A searchable encryption method and system with forward and backward security

By introducing delayed encryption and catalyst mechanisms, combined with lattice cryptography and blockchain technology, the vulnerability of traditional encryption algorithms in quantum computing environments is solved, achieving effective defense against quantum attacks and forward and backward data security, thereby improving data privacy protection and system security.

CN119519987BActive Publication Date: 2025-12-05SHANDONG COMP SCI CENTNAT SUPERCOMP CENT IN JINAN +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411665331.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-20
Publication Date
2025-12-05
Estimated Expiration
2044-11-20

AI Technical Summary

Technical Problem

The existing technical problems are: existing technologies cannot effectively resist the threats posed by quantum computing; traditional encryption algorithms are vulnerable to quantum computing; they lack multi-layered defense mechanisms; centralized key management leads to single-point failure risks; key updates are not timely; they lack time control and privacy protection; and they cannot effectively resist complex attacks.

Method used

By employing delayed encryption and catalyst mechanisms, combined with lattice cryptography and blockchain, and using VTLRS signature mechanism and dynamically updated keys, the system ensures that the signature of the trapdoor search is unverifiable within a specified time. The decentralized key management of blockchain enhances the forward and backward security of the system.

Benefits of technology

It significantly enhances the ability to resist online attacks, ensures the privacy and security of data during long-term storage, prevents old keys or trapdoors from being used for unauthorized access, and improves the protection of the identity privacy and legitimacy verification of data requesters.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119519987B_ABST
    Figure CN119519987B_ABST
Patent Text Reader

Abstract

The application provides a searchable encryption method and system with forward and backward security, and relates to the technical field of data security and privacy protection. The method comprises the following steps: a data owner uses a delayed encryption method to perform delayed encryption on plaintext data; a forward and inverted combination search index is created, and the search index is encrypted by combining a public key of the encrypted search index, to obtain an encrypted search index; a data requester uses a private key of the encrypted search index to encrypt a search keyword, introduces a catalyst mechanism, and generates a search trapdoor; time lock information is generated based on the search trapdoor, and the search trapdoor is signed by using a signature private key of the data requester; the data owner sends the delayed encrypted ciphertext and the encrypted search index to a cloud server, and the data requester sends the search trapdoor and the signature to the cloud server; the cloud server verifies the identity of the data requester, matches the search trapdoor and the encrypted search index, and returns the search result to the data requester. The application improves the overall security and flexibility of the searchable encryption system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of data security and privacy protection technology, and in particular relates to a searchable encryption method and system with forward and backward security. Background Technology

[0002] In the era of big data, data security and privacy protection have become increasingly prominent issues. Ensuring data privacy while achieving efficient data utilization has become a core problem in the field of information security. Searchable Encryption (SE) technology allows users to perform keyword searches on encrypted data and is one of the effective technical means to solve the problem of secure data sharing.

[0003] However, existing SE (Security Optimization) schemes face multiple privacy and security threats. For example, key leakage could allow attackers to access past and future data, significantly reducing system security. To address these issues, researchers have proposed forward and backward security schemes to enhance SE algorithms, aiming to ensure that even if keys are leaked, past data remains secure while future data protection is unaffected. However, although introducing forward and backward security strategies has effectively reduced the success rate of keyword guessing attacks to some extent, emerging threats continue to appear, posing a significant challenge to the overall security of SE systems.

[0004] With the development of quantum computing technology, traditional public-key encryption and keyword search schemes will be unable to withstand the threats posed by quantum computing. The powerful processing capabilities of quantum computing make keyword guessing attacks much easier, especially in the event of key leaks. Attackers can use leaked keys to guess, seriously threatening data security. Consequently, the risks of both online and offline attacks are continuously increasing. Online attackers can capture sensitive information for probing attacks by monitoring user requests and responses in real time, and advancements in quantum computing make these attacks even more efficient. Furthermore, offline attacks give attackers the ability to brute-force attacks using captured ciphertext without time constraints. Attackers will find it easier to use these methods to compromise the security of searchable encryption systems, making existing SE (Searchable Encryption) schemes unable to meet users' growing security needs. Therefore, it is urgent to improve the security of searchable encryption technologies to protect data privacy and security.

[0005] Currently, enhanced key management and sophisticated encryption strategies are commonly used to defend against cyberattacks. While these methods improve the security and attack resistance of searchable encryption systems to some extent, the following problems remain:

[0006] First, it lacks resistance to quantum attacks. Current encryption technologies are highly vulnerable to the potential threats posed by quantum computing. The vulnerabilities of traditional encryption algorithms may be exposed, thus exposing sensitive data to unprecedented threats.

[0007] Second, there is a lack of multi-layered defense mechanisms to deal with complex attacks. Existing solutions are easily breached when faced with frequent and complex attacks, and cannot provide sufficient defensive measures.

[0008] Third, untimely updates to keys and trapdoors compromise system security. In current schemes, keys and search trapdoors are typically not dynamically updated before a search, allowing attackers to exploit old keys or trapdoors for subsequent attacks, thus reducing the scheme's forward and backward security.

[0009] Fourth, there is a lack of effective time control and privacy protection mechanisms. The inability to effectively control signature verification time during identity authentication and data access makes the system vulnerable to time-sensitive attacks, thus reducing its privacy protection capabilities.

