Forward security dynamic symmetry searchable encryption method without client state

Through the forward-security dynamic symmetric searchable encryption method without client state, combined with the constrained pseudo-random function CPRF and server-side global update counting and cache, the problem of client storage bloat and multi-client deployment difficulties is solved, and efficient forward-security and rapid retrieval is achieved.

CN120050037APending Publication Date: 2025-05-27UNIV OF SCI & TECH OF CHINA
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510212726.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-25
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

In the existing forward-facing security dynamic symmetric searchable encryption scheme, client storage bloat and multi-client deployment difficulties.

Method used

By introducing a forward-security dynamic symmetric searchable encryption method with no client state, using the constrained pseudo-random function CPRF to generate updates and search traps, the server side manages global update counts and caches, and realizes forward-security and fast retrieval.

Benefits of technology

It solves the problems of client storage bloat and multi-client deployment, and realizes forward secure dynamic symmetric searchable encryption without client state, reducing search complexity and optimizing search efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050037A_ABST
    Figure CN120050037A_ABST
Patent Text Reader

Abstract

The invention discloses a forward security dynamic symmetric searchable encryption method without a client state, which comprises the following steps: in an initialization stage, a client generates a client key, and a server initializes an update count and each data structure; in the updating stage, the client side obtains and increases the updating count of the server side, based on the updating count and the target updating keyword, a limited pseudo-random function CPRF is used for generating an updating trap door and sending the updating trap door to the server side, and the server side executes updating according to the updating trap door; in the search stage, the client obtains the update count of the server, generates a search trap door based on the update count and the target keyword by using the limited pseudo-random function and sends the search trap door to the server, and the server executes search according to the search trap door to obtain a result and reorganizes the result into a cache to accelerate subsequent search. According to the method, the problems of client storage expansion and difficulty in multi-client deployment in the current forward security dynamic symmetric searchable encryption scheme can be solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular, to a forward-secure dynamic symmetric searchable encryption method without client state. Background Art

[0002] With the popularization of cloud computing, individuals and enterprises have gradually migrated their data to the cloud, which poses a huge challenge to the security of data stored in the cloud. Although traditional encryption methods can ensure data security, they usually make it difficult to retrieve data efficiently, restricting the availability of data. To solve this problem, symmetric searchable encryption technology has emerged. By creating an encrypted index, this technology enables fast retrieval while ensuring data encryption, effectively balancing the requirements of data privacy protection and availability, and has broad application prospects in fields such as healthcare, finance, and e-government.

[0003] Dynamic symmetric searchable encryption is a symmetric searchable encryption scheme that supports dynamic addition and deletion of data. Compared with traditional static schemes, it is more practical in many scenarios. Forward security is an important security attribute in dynamic symmetric searchable encryption, which ensures that previous searches do not disclose information about subsequent updates. Forward security requires that the grouping relationship of keywords among updates is not revealed to the server during the search process. This makes it common for existing schemes to require the client to maintain a state value for each keyword to ensure normal updates and searches, causing the client storage size to grow with the number of keywords. Consequently, the client's storage requirements increase with the number of keywords. On the one hand, such client states are prone to storage expansion in complex data scenarios such as databases; on the other hand, sharing client states in a multi-client environment also brings deployment difficulties, requiring the design of complex protocols, bearing high communication costs, and exposing a larger attack surface. Summary of the Invention

[0004] The purpose of the present invention is to provide a forward-secure dynamic symmetric searchable encryption method without client state, which can solve the problems of client storage expansion and difficult multi-client deployment in current forward-secure dynamic symmetric searchable encryption schemes.

[0005] The purpose of the present invention is achieved through the following technical solutions:

[0006] A forward-secure dynamic symmetric searchable encryption method without client state, the method comprising:

[0007] Step 1, in the initialization phase, the client generates a client key, and the server initializes an update count and each data structure;

[0008] Step 2. In the update phase, the client obtains and increments the update count on the server side. Based on the update count and the target update keyword, the client uses the constrained pseudorandom function CPRF to generate an update trapdoor and sends it to the server side. The server side performs the update according to the update trapdoor.

[0009] Step 3. In the search phase, the client obtains the update count on the server side. Based on the update count and the target keyword, the client uses the constrained pseudorandom function CPRF to generate a search trapdoor and sends it to the server side. The server side performs a search according to the search trapdoor to obtain results, and reorganizes the results into the cache to speed up subsequent searches.

