A Multi-User Searchable Encryption Method Resistant to Key Leakage in a Cloud-Edge Collaborative Environment

By building an indexed ciphertext binary search tree and regularly updating keys in a cloud-edge collaborative environment, the problem of key leakage in cloud-edge collaborative computing is solved, and the security and efficient search of multi-user searchable encryption are achieved, improving data privacy protection and system security.

CN119254458BActive Publication Date: 2025-07-04GUANGZHOU HAOXUAN INFORMATION TECHNOLOGY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411199131.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-29
Publication Date
2025-07-04
Estimated Expiration
2044-08-29

AI Technical Summary

Technical Problem

The existing searchable encryption technology fails to effectively prevent key leakage in the cloud-edge collaborative computing environment, resulting in data privacy and security risks, and it is difficult to achieve efficient search for multiple users and multi-tasks.

Method used

The multi-user searchable encryption method is adopted in the cloud-edge collaborative environment, and the system key and bilinear mapping are initialized through trusted authoritative organizations, and the indexed ciphertext binary search tree is built, and the edge server and cloud server cooperate to search data, and the key is updated regularly to resist key exposure, supporting data sharing and permission management of multiple users.

Benefits of technology

It realizes security against key leakage in a cloud-edge collaborative environment, improves data search efficiency, reduces the risks of unauthorized access and data abuse, enhances user privacy protection and data security, and reduces computing and communication delays.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119254458B_ABST
    Figure CN119254458B_ABST
Patent Text Reader

Abstract

The present invention provides a multi-user searchable encryption method resistant to key leakage in a cloud-edge collaborative environment, which relates to the field of multi-user searchable encryption technology. The specific steps include: a trusted authority initializes the system and generates system keys, cyclic groups, generators, and bilinear maps. The data owner encrypts the data and keywords and stores the ciphertext in the cloud server and the auxiliary server. The edge server constructs a binary search tree based on the index ciphertext for data retrieval. The user submits an encrypted search keyword, and the edge server matches and returns the data storage address. If not hit, it is forwarded to the cloud server for global search. After receiving the search results, the user decrypts the ciphertext using the private key and the proxy re-encryption algorithm, and can revoke the user's query permission. The present invention realizes the feature of resisting key leakage, enhances the security of the system, and the innovative global search structure improves the search efficiency, supports multi-user search and permission revocation, and enhances data security and privacy protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of multi - user searchable encryption, and particularly to a multi - user searchable encryption method for resisting key leakage in a cloud - edge collaborative environment. Background Technique

[0002] With the rapid development of Internet of Things technology, the massive amount of data generated can no longer be processed solely by cloud computing. Therefore, cloud - edge collaborative computing has emerged. Through the cooperation between cloud servers and edge servers, communication latency is effectively reduced, and the problems of computing and storing massive data are solved. However, this model also raises data security and privacy issues. Since cloud servers and edge servers may be subject to internal or external attacks and are not completely trustworthy, it may lead to the leakage of user data privacy. To ensure data security and privacy, users choose to encrypt their data before outsourcing storage. However, although data encryption ensures privacy security, it complicates the retrieval operation. For this reason, searchable encryption technology has been proposed, aiming to achieve the function of effectively searching encrypted data without sacrificing data privacy.

[0003] Although searchable encryption technology provides an important technology for data privacy protection, most current solutions are mainly designed for cloud computing environments and do not meet the special requirements of cloud - edge collaborative computing. These solutions only support single - user queries, while cloud - edge - end collaborative computing involves multiple users and multiple tasks. In a multi - user environment, protecting the data privacy of each user becomes more complex. It is necessary to ensure the confidentiality of user data during transmission and storage, preventing data leakage to unauthorized users or third parties. At the same time, in the face of untrusted cloud servers and edge devices, it is difficult to achieve global high - efficiency search and other problems. Therefore, inventing a multi - user searchable encryption method for the cloud - edge collaborative environment that can achieve privacy protection and support multi - user, multi - task, and real - time response has become an urgent challenge in the field of privacy protection.

[0004] The searchable encryption technology was first proposed by Song et al. in "Practical techniques for searches on encrypted data", thus opening up a new research direction in the field of cryptography. Since then, the searchable encryption technology has gradually become a research hotspot. For example, Boneh et al. proposed a public key encryption with keyword search (PEKS) in "Public key encryption with keyword search". Baek et al. proposed a new scheme in "Public key encryption with keyword search revisited", which eliminated the dependence of PEKS on a secure channel. However, Rahee et al. pointed out in "Improved searchable public key encryption with designated tester" that the scheme of Baek et al. has problems of low efficiency of the security model and limited adversary capabilities. Therefore, Rahee et al. redesigned the security model, introduced the concept of trapdoor indistinguishability, and at the same time proved that their scheme can resist offline keyword guessing attacks. Most of these schemes are applicable to single-user scenarios, which limits the wide application of searchable encryption technology in the cloud computing environment. To support multi-user data sharing, Wang et al. proposed a forward-secure multi-user searchable encryption scheme in "Multi-user forward secure dynamic searchable symmetric encryption". Their scheme achieved key sharing among multiple users by introducing a semi-trusted proxy server. To reduce the storage overhead of users, Zhang et al. constructed a multi-user searchable encryption scheme that saves storage space using key hiding technology in "Non-interactive multi-client searchable symmetric encryption with small client storage". Nevertheless, these schemes cannot be directly applied to the architecture based on cloud-edge collaborative computing.

[0005] Recently, Zhang et al. proposed a privacy-preserving encrypted search method for edge-cloud collaboration in IoT in the paper "Efficient and privacy-preserving search over edge-cloud collaborative entity in IoT". To meet the personalized search needs of users, this method designed a secure search architecture and search method for edge-cloud collaboration that supports diverse user requirements (such as real-time search and global search). Gao et al. constructed a searchable encryption scheme that supports fine-grained access control in the paper "Blockchain-enabled fine-grained searchable encryption with cloud-edge computing for electronic health records sharing" by combining blockchain technology, realizing multi-user secure retrieval in the cloud-edge-end collaborative architecture. Aiming at the verification problem of search results, Zhang et al. constructed a secure and verifiable data search scheme for cloud-assisted edge computing by combining blockchain and hash technology in the paper "A secure and verifiable multimedia data search scheme for cloud-assisted edge computing" and applied it to multimedia data search.

[0006] In summary, although existing searchable encryption schemes can provide search functions while ensuring data privacy, the risk of user key leakage has not been fully emphasized in these schemes. In actual operation, due to inadequate security measures or users' lack of security awareness, the risk of key leakage is extremely high. Once the key is leaked, all security protection measures will become ineffective, and the encrypted retrieval system will face the threat of collapse. More seriously, users often have difficulty realizing the leakage of the key, which may cause the threat brought by key exposure to persist for a long time, resulting in serious and irreparable losses. Therefore, it is particularly important and urgent to actively prevent user key leakage and design a multi-user searchable encryption method applicable to the cloud-edge collaboration environment with anti-key leakage characteristics. Summary of the Invention

[0007] The purpose of the present invention is to provide a multi-user searchable encryption method with anti-key leakage in a cloud-edge collaborative environment to solve the problems raised in the above background technology.

[0008] To achieve the above purpose, the present invention provides the following technical solutions:

[0009] A multi-user searchable encryption method resistant to key leakage in a cloud-edge collaborative environment, the specific steps comprising:

[0010] S1. The trusted authority initializes the system and generates the system's key, two p-order multiplication cyclic groups, generators, bilinear mappings, and one-way and collision-resistant hash functions. The data owner provides authorization to users who need to search and generates corresponding search keys and auxiliary search keys.