[0010] Finally, key management in SE schemes typically relies on centralized key storage, which presents a single point of failure risk. If the centralized node is attacked or malfunctions, the security and availability of the keys will be severely impacted. Summary of the Invention

[0011] To overcome the shortcomings of the prior art, the present invention provides a searchable encryption method and system with forward and backward security, which can improve the overall security and flexibility of the searchable encryption system.

[0012] To achieve the above objectives, one or more embodiments of the present invention provide the following technical solutions:

[0013] The first aspect of this invention provides a searchable encryption method with forward and backward security.

[0014] A searchable encryption method with forward and backward security includes the following steps:

[0015] The blockchain sends the generated keys, the public-private key pair for the encrypted search index, and their respective signing private and public keys to the data owners and data requesters.

[0016] The data owner uses a delayed encryption method, combining a key to perform delayed encryption on the plaintext data; based on the key information in the plaintext data, a forward and backward combined search index is created, and then encrypted using the public key of the encrypted search index to obtain the encrypted search index;

[0017] The data requester encrypts the search keywords using the private key of the encrypted search index. At the same time, a catalyst mechanism is selectively introduced to generate a search trapdoor. Based on the search trapdoor, a time lock information is generated, and based on the time lock information, the search trapdoor is signed using its own signing private key.

[0018] The data owner sends the delayed encrypted ciphertext and encrypted search index, while the data requester sends the search trapdoor and signature to the cloud server;

[0019] The cloud server verifies the identity of the data requester based on the signature, matches the search trapdoor with the encrypted search index, and returns the results that match the search criteria to the data requester.

[0020] A second aspect of the present invention provides a searchable encryption system with forward and backward security.

[0021] A searchable encryption system with forward and backward security, comprising:

[0022] The key generation module is configured to send the generated key, the public-private key pair for the encrypted search index, and their respective signing private and public keys to the data owner and data requester.

[0023] The plaintext and search index encryption module is configured as follows: the data owner uses a delayed encryption method, combined with a key, to perform delayed encryption on the plaintext data; based on the key information in the plaintext data, a forward and backward combined search index is created, and then encrypted using the public key of the encrypted search index to obtain the encrypted search index;

[0024] The search trapdoor generation and signing module is configured as follows: the data requester encrypts the search keywords using the private key of the encrypted search index, and selectively introduces a catalyst mechanism to generate a search trapdoor; time lock information is generated based on the search trapdoor, and the search trapdoor is signed using its own signing private key based on the time lock information.

[0025] The transmission module is configured such that: the data owner sends the delayed encrypted ciphertext and encrypted search index, and the data requester sends the search trapdoor and signature to the cloud server;

[0026] The verification and matching module is configured such that the cloud server verifies the identity of the data requester based on the signature, matches the search trapdoor with the encrypted search index, and returns the results that meet the search criteria to the data requester.

[0027] A third aspect of the present invention provides a computer-readable storage medium having a program stored thereon, which, when executed by a processor, implements the steps of the searchable encryption method with forward and backward security as described in the first aspect of the present invention.

[0028] A fourth aspect of the present invention provides an electronic device including a memory, a processor, and a program stored in the memory and executable on the processor, wherein the processor, when executing the program, implements the steps of the searchable encryption method with forward and backward security as described in the first aspect of the present invention.

[0029] The above one or more technical solutions have the following beneficial effects:

[0030] This invention provides a searchable encryption method and system with forward and backward security. It introduces delayed encryption and a catalyst mechanism when encrypting plaintext data to significantly enhance resistance to complex threats such as online attacks. Delayed encryption increases the difficulty for attackers to crack the encryption by postponing the encryption process of plaintext data to a predetermined time point. The catalyst mechanism provides additional acceleration processing, ensuring improved decryption speed under certain conditions, thus achieving an effective balance between security and efficiency.

[0031] This invention employs the VTLRS method, combining time-based locking with a signature mechanism to ensure that the signature of a search trapdoor cannot be verified within a specified time period. This mechanism not only enhances the protection of the data requester's identity privacy but also verifies the authenticity and legitimacy of the data requester's identity. The time-control characteristics of VTLRS further strengthen the system's ability to resist attacks, significantly improving overall data security and privacy protection.

[0032] This invention utilizes lattice cryptography to encrypt the search index, thereby effectively resisting the potential security threats posed by quantum computing and ensuring the privacy and security of data during long-term storage.

[0033] This invention employs a dynamic key update and search trapdoor approach to ensure that data owners and data requesters use the latest encryption key and trapdoor before each search operation. This effectively prevents attackers from obtaining old keys or trapdoors at a certain time and decrypting future data, thus effectively achieving forward and backward security for searchable encryption.

[0034] This invention combines blockchain technology and uses a practical Byzantine fault-tolerant consensus algorithm to elect a Key Control Center (KDC), solving the single point of failure problem in traditional key management. At the same time, blockchain technology ensures the secure storage and management of keys, enhancing their tamper-proof capability and security.

[0035] Advantages of additional aspects of the invention will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of the invention. Attached Figure Description

[0036] The accompanying drawings, which form part of this invention, are used to provide a further understanding of the invention. The illustrative embodiments of the invention and their descriptions are used to explain the invention and do not constitute an improper limitation of the invention.

