Privacy information retrieval method supporting Boolean retrieval model and related products
Through constant recoding and RLWE homomorphic encryption technology, the keywords in the database are encoded and encrypted, and the keywords in the database are generated that support secure retrieval - multi-hot code database. Through homomorphic equality operations and Boolean logic operations, the existing privacy information retrieval solutions are solved inefficient efficiency and insufficient privacy protection capabilities when dealing with many-to-many data relationships and supporting complex Boolean logic operations, and efficient and secure privacy information retrieval is achieved.
Patent Information
- Application Number
- CN202510056141.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-14
- Publication Date
- 2025-05-13
AI Technical Summary
Existing privacy information retrieval solutions have problems such as inefficiency, high computing and communication overhead, and insufficient privacy protection capabilities when dealing with many-to-many data relationships and supporting complex Boolean logic operations.
Through constant recoding and RLWE homomorphic encryption technology, keywords in the database are encoded and encrypted to generate keywords that support secure retrieval - multi-hot code database. During the search process, the final multi-hot code ciphertext is generated through homomorphic equality operation and Boolean logic operation processing, and the search result is output by matching with the value list.
It realizes the efficient search of complex Boolean logical operations on many-to-many relational databases while protecting user search privacy, which significantly improves the security and efficiency of the information retrieval system and meets the complex retrieval needs.
Smart Images

Figure CN119988376A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of privacy information retrieval, and in particular to a privacy information retrieval method supporting a Boolean retrieval model and related products. Background Art
[0002] With the rapid development of information technology and the increasing demand for data privacy protection, Private Information Retrieval (PIR) technology has gradually become a research hotspot. PIR technology allows users to retrieve the required information from the server without disclosing the retrieval content. Most of the existing PIR technologies focus on simple retrieval scenarios, that is, retrieval for a single keyword. However, in practical applications, many scenarios require retrieval of complex data relationships, which usually contain many-to-many mapping relationships between multiple keywords and values.
[0003] Traditional PIR schemes are usually designed based on a "one-to-one" data structure, that is, each keyword is associated with only one value. This type of design limits its adaptability to complex data models, especially when it is necessary to handle many-to-many data relationships. In addition, these schemes have limited capabilities in logical operations and cannot support combinations of Boolean logic operators (such as AND, OR, NOT).
[0004] In summary, existing privacy information retrieval schemes are difficult to effectively support many-to-many data relationships and Boolean logic operations, and show obvious limitations when faced with complex retrieval scenarios. Summary of the invention
[0005] The technical problem to be solved by the present invention is the low efficiency, high computational and communication overhead, and insufficient privacy protection capabilities of existing privacy information retrieval solutions when processing many-to-many data relationships and supporting complex Boolean logic operations. The purpose is to provide a privacy information retrieval method and related products that support a Boolean retrieval model, which can protect the user's retrieval privacy while efficiently performing complex Boolean logic operations on many-to-many relationship databases, thereby meeting the needs for accurate and expressive retrieval in practical applications.
[0006] The present invention is achieved through the following technical solutions:
[0007] A privacy information retrieval method supporting a Boolean retrieval model, comprising:
[0008] Database format determination: determine whether the database is a keyword-multi-hot code database. If not, reshape the many-to-many database into a keyword-multi-hot code database.
[0009] Encoding and encryption: Encode the keyword-multi-hot code database through constant weight encoding and RLWE homomorphic encryption technology; encrypt the query keywords through constant weight encoding and RLWE homomorphic encryption technology;
[0010] Retrieval and matching: Perform homomorphic equality operations on the RLWE ciphertext corresponding to the search keyword and the RLWE plaintext corresponding to multiple keywords in the database to generate multiple selected ciphertexts; determine the intermediate multi-hot code ciphertext corresponding to the search keyword based on the selected ciphertext;
[0011] Logical operation processing, performing corresponding Boolean logic operations on multiple intermediate multi-hot ciphertexts according to the Boolean operation logic between multiple search keywords to generate final multi-hot ciphertexts; if it is a single search keyword and no logical operation is required, the corresponding intermediate multi-hot ciphertext is used as the final multi-hot ciphertext;
[0012] The result is calculated and output. The final multi-hot code ciphertext is homomorphically multiplied with the value list, and the position of 1 in the multi-hot code is obtained, which corresponds to the value of the position in the value list. The parsed output is the search result.
[0013] Specifically, the methods for reshaping the database organization form include:
[0014] Determine all the different values in the database, and use RLWE homomorphic encryption technology to perform RLWE plaintext encoding on the value payload to generate a value list of corresponding size. The number of values in the value list is M;
[0015] Generate a multi-hot code of length M for each keyword in the database. If the keyword is associated with a value, the corresponding position of the multi-hot code is set to 1, otherwise it is set to 0;
[0016] Each keyword and its corresponding multi-hot code are reorganized into a keyword-multi-hot code database.