[0011] S2. The data owner encrypts the data and its keywords, and outsources the encrypted ciphertext to the auxiliary server and cloud server for storage and management. After receiving the ciphertext, the cloud server stores it and sends the storage address to the edge server;

[0012] S3. The edge server constructs an index ciphertext binary search tree based on the index ciphertext for searching encrypted data. Each node of the binary search tree contains a key code, a first ciphertext, a second ciphertext, a proxy conversion key, and a storage address. The characteristic of the binary search tree is that all node keys in the left subtree of any node are smaller than the key code of this node, and all node keys in the right subtree are larger than the key code of this node. The cloud server uses the search function, key code, first ciphertext, second ciphertext, proxy conversion key, and storage address sent by each edge server to construct a global search structure. The global search structure consists of a search function and multiple index ciphertext binary searches. The cloud server manages the index ciphertext binary search trees distributed on each edge server to achieve global data retrieval. The user encrypts the keyword, generates a search request, and sends it to the edge server to initiate a retrieval request.

[0013] S4. The edge server performs matching calculations between the search information and the index ciphertext according to the search request submitted by the user. Once the index ciphertext of the required data is found, the edge server will quickly forward the storage address of the data ciphertext to the cloud server. If the required information cannot be found, the edge server will forward the search request to the cloud server and request the cloud server to perform a global search.

[0014] S5. After receiving the data ciphertext storage address or global search request forwarded by the edge server, the cloud server will take corresponding actions. If it is a data ciphertext storage address, the cloud server will locate and obtain the data ciphertext according to the address, and then cooperate with the edge server to return the search results to the user; if it is a global search request, the cloud server uses its global search structure to locate an edge server according to the retrieval request and initiates a search request to it, and its edge server then performs the operation of step S4;

[0015] S6. After the user receives the search results, the user uses the private key and the proxy re - decryption algorithm to decrypt the key ciphertext, recover the symmetric key, and uses the symmetric key and the AES decryption algorithm to decrypt the data ciphertext to obtain the searched data content;

[0016] S7. At the initial moment of a certain time period, the data owner requests to update the key from the auxiliary server. After receiving the request, the auxiliary server calculates the auxiliary key for this time period and transmits it to the data owner. After receiving the auxiliary key, the data owner calculates the key for this time period using the auxiliary key, generates a new auxiliary search key and index ciphertext, and then sends the new auxiliary search key and index ciphertext to the edge server to update the original auxiliary search key and index ciphertext;

[0017] S8. When the data owner decides to revoke the query permissions of one or more users, the data owner deletes the permission information of the user from the authorized user set, and sends a revocation instruction to the edge server, instructing the edge server to delete the auxiliary search key corresponding to the user in the authorized auxiliary table.

[0018] Furthermore, the process by which the trusted authority initializes the system and generates the system keys, two multiplicative cyclic groups of order p, generators, bilinear maps, and one - way and collision - resistant hash functions is as follows:

[0019] The two multiplicative cyclic groups of order p are G1 and G2, the generator is g, g is the generator of the multiplicative group G1, the bilinear map is e, e: G1×G1→G2, the one - way and collision - resistant hash functions are H1 and H2, where, H1(·):{0,1} * →G1, H2(·):{0,1} * →G1, the pseudo - random functions are F1 and F2, F1:{0,1} * ×{0,1} * →{0,1} * ,F2:{0,1} * ×{0,1} * →{0,1} * ;

[0020] The trusted authority selects a single random number k to generate the system key k D , denotes the set of integers from 1 to p - 1, where p is a prime number, k D =F2(ID D ||t0) k , selects the second single random number k2 and the third single random number k3 as the password together, and through a secure channel, (k3,k D, k2) is sent to the data owner, (ID D , k, k2) is sent to the auxiliary server, and the third single random number k3 is sent to the cloud server. ID D is the identity identifier of the data owner;

[0021] The secret key k of the data owner D is generated by the pseudo-random function F2 by inputting the identity identifier ID of the data owner D and the timestamp t0, and is processed by the single random number k to generate the secret key k D is valid within the time period t0. At the next time period, the system will use a new timestamp to regenerate a new secret key;

[0022] The trusted authority publishes the public parameters pp, pp = (G1, G2, p, e, F1, F2, H1, H2);

[0023] After the data owner receives (k3, k D , k2), the first single random number k1 is selected, Calculate the private key and the public key according to the following formulas:

[0024]

[0025]

[0026] The data owner saves the secret key Remembers the password (k3, k2), but does not store (k3, k2) locally;

[0027] After the auxiliary server receives (ID D , k, k2), it securely stores this set of information (ID D , k, k2);

[0028] After the cloud server receives k3, it securely stores this set of information (ID D , k3);

[0029] The process by which the data owner provides authorization for the user to search and generates the corresponding search key and auxiliary search key is as follows:

[0030] The data owner generates a proxy re-encryption key pair {psk, ppk}, and publishes ppk. Among them, psk is the private proxy re-encryption key, and ppk is the public proxy re-encryption key;

[0031] The data owner selects the double random number γ i , Calculate the search key sk of the authorized user iand the auxiliary search key δ i , according to the following formula:

[0032]

[0033]

[0034] where the value range of i is from 1 to n, representing each authorized user in the U set, and U i represents the set of all authorized users, and ID i is the identity identifier of the authorized user;

[0035] The data owner sends the search key sk i to the authorized user U i , and sends the auxiliary search key (ID i , δ i ) to the edge server. The edge server stores (ID i , δ i ) in the authorization auxiliary table.

[0036] Furthermore, the data owner encrypts the data and its keywords, and outsources the encrypted ciphertext to the auxiliary server and the cloud server for storage and management. The process of the cloud server storing the data ciphertext and sending the storage address to the edge server is as follows:

[0037] Suppose there is a data message M with multiple keywords w1, w2,..., w j ,..., w z , where w j is the j-th keyword and z is the number of keywords;

[0038] The data owner selects D random numbers ξ D as the symmetric key, uses the AES algorithm to encrypt the data message M, that is, c jM = E AES (ξ D , M), and c jM is the encrypted ciphertext, and E AES is the symmetric encryption algorithm used to encrypt the plaintext;

[0039] The data owner uses the private proxy re-encryption key psk and the proxy re-encryption algorithm to encrypt ξ D , that is, c jp = E proxy (psk, ξ D ), and calculates the proxy transformation key ρ D->j , and c jp is the ciphertext after proxy re-encryption, and Eproxy is a proxy re-encryption algorithm;

[0040] The data owner selects a random number α from V v Calculate the first ciphertext c v1 and the second ciphertext c v2 , as well as the signed hash value The formula based on is as follows:

[0041]

[0042]

[0043] σ v = H2(c v2 )

[0044] where w v is an identifier, which is the input of the hash function, and H1(w v ) is to convert w v into an element in the group G1, v = 0, 1, 2,..., b, and b is the number of random numbers in V;

[0045] The data owner sends the encrypted ciphertext c jM , the ciphertext c after proxy re-encryption jp , the proxy transformation key ρ D->j , the first ciphertext c v1 , the second ciphertext c v2 and the signed hash value σ v to the edge server;

[0046] The edge server forwards the encrypted ciphertext c jM and the ciphertext c after proxy re-encryption jp to the cloud server. After receiving them, the cloud server stores them and sends the storage address β ε to the edge server. β ε is the storage address of the ε-th encrypted ciphertext c jM and the ciphertext c after proxy re-encryption jp , 1 ≤ ε ≤ χ, and χ is the number of storage addresses.

