Privacy information retrieval method based on GSW homomorphic encryption

By adopting GSW homomorphic encryption technology in privacy information retrieval, the problems of privacy protection and efficiency improvement are solved, efficient and secure privacy information retrieval is achieved, and security needs in the quantum computing era are adapted to the security needs.

CN119939654APending Publication Date: 2025-05-06GUANGZHOU FANGHE DATA SERVICE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510010075.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-03
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

In the retrieval of privacy information, the prior art is difficult to improve the efficiency of client request size and server response size while protecting user privacy, and traditional cryptographic solutions face security threats brought by quantum computing.

Method used

Using a private information retrieval method based on GSW homomorphic encryption, the server runs the initialization algorithm to generate public parameters. The client encodes the query index into a query vector and encrypts it into a query ciphertext vector. The server performs a split-dimensional search through homomorphic calculation, and returns the query result ciphertext to the client for decryption and decoding.

Benefits of technology

Effectively protect the privacy and security of user data, improve the efficiency and accuracy of data processing, reduce unnecessary calculations and data transmission, and improve the response speed and accuracy of retrieval.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939654A_ABST
    Figure CN119939654A_ABST
Patent Text Reader

Abstract

The invention discloses a privacy information retrieval method based on GSW homomorphic encryption, which is characterized in that user privacy is guaranteed through a GSW homomorphic encryption technology, a client encrypts a query index into a ciphertext vector and sends the ciphertext vector to a server, the server performs retrieval on encrypted data by using homomorphic calculation and ensures that a query result is also kept in an encrypted state until the client decrypts, and then the encrypted data are retrieved. According to the technology, the data processing efficiency and safety are improved, direct calculation without decryption is allowed, a fractal dimension retrieval technology optimizes the retrieval process, the response speed and accuracy are improved, a public parameter coding database is used for recording and supporting encrypted query, different requirements are flexibly adapted, a client side manages a secret key, the distribution and management process is simplified, and the user experience is improved. And meanwhile, encryption and decryption security is ensured, and efficient and safe data retrieval service is realized through an advanced encryption technology and an optimized retrieval method.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of cyberspace security technology, and in particular to a privacy information retrieval method based on GSW homomorphic encryption. Background Art

[0002] Private Information Retrieval (PIR) means that when a user makes a database query, the server cannot know the user's specific query content, while still returning the correct query results, thereby protecting the user's query privacy. In addition to being directly applied to database queries, private information retrieval is also the core building block of privacy-preserving applications, such as anonymous communication, private navigation, password checking, and secure browsing. Currently, there are three main performance metrics in private information retrieval: request size, response size, and server computational cost. Among them, compressing the server's response size can improve the efficiency of the client's response processing while reducing communication complexity; compressing the client's request size can reduce communication complexity while reducing the server's computational cost. Therefore, improving the client's request size and the server's response size while protecting privacy is a key issue in this research direction.

[0003] On the other hand, with the rapid development of quantum computing, traditional cryptographic schemes face severe security threats, which may undermine existing cryptographic security mechanisms, leading to the leakage and illegal access of sensitive data, and thus causing serious economic losses. Summary of the invention

[0004] In view of this, the present invention proposes a privacy information retrieval method based on GSW homomorphic encryption, which can effectively protect the privacy and security of user data and improve the efficiency and accuracy of data processing.

[0005] The technical solution of the present invention is achieved in this way:

[0006] A privacy information retrieval method based on GSW homomorphic encryption, specifically including:

[0007] The server runs the initialization algorithm to generate public parameters, encodes the database records according to the public parameters, and sends the public parameters to the client;

[0008] The client encodes the query index for retrieval into a query vector according to the public parameters, and generates a key for encrypting the query vector;

[0009] Encrypt the query vector according to the key to generate a query ciphertext vector, and send the query ciphertext vector to the server;

[0010] The server performs dimension retrieval based on the query ciphertext vector through homomorphic computing, obtains the query result ciphertext and sends it to the client;

[0011] The client decrypts and decodes the received query result ciphertext to obtain the query result.

