Image retrieval method and system supporting privacy protection in cloud environment

By using key management and homomorphic encryption algorithms in a cloud environment, the cluster index ball tree is constructed, which solves the problems of low security in the prior art encrypted image retrieval and inability to adapt to multi-source and multi-user scenarios, and achieves efficient and secure image retrieval.

CN119788423BActive Publication Date: 2025-05-09XIAN UNIV OF POSTS & TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510268703.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-07
Publication Date
2025-05-09
Estimated Expiration
2045-03-07

AI Technical Summary

Technical Problem

The prior art has low security when retrieving encrypted images in a cloud environment, and cannot adapt to the practical application scenarios of multi-source and multi-users, and its application scope is limited.

Method used

Through the authorization center, various keys are generated and distributed, the image owner clusters the image feature vector to generate the ciphertext image feature vector and clustering center, and uses homomorphic encryption algorithm and key conversion protocol to build a cluster index ball tree in a multi-cloud server environment to realize image retrieval.

Benefits of technology

It realizes secure and efficient retrieval of encrypted images in a cloud environment, adapts to multi-source and multi-user scenarios, and improves retrieval accuracy and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119788423B_ABST
    Figure CN119788423B_ABST
Patent Text Reader

Abstract

The present invention provides an image retrieval method and system supporting privacy protection in a cloud environment, and relates to the field of image retrieval technology. The method constructs a first ciphertext image feature vector, a first ciphertext cluster center and a ciphertext image for an image by an image owner, and uploads the image to a first cloud server; the first cloud server performs key conversion on the first ciphertext image feature vector, and constructs a cluster index ball tree together with a second cloud server; the image queryer uses a query key to encrypt the query feature vector to obtain a first query feature vector, and uploads the query to the first cloud server; the first cloud server performs key conversion on the first query feature vector, and performs a query operation together with the second cloud server to obtain a corresponding query result; the image queryer decrypts the encrypted image with an image decryption key to obtain an image retrieval result in plain text. The present invention uses homomorphic encryption technology for encryption, is suitable for multi-user and multi-owner scenarios, and is conducive to privacy protection during image retrieval.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of image retrieval technology, and in particular to an image retrieval method and system supporting privacy protection in a cloud environment. Background Art

[0002] With the development of modern technology, and in order to protect user privacy, people choose to encrypt images and upload them to cloud servers. However, this also makes image retrieval difficult.

[0003] In order to achieve image retrieval in encrypted domains, existing technologies provide solutions that use Convolutional Neural Networks (CNN) models to extract features, use asymmetric matrix scalar products to encrypt feature vectors, and design nonlinear indexes for retrieval. However, this solution has low security and does not consider the actual application scenarios of multiple sources and multiple users, and its application scope is limited. Therefore, an effective solution is urgently needed to solve the above problems. Summary of the invention

[0004] The present invention provides an image retrieval method and system supporting privacy protection in a cloud environment, so as to solve the defects of the prior art that the retrieval of encrypted images has low security and cannot adapt to multi-source and multi-user scenarios.

[0005] The present invention provides an image retrieval method supporting privacy protection in a cloud environment, comprising:

[0006] The authorization center generates a query key for each image queryer, a first service key for the first cloud server, a second service key for the second cloud server, and an owner key for each image owner, and distributes them;

[0007] Each of the image owners clusters the image feature vectors of their respective images to obtain a cluster center; based on the owner key, the image feature vector, the cluster center and the image, generates a first ciphertext image feature vector, a first ciphertext cluster center and a ciphertext image, and uploads the generated first ciphertext image feature vector, a first ciphertext cluster center and a ciphertext image;

[0008] The first cloud server performs key conversion on each of the first ciphertext image feature vectors and each of the first ciphertext cluster centers based on the first service key to obtain each second ciphertext image feature vector and each second ciphertext cluster center; with the assistance of the second cloud server, a cluster index ball tree is constructed based on the second service key, the homomorphic encryption algorithm and each of the second ciphertext cluster centers;

[0009] The image queryer encrypts the query feature vector of the query image based on the query key to obtain a first ciphertext query feature vector and uploads it;

[0010] The first cloud server performs key conversion on the first ciphertext query feature vector based on the first service key to obtain a second ciphertext query feature vector; with the assistance of the second cloud server, the cluster index ball tree is queried based on the second ciphertext query feature vector to obtain at least one second ciphertext cluster center; a second ciphertext image feature vector corresponding to the at least one second ciphertext cluster center is queried based on the second ciphertext query feature vector to obtain at least one second ciphertext image feature vector; and a ciphertext image corresponding to the at least one second ciphertext image feature vector and an identifier of a corresponding image owner are sent to the image queryer;

[0011] The image queryer decrypts the ciphertext image based on the owner key corresponding to the identifier to obtain the image.

[0012] According to an image retrieval method supporting privacy protection in a cloud environment provided by the present invention, the owner key includes an authorization key and an image encryption key;

[0013] The step of generating a first ciphertext image feature vector, a first ciphertext cluster center, and a ciphertext image based on the owner key, the image feature vector, the cluster center, and the image comprises:

[0014] Encrypting the image feature vector and the cluster center based on the authorization key to obtain a first ciphertext image feature vector and a first ciphertext cluster center;

[0015] Encrypting the image based on the image encryption key to obtain a ciphertext image;

[0016] The image queryer decrypts the ciphertext image based on the owner key corresponding to the identifier to obtain the image, including:

[0017] The image queryer obtains the image encryption key corresponding to the identifier from each image encryption key distributed by the authorization center, and uses the image encryption key as an image decryption key to decrypt the ciphertext image to obtain the image.

[0018] According to an image retrieval method supporting privacy protection in a cloud environment provided by the present invention, a cluster index ball tree is constructed based on the second service key, the homomorphic encryption algorithm and each second ciphertext cluster center with the assistance of the second cloud server, including:

[0019] Step A: The first cloud server and the second cloud server divide each of the second ciphertext cluster centers as nodes into a root sphere, and use the root sphere as the current sphere;

[0020] Step B: Based on the second service key and the homomorphic encryption algorithm, the mean of each node in the current sphere is calculated to obtain the central node of the current sphere;

[0021] Step C: Calculate the first distance between each remaining node and the central node; determine the remaining node with the largest first distance as the first boundary node of the current sphere, and use the largest first distance as the radius of the current sphere, wherein the remaining nodes refer to nodes that do not form a parent-child relationship;

[0022] Step D: calculating the second distance between each of the remaining nodes and the first boundary node; determining the remaining node with the largest second distance as the second boundary node of the current sphere;

[0023] Step E: assigning the first boundary node and the second boundary node to the central node and serving as the left child node and the right child node of the central node respectively;

[0024] Step F: dividing each of the remaining nodes in the current sphere according to the distances between each of the remaining nodes and the first boundary node and the second boundary node, to obtain two sub-spheres;

[0025] Step G: For each of the child spheres, take the child sphere as the current sphere and continue to execute steps B to G until the child sphere contains only one node, the radius of the child sphere is infinitely small, and the left child node and the right child node of the child sphere are both empty.