[0037] Figure 1 This is a flowchart of a searchable encryption method with forward and backward security.

[0038] Figure 2 This is an interaction diagram of a searchable encryption method with forward and backward security.

[0039] Figure 3 This is a searchable cryptographic framework diagram with forward and backward security. Detailed Implementation

[0040] It should be noted that the following detailed descriptions are exemplary and intended to provide further illustration of the invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains.

[0041] It should be noted that the terminology used herein is for the purpose of describing particular implementations only and is not intended to limit the exemplary implementations of the present invention.

[0042] Where there is no conflict, the embodiments and features in the embodiments of the present invention can be combined with each other.

[0043] Terminology Explanation

[0044] LBC, or lattice-based cryptography, is an encryption method based on high-dimensional lattice theory. Its security relies on the difficulty of solving certain mathematical problems, primarily the shortest vector problem and the learning-with-noise problem, which are difficult to solve in both classical and quantum computing environments. The advantage of this cryptographic system lies in its ability to effectively resist the threats of future quantum computing, avoiding the vulnerability of traditional encryption algorithms to quantum computers. This invention utilizes lattice cryptography to encrypt the search index, enhancing the security of searchable encryption systems to effectively resist the threat of quantum attacks.

[0045] Delayed encryption is a technique that encrypts data only under specific conditions, rather than encrypting it immediately upon data generation. This method reduces the impact of real-time encryption on system performance, improves user experience, and effectively counters online attacks. It increases the difficulty of cracking by preventing attackers from obtaining valid encrypted data within a short period. Furthermore, delayed encryption allows the system to take additional protective measures during data processing, ensuring that sensitive data is secure before being accessed. This invention employs a delayed encryption strategy when encrypting plaintext data, allowing decryption only after a specific time has elapsed, thus improving system efficiency and enhancing defense against online attacks.

[0046] VTLRS, or Verifiable Timed Linkable Ring Signature, is a novel cryptographic algorithm that combines linkable ring signatures with timed verification. This mechanism provides anonymity and untraceability for the signer while effectively controlling the timing of data decryption and verification through a time lock, ensuring that data cannot be accessed or tampered with before a specific time point. This enhances data security. This invention uses VTLRS as a search trapdoor for signing data requesters, verifying the legitimacy of their identity while protecting their privacy.

[0047] Example 1

[0048] As mentioned above, to better protect data security and privacy, this invention discloses a searchable encryption method and system with forward and backward security. Overall, it introduces delayed encryption and a catalyst mechanism, and utilizes lattice cryptography to effectively defend against threats such as quantum attacks and online attacks; by dynamically updating keys and search trapdoors, it ensures that data maintains forward and backward security throughout its entire lifecycle; by using verifiable timed-locked ring signatures, it guarantees that the signature of the search trapdoor will not be verified within a specified time period, thereby improving the reliability of identity authentication and the protection of identity privacy; and by leveraging the decentralized nature of blockchain, it enhances the trustworthiness and tamper-proof capabilities of key management.

[0049] like Figure 1 As shown, a searchable encryption method with forward and backward security includes the following steps:

[0050] The blockchain sends the generated keys, the public-private key pair for the encrypted search index, and their respective signing private and public keys to the data owners and data requesters.

[0051] The data owner uses a delayed encryption method, combining a key to perform delayed encryption on the plaintext data; based on the key information in the plaintext data, a forward and backward combined search index is created, and then encrypted using the public key of the encrypted search index to obtain the encrypted search index;

[0052] The data requester encrypts the search keywords using the private key of the encrypted search index. At the same time, a catalyst mechanism is selectively introduced to generate a search trapdoor. Based on the search trapdoor, a time lock information is generated, and based on the time lock information, the search trapdoor is signed using its own signing private key.

[0053] The data owner sends the delayed encrypted ciphertext and encrypted search index, while the data requester sends the search trapdoor and signature to the cloud server;

[0054] The cloud server verifies the identity of the data requester based on the signature, matches the search trapdoor with the encrypted search index, and returns the results that match the search criteria to the data requester.

[0055] Before elaborating on the forward and backward secure searchable encryption method disclosed in this embodiment, we first introduce the application objects of this forward and backward secure searchable encryption method. In this embodiment, the application objects include three parts: a client, a cloud server module (CS), and a blockchain module (BC). The client includes the data owner (DO) and the data requester (DU). The forward and backward secure searchable encryption method described in this embodiment is applied to the information exchange process between the aforementioned data owner (DO), data requester (DU), cloud server module (CS), and blockchain module (BC).

[0056] To better understand this technology, the following will combine... Figure 3 The main functions of the data owner (DO), data requester (DU), cloud server module (CS), and blockchain module (BC) are described as follows:

[0057] 1. Client:

[0058] Its main responsibilities include encrypting plaintext data, generating and encrypting search indexes, generating and signing search trapdoors, submitting encrypted search requests, and decrypting search results. The client is the core user of the system, interacting with cloud servers and the blockchain to achieve secure data storage and retrieval. The following is a functional description:

[0059] 1.1 System registration.

[0060] The data owner (DO) and data requester (DU) in the client submit their identity information (Info) via the blockchain, and the system automatically generates a unique identifier (u). id To ensure user uniqueness, upon successful registration, the system generates a signature key pair (sigsk, sigpk) for each user to ensure the privacy and security of sensitive information, thereby achieving secure and reliable identity management and data access.