[0012] As a further optional solution of the privacy information retrieval method based on GSW homomorphic encryption, the server runs an initialization algorithm to generate public parameters, encodes database records according to the public parameters, and sends the public parameters to the client, specifically including:

[0013] Enter the security parameter λ and database size N, and run Setup(1 λ , 1 N ) algorithm generates public parameters Params = (d, q, n, B, l, χ, σ), where d is the size of the polynomial ring, q is the modulus of the polynomial, is the query vector length, B is the cardinality of the Gadget matrix, l is the dimension of the Gadget vector, X is the noise distribution, and σ is the noise parameter;

[0014] Encode N database records into a two-dimensional polynomial matrix according to the common parameters Params Where R q =z q [x] / (X d +1);

[0015] Output common parameters Params = (d, q, n, B, l, xσ).

[0016] As a further optional solution of the private information retrieval method based on GSW homomorphic encryption, the client encodes the query index for retrieval into a query vector according to the public parameters and generates a key for encrypting the query vector, specifically including:

[0017] The client converts the query index idx into (idx1, idx2) according to the public parameter Params, where idx1 is the row index and idx2 is the column index, and encodes it into the corresponding n-dimensional query vectors v1 and v2, where v i =(v i [1],…,v i [n]), and only v i [idx i ]=1, the other components are 0;

[0018] Input public parameters Params and run the key generation algorithm GSW.KeyGen(Params), wherein the key generation algorithm GSW.KeyGen(Params) includes the private key generation algorithm GSW.SKGen(Params) and the public key generation algorithm GSW.PKGen(Params);

[0019] In the private key generation algorithm GSW.SKGen(Params), select a random polynomial s←R q , the output private key sk is

[0020] In the public key generation algorithm GSW.PKGen(Params), select a noise vector e←χ 2l , choose a random vector Calculate b = as + e, and output the public key pk as

[0021] As a further optional solution of the privacy information retrieval method based on GSW homomorphic encryption, encrypting the query vector according to the key to generate a query ciphertext vector, and sending the query ciphertext vector to the server specifically includes:

[0022] Run the GadgetEnc algorithm on each component of the query vector v1 to encrypt it, that is, for i∈1,...,n, run GadgetEnc(pk,v1[i]) to get

[0023] In GadgetEnc(pk, v1[i]), pk is the public key, v1[i] is the plaintext message to be encrypted, and for j∈1,...,l, run GSW.Encry(pk,B j-1 v1[i]) to get Will I GSW ciphertext C 1ij The output c of GadgetEnc(pk, v1[i]) is concatenated into a vector 1i , that is, c 1i =(c 1i1 , …, c 1il );

[0024] Will The vector c1=(c 11 , …, c 1n ), the query ciphertext vector corresponding to the query vector v1 is set to c1;

[0025] GSW encrypts each component of the query vector v2, that is, for i∈1,...,n, run GSw.Encry(pk, v2[i]) to obtain

[0026] In GSW.Encry(pk, v2[i]), Gadget vector g = (1, B, ..., B l-1 ), Gadget Matrix Pick a random matrix Output ciphertext

[0027] Will The vector c2 = (c 21 , …, c 2n ), the query ciphertext vector corresponding to the query vector v2 is set to c2;

[0028] Send query ciphertext vectors c1 and c2 to the server.

[0029] As a further optional solution of the privacy information retrieval method based on GSW homomorphic encryption, the server performs dimension retrieval through homomorphic calculation according to the query ciphertext vector, obtains the query result ciphertext and sends it to the client, which specifically includes:

[0030] Retrieve row dimension based on query ciphertext vector c1: Input query ciphertext vector c1 = (c 11 , …, c 1n ) and database records For i∈1,...,n and j∈1,...,n, compute M ij ←GadgetDecomp(D ij ), We get D′=(D′1, ..., D′ n ), where GadgetDecomp(a) decomposes a based on B and outputs a vector (a0, ..., a l-1 )satisfy

[0031] Retrieve column dimensions based on query ciphertext vector c2: Input query ciphertext vector c2 = (C 21 , …, C 2n ) and D′=(D′1,…,D′ n ), for j∈1,...,n, calculate Among them G -1 (D j ) j Run the GadgetDecomp algorithm on each element of

[0032] Output query result ciphertext C res , and send the query result ciphertext to the client.