[0026] According to an image retrieval method supporting privacy protection in a cloud environment provided by the present invention, each of the remaining nodes in the current sphere is divided according to the distance between each of the remaining nodes and the first boundary node and the second boundary node, so as to obtain two sub-spheres, including:

[0027] For each of the remaining nodes in the current sphere, calculating a third distance between the remaining node and the first boundary node, and a fourth distance between the remaining node and the second boundary node;

[0028] If the third distance is less than the fourth distance, the remaining nodes are allocated to the first boundary node; if the third distance is greater than or equal to the fourth distance, the remaining nodes are allocated to the second boundary node;

[0029] Each of the remaining nodes in the current sphere is traversed to form two sub-spheres.

[0030] According to an image retrieval method supporting privacy protection in a cloud environment provided by the present invention, the method of calculating the mean of each of the nodes in the current sphere based on the second service key and the homomorphic encryption algorithm to obtain the central node of the current sphere includes:

[0031] The first cloud server uses the additive property of the homomorphic encryption algorithm to blind the second ciphertext cluster centers corresponding to each of the nodes in the current sphere to obtain first blinded data corresponding to each of the second ciphertext cluster centers; and uses the additive property of the homomorphic encryption algorithm to calculate the sum of each of the first blinded data to obtain the first blinded data sum;

[0032] The second cloud server decrypts the first blinded data and based on the second service key to obtain a second blinded data and; calculates a ratio of the second blinded data and to a first quantity, where the first quantity is the number of the second ciphertext cluster centers in the current sphere; and encrypts the ratio based on the second service key to obtain an encrypted ratio;

[0033] The first cloud server uses the negation property and the addition property of the homomorphic encryption algorithm to de-blind the encrypted ratio to obtain the mean of each of the second ciphertext cluster centers; and determines the mean as the central node of the current sphere.

[0034] According to an image retrieval method supporting privacy protection in a cloud environment provided by the present invention, the calculating of the first distance between each remaining node and the central node includes:

[0035] For each of the remaining nodes, perform the following steps:

[0036] Subtract the remaining nodes from the central node to obtain a first difference, and call a sign determination algorithm to determine whether the first difference is greater than or equal to 0;

[0037] If yes, then add the first difference to the first blinded random number to obtain first data, and add the first difference to the second blinded random number to obtain second data;

[0038] If not, using the addition property and the negation property of the homomorphic encryption algorithm, calculate the inverse of the first difference to obtain a second difference; add the second difference to the first blinded random number to obtain the first data, and add the second difference to the second blinded random number to obtain the second data;

[0039] The second cloud server decrypts the first data and the second data based on the second service key to obtain third data and fourth data; multiplies the third data and the fourth data to obtain fifth data; and encrypts the fifth data based on the second service key to obtain sixth data;

[0040] The first cloud server performs Euclidean distance calculation based on the sixth data, the first blinded random number, the second blinded random number, the remaining nodes and the central node to obtain a first distance between the remaining nodes and the central node.

[0041] According to an image retrieval method supporting privacy protection in a cloud environment provided by the present invention, calling a symbol judgment algorithm to judge whether the first difference is greater than or equal to 0 includes:

[0042] Multiply the first difference by 2 and add 1 to obtain first ciphertext data;

[0043] Generate a first random number and flip coin s;

[0044] If the coin s=1, the product of the first ciphertext data and the first random number is calculated to obtain the second ciphertext data; if the coin s=-1, the inverse of the product of the first ciphertext data and the first random number is calculated to obtain the second ciphertext data;

[0045] The second cloud server decrypts the second ciphertext data based on the second service key to obtain second blinded data;

[0046] Performing bit value calculations on the second blinded data and the public key respectively to obtain a first bit value corresponding to the second blinded data and a second bit value corresponding to the public key;

[0047] If the first bit value is less than or equal to half of the second bit value, the comparison result is set to 1; if the first bit value is greater than half of the second bit value, the comparison result is set to -1;

[0048] Sending the comparison result to the first cloud server;

[0049] The first cloud server calculates the product of the coin s and the comparison result;

[0050] If the product of the coin s and the comparison result is 1, then the first difference is greater than or equal to 0;

[0051] If the product of the coin s and the comparison result is not 1, then the first difference is less than 0.

[0052] According to an image retrieval method supporting privacy protection in a cloud environment provided by the present invention, the clustering index ball tree is queried based on the second ciphertext query feature vector with the assistance of the second cloud server to obtain at least one second ciphertext clustering center, including:

[0053] Step a: The first cloud server and the second cloud server use the root sphere of the clustered index sphere tree as the current sphere;

[0054] Step b: calculating the fifth distance between the central node of the current sphere and the second ciphertext query feature vector;

[0055] Step c: based on the maximum inner product value of the fifth distance and the current sphere, obtaining at least one second ciphertext cluster center that has been queried.

[0056] According to an image retrieval method supporting privacy protection in a cloud environment provided by the present invention, obtaining at least one second ciphertext cluster center queried based on the maximum inner product value of the fifth distance and the current sphere includes:

[0057] When the fifth distance is greater than the maximum inner product value of the current sphere, a pruning operation is performed, and the brother sphere of the current sphere is used as the current sphere, and steps b to c are continued;

[0058] When the fifth distance is less than or equal to the maximum inner product value of the current sphere, the child sphere of the current sphere is used as the current sphere, and the steps b to c are continued until the leaf sphere is reached;

[0059] Calculating a sixth distance between a central node in the leaf sphere and the second encrypted query feature vector;

[0060] If the sixth distance is less than or equal to the seventh distance, then when the sixth distance is less than the eighth distance, the central node in the leaf sphere is saved in the search set, and the seventh distance is the sum of the radius of the leaf sphere and the eighth distance; when there is a node in the search set, the eighth distance is the minimum distance among the sixth distances corresponding to all nodes in the search set, and when there is no node in the search set, the eighth distance is infinity;

[0061] If the sixth distance is greater than the seventh distance, backtracking is performed from the leaf sphere to the root sphere, and during the backtracking process, steps b to c are performed for each sphere.

[0062] The present invention also provides an image retrieval system supporting privacy protection in a cloud environment, comprising:

[0063] At least one image owner, at least one image queryer, a first cloud server, a second cloud server, and an authorization center;

[0064] The authorization center is used to generate a query key of each image inquirer, a first service key of the first cloud server, a second service key of the second cloud server, and an owner key of each image owner, and distribute them;

[0065] Each of the image owners clusters the image feature vectors of their respective images to obtain a cluster center; based on the owner key, the image feature vector, the cluster center and the image, generates a first ciphertext image feature vector, a first ciphertext cluster center and a ciphertext image, and uploads them to a first cloud server;

[0066] The first cloud server is used to perform key conversion on each of the first ciphertext image feature vectors and each of the first ciphertext cluster centers based on the first service key to obtain each second ciphertext image feature vector and each second ciphertext cluster center;

[0067] The first cloud server and the second cloud server are used together to construct a cluster index ball tree based on the second service key, the homomorphic encryption algorithm and each of the second ciphertext cluster centers;

[0068] The image queryer is used to encrypt the query feature vector of the query image based on the query key to obtain a first encrypted query feature vector, and upload the first encrypted query feature vector to the first cloud server;

[0069] The first cloud server is further configured to perform key conversion on the first ciphertext query feature vector based on the first service key to obtain a second ciphertext query feature vector;

[0070] The first cloud server and the second cloud server are also used together to query the cluster index ball tree based on the second ciphertext query feature vector to obtain at least one second ciphertext cluster center; query the second ciphertext image feature vector corresponding to the at least one second ciphertext cluster center according to the second ciphertext query feature vector to obtain at least one second ciphertext image feature vector; send the ciphertext image corresponding to the at least one second ciphertext image feature vector and the corresponding image owner's identifier to the image queryer;

[0071] The image queryer is further used to decrypt the ciphertext image based on the owner key corresponding to the identifier to obtain the image.