[0047] Furthermore, the edge server constructs a binary search tree of index ciphertexts for searching encrypted data. Each node of the binary search tree contains a key, the first ciphertext, the second ciphertext, the proxy transformation key, and the storage address. The characteristic of the binary search tree is that the keys of all nodes in the left subtree of any node are less than the key of this node, and the keys of all nodes in the right subtree are greater than the key of this node. The process is as follows:

[0048] Each node of the binary search tree contains a key φη , the first ciphertext c v1 , the second ciphertext c v2 , the proxy conversion key ρ D->j and the storage address β ε , η is the number of keys, and the value range of η is from 1 to Γ. The edge server E f receives the key, the first ciphertext, the second ciphertext, the proxy conversion key, and the storage address, where E f represents the f-th edge server, and inserts the new data information into the binary search tree according to the following steps:

[0049] The edge server determines whether the root node of the binary search tree is empty. If the root node is empty, it directly inserts the data information, such as the key φ η , the first ciphertext c v1 , the second ciphertext c v2 , the proxy conversion key ρ D->j and the storage address β ε as the new root node; if the root node is not empty, execute the next step;

[0050] The edge server compares the key φ η of the data information to be inserted with the key φ0 of the current root node. If φ η is less than φ0, it turns to the left subtree to continue the search; if φ η is greater than φ0, it turns to the right subtree to continue the search;

[0051] Recursively move along the direction of the tree, and each time compare φ η with the key of the current node, and continue this process until an empty position is found, that is, an empty link position of a leaf node is found for inserting the key φ η , the first ciphertext c v1 , the second ciphertext c v2 , the proxy conversion key ρ D->j and the storage address β ε , and use it as a new node;

[0052] The edge server integrates the key φ η into the function S μ (X), that is, updates S μ (X) to S μ (X)(X - φ η ), where, where X represents an independent variable, T θ is the set of all keys stored by the edge server, N is an element of the set T θ , and σ N is a specific value related to the element N, called the root or zero point;

[0053] The edge server sends to the cloud server, where is an address linking to the index ciphertext binary search tree stored in the edge server E f , μ is the index of the polynomial function S μ (X), and the value range of μ is from 1 to is the number of terms of the function S μ (X).

[0054] Furthermore, the cloud server uses the search function, key, first ciphertext, second ciphertext, proxy transformation key, and storage address sent by each edge server to construct a global search structure. The global search structure consists of a search function and multiple index ciphertext binary searches. The cloud server manages the index ciphertext binary search trees distributed on each edge server. The process of realizing data retrieval within the global scope is as follows:

[0055] The cloud server uses the information sent by the edge server to construct a global search structure ES. ES consists of a series of tuple items, and each item contains a key item (E f , S μ (X)) and a pointer item , that is

[0056]

[0057] The user encrypts the search keyword, generates a search request, and sends it to the edge server. The process of initiating a retrieval request is as follows:

[0058] The authorized user U i selects a τ random number to calculate the third ciphertext q k1 and the fourth ciphertext q k2 , The basis formula is as follows:

[0059]

[0060]

[0061] Sends (ID i , q k1 , q k2 ) to the edge server to request a search service.

[0062] Furthermore, the specific process of step S4 is as follows:

[0063] The edge server finds the corresponding authorization key δ from the authorized auxiliary table Φ , and calculates the transformed q vand The formula based on is as follows:

[0064]

[0065]

[0066]

[0067] where sk i is the search key of the i-th user, is the transformed third ciphertext, q v is an intermediate value obtained by calculating the quotient of the bilinear pair, and is used for authentication, verification, encryption and decryption, is the hash value before signing;

[0068] Substitute into That is If is equal to zero, it means that the edge server E f stores the index ciphertext of the required query data. In this case, the edge server will perform the next step, and the index ciphertext binary search tree will continue to search for this data until the index ciphertext of the required data is located. If is not equal to zero, this indicates that the edge server E f does not contain the data required for this query. At this time, the edge server will forward the query request to the cloud server, and the cloud server will execute step S5 to continue processing this search request;

[0069] The edge server E f After detecting that is equal to zero, it confirms that it stores the index ciphertext of the query required data. Subsequently, it compares the query information with the key φ0 of the root node. If is less than φ0, it turns to the left subtree to continue the search; if is greater than φ0, it turns to the right subtree to continue the search;

[0070] Recursively move along the direction of the tree, and each time is compared with the key φ0 of the current root node, and this process continues until

[0071] Once is found, the edge server will extract the node information corresponding to this key from the corresponding node (σ v , c v1 , c v2 , ρ D->j , β ε ), and verify Whether it holds. If the verification passes, the edge server sends the data storage address to the cloud server.

[0072] Further, the specific process of step S5 is as follows:

[0073] If the received is the data ciphertext storage address, the cloud server locates and obtains the data ciphertext according to this address and forwards it to the edge server;

[0074] If the received is a global search request, the cloud server will retrieve the functions S1(X), S2(X),..., S from the global search structure, that is μ (X), and detect each whether it is zero. If a certain is zero, 1 ≤ Λ ≤ μ, which means that the edge server E f contains the data required for the query. Then the cloud server will forward the query to the edge server E f to continue searching in the data managed by this edge server;

[0075] If the calculation results of all are not zero, this indicates that the data satisfying the user's query cannot be found in all the stored data managed by the cloud server;

[0076] After receiving the data ciphertext (c jM , c jp ) sent by the cloud server, the edge server uses ρ D->j to perform proxy encryption conversion on c jp to generate the converted ciphertext and send the information to the user U i .

[0077] Further, after the user receives the search result, the process of decrypting the key ciphertext using the private key and the proxy re - decryption algorithm to recover the symmetric key, and then using the symmetric key and the AES decryption algorithm to decrypt the data ciphertext to obtain the searched data content is as follows:

[0078] The user U i receives the information and decrypts using the proxy re - encryption algorithm to obtain the symmetric key ξ D ;

[0079] Then the user uses the symmetric key ξ D to decrypt the ciphertext c jM = E AES (ξ D , M) to obtain the searched data content.

[0080] Furthermore, the specific process of step S7 is as follows:

[0081] For time period t D , the data owner selects a special random number r, and calculates the first intermediate value Q and the second intermediate value Y according to the following formulas:

[0082] Q = F2(ID D ||t D -1) -r F2(ID D ||t D ) r

[0083]

[0084] Send the second intermediate value Y to the auxiliary server, ⊕ is the exclusive OR operation, which compares bits one by one. If two bits are the same, the result is 0; if different, the result is 1. || is the concatenation operator, indicating that k2 and t D are concatenated as a whole and input into the hash function H1;

[0085] After receiving it, the auxiliary server calculates the auxiliary key B according to the following formula:

[0086]

[0087] A = Q k = F2(ID D ||t D -1) -rk F2(ID D ||t D ) rk

[0088]

[0089] Send the auxiliary key B to the data owner;

[0090] After receiving the auxiliary key B, the data owner calculates the key for this time period t D according to the following formula:

[0091]

[0092]

[0093]

[0094] where A is the new auxiliary key, The private key for t D time period, The public key for t D time period;

[0095] The data owner discards the private key for t D -1 time period Securely store the private key for t D time period

[0096] The data owner calculates the update information according to the following formula:

[0097]

[0098]

[0099]

[0100]

[0101] Wherein, is a ratio used to represent the relative change of the auxiliary search key δ D between two time points t0 and t i , t0 is a specific time point representing the initial time, and t D is another time point representing the time point compared with t0, L is the new first encrypted value, and C is the new second encrypted value, is the new first ciphertext;

[0102] Send (L, t D ) and (C, t D ) to the edge server;

[0103] After the edge server receives the updated (L, t D ), it updates the auxiliary search key and uses to replace δ in (ID i , δ i ), according to the following formula: i is the new auxiliary search key;

[0104]

[0105]

[0106] For the new auxiliary search key;

[0107] After the edge server receives the updated (C, t D ), it updates the ciphertext index and uses to replace c v1 , according to the following formula:

[0108]

[0109]

[0110] Among them, is the new ciphertext index.