[0033] As a further optional solution of the privacy information retrieval method based on GSW homomorphic encryption, the client decrypts and decodes the received query result ciphertext to obtain the query result, which specifically includes:

[0034] Enter the private key sk and the query result ciphertext C res , set t = sk, calculate v = C res t;

[0035] Let w = (0, ..., 1), calculate μ = vG -1 (w T )∈R q Get the query result plaintext polynomial μ;

[0036] The query result polynomial μ is decoded, and μ′←Decode(μ) is calculated to obtain the query result μ′.

[0037] A privacy information retrieval system based on GSW homomorphic encryption, comprising:

[0038] An initialization module is used to be set on the server, execute the initialization algorithm to generate public parameters, and encode the records in the database according to the public parameters; the server is also responsible for sending the public parameters to the client;

[0039] A query encoding and encryption module, which is configured to be arranged on the client, receive public parameters from the server, encode the query index input by the user into a query vector according to the public parameters, and generate a key for encrypting the query vector;

[0040] An encrypted query transmission module is used to be set on the client and send the encrypted query ciphertext vector to the server;

[0041] A homomorphic retrieval module is used to be set on the server, receive the query ciphertext vector from the client, perform a sub-dimensional search on the database through the homomorphic computing function of the GSW homomorphic encryption technology, obtain the encrypted query result ciphertext, and send the query result ciphertext back to the client;

[0042] The decryption and decoding module is used to be set on the client, receive the query result ciphertext from the server, use the generated key to decrypt the query result ciphertext, and decode to obtain the final query result.

[0043] A computing device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the above-mentioned privacy information retrieval method based on GSW homomorphic encryption are implemented.

[0044] A computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the above-mentioned method for private information retrieval based on GSW homomorphic encryption.

[0045] The beneficial effects of the present invention are as follows: through the GSW homomorphic encryption technology, the client can encode and encrypt the query index used for retrieval into a query ciphertext vector, and then send it to the server. During this process, the original content of the query index is kept confidential to the server, thereby preventing the server or a potential third party from directly obtaining the user's query privacy. After receiving the encrypted query ciphertext vector, the server performs dimensional retrieval through homomorphic calculation and returns the query result to the client in an encrypted form, which means that during the entire retrieval process, the content of the query result is also kept confidential to the server, and the final query result can only be obtained after the client uses a private key to decrypt and decode it. The GSW homomorphic encryption technology allows encrypted data to be calculated directly without decrypting the data, which enables the server to obtain encrypted query ciphertexts. The retrieval operation is performed on the vector without decrypting the data, thereby improving the efficiency and security of data processing. Through the sub-dimensional retrieval technology, the server can process the encrypted data more efficiently and quickly locate the query results required by the user. This retrieval method reduces unnecessary calculations and data transmission, and improves the response speed and accuracy of the retrieval. The public parameters generated by the server running the initialization algorithm are not only used to encode database records, but also serve as the basis for the client to generate encrypted query vectors. This design makes the system more flexible and can support query requirements of different users or different application scenarios. The client generates a key for encrypting the query vector and uses the same key when decrypting the query results. This key management method simplifies the key distribution and management process of the system, while ensuring the security of the encryption and decryption process. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0047] Figure 1 A schematic diagram of the steps of a privacy information retrieval method based on GSW homomorphic encryption provided in an embodiment of the present invention;

[0048] Figure 2 A schematic diagram of the composition of a privacy information retrieval system based on GSW homomorphic encryption provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0049] The technical solutions in the embodiments of the present invention are described clearly and completely below. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0050] refer to Figure 1 to Figure 2 , a privacy information retrieval method based on GSW homomorphic encryption, specifically including:

[0051] The server runs the initialization algorithm to generate public parameters, encodes the database records according to the public parameters, and sends the public parameters to the client;

[0052] The client encodes the query index for retrieval into a query vector according to the public parameters, and generates a key for encrypting the query vector;

[0053] Encrypt the query vector according to the key to generate a query ciphertext vector, and send the query ciphertext vector to the server;

[0054] The server performs dimension retrieval based on the query ciphertext vector through homomorphic computing, obtains the query result ciphertext and sends it to the client;

[0055] The client decrypts and decodes the received query result ciphertext to obtain the query result.