[0017] Specifically, the encoding and encryption methods include:
[0018] Perform constant weight encoding on all keywords in the keyword-multi-hot code database to obtain encoded keywords;
[0019] Based on the RLWE homomorphic encryption technology, the keywords after constant weight encoding are RLWE plaintext encoded; the multi-hot code corresponding to each keyword is RWLERLWE plaintext encoded; and the encoded keyword-multi-hot code database is obtained.
[0020] Multiple search keywords are encoded through constant weight encoding, and the encoded search keywords are encrypted based on RLWE homomorphic encryption technology.
[0021] Specifically, the retrieval and matching methods include:
[0022] Encode the search keywords with constant weight, and encrypt the encoded search keywords with RLWE based on RLWE homomorphic encryption technology;
[0023] Perform homomorphic equality operations on the RLWE ciphertext corresponding to the search keyword and the RLWE plaintext corresponding to all the encoding keywords in the database in turn to generate multiple selected ciphertexts; if the search keyword matches the encoding keyword, an all-1 ciphertext is generated, otherwise an all-0 ciphertext is generated;
[0024] The multi-hot ciphertexts are mapped to the values corresponding to all the encoding keywords in turn by multi-hot homomorphic multiplication operations, and all the results are homomorphically summed to obtain the intermediate multi-hot ciphertexts.
[0025] Specifically, the method of logic operation processing includes:
[0026] Obtain multiple intermediate multi-hot code ciphertexts through multiple search keywords;
[0027] Determine the Boolean logic relationship between multiple search keywords;
[0028] Boolean logic operations are performed on multiple intermediate multi-hot ciphertexts according to the Boolean logic relationship between the search keywords to generate final multi-hot ciphertexts.
[0029] Optionally, the basic Boolean logic operations include an AND operation, an OR operation, and a NOT operation;
[0030] The method of performing AND operation on multi-hot ciphertexts is as follows: homomorphically multiply two multi-hot ciphertexts;
[0031] The method of performing negation operation on the multi-hot ciphertext is: perform -1 operation on the multi-hot ciphertext, and then negate the intermediate vector after -1;
[0032] The method of performing an OR operation on multi-hot ciphertexts is: firstly perform a negation operation on both multi-hot ciphertexts, then perform a homomorphic multiplication operation on the two negation operation results, and then perform a negation operation on the homomorphic multiplication operation result.
[0033] Specifically, each RLWE plaintext / RLWE ciphertext unit contains multiple slots, and the number of slots is equal to the degree of the RLWE polynomial modulus; the capacity of each slot is based on the parameter setting of RLWE homomorphic encryption;
[0034] When the length of the multi-hot code exceeds the degree of the polynomial modulus in a single RLWE plaintext / RLWE ciphertext unit, multi-hot encoding is performed: the ratio of the multi-hot code length to the degree of the polynomial modulus is calculated and rounded up to determine the required number of RLWE plaintext units x; the multi-hot code is plaintext encoded using x RLWE plaintext units;
[0035] When the payload size of the value exceeds the slot capacity of a single RLWE plaintext / RLWE ciphertext unit, encode the payload of the value: calculate the ratio of the payload size of the value to the slot capacity and round up to determine the number of RLWE plaintext units y required; plaintext encode the payload of the value using y RLWE plaintext units;
[0036] Finally, the value payload is encoded as a matrix of x×y RLWE plaintext units.
[0037] A private information retrieval terminal supporting a Boolean retrieval model comprises a memory, a processor and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the private information retrieval method supporting a Boolean retrieval model as described above is implemented.
[0038] A computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method for retrieving private information supporting a Boolean retrieval model as described above is implemented.
[0039] A computer program product includes a computer program / instruction, which, when executed by a processor, implements the above-mentioned private information retrieval method supporting the Boolean retrieval model.
[0040] Compared with the prior art, the present invention has the following advantages and beneficial effects:
[0041] The present invention encodes keywords in a database by constant weight encoding, and encrypts the encoded keywords by using a homomorphic encryption technology based on RLWE, thereby generating a keyword-multi-hot code database supporting secure retrieval; in the retrieval process, after constant weight encoding and homomorphic encryption of the retrieval keywords, a homomorphic equality operation is performed with the encoded keywords in the database to generate a selected ciphertext; based on the selected ciphertext, an intermediate multi-hot code ciphertext is extracted, and multiple intermediate multi-hot code ciphertexts are processed in combination with Boolean logic operations to generate a final multi-hot code ciphertext, and finally the retrieval result is output by matching calculation with a value list.
[0042] The present invention ensures the privacy and security of keywords and search content during the search process through constant weight encoding and RLWE homomorphic encryption technology, avoids the server or third-party eavesdroppers from snooping on user search information, and thus greatly improves the security of the information retrieval system.