[0111] Furthermore, the specific process of step S8 is as follows:

[0112] The data owner decides to revoke the query permission of user U i , and the data owner removes user U from the authorized user set i ;

[0113] The data owner sends an instruction to revoke user U i to the edge server, and the edge server deletes the auxiliary search key (ID i , δ i ) in the authorized auxiliary table.

[0114] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0115] (1) In the present invention, the data owner periodically updates the keys for each time period with the help of the auxiliary server, thus achieving the anti-key exposure feature, which means that even if the key of the data user is exposed in the current time period, it will not affect the key security of the previous or subsequent time periods, thereby enhancing the security of the entire system.

[0116] (2) The present invention proposes an innovative global search structure. With this structure, the cloud server can quickly locate and specify the most suitable edge server to process the search task, thus eliminating the step of checking all edge servers one by one. In an environment with multiple edge servers, this optimization significantly improves the efficiency of encrypted data search.

[0117] (3) The present invention supports multiple users to search for encrypted data and has the ability to revoke the search permission of users, which is particularly crucial in multi-user scenarios such as the Internet of Things. It can significantly reduce the risks of unauthorized access and data abuse, thereby strengthening the protection of data security and user privacy.

[0118] (4) The present invention adopts a cloud-edge collaboration mechanism to perform encrypted data search, migrating the computing tasks from the cloud to the edge of the network, closer to the data source and users. This mechanism enables the index ciphertext to be directly processed on the edge server, thus effectively reducing the risk of data leakage and further strengthening the user privacy and data security. In addition, the cloud-edge collaboration mechanism also significantly reduces the data transmission delay and improves the response speed of real-time applications, thereby optimizing the overall user experience. Description of the Drawings

[0119] Figure 1 is a schematic flowchart of the present invention;

[0120] Figure 2 is a design diagram of the application system of the present invention. Detailed Description of the Invention

[0121] To make the objectives, technical solutions and advantages of the present invention more clear and understandable, the present invention will be further described in detail below with reference to specific embodiments.

[0122] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in the present invention shall have the ordinary meanings understood by those with ordinary skills in the field to which the present invention pertains. The "first", "second" and similar terms used in the present invention do not denote any order, quantity or importance, but are only used to distinguish different components. The terms such as "comprising" or "including" mean that the elements or objects appearing before this term cover the elements or objects listed after this term and their equivalents, without excluding other elements or objects. The terms such as "connected" or "coupled" are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. The terms such as "upper", "lower", "left" and "right" are only used to represent relative positional relationships, and when the absolute position of the object being described changes, the relative positional relationship may also change accordingly.

[0123] Embodiment:

[0124] Please refer to Figure 1 , the present invention provides a technical solution:

[0125] A multi - user searchable encryption method resistant to key leakage in a cloud - edge collaborative environment, the specific steps include:

[0126] S1. A trusted authority initializes the system and generates the system key, two multiplicative cyclic groups of order p, a generator, a bilinear mapping, and a one - way and collision - resistant hash function. The data owner provides authorization for the users who need to search, and generates the corresponding search key and auxiliary search key;

[0127] S2. The data owner encrypts the data and its keywords, and outsources the encrypted ciphertext to an auxiliary server and a cloud server for storage and management. After receiving the ciphertext, the cloud server stores it and sends the storage address to the edge server;

[0128] S3. The edge server constructs an index ciphertext binary search tree based on the index ciphertext for searching encrypted data. Each node of the binary search tree contains a key code, a first ciphertext, a second ciphertext, a proxy conversion key, and a storage address. The characteristic of the binary search tree is that all node keys in the left subtree of any node are smaller than the key code of this node, and all node keys in the right subtree are larger than the key code of this node. The cloud server uses the search function, key code, first ciphertext, second ciphertext, proxy conversion key, and storage address sent by each edge server to construct a global search structure. The global search structure consists of a search function and multiple index ciphertext binary searches. The cloud server manages the index ciphertext binary search trees distributed on each edge server to achieve global data retrieval. The user encrypts the keyword, generates a search request, and sends it to the edge server to initiate a retrieval request.

[0129] S4. The edge server performs matching calculations between the search information and the index ciphertext according to the search request submitted by the user. Once the index ciphertext of the required data is found, the edge server will quickly forward the storage address of the data ciphertext to the cloud server. If the required information cannot be found, the edge server will forward the search request to the cloud server and request the cloud server to perform a global search.

[0130] S5. After receiving the data ciphertext storage address or global search request forwarded by the edge server, the cloud server will take corresponding actions. If it is a data ciphertext storage address, the cloud server will locate and obtain the data ciphertext according to the address, and then cooperate with the edge server to return the search results to the user; if it is a global search request, the cloud server uses its global search structure to locate an edge server according to the retrieval request and initiates a search request to it, and its edge server then performs the operation of step S4;

[0131] S6. After receiving the search results, the user uses the private key and the proxy re-decryption algorithm to decrypt the key ciphertext, recover the symmetric key, and uses the symmetric key and the AES decryption algorithm to decrypt the data ciphertext to obtain the searched data content;

[0132] S7. At the beginning of a time period, the data owner requests the auxiliary server to update the key. After receiving the request, the auxiliary server calculates the auxiliary key for the time period and transmits it to the data owner. After receiving the auxiliary key, the data owner uses the auxiliary key to calculate the key for the time period and generates a new auxiliary search key and index ciphertext. The new auxiliary search key and index ciphertext are then sent to the edge server to update the original auxiliary search key and index ciphertext.

[0133] S8. When the data owner decides to revoke the query permissions of one or more users, the permission information of the user is deleted from the authorized user set. The data owner sends a revocation instruction to the edge server, instructing the edge server to delete the auxiliary search key corresponding to the user in the authorized auxiliary table.

[0134] Based on the above embodiments, the process of the trusted authority initializing the system and generating the system keys, two multiplicative cyclic groups of order p, generators, bilinear maps, and one-way and collision-resistant hash functions is as follows:

[0135] S1-1. The two multiplicative cyclic groups of order p are G1 and G2, the generator is g, g is the generator of the multiplicative group G1, the bilinear map is e, e: G1×G1→G2, the one-way and collision-resistant hash functions are H1 and H2, where, H1(·):{0,1} * →G1, H2(·):{0,1} * →G1, the pseudo-random functions are F1 and F2, F1:{0,1} * ×{0,1} * →{0,1} * ,F2:{0,1} * ×{0,1} * →{0,1} * ;

[0136] S1-2. The trusted authority selects a single random number k to generate the system key k D , denotes the set of integers from 1 to p-1, where p is a prime number, k D =F2(ID D ||t0) k , selects the second single random number k2 and the third single random number k3 as the password together, and sends (k3,k D ,k2) to the data owner through a secure channel, sends (ID D ,k,k2) to the auxiliary server, and sends the third single random number k3 to the cloud server. ID D is the identity identifier of the data owner;

[0137] The key k of the data owner D is generated by the pseudo-random function F2 by inputting the identity identifier ID of the data owner D and the timestamp t0, and is processed by the single random number k. The generated key k D is valid within the time period t0. In the next time period, the system will use a new timestamp to regenerate a new key;

[0138] S1-3. The trusted authority publishes the public parameters pp, where pp = (G1, G2, p, e, F1, F2, H1, H2);

[0139] S1-4. After the data owner receives (k3, k D , k2), the data owner selects the first single random number k1, and calculates the private key and the public key according to the following formulas:

