A method for accelerating aggregate queries on outsourced homomorphic encryption databases
By introducing ciphertext index and homomorphic aggregation calculation in homomorphic encrypted database, the problem of inefficient aggregation query is solved, and efficient and secure data query is achieved, which is suitable for cloud computing environments.
Patent Information
- Application Number
- CN202510227654.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-27
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2045-02-27
AI Technical Summary
Homomorphic encrypted databases are inefficient when aggregating queries and lack effective data indexing and query acceleration mechanisms, making it difficult to meet the requirements of efficient and real-time query.
By generating the master key and index key in the initialization stage, encrypted data and ciphertext index are generated in the data upload stage, and using ciphertext index to perform rapid query and homomorphic aggregation calculations in the query stage, outputting the ciphertext results of the aggregate query.
It effectively reduces the redundant computing overhead in homomorphic encrypted database aggregation queries, improves the execution speed of queries, protects the privacy of the query process and data security, and is suitable for various data service platforms in the cloud computing environment.
Smart Images

Figure CN119720282B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of outsourced databases, and in particular to an acceleration method for aggregate queries on outsourced homomorphic encryption databases. Background Art
[0002] With the widespread application of cloud computing technology, data outsourcing has become an effective way for enterprises and individual users to store and process large amounts of data. However, the outsourced storage and processing of data has raised concerns about data privacy and security. Homomorphic encryption technology, as a technology that allows direct calculations on encrypted data, provides a possible solution to this problem. It allows data to be processed and queried in an encrypted state, thereby ensuring the privacy and security of data in the cloud. Although homomorphic encryption technology provides an ideal solution in theory, it faces significant computational overhead problems in practical applications, especially when performing data aggregation queries. Due to the need to perform complex computations on a large amount of encrypted data, query processing often takes a long time and is inefficient. In addition, existing homomorphic encryption query solutions often lack effective data indexing and query acceleration mechanisms, making it difficult to meet the query requirements of efficiency and real-time performance in practical applications.
[0003] In order to overcome the above problems, a new method is needed to improve the query performance of homomorphic encrypted databases, especially in data aggregation queries, without sacrificing data security and privacy. Therefore, studying a method that can effectively reduce the redundant computing overhead in homomorphic encrypted database aggregation queries and improve query efficiency has become a key technical challenge that needs to be solved in this field of technology. Summary of the invention
[0004] The purpose of the present invention is to provide an acceleration method for aggregate query of outsourced homomorphic encryption database, which can solve the low efficiency problem faced by traditional homomorphic encryption database in aggregate query while ensuring the security and privacy of data.
[0005] The objective of the present invention is achieved through the following technical solutions:
[0006] A method for accelerating aggregate queries on an outsourced homomorphic encryption database, the method comprising:
[0007] Step 1: In the initialization phase, the user registers with the server to use the outsourced encryption database and generates a master key, and then derives the encryption key and index key based on the master key;
[0008] Step 2: During the data upload phase, the user generates encrypted data and a ciphertext index and uploads them to the server. After receiving the upload request, the server stores the received encrypted data in the database and obtains the unique identifier of the encrypted data. It calls the symmetric searchable encryption algorithm based on the unique identifier and the received ciphertext index to update the server-side ciphertext index.
[0009] Step 3: In the query phase, the user converts the plaintext conditions of the query statement into homomorphic ciphertext and ciphertext index query fields; the server outputs the ciphertext that meets the conditions according to the ciphertext index query fields, and then filters the output results according to the homomorphic ciphertext conditions, and finally performs homomorphic inner product aggregation calculation, outputs the ciphertext results of the aggregate query, and returns the ciphertext to the user;
[0010] Step 4: In the decryption phase, the user uses the homomorphic encryption algorithm to decrypt the returned ciphertext to obtain the plaintext of the aggregated query result.
[0011] It can be seen from the technical solution provided by the present invention that the above method can solve the inefficiency problem faced by traditional homomorphic encryption databases in aggregate queries, effectively reduce the calculation of redundant items in aggregate queries of homomorphic encryption databases, and improve the execution speed of queries. At the same time, it protects the privacy of the query process and the security of the data, and is suitable for various data service platforms in a cloud computing environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.
