Label constraint K-step reachability query method for privacy protection on label graph
By implementing the tag constraint K-step accessibility query method for privacy protection on the tag graph, the problem of difficult data privacy protection in traditional methods is solved, and a safe and efficient graph data query is achieved.
Patent Information
- Application Number
- CN202510138127.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-07
- Publication Date
- 2025-05-30
AI Technical Summary
Traditional label graph query methods are difficult to meet the needs of strict data privacy protection, especially in key management, graph data encryption and index construction, and privacy protection of query processes.
A tag constraint K-step accessibility query method for privacy protection on the tag graph is proposed, and data privacy protection during the query process is ensured through technical means such as key generation, graph encryption, secure index construction and secure subset verification protocols.
It realizes secure query of tag graph data, ensures data privacy protection, improves query efficiency and accuracy, and reduces the risk of information leakage.
Smart Images

Figure CN120068148A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of cloud computing security, and particularly to a label-constrained K-step reachability query method for privacy protection on a label graph. Background Art
[0002] In the fields of information processing and data management, a label graph is an important data structure. With the expansion of the network scale and the increase in data volume, the demand for querying label graphs is also growing day by day, especially reachability queries under label constraints.
[0003] However, traditional query methods often struggle to meet the strict requirements for data privacy protection. Specifically:
[0004] Key management problem: Traditional solutions often lack a systematic key generation and distribution mechanism, and are unable to provide secure and reasonable keys for different parties, making data vulnerable to theft or tampering during transmission and storage;
[0005] Encryption and indexing problems of graph data: Existing graph data encryption methods are not perfect in constructing secure indexes and cannot meet the security requirements under complex label constraints, resulting in the risk of illegal access or cracking of graph data stored on the cloud platform. Moreover, without a secure index, the query process needs to traverse more data, increasing the risk of information leakage;
[0006] Privacy protection problem in the query process: When the cloud platform processes queries, due to the lack of an effective secure subset verification protocol, it cannot perform secure filtering on constraints, which not only leads to privacy leakage but may also affect the accuracy and reliability of query results.
[0007] Therefore, the present invention proposes a label-constrained K-step reachability query method for privacy protection on a label graph, which provides a more secure and efficient solution for querying label graph data through a series of algorithms such as innovative key generation, encryption, and secure subset verification. Summary of the Invention
[0008] The purpose of the present invention is to overcome the deficiencies of the prior art and provide a label-constrained K-step reachability query method for privacy protection on a label graph to solve the problems raised in the above background art.
[0009] The purpose of the present invention can be achieved through the following technical solutions: A label-constrained K-step reachability query method for privacy protection on a label graph, including:
[0010] Step 1, key generation phase: The key generation center generates various keys and distributes them to different users, the cloud platform, and the computing service provider in the system model;
[0011] Step 2, Graph Encryption Phase: Based on the directed labeled graph, the user calls the Graph Enc algorithm to construct a secure index and sends it to the cloud platform for storage;
[0012] Step 3, Query Trapdoor Phase: When the user initiates a label-constrained K-step reachability query, the Token Gen algorithm is called to generate a query trapdoor and send it to the cloud platform;
[0013] Step 4, Query Phase: The cloud platform calls the Query algorithm to perform a privacy-preserving label-constrained K-step reachability query on the secure index, interacts with the computing service provider protocol through the designed secure subset verification protocol, obtains the encrypted query result, and sends it to the user;
[0014] Step 5, Decryption Phase: The user calls the Decrypt algorithm to decrypt the query result returned by the cloud platform.
[0015] Preferably, for Step 1, the key generation phase specifically includes:
[0016] The key generation center uses the Key Gen algorithm to generate a key set K key ; Set the security parameter λ, and the key generation center executes the Key Gen algorithm, a key k, a key pair (pk, sk), a hash function H, and a set of hash values H;
[0017] Among them, the length of the key is determined by the security parameter λ; pk and sk are the public key and private key of BGN respectively, and H is used for the array comparison protocol;
[0018] The key generation center sends k, pk, and sk to the user, sends pk to the cloud platform, and sends sk and (H, H) to the computing service provider.