[0043] The keyword-value representation through multi-hot coding supports the efficient processing of complex data structures and optimizes the retrieval efficiency, so that users' retrieval needs can still be quickly responded to on larger data sets.
[0044] By supporting Boolean logic operations (AND, OR, NOT), the expressiveness of retrieval is significantly improved, allowing users to use logical combinations to construct complex retrieval conditions and meet the needs of a richer range of application scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] The accompanying drawings illustrate exemplary embodiments of the present invention and, together with the description thereof, are used to explain the principles of the present invention. These drawings are included to provide a further understanding of the present invention, and the accompanying drawings are included in and constitute a part of this specification and do not constitute a limitation of the embodiments of the present invention.
[0046] Figure 1 It is a flowchart of a privacy information retrieval method supporting a Boolean retrieval model according to the present invention. DETAILED DESCRIPTION
[0047] To make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and implementation methods. It is understood that the specific implementation methods described herein are only used to explain the relevant content, rather than to limit the present invention.
[0048] It should also be noted that, for the convenience of description, only the parts related to the present invention are shown in the drawings.
[0049] In the absence of conflict, the embodiments and features of the embodiments of the present invention may be combined with each other. The present invention will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0050] The present invention provides a new keyword PIR (Private Information Retrieval) scheme, which can perform privacy-safe Boolean retrieval operations in databases with many-to-many relationships. Compared with the prior art, the present invention supports information retrieval using complex search conditions while protecting user retrieval privacy, breaking through the limitations of traditional keyword PIR methods. By supporting complex and secure keyword searches, the present invention significantly improves the practicality of PIR technology in real-world scenarios, and is particularly suitable for retrieval tasks that require high privacy protection, such as patent searches, web page searches, and file retrievals.
[0051] Existing keyword PIR schemes have difficulty supporting complex Boolean searches, which are a classic model in information retrieval that allows users to combine keywords through logical operators (such as AND, OR, and NOT) to form complex searches. This model is of great significance in improving the accuracy and expressiveness of search results. However, traditional keyword PIR schemes are mainly designed based on the "one-to-one" relationship between keywords and values, and their implicit assumption is that a search keyword will only correspond to one relevant value. This design cannot effectively handle databases with many-to-many relationships, nor can it support the combination or exclusion of multiple keywords through Boolean operators. Therefore, existing schemes show obvious limitations when facing many-to-many relationship databases or complex search tasks.
[0052] To overcome the above limitations, the present invention proposes a novel keyword PIR method based on homomorphic encryption technology. By reshaping and optimizing the database structure, the present invention can efficiently and safely support Boolean logic operations. For example, in a database, there may be a complex many-to-many relationship between a keyword set and a value. The present invention simplifies the data processing flow by introducing constant weight encoding and homomorphic equality operations, and greatly reduces calculation and communication overhead. In addition, by supporting Boolean logic operations, the present invention allows users to combine multiple keywords (such as "containing keyword A and not containing keyword B") through logical conditions to achieve complex retrieval, which is of great significance for improving the applicability of PIR technology in practical applications.
[0053] The keyword PIR protocol of the present invention includes two parts, a server and a client. The server maintains a database containing keywords and values, and pre-processes it through encoding and homomorphic encryption technology. The client sends an encrypted search request without disclosing the search content, and receives an encrypted response result from the server. Through homomorphic encryption technology, the server can complete matching calculations and Boolean operations without decrypting the search, thereby generating a ciphertext payload containing the search results. The client finally decrypts the payload and parses it into a plaintext result, thereby completing the entire search process.
[0054] In database relationships, the relationship between keywords and values can be divided into four main types according to the data structure: one-to-one, many-to-one, one-to-many, and many-to-many. Different types of relationships have different requirements on the adaptability and performance of the PIR solution. The specific characteristics are analyzed as follows:
[0055] One-to-one relationship: each keyword kw i are uniquely associated with a value v j For a retrieval Q(kw i ), the system directly retrieves and kw i The associated unique value v jThis relationship is the simplest data model, and all keyword PIR schemes can work on this model with a problem size of O(n), where n is the number of keywords. Since the retrieval is done on a linear structure of size n, the computation and communication overhead is low and it is suitable for simple data scenarios.
[0056] One-to-many relationship: each keyword kw i Associate a subset of values Where S i is a unique subset of the value set V. Retrieve Q(kw i ) will return the same as kw i The associated subset S i . Since retrieval needs to consider all possible value sets, the problem scale expands from the number of keywords to the size of the value set O(m), where m is the size of the maximum value set. Some optimized PIR schemes can only operate efficiently in one-to-one or many-to-one relationships, and in one-to-many relationships, only one matching value may be returned. Taking CwPIR (reference paper: Constant-weight PIR: Single-round keyword PIR via constant-weight equality operators) as an example, its database is modified to a linear structure with redundant keywords and values, and many-to-many relationships can be supported by calculating the inner product of the selection vector and the load. However, this modification will bring high response communication overhead and may leak database structure information.