[0056] In this embodiment, through the GSW homomorphic encryption technology, the client can encode and encrypt the query index used for retrieval into a query ciphertext vector, and then send it to the server. In this process, the original content of the query index is kept confidential to the server, thereby preventing the server or potential third parties from directly obtaining the user's query privacy. After receiving the encrypted query ciphertext vector, the server performs dimensional retrieval through homomorphic calculation and returns the query result to the client in an encrypted form. This means that during the entire retrieval process, the content of the query result is also kept confidential to the server until the client uses a private key to decrypt and decode it to obtain the final query result. The GSW homomorphic encryption technology allows encrypted data to be calculated directly without decrypting the data, which enables the server to obtain encrypted query ciphertext vectors. Retrieval operations can be performed on the server without decrypting the data, thereby improving the efficiency and security of data processing. Through dimensional retrieval technology, the server can process encrypted data more efficiently and quickly locate the query results required by the user. This retrieval method reduces unnecessary calculations and data transmission, and improves the response speed and accuracy of retrieval. The public parameters generated by the server running the initialization algorithm are not only used to encode database records, but also serve as the basis for the client to generate encrypted query vectors. This design makes the system more flexible and can support query requirements of different users or different application scenarios. The client generates a key for encrypting the query vector and uses the same key when decrypting the query results. This key management method simplifies the system's key distribution and management process, while ensuring the security of the encryption and decryption process.

[0057] Preferably, the server runs an initialization algorithm to generate public parameters, encodes database records according to the public parameters, and sends the public parameters to the client, specifically including:

[0058] Enter the security parameter λ and database size N, and run Setup(1 λ , 1 N ) algorithm generates public parameters Params = (d, q, n, B, l, χ, σ), where d is the size of the polynomial ring, q is the modulus of the polynomial, is the query vector length, B is the cardinality of the Gadget matrix, l is the dimension of the Gadget vector, X is the noise distribution, and σ is the noise parameter;

[0059] Encode N database records into a two-dimensional polynomial matrix according to the common parameters Params Where R q =z q [X] / (X d +1);

[0060] Output public parameters Params = (d, q, n, B, l, χ, σ).

[0061] In this embodiment, the server runs an initialization algorithm to generate public parameters (Params), and uses these public parameters to encode database records. This process ensures that sensitive information in the database has been encrypted before transmission and storage, thereby enhancing data security; after receiving the public parameters, the client can encode the query index into a query vector based on these parameters, and encrypt it to generate a query ciphertext vector. This step also ensures the privacy of the query process because the server cannot directly obtain the plaintext information of the query content; by encoding the database record and converting it into a two-dimensional polynomial matrix D, this step may help reduce redundant information in data transmission, thereby improving the efficiency of data transmission; at the same time, using public parameters to process the encoded data can optimize the subsequent homomorphic computing process, making the processing of encrypted data more efficient; homomorphic computing allows encrypted data to be directly calculated without decrypting the data. This feature enables the server to perform operations such as dimensional retrieval on the encrypted query ciphertext vector, thereby supporting more flexible query requirements; introducing mechanisms such as noise distribution and noise parameters helps to balance security and computing efficiency and ensure the accuracy and reliability of homomorphic computing results.

[0062] It should be noted that the cardinality (B) of the Gadget matrix: The cardinality B is an important parameter used to construct the Gadget matrix, which determines the value range of the elements in the Gadget matrix or the fineness of the decomposition. In the initialization algorithm, B is selected as an integer that meets certain conditions to ensure that the construction of the Gadget matrix meets security requirements and computational efficiency; the dimension (I) of the Gadget vector: The dimension I represents the length of the Gadget vector, which is also a key parameter in the algorithm. It affects the complexity of the encryption operation and the size of the ciphertext. In the initialization algorithm, I is determined according to the security parameter λ and the characteristics of the database (such as size N) to ensure the security and efficiency of the encryption process; The Setup (λ, N) algorithm can be regarded as a general initialization algorithm framework in the field of cryptography and privacy protection, which is used to generate the public parameters and master keys required by the system for subsequent encryption, decryption, signing and other operations.