[0019] Preferably, for Step 2, the graph encryption phase specifically includes:
[0020] Given a directed labeled graph G and a key set K key , the user calls the Graph Enc algorithm to construct a secure index
[0021] Generate an index Δ = {Δout, Δin} for the directed labeled graph G; where, Δout is the out-entry set; Δin is the in-entry set;
[0022] Initialize two dictionaries I out and I in , which are respectively used to store the encrypted out-entry set Δout and the encrypted in-entry set Δin;
[0023] For each node u ∈ V, its incoming entry set Δout(u) is encrypted; the hash function h(k, u||0) is computed by the algorithm to obtain T out,u , which is used to mark the position of Δout(u) in I out ;
[0024] For each entry (v, L u,v , d u,v ) ∈ Δout(u), the algorithm hides the node identifier by computing h(k, v); initialize a list EL u,v , which is used to store the encrypted L u,v ;
[0025] For each label l ∈ L u,v , the algorithm computes h(k, l) to hide the label l, and encrypts l′ using BGN.Enc(pk, l) to obtain the encrypted hidden label [l′]; where, [] represents the data after BGN encryption;
[0026] For the distance d u,v , it is encrypted as [d u,v using BGN.Enc(pk, d u,v , and (F v , EL u,v , [d u,v ) is added to I out [T out,u ; where, the generation process of I in is similar to I out ;
[0027] Output a secure index and send it to the cloud platform.
[0028] Preferably, for step 3, the query trapdoor phase specifically includes:
[0029] When the user initiates a query , the Token Gen algorithm is called to generate the query trapdoor τ u,v ;
[0030] By computing h(k, u||0) and h(k, v||1) through the algorithm, T out,u and T in,v are obtained respectively, which are used to locate in the index and
[0031] Initialize a list Q, which is used to store the encrypted label constraint set S; for each label l ∈ S, l′ is obtained by computing h(k, l) through the algorithm, and it is further encrypted as [l′] using BGN.Enc(pk, l′);
[0032] For the value of K, encrypt it as [K] using BGN.Enc(pk, K);
[0033] Finally, the algorithm outputs a query trapdoor τ u,v ={T out,u , T in,v , Q, [K]} and send it to the cloud platform.
[0034] Preferably, for step 4, the query phase specifically includes: when the cloud platform receives the query trapdoor τ u,v , call the Query algorithm to perform a privacy-preserving label-constrained K-step reachability query on the secure index; where, use the secure index and the query trapdoor τ u,v as inputs, and output the encrypted query result [f * ;
[0035] First, parse τ u,v to obtain {T out,u , T in,v , Q, [K]}; initialize the candidate set tmp to store encrypted path label and step value tuples;
[0036] Traverse each entry in I out [T out,u and I in [T in,v ;
[0037] If there exists (F t , EL u,t , [d u,t ) ∈ I out [T out,u and (F r , EL r,v , [d r,v ) ∈ I in [T in,v satisfying F t = F r , then the algorithm merges EL u,t and EL r,v into EL u,v , and calculates the step numbers of [d u,t and [d r,u and [d i ;
[0038] Incorporate the tuple (EL i , [d i ) into the candidate set tmp, and judge whether the candidate set tmp satisfies the step constraint; initialize an encrypted query result [f *, for each (EL i , [d i ) ∈ tmp, the algorithm calculates ADD([1], g([K], [d i ) -1 ) to obtain [w i ;
[0039] Among them, if w i = 0, it indicates that K ≥ d i ; if w i = 1, it indicates that K < d i , indicating that the candidate set tmp satisfies the step constraint.