[0140]

[0141]

[0142] The data owner saves the secret key and remembers the password (k3, k2), but does not store (k3, k2) locally;

[0143] S1-5. After the auxiliary server receives (ID D , k, k2), it securely stores this set of information (ID D , k, k2);

[0144] S1-6. After the cloud server receives k3, it securely stores this set of information (ID D , k3);

[0145] Based on the above embodiments, the process by which the data owner provides authorization for the user to search and generates the corresponding search key and auxiliary search key is as follows:

[0146] S1-7. The data owner generates a proxy re-encryption key pair {psk, ppk} and publishes ppk, where psk is the private proxy re-encryption key and ppk is the public proxy re-encryption key;

[0147] S1-8. The data owner selects the double random number γ i , and calculates the search key sk i and the auxiliary search key δ i for the authorized user according to the following formulas:

[0148]

[0149]

[0150] where the value range of i is from 1 to n, representing each authorized user in the U set, and U i represents the set of all authorized users, and ID i is the identity identifier of the authorized user;

[0151] S1 - 9. The data owner sends the search key sk i to the authorized user U i , and sends the auxiliary search key (ID i , δ i ) to the edge server;

[0152] S1 - 10. The edge server stores (ID i , δ i ) in the authorized auxiliary table.

[0153] Based on the above - mentioned embodiments, the data owner encrypts the data and its keywords, and outsources the encrypted ciphertext to the edge server and the cloud server for storage and management. The process of the cloud server storing the data ciphertext after receiving it and sending the storage address to the edge server is as follows:

[0154] Assume there is a data message M, which has multiple keywords w1, w2,..., w j ,..., w z , where w j is the j - th keyword, and z is the number of keywords;

[0155] S2 - 1. The data owner selects D random numbers ξ D as the symmetric key, and encrypts the data message M using the AES algorithm, i.e., c jM = E AES (ξ D , M), c jM is the encrypted ciphertext, and E AES is the symmetric encryption algorithm for encrypting the plaintext;

[0156] S2 - 2. The data owner encrypts ξ D using the private proxy re - encryption key psk and the proxy re - encryption algorithm, i.e., c jp = E proxy (psk, ξ D ), and calculates the proxy transformation key ρ D->j , c jp is the ciphertext after proxy re - encryption, and E proxy is the proxy re - encryption algorithm;

[0157] S2 - 3. The data owner selects V random numbers α v to calculate the first ciphertext c v1 and the second ciphertext c v2 , and the signed hash value σ v , The formulas are as follows:

[0158]

[0159]

[0160] σ v = H2(c v2 )

[0161] where w v is an identifier and the input of the hash function, H1(w v ) is to convert w v into an element in the group G1, v = 0, 1, 2,..., b, where b is the number of random numbers of V;

[0162] S2-4. The data owner sends the encrypted ciphertext c jM , the proxy re-encrypted ciphertext c jp , the proxy transformation key ρ D->j , the first ciphertext c v1 , the second ciphertext c v2 and the signed hash value σ v to the edge server;

[0163] S2-5. The edge server forwards the encrypted ciphertext c jM and the proxy re-encrypted ciphertext c jp to the cloud server. After receiving them, the cloud server stores them and sends the storage address β ε to the edge server. β ε is the storage address of the ε-th encrypted ciphertext c jM and the proxy re-encrypted ciphertext c jp , where 1 ≤ ε ≤ χ and χ is the number of storage addresses.

[0164] Based on the above embodiments, the edge server constructs a binary search tree of index ciphertexts for searching encrypted data. Each node of the binary search tree contains a key, a first ciphertext, a second ciphertext, a proxy transformation key, and a storage address. The characteristic of the binary search tree is that the keys of all nodes in the left subtree of any node are less than the key of this node, and the keys of all nodes in the right subtree are greater than the key of this node. The process is as follows:

[0165] Each node of the binary search tree contains a key φ η , a first ciphertext c v1 , a second ciphertext c v2 , a proxy transformation key ρ D->j and a storage address β ε , where η is the number of keys, and the value range of η is from 1 to Γ. The edge server E fReceived the key, the first ciphertext, the second ciphertext, the proxy conversion key, and the storage address, where E f represents the f-th edge server, and inserts the new data information into the binary search tree according to the following steps:

[0166] S3-1. The edge server determines whether the root node of the binary search tree is empty. If the root node is empty, directly insert the data information, such as the key φ η , the first ciphertext c v1 , the second ciphertext c v2 , the proxy conversion key ρ D->j and the storage address β ε as the new root node; if the root node is not empty, execute the next step;

[0167] S3-2. The edge server compares the key φ of the data information to be inserted η with the key φ0 of the current root node. If φ η is less than φ0, turn to the left subtree to continue the search; if φ η is greater than φ0, turn to the right subtree to continue the search;

[0168] S3-3. Recursively move along the direction of the tree, and each time compare φ η with the key of the current node, and continue this process until an empty position is found, that is, find an empty link position of a leaf node to insert the key φ η , the first ciphertext c v1 , the second ciphertext c v2 , the proxy conversion key ρ D->j and the storage address β ε , and use it as a new node;

[0169] S3-4. The edge server integrates the key φ η into the function S μ , that is, update S μ to S μ (X)(X - φ η ), where where X represents an independent variable, T θ is the set of all keys stored by the edge server, N is an element of the set T θ , and σ N is a specific value related to the element N, called the root or zero point;

[0170] S3-5. The edge server sends to the cloud server, where is a link to the edge server E fThe address of the stored index encrypted binary search tree, where μ is the polynomial function S μ (X), and the value range of μ is from 1 to is the function S μ (X) number of terms.

[0171] Based on the above embodiments, the cloud server uses the search function, key, first ciphertext, second ciphertext, proxy transformation key, and storage address sent by each edge server to construct a global search structure. The global search structure consists of a search function and multiple index encrypted binary searches. The cloud server manages the index encrypted binary search trees distributed on each edge server to implement the process of data retrieval within the global scope as follows:

[0172] S3-6. The cloud server uses the information sent by the edge server to construct a global search structure ES. ES consists of a series of tuple items, and each item contains a key item (E f , S μ (X)) and a pointer item constitutes, that is

[0173]

[0174] S3-7. The user encrypts the search keyword, generates a search request, and sends it to the edge server. The process of initiating a retrieval request is as follows:

[0175] The authorized user U i selects a τ random number to calculate the third ciphertext q k1 and the fourth ciphertext q k2 , The basis formula is as follows:

[0176]

[0177]

[0178] Send (ID i , q k1 , q k2 ) to the edge server to request search services.

[0179] Based on the above embodiments, the specific process of step S4 is as follows:

[0180] S4-1. The edge server finds the corresponding authorization key δ from the authorized auxiliary table Φ , and calculates the transformed q v and The basis formula is as follows:

[0181]

[0182]

[0183]

[0184] Among them, sk i is the search key of the i-th user, is the transformed third ciphertext, q v is an intermediate value obtained by calculating the quotient of the bilinear pair, and is used for authentication, verification, and encryption and decryption, is the hash value before signature;

[0185] S4-2. Substitute into That is If is equal to zero, it means that the edge server E f stores the index ciphertext of the required query data. In this case, the edge server will execute the next step, and the index ciphertext binary search tree will continue to search for this data until the index ciphertext of the required data is located. If is not equal to zero, this indicates that the edge server E f does not contain the data required for this query. At this time, the edge server will forward the query request to the cloud server, and the cloud server will execute step S5 to continue processing this search request;

[0186] S4-3. After the edge server E f detects that is equal to zero and confirms that it stores the index ciphertext of the query required data. Subsequently, compare the query information with the key φ0 of the root node. If is less than φ0, turn to the left subtree to continue the search; if is greater than φ0, turn to the right subtree to continue the search;

[0187] S4-4. Recursively move along the direction of the tree, and each time compare with the key φ0 of the current root node, and continue this process until

[0188] S4-5. Once is found, the edge server will extract the node information corresponding to this key from the corresponding node (σ v , c v1 , c v2 , ρ D->j ,β ε ), and verify Whether it holds. If the verification passes, the edge server sends the data storage address to the cloud server.

