Multi-user dynamic symmetric searchable encryption method with forward and backward security

By introducing symmetric puncture encryption and trusted proxy servers in multi-user dynamic symmetric searchable encryption, the index linked list structure is expanded, and the problem of neglecting backward privacy security in the prior art is solved, and forward and backward security is achieved.

CN120034388APending Publication Date: 2025-05-23HUAIYIN INSTITUTE OF TECHNOLOGY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510211652.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-25
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

The prior art ignores backward privacy security when implementing multi-user forward security dynamic symmetric searchable encryption, resulting in cloud servers that may disclose all query information related to deleted matches and keywords when searching for queries.

Method used

By introducing symmetric punctureable encryption (SPE) technology, SPE is used to encrypt the document index matching with keywords, and the updated index link list is expanded to add index link lists, delete index link lists and cache index link lists. Combined with trusted proxy servers and state link structures, forward and backward secure multi-user dynamic searchable.

Benefits of technology

It realizes the ability to ensure backward security while meeting forward security, prevents cloud servers from leaking deleted indexes and keyword-related query information, and enhances data privacy protection capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034388A_ABST
    Figure CN120034388A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of symmetric encryption, and discloses a forward and backward security multi-user dynamic symmetric searchable encryption method, which combines a trusted proxy server, a state chain and symmetric puncturable encryption. A trusted proxy server is introduced to generate keyword state information, update a keyword key, generate an encryption index and perform access control on a user; a state chain structure is adopted, index information matched with keywords is stored in a chain, and when search query is executed, the next state cannot be obtained from the current state to achieve forward security; a key is generated for each keyword to encrypt a document index matched with the keyword, the encrypted indexes are respectively stored in an index adding linked list, an index deleting linked list and a cache index linked list, and when the cloud server executes search query every time, the proxy server needs to send the keyword key to the cloud server to execute search operation. And the cloud server ensures that the deleted index does not appear in the search result by utilizing the characteristics of the puncture key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of symmetric encryption, and in particular to a forward-and-backward secure multi-user dynamic symmetric searchable encryption method. Background Art

[0002] Dynamic Symmetric Searchable Encryption (DSSE) combines the characteristics of dynamic searchable encryption and symmetric searchable encryption. Under the symmetric key architecture, it allows data to be dynamically changed (such as inserted, deleted, and modified), maintains the encryption state of the data, and can effectively search the encrypted data.

[0003] Symmetric Puncturable Encryption (SPE) is a symmetric version of puncturable encryption. It introduces the concept of "puncture" based on symmetric encryption technology. Puncturing the encryption key can change the encrypted result in a predefined way for certain specific inputs.

[0004] Incremental Puncture: The punctured key usually grows (or becomes very large) as the number of punctures increases, and it is impractical to store it on the client. n =(sk 0 ,sk 1 ,…,sk n ), the puncture algorithm is as follows: (sk′ 0 ,sk n+1 )=IncPuncture(sk 0 ,t), Puncture(SK n ,t)=(sk′ 0 ,sk 1 ,…,sk n ,sk n+1 ). By using this incremental puncture method, the client only needs to store the key sk 0 part, outsourcing the rest to the server, and the client's storage will remain linear in the number of keywords.

[0005] Forward security (i.e., forward privacy security) and backward security (i.e., backward privacy security) are two important properties of DSSE. In 2018, Wang et al. proposed a multi-user forward-secure DSSE scheme. The index structure of the scheme satisfies forward security. At the same time, by introducing a semi-trusted proxy server to manage keyword information and user access control permissions, it generates search tokens instead of data owners, thus realizing multi-user dynamic searchable encryption. In 2020, Lu et al. improved the DSSE scheme. Lu et al., namely Lu Bingjie, Zhou Jun, Cao Zhenfu. An Enhanced Multi-User Forward-Secure Dynamic Symmetric Searchable Encryption Scheme [J]. Journal of Computer Research and Development, 2020, 57(10): 2104-2116. Since Wang et al.'s scheme uses a semi-trusted proxy server, the data owner has to leak some information in order to achieve the purpose of hosting keyword information. In essence, it transfers part of the leakage to the proxy server, which violates the forward-secure property. For this reason, Lu et al. selected an honest and trustworthy proxy server to maintain keyword information and gave the proxy server full authority to generate keyword status. In addition, Lu et al. optimized the index structure by using a state chain to store the document identifiers matched by each keyword w in the chain. When a user wants to search for a keyword, he sends the last state st to the cloud server. c+1 , cloud server from st c+1 Traverse the state chain backwards to get all previous states st c ,st c-1 ,…,st 1 , but the cloud server cannot be c+1 Get the next state st c+2 , thus achieving forward security. Finally, Lu et al. proposed a multi-user forward-secure dynamic searchable encryption scheme by introducing a trusted proxy server and an improved state chain structure.

[0006] However, Lu et al.'s solution only focuses on forward privacy security and ignores backward privacy security. When the cloud server performs a search query on a keyword, the deleted matches will still be leaked, and the cloud server can learn the update information that affects the keyword. This type of solution may leak the deleted index and all queries related to the keyword because the cloud server can track all updated document indexes. Summary of the invention

[0007] Purpose of the invention: In view of the problems existing in the prior art, the present invention provides a forward and backward secure multi-user dynamic symmetric searchable encryption method, which uses SPE technology to encrypt the document index of keyword matching and expands the original update index linked list into an add index linked list EDB. add , delete the index list EDB del And cache index list EDBchache , combining trusted proxy servers, state chains, and symmetric pierceable encryption, while achieving forward-secure and backward-secure multi-user dynamic searchability.

