Data operation method and device based on oblivious search tree and data system
By implementing operation cache and tree cache on the client and performing tree node-related operations locally, the problem of inadvertent search tree efficiency is solved, and the data operation efficiency and system performance of the encrypted database are significantly improved.
Patent Information
- Application Number
- CN202510059416.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-14
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-01-14
AI Technical Summary
The efficiency of inadvertent search trees in existing encrypted databases leads to bottlenecks in actual deployment, especially in scenarios where data operations are frequent, which increases operation delay and system overhead.
By implementing operation cache and tree cache on the client, cache data to be written back after data operations, and perform tree node-related operations locally, reduce the number of interactions with server ORAM, and adjust the call methods of ReadAndRemove interface and Add interface to reduce redundant calls.
It significantly reduces the latency and system overhead when the client and the server encrypted database interaction, improves the efficiency of data operations, and reduces the response time of a single data operation.
Smart Images

Figure CN120067154A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application belong to the technical field of data privacy protection and secure storage, and particularly relate to a data operation method, device, and data system based on an oblivious search tree. Background Art
[0002] With the rapid development of cloud computing and the continuous growth of data storage requirements, database outsourcing has become a widely adopted model. By hosting the database with a cloud service provider, the data owner does not need to build and maintain storage facilities by themselves and only needs to pay fees according to actual needs. This model greatly improves the convenience and cost-effectiveness of data storage and management. However, this convenience is also accompanied by significant security challenges, especially in terms of data privacy protection. An untrusted cloud service provider may snooping on user data or leaking sensitive information.
[0003] To address these challenges, encrypted databases (EDBs) have gradually become a research and practice hotspot. Encrypted databases protect the privacy and security of data during storage and query through cryptographic techniques or trusted execution environments (TEEs). Among them, obliviousness is the core feature to achieve a higher level of data privacy protection. Obliviousness ensures that during the query process, an untrusted server cannot infer the query content by observing the access pattern, thus effectively protecting user privacy.
[0004] Oblivious Search Tree (OST) is the core technology for implementing tree-shaped indexes in encrypted databases (EDBs). However, its efficiency problem has long been an important bottleneck for practical deployment. Summary of the Invention
[0005] In view of this, the embodiments of the present application provide a data operation method, device, and data system based on an oblivious search tree to improve the operation efficiency of encrypted databases and significantly reduce the time required for data operations on encrypted databases.
[0006] The first aspect of the embodiments of the present application provides a data operation method based on an oblivious search tree, which is applied to a client. The client is connected to a server, and the server deploys a tree-shaped storage structure ORAM that supports oblivious random access; the client is provided with an operation cache and a tree cache; the operation cache is used to cache the data to be written back to the ORAM after each response to a data operation; the method includes:
[0007] In response to the received data operation, obtain the OST path corresponding to the data operation from the ORAM, store the data on the OST path in the tree cache; upload the data to be written back cached in the operation cache during the response process of the previous data operation to the ORAM;
[0008] Perform tree node related operations on the tree cache locally, and when the tree node related operations are completed, store the data in the tree cache as the data to be written back in the operation cache;
[0009] Empty the data in the tree cache.
[0010] In some implementation manners of the first aspect, the step of in response to the received data operation, obtaining the OST path corresponding to the data operation from the ORAM, storing the data on the OST path in the tree cache; uploading the data to be written back cached in the operation cache during the response process of the previous data operation to the ORAM includes:
[0011] For the data to be downloaded starting from the root node of the OST path, repeatedly perform the following operations:
[0012] If the data to be downloaded does not exist in the operation cache, read the data to be downloaded from the ORAM and write the read data to be downloaded into the tree cache; if the data to be downloaded exists in the operation cache, directly read the data to be downloaded from the operation cache, write the data to be downloaded into the tree cache, and read a random data from the ORAM;
[0013] Upload one of the data to be written back in the operation cache to the ORAM, and delete the uploaded data to be written back from the operation cache;
[0014] Determine new data to be downloaded according to the target data corresponding to the data operation.
[0015] In some implementation manners of the first aspect, the step of determining new data to be downloaded according to the target data corresponding to the data operation includes:
[0016] Obtain that the value of the key of the current data to be downloaded is the first value, and the value of the key of the target data of the data operation is the second value;
[0017] If the first value is less than the second value, determine the right child node of the current data to be downloaded as the new data to be downloaded; if the first value is greater than the second value, determine the left child node of the current data to be downloaded as the new data to be downloaded.
[0018] In some implementations of the first aspect, if the data to be downloaded exists in the operation cache, directly read the data to be downloaded from the operation cache, write the data to be downloaded into the tree cache, and read a random data from the ORAM, including:
[0019] If the data to be downloaded exists in the operation cache, directly read the data to be downloaded from the operation cache, and call the first interface to obtain a first random path from the ORAM. The first random path is used to upload one of the data to be written back in the operation cache to the ORAM of the server at the first random path;
[0020] Store the data to be downloaded in the tree cache.
[0021] In some implementations of the first aspect, if the data to be downloaded does not exist in the operation cache, read the data to be downloaded from the ORAM and write the read data to be downloaded into the tree cache, including:
[0022] If the data to be downloaded does not exist in the operation cache, call the first interface to obtain the data to be downloaded from the ORAM at a specified path; the specified path is the path of the data to be downloaded in the ORAM;
[0023] Store the data to be downloaded in the tree cache.
[0024] In some implementations of the first aspect, upload one of the data to be written back in the operation cache to the ORAM and delete the uploaded data to be written back from the operation cache, including:
[0025] Call the second interface to transmit a data to be written back in the operation cache to the ORAM at the ORAM path read by the first interface;
[0026] Delete the data that has been written back to the ORAM in the operation cache.
[0027] The second aspect of the embodiments of the present application provides another data operation method based on an oblivious search tree, which is applied to a server. The server is connected to a client, and the server is deployed with a tree-shaped storage structure ORAM that supports oblivious random access; the client is provided with an operation cache and a tree cache; the operation cache is used to cache the data to be written back to the ORAM after each response to a data operation; the method includes:
[0028] In response to a request from the client, send the OST path in the ORAM to the client; the OST path corresponds to the data operation received by the client;
[0029] The client is used to store the data on the OST path into the tree cache; upload the data to be written back cached in the operation cache during the response process of the previous data operation to the ORAM; perform tree node-related operations on the tree cache locally, and when the tree node-related operations are completed, store the data in the tree cache as the data to be written back into the operation cache; clear the data in the tree cache.