[0010] An electronic device includes a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the method.

[0011] A computer storage medium stores multiple instructions, and the instructions are adapted to be loaded and executed by the processor to execute the method.

[0012] It can be seen from the technical solutions provided by the present invention described above that the above method can solve the problems of client storage expansion and difficult deployment of multiple clients in the current forward-secure dynamic symmetric searchable encryption scheme, and is convenient for applications in a multi-client environment. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the following described accompanying drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0014] Figure 1 It is a schematic flowchart of a forward-secure dynamic symmetric searchable encryption method without client state provided by an embodiment of the present invention;

[0015] Figure 2 It is a schematic diagram of the update process according to an embodiment of the present invention;

[0016] Figure 3 It is a schematic diagram of the search process according to an embodiment of the present invention. DETAILED DESCRIPTION

[0017] The following clearly and completely describes the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments, which does not constitute a limitation to the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the protection scope of the present invention.

[0018] As Figure 1 is a schematic flowchart of a forward-secure dynamic symmetric searchable encryption method without a client state provided by an embodiment of the present invention, and the method includes:

[0019] Step 1, in the initialization phase, the client generates a client key, and the server initializes the update count and each data structure;

[0020] In this step, the client determines the security parameter λ and randomly generates a key k of a pseudorandom function (PRF, Pseudorandom Function) s ={0, 1} λ , and a key k of a constrained pseudorandom function (CPRF, Constrained Pseudorandom Function) m ={0, 1} λ , {0, 1} λ represents a bit string of random length λ;

[0021] Among them, PRF is an important cryptographic primitive that can receive a key of length λ and a fixed-length input bit string and output a fixed-length output bit string. Its security ensures that when the key is randomly selected, the output of PRF is computationally indistinguishable from that of a true random function. CPRF is a special type of PRF that can derive a sub-key that can only process a part of the specified input range from the original key. The sub-key can only produce a normal result when processing inputs within this range, otherwise the result is empty.

[0022] The server initializes the update count c to 0, and initializes the mapping T e and the mapping T c to be empty; among them, the mapping T e is used to store update items that have not been accessed during the search process, and the mapping T c is used for caching search results.

[0023] Step 2, in the update phase, the client obtains and increments the update count of the server, and based on the update count and the target update keyword, uses the constrained pseudorandom function CPRF to generate an update trapdoor and send it to the server, and the server performs an update according to the update trapdoor;

[0024] In this step, asFigure 2 The following is a schematic diagram of the update process according to an embodiment of the present invention. The specific process is as follows:

[0025] (1) The user inputs a keyword w to be updated, the document identifier ind corresponding to the keyword w, and an operator op to the client. The operator op is 'add' or 'del', indicating addition or deletion.

[0026] (2) The client obtains an update count c from the server, and the server increments the update count c by 1.

[0027] (3) The client calculates the tag t corresponding to the keyword w w = F(k s , H(w)); where F is a pseudo-random function PRF; H is a hash function.

[0028] (4) The client calculates the key-value pair (K, V) to be stored in the server mapping T e . Among them,

[0029]

[0030] Among them, is a constrained pseudo-random function CPRF; represents performing m the evaluation process with the key k w and the input t ||(c + 1); H1 and H2 are different hash functions; || represents the concatenation of bit strings. represents the exclusive OR of bit strings.

[0031] (5) The client sends the key-value pair (K, V) as an update trapdoor to the server.

[0032] (6) The server sets T e [K] to V according to the update trapdoor, indicating that the value corresponding to the K key of the mapping T e is set to V.

[0033] Step 3: In the search phase, the client obtains the update count from the server. Based on the update count and the target keyword, the client uses the constrained pseudo-random function CPRF to generate a search trapdoor and sends it to the server. The server performs a search according to the search trapdoor to obtain the result and reorganizes the result into the cache to speed up subsequent searches.

[0034] In this step, as Figure 3 shown in the following is a schematic diagram of the search process according to an embodiment of the present invention. The specific process is as follows:

[0035] (1) The user inputs a keyword w to be searched to the client.

[0036] (2) The client obtains the update count c from the server.