[0057] Many-to-many relationship: Allow each keyword kw i Associating multiple subsets of values And the value sets between multiple keywords may overlap. i ), the system needs to retrieve kw i The associated value set S i . At this point, the problem size increases to O(n·m) because it is necessary to handle the overlap and potential combinations of all keyword and value sets. The length of the linear structure varies in the range [n,nm], which leads to a significant increase in computational and communication overhead. Even PIR schemes that can support many-to-many relationships (such as CwPIR) still face significant performance bottlenecks, including increased database storage overhead, returning duplicate values, privacy leakage risks, and complexity increased to O(n·m).
[0058] Homomorphic Encryption (HE) is an encryption technology that allows direct calculations on encrypted data, and the encrypted output of the calculation result is consistent with the result of the same calculation on the original plaintext after decryption. This feature makes it possible to perform calculations on encrypted data without exposing the original data, thereby greatly improving the ability to protect data privacy. In the present invention, HE technology is applied to private information retrieval (PIR), and the user sends an encrypted query to the server, and the server processes it and returns the encrypted result without decrypting the query content. This method can reduce communication costs while simplifying deployment on a single server.
[0059] If a homomorphic encryption scheme can support any number of addition and multiplication operations, it is called fully homomorphic encryption (FHE). However, due to the high computational cost of FHE with arbitrary computational depth, a leveled homomorphic encryption (Leveled FHE) scheme with a fixed computational depth is usually adopted in practice. Leveled FHE strikes a balance between computational depth and cost and is the mainstream choice in practical applications. Mainstream Leveled FHE schemes include FV, BGV, and CKKS, which are usually based on the difficult problem of learning with errors (LWE) and its variant, ring-based LWE (RLWE), and use noisy ciphertexts.
[0060] The RLWE homomorphic encryption scheme used in the present invention has the characteristics of Single Instruction Multiple Data (SIMD), and its SIMD homomorphic operation includes the following primitives:
[0061] CtCtAdd: Adds two ciphertexts element by element to generate the resulting ciphertext.
[0062] CtPtAdd: Adds the ciphertext and plaintext element by element to generate the resulting ciphertext.
[0063] CtCtMul: Performs element-wise homomorphic multiplication of two ciphertexts to generate the resulting ciphertext.
[0064] CtPtMul: Performs element-by-element homomorphic multiplication of ciphertext and plaintext to generate the resulting ciphertext.
[0065] CtRotate: Performs cyclic shift on the elements in the ciphertext to generate the resulting ciphertext.
[0066] CtNegate: Negates the elements in the ciphertext one by one to generate the resulting ciphertext.
[0067] The homomorphic operations involved in the present invention all perform SIMD operations by default.
[0068] Constant-weight codes are a special type of binary encoding where each codeword contains the same number of 1s and 0s. The Hamming weight of these codewords is represented by k, which refers to the number of "1s" in the binary string. The code length w represents the total number of bits in the codeword, while the codeword space size h is the total number of constructible codewords. In constant-weight codes, each number is uniquely mapped to a constant-weight code to ensure uniqueness under certain constraints.
[0069] Constant weight encoding satisfies the following constraints: in, represents the number of combinations of selecting k bits from w bits. Constant weight coding can be represented by CW(w,k), which represents a set of constant weight codes with code length w and Hamming weight k. By optimizing the selection of w, k, and h, a unique codeword can be assigned to each number from 1 to h in the constant weight coding space.
[0070] The role of constant weight encoding in the keyword PIR scheme is to select an appropriate hash function to perform hash operations on the keywords, map them to a unique number, and then perform constant weight encoding on this number. Through the characteristics of these codes, the privacy protection and matching of keywords can be achieved in a homomorphic encryption environment.
[0071] The constant weight equality operation is a keyword PIR scheme based on constant weight codes, which is used to compare whether two constant weight codes are equal in a homomorphic encryption environment. The basic idea is as follows: represent the two constant weight codes as binary vectors respectively. The process of comparing two constant weight codes: homomorphically multiply the bits with a value of 1 in one constant weight code with the values of the corresponding positions in the other constant weight code. All intermediate results are homomorphically multiplied to generate a final product result. If the final result is 1, the two constant weight codes are equal; otherwise, they are not equal. In addition, an arithmetic method can be used to compare the two constant weight codes on a field with k! multiplication inverse elements. If the two constant weight codes are equal, the positions of the bits equal to 1 in the two constant weight codes are the same, and the inner product k′ of the two constant weight codes will be equal to k. When they are not equal, the inner product will be in the set {0,1,…,k-1}. Therefore, the calculation If the result is 1, the two constant weight codes are equal, and if it is 0, they are not equal.