[0030] A third aspect of the embodiments of the present application provides a data operation device based on an oblivious search tree, which is applied to a client. The client is connected to a server, and the server is deployed with an ORAM (Oblivious Random Access Memory) having a tree-like storage structure that supports oblivious random access; the client is provided with an operation cache and a tree cache; the operation cache is used to cache the data to be written back to the server ORAM after each data operation; the device includes:
[0031] A data operation response module, configured to, in response to a received data operation, obtain the OST path corresponding to the data operation from the ORAM, store the data on the OST path into the tree cache; upload the data to be written back cached in the operation cache during the response process of the previous data operation to the ORAM;
[0032] A tree operation module, configured to perform tree node-related operations on the tree cache locally, and when the tree node-related operations are completed, store the data in the tree cache as the data to be written back into the operation cache;
[0033] A tree cache clearing module, configured to clear the data in the tree cache.
[0034] A fourth aspect of the embodiments of the present application provides another data operation device based on an oblivious search tree, which is applied to a server. The server is connected to a client, and the server is deployed with an ORAM having a tree-like storage structure that supports oblivious random access; the client is provided with an operation cache and a tree cache; the operation cache is used to cache the data to be written back to the ORAM after each response to a data operation; the device includes:
[0035] An OST path sending module, configured to, in response to a request from the client, send the OST path in the ORAM to the client; the OST path corresponds to the data operation received by the client;
[0036] The client is used to store the data on the OST path into the tree cache; upload the data to be written back cached in the operation cache during the response process of the previous data operation to the ORAM; perform tree node-related operations on the tree cache locally, and when the tree node-related operations are completed, store the data in the tree cache as the data to be written back into the operation cache; clear the data in the tree cache.
[0037] A fifth aspect of the embodiments of the present application provides a data system, the data system includes a server, and at least one client connected to the server; the server deploys a tree-shaped storage structure ORAM that supports oblivious random access; the client is provided with an operation cache and a tree cache; the operation cache is used to cache the data to be written back to the ORAM after each response to a data operation;
[0038] The server includes: an OST path sending module, configured to respond to a request from the client and send the OST path in the ORAM to the client; the OST path corresponds to the data operation received by the client;
[0039] The client includes:
[0040] A data operation response module, configured to respond to a received data operation, obtain the OST path corresponding to the data operation from the ORAM, store the data on the OST path into the tree cache; upload the data to be written back cached in the operation cache during the response process of the previous data operation to the ORAM;
[0041] A tree operation module, configured to perform tree node-related operations on the tree cache locally, and when the tree node-related operations are completed, store the data in the tree cache as the data to be written back into the operation cache;
[0042] A tree cache clearing module, configured to clear the data in the tree cache.
[0043] A sixth aspect of the embodiments of the present application provides an electronic device, including a processor, a memory, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the electronic device implements the oblivious search tree-based data operation method as described in the first aspect above.
[0044] A seventh aspect of the embodiments of the present application provides a computer program product, including a computer program. When the computer program is run, the oblivious search tree-based data operation method as described in the first aspect above is executed.
[0045] The eighth aspect of the embodiments of the present application provides a computer-readable storage medium storing a computer program, which when executed by a processor implements the data operation method based on the oblivious search tree as described in the first aspect above.
[0046] The embodiments of the present application have the following beneficial effects:
[0047] In the embodiments of the present application, in response to a received data operation, the client requests the server to obtain the OST path corresponding to the data operation from the ORAM, and stores the data on the OST path in the tree cache. At the same time as the above process, the data to be written back stored in the operation cache during the previous data operation process is uploaded to the ORAM of the server; tree node-related operations are performed on the tree cache locally, and when the tree node-related operations are completed, the data in the tree cache is stored in the operation cache as the data to be written back; the data in the tree cache is cleared, so as to realize that while obtaining the target data corresponding to the data operation, the data to be written back is transmitted to the ORAM of the server. By locally completing the tree-related operations on the target data corresponding to the data operation, the number of times of calling the ORAM-related interfaces when the client interacts with the encrypted database of the server is greatly reduced, the latency of responding to the data operation is reduced, and the interaction efficiency between the client and the encrypted database of the server is improved. Description of the Drawings
[0048] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings in the following description are only some embodiments of the present application, and those of ordinary skill in the art can also obtain other drawings based on these drawings without creative efforts.
[0049] Figure 1 It is a schematic diagram of path download in a related art;
[0050] Figure 2 It is a schematic diagram of path write-back in a related art;
[0051] Figure 3 It is a schematic diagram of a data operation method based on an oblivious search tree provided by an embodiment of the present application;
[0052] Figure 4 It is a schematic diagram of path download and write-back provided by an embodiment of the present application;
[0053] Figure 5 It is a schematic diagram of another data operation method based on an oblivious search tree provided by an embodiment of the present application;
[0054] Figure 6 It is a schematic diagram of a data operation device based on oblivious search tree provided by an embodiment of the present application;
[0055] Figure 7 It is a schematic diagram of another data operation device based on oblivious search tree provided by an embodiment of the present application;
[0056] Figure 8 It is a schematic diagram of a data system provided by an embodiment of the present application;
[0057] Figure 9 It is a schematic diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners
[0058] In the following description, for the purpose of illustration rather than limitation, specific details such as specific system architectures, technologies, etc. are proposed to thoroughly understand the embodiments of the present application. However, those skilled in the art should clearly understand that the present application can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid unnecessary details from interfering with the description of the present application.
[0059] It should be understood that when used in the specification and claims of the present application, the term "comprising" indicates the presence of the described features, wholes, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.
[0060] It should also be understood that the term "and / or" as used in the specification and claims of the present application refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0061] As used in the specification and claims of the present application, the term "if" can be interpreted as "when", "once", "in response to determining", or "in response to detecting" depending on the context. Similarly, the phrase "if determined" or "if [the described condition or event] is detected" can be interpreted as meaning "once determined", "in response to determining", "once [the described condition or event] is detected", or "in response to detecting [the described condition or event]" depending on the context.