[0013] Figure 1 A schematic flow chart of an acceleration method for aggregate query of an outsourced homomorphic encrypted database provided by an embodiment of the present invention;
[0014] Figure 2 The figure is a schematic diagram of the implementation process of the aggregate query acceleration method described in an embodiment of the present invention. DETAILED DESCRIPTION
[0015] The following is a clear and complete description of the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments, which does not constitute a limitation of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0016] like Figure 1The figure is a schematic flow chart of an acceleration method for aggregate query of an outsourced homomorphic encryption database provided by an embodiment of the present invention, the method comprising:
[0017] Step 1: In the initialization phase, the user registers with the server to use the outsourced encryption database and generates a master key, and then derives the encryption key and index key based on the master key;
[0018] In this step, the user applies to the server for the use of the outsourced encrypted database, the server applies for resources for the user, and the two establish a secure transmission channel;
[0019] The user uses a random number generation algorithm to generate a master key, and uses the master key to derive an encryption key and an index key. The encryption key is used to encrypt plaintext data when uploading data, and the index key is used to generate ciphertext of index fields during the data upload and query stages.
[0020] In the specific implementation, the encryption algorithm category is a fully homomorphic encryption algorithm of the LWE type, and the key length can be adjusted according to the security level required by the actual scenario in combination with the homomorphic encryption algorithm.
[0021] Step 2: During the data upload phase, the user generates encrypted data and a ciphertext index and uploads them to the server. After receiving the upload request, the server stores the received encrypted data in the database and obtains the unique identifier of the encrypted data. It calls the symmetric searchable encryption algorithm based on the unique identifier and the received ciphertext index to update the server-side ciphertext index.
[0022] In this step, the user uses the encryption key and homomorphic encryption algorithm to encrypt the data. After encoding the data to generate a keyword set, the index key and symmetric searchable encryption algorithm are used to construct a ciphertext index for the keyword set. The encrypted data is encapsulated into an SQL statement and sent to the server together with the ciphertext index.
[0023] After receiving the upload request, the server delivers the database interface according to the received SQL statement containing the encrypted data, obtains the unique identifier of the encrypted data in the database (which can be the primary key value), takes the ciphertext index update field as input, and calls the symmetric searchable encryption algorithm to output the key value storage of the server-side ciphertext index, and updates the unique identifier of the uploaded encrypted data to the ciphertext index;
[0024] The symmetric searchable encryption algorithm refers to a method in which a user generates ciphertext by calling a pseudo-random function and a hash algorithm in a specific order according to the data value, the table name and the attribute to which it belongs.
[0025] For example, if Figure 2The figure shows a schematic diagram of the implementation process of the aggregate query acceleration method described in an embodiment of the present invention. The user encrypts a row of data to be uploaded using an encryption key and embeds it into an INSERT statement. At the same time, each attribute value of the uploaded data is binary-encoded and a leaf node corresponding to the attribute binary tree is constructed. In this process, it is necessary to ensure that the encoding of each node of each binary tree is different. The encoding set of each attribute value from the root node to the leaf node corresponding to the attribute value is obtained as the keyword set of a row of data, and then the symmetric searchable encryption algorithm is called to encrypt the keyword set to generate an index encrypted upload field, and the encrypted INSERT statement and the encrypted upload field are sent to the server together.
[0026] like Figure 2 As shown in the figure, taking the age attribute with the personnel attribute type set to uint_32 as the "table name" as an example, a binary tree with a depth of 32+1=33 is established for this attribute, and each node is uniquely encoded. The encoding method can be set to "table name|attribute|depth|path", where the path is a left-to-right sequence from the root node to the current node, which can be set to 0 on the left and 1 on the right; when inserting an attribute value "5", first generate the encoding "personnel|age|32|0x0005" (leaf node) on the binary tree according to its binary, and generate the encoding of all nodes from this node to the root node, such as "personnel|age|30|0x0002"; then, the encoding set of the attribute value is input into the symmetric searchable encryption algorithm using the user query key, the ciphertext index upload field is generated, and the attribute value is encrypted with the encryption key and sent to the server together.
