation is not allowed to continue. This can prevent malicious users from impersonating legitimate users to access the system and steal images from image owners, thus avoiding image privacy leaks.
[0074] It should be noted that, in the embodiments of this application, after the cloud server determines whether the first user role corresponding to the first encrypted role value is a first legitimate user role based on the first encrypted role value and the first role polynomial function, it can determine the second role polynomial function based on a preset random number and the first role polynomial function.
[0075] It should be noted that, in the embodiments of this application, the preset random number can be any positive integer, and this application does not specifically limit the size of the preset random number.
[0076] It should be noted that, in the embodiments of this application, the second role polynomial function can be represented by the following formula (4).
[0077] f ′ (v)=mf(v) (4)
[0078] Where m represents a preset random number, and f(v) represents the first role polynomial function.
[0079] It should be noted that, in the embodiments of this application, the cloud server uses a preset random number to reset the first role polynomial function, so that the role polynomial function is updated with each query, thereby preventing attackers from stealing the legitimate user set based on the role polynomial function.
[0080] It should be noted that, in the embodiments of this application, the cloud server can also receive a second image retrieval request sent by the second device; wherein, the second image retrieval request carries a second encryption trapdoor and a second encryption role value; based on the second encryption role value and the second role polynomial function, it is determined whether the second user role corresponding to the second encryption role value is a first legitimate user role; if the second user role is a first legitimate user role, the target image is determined based on the encryption index, the second encryption trapdoor, and the encryption image library.
[0081] In other words, in the embodiments of this application, after receiving the second image retrieval request sent by the second device, the cloud server can determine whether the second user role corresponding to the second encrypted role value is the first legitimate user role based on the updated second role polynomial function and the second encrypted role value.
[0082] Step 104: If the first user role is the first legitimate user role, determine the target image based on the encrypted index, the first encrypted trapdoor, and the encrypted image library, and send the target image to the second device.
[0083] In the embodiments of this application, after the cloud server determines whether the first user role corresponding to the first encrypted role value is a first legitimate user role based on the first encrypted role value and the first role polynomial function, it can determine the target image based on the encrypted index, the first encrypted trapdoor and the encrypted image library if the first user role is a first legitimate user role, and then send the target image to the second device.
[0084] It should be noted that, in the embodiments of this application, the encrypted index includes N encrypted index vectors, where N is a positive integer, and this application does not impose a specific limit on the number of encrypted index vectors.
[0085] It should be noted that, in the embodiments of this application, when the cloud server determines the target image based on the encrypted index, the first encrypted trapdoor, and the encrypted image library, it can determine the target encrypted index vector based on the first encrypted trapdoor and N encrypted index vectors; then it can determine the target image based on the target encrypted index vector and the encrypted image library.
[0086] For example, in an embodiment of this application, the cloud server can calculate the product of the first encryption trapdoor and N encryption index vectors. The image corresponding to the encryption index with the smallest product (target encryption index) is the image that the user is interested in, i.e., the target image. The calculation formula is shown in the following formula (5).
[0087]
[0088] Where q represents the cryptographic trapdoor, f i,r Let f(v) represent a certain encrypted index vector, and α represent a random positive number. Since the user has been verified as a legitimate user, f(v) = 0.
[0089] It should be noted that, in the embodiments of this application, the cloud server can receive role function information sent by the first device; wherein, the role function information includes a first role function and / or a second role function; and then the first role polynomial function can be updated based on the role function information.
[0090] It should be noted that, in the embodiments of this application, the first role function can be a function generated based on the newly added user role.
[0091] It should be noted that, in the embodiments of this application, the second role function can be a function generated based on the reduced user roles.
[0092] For example, in an embodiment of this application, it is assumed that after the cloud server receives the first role function sent by the first device, it can update the first role polynomial function based on the first role function. The updated role polynomial function is shown in the following formula (6).
[0093] f ′ (v)=f new (v)f(v) (6)
[0094] Among them, f new (v) denotes the first role function, and f(v) denotes the first role polynomial function.
[0095] For example, in an embodiment of this application, it is assumed that after the cloud server receives the second role function sent by the first device, it can update the first role polynomial function based on the second role function. The updated role polynomial function is shown in the following formula (7).
[0096] f ′ (v)=f(v) / f r (v) (7)
[0097] Among them, f r (v) represents the second role function.
[0098] In other words, in the embodiments of this application, the cloud server can update the first role polynomial function based on the received role function information, without the first device having to regenerate the role polynomial function and upload it to the cloud server, thereby reducing the burden on the first device.
[0099] In summary, after receiving the encrypted index, first role polynomial function, and encrypted image library from the first device, and the first image retrieval request from the second device (where the first image retrieval request carries a first encrypted trapdoor and a first encrypted role value), the cloud server can determine whether the first user role corresponding to the first encrypted role value is a legitimate user role based on the first encrypted role value and the first role polynomial function. That is, the cloud server can verify the user role; if the user role is legitimate, the image retrieval operation is allowed to continue; if the user is not legitimate, the image retrieval operation is not allowed to continue. This prevents malicious users from impersonating legitimate users to access the system and steal images from image owners, thus avoiding image privacy leaks. The cloud server can also receive role function information from the first device, including a first role function and / or a second role function. It can then update the first role polynomial function based on the role function information without requiring the first device to regenerate the role polynomial function and upload it to the cloud server, thereby reducing the burden on the first device.
[0100] This application provides an image retrieval method applied to a cloud server. The cloud server receives an encrypted index, a first role polynomial function, and an encrypted image library sent by a first device; and receives a first image retrieval request sent by a second device. The first image retrieval request carries a first encrypted trapdoor and a first encrypted role value. Based on the first encrypted role value and the first role polynomial function, the method determines whether the first user role corresponding to the first encrypted role value is a first legitimate user role. If the first user role is a first legitimate user role, the method determines a target image based on the encrypted index, the first encrypted trapdoor, and the encrypted image library, and sends the target image to the second device. Therefore, the role value received by the cloud server is the first encrypted role value, not the plaintext role value, thus avoiding the privacy leakage problem that may be caused by uploading plaintext roles. Furthermore, this application proposes a lightweight access control strategy, which can verify the identity information of the first user role corresponding to the first encrypted role value. The cloud server can determine whether the first user role corresponding to the first encrypted role value is a first legitimate user role based on the first encrypted role value and the first role polynomial function. If the first user role is verified to be a first legitimate user role, the target image can be determined based on the encrypted index, the first encrypted trapdoor, and the encrypted image library. This can prevent malicious users from accessing the system, further avoid the image privacy leakage problem, and thus improve the security of image retrieval.