[0062] In addition, in the description of the specification and claims of the present application, the terms "first", "second", "third", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.
[0063] References to "one embodiment" or "some embodiments" etc. described in the specification of this application mean that a particular feature, structure, or characteristic described in connection with the embodiment is included in one or more embodiments of this application. Thus, statements such as "in one embodiment", "in some embodiments", "in other some embodiments", "in still other embodiments", etc. that appear in different places in this specification are not necessarily all referring to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in another way. The terms "comprising", "including", "having" and their variants all mean "including but not limited to", unless otherwise specifically emphasized in another way.
[0064] The high interaction cost of OST operations is particularly significant in a Wide Area Network (WAN) environment. Due to the need for frequent interaction between the client and the server, the operation latency increases significantly. In addition, there are also significant operation overheads in existing OST implementations, especially during the path download and path write-back processes. Generally, these operations rely on the ReadAndRemove and Add interfaces of the underlying ORAM. As Figure 1 shown, a path download schematic diagram in the related art is shown.
[0065] Taking data insertion as an example, during the path download process, that is, the process of determining the insertion position, the client needs to call ReadAndRemove and Add h times (where h is the maximum height of the OST tree). However, the Add call here is paired with ReadAndRemove to ensure security and has no actual operation on the data of the OST tree itself. As Figure 2 shown, a path write-back schematic diagram in the related art is shown. And in the stage of writing a path of the OST tree back to the server, an additional h + 1 times of ReadAndRemove and Add need to be called. The call of ReadAndRemove is only used to randomly read the ORAM path to match the subsequent Add operation, and also has no actual operation on the data of the OST tree itself. Obviously, significant redundancy is introduced in the related art. The embodiments of this application greatly reduce the redundant call situation of the ReadAndRemove interface and the Add interface by adjusting the call methods of the ReadAndRemove interface and the Add interface, and making certain processing flow adjustments locally.
[0066] The technical solution of this application will be described below through specific embodiments.
[0067] Refer to Figure 3, showing a schematic diagram of a data operation method based on an oblivious search tree provided by an embodiment of the present application, which is applied to a client. The client is connected to a server, and the server deploys a tree-shaped storage structure ORAM (Oblivious Random Access Machine) that supports oblivious random access; the client is provided with an operation cache and a tree cache; the operation cache is used to cache the data to be written back to the ORAM after each response to a data operation;
[0068] ORAM (Oblivious Random Access Machine) is a cryptographic primitive jointly maintained by the client and the server. It is used to hide the specific access of a program to memory through a pseudo-randomized access pattern, including the accessed instructions, addresses, and data, to protect program privacy and data security and prevent attackers from inferring sensitive information by observing the access pattern. ORAM can be regarded as a key-value store, that is, key-value ORAM, where the key is a unique identifier and the value is an arbitrary data item; ORAM supports two basic operations: read and write. The read operation returns the corresponding "value" according to the given "key"; the write operation updates or inserts a ("key", "value") pair according to the given "key" and "value".
[0069] The server can deploy ORAM to store data, and the client can interact with the ORAM in the server based on ORAM technology, such as data reading and writing.
[0070] The tree cache is used to temporarily store the data currently being processed locally on the client and supports insertion and rotation operations on the OST; the operation cache is used to temporarily store the data to be written back to the ORAM, that is, the data to be written back, and has a certain capacity limit. Two variables (Tk, Tp) maintained by the client are used to indicate the currently processed OST tree node. Before step 101 below, (Tk, Tp) indicates the root node of the OST tree. Tk represents the key of the currently operated OST node, and Tp represents the path pointer of the tree node in the ORAM. Through (Tk, Tp), the position of the data to be downloaded for the current operation can be located, and the subsequent data to be downloaded (new data to be downloaded) that needs to be processed can be determined in combination with this position.
[0071] The embodiments of the present application may specifically include the following steps:
[0072] Step 101, in response to the received data operation, obtain the OST path corresponding to the data operation from the ORAM, store the data on the OST path in the tree cache; upload the data to be written back cached in the operation cache during the response process of the previous data operation to the ORAM;
[0073] Before receiving the data operation, it is necessary to clear the tree cache to avoid subsequent incorrect operations on the OST, and it is necessary to set the capacity of the operation cache in advance according to the height of the OST tree to avoid overflow of the operation cache.
[0074] Taking the OST tree as an example of the AVL structure OST, the capacity of the operation cache can be set to h + 1, where h is the height of the AVL structure OST.
[0075] The data operation can be one of an insertion operation, a deletion operation, and an update operation.
[0076] After receiving the data operation, the client can generate a request for the data operation and send the request to the server. The client receives the OST path in the ORAM sent by the server in response to the request, so that the client can obtain the OST path corresponding to the current data operation from the ORAM. At the same time, by calling the first interface and the second interface according to a preset number of times, the data to be written back cached in the operation cache during the response process of the previous data operation is transmitted to the ORAM, that is, part of the data to be written back is written back to the server. Obtain the data on the OST path corresponding to the operation data, and store the data on the OST path in the tree cache.
[0077] For example: The data operation is an insertion operation, that is, the target data is the data to be inserted.
[0078] The preset number of times can be determined according to the tree structure of the OST and the height of the OST tree, as long as it satisfies that the predicted number of times can satisfy traversing the complete OST path.
[0079] As an example, the tree structure of the OST is AVL (that is, the OST is an AVL tree), and the preset number of times can be h + 1, where h is the height of the AVL tree.
[0080] As an example, the first interface is the ReadAndRemove interface, and the second interface is the Add interface. The first interface and the second interface are two core interfaces used to implement oblivious access in the ORAM. The ReadAndRemove interface is used to read all data blocks on a specified path from the ORAM structure and obtain the target data from the path. Through ReadAndRemove, the client can obtain all data nodes of a path in the ORAM structure without exposing the specific access target. Matched with ReadAndRemove, the Add interface is used to rewrite the data back to the path.
[0081] As another example, the first interface can also be an interface other than the ReadAndRemove interface, as long as it can read the data blocks on the specified path from the ORAM structure. Similarly, the second interface can also be an interface other than the Add interface, as long as it can write the data back to the ORAM by obtaining the path from the ORAM.