[0008] Technical solution: The present invention provides a forward and backward secure multi-user dynamic symmetric searchable encryption method, including a parameter setting module, a document adding module, a document deleting module, a user registration module, a keyword searching module, and a user decryption module, and specifically performs the following steps:

[0009] Step 1: Parameter setting module, the data owner outputs the public parameter PP, the data owner's private key SK, the document encryption database EDB, the keyword search frequency table SC, and the document index set EDB add , delete the document puncture collection EDB del , Search result cache collection EDB cache , master key set MSK and local key sharing set PSK for puncture, keyword state table W add and W del , the data owner secretly holds the private key SK, discloses the public parameter PP, and converts EDB, EDB cache 、EDB add 、EDB del Send to the cloud server, SC, MSK, PSK, W add and W del Send to the proxy server;

[0010] Step 2: Document adding module, input document f, the data owner adds the document, encrypts document f and uploads it to the cloud server document encryption database EDB; the data owner sends the document information to be added to the proxy server, for each keyword w contained in the document, the proxy server calculates its puncture mark t, the proxy server queries the search count i of keyword w from SC, the proxy server sends the update information corresponding to the keyword, that is, the document identifier / puncture mark pair (ind, t), to the cloud server, and the cloud server inserts the added information into EDB add [w||i], w||i represents the keyword status from the last search operation for keyword w to the current search operation;

[0011] Step 3: Document deletion module, input document f, the data owner deletes the document and sends the document information to the proxy server. For each keyword w contained in the document, the proxy server calculates its puncture mark t. The proxy server queries the search count i of keyword w from SC and generates the key puncture share psk corresponding to the document and keyword w. The proxy server sends the keyword corresponding update information puncture key share / puncture mark pair (psk t,t) is sent to the cloud server, which inserts the deletion information into EDB del [w||i];

[0012] Step 4: User registration module, for user u, the data owner generates a unique identifier uid and user private key SK u , S.K. u Saved by the user, the data owner sends part of the user information to the proxy server and saves it to the user table Ucqt and the cloud server and saves it to the user table Ucdt;

[0013] Step 5: Keyword search module: Enter the search keyword w, the user sends a search request for keyword w to the proxy server, the proxy server verifies the user information based on Ucqt, the proxy server obtains the search count i of keyword w from SC, generates a search token of w||i and sends it to the cloud server; the cloud server queries the set EDB add Get the document identifier / tag pair for keyword w||i and query the EDB set del Get the puncture key sharing / marking pair of w||i and puncture the key, query the cache set EDB cache Get the last search result of keyword w; the cloud server uses the characteristics of the puncture key to remove the deleted documents contained in the search results, obtain the matching document identifier of keyword w, search the corresponding ciphertext in EDB and calculate the decryption key according to the user verification information in the user table Ucdt, and finally store the ciphertext / key pair in the search result Rst and send it to the search user. Finally, the proxy server updates the keyword search count SC[w]=i+1 and regenerates the key for keyword w;

[0014] Step 6: User decrypts the module, inputs Rst, and uses the private key SK u Decrypt the ciphertext in Rst to get the final search result.

[0015] Furthermore, in step 1, the specific execution process is as follows:

[0016] Step 1.1: Given a key space K 1 , domain X and range Y, based on the piercing pseudorandom function F 1 :K 1 ×X→Y, execute algorithm KeyGen(1 λ ), given the security parameter λ, from the key space K 1 Randomly select a sk 0 , output master key msk = sk 0 ;

[0017] Given a key space K 2, domain M and range C, pseudo-random permutation F based on pseudo-random function 2 :K 2 ×M→C and :K 2 ×C→M∪{⊥}, execute algorithm Gen(1 λ ), given the security parameter λ, output k∈K 2 ;

[0018] Step 1.2: Input security parameter λ, the data owner randomly selects a large prime number p, and randomly selects K s ,K t ∈{0,1} λ , from Z p * Select a random number ek from the given bilinear map g 1 and g 2 G 1 and G 2 The generator of the pseudo-random permutation function R 1 and R 2 , Hash function H 1 , H 2 , H 3 , the data owner runs the algorithm Gen(1 λ ) Generate a pseudo-random permutation R 1 The key K G , the data owner initializes the document encryption database EDB and the search result cache collection EDB cache , keyword search times table SC, add document index collection EDB add , delete the document puncture collection EDB del , master key set MSK, puncture key sharing set PSK and keyword state table W add and W del ; EDB, EDB cache 、EDB add and EDB del Send to the cloud server, SC, MSK, PSK, W add and W del Sent to the proxy server, the data owner saves the private key SK=(ek,K s ,K t ,K G ) and transmit K G Sent to the proxy server for secret storage, and the data owner publishes public parameters

[0019] Furthermore, in step 2, when adding a document, the specific process is as follows:

[0020] Step 2.1: Input a document f, document identifier ind f , all keywords W(f) contained in the document, the data owner from G 1 Randomly select r f , calculate the document encryption key Use the AES encryption algorithm to encrypt the document to obtain the ciphertext C f =AES.Encrypt(ek f ,f), the data owner will ciphertext (C f ,r f ) is sent to the cloud server and stored in EDB;

[0021] Step 2.2: The data owner performs an add operation on the document, i.e., op = add. For each keyword w∈W(f), the data owner uses a pseudo-random function F:{0,1} λ ×{0,1} m →{0,1} n Calculate the keyword identifier tkn=F(K s ,w) and keyword puncture tags F(K t ,(w,ind)), obtain the keyword master key msk←MSK[tkn] from the master key set, and use the symmetric piercing encryption algorithm SPE to encrypt the document identifier ct=SPE.Enc(msk,ind,t); the data owner queries the keyword search count i←SC[tkn] and initializes a set Γ upd , will upd w =R 1 (K G ,tkn||i||(ct,t)||op) inserts into the set Γ upd Finally, the data owner will upd Send to the proxy server;

[0022] Step 2.3: The proxy server receives the set Γ upd Then for each upd w ∈Γ upd By permutation algorithm R 1 -1 get Where op = add; the proxy server queries the keyword status table (st c ,c)←W add [tkn||i], where st c Indicates the keyword status, c indicates the number of keyword updates; the proxy server generates a new status word st for the keyword c+1 ←{0,1} λ , initialize a set Γadd , calculate u=H 1 (tkn||i,st c+1 ), Γ add ←(u,e); Finally, the proxy server will set Γ add Send to the cloud server and update the keyword status table W add [tkn||i]←(st c+1 ,c+1);

[0023] Step 2.4: The cloud server receives the set Γ add Then add the information according to the keyword and store it in the state chain to add the document index collection EDB add For every pair (u,e)∈Γ add Execute Operation EDB add [u] = e.