[0101] Example 2
[0102] Based on the above embodiments, another embodiment of this application provides an image retrieval method, which is applied to a first device. Figure 2This is a schematic diagram of the image retrieval method proposed in the embodiments of this application. Figure 2 ,like Figure 2 As shown, an image retrieval method may include the following steps:
[0103] Step 201: Determine the encrypted user role set based on the set of legitimate user roles corresponding to the image set.
[0104] In embodiments of this application, the first device may determine the encrypted user role set based on the set of legitimate user roles corresponding to the image set.
[0105] It should be noted that, in the embodiments of this application, the first device may be the physical device corresponding to the image owner, and this application does not specifically limit the type of the first device.
[0106] For example, in an embodiment of this application, it is assumed that the role of user i can be represented by an integer v. i The set of legal user roles corresponding to the image set can be represented as ε = {v1, v2, ..., v...}. m}, where m represents the total number of users who can access the data set.
[0107] For example, in an embodiment of this application, after determining the set of legitimate user roles corresponding to the image set, the first device can encrypt the set of legitimate user roles to generate an encrypted set of user roles. Where g represents a random integer.
[0108] Step 202: Determine the first role polynomial function based on the encrypted user role set.
[0109] In the embodiments of this application, after determining the encrypted user role set based on the set of legal user roles corresponding to the image set, the first device can determine the first role polynomial function based on the encrypted user role set.
[0110] For example, in an embodiment of this application, the first device generates an encrypted user role set. Then, it can be based on the encrypted user role set. The first role polynomial function is determined as shown in the above formula (1).
[0111] It should be noted that, in the embodiments of this application, the first device can determine N corresponding feature vectors based on N images in the image set; where N is a positive integer; then it can determine N encrypted index vectors based on the N feature vectors; and further, it can determine an encrypted index based on the N encrypted index vectors.
[0112] For example, in an embodiment of this application, the first device can determine N corresponding feature vectors f based on N images in the image set. i =(f i,1 ,f i,2 ,...,f i,l ), i represents the sequence number of the image in the image library, l represents the dimension of the feature, and then N feature vectors can be used to determine N encrypted index vectors, and then the encrypted index can be determined based on the N encrypted index vectors. The encrypted index can be represented by the above formula (2).
[0113] It should be noted that, in the embodiments of this application, when a second legitimate user role is added, the first device can determine a third encrypted role value based on the second legitimate user role; then it can determine a first role function based on the third encrypted role value; when a third legitimate user role is reduced, the first device can determine a fourth encrypted role value based on the third legitimate user role; then it can determine a second role function based on the fourth encrypted role value; and then it can send role function information to the cloud server; wherein, the role function information includes the first role function and / or the second role function.
[0114] For example, in an embodiment of this application, when adding a second legitimate user role, assume the added second legitimate user role is v. new The first device can be based on the second legitimate user role v new Determine the third encrypted role value Then the first role function can be determined based on the third encrypted role value, and the first role function is shown in the following formula (8).
[0115]
[0116] in, This represents the third encrypted role value, where v represents the user's role.
[0117] For example, in an embodiment of this application, when reducing the number of third legitimate user roles, it is assumed that the reduced third legitimate user role is v. r The first device can be based on a third legitimate user role v r Determine the fourth encrypted role value Then the second role function can be determined based on the fourth encrypted role value, and the second role function is shown in the following formula (9).
[0118]
[0119] in, This represents the fourth encrypted role value, where v represents the user's role.
[0120] Step 203: Send the first role polynomial function, the encrypted index, and the encrypted image library to the cloud server so that the cloud server can determine the target image based on the first role polynomial function, the encrypted index, and the encrypted image library.
[0121] In the embodiments of this application, after the first device determines the first role polynomial function based on the encrypted user role set, it can send the first role polynomial function, the encrypted index, and the encrypted image library to the cloud server, so that the cloud server can determine the target image based on the first role polynomial function, the encrypted index, and the encrypted image library.
[0122] It should be noted that, in the embodiments of this application, the first device may use an image encryption algorithm to encrypt the image library. The encryption algorithm may be an Advanced Encryption Standard (AES) algorithm. This application does not specifically limit the type of image encryption algorithm.
[0123] In summary, the first device can first determine the set of legitimate user roles for the image set, and then determine the encrypted user role set based on the set of legitimate user roles corresponding to the image set; furthermore, it can determine the first role polynomial function based on the encrypted user role set. That is, when generating the first role polynomial function, this application can encrypt the set of legitimate user roles and send the first role polynomial function, the encrypted index, and the encrypted image library to the cloud server, so that the cloud server can determine the target image based on the first role polynomial function, the encrypted index, and the encrypted image library.
[0124] This application provides an image retrieval method applied to a first device. The first device determines an encrypted user role set based on a set of legitimate user roles corresponding to an image set; determines a first role polynomial function based on the encrypted user role set; and sends the first role polynomial function, an encrypted index, and an encrypted image library to a cloud server, so that the cloud server can determine the target image based on the first role polynomial function, the encrypted index, and the encrypted image library. Therefore, the first device can determine the encrypted user role set based on the set of legitimate user roles corresponding to an image set; then it can determine the first role polynomial function based on the encrypted user role set. That is, when generating the first role polynomial function, this application can encrypt the set of legitimate user roles, thereby ensuring the privacy of user roles, and then send the first role polynomial function, the encrypted index, and the encrypted image library to the cloud server, so that the cloud server can determine the target image based on the first role polynomial function, the encrypted index, and the encrypted image library.