[0082] Step 102: Perform operations related to tree nodes on the local tree cache. When the operations related to tree nodes are completed, store the data in the tree cache as the data to be written back into the operation cache.
[0083] Perform operations related to tree nodes on the tree cache locally on the client side, such as: insertion, balancing, deletion, update, etc. After the operations related to tree nodes are completed, determine the data in the tree cache as the data to be written back, and store the data to be written back into the operation cache.
[0084] Through the data interaction between the tree cache and the operation cache, the data that has completed the tree-related operations can be quickly determined as the data to be written back.
[0085] Since after a single insertion or deletion operation is performed in Step 102, the OST path after the operation is not immediately written back to the ORAM of the server, but is postponed to Step 101 in the next insertion or deletion operation, this reduces the interaction between the client and the server based on the first interface and the second interface, and avoids the need to complete a single insertion or deletion operation by calling the first interface and the second interface multiple times as in the related art.
[0086] Taking the OST tree as an AVL tree with a height of h as an example, the embodiment of the present application can reduce the number of calls to the first interface and the second interface from 2h + 1 times required in the existing solution to h + 1 times, greatly reducing the calls to the first interface and the second interface and reducing the system overhead.
[0087] Since the number of calls to the first interface and the second interface is reduced by nearly half, the embodiment of the present application can reduce the latency of data operations by nearly 50%, greatly improving the efficiency of accessing the encrypted database using the first interface and the second interface.
[0088] Step 103: Clear the data in the tree cache.
[0089] After storing the data in the tree cache into the operation cache, the data in the tree cache can be cleared to restore the state of the tree cache to the initial state and wait for the next data operation.
[0090] In an embodiment of the present application, in response to a received data operation, the client requests the server to obtain the OST path corresponding to the data operation from the ORAM, and stores the data on the obtained OST path in the tree cache. During the above process, the data to be written back stored in the operation cache during the previous data operation is uploaded to the ORAM of the server; tree node-related operations are performed on the tree cache locally, and when the tree node-related operations are completed, the data in the tree cache is stored in the operation cache as the data to be written back; the data in the tree cache is cleared, so as to realize that while obtaining the target data corresponding to the data operation, the data to be written back is transmitted to the ORAM of the server. By locally completing the tree-related operations on the target data corresponding to the data operation, the number of times of calling the ORAM-related interfaces when the client interacts with the encrypted database of the server is greatly reduced, the latency of responding to the data operation is reduced, and the interaction efficiency between the client and the encrypted database of the server is improved.
[0091] In some implementation manners of the embodiment of the present application, step 101 includes:
[0092] For the data to be downloaded starting from the root node of the OST path, repeat the following operations:
[0093] If the data to be downloaded does not exist in the operation cache, read the data to be downloaded from the ORAM and write the read data to be downloaded into the tree cache; if the data to be downloaded exists in the operation cache, directly read the data to be downloaded from the operation cache, write the data to be downloaded into the tree cache, and read a random data from the ORAM.
[0094] Upload one of the data to be written back in the operation cache to the ORAM, and delete the uploaded data to be written back from the operation cache.
[0095] Determine new data to be downloaded according to the target data corresponding to the data operation.
[0096] For the data to be downloaded starting from the root node of the OST tree according to the OST path, repeat the corresponding operations. Determine whether there is data to be written back corresponding to the node path in the operation cache. There are the following two situations. If the data to be downloaded exists in the operation cache, directly read the data from the operation cache, write it into the tree cache, and randomly read a piece of data from the ORAM of the server. If the data to be downloaded does not exist in the operation cache, read the data to be downloaded from the ORAM of the server and write the read data to be downloaded into the tree cache. Determine new data to be downloaded according to the target data corresponding to the data operation.
[0097] to obtain the OST path corresponding to the data operation from the ORAM, and upload the data to be written back stored in the operation cache during the previous data operation to the ORAM of the server.
[0098] In some implementation manners of the embodiments of the present application, the determining the new data to be downloaded according to the target data corresponding to the data operation includes:
[0099] Obtaining that the value of the key of the currently to-be-downloaded data is a first value, and the value of the key of the target data of the data operation is a second value;
[0100] If the first value is less than the second value, determining the right child node of the currently to-be-downloaded data as the new to-be-downloaded data; if the first value is greater than the second value, determining the left child node of the currently to-be-downloaded data as the new to-be-downloaded data.
[0101] By comparing the value of the key of the current data node and the value of the key of the operation target data, determining the next to-be-downloaded data (i.e., the new to-be-downloaded data).
[0102] In some implementation manners of the embodiments of the present application, if the to-be-downloaded data exists in the operation cache, directly reading the to-be-downloaded data from the operation cache, writing the to-be-downloaded data into the tree cache, and reading a random data from the ORAM includes: if the to-be-downloaded data exists in the operation cache, directly reading the to-be-downloaded data from the operation cache, and calling a first interface to obtain a first random path from the ORAM, where the first random path is used to upload one of the data to be written back in the operation cache to the ORAM of the server at the first random path; storing the to-be-downloaded data into the tree cache.
[0103] If the data to be written back corresponding to the node path exists in the operation cache, call the first interface to obtain the first random path and the data on the path (i.e., randomly read the data) to maintain the randomness of data access. And use a second interface to transfer the data to be written back to the ORAM according to the first random path, so as to implement transferring the data to be written back corresponding to the previous data operation to the server.
[0104] In some implementation manners of the embodiments of the present application, if the to-be-downloaded data does not exist in the operation cache, reading the to-be-downloaded data from the ORAM and writing the read to-be-downloaded data into the tree cache includes: if the to-be-downloaded data does not exist in the operation cache, calling a first interface to obtain the to-be-downloaded data from the ORAM at a specified path; the specified path is the path of the to-be-downloaded data in the ORAM; storing the to-be-downloaded data into the tree cache.
[0105] If there is no data to be written back corresponding to the node path in the operation cache, obtain a specified path through the corresponding variable Tp in the current tree node. The specified path is a random path corresponding to Tp, and obtain the current data to be downloaded through the specified path.
[0106] In some implementation manners of the embodiments of the present application, uploading one of the data to be written back in the operation cache to the ORAM and deleting the uploaded data to be written back from the operation cache includes: calling a second interface to transmit one data to be written back in the operation cache to the ORAM at the ORAM path read by the first interface; deleting the data that has been written back to the ORAM from the operation cache.