[0024] Furthermore, the document deletion module in step 3 specifically performs the following steps:

[0025] Step 3.1: If the document is deleted, that is, op = del, for each keyword w∈W(f) contained in the document, the data owner calculates the puncture label t = F Kt (w, ind), query the local key sharing set msk′←PSK[tkn] for puncture, and use the symmetric puncturable encryption algorithm SPE to puncture msk′ (msk″, psk t )←SPE.IncPun(msk′,t) to get the puncture key share psk t and the new local key share msk″, update the local puncture key share PSK[w]←msk″, and the data owner initializes a set Γ upd , will update w =R 1 (K G ,tkn||i||(psk t ,t)||op) insert into set Γ upd , finally, the data owner will upd Send to the proxy server;

[0026] Step 3.2: The proxy server receives the set Γ upd Then for each upd w ∈Γ upd , through the permutation algorithm R 1 -1 get The proxy server queries the keyword status table to obtain (st c ,c)←W del[tkn||i], and generate a new status word st for the keyword c+1 ←{0,1} λ , the proxy server initializes a set Γ del , u=H 1 (tkn||i||st c+1 ), Γ del ←(u,e), finally, the proxy server will set Γ del Send to the cloud server and update the keyword status table W del [tkn||i]←(st c+1 ,c+1);

[0027] Step 3.3: The cloud server receives the set Γ del Then the deletion information will be stored in the state chain according to the keyword to delete the document puncture collection EDB del For every pair (u,e)∈Γ del Execute Operation EDB del [u] = e.

[0028] Furthermore, in step 4, the data owner generates a unique identifier uid∈{0,1} for each user. λ , the data owner runs the algorithm Gen(1 λ ) Generate a pseudo-random permutation R 2 The key qk u ,from Randomly select dk u As the decryption key, calculate the auxiliary decryption key Generate user search counter s=0, proxy server saves (uid,qk u ,s), cloud server saves (uid,dk c ), the user saves SK u =(uid,qk u ,dk u ,K s ,s).

[0029] Furthermore, in step 5, the keyword search module performs the following steps:

[0030] Step 5.1: Enter the query keyword w, and the user uses the private key SK u =(uid,qk u ,dk u ,K s ,s) calculate the keyword identifier tkn = F(K s ,w), user search times s = s + 1, generate query request τ u =R 2(qk u ,tkn||s), the user sends uid and query request τ u Send to the proxy server;

[0031] Step 5.2: The proxy server receives the user uid and query request τ u After that, the proxy server queries the user information table to obtain the user search key and query counter (qk u ,s c )←Ucqt[uid], where qk u Search key for user, s c To query the counter; the proxy server uses a replacement algorithm Get keyword information The proxy server queries the search count i←SC[tkn] of keyword w and the local key share msk′←PSK[tkn], and queries the keyword status in and c add They respectively represent the latest status of keyword addition and update before this query. and c del They represent the latest status of keyword deletion and update before this query respectively; the proxy server generates a search token τ w ←(tkn||i,st cadd ,c add ,st cdel ,c del ,msk′),(uid,τ w ) is sent to the cloud server, and the proxy server uses the key generation algorithm KeyGen(1 λ ) Regenerate the master key msk of keyword w and update the user information and status information of keyword w as follows:

[0032] Ucqt[uid]←(qk u ,s c +1), MSK[tkn]←msk, PSK[tkn]←msk, SC[tkn]←i+1, W add [tkn||i+1]←(st c =⊥,c=0),W del [tkn||i+1]←(st c =⊥,c=0)

[0033] Step 5.3: The cloud server receives the uid and search token τ w After that, four sets NewR, OldR, IND and Rst are initialized, and the cloud server obtains the query information (tkn||i,st cadd ,c add ,stcdel ,c del ,msk′)←τ w , respectively in EDB add and EDB del Query the matching information of tkn||i and query EDB cache Get the last search results for the keyword tkn, the cloud server is used in EDB del The query result in punctures the key to obtain SK 0 =(msk′,psk 1 ,…,psk m ) and decrypted in EDB add The encrypted document identifier / tag pair (ct, t) matched in the query is obtained, and the decrypted identifier / tag pair (ind, t) is saved in the set NewR; the cloud server queries EDB cache The last search result corresponding to the keyword in the query is stored in the set OldR. The cloud server deletes the last query result OldR and EDB del The overlapping document identifiers in the query results are then merged with NewR and OldR to obtain the final matching document identifier set IND←NewR∪OldR;

[0034] Step 5.4: The cloud server stores the search results in EDB cache [tkn]←IND for use in the next search; the cloud server queries the user table Ucdt based on uid to obtain the auxiliary decryption key dk c ←Ucdt[uid], for each document identifier ind∈IND, the cloud server searches for the corresponding encrypted document (r ind ,C ind ), where r ind , C ind The random number and document ciphertext selected for the encrypted document when the document identifier is ind, and the ciphertext information is calculated The ciphertext information cds ind and ciphertext C ind Insert the final search result set

[0035] Rst←Rst∪(cds ind ,C ind ), and finally the cloud server returns Rst to the user.

[0036] Furthermore, in step 6, after receiving the search result Rst, the user initializes the set File, and for each pair (cds ind ,C ind )∈Rst calculate the decryption key dk ind =H 3 (cdsind dku ), then decrypt the document f ind =AES.Decrypt(dk ind ,Cind), and finally get File = File∪f ind , File is the search result obtained by the end user.