[0072] Embodiment 1
[0073] Provide as Figure 1 A privacy information retrieval method supporting a Boolean retrieval model is shown, comprising:
[0074] Database format determination: Determine whether the database is a keyword-multi-hot code database. If not, reshape the many-to-many database (i.e., each keyword may be associated with multiple values, and each value may be associated with multiple keywords) into a keyword-multi-hot code database. During the reshaping process, the multi-hot code represents the position of the value in the database. First, there must be a list of values. If the value is in a certain position in the list, the multi-hot code bit is 1, otherwise it is set to 0.
[0075] Encoding and encryption: Encode the keywords in the database through constant weight encoding, and encode the encoded keywords in plain text based on RLWE homomorphic encryption technology; generate binary code for each keyword through constant weight encoding, so that each keyword in the encoding space is unique and evenly distributed. Use RLWE homomorphic encryption technology to encrypt the keywords after constant weight encoding. The reason for using RLWE homomorphic encryption is that RLWE allows operations to be performed directly in the ciphertext state to ensure that privacy is not leaked.
[0076] The search keywords are encoded through constant weight encoding, and the encoded search keywords are encrypted based on the RLWE homomorphic encryption technology; if Boolean search is required for multiple keywords, continue to add search keywords, and the added search keywords are again constant weight encoded and RLWE encrypted.
[0077] Retrieval and matching: Perform homomorphic equality operations on the RLWE ciphertext corresponding to the search keyword and the RLWE plaintext corresponding to all keywords in the database, that is, use the equality operation of homomorphic encryption to generate multiple selected ciphertexts; determine the intermediate multi-hot code ciphertext corresponding to the search keyword based on the selected ciphertext.
[0078] Logical operation processing: perform corresponding Boolean logic operations on the intermediate multi-hot ciphertext according to the Boolean operation logic of the search keyword to generate the final multi-hot ciphertext; perform logical operations on the intermediate multi-hot ciphertext according to the Boolean logic relationship (such as AND, OR, NOT) between the keywords in the user's search. If it is a single search keyword and no logical operation is required, the corresponding intermediate multi-hot ciphertext will be used as the final multi-hot ciphertext.
[0079] The result is calculated and output. The search results that meet the Boolean search conditions are output based on the final multi-hot code ciphertext. The final multi-hot code ciphertext is homomorphically multiplied with the value list payload in the database to obtain the payload of the value in the same position in the value list corresponding to the position of the bit that is 1 in the multi-hot code. These values are parsed and output as the search results.
[0080] In the attached Figure 1 In the expression, (multiple) depends on whether there are multiple search keywords; if the number of search keywords is multiple, multiple intermediate multi-hot codes are obtained.
[0081] (List) depends on whether the multi-hot code length (value set size M) is greater than the degree of the polynomial modulus. If the multi-hot code length is greater than the degree of the polynomial modulus, a multi-hot code RLWE plaintext list is generated.
[0082] (Matrix) In addition to depending on whether the multi-hot code length is greater than the degree of the polynomial modulus, it also depends on whether the value payload size is greater than the capacity of each RLWE slot. If the multi-hot code length is greater than the degree of the polynomial modulus and the value payload size is greater than the capacity of each RLWE slot, then a value payload RLWE plaintext matrix is generated.
[0083] Embodiment 2
[0084] Methods for reshaping the database organization include:
[0085] Determine all the values in the database, generate a value set of size M, and use RLWE homomorphic encryption technology to plaintext encode the payload of the values in the value set to generate a value list of the corresponding size;
[0086] Scan the database, extract all unique values, and build a list of values in order. The contents of the list of values are the plaintext-encoded value payload of each value.
[0087] Generate a multi-hot code of length M for each keyword in the database. If the keyword is associated with a value, the corresponding position of the multi-hot code is set to 1, otherwise it is set to 0; for example, if keyword A is associated with value 1 and value 3, the multi-hot code of keyword A is [1,0,1,0,…].
[0088] Each keyword and its corresponding multi-hot code are reorganized into a keyword-multi-hot code database; the many-to-many relationship is simplified into a one-to-one mapping, and each keyword is associated with a unique multi-hot code.
[0089] The method for calculating and outputting the result includes: performing homomorphic multiplication operation on the final multi-hot code ciphertext and the value list, and calculating the inner product of the multi-hot code and the value (load) list. If a position of the multi-hot code is 1, the value of the corresponding position in the value list is retained; if it is 0, the value of the position is ignored. That is, the multi-hot code and the load are operated, and the load is finally returned.