[0072] The image retrieval method and system supporting privacy protection in a cloud environment provided by the present invention, the image owner constructs a first ciphertext image feature vector, a first ciphertext cluster center and a ciphertext image for the image, and uploads them to the first cloud server; the first cloud server performs key conversion on the first ciphertext image feature vector, and then constructs a cluster index ball tree together with the second cloud server; the image queryer uses the query key to encrypt the query feature vector to obtain the first query feature vector, and uploads it to the first cloud server; the first cloud server performs key conversion on the first query feature vector, and then performs a query operation together with the second cloud server to obtain the corresponding query result; the image queryer uses the image decryption key to decrypt the encrypted image to obtain the image retrieval result in plain text. The present invention uses a homomorphic encryption algorithm to encrypt the feature vector, and adopts a key conversion protocol, so that each image owner and image queryer has their own key, and designs a cluster index ball tree during retrieval, which can realize multi-source and multi-user image retrieval. BRIEF DESCRIPTION OF THE DRAWINGS

[0073] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0074] Figure 1 It is a flowchart of an image retrieval method supporting privacy protection in a cloud environment provided by the present invention.

[0075] Figure 2 It is a schematic diagram of the process of the clustered index ball tree provided by the present invention.

[0076] Figure 3 It is a structural schematic diagram of an image retrieval system supporting privacy protection in a cloud environment provided by the present invention. DETAILED DESCRIPTION

[0077] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with the drawings of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0078] Combine the following Figure 1-Figure 3 The present invention describes an image retrieval method and system supporting privacy protection in a cloud environment.

[0079] In order to facilitate a clearer understanding of the technical solutions of the embodiments of the present application, some technical contents related to the embodiments of the present application are first introduced.

[0080] With the development of modern technology, people generate a large amount of image data in their daily life or study, which also increases the local storage pressure. The development of cloud server technology has brought a large amount of storage and computing resources to people, so more and more people choose to upload local image data to cloud servers. Cloud services are curious about image resources while storing them, which raises the issue of privacy protection. In order to protect the privacy of users, people choose to encrypt images and then upload them to cloud servers. However, this also makes image retrieval difficult. In order to achieve image retrieval in the encrypted domain, researchers have conducted various explorations.

[0081] At present, researchers have proposed a variety of retrieval schemes for encrypted images, but these schemes have some problems to varying degrees. For example, the retrieval accuracy is low. Some schemes use the Scale-Invariant Feature Transform (SIFT) algorithm, the Speeded Up Robust Features (SURF) algorithm, the Multimedia Content Description Interface (MPEG-7) algorithm, etc. to extract feature vectors, which leads to the inaccuracy of the retrieval results. For example, the retrieval efficiency is low. Some schemes use linear indexes. When searching, all feature vectors need to be searched in sequence, resulting in slow retrieval time. For example, the security performance is low. Some schemes use the secure K-Nearest Neighbor (KNN) algorithm to encrypt feature vectors. Although the retrieval efficiency is improved, the secure KNN algorithm cannot resist linear analysis attacks. In order to improve the above problems, there are schemes that use CNN models to extract features and design nonlinear indexes for retrieval. However, most of these schemes also have low security and do not consider the actual application scenarios of multiple sources and multiple users. As a result, the scope of application is limited.

[0082] Figure 1 : is a flow chart of the image retrieval method supporting privacy protection in a cloud environment provided by the present invention. Figure 1 As shown, the method includes steps 101 to 106.

[0083] Step 101: The authorization center generates a query key for each image inquirer, a first service key for the first cloud server, a second service key for the second cloud server, and an owner key for each image owner, and distributes them.

[0084] In practical applications, a multi-source and multi-user image retrieval system supporting privacy protection in a cloud environment includes at least one image owner (IOs), at least one image queryer (IUs), a first cloud server (Cloud Sever 1, CS1), a second cloud server (Cloud Sever 2, CS2) and a trusted authorization center (TAC). TAC generates keys for other members in the image retrieval system and distributes the keys to the corresponding members. That is, the authorization center generates a query key for each image queryer, a first service key for the first cloud server, a second service key for the second cloud server, and an owner key for each image owner, and sends the query key to each image queryer, the first service key to the first cloud server, the second service key to the second cloud server, and each owner key to each image owner.

[0085] Specifically, the owner key includes an authorization key and an image encryption key.

[0086] First, TAC generates two large prime numbers p and q according to the security parameter k, and L(p)=L(q)=k, where L( ) represents the calculated bit value; then p=2p'+1 and q=2q'+1 are calculated to obtain p' and q', where p' and q' are also prime numbers. Calculate the public key n=pq and select a generator g=-z 2n , where the order of g is λ=2p'q', and , express The multiplicative group under the module, that is, less than Generate a random number r∈[1,n / 4].

[0087] Then, the TAC generates the key first service key and the second service key , and generate authorization keys for each IOs and the image encryption key K i , generate query keys for each IUs , public parameter PK=g ab Among them, a and b are adjustable parameters; i represents the key conversion parameter, that is, different conversion keys; sk represents the private key.

[0088] Furthermore, TAC distributes keys, that is, and K i Distribute to IOs, upload i to cloud server CS1; transmit key through secure channel Distribute to IUs, upload i to cloud server CS1; transmit Send to CS1, Send to CS2.

[0089] Step 102: Each of the image owners clusters the image feature vectors of their respective images to obtain a cluster center; based on the owner key, the image feature vector, the cluster center and the image, a first ciphertext image feature vector, a first ciphertext cluster center and a ciphertext image are generated and uploaded.

[0090] Specifically, IOs first extracts the feature vector of the image (plaintext image) it owns to obtain the image feature vector. Then it applies the clustering algorithm to cluster the image feature vector to obtain the cluster center. Next, IOs uses its own key The cluster center and the corresponding image feature vector are encrypted respectively, and the encryption algorithm is as follows:

[0091]

[0092] Among them, m represents the encrypted object, that is, the cluster center or image feature vector, Indicates the encryption key used, that is , r is the random number used for encryption.

[0093] At the same time, IOs also need to use K i To encrypt the image, you can use any symmetric encryption algorithm.

[0094] Afterwards, IOs uploads the encrypted cluster center (the first ciphertext cluster center), the encrypted feature vector (the first ciphertext image feature vector) and the ciphertext image to CS1.