[0037] Beneficial effects:

[0038] 1. The present invention uses SPE technology to achieve backward security while satisfying forward security. The present invention generates a key for each keyword, uses SPE to encrypt the document index matched by the keyword, and expands the original update index linked list to the add index linked list EDB add , delete the index list EDB del And cache index list EDB chache In the update operation, when op=add, the present invention performs the add operation and stores the index information of the added document into the EDB. add When op=del, the delete operation is performed, the corresponding keyword key is punctured, and the key and deleted document index information are stored in EDB del In addition, after each search query, the cloud server stores the search results in EDB chache Each time the cloud server performs a search query, the proxy server sends the keyword key to the cloud server to perform the search operation, and the cloud server queries the EDB add 、EDB del and EDB chache , and uses the characteristics of puncture keys to ensure that deleted indexes do not appear in search results. Once the cloud server has the keyword key, the proxy server can no longer use the key to continue encrypting future updated index information, because the key can be used to decrypt all non-deleted indexes. Therefore, after each search, the proxy server updates the keyword state and generates a new key for it, but the proxy server does not need to re-encrypt the search results with a new key, because the cloud server can track the results of repeated search queries from the access pattern.

[0039] 2. The present invention combines a trusted proxy server, a state chain, and symmetric pierceable encryption to achieve forward-safe and backward-safe dynamic searchability for multiple users: The present invention introduces a trusted proxy server to replace the data owner to generate keyword state information, update keyword keys, generate encryption indexes, and perform access control on users, thereby achieving multi-user. The present invention adopts a state chain structure to store the index information of keyword matching in the chain. When executing a search query, the cloud server searches for the keyword in the search token according to the last state st c+1 , from st c+1Traverse the state chain backwards to get all previous states st c ,st c-1 ,…,st 1 , and the cloud server cannot be c+1 Get the next state st c+2 Thus, forward security is achieved. In addition, the present invention generates a key for each keyword to encrypt the document index matched by the keyword, and stores the encrypted index in the add index chain list, delete index chain list and cache index chain list respectively. Every time the cloud server executes a search query, the proxy server sends the keyword key to the cloud server to perform the search operation, and the cloud server queries the EDB add 、EDB del and EDB chache And use the puncture key feature to ensure that deleted indexes do not appear in search results.

[0040] 3. In actual application scenarios of the present invention, such as the internal file system of a company department, the department manager uploads the encrypted file to the cloud server and dynamically manages the uploading and deletion of the file, and then entrusts the keyword information and user information to the trusted agent. Other authorized members of the department can search the encrypted database based on keywords without the need for the department manager to be online all the time. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] Figure 1 It is a schematic diagram of the entity of the present invention;

[0042] Figure 2 It is a schematic diagram of the working of the module of the present invention;

[0043] Figure 3 Add index update and search diagram for the present invention document. DETAILED DESCRIPTION

[0044] The present invention will be further described below in conjunction with the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solution of the present invention, and cannot be used to limit the protection scope of the present invention.

[0045] The present invention discloses a forward and backward secure multi-user dynamic symmetric searchable encryption method, comprising the following steps:

[0046] like Figure 1 As shown, the present invention mainly includes four entities:

[0047] ① Data owner: The data owner is responsible for parameter setting, document encryption, adding and deleting documents, generating puncture key sharing and puncture tags, and managing user registration and revocation.

[0048] ②Proxy server: The proxy server is responsible for user access control, generating encrypted indexes and search tokens, and regenerating keys for keyword w. The proxy server verifies whether the search request sent by the user is valid through the locally stored user table Ucqt. According to the update information sent by the data owner, for each keyword w, the encrypted index is stored in the added set Γ when adding a document add , when deleting a document, store the encrypted index in the deletion set Γ del , and sent to the cloud server. After the search token is sent, the proxy server updates the keyword status and regenerates the key for the keyword.

[0049] ③Data users: Data users can search for keyword w and decrypt the search results returned by the cloud server.

[0050] ④ Cloud server: The cloud server is responsible for storing and searching encrypted documents and encrypted indexes. When searching for keywords, it searches the encrypted indexes and encrypted documents based on the search token sent by the proxy server, and then generates a decryption key for the user and sends the encrypted document and key to the user.

[0051] (1) Parameter setting module: input security parameter λ, data owner outputs public parameter PP, data owner's private key SK, document encryption database EDB, keyword search frequency table SC, add document index set EDB add , delete the document puncture collection EDB del , Search result cache collection EDB cache , master key set MSK and local key sharing set PSK for puncture, keyword state table W add and W del The data owner secretly holds the private key SK, discloses the public parameter PP, and converts EDB and EDB cache 、EDB add 、EDB del Send to the cloud server, SC, MSK, PSK, W add and W del Sent to the proxy server.

[0052] Step 1.1: Given a key space K 1 , domain X and range Y, based on the piercing pseudorandom function F 1 :K 1 ×X→Y, execute algorithm KeyGen(1 λ ), given the security parameter λ, from the key space K 1 Randomly select a sk 0 , output master key msk = sk 0 .

[0053] Given a key space K2 , domain M and range C, pseudo-random permutation F based on pseudo-random function 2 :K 2 ×M→C and Execution algorithm Gen(1 λ ), given the security parameter λ, output k∈K 2 .

[0054] Step 1.2: Input security parameter λ, the data owner randomly selects a large prime number p, and randomly selects K s ,K t ∈{0,1} λ , from Z p * Select a random number ek from the given bilinear map g 1 and g 2 G 1 and G 2 The generator of the pseudo-random permutation function R 1 and R 2 , Hash function H 1 , H 2 , H 3 The data owner runs the algorithm Gen(1 λ ) Generate a pseudo-random permutation R 1 The key K G The data owner initializes the document encryption database EDB and the search result cache collection EDB cache , keyword search times table SC, add document index collection EDB add , delete the document puncture collection EDB del , master key set MSK, puncture key sharing set PSK and keyword state table W add and W del . EDB, EDB cache 、EDB add 、EDB del Send to the cloud server, SC, MSK, PSK, W add and W del The data owner saves the private key SK=(ek,K s ,K t ,K G ) and transmit K G Sent to the proxy server for secret storage, and the data owner publishes public parameters

[0055] (2) Document adding module: input document f, the data owner adds the document, encrypts document f and uploads it to the cloud server encrypted database EDB. The data owner sends the document information to be added to the proxy server. For each keyword w contained in the document, the proxy server calculates its puncture mark t. The proxy server queries the search count i of keyword w from SC, where w||i represents the keyword status from the last search operation for keyword w to the current search operation. The proxy server sends the update information corresponding to the keyword, i.e., the document identifier / puncture mark pair (ind, t), to the cloud server, and the cloud server inserts the added information into EDB. add [w||i].