[0189] Based on the above embodiments, the specific process of step S5 is as follows:

[0190] S5-1. If the received is the data ciphertext storage address, the cloud server locates and obtains the data ciphertext according to this address, and forwards it to the edge server, then executes step S5-4;

[0191] S5-2. If the received is a global search request, the cloud server will retrieve the functions S1(X), S2(X),..., S from the global search structure, that is, μ (X), and detect each whether it is zero. If a certain is zero, 1≤Λ≤μ, which means that the edge server E f contains the data required for the query. Then the cloud server will forward the query to the edge server E f to continue searching in the data managed by this edge server;

[0192] S5-3. If the calculation results of all are not zero, this indicates that the data satisfying the user's query cannot be found in all the stored data managed by the cloud server;

[0193] S5-4. After receiving the data ciphertext (c jM , c jp ) sent by the cloud server, the edge server uses ρ D->j to perform proxy encryption conversion on c jp to generate the converted ciphertext and send the information to the user U i .

[0194] Based on the above embodiments, after the user receives the search result, the process of decrypting the key ciphertext using the private key and the proxy re-decryption algorithm to restore the symmetric key, and decrypting the data ciphertext using the symmetric key and the AES decryption algorithm to obtain the searched data content is as follows:

[0195] S6-1. After the user U i receives the information , decrypts using the proxy re-encryption algorithm to obtain the symmetric key ξ D ;

[0196] S6-2. Then the user uses the symmetric key ξ D to decrypt the ciphertext c jM =EAES (ξ D , M) is decrypted to obtain the retrieved data content.

[0197] Based on the above embodiments, the specific process of step S7 is as follows:

[0198] S7-1. For time period t D , the data owner selects a special random number r, and calculates the first intermediate value Q and the second intermediate value Y according to the following formulas:

[0199] Q = F2(ID D ||t D -1) -r F2(ID D ||t D ) r

[0200]

[0201] The second intermediate value Y is sent to the auxiliary server. is the exclusive OR operation, which compares bits one by one. If two bits are the same, the result is 0; if different, the result is 1. || is the concatenation operator, indicating that k2 and t D are concatenated as a whole and input into the hash function H1;

[0202] S7-2. After receiving it, the auxiliary server calculates the auxiliary key B according to the following formula:

[0203]

[0204] A = Q k = F2(ID D ||t D -1) -rk F2(ID D ||t D ) rk

[0205]

[0206] The auxiliary key B is sent to the data owner;

[0207] S7-3. After receiving the auxiliary key B, the data owner calculates the key for the time period t D according to the following formula:

[0208]

[0209]

[0210]

[0211] Among them, A is the new auxiliary key, is the private key for the t D time period, is the public key for the t D time period;

[0212] S7-4. The data owner discards the private key for the t D -1 time period and securely stores the private key for the t D time period

[0213] S7-5. The data owner calculates the update information according to the following formula:

[0214]

[0215]

[0216]

[0217]

[0218] Among them, is the ratio, used to represent the relative change of the auxiliary search key δ D between two time points t0 and t i , t0 is a specific time point, representing the initial time, and t D is another time point, representing the time point compared with t0, L is the new first encrypted value, C is the new second encrypted value, is the new first ciphertext;

[0219] Send (L, t D ) and (C, t D ) to the edge server;

[0220] S7-6. After the edge server receives the updated (L, t D ), it updates the auxiliary search key and replaces δ in (ID i , δ i ) with i according to the following formula:

[0221]

[0222]

[0223] is the new auxiliary search key;

[0224] S7-7. The edge server receives the updated (C,t D ), update the ciphertext index and use Replace c v1 , based on the following formula:

[0225]

[0226]

[0227] in, The new ciphertext index.

[0228] Based on the above embodiment, the specific process of step S8 is as follows:

[0229] S8-1. The data owner decides to revoke the user U i The data owner removes user U from the authorized user set. i ;

[0230] S8-2. The data owner sends a request to the edge server to revoke the user U i The edge server deletes the auxiliary search key (ID i ,δ i ).

[0231] In the cloud-edge collaborative environment, a specific example of implementing a multi-user searchable encryption method that resists key leakage is as follows: Figure 2 As shown, the graph contains six entities, each of which performs the following operations:

[0232] Trusted authority: is fully trusted, is responsible for performing the system initialization process, and does not need to be continuously online to operate.

[0233] Cloud server: responsible for storing user encrypted data and coordinating data queries of multiple edge servers in the entire system. Once the data is retrieved, it will collaborate with the edge server to return the data securely to the data user. The cloud server uses the search function and other information sent by the edge server to build an efficient global search structure. When the required query data cannot be found in a certain edge server, the cloud server uses the global search structure to quickly locate the appropriate edge server and initiate a query request to it, thereby greatly improving the data query efficiency and reducing computing and communication costs.

[0234] Auxiliary server: At the beginning of each time period, it assists the data owner to update his private key to ensure that the system has the characteristics of resisting key exposure.

[0235] Edge Server: It is mainly responsible for storing the local index ciphertext and responding to the query requests of data users. The edge server can match and retrieve based on the user's query information and the ciphertext index, and promptly transmit the matching information to the cloud server to ensure the efficiency of the query process and the timeliness of data transmission.

[0236] Data Owner: The data owner encrypts the local data and outsources it to the edge server and the cloud server, and provides authorization for users who need to query the data, that is, generates the corresponding query key and auxiliary query key, and distributes them to the authorized users and the edge server for data query.

[0237] User: Each user terminal belongs to an edge server. Once authorized, the user can conduct queries with the assistance of the edge server. Applicable devices include but are not limited to mobile phones, tablets, laptops, or desktop computers.

[0238] The above formulas are all dimensionless and take their numerical values for calculation. The formulas are obtained by collecting a large amount of data and performing software simulation to get a formula closest to the actual situation. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.

[0239] The above embodiments can be implemented in whole or in part by software, hardware, firmware, or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. Those skilled in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed by hardware or software methods depends on the specific application and design constraints of the technical solution.

[0240] The units described as separate components may or may not be physically separated. The components shown as units may or may not be physical units. They can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0241] As described above, only the specific implementation manners of this application are provided, but the protection scope of this application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed in this application, and all should be covered within the protection scope of this application.