[0095] Step 103: The first cloud server performs key conversion on each of the first ciphertext image feature vectors and each of the first ciphertext cluster centers based on the first service key to obtain each second ciphertext image feature vector and each second ciphertext cluster center; with the assistance of the second cloud server, a cluster index ball tree is constructed based on the second service key, the homomorphic encryption algorithm and each of the second ciphertext cluster centers.

[0096] In actual applications, after CS1 receives the first ciphertext cluster center and the first ciphertext image feature vector, it first converts the key and converts the encrypted data set (the first ciphertext cluster center and the first ciphertext image feature vector) into a data set encrypted with the key of the cloud server CS2 (the second ciphertext image feature vector and the second ciphertext cluster center), which is a decryption process. The algorithm is as follows:

[0097]

[0098] Where m represents the encrypted object, i.e., the cluster center or image feature vector; is the public key in the second service key, .

[0099] Furthermore, CS1 and CS2 cooperate to build a tree of the second ciphertext cluster centers based on the second service key and the homomorphic encryption algorithm, and jointly construct a cluster index ball tree.

[0100] Step 104: The image queryer encrypts the query feature vector of the query image based on the query key to obtain a first ciphertext query feature vector and uploads it.

[0101] In practical applications, the image queryer applies a feature extractor to the query image to extract a feature vector and obtains the query feature vector ; then use your own key The query feature vector is encrypted and the encrypted query vector (the first ciphertext query feature vector) is sent to CS1.

[0102] Specifically, the encryption algorithm is as follows:

[0103]

[0104] in, Indicates the encryption key used, here is .

[0105] Step 105: The first cloud server performs key conversion on the first ciphertext query feature vector based on the first service key to obtain a second ciphertext query feature vector; with the assistance of the second cloud server, the clustering index ball tree is queried based on the second ciphertext query feature vector to obtain at least one second ciphertext clustering center; the second ciphertext image feature vector corresponding to the at least one second ciphertext clustering center is queried according to the second ciphertext query feature vector to obtain at least one second ciphertext image feature vector; and the ciphertext image corresponding to the at least one second ciphertext image feature vector and the corresponding image owner's identifier are sent to the image queryer.

[0106] In actual applications, after receiving the second ciphertext query feature vector, CS1 performs key conversion and converts it into a ciphertext encrypted with CS2's key, that is, the second ciphertext query feature vector. The algorithm is as follows:

[0107]

[0108] Further, CS1 and CS2 cooperate to initiate a query on the cluster index ball tree based on the second ciphertext query feature vector to obtain at least one second ciphertext cluster center.

[0109] Then, CS1 continues to perform linear search on at least one of the queried second ciphertext cluster centers: calculate the Euclidean distance between the second ciphertext query feature vector and each vector to be searched (node ​​to be searched) in turn, where the vector to be searched is the second ciphertext image feature vector corresponding to any queried second ciphertext cluster center, obtain at least one queried second ciphertext image feature vector, and feed back the ciphertext image corresponding to the at least one queried second ciphertext image feature vector to IUs, and feed back the identifier of the IOs corresponding to the fed-back ciphertext image to IUs.

[0110] Exemplarily, in order to reduce the amount of feedback and ensure the accuracy of retrieval, when the number of at least one second ciphertext clustering centers is greater than or equal to X, the first X second ciphertext clustering centers closest to the second ciphertext query feature vector are selected from at least one second ciphertext clustering center for linear search, and finally Y ciphertext images for feedback are obtained.

[0111] Step 106: The image queryer decrypts the ciphertext image based on the owner key corresponding to the identifier to obtain the image.

[0112] In actual applications, after obtaining the ciphertext image and the identifier of the IOs corresponding to the ciphertext image, the IUs can obtain the image encryption key from the IOs based on the identifier to decrypt the ciphertext image, thereby obtaining the image; or when the TAC distributes keys, the owner key of each IOs or the image encryption key in the owner key is sent to the IUs through a secure channel. The IUs can look up the corresponding image encryption key based on the identifier of the IOs corresponding to the ciphertext image, decrypt the ciphertext image, and obtain the image.

[0113] In one or more optional embodiments of the present invention, the owner key includes an authorization key and an image encryption key; accordingly, generating a first ciphertext image feature vector, a first ciphertext cluster center, and a ciphertext image based on the owner key, the image feature vector, the cluster center, and the image includes:

[0114] Encrypting the image feature vector and the cluster center based on the authorization key to obtain a first ciphertext image feature vector and a first ciphertext cluster center;

[0115] Encrypting the image based on the image encryption key to obtain a ciphertext image;

[0116] The image queryer decrypts the ciphertext image based on the owner key corresponding to the identifier to obtain the image, including:

[0117] The image queryer obtains the image encryption key corresponding to the identifier from each image encryption key distributed by the authorization center, and uses the image encryption key as an image decryption key to decrypt the ciphertext image to obtain the image.

[0118] In actual applications, IOs uses authorization keys The cluster centers and the corresponding image feature vectors are encrypted separately, and the image encryption key K is used i Encrypt the image.

[0119] When TAC distributes keys, it also sends the image encryption key K i Therefore, when IUs obtain the identifier, they only need to obtain the image encryption key K corresponding to the identifier. i As the image decryption key, and use the image decryption key to decrypt the ciphertext image.

[0120] In this way, different keys are used for encryption to avoid leakage of authorization keys when feeding back keys to IUs, which would lead to leakage of relevant privacy of IOs and improve security.

[0121] Optionally, the step of constructing a cluster index ball tree based on the second service key, a homomorphic encryption algorithm and each of the second ciphertext cluster centers with the assistance of the second cloud server includes:

[0122] Step A: The first cloud server and the second cloud server divide each of the second ciphertext cluster centers as nodes into a root sphere, and use the root sphere as the current sphere;

[0123] Step B: Based on the second service key and the homomorphic encryption algorithm, the mean of each node in the current sphere is calculated to obtain the central node of the current sphere;

[0124] Step C: Calculate the first distance between each remaining node and the central node; determine the remaining node with the largest first distance as the first boundary node of the current sphere, and use the largest first distance as the radius of the current sphere, wherein the remaining nodes refer to nodes that do not form a parent-child relationship;

[0125] Step D: calculating the second distance between each of the remaining nodes and the first boundary node; determining the remaining node with the largest second distance as the second boundary node of the current sphere;

[0126] Step E: assigning the first boundary node and the second boundary node to the central node and serving as the left child node and the right child node of the central node respectively;

[0127] Step F: dividing each of the remaining nodes in the current sphere according to the distances between each of the remaining nodes and the first boundary node and the second boundary node, to obtain two sub-spheres;

[0128] Step G: For each of the child spheres, take the child sphere as the current sphere and continue to execute steps B to G until the child sphere contains only one node, the radius of the child sphere is infinitely small, and the left child node and the right child node of the child sphere are both empty.

[0129] Specifically, the distances involved in the embodiments of the present invention are all distances calculated under ciphertext.