[0037] (3) The client calculates the tag t corresponding to the keyword w w = F(k s , H(w)); where F is a pseudo-random function PRF; H is a hash function;

[0038] (4) The client generates a sub-key denoted as using the key k m and the input range is t w || 1 to t w || c to derive the sub-key k of the constrained pseudo-random function c ;

[0039] (5) The client sends the value pair (t w , k c ) as a search trapdoor to the server.

[0040] (6) The server finds the cache T w of the keyword w when it was last searched according to the tag t c [t w , that is, the value corresponding to the t c key of the mapping T w , and parses it as (c′, ID), where c′ and ID represent the update count and the list of document identifiers cached for the keyword w last time. If the value corresponding to the t c key of the mapping T w does not exist, set c′ to 0 and ID to an empty list instead;

[0041] (7) The server obtains the new updates between the last search and this search, and updates the list of document identifiers ID;

[0042] Specifically, for each positive integer i between the last cached update count c′ and the current search update count c, calculate the key to find the value T e [K] corresponding to the K key of the mapping T e ;

[0043] XOR T e [K] with the mask used to hide the update content in the last update phase to obtain the plaintext update ind||op. If the operator op is 'add', add the document identifier ind to the list of document identifiers ID; otherwise, delete the document identifier ind from the list of document identifiers ID;

[0044] (8) The server deletes all T e [K] accessed in (7) and updates the cache Tc [t w , set as the cache (c, ID) for this search;

[0045] (9) The server returns the document identifier list ID as the result to the client.

[0046] An embodiment of the present invention also provides an electronic device, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the method.

[0047] An embodiment of the present invention also provides a computer storage medium. The computer storage medium stores multiple instructions, and the instructions are adapted to be loaded and executed by the processor to execute the method.

[0048] It should be noted that the content not described in detail in the embodiments of the present invention belongs to the prior art well-known to those skilled in the art.

[0049] Based on the above solution, in principle, the core of the method described in the embodiments of the present invention is to unify the state values of different keywords commonly found in the existing solution into a global update count, reducing the storage to a constant level, providing a foundation for further transferring the client state value; next, since this count does not have privacy compared to the previous state value (the server must know the total number of updates), it can be directly transferred to the server for storage, thus realizing a stateless client. At this time, it can be regarded that the server divides all updates, regardless of the keyword, into the same group; therefore, during the search, on the one hand, in order to ensure forward security, it is necessary to limit the counting range accessible to the server, and on the other hand, in order to prevent the leakage of information about non-search target keywords, it is necessary to limit the keywords accessible to the server. The constrained pseudorandom function CPRF provides a solution to this problem. CPRF can derive a sub-key that can only evaluate a certain input range based on the master key and a certain input range. The embodiments of the present invention introduce CPRF, which limits the counting range available during the search while distinguishing target and non-target keywords, ensuring forward security.

[0050] In addition, the introduction of the global count results in the search needing to traverse the updates of the entire counting range, increasing the search complexity. The present invention optimizes the search efficiency by introducing a server-side cache, where the search results for each keyword are saved, avoiding repeated traversal of the accessed counting range, so that the average search performance is close to the optimal level of the traditional solution.

[0051] In summary, the method described in the embodiments of the present invention has the following advantages compared with the background technology:

[0052] 1. Stateless client: In the present invention, the state value maintained by the client for each keyword in the existing forward-secure dynamic symmetric searchable encryption is converted into a global update count on the server side, and forward security is achieved by combining the constrained pseudorandom function CPRF, realizing a stateless client, avoiding the storage expansion problem in the existing solutions, and simplifying the deployment in the multi-client scenario;

[0053] 2. Low search efficiency loss: By designing the server-side cache structure, the present invention effectively alleviates the problem of increased search overhead that may be brought about by the global counting mechanism. Compared with the existing forward-secure dynamic symmetric searchable encryption scheme, the search efficiency will not deteriorate significantly on average.

[0054] In addition, those of ordinary skill in the art can understand that all or part of the steps in implementing the above-mentioned embodiment methods can be completed by instructing relevant hardware through a program, and the corresponding program can be stored in a computer-readable storage medium. The above-mentioned storage medium can be a read-only memory, a magnetic disk or an optical disc, etc.

[0055] As mentioned above, the above are only the preferred specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims. The information disclosed in the background art part of this article is only intended to deepen the understanding of the overall background art of the present invention, and should not be regarded as an admission or any form of implication that this information constitutes the prior art already known to those skilled in the art.