[0063] Preferably, the client encodes the query index for retrieval into a query vector according to the public parameters, and generates a key for encrypting the query vector, specifically including:

[0064] The client converts the query index idx into (idx1, idx2) according to the public parameter Params, where idx1 is the row index and idx2 is the column index, and encodes it into the corresponding n-dimensional query vectors v1 and v2, where v i =(v i [1],…,v i[n]), and only v i [idx i ]=1, the other components are 0;

[0065] Input public parameters Params and run the key generation algorithm GSW.KeyGen(Params), wherein the key generation algorithm GSW.KeyGen(Params) includes the private key generation algorithm GSW.SKGen(Params) and the public key generation algorithm GSW.PKGen(Params);

[0066] In the private key generation algorithm GSW.SKGen(Params), select a random polynomial s←R q , the output private key sk is

[0067] In the public key generation algorithm GSW.PKGen(Params), select a noise vector e←χ 2l , choose a random vector Calculate b = as + e, and output the public key pk as

[0068] In this embodiment, the client encodes the query index idx into n-dimensional query vectors v1, v2 according to the public parameter Params, where only the value of the component corresponding to idx1 is 1, and the other components are 0. This sparse vector encoding method not only effectively reduces the data transmission volume, but also enhances the confidentiality of the data, making it difficult for unauthorized third parties to directly infer the original query index from the query vector; further, by generating a key for encrypting the query vector, the scheme ensures the security of the query vector during transmission. Even if the query vector is intercepted, the original query information cannot be decrypted without the corresponding key, thereby effectively preventing data leakage; GSW (Gentry-Sahai-Waters) homomorphic encryption technology is used to generate the key for encrypting the query vector. GSW homomorphic encryption technology is known for its strong security and homomorphic computing capabilities. It is possible to directly calculate the encrypted data without decrypting it, which provides a strong guarantee for the realization of secure query processing. In the key generation process, the generation of private key and public key is completed by private key generation algorithm GSW.SKGen (Params) and public key generation algorithm GSW.PKGen (Params) respectively. The private key is used for operations such as decryption and signing, while the public key is used for operations such as encryption and verification. This design of separation of public and private keys further enhances the security of the system. By encoding the query index into a query vector and encrypting it and sending it to the server for processing, flexible query of data in the database is achieved. After receiving the encrypted query vector, the server can use homomorphic computing technology to directly calculate on the encrypted data to obtain encrypted query results. This method not only avoids direct exposure of data, but also ensures the accuracy and completeness of the query results.

[0069] It should be noted that in the private key generation algorithm GSW.SKGen(Params), the random polynomial s is a random polynomial from the polynomial ring R q This means that s is a polynomial with coefficients modulo q and the degree and form of the polynomial are in R q In the public key generation algorithm GSW.PKGen(Params), the random vector a is randomly determined within the domain of R 2 Randomly selected from the 2 represents a two-dimensional vector space.

[0070] Preferably, encrypting the query vector according to the key to generate a query ciphertext vector, and sending the query ciphertext vector to the server specifically includes:

[0071] Run the GadgetEnc algorithm on each component of the query vector v1 to encrypt it, that is, for i∈1,...,n, run GadgetEnc(pk,v1[i]) to get

[0072] In GadgetEnc(pk, v1[i]), pk is the public key, v1[i] is the plaintext message to be encrypted, and for j∈1,...,l, run GSW.Encry(pk,B j-1 v1[i]) to get I GSW ciphertext C 1ij The output c of GadgetEnc(pk, v1[i]) is concatenated into a vector 1i , that is, c 1i =(c 1i1 , …, c 1il );

[0073] Will The vector c1=(c 11 , …, c 1n ), the query ciphertext vector corresponding to the query vector v1 is set to c1;

[0074] GSW encrypts each component of the query vector v2, that is, for i∈1,...,n, run GSW.Encry(pk, v2[i]) to obtain

[0075] In GSW.Encry(pk, v2[i]), Gadget vector g = (1, B, ..., B l-1 ), Gadget Matrix Pick a random matrix Output ciphertext

[0076] Will The vector c2 = (c 21 , …, c 2n ), the query ciphertext vector corresponding to the query vector v2 is set to c2;

[0077] Send query ciphertext vectors c1 and c2 to the server.