[0130] In practical applications, see Figure 2 , Figure 2 The process diagram of the cluster index ball tree provided by the present invention is as follows: first, the second service key and the homomorphic encryption algorithm are used to calculate the mean of all the current second ciphertext cluster centers, a central node is obtained, and the central node is used as the root node. The root sphere includes all the second ciphertext cluster centers, and the sphere is represented as ,in, is the central node, is the radius of the sphere, is the second ciphertext cluster center contained in the sphere, is the left child node, It is the right child node.

[0131] Use the Euclidean distance calculation method to calculate the first distance between the remaining nodes and the current center node in turn, find the node P1 (the first boundary node) farthest from the center node, and use the first distance between the center node and P1 as the radius of the center node. Then continue to use the above method to calculate the distance between the remaining nodes and P1, and find the node P2 (the second boundary node) farthest from P1. Let P1 and P2 be the left and right child nodes of the center node respectively. Then calculate the Euclidean distance between the remaining nodes in the sphere and P1 and P2 respectively, and distribute the remaining nodes according to the distance from P1 and P2 in turn, so that two sub-spheres are generated, of which P1 and P2 are the left and right child nodes of the center node.

[0132] Recalculate the center node P of the sub-sphere (take the average, that is, calculate the average of all the second ciphertext cluster centers in the current sphere), and repeat the steps of calculating the center node, radius, and left and right sub-spheres of the current sphere. Repeat the above steps for the sub-spheres until the leaf node contains only one data node. At this time, let the radius be infinitely small and the left and right child nodes be empty. Now all cluster centers have been built as leaf nodes in the index tree, and the index tree is built.

[0133] In one or more optional embodiments of the present invention, the step of dividing each of the remaining nodes in the current sphere according to the distances between each of the remaining nodes and the first boundary node and the second boundary node to obtain two sub-spheres includes:

[0134] For each of the remaining nodes in the current sphere, calculating a third distance between the remaining node and the first boundary node, and a fourth distance between the remaining node and the second boundary node;

[0135] If the third distance is less than the fourth distance, the remaining nodes are allocated to the first boundary node; if the third distance is greater than or equal to the fourth distance, the remaining nodes are allocated to the second boundary node;

[0136] Each of the remaining nodes in the current sphere is traversed to form two sub-spheres.

[0137] In practical applications, the Euclidean distances (third distances) between the remaining nodes in the current sphere and P1 are calculated respectively, and the Euclidean distances (fourth distances) between the remaining nodes in the current sphere and P2 are calculated respectively. The remaining nodes are distributed in turn according to the distance from P1 and P2. The node is distributed to the node that is closer to it, thus generating two sub-spheres.

[0138] In one or more optional embodiments of the present invention, the calculating the mean of each of the nodes in the current sphere based on the second service key and the homomorphic encryption algorithm to obtain the central node of the current sphere includes:

[0139] The first cloud server uses the additive property of the homomorphic encryption algorithm to blind the second ciphertext cluster centers corresponding to each of the nodes in the current sphere to obtain first blinded data corresponding to each of the second ciphertext cluster centers; and uses the additive property of the homomorphic encryption algorithm to calculate the sum of each of the first blinded data to obtain the first blinded data sum;

[0140] The second cloud server decrypts the first blinded data and based on the second service key to obtain a second blinded data and; calculates a ratio of the second blinded data and to a first quantity, where the first quantity is the number of the second ciphertext cluster centers in the current sphere; and encrypts the ratio based on the second service key to obtain an encrypted ratio;

[0141] The first cloud server uses the negation property and the addition property of the homomorphic encryption algorithm to de-blind the encrypted ratio to obtain the mean of each of the second ciphertext cluster centers; and determines the mean as the central node of the current sphere.

[0142] In practical applications, the homomorphic addition property is used to blind the current data (the second ciphertext cluster center corresponding to each node in the current sphere): .in, is the i-th first blinded data, is the second ciphertext cluster center, and R is the random number generated by the first cloud server. Then, the sum of all the first blinded data is calculated using the homomorphic addition property to obtain the sum of the first blinded data. ,in, is the sum of the first blinded data, and N is the number of the first blinded data, that is, the number of the second ciphertext clustering centers in the current sphere.

[0143] Further, CS2 performs decryption , where M is the second blinded data and D is the decryption algorithm. CS2 calculates the mean (the mean is in a blinded state at this time): ,in, is the ratio of the second blinded data sum to the first number; CS2 encrypts the mean (the ratio of the second blinded data sum to the first number) and sends it to CS1: ,in, is the encrypted ratio, and E is the encryption algorithm.

[0144] Finally, CS1 gets the correct mean by the additive property: ,in, is the mean of the second ciphertext cluster centers, and neg is the negation algorithm of the homomorphic encryption algorithm.

[0145] In one or more optional embodiments of the present invention, the calculating the first distance between each remaining node and the central node includes:

[0146] For each of the remaining nodes, perform the following steps:

[0147] Subtract the remaining nodes from the central node to obtain a first difference, and call a sign determination algorithm to determine whether the first difference is greater than or equal to 0;

[0148] If yes, then add the first difference to the first blinded random number to obtain first data, and add the first difference to the second blinded random number to obtain second data;

[0149] If not, using the addition property and the negation property of the homomorphic encryption algorithm, calculate the inverse of the first difference to obtain a second difference; add the second difference to the first blinded random number to obtain the first data, and add the second difference to the second blinded random number to obtain the second data;

[0150] The second cloud server decrypts the first data and the second data based on the second service key to obtain third data and fourth data; multiplies the third data and the fourth data to obtain fifth data; and encrypts the fifth data based on the second service key to obtain sixth data;

[0151] The first cloud server performs Euclidean distance calculation based on the sixth data, the first blinded random number, the second blinded random number, the remaining nodes and the central node to obtain a first distance between the remaining nodes and the central node.

[0152] Specifically, the first distance is the Euclidean distance.

[0153] In actual applications, x is the remaining node and y is the central node. CS1 first calculates xy (the first difference), then calls the sign judgment algorithm. If xy ≥ 0, then it calculates ,in, is the first data, is the first blinded random number, is the second data, is the first blinded random number. Otherwise, using the add and neg properties of the homomorphic encryption algorithm, first calculate yx (the second difference), and then calculate . Then and Send to CS2.

[0154] CS2 first and Decrypt them respectively to get the third data and the fourth data ; Then calculate the fifth data CS2 then uses its own key pair Encrypt to get the sixth data , and transmits it to CS1, which passes Calculate and get the first distance between x and y.

[0155] In one or more optional embodiments of the present invention, calling a sign determination algorithm to determine whether the first difference is greater than or equal to 0 includes:

[0156] Multiply the first difference by 2 and add 1 to obtain first ciphertext data;

[0157] Generate a first random number and flip coin s;

[0158] If the coin s=1, the product of the first ciphertext data and the first random number is calculated to obtain the second ciphertext data; if the coin s=-1, the inverse of the product of the first ciphertext data and the first random number is calculated to obtain the second ciphertext data;

[0159] The second cloud server decrypts the second ciphertext data based on the second service key to obtain second blinded data;

[0160] Performing bit value calculations on the second blinded data and the public key respectively to obtain a first bit value corresponding to the second blinded data and a second bit value corresponding to the public key;

[0161] If the first bit value is less than or equal to half of the second bit value, the comparison result is set to 1; if the first bit value is greater than half of the second bit value, the comparison result is set to -1;

[0162] Sending the comparison result to the first cloud server;

[0163] The first cloud server calculates the product of the coin s and the comparison result;

[0164] If the product of the coin s and the comparison result is 1, then the first difference is greater than or equal to 0;

[0165] If the product of the coin s and the comparison result is not 1, then the first difference is less than 0.