[0125] Example 3
[0126] Based on the above embodiments, another embodiment of this application provides an image retrieval method, which is applied to a cloud server and a first device. Figure 3 This is a schematic diagram of the image retrieval method proposed in the embodiments of this application. Figure 3 ,like Figure 3 As shown, an image retrieval method may include the following steps:
[0127] Step 301: The first device determines the encrypted user role set based on the set of legitimate user roles corresponding to the image set.
[0128] It should be noted that, in the embodiments of this application, the first device may be the physical device corresponding to the image owner, and this application does not specifically limit the type of the first device.
[0129] For example, in an embodiment of this application, it is assumed that the role of user i can be represented by an integer v. i The set of legal user roles corresponding to the image set can be represented as ε = {v1, v2, ..., v...}. m}, where m represents the total number of users who can access the data set.
[0130] For example, in an embodiment of this application, after determining the set of legitimate user roles corresponding to the image set, the first device can encrypt the set of legitimate user roles to generate an encrypted set of user roles. Where g represents a random integer.
[0131] Step 302: The first device determines the first role polynomial function based on the encrypted user role set.
[0132] For example, in an embodiment of this application, the first device generates an encrypted user role set. Then, it can be based on the encrypted user role set. The first role polynomial function is determined as shown in the above formula (1).
[0133] It should be noted that, in the embodiments of this application, the first device can determine N corresponding feature vectors based on N images in the image set; where N is a positive integer; then it can determine N encrypted index vectors based on the N feature vectors; and further, it can determine an encrypted index based on the N encrypted index vectors.
[0134] For example, in an embodiment of this application, the first device can determine N corresponding feature vectors f based on N images in the image set. i =(f i,1 ,f i,2 ,...,f i,l), i represents the sequence number of the image in the image library, l represents the dimension of the feature, and then N feature vectors can be used to determine N encrypted index vectors, and then the encrypted index can be determined based on the N encrypted index vectors. The encrypted index can be represented by the above formula (2).
[0135] It should be noted that, in the embodiments of this application, when a second legitimate user role is added, the first device can determine a third encrypted role value based on the second legitimate user role; then it can determine a first role function based on the third encrypted role value; when a third legitimate user role is reduced, the first device can determine a fourth encrypted role value based on the third legitimate user role; then it can determine a second role function based on the fourth encrypted role value; and then it can send role function information to the cloud server; wherein, the role function information includes the first role function and / or the second role function.
[0136] For example, in an embodiment of this application, when adding a second legitimate user role, assume the added second legitimate user role is v. new The first device can be based on the second legitimate user role v new Determine the third encrypted role value Then the first role function can be determined based on the third encrypted role value, and the first role function is shown in the above formula (8).
[0137] For example, in an embodiment of this application, when reducing the number of third legitimate user roles, it is assumed that the reduced third legitimate user role is v. r The first device can be based on a third legitimate user role v r Determine the fourth encrypted role value Then the second role function can be determined based on the fourth encrypted role value, and the second role function is shown in the above formula (9).
[0138] Step 303: The first device sends the first role polynomial function, the encrypted index, and the encrypted image library to the cloud server, so that the cloud server can determine the target image based on the first role polynomial function, the encrypted index, and the encrypted image library.
[0139] It should be noted that, in the embodiments of this application, the first device may use an image encryption algorithm to encrypt the image library. The encryption algorithm may be an Advanced Encryption Standard (AES) algorithm. This application does not specifically limit the type of image encryption algorithm.
[0140] Step 304: The cloud server receives the first image retrieval request sent by the second device; wherein the first image retrieval request carries a first encrypted trapdoor and a first encrypted role value.
[0141] It should be noted that in the embodiments of this application, the second device may be a user device, and this application does not specifically limit the type of the second device.
[0142] It should be noted that, in the embodiments of this application, the encryption trapdoor can be represented by the above formula (3).
[0143] It should be noted that, in the embodiments of this application, the first encrypted role value can be obtained by encrypting the user's role. For example, the user's role v can be encrypted to generate the first encrypted role value g. v .
[0144] Step 305: The cloud server determines whether the first user role corresponding to the first encrypted role value is the first legitimate user role based on the first encrypted role value and the first role polynomial function.
[0145] It should be noted that, in the embodiments of this application, when the cloud server determines whether the first user role corresponding to the first encrypted role value is a first legitimate user role based on the first encrypted role value and the first role polynomial function, it can input the first encrypted role value into the first role polynomial function to obtain an output value; if the output value is a first preset value, the first user role is determined to be a first legitimate user role; if the output value is not the first preset value, the first user role is determined not to be a first legitimate user role.
[0146] It should be noted that in the embodiments of this application, the first preset value can be 0, and this application does not specifically limit the size of the first preset value.
[0147] For example, in an embodiment of this application, it is assumed that the value of the first encryption role is... The first encrypted role value is input into the first role polynomial function, i.e., the above formula (1), to obtain the output value; if the output value is 0, the first user role is determined to be the first legal user role; if the output value is not 0, the first user role is determined to be the first legal user role.
[0148] In other words, in the embodiments of this application, the cloud server can verify the user role. If the user role belongs to a legitimate user, the image retrieval operation is allowed to continue; if the user is not a legitimate user, the image retrieval operation is not allowed to continue. This can prevent malicious users from impersonating legitimate users to access the system and steal images from image owners, thus avoiding image privacy leaks.
[0149] It should be noted that, in the embodiments of this application, after the cloud server determines whether the first user role corresponding to the first encrypted role value is a first legitimate user role based on the first encrypted role value and the first role polynomial function, it can determine the second role polynomial function based on a preset random number and the first role polynomial function.
[0150] It should be noted that, in the embodiments of this application, the preset random number can be any positive integer, and this application does not specifically limit the size of the preset random number.
[0151] It should be noted that, in the embodiments of this application, the second role polynomial function can be represented by the above formula (4).