[0107] Call a second interface to transmit one data to be written back in the operation cache to the ORAM at the ORAM path read by the first interface; delete the data to be downloaded that has been written back to the ORAM from the operation cache, so as to write back the data to be downloaded corresponding to the previous data operation to the ORAM in sequence.
[0108] In some implementation manners of the embodiments of the present application, since there may be a lot of data in the client, some data can be used as a dataset to be processed, and interact with the server for the dataset to be processed to construct an OST tree.
[0109] Select a suitable tree structure of the OST tree according to requirements, such as an AVL tree, a B tree, a B+ tree, or a red-black tree, etc. These tree structures have their own characteristics: for example: AVL tree: a self-balancing binary search tree, suitable for scenarios with frequent searches and insertions; B tree: a multi-way balanced search tree, suitable for disk storage and a large amount of data; B+ tree: a variant of the B tree, suitable for databases and file systems; red-black tree: an approximately balanced binary search tree, suitable for insertions, deletions, and search operations.
[0110] In some implementation manners of the embodiments of the present application, in response to the received data operation, obtaining the OST path corresponding to the data operation from the ORAM and storing the data on the OST path in the tree cache; before uploading the data to be written back cached in the operation cache during the response process of the previous data operation to the ORAM, the method further includes: determining the tree height of the OST tree; setting the operation cache capacity according to the tree height.
[0111] The tree height refers to the path length from the root node to the farthest leaf node. By setting the operation cache capacity according to the tree height, it is possible to ensure that the OST path length can be covered while preventing overflow.
[0112] Next, taking the OST tree as an AVL tree and the data operation as an insertion operation as an example, the embodiments of the present application will be further described.
[0113] The client maintains two caches: an operation cache and a tree cache. The operation cache is used to temporarily store records to be written back, and the tree cache is used to temporarily store records on the AVL path corresponding to the operation. The client maintains two variables (Tk, Tp) to indicate nodes in the AVL tree, initially pointing to the root node of the AVL tree. Where Tk represents the key of the node, and Tp represents the path corresponding to the node in the oblivious random access machine (ORAM).
[0114] Before data insertion, the tree cache of the client is empty, and the capacity of the operation cache is set to temporarily store at most h + 1 data to be written back.
[0115] The specific data insertion operation includes the following stages:
[0116] (1) Path download and write-back stage. When the user starts the insertion operation, the client completes the download of the AVL OST path through h + 1 calls (O.ReadAndRemove, O.Add).
[0117] Among them, O.ReadAndRemove represents the ReadAndRemove interface, O.Add represents the Add interface, and (O.ReadAndRemove, O.Add) represents calling the ReadAndRemove interface and the Add interface in sequence.
[0118] (2) Local processing stage. The client completes the insertion and balancing operations of the AVL tree in the local cache. All operations in this stage are completed locally on the client and do not involve interaction with the server.
[0119] (3) Update the cache by swapping the contents of the operation cache and the tree cache, and empty the contents of the tree cache so that the client returns to the state before the path download and write-back stage and can process the next data operation.
[0120] Refer to Figure 4 , which shows a schematic diagram of path download and write-back provided by the embodiments of the present application. In the path download and write-back stage, the path download and write-back are as Figure 4 shown.
[0121] Among them, for (1) the path download and write-back stage. The process of calling (O.ReadAndRemove, O.Add) will read a record in the AVL path corresponding to the current operation (through O.ReadAndRemove), and write back a record on the AVL path corresponding to the previous operation (through O.Add). This process includes the following steps:
[0122] (1.1) Check whether the record to be read currently is cached in the operation cache:
[0123] a) If the record exists in the operation cache, remove the record from the operation cache and directly use it as the record to be read, and call O.ReadAndRemove to read a random path to maintain the randomness of the access pattern;
[0124] b) If the record is not in the operation cache, call O.ReadAndRemove to read the specified path in the ORAM (determined by Tp), and then obtain the record to be read currently from the path through Tk.
[0125] (1.2) Write the record obtained in step (1.1) into the tree cache;
[0126] (1.3) Call O.Add to write a cached record in the operation cache back to the ORAM (even if the operation cache is empty at this time, O.Add still needs to be called), and delete this record from the operation cache;
[0127] (1.4) Determine the next tree node to be read according to the comparison result between the current node key value and the inserted record key value (this process follows the operations of a basic AVL search tree, that is, if the current node key value is less than the inserted record key value, recursively search for the appropriate insertion point in the right subtree; if the current node key value is greater than the inserted record key value, recursively search for the appropriate insertion point in the left subtree).
[0128] The inserted record key value is determined by the OST path corresponding to the insert operation.
[0129] In an actual scenario, the embodiments of the present application can be widely applied to the scenario of an outsourced database, especially in the field of privacy protection for encrypted databases. Suppose an outsourced database service provider provides data storage and query services for customers. The customer's database may contain highly sensitive information such as transaction records, financial data, and medical records. In order to optimize the database performance while ensuring privacy security, the service provider needs to ensure the obliviousness during the data operation process. At the same time, to save the storage resources of the client, the service provider chooses to adopt the oblivious search tree (OST) scheme. However, common database operations such as search, insertion, and deletion usually require frequent interactions between the client and the server, which significantly increases the communication overhead and processing latency, especially in a wide area network (WAN) environment. To address the above problems, the embodiments of the present application propose an optimized oblivious search tree (OST) operation process. This method significantly reduces the number of interactions and communication overhead between the client and the server while strictly ensuring the privacy protection requirements. For example, when a large number of insert or update operations need to be performed, the optimized process of the embodiments of the present application can effectively reduce the network latency and ensure the strict obliviousness requirements of the access pattern. In addition, the efficient operation process of the embodiments of the present application does not require large-scale modifications to the existing encrypted database architecture, has good compatibility, and can be easily integrated into the existing system. Through the implementation of the embodiments of the present application, the service provider can not only provide more efficient database services but also provide stronger privacy protection for customers, laying a solid foundation for the popularization and application of outsourced database technology.