[0166] In practical applications, CS1 first calculates the first ciphertext data CS1 generates the first random number R and flips the coin s. If s=1, the second ciphertext data is calculated. If s=-1, calculate . And transmit the encrypted data to CS2.

[0167] CS2 first decrypts to obtain the second blinded data , then calculate the first bit value and the second bit value ,in, Indicates the calculation of bit value. If , the comparison result u=1, otherwise the comparison result u=-1. Then u is transmitted to CS1, which calculates the product of coin s and the comparison result. ,if ,otherwise .

[0168] In one or more optional embodiments of the present invention, querying the cluster index ball tree based on the second ciphertext query feature vector with the assistance of the second cloud server to obtain at least one second ciphertext cluster center includes:

[0169] Step a: The first cloud server and the second cloud server use the root sphere of the clustered index sphere tree as the current sphere;

[0170] Step b: calculating the fifth distance between the central node of the current sphere and the second ciphertext query feature vector;

[0171] Step c: based on the maximum inner product value of the fifth distance and the current sphere, obtaining at least one second ciphertext cluster center that has been queried.

[0172] In practical applications, the search starts from the root sphere of the cluster index sphere tree. The distance (fifth distance) between the center node of the current sphere and the second ciphertext query feature vector is calculated to determine whether this distance is less than or equal to the maximum inner product value of the current sphere. If so, continue to search down the branch, otherwise recursively traverse the tree to obtain at least one second ciphertext cluster center that has been queried.

[0173] Assume a ball From the center of the ball , radius rad, and query point (second ciphertext query feature vector) Q, then the query point Q and the ball The upper bound of the maximum possible inner product between is: ,in, For the ball The point that maximizes the inner product.

[0174] In one or more optional embodiments of the present invention, obtaining the at least one second ciphertext cluster center found based on the maximum inner product value of the fifth distance and the current sphere includes:

[0175] When the fifth distance is greater than the maximum inner product value of the current sphere, a pruning operation is performed, and the brother sphere of the current sphere is used as the current sphere, and steps b to c are continued;

[0176] When the fifth distance is less than or equal to the maximum inner product value of the current sphere, the child sphere of the current sphere is used as the current sphere, and the steps b to c are continued until the leaf sphere is reached;

[0177] Calculating a sixth distance between a central node in the leaf sphere and the second encrypted query feature vector;

[0178] If the sixth distance is less than or equal to the seventh distance, then when the sixth distance is less than the eighth distance, the central node in the leaf sphere is saved in the search set, and the seventh distance is the sum of the radius of the leaf sphere and the eighth distance; when there is a node in the search set, the eighth distance is the minimum distance among the sixth distances corresponding to all nodes in the search set, and when there is no node in the search set, the eighth distance is infinity;

[0179] If the sixth distance is greater than the seventh distance, backtracking is performed from the leaf sphere to the root sphere, and during the backtracking process, steps b to c are performed for each sphere.

[0180] In practical applications, when the search starts, the minimum distance currently searched is set to infinity, and the currently searched node is set to empty, which is specifically expressed as ,in For the current search results, is the node that has been searched, and inf is the Euclidean distance between the node and the query node (the second ciphertext query feature vector). First, the Euclidean distance (fifth distance) between the center node of the current sphere and the query node is calculated in sequence according to the Euclidean distance algorithm, and then it is determined whether the fifth distance is less than or equal to the upper limit of the maximum possible inner product (maximum inner product value). If it is less than or equal to, then enter the branch and continue to explore until the leaf sphere, and then determine whether the Euclidean distance (sixth distance) between the root node of the leaf sphere and the query node is less than or equal to the sum of the Euclidean distance (eighth distance) of the nearest node that has been searched and the radius of the leaf sphere. If it is less than or equal to, then save this node if the sixth distance is less than or equal to the eighth distance, otherwise, discard this point. Then backtrack from the leaf sphere to the root sphere. During the backtracking process, the Euclidean distance between the center node of the sphere to be retrieved and the query vector is also calculated, and the size of the upper limit of the current maximum inner product value is determined. If it is less than, then enter the node for search, otherwise do not enter the node and perform branch reduction. Finally, the search result is obtained.

[0181] The following is an introduction to the homomorphic properties involved in the homomorphic encryption algorithm:

[0182] Homomorphic addition : PK is the encryption key. and Represents two plaintexts respectively. Its meaning is that after encrypting the plaintext, multiplying the ciphertext is equivalent to adding the plaintext and then encrypting it.

[0183] Homomorphic multiplication : Among them, t is a constant, v is plain text, and its meaning is plain text The encrypted result is equal to the power operation performed on the ciphertext.

[0184] Homomorphic Negation : .

[0185] CS1 generates a random number key_R: First, CS1 generates a random number R and encrypts it with the public keys of CS1 and CS2: , then CS1 partially decrypts the random number with its own private key and converts it into ciphertext encrypted by CS2's public key: .

[0186] The random number generated by CS1 is used for blinding. If blinding is not performed, CS2 can directly obtain the plaintext by decryption. In other words, if CS2 decrypts the plaintext data without blinding, and blinding is performed, CS2 decrypts the blinded data, and the plaintext data cannot be directly obtained. This is a kind of encryption protection for the plaintext data.

[0187] The image retrieval supporting privacy protection in the cloud environment provided by the present invention can support multi-source multi-user image retrieval supporting privacy protection in the cloud environment. The feature vector is encrypted by the homomorphic encryption algorithm to achieve semantic security. Based on the properties of the homomorphic encryption algorithm, a key conversion protocol is adopted so that each user and image owner has his own key, avoiding the problem of key leakage. The designed index structure can support fast retrieval. The CNN model based on the large model is used to extract the image feature vector, which effectively improves the retrieval accuracy.