[0027] After receiving the upload request, the server delivers the received INSERT upload statement to the database and stores the ciphertext in the database, obtaining the unique identifier of the row of data for index maintenance; for the received ciphertext upload field, the server updates the keyword set corresponding to it, that is, adds the unique identifier of the uploaded data to the unique identifier set that can be indexed by each keyword; the ciphertext index storage data structure is key-value storage, where the key is the ciphertext corresponding to the keyword, and the value is the unique identifier set of the keyword corresponding to the data. Here, you can choose to call the most advanced symmetric searchable encryption server algorithm to update the server-side stored ciphertext index.
[0028] like Figure 2 As shown in the figure, taking the insertion of the attribute value "5" of the age attribute with the attribute type set to uint_32 as an example, the server first inserts the ciphertext of the attribute value and other attribute values into the database and obtains the unique identifier of the row; then the received ciphertext index upload field is unpacked, and the ciphertext fields corresponding to all keywords (the unique identifier of the node on the user side) on the server are used as the key of the key-value storage, whose value type is a collection of unique identifier types, the unique identifier is inserted into the value, and the ciphertext index is updated according to the algorithm requirements.
[0029] Step 3: In the query phase, the user converts the plaintext conditions of the query statement into homomorphic ciphertext and ciphertext index query fields; the server outputs the ciphertext that meets the conditions according to the ciphertext index query fields, and then filters the output results according to the homomorphic ciphertext conditions, and finally performs homomorphic inner product aggregation calculation, outputs the ciphertext results of the aggregate query, and returns the ciphertext to the user;
[0030] In this step, in step 3, at the query stage, the user encrypts the query conditions through the homomorphic encryption algorithm, converts the query conditions into keywords according to the single keyword range coverage algorithm, and uses the index key of step 1 to generate a ciphertext index query field according to the keyword through the symmetric searchable encryption algorithm; then encapsulates the encrypted query conditions into an SQL statement and sends it to the server together with the ciphertext index query field;
[0031] The server uses the received ciphertext index query field to query the ciphertext index key value storage to obtain a unique identifier set, and inputs the unique identifier value set as a database subquery to obtain an output result table. Then, based on the input homomorphic ciphertext condition, the server calls the homomorphic subtraction and homomorphic highest bit algorithms in a specific order for each row of the output result table, outputs whether the ciphertext bits meet the conditions, and then performs a vector inner product operation on the converted result and the ciphertext bits, outputs the ciphertext result of the aggregate query, and returns the ciphertext to the user.
[0032] Among them, the homomorphic conversion algorithm refers to converting the ciphertext format from the LWE format to the RLWE format, that is, outputting the ciphertext in a format that supports batch aggregation calculations.
[0033] For example, the user uses an encryption key to encrypt the conditions to be queried and encapsulates them into a SELECT statement. At the same time, the user finds the equivalent conditions or range conditions in the conditions, binary encodes the values corresponding to the conditions, and corresponds them to the leaf nodes of the binary tree in combination with their attributes. For the equivalent conditions, the leaf node is selected as the keyword; for the range conditions, a node on the binary tree that can contain the interval is selected as the keyword; the search algorithm of symmetric searchable encryption is called to encrypt the selected keywords and generate an index encrypted query field; and the encrypted SELECT statement and the encrypted query field are sent to the server together.
[0034] like Figure 2 As shown in the figure, when a range query of [1,3] is performed on the age attribute of the personnel table, the generator will find the smallest node [0,3] that contains all values from 1 to 3 as the query keyword, and generate its encoding "personnel|age|30|0x00000000", input it into the user query algorithm of symmetric searchable encryption, and generate a ciphertext index query field, which is sent to the server together with the ciphertext value of [1,3].
[0035] After receiving the query request, the server will not deliver the received SELECT upload statement to the database temporarily. First, it will perform the first-level filtering to achieve a rough screening of the conditions. The server will find the unique identifier set corresponding to the keyword set corresponding to the ciphertext index query field, that is, find the unique identifier set that can be indexed by the keyword according to the query keyword; here, you can choose to call the most advanced symmetric searchable encryption server query algorithm to query the server-side stored ciphertext index; generate a new query statement for the obtained unique identifier set, filter out all the data in the unique identifier set, and output the obtained result as a new table. For example, when performing a [1,3] range query on the age attribute of the personnel table, the server will unpack the received ciphertext index query field, find the corresponding index key and obtain the corresponding unique identifier set based on it, and request the database for the rows of these unique identifiers to build a new table as the input for homomorphic filtering processing.