[0152] It should be noted that, in the embodiments of this application, the cloud server uses a preset random number to reset the first role polynomial function, so that the role polynomial function is updated with each query, thereby preventing attackers from stealing the legitimate user set based on the role polynomial function.
[0153] It should be noted that, in the embodiments of this application, the cloud server can also receive a second image retrieval request sent by the second device; wherein, the second image retrieval request carries a second encryption trapdoor and a second encryption role value; based on the second encryption role value and the second role polynomial function, it is determined whether the second user role corresponding to the second encryption role value is a first legitimate user role; if the second user role is a first legitimate user role, the target image is determined based on the encryption index, the second encryption trapdoor, and the encryption image library.
[0154] In other words, in the embodiments of this application, after receiving the second image retrieval request sent by the second device, the cloud server can determine whether the second user role corresponding to the second encrypted role value is the first legitimate user role based on the updated second role polynomial function and the second encrypted role value.
[0155] Step 306: If the first user role is the first legitimate user role, the cloud server determines the target image based on the encrypted index, the first encrypted trapdoor, and the encrypted image library, and sends the target image to the second device.
[0156] It should be noted that, in the embodiments of this application, the encrypted index includes N encrypted index vectors, where N is a positive integer, and this application does not impose a specific limit on the number of encrypted index vectors.
[0157] It should be noted that, in the embodiments of this application, when the cloud server determines the target image based on the encrypted index, the first encrypted trapdoor, and the encrypted image library, it can determine the target encrypted index vector based on the first encrypted trapdoor and N encrypted index vectors; then it can determine the target image based on the target encrypted index vector and the encrypted image library.
[0158] For example, in an embodiment of this application, the cloud server can calculate the product of the first encryption trapdoor and N encryption index vectors. The image corresponding to the encryption index with the smallest product (target encryption index) is the image that the user is interested in, i.e., the target image. The calculation formula is as shown in the formula (5) above.
[0159] It should be noted that, in the embodiments of this application, the cloud server can receive role function information sent by the first device; wherein, the role function information includes a first role function and / or a second role function; and then the first role polynomial function can be updated based on the role function information.
[0160] It should be noted that, in the embodiments of this application, the first role function can be a function generated based on the newly added user role.
[0161] It should be noted that, in the embodiments of this application, the second role function can be a function generated based on the reduced user roles.
[0162] For example, in an embodiment of this application, it is assumed that after the cloud server receives the first role function sent by the first device, it can update the first role polynomial function based on the first role function. The updated role polynomial function is as shown in the above formula (6).
[0163] For example, in an embodiment of this application, it is assumed that after the cloud server receives the second role function sent by the first device, it can update the first role polynomial function based on the second role function. The updated role polynomial function is as shown in the above formula (7).
[0164] In other words, in the embodiments of this application, the cloud server can update the first role polynomial function based on the received role function information, without the first device having to regenerate the role polynomial function and upload it to the cloud server, thereby reducing the burden on the first device.
[0165] In summary, after receiving the encrypted index, first role polynomial function, and encrypted image library from the first device, and the first image retrieval request from the second device (where the first image retrieval request carries a first encrypted trapdoor and a first encrypted role value), the cloud server can determine whether the first user role corresponding to the first encrypted role value is a legitimate user role based on the first encrypted role value and the first role polynomial function. That is, the cloud server can verify the user role; if the user role is legitimate, the image retrieval operation is allowed to continue; if the user is not legitimate, the image retrieval operation is not allowed to continue. This prevents malicious users from impersonating legitimate users to access the system and steal images from image owners, thus avoiding image privacy leaks. The cloud server can also receive role function information from the first device, including a first role function and / or a second role function. It can then update the first role polynomial function based on the role function information without requiring the first device to regenerate the role polynomial function and upload it to the cloud server, thereby reducing the burden on the first device.
[0166] This application provides an image retrieval method applied to a cloud server and a first device. The cloud server receives an encrypted index, a first role polynomial function, and an encrypted image library sent by the first device; it also receives a first image retrieval request sent by a second device. The first image retrieval request carries a first encrypted trapdoor and a first encrypted role value. Based on the first encrypted role value and the first role polynomial function, the method determines whether the first user role corresponding to the first encrypted role value is a first legitimate user role. If the first user role is a first legitimate user role, the method determines a target image based on the encrypted index, the first encrypted trapdoor, and the encrypted image library, and sends the target image to the second device. The first device determines an encrypted user role set based on the set of legitimate user roles corresponding to the image set; it determines a first role polynomial function based on the encrypted user role set; and it sends the first role polynomial function, the encrypted index, and the encrypted image library to the cloud server, so that the cloud server determines the target image based on the first role polynomial function, the encrypted index, and the encrypted image library. Therefore, the role value received by the cloud server is the first encrypted role value, not the plaintext role value, thus avoiding the privacy leakage problem that may be caused by uploading plaintext roles. Furthermore, this application proposes a lightweight access control strategy, which can verify the identity information of the first user role corresponding to the first encrypted role value. The cloud server can determine whether the first user role corresponding to the first encrypted role value is a first legitimate user role based on the first encrypted role value and the first role polynomial function. If the first user role is verified to be a first legitimate user role, the target image can be determined based on the encrypted index, the first encrypted trapdoor, and the encrypted image library. This can prevent malicious users from accessing the system, further avoid the image privacy leakage problem, and thus improve the security of image retrieval.
[0167] Example 4
[0168] Based on the above embodiments, another embodiment of this application provides an image retrieval method, which is applied to an image retrieval system model. Figure 4 This is a schematic diagram of the image retrieval system model proposed in the embodiments of this application, such as... Figure 4 As shown, the image retrieval system model comprises four entities: a cloud server, an image owner (first device), and a user (second device). The image owner (first device) owns an image database, encrypts it, and uploads it to the cloud server. It generates an encrypted index based on the images and uploads it to the cloud server. It sets access control policies for the system, generates a role polynomial (first role polynomial function), and uploads it to the cloud server to determine user access permissions. The cloud server stores the encrypted database and encrypted index. It executes image retrieval tasks and returns the final query results to the user (second device). The user generates an encrypted trapdoor (first encrypted trapdoor) based on the query image and uploads it to the cloud server. After the cloud server executes the image retrieval task, the user decrypts the image to obtain the image of interest (target image).