[0130] The following further illustrates the effects of the embodiments of the present application with two actual application examples:
[0131] The first application example
[0132] In a certain implementation environment, the client and the database service provider are respectively running on two machines with the same configuration (system version, processor model, memory model, hard disk model). The two machines are located in the same local area network. The client first encrypts the database and then uploads the encrypted database to the service provider. Initially, the database is empty, and then the data volume is increased to the target value preset in the experiment by inserting data items one by one. The oblivious search tree scheme of the embodiments of the present application is compared with the traditional oblivious search tree scheme. The experiment compares the average time consumption of each insertion operation. The oblivious random access machine (ORAM) adopts the PathORAM scheme, where each bucket stores 4 blocks, and the capacity limit of the client stash is at most 7logn blocks, where n is the size of the database, that is, the number of records contained in the database. Table 1 shows the running times of the two schemes in different database size scenarios.
[0133]
[0134] Table 1
[0135] As can be seen from Table 1, compared with the traditional OST scheme, the OST scheme provided by the embodiments of the present application reduces the single insertion operation time by about 50%.
[0136] Second application example
[0137] The embodiments of the present application can be applied to the discovery of functional dependencies in encrypted databases. In a certain implementation environment, the client and the database service provider run on two machines with the same configuration (system version, processor model, memory model, hard disk model). The two machines are located in the same local area network. The client encrypts each data item of a dynamic database initially containing n rows and m columns it owns using the AES / CBC algorithm, and the key length used is 128 bits. The encrypted database of the client is uploaded to the service provider. The oblivious random access machine in this scheme adopts the PathORAM scheme, where 4 blocks are placed in each bucket, and it is restricted that the stash of the client can store at most 7logn blocks, where n is the size of the database, that is, the number of records contained in the database.
[0138] In scenarios with different database sizes, when using the traditional OST scheme for functional dependency discovery and comparing it with the OST scheme provided by the embodiments of the present application for functional dependency discovery, the actual running times of the two schemes are as
[0139] shown in Table 2
[0140]
[0141] Table 2
[0142] It can be known from Table 2 that the OST scheme provided by the embodiments of the present application reduces both the communication overhead and the calculation time to half of the traditional scheme, greatly improving the performance and practical feasibility of the functional dependency discovery scheme. Thus, it can be seen that the OST scheme provided by the embodiments of the present application has significant advantages in the actual application of encrypted databases, not only effectively reducing the resource consumption of the system, but also improving the efficiency and practicality of the scheme.
[0143] It should be noted that the magnitudes of the sequence numbers of the steps in the above embodiments do not mean the order of execution. The execution order of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.
[0144] Refer to Figure 5, which shows a schematic diagram of another data operation method based on oblivious search tree provided by an embodiment of the present application, is applied to a server. The server is connected to a client, and the server is deployed with a tree-shaped storage structure ORAM that supports oblivious random access; the client is provided with an operation cache and a tree cache; the operation cache is used to cache the data to be written back to the ORAM after each response to a data operation; the method includes:
[0145] Step 501, in response to a request from the client, send the OST path in the ORAM to the client; the OST path corresponds to the data operation received by the client;
[0146] The client is used to store the data on the OST path into the tree cache; upload the data to be written back cached in the operation cache during the response process of the previous data operation to the ORAM; perform tree node-related operations on the tree cache locally, and when the tree node-related operations are completed, store the data in the tree cache as the data to be written back in the operation cache; clear the data in the tree cache.
[0147] After receiving a data operation, the client can generate a request for the data operation and send the request to the server. The server can respond to the request and send the OST path to the client.
[0148] Refer to Figure 6 , which shows a schematic diagram of a data operation device based on oblivious search tree provided by an embodiment of the present application. The device is located in the client. The client is connected to the server, and the server is deployed with a tree-shaped storage structure ORAM that supports oblivious random access; the client is provided with an operation cache and a tree cache; the operation cache is used to cache the data to be written back to the ORAM after each response to a data operation; the device may specifically include:
[0149] A data operation response module 601, configured to, in response to a received data operation, obtain the OST path corresponding to the data operation from the ORAM, store the data on the OST path in the tree cache; upload the data to be written back cached in the operation cache during the response process of the previous data operation to the ORAM;
[0150] A tree operation module 602, configured to perform tree node-related operations on the tree cache locally, and when the tree node-related operations are completed, store the data in the tree cache as the data to be written back in the operation cache;
[0151] A tree cache clearing module 603, configured to clear the data in the tree cache.
[0152] In some implementation manners of the embodiments of the present application, the data operation response module 601 is configured to repeatedly call the following sub-modules for the data to be downloaded starting from the root node of the OST path:
[0153] The data acquisition sub-module is configured to, if the data to be downloaded does not exist in the operation cache, read the data to be downloaded from the ORAM and write the read data to be downloaded into the tree cache; if the data to be downloaded exists in the operation cache, directly read the data to be downloaded from the operation cache, write the data to be downloaded into the tree cache, and read a random data from the ORAM;
[0154] The data write-back sub-module is configured to upload one of the data to be written back in the operation cache to the ORAM and delete the uploaded data to be written back from the operation cache;
[0155] The current data to be downloaded re-determination sub-module is configured to determine new data to be downloaded according to the target data corresponding to the data operation.
[0156] In some implementation manners of the embodiments of the present application, the current data to be downloaded re-determination sub-module includes:
[0157] The key value determination unit of the node is configured to obtain that the key value of the current data to be downloaded is a first value and the key value of the target data of the data operation is a second value;
[0158] The comparison unit is configured to, if the first value is less than the second value, determine the right child node of the current data to be downloaded as the new data to be downloaded; if the first value is greater than the second value, determine the left child node of the current data to be downloaded as the new data to be downloaded.
[0159] In some implementation manners of the embodiments of the present application, the data acquisition sub-module includes:
[0160] The first acquisition unit is configured to, if the current data to be downloaded exists in the operation cache, directly read the current data to be downloaded from the operation cache and call a first interface to obtain a first random path from the ORAM, where the first random path is used for uploading one of the data to be written back in the operation cache to the ORAM of the server when uploading;
[0161] The first storage unit is configured to store the current data to be downloaded into the tree cache.
[0162] In some implementation manners of the embodiments of the present application, the data acquisition sub-module includes:
[0163] A second acquisition unit, configured to, if the current data to be downloaded does not exist in the operation cache, call a first interface to acquire the current data to be downloaded from the ORAM at a specified path; the specified path is the path of the current data to be downloaded in the ORAM.