[0036] After completing the first level of filtering, the server outputs the encrypted row number information (LWE ciphertext). This process is the second level of filtering. This level of filtering uses homomorphic filtering technology to accurately filter the results of the first level of filtering. The second level uses homomorphic filtering to refine the results based on the data obtained from the first level of filtering. The first level of filtering will remove data that does not meet the conditions, and the second level of filtering uses a homomorphic ciphertext vector with a Boolean encoding type to save the filtering results. The input of the final aggregation stage includes two parts of homomorphic ciphertext, the ciphertext data obtained by the first level of filtering, and the Boolean homomorphic ciphertext vector obtained by the second level of filtering. For example, when a [1,3] range query is performed on the age attribute of the personnel table, the result obtained in the first level of filtering is all [0,3] rows. In the second level of homomorphic filtering, the age field of these rows is calculated on the ciphertext, that is, ciphertext subtraction and ciphertext first bit algorithm, to obtain a Boolean homomorphic ciphertext vector, where the ciphertext value of 0 represents non-compliance and 1 represents compliance. The vector and the obtained table are both LWE ciphertexts, and are used together as the filtering results for ciphertext conversion.
[0037] After completing the second level of filtering, the server inputs the output data and ciphertext bits into the homomorphic transformation algorithm, and the output is a ciphertext in a format that supports batch aggregation calculations on the ciphertext.
[0038] After completing the homomorphic ciphertext conversion, the server performs efficient batch packaging and aggregation calculations on the converted RLWE ciphertext. For example, when performing a counting operation on the result of a range query of [1,3] on the age attribute of the personnel table, the bit ciphertext vector is summed on the converted RLWE ciphertext; for the summation aggregation operation, the vector inner product calculation is performed on the bit ciphertext vector and the attribute to be aggregated on the converted RLWE ciphertext. The above operations can be quickly processed through the RLWE ciphertext packaging calculation.
[0039] Finally, the server transmits the encrypted results of the output aggregation query to the user through a secure channel.
[0040] Step 4: In the decryption phase, the user uses the homomorphic encryption algorithm to decrypt the returned ciphertext to obtain the plaintext of the aggregated query result.
[0041] In this step, the user uses the encryption key to decrypt the returned result ciphertext to obtain the plaintext of the aggregated query result. Different from the LWE ciphertext format during encryption, the ciphertext to be decrypted in this step is in the RLWE ciphertext format and is decrypted using the homomorphic encryption algorithm.
[0042] It is worth noting that the contents not described in detail in the embodiments of the present invention belong to the prior art known to professional and technical personnel in the field.
[0043] In summary, the method described in the embodiment of the present invention has the following significant advantages and improvements compared with the prior art:
[0044] 1. Accelerate aggregate query: This invention greatly reduces the aggregate query processing time for encrypted data by introducing an efficient ciphertext query index construction method and homomorphic filtering, significantly improving query efficiency compared to the prior art. This is particularly important for application scenarios with large amounts of data and can meet the needs of real-time queries.
[0045] 2. Reduce redundant calculations: The present invention significantly reduces unnecessary calculation overhead by optimizing ciphertext processing and screening data rows before querying. In particular, the complexity and resource consumption of aggregate queries are effectively reduced by optimizing the format conversion of homomorphic ciphertext and homomorphic aggregate calculations.
[0046] 3. Ensure data security and privacy: The present invention utilizes advanced homomorphic encryption technology and the processing flow of encrypted query statements to achieve secure storage and encrypted query of data without exposing plaintext data and query content. This method provides additional protection for user data privacy and meets the current growing demand for data protection.
[0047] In addition, a person skilled in the art can understand that all or part of the steps in the above-mentioned embodiment method can be implemented by instructing related hardware through a program, and the corresponding program can be stored in a computer-readable storage medium. The above-mentioned storage medium can be a read-only memory, a disk or an optical disk, etc.