[0061] 1.2 Data encryption.

[0062] After successfully registering in the system, the data owner DO obtains the data encryption key msk returned by the blockchain, and then encrypts the plaintext data M into ciphertext CT.

[0063] 1.3 Delayed encryption.

[0064] To effectively defend against online attacks, the data owner DO introduced a delayed encryption strategy. By setting a delay time parameter 'time', the ciphertext CT is generated after delay processing based on a delay function. delayed This mechanism ensures that the ciphertext cannot be decrypted within a set time, thus guaranteeing the security and integrity of the data.

[0065] 1.4 Generate and encrypt the search index.

[0066] The data owner (DO) creates a combined forward and inverted search index based on the key information in the data, encrypts it to obtain the search index (EI), and then sends it along with the ciphertext to the cloud server.

[0067] 1.5 Generate search trapdoors.

[0068] The data requester DU selects the set of keywords to be retrieved and encrypts them using DU's private key sk. At the same time, a catalyst Cat is introduced to accelerate the decryption process in specific scenarios, ultimately resulting in the search trapdoor.

[0069] 1.6 Generate signature σ Trapdoor .

[0070] After the search trapdoor is generated, the data requester DU uses the VTLRS method to combine the hash value of the search trapdoor with a preset delay time to generate a time lock TL. Then, it signs the trapdoor using its signing private key sigsk, ensuring that the search trapdoor cannot be verified within the specified time, thus effectively enhancing its ability to resist attacks. Finally, the signed search trapdoor is sent to the cloud server to request a ciphertext search operation.

[0071] 1.7 Search Trapdoor Update.

[0072] When keys are updated or access permissions change, the data requester (DU) generates a new search trapdoor via the client and submits it to the cloud server, replacing the old one. This ensures that even if the search trapdoor is leaked, attackers cannot use the old one to access or search encrypted data, thus achieving forward security and enhancing the overall system security.

[0073] 1.8 Decrypt the search results.

[0074] After receiving the encrypted search results from the cloud server, the client uses its private key to decrypt the returned encrypted data. The decrypted data is then the plaintext data M representing the search results.

[0075] 2. Cloud Server Module:

[0076] The cloud server is primarily responsible for storing encrypted text and search indexes, receiving search requests, executing encrypted search operations after successful signature verification, and returning the final search results. The following is a description of its functions:

[0077] 2.1 Ciphertext and Index Storage.

[0078] The cloud server receives the encrypted CT sent by the client. delayed After successful storage of the corresponding encrypted search index EI, the system returns the ciphertext and index hash storage address addr. CT and addr EI And it manages them effectively. Because both data and indexes are encrypted, the cloud server cannot access the plaintext content of the data, ensuring data security.

[0079] 2.2 Signature verification.

[0080] The cloud server receives the search trap and signature σ submitted by the client. Trapdoor Next, the signature is first hashed and verified. If the verification is successful, the ciphertext operation can continue; otherwise, the search request is rejected.

[0081] 2.3 Ciphertext Search.

[0082] Once the signature verification is successful, the cloud server retrieves the corresponding encrypted data based on the matching results between the search trapdoor and the encrypted search index.

[0083] 2.4 Return search results.

[0084] Once the cloud server successfully matches encrypted data related to the search trapdoor, it will use this encrypted data as the search results (SearchResults) and its corresponding storage address (addr). l This information is then returned to the client.

[0085] 3. Blockchain Module:

[0086] The blockchain module is responsible for electing the key distribution center, managing the generation, updating, and revocation of keys, and recording all encryption and operational processes to ensure the system's decentralization and transparency. The participating nodes in the blockchain collectively maintain the security and consistency of these operations. The following is a functional description:

[0087] 3.1 Election Key Distribution Center (KDC)

[0088] The blockchain module elects a Key Distribution Center (KDC) using a practical Byzantine fault-tolerant consensus algorithm. The KDC is responsible for generating encryption keys for encrypting plaintext data and search indexes, performing key update and revocation functions, and generating public and private keys for signing.

[0089] 3.2 Key generation.

[0090] The key distribution center uses the AES encryption algorithm to generate encryption keys. At the same time, it uses lattice cryptography to obtain the public and private key pair of the encryption search index by selecting appropriate parameters and randomly generating invertible polynomials f and g. It also sets a time parameter for the delayed encryption strategy to resist online attacks.

[0091] 3.3 Key storage.

[0092] All generated encryption keys are stored on the blockchain to ensure that the key information cannot be tampered with, reduce the risk of data leakage, and guarantee the trustworthiness of the keys.

[0093] 3.4 Key update and revocation.

[0094] To ensure the forward and backward security of searchable encryption, the key distribution center periodically triggers a key update mechanism. During this process, a new key replaces the old key, guaranteeing that the system can still protect data security in the event of key leakage or threats. Furthermore, when a client revokes access permissions or a key leakage is detected, the key distribution center immediately performs a key revocation operation and records this process on the blockchain, ensuring that revoked keys cannot decrypt or access data.