[0056] Step 2.1: Input a document f, document identifier ind f , all keywords W(f) contained in the document, the data owner from G 1 Randomly select r f , calculate the document encryption key Use the AES encryption algorithm to encrypt the document to obtain the ciphertext C f =AES.Encrypt(ek f ,f). The data owner will ciphertext (C f ,r f ) is sent to the cloud server and stored in EDB.

[0057] Step 2.2: The data owner performs an add operation on the document, op = add. For each keyword w∈W(f), the data owner uses a pseudo-random function F:{0,1} λ ×{0,1} m →{0,1} n Calculate the keyword identifier tkn=F(K s ,w), calculate the puncture label of the keyword F(K t ,(w,ind)), obtain the keyword master key msk←MSK[tkn] from the key table, and use the symmetric piercing encryption (SPE) algorithm to encrypt the document identifier ct=SPE.Enc(msk,ind,t). The data owner queries the keyword search count i←SC[tkn] and initializes a set Γ upd , will update w =R 1 (K G ,tkn||i||(ct,t)||op) inserts into the set Γ upd Finally, the data owner will upd Sent to the proxy server.

[0058] Step 2.3: The proxy server receives the set Γupd Then for each upd w ∈Γ upd By permutation algorithm R 1 -1 get Where op = add. The proxy server queries the keyword status table (st c ,c)←W add [tkn||i], where st c Indicates the keyword status, c indicates the number of keyword updates. And generates a new status word st for the keyword c+1 ←{0,1} λ , initialize a set Γ add , calculate u=H 1 (tkn||i,st c+1 ), Γ add ←(u,e). Finally, the proxy server sets Γ add Send to the cloud server and update the keyword status table W add [tkn||i]←(st c+1 ,c+1).

[0059] Step 2.4: The cloud server receives the set Γ add Then, the added information is stored in the state chain EDB according to the keyword add For every pair (u,e)∈Γ add Execute Operation EDB add [u] = e.

[0060] (3) Document deletion module: input document f, the data owner deletes the document and sends the document information to the proxy server. For each keyword w contained in the document, the proxy server calculates its puncture mark t, queries the search count i of keyword w from SC, generates the key puncture share psk corresponding to the document and keyword w, and sends the keyword update information puncture key share / puncture mark pair (psk t ,t) is sent to the cloud server, which inserts the deletion information into EDB del [w||i].

[0061] Step 3.1: If the document is deleted, op = del, for each keyword w∈W(f) contained in the document, the data owner calculates the puncture label t = F Kt (w, ind), query the local puncture key share msk′←PSK[tkn], and use the symmetric puncturable encryption (SPE) algorithm to puncture msk′ (msk″, psk t)←SPE.IncPun(msk′,t) to get the puncture key share psk t and the new local key share msk″, update the local puncture key share PSK[w]←msk″. The data owner initializes a set Γ upd , will update w =R 1 (K G ,tkn||i||(psk t ,t)||op) insert into set Γ upd Finally, the data owner will upd Sent to the proxy server.

[0062] Step 3.2: The proxy server receives the set Γ upd Then for each upd w ∈Γ upd , through the permutation algorithm R 1 -1 get Where op = del. The proxy server queries the keyword status table to obtain (st c ,c)←W del [tkn||i], and generate a new status word st for the keyword c+1 ←{0,1} λ The proxy server initializes a set Γ del , u=H 1 (tkn||i||st c+1 ), Γ del ←(u,e). Finally, the proxy server sets Γ del Send to the cloud server and update the keyword status table W del [tkn||i]←(st c+1 ,c+1).

[0063] Step 3.3: The cloud server receives the set Γ del Then the deletion information will be stored in the state chain EDB according to the keyword del For every pair (u,e)∈Γ del Execute Operation EDB del [u] = e.

[0064] (4) User registration module: For user u, the data owner generates a unique identifier uid and a user private key SK u , S.K. u Saved by the user, the data owner sends part of the user information to the proxy server to save to Ucqt and the cloud server to save to Ucdt.

[0065] The data owner generates a unique identifier uid∈{0,1} for each user λ The data owner runs the algorithm Gen(1 λ ) Generate a pseudo-random permutation R 2 The key qk u ,from Randomly select dk u As the decryption key, calculate the auxiliary decryption key Generate user search counter s = 0. The proxy server saves (uid, qk u ,s), cloud server saves (uid,dk c ), the user saves SK u =(uid,qk u ,dk u ,K s ,s).

[0066] (5) Keyword search module: Enter the search keyword w. The user sends a search request for keyword w to the proxy server, and the proxy server verifies the user information based on Ucqt. The proxy server obtains the search count i of keyword w from SC, generates a search token of w||i and sends it to the cloud server. The cloud server queries the EDB set add Get the document identifier / tag pair for keyword w||i and query the EDB set del Get the puncture key sharing / marking pair of w||i and puncture the key, query the cache set EDB cache Get the last search result of keyword w. The cloud server uses the characteristics of the puncture key to remove the deleted documents contained in the search results, obtain the matching document identifier of keyword w, search the corresponding ciphertext in EDB and calculate the decryption key based on the user verification information in the user table Ucdt, and finally store the ciphertext / key pair in the search result Rst and send it to the search user. Finally, the proxy server updates the keyword search count SC[w]=i+1 and regenerates the key for keyword w. There is no need to re-encrypt the search results with a new key because the cloud server can track them from the access pattern.