[0188] The following describes an image retrieval system supporting privacy protection in a cloud environment provided by the present invention. The image retrieval system supporting privacy protection in a cloud environment described below and the image retrieval method supporting privacy protection in a cloud environment described above can be referred to in correspondence with each other. Figure 3 As shown, Figure 3 : is a schematic diagram of the structure of the image retrieval system supporting privacy protection in a cloud environment provided by the present invention, including:

[0189] At least one image owner 301, at least one image queryer 302, a first cloud server 303, a second cloud server 304 and an authorization center 305;

[0190] The authorization center 305 is used to generate a query key of each image queryer 302, a first service key of the first cloud server 303, a second service key of the second cloud server 304, and an owner key of each image owner 301, and distribute them;

[0191] Each of the image owners 301 is used to cluster the image feature vectors of their respective images to obtain a cluster center; based on the owner key, the image feature vector, the cluster center and the image, a first ciphertext image feature vector, a first ciphertext cluster center and a ciphertext image are generated, and uploaded to the first cloud server 303;

[0192] The first cloud server 303 is used to perform key conversion on each of the first ciphertext image feature vectors and each of the first ciphertext cluster centers based on the first service key to obtain each second ciphertext image feature vector and each second ciphertext cluster center;

[0193] The first cloud server 303 and the second cloud server 304 are used together to construct a cluster index ball tree based on the second service key, the homomorphic encryption algorithm and each of the second ciphertext cluster centers;

[0194] The image queryer 302 is used to encrypt the query feature vector of the query image based on the query key to obtain a first encrypted query feature vector, and upload the first encrypted query feature vector to the first cloud server 303;

[0195] The first cloud server 303 is further configured to perform key conversion on the first ciphertext query feature vector based on the first service key to obtain a second ciphertext query feature vector;

[0196] The first cloud server 303 and the second cloud server 304 are also used together to query the cluster index ball tree based on the second ciphertext query feature vector to obtain at least one second ciphertext cluster center; query the second ciphertext image feature vector corresponding to the at least one second ciphertext cluster center according to the second ciphertext query feature vector to obtain at least one second ciphertext image feature vector; send the ciphertext image corresponding to the at least one second ciphertext image feature vector and the identifier of the corresponding image owner 301 to the image queryer 302;

[0197] The image queryer 302 is further used to decrypt the ciphertext image based on the owner key corresponding to the identifier to obtain the image.

[0198] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a necessary general hardware platform, and of course, can also be implemented by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0199] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. An image retrieval method supporting privacy protection in a cloud environment, characterized in that: include: The authorization center generates a query key for each image queryer, a first service key for the first cloud server, a second service key for the second cloud server, and an owner key for each image owner, and distributes them; Each of the image owners clusters the image feature vectors of their respective images to obtain a cluster center; based on the owner key, the image feature vector, the cluster center and the image, generates a first ciphertext image feature vector, a first ciphertext cluster center and a ciphertext image, and uploads the generated first ciphertext image feature vector, a first ciphertext cluster center and a ciphertext image; The first cloud server performs key conversion on each of the first ciphertext image feature vectors and each of the first ciphertext cluster centers based on the first service key to obtain each second ciphertext image feature vector and each second ciphertext cluster center; with the assistance of the second cloud server, a cluster index ball tree is constructed based on the second service key, the homomorphic encryption algorithm and each of the second ciphertext cluster centers; The image queryer encrypts the query feature vector of the query image based on the query key to obtain a first ciphertext query feature vector and uploads it; The first cloud server performs key conversion on the first ciphertext query feature vector based on the first service key to obtain a second ciphertext query feature vector; with the assistance of the second cloud server, the cluster index ball tree is queried based on the second ciphertext query feature vector to obtain at least one second ciphertext cluster center; a second ciphertext image feature vector corresponding to the at least one second ciphertext cluster center is queried based on the second ciphertext query feature vector to obtain at least one second ciphertext image feature vector; and a ciphertext image corresponding to the at least one second ciphertext image feature vector and an identifier of a corresponding image owner are sent to the image queryer; The image queryer decrypts the ciphertext image based on the owner key corresponding to the identifier to obtain the image; The step of constructing a cluster index ball tree based on the second service key, the homomorphic encryption algorithm and each of the second ciphertext cluster centers with the assistance of the second cloud server includes: Step A: The first cloud server and the second cloud server divide each of the second ciphertext cluster centers as nodes into a root sphere, and use the root sphere as the current sphere; Step B: Based on the second service key and the homomorphic encryption algorithm, the mean of each node in the current sphere is calculated to obtain the central node of the current sphere; Step C: Calculate the first distance between each remaining node and the central node; determine the remaining node with the largest first distance as the first boundary node of the current sphere, and use the largest first distance as the radius of the current sphere, wherein the remaining nodes refer to nodes that do not form a parent-child relationship; Step D: calculating the second distance between each of the remaining nodes and the first boundary node; determining the remaining node with the largest second distance as the second boundary node of the current sphere; Step E: assigning the first boundary node and the second boundary node to the central node and serving as the left child node and the right child node of the central node respectively; Step F: dividing each of the remaining nodes in the current sphere according to the distances between each of the remaining nodes and the first boundary node and the second boundary node, to obtain two sub-spheres; Step G: For each of the child spheres, take the child sphere as the current sphere and continue to execute steps B to G until the child sphere contains only one node, the radius of the child sphere is infinitely small, and the left child node and the right child node of the child sphere are both empty.

2. The image retrieval method supporting privacy protection in a cloud environment according to claim 1, characterized in that: The owner key includes an authorization key and an image encryption key; The step of generating a first ciphertext image feature vector, a first ciphertext cluster center, and a ciphertext image based on the owner key, the image feature vector, the cluster center, and the image comprises: Encrypting the image feature vector and the cluster center based on the authorization key to obtain a first ciphertext image feature vector and a first ciphertext cluster center; Encrypting the image based on the image encryption key to obtain a ciphertext image; The image queryer decrypts the ciphertext image based on the owner key corresponding to the identifier to obtain the image, including: The image queryer obtains the image encryption key corresponding to the identifier from each image encryption key distributed by the authorization center, and uses the image encryption key as an image decryption key to decrypt the ciphertext image to obtain the image.

3. The image retrieval method supporting privacy protection in a cloud environment according to claim 2, characterized in that: The step of dividing each of the remaining nodes in the current sphere according to the distances between each of the remaining nodes and the first boundary node and the second boundary node to obtain two sub-spheres includes: For each of the remaining nodes in the current sphere, calculating a third distance between the remaining node and the first boundary node, and a fourth distance between the remaining node and the second boundary node; If the third distance is less than the fourth distance, the remaining nodes are allocated to the first boundary node; if the third distance is greater than or equal to the fourth distance, the remaining nodes are allocated to the second boundary node; Each of the remaining nodes in the current sphere is traversed to form two sub-spheres.

4. The image retrieval method supporting privacy protection in a cloud environment according to claim 1 or 3, characterized in that: The calculating, based on the second service key and the homomorphic encryption algorithm, the mean of each of the nodes in the current sphere to obtain the central node of the current sphere includes: The first cloud server uses the additive property of the homomorphic encryption algorithm to blind the second ciphertext cluster centers corresponding to each of the nodes in the current sphere to obtain first blinded data corresponding to each of the second ciphertext cluster centers; and uses the additive property of the homomorphic encryption algorithm to calculate the sum of each of the first blinded data to obtain the first blinded data sum; The second cloud server decrypts the first blinded data and based on the second service key to obtain a second blinded data and; calculates a ratio of the second blinded data and to a first quantity, where the first quantity is the number of the second ciphertext cluster centers in the current sphere; and encrypts the ratio based on the second service key to obtain an encrypted ratio; The first cloud server uses the negation property and the addition property of the homomorphic encryption algorithm to de-blind the encrypted ratio to obtain the mean of each of the second ciphertext cluster centers; and determines the mean as the central node of the current sphere.