Claims

1. A multi - user searchable encryption method resistant to key leakage in a cloud - edge collaborative environment, characterized in that, The specific steps include: S1. A trusted authority initializes the system and generates the system's secret key, two multiplicative cyclic groups of order p, generators, bilinear maps, and one-way and collision-resistant hash functions. The data owner provides authorization for the users who need to search, and generates the corresponding search key and auxiliary search key; S2. The data owner encrypts the data and its keywords, and outsources the encrypted ciphertext to the auxiliary server and the cloud server for storage and management. After receiving the ciphertext, the cloud server stores it and sends the storage address to the edge server; S3. The edge server constructs an index ciphertext binary search tree based on the index ciphertext for searching encrypted data. Each node of the binary search tree contains a key code, a first ciphertext, a second ciphertext, a proxy transformation key, and a storage address. The characteristic of the binary search tree is that the key codes of all nodes in the left subtree of any node are less than the key code of this node, while the key codes of all nodes in the right subtree are greater than the key code of this node. The cloud server uses the search function, key code, first ciphertext, second ciphertext, proxy transformation key, and storage address sent by each edge server to construct a global search structure. The global search structure consists of a search function and multiple index ciphertext binary searches. The cloud server manages the index ciphertext binary search trees scattered on each edge server to achieve data retrieval within a global scope. The user encrypts the keyword, generates a search request, and sends it to the edge server to initiate a retrieval request; S4. The edge server performs a matching calculation of the search information and the index ciphertext according to the search request submitted by the user. Once the index ciphertext of the required data is found, the edge server quickly forwards the storage address of the data ciphertext to the cloud server. If the required information cannot be found, the edge server forwards the search request to the cloud server, requesting the cloud server to perform a global search; S5. After receiving the storage address of the data ciphertext forwarded by the edge server or the request for a global search, the cloud server will take corresponding actions. If it is the storage address of the data ciphertext, the cloud server locates and obtains the data ciphertext according to this address, and then cooperates with the edge server to return the search result to the user. If the received request is for a global search, the cloud server uses its global search structure to locate an edge server according to the retrieval request and sends a search request to it. The edge server then performs the operations in step S4; S6. After receiving the search result, the user uses the private key and the proxy re-decryption algorithm to decrypt the key ciphertext to recover the symmetric key, and uses the symmetric key and the AES decryption algorithm to decrypt the data ciphertext to obtain the searched data content; S7. At the initial moment of a certain time period, the data owner requests an updated key from the auxiliary server. After receiving the request, the auxiliary server calculates the auxiliary key for this time period and transmits it to the data owner. After receiving the auxiliary key, the data owner calculates the key for this time period using the auxiliary key, and generates a new auxiliary search key and index ciphertext. Subsequently, the new auxiliary search key and index ciphertext are sent to the edge server to update the original auxiliary search key and index ciphertext; S8. When the data owner decides to revoke the query permissions of one or more users, the permission information of this user is deleted from the authorized user set. The data owner sends a revocation instruction to the edge server, instructing the edge server to delete the auxiliary search key corresponding to this user in the authorized auxiliary table; The process by which the trusted authority initializes the system and generates the system key, two multiplicative cyclic groups of order p, generators, bilinear maps, and one-way and collision-resistant hash functions is as follows: There are two multiplicative cyclic groups of order p, namely G1 and G2, with a generator g. g is the generator of the multiplicative group G1, a bilinear mapping e, where e: G1×G1→G2, one-way and collision-resistant hash functions H1 and H2, where H1(·): {0,1} * →G1, H2(·): {0,1} * →G1, pseudorandom functions F1 and F2, where F1: {0,1} * ×{0,1} * →{0,1} * , F2: {0,1} * ×{0,1} * →{0,1} * ; The trusted authority selects a single random number k to generate the secret key k of the system D , denotes the set of integers from 1 to p - 1, where p is a prime number, k D = F2(ID D ||t0) k , selects the second single random number k2 and the third single random number k3 as the password together, and sends (k3, k D , k2) to the data owner through a secure channel, sends (ID D , k, k2) to the auxiliary server, and sends the third single random number k3 to the cloud server. ID D is the identity identifier of the data owner; The key k of the data owner D is generated by the pseudo-random function F2 by inputting the identity ID of the data owner D and the timestamp t0, and is processed by the single random number k to generate the key k D is valid within the time period t0. In the next time period, the system will use a new timestamp to regenerate a new key; The trusted authority publishes the public parameters pp, where pp = (G1, G2, p, e, F1, F2, H1, H2); After the data owner receives (k3, k D , k2), the data owner selects the first single random number to calculate the private key and the public key The formulas are as follows: The data owner stores the secret key Remember the password (k3, k2), but do not store (k3, k2) locally; After the auxiliary server receives (ID D , k, k2), it securely stores this set of information (ID D , k, k2); After the cloud server receives k3, it securely stores this set of information (ID D , k3); The process by which the data owner provides authorization for the users to be searched and generates the corresponding search key and auxiliary search key is as follows: The data owner generates a proxy re-encryption key pair {psk, ppk} and publishes ppk, where psk is the private proxy re-encryption key and ppk is the public proxy re-encryption key; The data owner selects two random numbers γ i , to calculate the search key sk i of the authorized user and the auxiliary search key δ i , and the basis formula is as follows: Among them, the value range of i is from 1 to n, representing each authorized user in the U set, and U i represents the set of all authorized users, and ID i is the identity identifier of the authorized user; The data owner sends the search key sk i to the authorized user U i , and sends the auxiliary search key (ID i , δ i ) to the edge server. The edge server stores (ID i , δ i ) in the authorized auxiliary table.

2. The multi-user searchable encryption method for resisting key leakage in the cloud-edge collaborative environment according to claim 1, wherein: The process by which the data owner encrypts the data and its keywords, and outsources the encrypted ciphertext to the auxiliary server and the cloud server for storage and management. After receiving the data ciphertext, the cloud server stores it and sends the storage address to the edge server is as follows: Suppose there is a data message M, and M has multiple keywords w1, w2,..., w j ,..., w z , where w j is the j-th keyword, and z is the number of keywords; The data owner selects a random number ξ D as the symmetric key, and uses the AES algorithm to encrypt the data information M, i.e., c jM = E AES (ξ D , M), where c jM is the encrypted ciphertext, and E AES is the symmetric encryption algorithm used to encrypt the plaintext; The data owner uses the private proxy re-encryption key psk and the proxy re-encryption algorithm to encrypt ξ D , that is, c jp = E proxy (psk, ξ D ), and calculates the proxy transformation key ρ D->j , c jp is the ciphertext after proxy re-encryption, and E proxy is the proxy re-encryption algorithm; The data owner selects a random number α v Calculate the first ciphertext c v1 and the second ciphertext c v2 , as well as the signed hash value σ v , The formula is as follows: σ v = H2(c v2 ) where, w v is an identifier and is the input of the hash function. H1(w v ) is to convert w v into an element in the group G1, v = 0, 1, 2, ..., b, where b is the number of random numbers of V; The data owner sends the encrypted ciphertext c jM , the ciphertext c jp after proxy re-encryption, the proxy transformation key ρ D->j , the first ciphertext c v1 , the second ciphertext c v2 and the signed hash value σ v to the edge server; The edge server transfers the encrypted ciphertext c jM and the ciphertext c after proxy re-encryption jp to the cloud server. After receiving them, the cloud server stores them and sends the storage address β ε to the edge server. β ε is the storage address of the ε-th encrypted ciphertext c jM and the ciphertext c after proxy re-encryption jp , where 1 ≤ ε ≤ χ and χ is the number of storage addresses.