[0095] Next, we will combine Figure 1 and Figure 2 The method of this embodiment will be explained in detail below. The specific steps of the method described in this embodiment are as follows:

[0096] 1. Initialization: Setup(λ) → {param, n, T}

[0097] Using a practical Byzantine fault-tolerant consensus algorithm, a Key Distribution Center (KDC) is elected by the blockchain nodes. The KDC is then input with a random parameter λ to generate system parameters param, which lay the foundation for subsequent key generation. At the same time, the ring size n, i.e. the size of the set of users participating in signature verification, and the time lock parameter T are initialized to support the timed verification mechanism.

[0098] 2. Identity Registration: ClientAuth(Info) → {u id ,sigsk,sigpk}

[0099] Data requesters (DU) and data owners (DO) register their identities via the blockchain, providing identity information (Info). A unique identifier (u) is automatically generated during registration. id After successful registration, KDC will be responsible for generating the signing private key sigsk. id and public key sigpk id .

[0100] 3. Key generation: keyGen(param,q,N)→{msk,pk,sk}

[0101] Generate the key msk for encrypting the original data, and generate the public-private key pair for the encrypted search index based on the LBC encryption method. The specific public-private key generation steps are as follows:

[0102] 3.1 Select parameters. Choose the polynomial order N and the modulus q, usually q is a large prime number. Choose a small positive integer p to limit the coefficients of the polynomial.

[0103] 3.2 Randomly select polynomials. Randomly generate polynomials f and g:

[0104] f(x) = f0 + f1x + f2x 2 +…+f N-1 x N-1 #(1)

[0105] g(x) = g0 + g1x + g2x 2 +…+g N-1 x N-1 #(2)

[0106] This requires ensuring that f is invertible and has specific coefficients, typically finvertible. i ∈(-1,0,1). g is also randomly generated, and its coefficient range is...

[0107] 3.3 Calculate the key pair. This is done through polynomial division and modular arithmetic.

[0108]

[0109] Let h be the public key for the encrypted search index, i.e., pk = h, and f be the private key, i.e., sk = f.

[0110] 4. Key storage: Store(msk, pk, sk, sigsk, sigpk) → Blockchain

[0111] The key msk for generating the ciphertext, the public-private key pair (pk, sk) for the encrypted search index, and the signing key are securely stored on the blockchain.

[0112] 5. Ciphertext generation: Enc_ciphertext(msk,M)→CT

[0113] In the data encryption step, the plaintext data M is encrypted using the key msk to generate the ciphertext CT.

[0114] 6. Delay processing: Delay(CT, time) → CT delayed

[0115] After generating the encrypted CT, set the delay time (time) according to the delay function formula.

[0116]

[0117] A delay is applied, where `time` is the delay parameter controlling the decryption complexity, `g` is the base, usually a small integer, and `R` is the product of two large prime numbers. The final result is the delayed ciphertext CT. delayed This step ensures that the encrypted text cannot be decrypted within the set time, effectively resisting online attacks.

[0118] 7. Search Index Generation and Encryption: Index_Gen&Enc(CT) delayed ,pk)→EI

[0119] After the ciphertext is generated, a relevant search index is generated based on the key information in the data and then encrypted. The specific steps are as follows:

[0120] 7.1 Index information processing.

[0121] Extract keywords from the data to form a keyword set {kw1,kw2,…,kw} g} and map each keyword to the corresponding set of data entries.

[0122] D(kw i )={d1,d2,…,d m}#(5)

[0123] Where d i Represents a data entry; D(kw) i ) indicates the keyword kw i A set of related data entries, where each data entry is a single data record actually stored in a database or file and associated with a keyword. Each data entry may contain multiple keywords, for example: d1: contains the keywords "fever" and "cough". d2: contains the keywords "fever" and "fatigue". The set of data entries corresponding to the keyword "fever" is D(kw i This includes d1 and d2.

[0124] 7.2 Index generation.

[0125] First, the mapping between each data entry and the keywords it contains is as follows:

[0126] F(d j )={kw1,kw2,…,kw g},#(6)

[0127] Where F(d) j ) indicates from data entry d j The set of all keywords extracted; d j It refers to a specific data entry, namely {d1, d2, ..., d...}. m Any one of the following, for example, suppose there are three data entries: d1 = "Patient A, symptoms include fever and cough.", where d1 contains the keywords F(d1) = {"fever", "cough"}; d2 = "Patient B, symptoms include fatigue and fever.", where d2 contains the keywords F(d2) = {"fever", "fatigue"}; and d3 = "Patient C, symptoms include headache.", where d3 contains the keyword F(d3) = {"headache"}.

[0128] Generate the corresponding positive index FI according to formula (6).

[0129] FI={(d1,F(d1)),(d2,F(d2)),…,(d m ,F(d m ))}.#(7)

[0130] Then, an inverted index is generated to quickly find relevant data entries based on keywords, where the keyword is kw. i In the positive index F(d) j All data entries d in ) j The set I(kw) i )for:

[0131] I(kw i )={d j |kw i ∈F(d j )},#(8)

[0132] Generate the corresponding inverted index II according to formula (8).

[0133] II={(kw1,I(kw1)),(kw2,I(kw2)),…,(kw g ,I(kw g ))}.#(9)

[0134] Finally, a search index I for the forward inverted combination is generated. FI&II .