[0164] A second storage unit, configured to store the current data to be downloaded into the tree cache.
[0165] In some implementation manners of the embodiments of the present application, the data write-back sub-module includes:
[0166] A path acquisition unit, configured to call a second interface to transmit a data to be written back in the operation cache to the ORAM at an ORAM path read by the first interface;
[0167] A data write-back unit, configured to delete the data that has been written back to the ORAM in the operation cache.
[0168] In some implementation manners of the embodiments of the present application, the apparatus further includes:
[0169] A tree height determination module, configured to determine the tree height of the OST tree;
[0170] An operation cache capacity setting module, configured to set the operation cache capacity according to the tree height.
[0171] A data operation apparatus based on an oblivious search tree provided by an embodiment of the present application. By applying this apparatus, each step in the foregoing method embodiments can be implemented.
[0172] For the apparatus embodiments, since they are basically similar to the method embodiments, the description is relatively simple. For related parts, refer to the description in the method embodiment section.
[0173] Refer to Figure 7 , which shows a schematic diagram of another data operation apparatus based on an oblivious search tree provided by an embodiment of the present application; applied to a server, the server is connected to a client, and the server is deployed with a tree-shaped storage structure ORAM that supports oblivious random access; the client is provided with an operation cache and a tree cache; the operation cache is used to cache the data to be written back to the ORAM after each response to a data operation; the apparatus includes:
[0174] An OST path sending module 701, configured to, in response to a request from the client, send the OST path in the ORAM to the client; the OST path corresponds to the data operation received by the client.
[0175] The client is used to store the data on the OST path into the tree cache; upload the data to be written back cached in the operation cache during the response process of the previous data operation to the ORAM; perform tree node-related operations on the tree cache locally, and when the tree node-related operations are completed, store the data in the tree cache as the data to be written back into the operation cache; clear the data in the tree cache.
[0176] Refer to Figure 8 , which shows a data system provided by an embodiment of the present application. The data system includes a server and at least one client connected to the server; the server is deployed with a tree-shaped storage structure ORAM that supports oblivious random access; the client is provided with an operation cache and a tree cache; the operation cache is used to cache the data to be written back to the ORAM after each response to a data operation;
[0177] The server includes: an OST path sending module, configured to respond to a request from the client and send the OST path in the ORAM to the client; the OST path corresponds to the data operation received by the client;
[0178] The client includes:
[0179] A data operation response module, configured to respond to a received data operation, obtain the OST path corresponding to the data operation from the ORAM, store the data on the OST path into the tree cache; upload the data to be written back cached in the operation cache during the response process of the previous data operation to the ORAM;
[0180] A tree operation module, configured to perform tree node-related operations on the tree cache locally, and when the tree node-related operations are completed, store the data in the tree cache as the data to be written back into the operation cache;
[0181] A tree cache clearing module, configured to clear the data in the tree cache.
[0182] For the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple. For related parts, refer to the description in the method embodiment section.
[0183] Refer to Figure 9 , which shows a schematic diagram of an electronic device provided by an embodiment of the present application. As Figure 4As shown in the figure, the electronic device 900 in the embodiment of the present application includes: a processor 910, a memory 920, and a computer program 921 stored in the memory 920 and operable on the processor 910. When the processor 910 executes the computer program 921, it implements the steps in each of the above embodiments of the data operation method based on the oblivious search tree, such as Figure 3 the steps 101 to 103 shown in the figure, or as Figure 5 the step 501 shown in the figure. Alternatively, when the processor 910 executes the computer program 921, it implements the functions of each module / unit in each of the above device embodiments, such as Figure 6 the functions of the modules 601 to 603 shown in the figure, or as Figure 7 the function of the module 701 shown in the figure.
[0184] Exemplarily, the computer program 921 can be divided into one or more modules / units, and the one or more modules / units are stored in the memory 920 and executed by the processor 910 to complete the present application. The one or more modules / units can be a series of computer program instruction segments capable of performing specific functions, and these instruction segments can be used to describe the execution process of the computer program 921 in the electronic device 900.
[0185] The electronic device 900 may include, but is not limited to, a processor 910 and a memory 920. Those skilled in the art can understand that Figure 9 this is only an example of the electronic device 900 and does not constitute a limitation on the electronic device 900. It may include more or fewer components than those shown in the figure, or combine certain components, or different components. For example, the electronic device 900 may further include input / output devices, network access devices, buses, etc.
[0186] The processor 910 may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0187] The memory 920 may be an internal storage unit of the electronic device 900, such as a hard disk or memory of the electronic device 900. The memory 920 may also be an external storage device of the electronic device 900, such as a plug-in hard disk equipped on the electronic device 900, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, and so on. Further, the memory 920 may also include both the internal storage unit of the electronic device 900 and an external storage device. The memory 920 is used to store the computer program 921 and other programs and data required by the electronic device 900. The memory 920 may also be used to temporarily store data that has been output or is to be output.
[0188] An embodiment of the present application also discloses a computer-readable storage medium storing a computer program, which when executed by a processor implements the data operation method based on an oblivious search tree as described in the foregoing various embodiments.
[0189] An embodiment of the present application also discloses a computer program product including a computer program, which when run causes the data operation method based on an oblivious search tree as described in the foregoing various embodiments to be executed.
[0190] The above-described embodiments are only used to illustrate the technical solutions of the present application and are not intended to limit them. Although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the various embodiments of the present application and should all be included within the protection scope of the present application.
Claims
1. A data operation method based on an oblivious search tree, characterized in that: Applied to a client, the client is connected to a server, and the server is deployed with a tree-like storage structure ORAM supporting inadvertent random access; The client is provided with an operation cache and a tree cache; The operation cache is used to cache data to be written back to the ORAM after each response data operation; the method comprises: In response to the received data operation, the OST path corresponding to the data operation is obtained from the ORAM, and the data on the OST path is stored in the tree cache; the to-be-written-back data cached in the operation cache in the response process of the previous data operation is uploaded to the ORAM; Performing tree node related operations on the tree cache locally, and when the tree node related operations are completed, storing the data in the tree cache as the data to be written back in the operation cache; Clear the data in the tree cache.