[0169] It should be noted that, in the embodiments of this application, Figure 5 This is a schematic diagram of the image retrieval method proposed in the embodiments of this application. Figure 4 ,like Figure 5 As shown, the image retrieval method may include the following steps: Step 401: The image owner (first device) generates an encrypted role set (encrypted user role set) based on the legitimate user set (legitimate user role set), generates a role polynomial (first role polynomial function), an encrypted index, and an encrypted image library, and uploads them to the cloud server; Step 402: The user generates and uploads an encrypted trapdoor (first encrypted trapdoor) and an encrypted role (first encrypted role value) to the cloud server; Step 403: The cloud server verifies the identity of the user (the first user role corresponding to the first encrypted role value) based on the user role (first encrypted role value) and the role polynomial (first role polynomial function). If the verification is successful, proceed to Step 404: The cloud server finds the image (target image) of interest to the user based on the encrypted trapdoor (first encrypted trapdoor) and the encrypted index, and sends it to the user; Step 405: The user decrypts the image to obtain the plaintext image; if the verification fails, proceed to Step 406: The retrieval ends.
[0170] It should be noted that, in the embodiments of this application, the process executed by the image owner (first device) is as follows: Step 1: Generate a role-based polynomial function (first role polynomial function). Assume that the role of user i can be represented by an integer v. iRepresentation. Suppose that the set of legal roles (legal user roles) of a selectable image set is represented as ε = {v1, v2, ..., v...} m} where m represents the total number of users who can access the dataset. A user only has permission to access the dataset if their role belongs to that set. The user role set is encrypted to generate an encrypted role set (encrypted user role set). Where g represents a random integer. For a selectable image set, its access control policy role polynomial (first role polynomial function) is as shown in formula (1) above; further, the coefficient set of the role polynomial is represented as {c0,c1,c2,...,c...} m Step 2: Generate an unencrypted index (plaintext index), and the image owner (first device) extracts image m from the image library. i Based on the characteristics, the feature vector f is obtained. i =(f i,1 ,f i,2 ,...,f i,l ), where i represents the image number in the image library and l represents the dimension of the feature; Step 3: The image owner generates an encrypted index, which can be represented by the above formula (2); Step 4: Encrypt the image library using an image encryption algorithm, such as the AES encryption algorithm, and upload the encrypted image library, encrypted index, and role-based polynomial function (first role polynomial function) to the cloud server.
[0171] It should be noted that, in the embodiments of this application, the process executed by the user (second device) is as follows: Step 1: Encrypt the user's role v to generate the encrypted role g for querying the user. v (First encrypted role value); Step 2: Generate an unencrypted trapdoor (plaintext trapdoor), and the user extracts the query image q. i Based on the characteristics, the feature vector q is obtained. i =(q1,q2,...,q l ), where l represents the dimension of the feature; Step 3: The user generates an encryption trapdoor, which can be represented by the above formula (3); Step 4: Combine the encryption trapdoor and the encryption role g v (The first encrypted role value) is uploaded to the cloud server together.
[0172] It should be noted that in the embodiments of this application, the cloud server executes the following process: Step 1: Role verification: The cloud server verifies the user's identity based on the user's role. The user's role value (first encrypted role value) is used as input and input into the role polynomial function. The first role polynomial function can be represented by the above formula (1). If the output is 0 (first preset value), it means that the user (first user role) is a legitimate user and is allowed to continue the image retrieval operation; otherwise, the user (first user role) is not a legitimate user and is not allowed to continue the image retrieval operation. After verification, the cloud generates a random number m (preset random number) and uses the random number to reset the polynomial function (first role polynomial function) so that the polynomial function is updated for each query, preventing attackers from stealing the legitimate user set based on the polynomial function. The new polynomial function (second role polynomial function) is represented by the above formula (4); Step 2: Similarity comparison: The cloud server calculates the product of all encrypted trapdoors (first encrypted trapdoors) and encrypted indexes. The image corresponding to the encrypted index (target encrypted index vector) with the smallest product is the image (target image) that the user is interested in, i.e., the query result; where, calculating the encrypted trapdoors and a certain encrypted index The product of the two is calculated as shown in formula (5) above. Step 3: The cloud server returns the query results to the user, and the user decrypts the plaintext image.
[0173] It should be noted that, in the embodiments of this application, the encrypted index includes N encrypted index vectors, where N is a positive integer, and this application does not impose a specific limit on the number of encrypted index vectors.
[0174] It should be noted that, in the embodiments of this application, the comparison relationship between the Euclidean distance of the plaintext trapdoor and the plaintext index is shown in the following formula (10). Since β>0 and α>0, it can be seen that... Equivalent to dist 2 (f i ,q) <dist 2 (f j Therefore, the smaller the product of the encrypted trapdoor and the encrypted index, the smaller the Euclidean distance between the plaintext trapdoor and the plaintext index, and the more similar the image corresponding to the plaintext index is to the query image.
[0175]
[0176] It should be noted that, in the embodiments of this application, a role polynomial update method is provided when a legitimate role is added or removed. The work of the target owner (first device): When a legitimate role (second legitimate user role) is added, assuming the role of the newly added user (second legitimate user role) is represented as v... newThen the image owner generates the first role function, which is shown in the above formula (8), and uploads it to the cloud server; when the number of legitimate roles (third legitimate user roles) decreases, assuming the role of the user to be reduced (third legitimate user role) is represented as v r Then the image owner generates a second role function, as shown in formula (9) above, and uploads it to the cloud server. The cloud server works as follows: when a legal role is added, the new role polynomial (the updated role polynomial function) is as shown in formula (6) above; when a legal role is reduced, the new role polynomial (the updated role polynomial function) is as shown in formula (7) above.