[0067] Step 5.1: Enter the query keyword w, and the user uses the private key SK u =(uid,qk u ,dk u ,K s ,s) calculate the keyword identifier tkn = F(K s ,w), user search times s = s + 1, generate query request τ u =R 2 (qk u ,tkn||s), the user sends uid and query request τ uSent to the proxy server.

[0068] Step 5.2: The proxy server receives the user uid and query request τ u After that, the proxy server queries the user table to obtain the user search key and query counter (qk u ,s c )←Ucqt[uid], where qk u Search key for user, s c To query the counter. The proxy server uses a permutation algorithm Get keyword information The proxy server queries the search count i←SC[tkn] of keyword w and the local key share msk′←PSK[tkn], and queries the keyword status (st cadd ,c add )←W add [tkn],(st cdel ,c del )←W del [tkn]. The proxy server generates a search token τ w ←(tkn||i,st cadd ,c add ,st cdel ,c del ,msk′),(uid,τ w ) is sent to the cloud server. The proxy server uses the key generation algorithm KeyGen(1 λ ) regenerates the master key msk of keyword w and updates the user information and the status information of keyword w as follows: Ucqt[uid]←(qk u ,s c +1), MSK[tkn]←msk, PSK[tkn]←msk, SC[tkn]←i+1, W add [tkn||i+1]←(st c =⊥,c=0),W del [tkn||i+1]←(st c =⊥,c=0).

[0069] Step 5.3: The cloud server receives the uid and search token τ w Then, four sets NewR, OldR, IND and Rst are initialized. The cloud server obtains the query information (tkn||i,st cadd ,c add ,st cdel ,c del ,msk′)←τ w , respectively in EDB add and EDB delQuery the matching information of tkn||i and query EDB cache Get the last search results for the keyword tkn. add For example, let c = c add , when st c ≠⊥, calculate u=H 1 (tkn||i||st c ), e=EDB add [u], thus obtaining Repeat the above steps according to st c-1 Get the last matching document identifier (ct c-1 ,t c-1 ), until st c =⊥, get the search results ((ct 1 ,t 1 ),(ct 2 ,t 2 ),…,(ct n ,t n )). Similarly, cloud servers are in EDB del The puncture key share (psk 1 ,t′ 1 ),(psk 2 ,t′ 2 ),…,(psk m ,t′ m )). Cloud server is used in EDB del The query result is punctured to get the key SK 0 =(msk′,psk 1 ,…,psk m ) and decrypted in EDB add The encrypted document identifier / tag pair (ct, t) matched in the query is obtained, and the decrypted identifier / tag pair (ind, t) is saved in the set NewR. The cloud server queries EDB cache The cloud server deletes the last query result OldR and EDB del The overlapping document identifiers in the query results are OldR\{(ind,t): t=t′ i}, then merge NewR and OldR to get the final matching document identifier set IND←NewR∪OldR. The cloud server stores the search results in EDB cache [tkn]←IND for use in the next search. The cloud server queries the user table based on uid to obtain the auxiliary decryption key dk c←Ucdt[uid]. For each ind∈IND, the cloud server searches for the corresponding encrypted document (r ind ,C ind ), where r ind , C ind The random number and document ciphertext selected for the encrypted document when the document identifier is ind, and the ciphertext information is calculated The ciphertext information cds ind and ciphertext C ind Insert the final search result set Rst←Rst∪(cds ind ,C ind ). Finally, the cloud server returns Rst to the user.

[0070] (6) User decryption module: Input Rst, the user uses the private key SK u Decrypt the ciphertext in Rst to get the final search result. After receiving the search result Rst, the user initializes the set File. For each pair (cds ind ,C ind )∈Rst calculate the decryption key dk ind =H 3 (cds ind dku ), then decrypt the document f ind =AES.Decrypt(dk ind ,Cind), and finally get File = File∪f ind . File is the search result obtained by the end user.

[0071] Table 1

[0072]

[0073] As shown in Table 1, compared with the scheme of Lu et al., the implementation of the present invention reduces backward privacy leakage and meets backward security. Compared with the scheme of Sun et al., it is suitable for multi-user environments. Among them, the scheme of Lu et al. is Lu Bingjie, Zhou Jun, Cao Zhenfu. An enhanced multi-user forward-secure dynamic symmetric searchable encryption scheme [J]. Computer Research and Development, 2020, 57(10): 2104-2116. The scheme of Sun et al. is Sun, Shi-Feng; Yuan, Xingliang; Liu, Joseph K.; Steinfeld, Ron; Sakzad, Amin; Vo, Viet; Nepal, Surya. Practical Backward-Secure Searchable Encryption from Symmetric Puncturable Encryption [A]. CCS'18: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security [C], 2018.

[0074] Table 2

[0075]

[0076]

[0077] As shown in Table 2, the length of the keyword state chain of Lu et al. is T wa +T wd , where T wa and T wd They represent the number of additions and deletions of all documents corresponding to keyword w. As the number of added and deleted documents increases, the corresponding status chain list will become longer and longer, and the time required to traverse the status chain when the cloud server queries will be longer. The above implementation method divides the keyword status chain into three parts, among which EDB chache Stores the last search results for a keyword, EDB add 、EDB del The document identifiers of keywords added and deleted after the last search and before the current search are stored separately, which greatly shortens the length of the state chain and allows traversal of EDB at the same time when querying the cloud server add 、EDB del and EDB chache This reduces the time required to query the linked list.

[0078] The above embodiments are only for illustrating the technical concept and features of the present invention, and their purpose is to enable people familiar with the technology to understand the content of the present invention and implement it accordingly, and they cannot be used to limit the protection scope of the present invention. Any equivalent transformation or modification made according to the spirit of the present invention should be included in the protection scope of the present invention.