[0090] When the length of a multi-hot code (i.e., the size M of the set of all values in the database) exceeds the number of slots of a single RLWE plaintext / ciphertext (the degree of the polynomial modulus), multiple RLWE plaintexts / ciphertexts are required to accommodate it. For example, when the degree of the polynomial modulus is 8196 and M=16384, two RLWE plaintexts / ciphertexts are required to encode / encrypt these multi-hot codes, and so on. At this time, a multi-hot code requires multiple RLWE plaintexts / ciphertexts to encode / encrypt, which is equivalent to one keyword corresponding to a multi-hot code RLWE plaintext / ciphertext list, assuming that the length of the list is x.
[0091] Encode the value payload as a matrix, where each column corresponds to the payload of the value of the RLWE polynomial modulus, the number of columns in the matrix is equal to the number of values in the value list divided by the degree of the polynomial modulus and rounded up, and the number of rows in the matrix is equal to the size of the value payload divided by the size of the RLWE slot capacity and rounded up, that is, the number of RLWE plaintext / ciphertext slots required to accommodate the value payload size. For simplicity, assume that the payload size of all values is the same, and the size of the matrix is x×y.
[0092] Finally, the final multi-hot code ciphertext list is used to perform homomorphic multiplication with the value list load matrix. The calculation rule is: perform homomorphic multiplication operations on each ciphertext in the final multi-hot code ciphertext list with each row in the column of the value list load matrix corresponding to the column where the ciphertext is located. That is, a total of x×y homomorphic multiplication operations are performed.
[0093] Embodiment 3
[0094] Encoding and encryption methods include:
[0095] Perform constant weight encoding on all keywords in the keyword-multi-hot code database to obtain encoded keywords; the encoded keywords are binary codes with given Hamming weights;
[0096] The encoded keywords are encoded in plaintext based on RLWE homomorphic encryption technology; RLWE homomorphic encryption allows ciphertext-plaintext and ciphertext-ciphertext homomorphic operations, and the results are all ciphertext.
[0097] Get the encoded keywords - multi-hot code database.
[0098] The search and matching methods include:
[0099] The search keyword is encoded with constant weight to generate a binary code. The encoding length of the constant weight encoding is equal to the encoding length of the keyword encoding.
[0100] The encoded search keywords are encrypted based on the RLWE homomorphic encryption technology; at this time, the RLWE ciphertext of the search keywords is used for subsequent operations to maintain the privacy of the search keywords and prevent them from being leaked.
[0101] The RLWE ciphertext corresponding to the search keyword is sequentially subjected to homomorphic equality operations with the RLWE plaintext corresponding to all the encoding keywords in the database to generate multiple selected ciphertexts. The number of selected ciphertexts is equal to the number of encoding keywords, and the order positions are consistent.
[0102] If the search keyword matches the encoding keyword, a ciphertext of all 1s is generated, otherwise a ciphertext of all 0s is generated; that is, the number of ciphertexts generated will be the same as the number of encoding keywords, and the server cannot directly view the ciphertext vector content, and the matching result exists entirely in ciphertext form.
[0103] Perform homomorphic multiplication operations on multiple selected ciphertexts and the multi-hot codes that map the values corresponding to all the encoded keywords in turn. If the selected ciphertext is an all-1 vector, the result of the homomorphic multiplication operation with the multi-hot code is the multi-hot code, and the search content of the keyword is retained. If the selected ciphertext is an all-0 vector, the result of the homomorphic multiplication operation with the multi-hot code is all 0, which is considered to exclude the keyword. And all the results are homomorphically summed to obtain the intermediate multi-hot code ciphertext. This process can be regarded as the process of homomorphically calculating the inner product of the selected ciphertext and the multi-hot code.
[0104] Embodiment 4
[0105] This embodiment performs Boolean logic operations on the intermediate multi-hot code ciphertexts to integrate the search results of multiple search keywords to generate a multi-hot code that finally meets the Boolean logic conditions. The logic operation processing method includes:
[0106] Multiple intermediate multi-hot ciphertexts are obtained through multiple search keywords; each search keyword generates an intermediate multi-hot ciphertext, which indicates the matching status of the keyword in the database.
[0107] Determine the Boolean logic relationship between multiple search keywords; Boolean logic operations include AND operation, OR operation and NOT operation; NOT operation is a logic operation that can be performed on a single keyword, and AND and OR operations require more than two keywords, and the basic operators of RLWE homomorphic operations are used to implement these logic operations.
[0108] Boolean logic operations are performed on multiple intermediate multi-hot ciphertexts according to the Boolean logic relationship between the search keywords to generate final multi-hot ciphertexts.
[0109] The method of performing AND operation on multi-hot ciphertexts is: homomorphically multiply two multi-hot ciphertexts; the result is 1 only when the corresponding bits of the two multi-hot ciphertexts are both 1; otherwise the result is 0.
[0110] The method of performing a negation operation on a multi-hot ciphertext is to perform a minus 1 operation on the multi-hot ciphertext, and then invert the intermediate vector after minus 1 to obtain the final result of the negation operation - replacing 1 in the original multi-hot ciphertext with 0, and replacing 0 with 1.