[0078] In this embodiment, two encryption methods are used: one is to use the GadgetEnc algorithm to encrypt each component of the query vector, and the algorithm also embeds GSW (Gentry-Sahai-Waters) homomorphic encryption; the other is to directly use GSW encryption for each component of another version (v2) of the query vector. This multi-level encryption strategy provides higher flexibility and security, and the appropriate encryption method can be selected according to different needs; by encrypting the query vector into a ciphertext vector and sending these ciphertext vectors to the server, data processing (such as search, calculation, etc.) can be performed without decryption, thereby improving the efficiency of data transmission and processing. The characteristics of homomorphic encryption enable the server to perform calculations directly on the encrypted data without decryption, thereby reducing the complexity and time cost of data transmission; by decomposing the query vector into multiple parts and encrypting them separately, the technical solution can support more complex queries and advanced data operations. For example, different encryption levels or access rights can be set for different parts in the query vector to meet different data security and privacy requirements.

[0079] Preferably, the server performs sub-dimensional retrieval through homomorphic computing according to the query ciphertext vector, obtains the query result ciphertext and sends it to the client, specifically including:

[0080] Retrieve row dimension based on query ciphertext vector c1: Input query ciphertext vector c1 = (c 11 , …, c 1n ) and database records For i∈1,...,n and j∈1,...,n, compute M ij ←GadgetDecomp(D ij ), We get D′=(D′1, ..., D′ n ), where GadgetDecomp(a) decomposes a based on B and outputs a vector (a0, ..., a l-1 )satisfy

[0081] Retrieve column dimensions based on query ciphertext vector c2: Input query ciphertext vector c2 = (c 21 , …, c 2n ) and D′=(D′1,…,D′ n ), for j∈1,...,n, calculate Among them G -1 (D j ) j Run the GadgetDecomp algorithm on each element of

[0082] Output query result ciphertext C res, and send the query result ciphertext to the client.

[0083] In this embodiment, through the "GadgetDecomp" algorithm, the technical solution can achieve efficient retrieval of the database. The algorithm converts the database records into a series of numbers (D1, D2, ..., Dn), and multiplies them with the query ciphertext vector to generate a new ciphertext vector D'. This process utilizes the characteristics of homomorphic computing, so that the retrieval operation can be performed directly on the encrypted data without decryption, thereby improving the retrieval efficiency; by processing the query ciphertext vectors C1 and C2 separately, the accurate matching of the data in the database can be achieved. This multi-dimensional retrieval method allows users to construct query conditions more flexibly to meet different data retrieval requirements; since the technical solution is based on homomorphic computing and the "GadgetDecomp" algorithm, it has good scalability and flexibility. With the expansion of the database scale and the complexity of query requirements, the retrieval performance and data security can be further improved by adjusting the algorithm parameters or introducing new optimization strategies.

[0084] Preferably, the client decrypts and decodes the received query result ciphertext to obtain the query result, which specifically includes:

[0085] Enter the private key sk and the query result ciphertext C res , set t = sk, calculate v = C res t;

[0086] Let w = (0, ..., 1), calculate μ = vG -1 (w T )∈R q Get the query result plaintext polynomial μ;

[0087] The query result polynomial μ is decoded, and μ′←Decode(μ) is calculated to obtain the query result μ′.

[0088] In this embodiment, the query result ciphertext Cres is decrypted by using the private key sk. This technical solution ensures the security of the data during transmission. Even if the data is intercepted during transmission, the original data cannot be decrypted without the corresponding private key, thereby preventing the leakage of sensitive information. By comparing the decrypted and decoded polynomial v with Decode(u), the correctness of the decryption and decoding process can be verified, which ensures that the query result μ′ finally extracted is accurate, thereby improving the reliability and stability of the system.