Claims

1. A forward-and-backward secure multi-user dynamic symmetric searchable encryption method, characterized in that: It includes parameter setting module, document adding module, document deleting module, user registration module, keyword searching module and user decryption module, and specifically performs the following steps: Step 1: Parameter setting module, the data owner outputs the public parameter PP, the data owner's private key SK, the document encryption database EDB, the keyword search frequency table SC, and adds the document index set EDB add , delete the document puncture collection EDB del , Search result cache collection EDB cache , master key set MSK and local key sharing set PSK for puncture, keyword state table W add and W del , the data owner secretly holds the private key SK, discloses the public parameter PP, and converts EDB, EDB cache 、EDB add 、EDB del Send to the cloud server, SC, MSK, PSK, W add and W del Send to the proxy server; Step 2: Document adding module, input document f, the data owner adds the document, encrypts document f and uploads it to the cloud server document encryption database EDB; the data owner sends the document information to be added to the proxy server, for each keyword w contained in the document, the proxy server calculates its puncture mark t, the proxy server queries the search count i of keyword w from SC, the proxy server sends the update information corresponding to the keyword, that is, the document identifier / puncture mark pair (ind, t), to the cloud server, and the cloud server inserts the added information into EDB add [w||i], w||i represents the keyword status from the last search operation for keyword w to the current search operation; Step 3: Document deletion module, input document f, the data owner deletes the document and sends the document information to the proxy server. For each keyword w contained in the document, the proxy server calculates its puncture mark t. The proxy server queries the search count i of keyword w from SC and generates the key puncture share psk corresponding to the document and keyword w. The proxy server sends the keyword corresponding update information puncture key share / puncture mark pair (psk t ,t) is sent to the cloud server, which inserts the deletion information into EDB del [w||i]; Step 4: User registration module, for user u, the data owner generates a unique identifier uid and user private key SK u , S.K. u Saved by the user, the data owner sends part of the user information to the proxy server and saves it to the user table Ucqt and the cloud server and saves it to the user table Ucdt; Step 5: Keyword search module: Enter the search keyword w, the user sends a search request for keyword w to the proxy server, the proxy server verifies the user information according to Ucqt, the proxy server obtains the search count i of keyword w from SC, generates a search token of w||i and sends it to the cloud server; Cloud Server Query Collection EDB add Get the document identifier / tag pair for keyword w||i and query the EDB set del Get the puncture key sharing / marking pair of w||i and puncture the key, query the cache set EDB cache Get the last search result of keyword w; The cloud server uses the characteristics of the puncture key to remove the deleted documents included in the search results, obtains the document identifier that matches the keyword w, searches for the corresponding ciphertext in the EDB and calculates the decryption key based on the user verification information in the user table Ucdt, and finally stores the ciphertext / key pair in the search result Rst and sends it to the search user. Finally, the proxy server updates the keyword search count SC[w]=i+1 and regenerates the key for the keyword w; Step 6: User decrypts the module, inputs Rst, and uses the private key SK u Decrypt the ciphertext in Rst to get the final search result.

2. The forward-backward secure multi-user dynamic symmetric searchable encryption method according to claim 1, characterized in that: In step 1, the specific execution process is as follows: Step 1.1: Given the key space K1, the domain X, and the range Y, execute the algorithm KeyGen(1 λ ), given a security parameter λ, randomly select a sk0 from the key space K1 and output the master key msk=sk0; Given a key space K2, a domain M, and a range C, a pseudo-random permutation F2:K2×M→C based on a pseudo-random function and K2×C→M∪{⊥}, execute algorithm Gen(1 λ ), given the security parameter λ, output k∈K2; Step 1.2: Input security parameter λ, the data owner randomly selects a large prime number p, and randomly selects K s ,K t ∈{0,1} λ , from Z p * Select a random number ek from the given bilinear map G1×G1→G2, g1 and g2 are the generators of G1 and G2 respectively. Given pseudo-random permutation functions R1 and R2, hash functions H1, H2, H3, the data owner runs the algorithm Gen(1 λ ) Generate the key K of pseudo-random permutation R1 G , the data owner initializes the document encryption database EDB and the search result cache collection EDB cache , keyword search times table SC, add document index collection EDB add , delete the document puncture collection EDB del , master key set MSK, puncture key sharing set PSK and keyword state table W add and W del ; EDB, EDB cache 、EDB add and EDB del Send to the cloud server, SC, MSK, PSK, W add and W del Sent to the proxy server, the data owner saves the private key SK=(ek,K s ,K t ,K G ) and transmit K G Sent to the proxy server for secret storage, and the data owner publishes public parameters 3. The forward-backward secure multi-user dynamic symmetric searchable encryption method according to claim 2, characterized in that: In step 2, when adding a document, the specific process is as follows: Step 2.1: Input a document f, document identifier ind f , all keywords W(f) contained in the document, the data owner randomly selects r from G1 f , calculate the document encryption key Use the AES encryption algorithm to encrypt the document to obtain the ciphertext C f =AES.Encrypt(ek f ,f), the data owner will ciphertext (C f ,r f ) is sent to the cloud server and stored in EDB; Step 2.2: The data owner performs an add operation on the document, i.e., op = add. For each keyword w∈W(f), the data owner uses a pseudo-random function F:{0,1} λ ×{0,1} m →{0,1} n Calculate the keyword identifier tkn=F(K s ,w) and keyword puncture tags F(K t ,(w,ind)), obtain the keyword master key msk←MSK[tkn] from the master key set, and use the symmetric piercing encryption algorithm SPE to encrypt the document identifier ct=SPE.Enc(msk,ind,t); the data owner queries the keyword search count i←SC[tkn] and initializes a set Γ upd , will update w =R1(K G ,tkn||i||(ct,t)||op) inserts into the set Γ upd Finally, the data owner will upd Send to the proxy server; Step 2.3: The proxy server receives the set Γ upd Then for each upd w ∈Γ upd By permutation algorithm R1 -1 get Where op = add; The proxy server queries the keyword status table (st c ,c)←W add [tkn||i], where st c Indicates the keyword status, c indicates the number of keyword updates; The proxy server generates a new status word st for the keyword c+1 ←{0,1} λ , initialize a set Γ add ,calculate Γ add ←(u,e); Finally, the proxy server will set Γ add Send to the cloud server and update the keyword status table W add [tkn||i]←(st c+1 ,c+1); Step 2.4: The cloud server receives the set Γ add Then add the information according to the keyword and store it in the state chain to add the document index collection EDB add For every pair (u,e)∈Γ add Execute Operation EDB add [u] = e.