[0111] The method of performing an OR operation on multi-hot ciphertexts is to first perform a negation operation on both multi-hot ciphertexts, then perform a homomorphic multiplication operation on the two negation results, and then perform a negation operation on the homomorphic multiplication result. If any of the multi-hot ciphertexts is 1 in the corresponding position, the result is 1; otherwise, it is 0.
[0112] The user enters multiple search keywords, such as keyword1 and keyword2, and requires matching records that contain both (AND operation) or any one of them (OR operation);
[0113] In the homomorphic encryption state, the server cannot directly view the retrieval multi-hot code or retrieval results, but can correctly filter the qualified results by selecting ciphertext and logical operations; for unnecessary keywords, related records can be excluded through non-operations.
[0114] Embodiment 5
[0115] A private information retrieval terminal supporting a Boolean retrieval model comprises a memory, a processor and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the private information retrieval method supporting a Boolean retrieval model as described above is implemented.
[0116] The memory can be used to store software programs and modules. The processor executes various functional applications and data processing of the terminal by running the software programs and modules stored in the memory. The memory can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, an execution program required for at least one function, etc.
[0117] The data storage area can store data created according to the use of the terminal, etc. In addition, the memory may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other volatile solid-state storage devices.
[0118] A computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method for retrieving private information supporting a Boolean retrieval model as described above is implemented.
[0119] Without loss of generality, computer readable media may include computer storage media and communication media. Computer storage media include volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information such as computer readable instruction data structures, program modules or other data. Computer storage media include RAM, ROM, EPROM, EEPROM, flash memory or other solid-state storage technology, CD-ROM, DVD or other optical storage, cassettes, magnetic tapes, disk storage or other magnetic storage devices. Of course, those skilled in the art will appreciate that computer storage media are not limited to the above. The above-mentioned system memory and mass storage devices can be collectively referred to as memory.
[0120] A computer program product includes a computer program / instruction, which, when executed by a processor, implements the above-mentioned private information retrieval method supporting the Boolean retrieval model.
[0121] A computer program product includes a computer program or set of instructions for performing specific tasks or implementing specific functions. These programs or instructions are designed to be executed by a processor to implement a series of predefined steps or operations. The program product may be stored in various forms of computer storage media, such as memory, hard disk, solid-state drive, optical disk or other forms of digital storage devices. It may exist in the form of compiled binary code or in the form of scripts or bytecodes that can be executed by an interpreter. The program product uses carefully designed algorithms and logical instructions to enable the processor to process data in a specific order and manner to complete various functions such as data analysis, user interaction, device control, etc.
[0122] In the description of this specification, the description with reference to the terms "one embodiment / method", "some embodiments / methods", "example", "specific example", or "some examples" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment / method or example are included in at least one embodiment / method or example of the present application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment / method or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments / methods or examples in a suitable manner. In addition, those skilled in the art may combine and combine the different embodiments / methods or examples described in this specification and the features of the different embodiments / methods or examples, unless they are contradictory.
[0123] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined as "first" and "second" may explicitly or implicitly include at least one of the features. In the description of this application, the meaning of "plurality" is at least two, such as two, three, etc., unless otherwise clearly and specifically defined.
[0124] It should be understood by those skilled in the art that the above embodiments are only for the purpose of clearly illustrating the present invention, and are not intended to limit the scope of the present invention. For those skilled in the art, other changes or modifications may be made based on the above invention, and these changes or modifications are still within the scope of the present invention.
Claims
1. A privacy information retrieval method supporting a Boolean retrieval model, characterized in that: include: Database format determination: determine whether the database is a keyword-multi-hot code database. If not, reshape the many-to-many database into a keyword-multi-hot code database. Encoding and encryption: Encode the keyword-multi-hot code database through constant weight encoding and RLWE homomorphic encryption technology; encrypt the query keywords through constant weight encoding and RLWE homomorphic encryption technology; Retrieval and matching: Perform homomorphic equality operations on the RLWE ciphertext corresponding to the search keyword and the RLWE plaintext corresponding to multiple keywords in the database to generate multiple selected ciphertexts; determine the intermediate multi-hot code ciphertext corresponding to the search keyword based on the selected ciphertext; Logical operation processing, performing corresponding Boolean logic operations on multiple intermediate multi-hot ciphertexts according to the Boolean operation logic between multiple search keywords to generate final multi-hot ciphertexts; If it is a single search keyword and no logical operation needs to be performed, the corresponding intermediate multi-hot ciphertext is used as the final multi-hot ciphertext; The result is calculated and output. The final multi-hot code ciphertext is homomorphically multiplied with the value list, and the value of the position of 1 in the multi-hot code corresponding to the position in the value list is obtained. The parsed output is the search result.