[0177] In summary, after receiving the encrypted index, first role polynomial function, and encrypted image library from the first device, and the first image retrieval request from the second device (where the first image retrieval request carries a first encrypted trapdoor and a first encrypted role value), the cloud server can determine whether the first user role corresponding to the first encrypted role value is a legitimate user role based on the first encrypted role value and the first role polynomial function. That is, the cloud server can verify the user role; if the user role is legitimate, the image retrieval operation is allowed to continue; if the user is not legitimate, the image retrieval operation is not allowed to continue. This prevents malicious users from impersonating legitimate users to access the system and steal images from image owners, thus avoiding image privacy leaks. The cloud server can also receive role function information from the first device, including a first role function and / or a second role function. It can then update the first role polynomial function based on the role function information without requiring the first device to regenerate the role polynomial function and upload it to the cloud server, thereby reducing the burden on the first device.
[0178] This application provides an image retrieval method applied to a cloud server and a first device. The cloud server receives an encrypted index, a first role polynomial function, and an encrypted image library sent by the first device; it also receives a first image retrieval request sent by a second device. The first image retrieval request carries a first encrypted trapdoor and a first encrypted role value. Based on the first encrypted role value and the first role polynomial function, the method determines whether the first user role corresponding to the first encrypted role value is a first legitimate user role. If the first user role is a first legitimate user role, the method determines a target image based on the encrypted index, the first encrypted trapdoor, and the encrypted image library, and sends the target image to the second device. The first device determines an encrypted user role set based on the set of legitimate user roles corresponding to the image set; it determines a first role polynomial function based on the encrypted user role set; and it sends the first role polynomial function, the encrypted index, and the encrypted image library to the cloud server, so that the cloud server determines the target image based on the first role polynomial function, the encrypted index, and the encrypted image library. Therefore, the role value received by the cloud server is the first encrypted role value, not the plaintext role value, thus avoiding the privacy leakage problem that may be caused by uploading plaintext roles. Furthermore, this application proposes a lightweight access control strategy, which can verify the identity information of the first user role corresponding to the first encrypted role value. The cloud server can determine whether the first user role corresponding to the first encrypted role value is a first legitimate user role based on the first encrypted role value and the first role polynomial function. If the first user role is verified to be a first legitimate user role, the target image can be determined based on the encrypted index, the first encrypted trapdoor, and the encrypted image library. This can prevent malicious users from accessing the system, further avoid the image privacy leakage problem, and thus improve the security of image retrieval.
[0179] Example 5
[0180] Based on the above embodiments, this application provides a cloud server. Figure 6 A schematic diagram of the cloud server's structure. Figure 1 ,like Figure 6 As shown, the cloud server 10 includes: a receiving unit 11, a judging unit 12, a first determining unit 13, and a first sending unit 14;
[0181] The receiving unit 11 is used to receive the encrypted index, the first role polynomial function, and the encrypted image library sent by the first device;
[0182] The receiving unit 11 is further configured to receive a first image retrieval request sent by the second device; wherein the first image retrieval request carries a first encryption trapdoor and a first encryption role value;
[0183] The judgment unit 12 is used to determine whether the first user role corresponding to the first encrypted role value is a first legitimate user role based on the first encrypted role value and the first role polynomial function.
[0184] The first determining unit 13 is used to determine the target image based on the encrypted index, the first encrypted trapdoor, and the encrypted image library when the first user role is the first legitimate user role;
[0185] The first sending unit 14 is used to send the target image to the second device.
[0186] In the embodiments of this application, further, Figure 7 A schematic diagram of the cloud server's structure. Figure 2 ,like Figure 7 As shown, the cloud server 10 proposed in this application embodiment may further include a first processor 15, a first memory 16 storing instructions executable by the first processor 15, and further, the cloud server 10 may further include a first communication interface 17 and a first bus 18 for connecting the first processor 15, the first memory 16 and the first communication interface 17.
[0187] In the embodiments of this application, the first processor 15 can be at least one of the following: Application-Specific Integrated Circuit (ASIC), Digital Signal Processor (DSP), Digital Signal Processing Device (DSPD), Programmable Logic Device (PLD), Field Programmable Gate Array (FPGA), Central Processing Unit (CPU), Controller, Microcontroller, and Microprocessor. It is understood that for different devices, the electronic device used to implement the above-mentioned processor function can also be other types, and this application embodiment does not specifically limit this. The cloud server 10 may also include a first memory 16, which can be connected to the first processor 15. The first memory 16 is used to store executable program code, which includes computer operation instructions. The first memory 16 may include high-speed RAM memory and may also include non-volatile memory, such as at least two disk drives.
[0188] In embodiments of this application, the first bus 18 is used to connect the first communication interface 17, the first processor 15, and the first memory 16, as well as the mutual communication between these devices.
[0189] In embodiments of this application, the first memory 16 is used to store instructions and data.
[0190] Furthermore, in the embodiments of this application, the first processor 15 is configured to: receive an encrypted index, a first role polynomial function, and an encrypted image library sent by a first device; receive a first image retrieval request sent by a second device; wherein the first image retrieval request carries a first encrypted trapdoor and a first encrypted role value; determine whether the first user role corresponding to the first encrypted role value is a first legitimate user role based on the first encrypted role value and the first role polynomial function; if the first user role is the first legitimate user role, determine a target image based on the encrypted index, the first encrypted trapdoor, and the encrypted image library, and send the target image to the second device.
[0191] In practical applications, the first memory 16 can be volatile memory, such as random-access memory (RAM); or non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid-state drive (SSD); or a combination of the above types of memory, and provide instructions and data to the first processor 15.