[0048] The above is only a preferred specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by any technician familiar with the technical field within the technical scope disclosed in the present invention should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention should be based on the protection scope of the claims. The information disclosed in the background technology section of this article is only intended to deepen the understanding of the overall background technology of the present invention, and should not be regarded as an admission or in any form that the information constitutes prior art known to those skilled in the art.
Claims
1. A method for accelerating aggregate queries on outsourced homomorphic encryption databases, characterized in that: The method comprises: Step 1: In the initialization phase, the user registers with the server to use the outsourced encryption database and generates a master key, and then derives the encryption key and index key based on the master key; Step 2: During the data upload phase, the user generates encrypted data and a ciphertext index and uploads them to the server. After receiving the upload request, the server stores the received encrypted data in the database and obtains the unique identifier of the encrypted data. It calls the symmetric searchable encryption algorithm based on the unique identifier and the received ciphertext index to update the server-side ciphertext index. Step 3: In the query phase, the user converts the plaintext conditions of the query statement into homomorphic ciphertext and ciphertext index query fields; the server outputs the ciphertext that meets the conditions according to the ciphertext index query fields, and then filters the output results according to the homomorphic ciphertext conditions, and finally performs homomorphic inner product aggregation calculation, outputs the ciphertext results of the aggregate query, and returns the ciphertext to the user; Step 4: In the decryption phase, the user uses the homomorphic encryption algorithm to decrypt the returned ciphertext to obtain the plaintext of the aggregated query result.
2. The acceleration method for aggregate query of outsourced homomorphic encryption database according to claim 1 is characterized in that: In step 1, the user applies to the server for the use of an outsourced encrypted database, the server applies for resources for the user, and the two establish a secure transmission channel; The user uses a random number generation algorithm to generate a master key, and uses the master key to derive an encryption key and an index key; the encryption key is used to encrypt plaintext data when uploading data, and the index key is used to generate ciphertext of the index field during the data upload and query stages.
3. The acceleration method for aggregate query of outsourced homomorphic encryption database according to claim 1 is characterized in that: In step 2, the user uses the encryption key and homomorphic encryption algorithm to encrypt the data. After encoding the data to generate a keyword set, the user uses the index key and symmetric searchable encryption algorithm to construct a ciphertext index for the keyword set, and encapsulates the encrypted data into an SQL statement and sends it to the server together with the ciphertext index. After receiving the upload request, the server delivers the database interface according to the received SQL statement containing the encrypted data, obtains the unique identifier of the encrypted data in the database, takes the ciphertext index update field as input, and calls the symmetric searchable encryption algorithm to output the key value storage of the server-side ciphertext index, and updates the unique identifier of the uploaded encrypted data to the ciphertext index; The symmetric searchable encryption algorithm refers to a method in which a user generates ciphertext by calling a pseudo-random function and a hash algorithm in a specific order according to the data value, the table name and the attribute to which it belongs.
4. The acceleration method for aggregate query of outsourced homomorphic encryption database according to claim 1 is characterized in that: In step 3, during the query phase, the user encrypts the query conditions using a homomorphic encryption algorithm, converts the query conditions into keywords using a single keyword range coverage algorithm, and uses the index key from step 1 to generate a ciphertext index query field based on the keywords using a symmetric searchable encryption algorithm; Then encapsulate the encrypted query conditions into an SQL statement and send it to the server together with the ciphertext index query field; The server uses the received ciphertext index query field to query the ciphertext index key value storage to obtain a unique identifier set, and inputs the unique identifier value set as a database subquery to obtain an output result table. Then, based on the input homomorphic ciphertext condition, the server calls the homomorphic subtraction and homomorphic highest bit algorithms in a specific order for each row of the output result table, outputs whether the ciphertext bits meet the conditions, and then performs a vector inner product operation on the converted result and the ciphertext bits, outputs the ciphertext result of the aggregate query, and returns the ciphertext to the user.
Citation Information
Patent Citations
Database ciphertext retrieval system and method based on bidirectional security index
CN112800088A
Verifiable homomorphic ciphertext database system and application method thereof
CN118364482A