2. The method according to claim 1, characterized in that In response to the received data operation, obtaining the OST path corresponding to the data operation from the ORAM, and storing the data on the OST path in the tree cache; Uploading the to-be-written-back data cached in the operation cache in the response process of the previous data operation to the ORAM, including: For the data to be downloaded starting from the root node of the OST path, repeatedly perform the following operations: If the data to be downloaded does not exist in the operation cache, the data to be downloaded is read from the ORAM, and the read data to be downloaded is written into the tree cache; if the data to be downloaded exists in the operation cache, the data to be downloaded is directly read from the operation cache, the data to be downloaded is written into the tree cache, and a random data is read from the ORAM; Uploading one of the to-be-written-back data in the operation cache to the ORAM, and deleting the uploaded to-be-written-back data from the operation cache; New data to be downloaded is determined according to the target data corresponding to the data operation.
3. The method according to claim 2, characterized in that The step of determining new data to be downloaded based on the target data corresponding to the data operation includes: Acquire the key value of the current data to be downloaded as a first value, and the key value of the target data of the data operation as a second value; If the first value is less than the second value, the right child node of the current data to be downloaded is determined to be the new data to be downloaded; if the first value is greater than the second value, the left child node of the current data to be downloaded is determined to be the new data to be downloaded.
4. The method according to claim 2, characterized in that: If the data to be downloaded exists in the operation cache, directly reading the data to be downloaded from the operation cache, writing the data to be downloaded into the tree cache, and reading a random data from the ORAM, including: If the data to be downloaded exists in the operation cache, directly read the data to be downloaded from the operation cache, and call the first interface to obtain a first random path from the ORAM, where the first random path is used to upload one of the data to be written back in the operation cache to the ORAM of the server using the first random path; The data to be downloaded is stored in the tree cache.
5. The method according to claim 2, characterized in that: If the data to be downloaded does not exist in the operation cache, reading the data to be downloaded from the ORAM, and writing the read data to be downloaded into the tree cache, comprising: If the data to be downloaded does not exist in the operation cache, calling the first interface to obtain the data to be downloaded from the ORAM through a specified path; the specified path is a path of the data to be downloaded in the ORAM; The data to be downloaded is stored in the tree cache.
6. The method according to claim 2, characterized in that The uploading one of the to-be-written-back data in the operation cache to the ORAM, and deleting the uploaded to-be-written-back data from the operation cache, comprises: Calling the second interface to transfer a to-be-written-back data of the operation cache to the ORAM through the ORAM path read by the first interface; The data written back to the ORAM is deleted from the operation cache.
7. A data operation method based on an oblivious search tree, characterized in that: Applied to a server, the server is connected to a client, and the server is deployed with a tree-like storage structure ORAM supporting inadvertent random access; The client is provided with an operation cache and a tree cache; The operation cache is used to cache data to be written back to the ORAM after each response data operation; the method comprises: In response to a request from the client, sending an OST path in the ORAM to the client; the OST path corresponds to a data operation received by the client; The client is used to store the data on the OST path into the tree cache; upload the to-be-written-back data cached in the operation cache during the response process of the previous data operation to the ORAM; perform tree node related operations on the tree cache locally, and when the tree node related operations are completed, store the data in the tree cache as the to-be-written-back data in the operation cache; and clear the data in the tree cache.
8. A data operation device based on an oblivious search tree, characterized in that: Applied to a server, the server is connected to a client, and the server is deployed with a tree-like storage structure ORAM supporting inadvertent random access; The client is provided with an operation cache and a tree cache; The operation cache is used to cache data to be written back to the ORAM after each response data operation; the device comprises: An OST path sending module, configured to send the OST path in the ORAM to the client in response to a request from the client; the OST path corresponds to the data operation received by the client; The client is used to store the data on the OST path into the tree cache; upload the to-be-written-back data cached in the operation cache during the response process of the previous data operation to the ORAM; perform tree node related operations on the tree cache locally, and when the tree node related operations are completed, store the data in the tree cache as the to-be-written-back data in the operation cache; and clear the data in the tree cache.
9. A data operation device based on an oblivious search tree, characterized in that: Applied to a client, the client is connected to a server, and the server is deployed with a tree-structured storage space ORAM supporting inadvertent random access; The client is provided with an operation cache and a tree cache; The operation cache is used to cache data to be written back to the server ORAM after each data operation; the device includes: A data operation response module, configured to, in response to a received data operation, obtain an OST path corresponding to the data operation from the ORAM, store the data on the OST path in the tree cache, and upload the to-be-written-back data cached in the operation cache in the response process of the previous data operation to the ORAM; A tree operation module, used to perform tree node related operations on the tree cache locally, and when the tree node related operations are completed, store the data in the tree cache as the data to be written back in the operation cache; The tree cache clearing module is used to clear the data in the tree cache.
10. A data system, characterized in that: The data system includes a server and at least one client connected to the server; the server is deployed with a tree-like storage structure ORAM supporting inadvertent random access; The client is provided with an operation cache and a tree cache; The operation cache is used to cache data to be written back to the ORAM after each response data operation; The server comprises: an OST path sending module, configured to send the OST path in the ORAM to the client in response to a request from the client; the OST path corresponds to the data operation received by the client; The client comprises: A data operation response module, configured to, in response to a received data operation, obtain an OST path corresponding to the data operation from the ORAM, store the data on the OST path in the tree cache, and upload the to-be-written-back data cached in the operation cache in the response process of the previous data operation to the ORAM; A tree operation module, used to perform tree node related operations on the tree cache locally, and when the tree node related operations are completed, store the data in the tree cache as the data to be written back in the operation cache; The tree cache clearing module is used to clear the data in the tree cache.
11. An electronic device, characterized in that: The electronic device comprises a processor, a memory, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the electronic device implements the method as claimed in any one of claims 1 to 6 or 7.
12. A computer program product, characterized in that The invention comprises a computer program, which, when being executed, enables the method according to any one of claims 1 to 6 or 7 to be performed.
Citation Information
Patent Citations
Security data retrieval method based on oblivious ciphertext inverted index
CN113722366A
Multi-path cache write-back method and device based on Path + ORAM (Optical Random Access Memory) and related equipment
CN117094037A
ORAM optimization strategy in multi-user shared storage scene
CN118627129A
Methods for implementing and obfuscating a cryptographic algorithm having a given secret key
US20200382271A1