[0192] This application provides a cloud server that receives an encrypted index, a first role polynomial function, and an encrypted image library from a first device; receives a first image retrieval request from a second device; wherein the first image retrieval request carries a first encrypted trapdoor and a first encrypted role value; determines whether the first user role corresponding to the first encrypted role value is a first legitimate user role based on the first encrypted role value and the first role polynomial function; if the first user role is the first legitimate user role, determines a target image based on the encrypted index, the first encrypted trapdoor, and the encrypted image library, and sends the target image to the second device. Therefore, the role value received by the cloud server is the first encrypted role value, not the plaintext role value, thus avoiding the privacy leakage problem that may be caused by uploading plaintext roles. Furthermore, this application proposes a lightweight access control strategy, which can verify the identity information of the first user role corresponding to the first encrypted role value. The cloud server can determine whether the first user role corresponding to the first encrypted role value is a first legitimate user role based on the first encrypted role value and the first role polynomial function. If the first user role is verified to be a first legitimate user role, the target image can be determined based on the encrypted index, the first encrypted trapdoor, and the encrypted image library. This can prevent malicious users from accessing the system and further avoid the problem of image privacy leakage.
[0193] This application provides a computer-readable storage medium storing a program thereon, which, when executed by a processor, implements the image retrieval method described above.
[0194] Specifically, the program instructions corresponding to an image retrieval method in this embodiment can be stored on storage media such as optical discs, hard disks, and USB flash drives. When the program instructions corresponding to an image retrieval method in the storage media are read or executed by an electronic device, the following steps are included:
[0195] Receive the encrypted index, the first role polynomial function, and the encrypted image library sent by the first device;
[0196] Receive a first image retrieval request sent by a second device; wherein the first image retrieval request carries a first encrypted trapdoor and a first encrypted role value;
[0197] Based on the first encrypted role value and the first role polynomial function, determine whether the first user role corresponding to the first encrypted role value is a first legitimate user role;
[0198] If the first user role is the first legitimate user role, the target image is determined based on the encrypted index, the first encrypted trapdoor, and the encrypted image library, and the target image is sent to the second device.
[0199] In the embodiments of this application, further, Figure 8 Schematic diagram of the composition structure of the first device Figure 1 ,like Figure 8 As shown, the first device 20 includes: a second determining unit 21 and a second sending unit 22;
[0200] The second determining unit 21 is used to determine an encrypted user role set based on a legitimate user role set;
[0201] The second determining unit 21 is further configured to determine a first role polynomial function based on the encrypted user role set;
[0202] The second sending unit 22 is used to send the first role polynomial function, the encrypted index, and the encrypted image library to the cloud server, so that the cloud server can determine the target image based on the first role polynomial function, the encrypted index, and the encrypted image library.
[0203] In the embodiments of this application, further, Figure 9 Schematic diagram of the composition structure of the first device Figure 2 ,like Figure 9 As shown, the first device 20 proposed in this application embodiment may further include a second processor 23, a second memory 24 storing instructions executable by the second processor 23, and further, the first device 20 may further include a second communication interface 25 and a second bus 26 for connecting the second processor 23, the second memory 24 and the second communication interface 25.
[0204] In the embodiments of this application, the second processor 23 can be at least one of the following: Application-Specific Integrated Circuit (ASIC), Digital Signal Processor (DSP), Digital Signal Processing Device (DSPD), Programmable Logic Device (PLD), Field-Programmable Gate Array (FPGA), Central Processing Unit (CPU), Controller, Microcontroller, and Microprocessor. It is understood that for different devices, the electronic device used to implement the above-mentioned processor function can also be other types, and this application embodiment does not specifically limit the specific types. The first device 20 may further include a second memory 24, which can be connected to the second processor 23. The second memory 24 is used to store executable program code, which includes computer operation instructions. The second memory 24 may include high-speed RAM memory and may also include non-volatile memory, such as at least two disk drives.
[0205] In embodiments of this application, the second bus 26 is used to connect the second communication interface 25, the second processor 23, and the second memory 24, as well as the mutual communication between these devices.
[0206] In embodiments of this application, the second memory 24 is used to store instructions and data.
[0207] Furthermore, in an embodiment of this application, the second processor 23 is configured to determine an encrypted user role set based on a set of legitimate user roles corresponding to the image set; determine a first role polynomial function based on the encrypted user role set; and send the first role polynomial function, the encrypted index, and the encrypted image library to a cloud server, so that the cloud server determines the target image based on the first role polynomial function, the encrypted index, and the encrypted image library.
[0208] In practical applications, the aforementioned second memory 24 can be volatile memory, such as random-access memory (RAM); or non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid-state drive (SSD); or a combination of the above types of memory, and provide instructions and data to the second processor 23.
[0209] This application provides a first device that determines an encrypted user role set based on a set of legitimate user roles corresponding to an image set; determines a first role polynomial function based on the encrypted user role set; and sends the first role polynomial function, an encrypted index, and an encrypted image library to a cloud server, so that the cloud server can determine a target image based on the first role polynomial function, the encrypted index, and the encrypted image library. Therefore, the first device can determine an encrypted user role set based on a set of legitimate user roles corresponding to an image set; then it can determine a first role polynomial function based on the encrypted user role set. That is, when generating the first role polynomial function, this application can encrypt the set of legitimate user roles, thereby ensuring the privacy of user roles, and then send the first role polynomial function, the encrypted index, and the encrypted image library to a cloud server, so that the cloud server can determine a target image based on the first role polynomial function, the encrypted index, and the encrypted image library.
[0210] This application provides a computer-readable storage medium storing a program thereon, which, when executed by a processor, implements the image retrieval method described above.
[0211] Specifically, the program instructions corresponding to an image retrieval method in this embodiment can be stored on storage media such as optical discs, hard disks, and USB flash drives. When the program instructions corresponding to an image retrieval method in the storage media are read or executed by an electronic device, the following steps are included:
[0212] Determine the encrypted user role set based on the set of legitimate user roles corresponding to the image set;
[0213] The first role polynomial function is determined based on the encrypted user role set;
[0214] The first role polynomial function, the encrypted index, and the encrypted image library are sent to the cloud server so that the cloud server can determine the target image based on the first role polynomial function, the encrypted index, and the encrypted image library.
[0215] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of hardware embodiments, software embodiments, or embodiments combining software and hardware aspects. Furthermore, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.