3. The multi-user searchable encryption method for resisting key leakage in a cloud-edge collaborative environment according to claim 2, characterized in that: The edge server constructs a binary search tree of index ciphertexts for searching encrypted data. Each node of the binary search tree contains a key code, a first ciphertext, a second ciphertext, a proxy conversion key, and a storage address. The characteristic of the binary search tree is that the key codes of all nodes in the left subtree of any node are less than the key code of this node, and the key codes of all nodes in the right subtree are greater than the key code of this node. The process is as follows: Each node of the binary search tree contains a key Φ η , the first ciphertext c v1 , the second ciphertext c v2 , the proxy transformation key ρ D->j and the storage address β ε , η is the number of keys, the value range of η is from 1 to Γ, and the edge server E f receives the key, the first ciphertext, the second ciphertext, the proxy transformation key and the storage address, where E f represents the f-th edge server, and inserts the data information into the binary search tree according to the following steps: The edge server determines whether the root node of the binary search tree is empty. If the root node is empty, it directly inserts the data information: key Φ η , the first ciphertext c v1 , the second ciphertext c v2 , the proxy conversion key ρ D->j and the storage address β ε as the new root node; if the root node is not empty, proceed to the next step; The edge server takes the key of the data information to be inserted Φ η and compares it with the key of the current root node Φ 0 If Φ η it is less than Φ 0 , then it turns to the left subtree to continue the search; if Φ 0 it is greater than Φ 0 , then it turns to the right subtree to continue the search; Recursively move along the direction of the tree, and each time compare Φ η with the key of the current node, and continue this process until an empty position is found, that is, an empty sub-link position of a leaf node is found for inserting the key Φ η , the first ciphertext c v1 , the second ciphertext c v2 , the proxy transformation key ρ D->j and the storage address β ε , and use them as a new node; The edge server integrates the key Φ η into the function S μ (X), that is, updates S μ (X) to S μ (X)(X - Φ η ), where where X represents an independent variable, T θ is the set of all keys stored in the edge server, N is an element of the set T θ , and σ N is a specific value associated with the element N, called the root or zero point; The edge server will send to the cloud server, where is an address linking to the index encrypted binary search tree stored in the edge server E f μ is the index of the polynomial function S μ (X), and the value range of μ is from 1 to is the number of terms of the function S μ (X).

4. The multi-user searchable encryption method for resisting key leakage in the cloud-edge collaborative environment according to claim 3, wherein: The cloud server uses the search function, key code, first ciphertext, second ciphertext, proxy conversion key, and storage address sent by each edge server to construct a global search structure. The global search structure consists of a search function and multiple index ciphertext binary searches. The cloud server manages the index ciphertext binary search trees scattered on each edge server to implement data retrieval within a global scope. The process is as follows: The cloud server utilizes the information sent by the edge server to construct a global search structure ES, which consists of a series of tuple items, and each item contains a key item (E f , S μ (X)) and a pointer item and is formed as follows The process by which the user encrypts the search keyword, generates a search request, and sends it to the edge server to initiate a retrieval request is as follows: Authorized user U i Select a τ random number to calculate the third ciphertext q k1 and the fourth ciphertext q k2 , The formula is as follows: Send (ID i , q k1 , q k2 ) to the edge server to request a search service.

5. The multi-user searchable encryption method for resisting key leakage in the cloud-edge collaborative environment according to claim 4, wherein: The specific process of step S4 is as follows: The edge server finds the corresponding authorization key δ from the authorized auxiliary table Φ , and calculates the transformed q v and The basis formula is as follows: Among them, sk i is the search key of the i-th user, is the transformed third ciphertext, q v is an intermediate value obtained by calculating the quotient of the bilinear pair, and is used for authentication, verification, and encryption and decryption, is the hash value before signing; Bring into That is If equals zero, it means that the edge server E f stores the index ciphertext of the required query data. In this case, the edge server will perform the next step, and the index ciphertext binary search tree will continue to search for the data until the index ciphertext of the required data is located. If is not equal to zero, this indicates that the edge server E f does not contain the data required for this query. At this time, the edge server will forward the query request to the cloud server, and the cloud server will execute step S5 to continue processing this search request; Edge server E f After detection equals zero, confirm that it stores the index ciphertext of the data required for the query. Subsequently, the query information is compared with the key of the root node Φ 0 If less than Φ 0 , then turn to the left subtree to continue the search; if greater than Φ 0 , then turn to the right subtree to continue the search; Recursively move along the direction of the tree, and each time compare with the key of the current root node Φ 0 and continue this process until finding Once found The edge server extracts the node information corresponding to the key (σ v , c v1 , c v2 , ρ D->j , β ε ) from the corresponding node and verifies whether it holds. If the verification passes, the edge server sends the data storage address to the cloud server.

6. The multi-user searchable encryption method for resisting key leakage in the cloud-edge collaborative environment according to claim 5, characterized in that: The specific process of step S5 is as follows: If the received is the storage address of the data ciphertext, the cloud server locates and obtains the data ciphertext according to this address and forwards it to the edge server; If a global search request is received, the cloud server will retrieve the functions S1(X), S2(X),..., S one by one from the global search structure, namely μ (X), and detect each to see if it is zero. If a certain is zero, where 1 ≤ Λ ≤ μ, it means that the edge server E f contains the data required for the query. Then the cloud server will forward the query to the edge server E f to continue the search in the data managed by this edge server; If all of the calculation results are non-zero, this indicates that no data satisfying the user's query can be found among all the stored data managed by the cloud server; After receiving the data ciphertext (c jM , c jp ) sent by the cloud server, the edge server uses ρ D->j to perform proxy encryption conversion on c jp , generating the converted ciphertext and sending the information to user U i .

7. The multi-user searchable encryption method for resisting key leakage in the cloud-edge collaborative environment according to claim 6, wherein: After the user receives the search results, the process of decrypting the key ciphertext using the private key and the proxy re-encryption algorithm to recover the symmetric key, and then decrypting the data ciphertext using the symmetric key and the AES decryption algorithm to obtain the searched data content is as follows: User U i receives the information and then uses the proxy re-encryption algorithm to decrypt it to obtain the symmetric key ξ D ; Next, the user uses the symmetric key ξ D to decrypt the ciphertext c jM = E AES (ξ D , M), and obtains the retrieved data content.

8. The multi-user searchable encryption method for resisting key leakage in the cloud-edge collaborative environment according to claim 7, wherein: The specific process of step S7 is as follows: For time period t D , the data owner selects a special random number r, and calculates the first intermediate value Q and the second intermediate value Y according to the following formulas: Q = F2(ID D ||t D -1) -r F2(ID D ||t D ) r Send the second intermediate value Y to the auxiliary server. is an exclusive OR operation, which performs a bit-by-bit comparison of bits. If the two bits are the same, the result is 0; if they are different, the result is 1. || is a concatenation operator, indicating that k2 and t D are concatenated as a whole and input into the hash function H1. After the auxiliary server receives it, it calculates the auxiliary key B according to the following formula: Send the auxiliary key B to the data owner; After the data owner receives the auxiliary key B, the data owner calculates the key for the time period t using the auxiliary key B. The formula is as follows: D as follows: Among them, A is a new auxiliary key, which is the private key for the D time period t, and D is the public key for the time period t; The data owner discards the private key of time period t D -1 Securely store the private key of time period t D The private key of time period t The data owner calculates the update information according to the following formula: Among them, is a ratio used to represent the auxiliary search key δ D between two time points t0 and t i for relative change, where t0 is a specific time point representing the initial time, and t D is another time point representing the time point compared with t0, L is the new first encrypted value, C is the new second encrypted value, is the new first ciphertext; Send (L, t D ) and (C, t D ) to the edge server; After the edge server receives the updated (L, t D ), it updates the auxiliary search key and uses to replace δ in (ID i , δ i ), according to the following formula: i ​ is a new auxiliary search key; After the edge server receives the updated (C, t D ), it updates the ciphertext index and uses to replace c v1 , and the basis formula is as follows: Among them, is the new ciphertext index.

9. The multi-user searchable encryption method for resisting key leakage in the cloud-edge collaborative environment according to claim 8, wherein: The specific process of step S8 is as follows: The data owner decides to revoke the query permission of user U i The data owner removes user U from the authorized user set i ; The data owner sends an instruction to revoke user U i to the edge server, and the edge server deletes the auxiliary search key (ID i , δ i ) in the authorization assistance table.

Citation Information

Patent Citations

  • Searchable public key encryption method and system with key updating and ciphertext sharing functions

    CN113407966A