2. According to claim 1, a privacy information retrieval method supporting a Boolean retrieval model is characterized in that: Methods for reshaping the database organization include: Determine all the values in the database, generate a value set of size M, and use RLWE homomorphic encryption technology to plaintext encode the payload of the values in the value set to generate a value list of the corresponding size; Generate a multi-hot code of length M for each keyword in the database. If the keyword is associated with a value, the corresponding position of the multi-hot code is set to 1, otherwise it is set to 0; reorganizing each keyword and its corresponding multi-hot code into a keyword-multi-hot code database; The method for calculating and outputting the result includes: performing homomorphic multiplication operation on the final multi-hot code ciphertext and the value list, obtaining the value at position 1 in the value list, and parsing and outputting it as the search result.
3. According to claim 1, a privacy information retrieval method supporting a Boolean retrieval model is characterized in that: Encoding and encryption methods include: Perform constant weight encoding on all keywords in the keyword-multi-hot code database to obtain encoded keywords; The encoded keywords are plaintext-encoded based on the RLWE homomorphic encryption technology; and the encoded keyword-multi-hot code database is obtained. Multiple search keywords are encoded through constant weight encoding, and the encoded search keywords are encrypted based on RLWE homomorphic encryption technology.
4. According to the privacy information retrieval method supporting Boolean retrieval model as claimed in claim 1, it is characterized in that: The search and matching methods include: The search keywords are encoded with constant weight, and the encoded search keywords are ciphertext-encoded based on the RLWE homomorphic encryption technology; Perform homomorphic equality operations on the ciphertext corresponding to the search keyword and the plaintext corresponding to all the encoding keywords in the database in turn to generate multiple selected ciphertexts; if the search keyword matches the encoding keyword, an all-1 ciphertext is generated, otherwise an all-0 ciphertext is generated; The multi-hot ciphertexts are mapped to the values corresponding to all the encoding keywords in turn by multi-hot homomorphic multiplication operations, and all the results are homomorphically summed to obtain the intermediate multi-hot ciphertexts.
5. The method for private information retrieval supporting a Boolean retrieval model according to claim 1, characterized in that: The methods of logical operation processing include: Obtain multiple intermediate multi-hot code ciphertexts through multiple search keywords; Determine the Boolean logic relationship between multiple search keywords; Boolean logic operations are performed on multiple intermediate multi-hot ciphertexts according to the Boolean logic relationship between the search keywords to generate final multi-hot ciphertexts.
6. A privacy information retrieval method supporting a Boolean retrieval model according to claim 5, characterized in that: Basic Boolean logic operations include AND, OR, and NOT; The method of performing AND operation on multi-hot ciphertexts is as follows: homomorphically multiply two multi-hot ciphertexts; The method of performing negation operation on the multi-hot ciphertext is: perform -1 operation on the multi-hot ciphertext, and then negate the intermediate vector after -1; The method of performing an OR operation on multi-hot ciphertexts is: firstly perform a negation operation on both multi-hot ciphertexts, then perform a homomorphic multiplication operation on the two negation operation results, and then perform a negation operation on the homomorphic multiplication operation result.
7. The method for retrieving private information supporting a Boolean retrieval model according to claim 2, characterized in that: Each RLWE plaintext / RLWE ciphertext unit contains multiple slots, and the number of slots is equal to the degree of the RLWE polynomial modulus; the capacity of each slot is based on the parameter setting of RLWE homomorphic encryption; When the length of the multi-hot code exceeds the degree of the polynomial modulus in a single RLWE plaintext / RLWE ciphertext unit, multi-hot encoding is performed: the ratio of the multi-hot code length to the degree of the polynomial modulus is calculated and rounded up to determine the required number of RLWE plaintext units x; The multi-hot code is plaintext encoded using x RLWE plaintext units; When the payload size of the value exceeds the slot capacity of a single RLWE plaintext / RLWE ciphertext unit, the payload of the value is encoded: the ratio of the payload size of the value to the slot capacity is calculated and rounded up to determine the number of RLWE plaintext units y required; Encode the value payload in plain text using y RLWE plain text units; Finally, the value payload is encoded as a matrix of x×y RLWE plaintext units.
8. A private information retrieval terminal supporting a Boolean retrieval model, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the private information retrieval method supporting the Boolean retrieval model as described in any one of claims 1 to 7 is implemented.
9. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method for retrieving private information supporting a Boolean retrieval model according to any one of claims 1 to 7 is implemented.
10. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instruction is executed by a processor, the method for private information retrieval supporting a Boolean retrieval model as described in any one of claims 1 to 7 is implemented.
Citation Information
Cited By
Ciphertext retrieval method and system based on homomorphic encryption
CN121009583A
Communication method and device based on privacy protection
CN121125054A