[0216] This application is described with reference to schematic and / or block diagrams of implementations of methods, apparatus (systems), and computer program products according to embodiments of this application. It should be understood that each block of the schematic and / or block diagrams can be implemented by computer program instructions, and combinations of blocks in the schematic and / or block diagrams can be implemented. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create a machine for implementing the schematic and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0217] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in the implementation flow diagram. Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0218] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0219] The above description is merely a preferred embodiment of this application and is not intended to limit the scope of protection of this application.
Claims
1. An image retrieval method characterized by, The method is applied to a cloud server, and the method comprises: receiving an encrypted index, a first role polynomial function and an encrypted image library sent by a first device; receiving a first image retrieval request sent by a second device; wherein the first image retrieval request carries a first encrypted trapdoor and a first encrypted role value; determining whether a first user role corresponding to the first encrypted role value is a first legal user role based on the first encrypted role value and the first role polynomial function; wherein the first role polynomial function is determined by the first device based on an encrypted user role set, and the encrypted user role set is determined based on a legal user role set corresponding to an image set; in a case where the first user role is the first legal user role, determining a target image based on the encrypted index, the first encrypted trapdoor and the encrypted image library, and sending the target image to the second device.
2. The method of claim 1, wherein, The determination whether the first user role corresponding to the first encrypted role value is the first legal user role based on the first encrypted role value and the first role polynomial function comprises: inputting the first encrypted role value into the first role polynomial function to obtain an output value; in a case where the output value is a first preset value, determining that the first user role is the first legal user role; in a case where the output value is not the first preset value, determining that the first user role is not the first legal user role.
3. The method according to claim 1 or 2, characterized in that, After the determination whether the first user role corresponding to the first encrypted role value is the first legal user role based on the first encrypted role value and the first role polynomial function, the method further comprises: determining a second role polynomial function based on a preset random number and the first role polynomial function.
4. The method of claim 3, wherein, The method further comprises: receiving a second image retrieval request sent by the second device; wherein the second image retrieval request carries a second encrypted trapdoor and a second encrypted role value; determining whether a second user role corresponding to the second encrypted role value is the first legal user role based on the second encrypted role value and the second role polynomial function; in a case where the second user role is the first legal user role, determining a target image based on the encrypted index, the second encrypted trapdoor and the encrypted image library.
5. The method of claim 1, wherein, The encrypted index comprises N encrypted index vectors, the N being a positive integer, and the determination of the target image based on the encrypted index, the first encrypted trapdoor and the encrypted image library comprises: determining a target encrypted index vector based on the first encrypted trapdoor and the N encrypted index vectors; determining the target image based on the target encrypted index vector and the encrypted image library.
6. The method of claim 1, wherein, The method further comprises: receiving role function information sent by the first device; wherein the role function information comprises a first role function and / or a second role function; updating the first role polynomial function based on the role function information.
7. An image retrieval method characterized by, The method is applied to a first device, and the method comprises: determining an encrypted user role set based on a legal user role set corresponding to an image set; determining a first role polynomial function based on the encrypted user role set; sending the first role polynomial function, the encrypted index, and the encrypted image library to a cloud server, so that the cloud server determines a target image based on the first role polynomial function, the encrypted index, and the encrypted image library; wherein the first role polynomial function is used to determine whether a first user role corresponding to a first encrypted role value is a first legal user role.
8. The method of claim 7, wherein, The method further comprises: determining N feature vectors corresponding to N images in the image set; wherein N is a positive integer; determining N encrypted index vectors based on the N feature vectors; determining the encrypted index based on the N encrypted index vectors.
9. The method of claim 7, wherein, The method further comprises: in the case of adding a second legal user role, determining a third encrypted role value based on the second legal user role; determining a first role function based on the third encrypted role value; in the case of reducing a third legal user role, determining a fourth encrypted role value based on the third legal user role; determining a second role function based on the fourth encrypted role value; sending role function information to the cloud server; wherein the role function information includes the first role function and / or the second role function.
10. A cloud server, characterized by, The cloud server comprises: a receiving unit, a determining unit, a first determining unit, and a first sending unit. The receiving unit is configured to receive the encrypted index, the first role polynomial function, and the encrypted image library sent by the first device. The receiving unit is further configured to receive a first image retrieval request sent by a second device; wherein the first image retrieval request carries a first encrypted trapdoor and a first encrypted role value. The determining unit is configured to determine whether a first user role corresponding to the first encrypted role value is a first legal user role based on the first encrypted role value and the first role polynomial function; wherein the first role polynomial function is determined by the first device based on an encrypted user role set, and the encrypted user role set is determined based on a legal user role set corresponding to an image set. The first determining unit is configured to determine a target image based on the encrypted index, the first encrypted trapdoor, and the encrypted image library in the case that the first user role is the first legal user role. The first sending unit is configured to send the target image to the second device.
11. A cloud server, characterized by The cloud server comprises a first processor and a first memory; wherein The first memory is configured to store a computer program capable of running on the processor; The first processor is configured to execute the method of any one of claims 1-6 when running the computer program.
12. A first device, comprising: The first device comprises a second determining unit and a second sending unit, The second determining unit is configured to determine an encrypted user role set based on a legal user role set; The second determining unit is further configured to determine a first role polynomial function based on the encrypted user role set; The second sending unit is configured to send the first role polynomial function, the encrypted index, and the encrypted image library to a cloud server, so that the cloud server determines a target image based on the first role polynomial function, the encrypted index, and the encrypted image library; wherein the first role polynomial function is used to determine whether a first user role corresponding to a first encrypted role value is a first legal user role.
13. A first device, comprising: The first device comprises a second processor and a second memory; wherein The second memory is configured to store a computer program capable of running on the processor; The second processor is configured to execute the method according to any one of claims 7-9 when the computer program is running.
14. A computer-readable storage medium, characterized in that, The storage medium has computer program code stored thereon, which, when executed by a computer, performs the method according to any one of claims 1-6 or 7-9.
15. A computer program product comprising a computer program, characterized in that, The computer program, when executed by a processor, implements the method according to any one of claims 1-6 or 7-9.
Citation Information
Patent Citations
Searchable image encryption algorithm
CN106875325A
Privacy-protected encrypted image retrieval method and system
CN112528064A