[0135] 7.3 Encrypted Search Index

[0136] Data owner DO uses data requester DU's public key pk to combine the forward and inverted indexes I. FI&II Encryption is used to generate an encrypted search index, EI.

[0137] 8. Store (CT) for storing encrypted data and searching indexes delayed ,EI)→{addr CT ,addr EI}

[0138] encrypted CT delayed Securely upload the encrypted search index (EI) to the cloud server, and return the corresponding storage address (addr) after storage. CT with addr EI This delayed encryption process ensures that the cloud server cannot decrypt the stored information, preventing unauthorized access and protecting data privacy.

[0139] 9. Generate a search trapdoor: TrapGen(W, sk, Cat) → Trapdoor

[0140] The search keywords are encrypted using the private key sk of the data requester DU to generate a search trapdoor bound to the user's identity information. A catalyst mechanism is introduced during the trapdoor generation process to enhance security and complexity, ensuring the trapdoor has stronger protection when matched with the encrypted index.

[0141] 9.1 Select keywords.

[0142] The data requester DU selects the set of keywords W to search for and encrypts the search keywords using its private key sk.

[0143] 9.2 Introduction of catalyst mechanism.

[0144] Introducing the catalyst Cat into the trapdoor generation process allows the data requester (DU) to selectively accelerate the trapdoor generation process while communicating with the honest data owner (DO). This setting enables the data requester (DU) to respond flexibly to different situations, either delaying the generation of ciphertext in general to improve security, or responding quickly in specific scenarios without compromising overall security and privacy protection.

[0145] It can be understood that Catalyst here is a mechanism used to accelerate the trapdoor generation process. It allows data requesters to expedite operations in specific situations (such as urgent needs on a trusted basis), while maintaining regular delay mechanisms to ensure security in general. The core value of Catalyst lies in its flexibility and efficiency, specifically ensuring that the overall privacy and security of the system are not compromised.

[0146] 9.3 Generate search trapdoors.

[0147] 1) If the search request of the data requester DU can guarantee that the data owner DO is completely trusted, such as a legitimate medical institution, and the data requester DU needs to speed up the search time, then a catalyst Cat can be introduced when generating the search trapdoor to accelerate the search trapdoor generation process and ensure the real-time response of the search operation.

[0148] 2) If the data requester DU's search request is in an environment that requires strict privacy and security, and there are no special requirements for search speed, then there is no need to introduce a catalyst, and the encrypted search operation is performed after the signature verification is completed.

[0149] 10. Signature generation Sig(Trapdoor, sigsk) id ,T)→σ Trapdoor

[0150] Data requester DU uses the signing private key sigsk to generate a signature σ on the search trapdoor. Trapdoor The specific process is as follows:

[0151] 1) Signature search trap.

[0152] Based on the required delay time T, use VTLRS to generate time lock information.

[0153] TL=TimeLock(Hash(Trapdoor),T),#(10)

[0154] Here, TL represents the time lock information, ensuring that unlocking and access operations (such as unlocking and access) can only be performed after a specified delay time T; Hash(Trapdoor) hashes the search trapdoor (query condition) to generate a fixed-length string for enhanced security; T is the delay time, specifying when operations cannot be performed, adding execution time control; TimeLock is a function name of an encryption algorithm that takes the hash(Trapdoor) obtained by hashing the generated search trapdoor as input and the delay time parameter T to generate an encrypted time lock TL. Then, the data requester DU signs the generated search trapdoor.

[0155] σ Trapdoor =Signature(TL,sigsk).#(11)

[0156] 2) Submit a search request.

[0157] Data requester DU will generate the search trapdoor and its signature σ TrapdoorThe results were submitted to the cloud server, requesting it to retrieve the encrypted results related to the search trapdoor.

[0158] 11. Key update and revocation mechanism: Update&Rew(pk,sk,ω) → {pk′,sk′}

[0159] The Key Distribution Center (KDC) updates the keys pk and sk based on the ciphertext state ω or periodically to ensure that even if a key is leaked, the old key cannot decrypt future data. Simultaneously, when the data owner (DO) does not wish for the data requester to continue accessing the ciphertext, they can promptly delete the relevant information and revoke unused keys. This effectively prevents the malicious use of leaked keys and enhances the forward and backward security of the searchable encryption algorithm, ensuring that sensitive information is not illegally accessed.

[0160] 12. Search for trapdoors and update TrapUpda(W,Trapdoor,sk′) → {Trapdoor′}

[0161] As data and access permissions change, the data requester (DU) periodically updates the search trapdoor to ensure the security and effectiveness of the search mechanism. By combining the old search trapdoor with the new key sk′, the data requester uses a hash function to calculate the new search trapdoor′:

[0162] Trapdoor′=Hash(Trapdoor,sk′)#(12)

[0163] After the trapdoor update is complete, the data requester (DU) needs to replace the old trapdoor stored in the cloud server with the newly generated trapdoor to ensure that all search operations in the system are based on the latest trapdoor. By updating the search trapdoor, it is ensured that even if an attacker obtains the old search trapdoor, they cannot deduce the new trapdoor, thereby enhancing the forward and backward security of the searchable encryption algorithm.