[0089] It should be noted that “Decode(u)” represents the process of decoding the query result u, which may be implemented by a defined decoding function or algorithm.

[0090] A privacy information retrieval system based on GSW homomorphic encryption, comprising:

[0091] An initialization module is used to be set on the server, execute the initialization algorithm to generate public parameters, and encode the records in the database according to the public parameters; the server is also responsible for sending the public parameters to the client;

[0092] A query encoding and encryption module, which is configured to be arranged on the client, receive public parameters from the server, encode the query index input by the user into a query vector according to the public parameters, and generate a key for encrypting the query vector;

[0093] An encrypted query transmission module is used to be set on the client and send the encrypted query ciphertext vector to the server;

[0094] A homomorphic retrieval module is used to be set on the server, receive the query ciphertext vector from the client, perform a sub-dimensional search on the database through the homomorphic computing function of the GSW homomorphic encryption technology, obtain the encrypted query result ciphertext, and send the query result ciphertext back to the client;

[0095] The decryption and decoding module is used to be set on the client, receive the query result ciphertext from the server, use the generated key to decrypt the query result ciphertext, and decode to obtain the final query result.

[0096] A computing device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the above-mentioned privacy information retrieval method based on GSW homomorphic encryption are implemented.

[0097] A computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the above-mentioned method for private information retrieval based on GSW homomorphic encryption.

[0098] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the protection scope of the present invention.

Claims

1. A privacy information retrieval method based on GSW homomorphic encryption, characterized in that: Specifically include: The server runs the initialization algorithm to generate public parameters, encodes the database records according to the public parameters, and sends the public parameters to the client; The client encodes the query index for retrieval into a query vector according to the public parameters, and generates a key for encrypting the query vector; Encrypt the query vector according to the key to generate a query ciphertext vector, and send the query ciphertext vector to the server; The server performs dimension retrieval based on the query ciphertext vector through homomorphic computing, obtains the query result ciphertext and sends it to the client; The client decrypts and decodes the received query result ciphertext to obtain the query result.

2. According to claim 1, a privacy information retrieval method based on GSW homomorphic encryption is characterized in that: The server runs an initialization algorithm to generate public parameters, encodes database records according to the public parameters, and sends the public parameters to the client, specifically including: Enter the security parameter λ and database size N, and run Setup(1 λ , 1 N ) algorithm generates public parameters Params = (d, q, n, B, l, χ, σ), where d is the size of the polynomial ring, q is the modulus of the polynomial, is the query vector length, B is the cardinality of the Gadget matrix, l is the dimension of the Gadget vector, χ is the noise distribution, and σ is the noise parameter; Encode N database records into a two-dimensional polynomial matrix according to the common parameters Params Where R q =Z q [X] / (X d +1); Output public parameters Params = (d, q, n, B, l, χ, σ).