4. The forward-backward secure multi-user dynamic symmetric searchable encryption method according to claim 2, characterized in that: The document deletion module in step 3 specifically performs the following steps: Step 3.1: If the document is deleted, that is, op = del, for each keyword w∈W(f) contained in the document, the data owner calculates the puncture label Query the local key sharing set msk′←PSK[tkn] for puncture, and use the symmetric puncturable encryption algorithm SPE to puncture msk′ (msk″, psk t )←SPE.IncPun(msk′,t) to get the puncture key share psk t and the new local key share msk″, update the local puncture key share PSK[w]←msk″, and the data owner initializes a set Γ upd , will update w =R1(K G ,tkn||i||(psk t ,t)||op) insert into set Γ upd , finally, the data owner will upd Send to the proxy server; Step 3.2: The proxy server receives the set Γ upd Then for each upd w ∈Γ upd , through the permutation algorithm R1 -1 get The proxy server queries the keyword status table to obtain (st c ,c)←W del [tkn||i], and generate a new status word st for the keyword c+1 ←{0,1} λ , the proxy server initializes a set Γ del ,u=H1(tkn||i||st c+1 ), Γ del ←(u,e), finally, the proxy server will set Γ del Send to the cloud server and update the keyword status table W del [tkn||i]←(st c+1 ,c+1); Step 3.3: The cloud server receives the set Γ del Then the deletion information will be stored in the state chain according to the keyword to delete the document puncture collection EDB del For every pair (u,e)∈Γ del Execute Operation EDB del [u] = e.

5. The forward-backward secure multi-user dynamic symmetric searchable encryption method according to claim 2, characterized in that: In step 4, the data owner generates a unique identifier uid∈{0,1} for each user. λ , the data owner runs the algorithm Gen(1 λ ) Generate the pseudo-random permutation key qk of R2 u ,from Randomly select dk u As the decryption key, calculate the auxiliary decryption key Generate user search counter s=0, proxy server saves (uid,qk u ,s), cloud server saves (uid,dk c ), the user saves SK u =(uid,qk u ,dk u ,K s ,s).

6. The forward-backward secure multi-user dynamic symmetric searchable encryption method according to claim 5, characterized in that: In step 5, the keyword search module performs the following steps: Step 5.1: Enter the query keyword w, and the user uses the private key SK u =(uid,qk u ,dk u ,K s ,s) calculate the keyword identifier tkn = F(K s ,w), user search times s = s + 1, generate query request τ u =R2(qk u ,tkn||s), the user sends uid and query request τ u Send to the proxy server; Step 5.2: The proxy server receives the user uid and query request τ u After that, the proxy server queries the user information table to obtain the user search key and query counter (qk u ,s c )←Ucqt[uid], where qk u Search key for user, s c To query the counter; the proxy server uses a replacement algorithm Get keyword information The proxy server queries the search count i←SC[tkn] of keyword w and the local key share msk′←PSK[tkn], and queries the keyword status in and c add They respectively represent the latest status of keyword addition and update before this query. and c del They respectively represent the latest status of keyword deletion and update before this query; the proxy server generates a search token (uid,τ w ) is sent to the cloud server, and the proxy server uses the key generation algorithm KeyGen(1 λ ) Regenerate the master key msk of keyword w and update the user information and status information of keyword w as follows: Ucqt[uid]←(qk u ,s c +1),MSK[tkn]←msk,PSK[tkn]←msk,SC[tkn]←i+1,W add [tkn||i+1]←(st c =⊥,c=0),W del [tkn||i+1]←(st c =⊥,c=0) Step 5.3: The cloud server receives the uid and search token τ w After that, four sets NewR, OldR, IND and Rst are initialized, and the cloud server obtains the query information In EDB add and EDB del Query the matching information of tkn||i and query EDB cache Get the last search results for the keyword tkn, the cloud server is used in EDB del The query result is punctured to obtain SK0 = (msk′, psk1,…, psk m ) and decrypted in EDB add The encrypted document identifier / tag pair (ct, t) matched in the query is obtained, and the decrypted identifier / tag pair (ind, t) is saved in the set NewR; the cloud server queries EDB cache The last search result corresponding to the keyword in the query is stored in the set OldR. The cloud server deletes the last query result OldR and EDB del The overlapping document identifiers in the query results are then merged with NewR and OldR to obtain the final matching document identifier set IND←NewR∪OldR; Step 5.4: The cloud server stores the search results in EDB cache [tkn]←IND for use in the next search; the cloud server queries the user table Ucdt based on uid to obtain the auxiliary decryption key dk c ←Ucdt[uid], for each document identifier ind∈IND, the cloud server searches for the corresponding encrypted document (r ind ,C ind ), where r ind , C ind The random number and document ciphertext selected for the encrypted document when the document identifier is ind, and the ciphertext information is calculated The ciphertext information cds ind and ciphertext C ind Insert the final search result set Rst←Rst∪(cds ind ,C ind ), and finally the cloud server returns Rst to the user.

7. The forward-backward secure multi-user dynamic symmetric searchable encryption method according to claim 6, characterized in that: In step 6, after receiving the search result Rst, the user initializes the set File, and for each pair (cds ind ,C ind )∈Rst calculates the decryption key dk ind =H3(cds ind dku ), then decrypt the document f ind =AES.Decrypt(dk ind ,Cind), and finally get File = File∪f ind , File is the search result obtained by the end user.