[0164] 13. Verify signature (σ) Ttapdoor ,Trapdoor)→{'true','false'}

[0165] The cloud server received the search trap and signature σ submitted by the data requester DU. Trapdoor Then, the signature of the data requester is hashed and verified. If the signature verification is successful and returns "true", it means that the search trap was signed by a legitimate data requester, confirming that the user is a legitimate registered user. Otherwise, if the signature returns "false", it means that there may be an attacker, so the search request is rejected and corresponding security measures are taken.

[0166] 14. Encrypted Search: Search(Trapdoor, EI, 'true') → SearchResults

[0167] After successful signature verification, the cloud server performs a encrypted search operation, matching the search traps submitted by the data requester DU with the encrypted search index EI to find results that meet the search criteria (SearchResults).

[0168] 15. Return the encrypted search results. Return(SearchResults, addr) l →DU

[0169] The cloud server will store the search results (SearchResults) and their corresponding storage address (addr). l Returned to the data requester DU.

[0170] 16. Decrypt the search results Dec(SearchResults, addr l ,sk)→Results

[0171] The data requester DU receives encrypted search results (SearchResults) returned by the cloud server, based on its address (addr). l Download the ciphertext, then use its private key sk to decrypt the ciphertext search results to obtain the plaintext data Results.

[0172] This embodiment discloses a searchable encryption method with forward and backward security. First, it introduces delayed encryption and a catalyst mechanism to increase the difficulty of network attacks and enhance the ability to resist online attacks. Second, it uses lattice cryptography to encrypt the search index to effectively resist the threat of quantum attacks. Third, it employs a verifiable time-locked ring signature method, combining a time lock with a signature mechanism to ensure that the signature of the search trapdoor cannot be cracked or forged within a specified time period, and to achieve privacy protection and legitimacy verification of the data requester's identity. Fourth, it uses a dynamically updated key and search trapdoor approach to prevent attackers from using old keys or trapdoors for unauthorized access, ensuring the forward and backward security of encrypted data during the search process. Finally, to ensure the security and trustworthiness of the key, a key distribution center is elected using a blockchain consensus algorithm, ensuring the transparency and tamper-proof capability of the key management process.

[0173] Example 2

[0174] This embodiment discloses a searchable encryption system with forward and backward security.

[0175] A searchable encryption system with forward and backward security, comprising:

[0176] The key generation module is configured to send the generated key, the public-private key pair for the encrypted search index, and their respective signing private and public keys to the data owner and data requester.

[0177] The plaintext and search index encryption module is configured as follows: the data owner uses a delayed encryption method, combined with a key, to perform delayed encryption on the plaintext data; based on the key information in the plaintext data, a forward and backward combined search index is created, and then encrypted using the public key of the encrypted search index to obtain the encrypted search index;

[0178] The search trapdoor generation and signing module is configured as follows: the data requester encrypts the search keywords using the private key of the encrypted search index, and selectively introduces a catalyst mechanism to generate a search trapdoor; time lock information is generated based on the search trapdoor, and the search trapdoor is signed using its own signing private key based on the time lock information.

[0179] The transmission module is configured such that: the data owner sends the delayed encrypted ciphertext and encrypted search index, and the data requester sends the search trapdoor and signature to the cloud server;

[0180] The verification and matching module is configured such that the cloud server verifies the identity of the data requester based on the signature, matches the search trapdoor with the encrypted search index, and returns the results that meet the search criteria to the data requester.

[0181] Example 3

[0182] The purpose of this embodiment is to provide a computer-readable storage medium.

[0183] A computer-readable storage medium having a computer program stored thereon that, when executed by a processor, implements the steps of the searchable encryption method with forward and backward security as described in Embodiment 1 of this disclosure.

[0184] Example 4

[0185] The purpose of this embodiment is to provide an electronic device.

[0186] An electronic device includes a memory, a processor, and a program stored in the memory and executable on the processor, wherein the processor, when executing the program, implements the steps of the searchable encryption method with forward and backward security as described in Embodiment 1 of this disclosure.

[0187] The steps and methods involved in the apparatuses of Embodiments 2, 3, and 4 above correspond to those in Embodiment 1. For specific implementation details, please refer to the relevant description section of Embodiment 1. The term "computer-readable storage medium" should be understood as a single medium or multiple media including one or more instruction sets; it should also be understood as including any medium capable of storing, encoding, or carrying an instruction set for execution by a processor and enabling the processor to perform any of the methods in this invention.

[0188] Those skilled in the art will understand that the modules or steps of the present invention described above can be implemented using general-purpose computer devices. Optionally, they can be implemented using computer-executable program code, thereby allowing them to be stored in a storage device for execution by a computer device, or they can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. The present invention is not limited to any particular combination of hardware and software.

[0189] While the specific embodiments of the present invention have been described above in conjunction with the accompanying drawings, this is not intended to limit the scope of protection of the present invention. Those skilled in the art should understand that various modifications or variations that can be made by those skilled in the art without creative effort based on the technical solutions of the present invention are still within the scope of protection of the present invention.