Claims

1. A client-free forward-secure dynamic symmetric searchable encryption method, characterized in that: The method comprises: Step 1: In the initialization phase, the client generates a client key, and the server initializes the update count and various data structures; Step 2: In the update phase, the client obtains and increases the update count of the server. Based on the update count and the target update keyword, the client generates an update trap using the restricted pseudo-random function CPRF and sends it to the server. The server performs the update according to the update trap. Step 3: In the search phase, the client obtains the update count of the server, and based on the update count and the target keyword, uses the restricted pseudo-random function CPRF to generate a search trap and sends it to the server. The server performs a search based on the search trap to obtain the result, and reorganizes the result into the cache to speed up subsequent searches.

2. According to the client-free stateless forward-secure dynamic symmetric searchable encryption method of claim 1, characterized in that: In step 1, the client determines the security parameter λ and randomly generates a pseudo-random function PRF key k s ={0,1} λ , and the restricted pseudo-random function CPRF key k m ={0,1} λ , {0, 1} λ represents a random bit string of length λ; The server initializes the update count c to 0 and maps T e and the mapping T c Initialized to empty; Among them, the mapping T e Used to store update items that have not been accessed by the search process, mapping T c Cache for search results.

3. According to claim 2, the forward-secure dynamic symmetric searchable encryption method without client state is characterized in that: The process of step 2 is specifically as follows: (1) The user inputs the keyword w to be updated, the document identifier ind corresponding to the keyword w, and the operator op to the client; the operator op is 'add' or 'del', indicating addition or deletion; (2) The client obtains the update count c from the server, and the server increments the update count c by 1; (3) The client calculates the label t corresponding to the keyword w w =F(k s , H(w)); where F is a pseudo-random function PRF; H is a hash function; (4) Client calculations need to be stored in the server-side mapping T e A key-value pair (K, V), where in is the restricted pseudo-random function CPRF; Indicates that the key k m and input t w ||(c+1)Execute The evaluation process; H1 and H2 are different hash functions; || represents the concatenation of bit strings; Represents the exclusive OR of a bit string; (5) The client sends the key-value pair (K, V) to the server as an update trapdoor; (6) The server sets T according to the updated trap e [K] is set to V, indicating that the mapping T e Set the value corresponding to the K key to V.

4. According to claim 3, the forward-secure dynamic symmetric searchable encryption method without client state is characterized in that: The process of step 3 is specifically as follows: (1) The user enters the keyword w to be searched into the client; (2) The client obtains the update count c from the server; (3) The client calculates the label t corresponding to the keyword w w =F(k s , H(w)); where F is a pseudo-random function PRF; H is a hash function; (4) The client generates a subkey Indicates that the key k m and the input range is t w ||1 to t w ||c derives a restricted pseudo-random function The subkey k c ; (5) The client sends the value pair (t w , k c ) is sent to the server as a search trap; (6) The server side uses the tag t w Find the cache T of the last time keyword w was searched c [t w ], that is, mapping T c t w The value corresponding to the key is parsed as (c′, ID), where c′ and ID represent the update count and document identifier list of the last cached keyword w. If the mapping T c t w The value corresponding to the key does not exist, so c′ is set to 0 and ID is an empty list; (7) The server obtains the new updates from the last search to the current search and updates the document identifier list ID; Specifically, for each positive integer i between the last cached update count c′ and the current search update count c, calculate the key Find the mapping T e The value T corresponding to the K key e [K]; T e [K] XOR mask used to hide the updated content during the last update phase Obtain the plaintext update ind||op. If the operator op is 'add', add the document identifier ind to the document identifier list ID; otherwise, delete the document identifier ind from the document identifier list ID. (8) The server deletes all T accessed in (7) e [K], update cache T c [t w ], set as the cache (c, ID) for this search; (9) The server returns the document identifier list ID to the client as a result.

5. An electronic device comprising a memory and a processor, characterized in that: A computer program is stored in the memory, and the processor is configured to run the computer program to perform the method according to any one of claims 1 to 4.

6. A computer storage medium, characterized in that: The computer storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor and executing the method according to any one of claims 1 to 4.

Citation Information

Cited By

  • Searchable encryption method based on key homomorphic PRF and VRF

    CN121098478A

  • A searchable encryption method based on key-homomorphic prf and vrf

    CN121098478B