3. According to claim 2, a privacy information retrieval method based on GSW homomorphic encryption is characterized in that: The client encodes the query index for retrieval into a query vector according to the public parameters, and generates a key for encrypting the query vector, specifically including: The client converts the query index idx into (idx1, idx2) according to the public parameter Params, where idx1 is the row index and idx2 is the column index, and encodes it into the corresponding n-dimensional query vectors v1 and v2, where v i =(v i [1], …, v i [n]), and only v i [idx i ]=1, the other components are 0; Input public parameters Params and run the key generation algorithm GSW.KeyGen(Params), wherein the key generation algorithm GSW.KeyGen(Params) includes the private key generation algorithm GSW.SKGen(Params) and the public key generation algorithm GSW.PKGen(Params); In the private key generation algorithm GSW.SKGen(Params), select a random polynomial s←R q , output private key sk is In the public key generation algorithm GSW.PKGen(Params), select a noise vector e←χ 2l , choose a random vector Calculate b = as + e, and output the public key pk as 4. According to claim 3, a privacy information retrieval method based on GSW homomorphic encryption is characterized in that: The step of encrypting the query vector according to the key to generate a query ciphertext vector and sending the query ciphertext vector to the server specifically includes: Run the GadgetEnc algorithm on each component of the query vector v1 to encrypt it, that is, for i∈1,...,n, run GadgetEnc(pk,v1[i]) to get In GadgetEnc(pk, v1[i]), pk is the public key, v1[i] is the plaintext message to be encrypted, and for j∈1,...,l, run GSW.Encry(pk,B j-1 v1[i]) to get The l GSW ciphertext C 1ij The output c of GadgetEnc(pk, v1[i]) is concatenated into a vector 1i , that is, c 1i =(C 1i1 , …, C 1il ); Will The vector c1=(c 11 , …, c 1n ), the query ciphertext vector corresponding to the query vector v1 is set to c1; GSW encrypts each component of the query vector v2, that is, for i∈1,...,n, run GSW.Encry(pk,v2[i]) to obtain In GSW.Encry(pk, v2[i]), Gadget vector g = (1, B, ..., B l-1 ),Gadget Matrix Pick a random matrix Output ciphertext Will The vector c2 = (C 21 , …, C 2n ), the query ciphertext vector corresponding to the query vector v2 is set to c2; Send query ciphertext vectors c1 and c2 to the server.

5. According to claim 4, a privacy information retrieval method based on GSW homomorphic encryption is characterized in that: The server performs a sub-dimensional search based on the query ciphertext vector through homomorphic computing, obtains the query result ciphertext and sends it to the client, specifically including: Retrieve row dimension based on query ciphertext vector c1: Input query ciphertext vector c1 = (c 11 ,…,c 1n ) and database records For i∈1,...,n and j∈1,...,n, compute M ij ←GadgetDecomp(D ij ), We get D′=(D′1, ..., D′ n ), where GadgetDecomp(a) decomposes a based on B and outputs a vector (a0, ..., a l-1 )satisfy Retrieve column dimensions based on query ciphertext vector c2: Input query ciphertext vector c2 = (C 21 , …, C 2n )) and D′=(D′1,…,D′ n ), for j∈1,...,n, calculate Among them G -1 (D j ) j Run the GadgetDecomp algorithm on each element of Output query result ciphertext C res , and send the query result ciphertext to the client.

6. According to claim 5, a privacy information retrieval method based on GSW homomorphic encryption is characterized in that: The client decrypts and decodes the received query result ciphertext to obtain the query result, which specifically includes: Enter the private key sk and the query result ciphertext C res , set t = sk, calculate v = C res t; Let w = (0, ..., 1), calculate μ = vG -1 (w T )∈R q Get the query result plaintext polynomial μ; The query result polynomial μ is decoded, and μ′←Decode(μ) is calculated to obtain the query result μ′.

7. A privacy information retrieval system based on GSW homomorphic encryption, characterized in that: include: An initialization module, which is set on the server, executes an initialization algorithm to generate public parameters, and encodes records in the database according to the public parameters; The server is also responsible for sending the public parameters to the client; A query encoding and encryption module, which is configured to be arranged on the client, receive public parameters from the server, encode the query index input by the user into a query vector according to the public parameters, and generate a key for encrypting the query vector; An encrypted query transmission module is used to be set on the client and send the encrypted query ciphertext vector to the server; A homomorphic retrieval module is used to be set on the server, receive the query ciphertext vector from the client, perform a sub-dimensional search on the database through the homomorphic computing function of the GSW homomorphic encryption technology, obtain the encrypted query result ciphertext, and send the query result ciphertext back to the client; The decryption and decoding module is used to be set on the client, receive the query result ciphertext from the server, use the generated key to decrypt the query result ciphertext, and decode to obtain the final query result.

8. A computing device, characterized in that The method comprises a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the method implements the steps of the privacy information retrieval method based on GSW homomorphic encryption as described in any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that: The storage medium stores a computer program, which, when executed by a processor, implements the steps of the privacy information retrieval method based on GSW homomorphic encryption as described in any one of claims 1 to 6.