5. The image retrieval method supporting privacy protection in a cloud environment according to claim 1, characterized in that: The calculating the first distance between each remaining node and the central node includes: For each of the remaining nodes, perform the following steps: Subtract the remaining nodes from the central node to obtain a first difference, and call a sign determination algorithm to determine whether the first difference is greater than or equal to 0; If yes, then add the first difference to the first blinded random number to obtain first data, and add the first difference to the second blinded random number to obtain second data; If not, using the addition property and the negation property of the homomorphic encryption algorithm, calculate the inverse of the first difference to obtain a second difference; add the second difference to the first blinded random number to obtain the first data, and add the second difference to the second blinded random number to obtain the second data; The second cloud server decrypts the first data and the second data based on the second service key to obtain third data and fourth data; multiplies the third data and the fourth data to obtain fifth data; and encrypts the fifth data based on the second service key to obtain sixth data; The first cloud server performs Euclidean distance calculation based on the sixth data, the first blinded random number, the second blinded random number, the remaining nodes and the central node to obtain a first distance between the remaining nodes and the central node.

6. The image retrieval method supporting privacy protection in a cloud environment according to claim 5, characterized in that: The calling of the sign determination algorithm to determine whether the first difference is greater than or equal to 0 includes: Multiply the first difference by 2 and add 1 to obtain first ciphertext data; Generate a first random number and flip coin s; If the coin s=1, the product of the first ciphertext data and the first random number is calculated to obtain the second ciphertext data; if the coin s=-1, the inverse of the product of the first ciphertext data and the first random number is calculated to obtain the second ciphertext data; The second cloud server decrypts the second ciphertext data based on the second service key to obtain second blinded data; Performing bit value calculations on the second blinded data and the public key respectively to obtain a first bit value corresponding to the second blinded data and a second bit value corresponding to the public key; If the first bit value is less than or equal to half of the second bit value, the comparison result is set to 1; if the first bit value is greater than half of the second bit value, the comparison result is set to -1; Sending the comparison result to the first cloud server; The first cloud server calculates the product of the coin s and the comparison result; If the product of the coin s and the comparison result is 1, then the first difference is greater than or equal to 0; If the product of the coin s and the comparison result is not 1, then the first difference is less than 0.

7. The image retrieval method supporting privacy protection in a cloud environment according to claim 1, characterized in that: The step of querying the cluster index ball tree based on the second ciphertext query feature vector with the assistance of the second cloud server to obtain at least one second ciphertext cluster center includes: Step a: The first cloud server and the second cloud server use the root sphere of the clustered index sphere tree as the current sphere; Step b: calculating the fifth distance between the central node of the current sphere and the second ciphertext query feature vector; Step c: based on the maximum inner product value of the fifth distance and the current sphere, obtaining at least one second ciphertext cluster center that has been queried.

8. The image retrieval method supporting privacy protection in a cloud environment according to claim 7, characterized in that: The obtaining, based on the maximum inner product value of the fifth distance and the current sphere, at least one second ciphertext cluster center obtained by querying includes: When the fifth distance is greater than the maximum inner product value of the current sphere, a pruning operation is performed, and the brother sphere of the current sphere is used as the current sphere, and steps b to c are continued; When the fifth distance is less than or equal to the maximum inner product value of the current sphere, the child sphere of the current sphere is used as the current sphere, and the steps b to c are continued until the leaf sphere is reached; Calculating a sixth distance between a central node in the leaf sphere and the second encrypted query feature vector; If the sixth distance is less than or equal to the seventh distance, then when the sixth distance is less than the eighth distance, the central node in the leaf sphere is saved in the search set, and the seventh distance is the sum of the radius of the leaf sphere and the eighth distance; when there is a node in the search set, the eighth distance is the minimum distance among the sixth distances corresponding to all nodes in the search set, and when there is no node in the search set, the eighth distance is infinity; If the sixth distance is greater than the seventh distance, backtracking is performed from the leaf sphere to the root sphere, and during the backtracking process, steps b to c are performed for each sphere.

9. An image retrieval system supporting privacy protection in a cloud environment, characterized in that: include: At least one image owner, at least one image queryer, a first cloud server, a second cloud server, and an authorization center; The authorization center is used to generate a query key of each image inquirer, a first service key of the first cloud server, a second service key of the second cloud server, and an owner key of each image owner, and distribute them; Each of the image owners clusters the image feature vectors of their respective images to obtain a cluster center; based on the owner key, the image feature vector, the cluster center and the image, generates a first ciphertext image feature vector, a first ciphertext cluster center and a ciphertext image, and uploads them to a first cloud server; The first cloud server is used to perform key conversion on each of the first ciphertext image feature vectors and each of the first ciphertext cluster centers based on the first service key to obtain each second ciphertext image feature vector and each second ciphertext cluster center; The first cloud server and the second cloud server are used together to construct a cluster index ball tree based on the second service key, the homomorphic encryption algorithm and each of the second ciphertext cluster centers; The image queryer is used to encrypt the query feature vector of the query image based on the query key to obtain a first encrypted query feature vector, and upload the first encrypted query feature vector to the first cloud server; The first cloud server is further configured to perform key conversion on the first ciphertext query feature vector based on the first service key to obtain a second ciphertext query feature vector; The first cloud server and the second cloud server are also used together to query the cluster index ball tree based on the second ciphertext query feature vector to obtain at least one second ciphertext cluster center; query the second ciphertext image feature vector corresponding to the at least one second ciphertext cluster center according to the second ciphertext query feature vector to obtain at least one second ciphertext image feature vector; send the ciphertext image corresponding to the at least one second ciphertext image feature vector and the corresponding image owner's identifier to the image queryer; The image queryer is further used to decrypt the ciphertext image based on the owner key corresponding to the identifier to obtain the image; The first cloud server and the second cloud server are used together to construct a cluster index ball tree based on the second service key, the homomorphic encryption algorithm and each of the second ciphertext cluster centers, including: Step A: The first cloud server and the second cloud server divide each of the second ciphertext cluster centers as nodes into a root sphere, and use the root sphere as the current sphere; Step B: Based on the second service key and the homomorphic encryption algorithm, the mean of each node in the current sphere is calculated to obtain the central node of the current sphere; Step C: Calculate the first distance between each remaining node and the central node; determine the remaining node with the largest first distance as the first boundary node of the current sphere, and use the largest first distance as the radius of the current sphere, wherein the remaining nodes refer to nodes that do not form a parent-child relationship; Step D: calculating the second distance between each of the remaining nodes and the first boundary node; determining the remaining node with the largest second distance as the second boundary node of the current sphere; Step E: assigning the first boundary node and the second boundary node to the central node and serving as the left child node and the right child node of the central node respectively; Step F: dividing each of the remaining nodes in the current sphere according to the distances between each of the remaining nodes and the first boundary node and the second boundary node, to obtain two sub-spheres; Step G: For each of the child spheres, take the child sphere as the current sphere and continue to execute steps B to G until the child sphere contains only one node, the radius of the child sphere is infinitely small, and the left child node and the right child node of the child sphere are both empty.

Citation Information

Patent Citations

  • K-NN image retrieval method and system based on response length hiding

    CN110866135A

  • Stepless voltage regulating module system of developments

    CN206004314U