Claims

1. A searchable encryption method with forward and backward security, characterized by, The method comprises the following steps: The blockchain sends the generated key, the public and private key pair of the encrypted search index, and the respective signature private key and public key to the data owner and the data requester; The data owner uses a delayed encryption method to combine the key and plaintext data for delayed encryption; according to the key information in the plaintext data, a search index of forward and inverted combination is created, and the public key of the encrypted search index is combined for encryption to obtain an encrypted search index; The data requester encrypts the search keyword by using the private key of the encrypted search index, and selectively introduces a catalyst mechanism to generate a search trapdoor; time lock information is generated based on the search trapdoor, and the search trapdoor is signed by using the signature private key of the data requester based on the time lock information; The data owner sends the delayed encrypted ciphertext and the encrypted search index to the cloud server, and the data requester sends the search trapdoor and the signature to the cloud server; The cloud server verifies the identity of the data requester based on the signature, and matches the search trapdoor and the encrypted search index to find the result meeting the search condition and return the result to the data requester.

2. The searchable encryption method with forward and backward security as claimed in claim 1, wherein, Further, the blockchain generates the key, the public and private key pair of the encrypted search index, and the signature private key and public key, specifically including: The data requester and the data owner register their identities through the blockchain, and the signature private key and public key are generated by the key distribution center (KDC) of the blockchain after successful registration; The blockchain generates the public and private key pair of the encrypted search index based on the LBC encryption method, specifically including: Selecting the polynomial order and the modulus ; Based on polynomial order , randomly generate two polynomials and ; polynomials and , and modulus , the public key of the encrypted search index is calculated by polynomial division and modulus operation, and one of the polynomials is taken as the private key of the encrypted search index.

3. The searchable encryption method with forward and backward security as claimed in claim 1, wherein, The data owner uses a delayed encryption method to combine the key and plaintext data for delayed encryption, specifically including: Encrypting the plaintext data M using the key msk, generating ciphertext ; Setting a delay time , according to the delay function, the ciphertext delay processing, get the delay ciphertext .

4. The searchable encryption method with forward and backward security as claimed in claim 3, wherein, According to the key information in the plaintext data, a search index of forward and inverted combination is created, specifically including: The key information in the plaintext data is extracted to form a keyword set, and each keyword is mapped to a corresponding data entry set; The mapping between each data entry and the keywords contained therein is determined to generate a corresponding forward index; The set of all data entries of the keyword in the forward index is determined to generate an inverted index for quickly finding related data entries according to the keyword; The forward and inverted combination search index is generated by combining the forward index and the inverted index.

5. The searchable encryption method with forward and backward security as claimed in claim 1, wherein, The data requester encrypts the search keyword by using the private key of the encrypted search index, and selectively introduces a catalyst mechanism to generate a search trapdoor, specifically including: The data requester selects a search keyword and encrypts the search keyword by using the private key of the encrypted search index to obtain an encrypted search keyword; The catalyst is introduced into the generation process of the search trapdoor, and the data requester selectively accelerates the generation process of the ciphertext; The search trapdoor is generated according to the encrypted search keyword information and the introduced catalyst.

6. The searchable encryption method with forward and backward security as claimed in claim 1, wherein, Time lock information is generated based on the search trapdoor, and the search trapdoor is signed by using the signature private key of the data requester based on the time lock information, specifically including: The data requester uses the VTLRS method to combine the hash value of the search trapdoor with the preset delay time to generate time lock information; The search trapdoor is signed based on the time lock information and the signature private key of the data requester.

7. The searchable encryption method with forward and backward security as claimed in claim 1, wherein, Further, the public and private key pair of the encrypted search index and the search trapdoor are dynamically updated, specifically including: The blockchain sends a public-private key pair for encrypting the search index according to the ciphertext state or timing update; The data requester generates a new search trapdoor and updates it in the cloud server when the key is updated or the access right is changed; When the data owner does not want the data requester to continue to access the ciphertext information, the key revocation operation is performed through the key distribution center to revoke the key that is no longer used.

8. A searchable encryption system with forward and backward security, characterized by, The key generation module is configured to send the generated key, the public-private key pair for encrypting the search index, and the respective signature private key and public key to the data owner and the data requester by the blockchain; The plaintext and search index encryption module is configured to encrypt the plaintext data by the data owner using a delayed encryption method in combination with the key; create a forward-inverted combined search index according to the key information in the plaintext data, and encrypt the search index in combination with the public key of the encrypted search index to obtain the encrypted search index; The search trapdoor generation and signature module is configured to encrypt the search keyword by the data requester using the private key of the encrypted search index, and selectively introduce a catalyst mechanism to generate a search trapdoor; generate time lock information based on the search trapdoor, and use the own signature private key to sign the search trapdoor based on the time lock information; The transmission module is configured to send the delayed encrypted ciphertext and the encrypted search index by the data owner, and send the search trapdoor and the signature by the data requester to the cloud server; The verification and matching module is configured to verify the identity of the data requester based on the signature by the cloud server, and match the search trapdoor and the encrypted search index to find the result meeting the search condition and return it to the data requester. The program is executed by the processor to implement the steps in the searchable encryption method with forward and backward security according to any one of claims 1-7.

9. A computer-readable storage medium having stored thereon a program, characterized in that, The processor executes the program to implement the steps in the searchable encryption method with forward and backward security according to any one of claims 1-7.

10. An electronic device comprising a memory, a processor, and a program stored on the memory and executable on the processor, characterized in that, ​

Citation Information

Patent Citations

  • Efficient searchable symmetric encryption method and system with forward and backward security

    CN110457915A

  • VDF-based cloud storage time sensitive data automatic deletion scheme and system

    CN117421745A