[0040] Preferably, the query phase further includes: calling a secure subset verification protocol to calculate SSV(EL i , Q) to obtain [f i , to determine whether the constraint is satisfied;
[0041] By homomorphically adding [w i and [f i , obtain If then it means that the tuple (EL i , [d i ) satisfies the label and step constraints;
[0042] By calculating to update [f * ; if there exists any one (EL u,v , [d i ) ∈ tmp that satisfies and Dist ≥ D i , then f * = 0;
[0043] Finally, the algorithm outputs an encrypted query result [f * .
[0044] Preferably, for the secure subset verification protocol described in step 4, it includes:
[0045] Based on BGN homomorphic encryption, a secure subset verification protocol is designed, taking X and Y as inputs and outputting an encrypted verification result [f]; where X and Y are two sets of encrypted integers by BGN, and their sizes are respectively represented as |X| and |Y|;
[0046] If f = 0, it means Otherwise,
[0047] By determining whether each element in X is an element in Y one by one, for the element [x in X i , the protocol gradually updates [f′ i to check whether x i is equal to an element in Y; where 0 ≤ i < |X|.
[0048] Preferably, for step 5, the decryption phase specifically includes:
[0049] When the user receives an encrypted query result [f * from the cloud platform, the Decrypt algorithm is called to obtain the query result; this algorithm calls BGN.Dec(sk, [f * ) to decrypt [f * ; if f * = 0, it means that the label-constrained K-step reachability query returns true; otherwise, it returns false.
[0050] Preferably, the key generation center is responsible for generating and distributing keys; it is used to execute the key generation algorithm to generate keys and distribute the generated keys to users, the cloud platform, and computing service providers in the system model;
[0051] As the owner of the graph data, the user executes the Graph Enc algorithm to establish a secure index based on the directed labeled graph and outsources it to the cloud platform;
[0052] As the initiator of the query, for each label-constrained K-step reachability query, execute the Token Gen algorithm to generate a query trapdoor and send it to the cloud platform; after receiving the result from the cloud platform, execute the decryption algorithm to obtain the final query result;
[0053] The cloud platform is responsible for storing the secure index and responding to label-constrained K-step reachability queries;
[0054] The computing service provider is responsible for providing online secure computing services, including cooperating with the cloud platform and being responsible for decrypting and re-encrypting intermediate results.
[0055] Compared with the existing solutions, the beneficial effects achieved by the present invention:
[0056] The present invention can effectively process label-constrained K-step reachability queries while ensuring the privacy of graph data;
[0057] The present invention designs a secure subset comparison protocol based on the BGN homomorphic encryption system, which can securely verify the subset relationship between two encrypted integer sets without exposing any label information;
[0058] By combining a secure two-hop index with a secure subset comparison protocol, the proposed solution can accurately determine whether there exists a path that satisfies the label constraints and has a length no greater than K between two query nodes without revealing the privacy of the graph data. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] The present invention will be further described below with reference to the accompanying drawings.
[0060] Figure 1 It is a flowchart of the present invention.
[0061] Figure 2 It is a schematic diagram of the system model.
[0062] Figure 3 It is for constructing a two-hop index instance graph.
[0063] Figure 4 It is a graph of the Key Gen algorithm.
[0064] Figure 5 It is a graph of the Graph Enc algorithm.
[0065] Figure 6 It is a graph of the Token Gen algorithm.
[0066] Figure 7 It is a graph of the Query algorithm.
[0067] Figure 8 It is a graph of the Decrypt algorithm.
[0068] Figure 9 It is a graph of the secure subset verification protocol. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0069] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments.
[0070] Please refer to Figures 1-9 , the present invention is a privacy-preserving label-constrained K-step reachability query method on a labeled graph, including:
[0071] Step 1, Key Generation Phase: The key generation center generates various keys and distributes them to different users, cloud platforms, and computing service providers in the system model;
[0072] Step 2, Graph Encryption Phase: The user constructs a secure index by invoking the Graph Enc algorithm based on the directed labeled graph and sends it to the cloud platform for storage;
[0073] Step 3, Query Trapdoor Phase: When the user initiates a label-constrained K-step reachability query, the Token Gen algorithm is called to generate a query trapdoor, which is then sent to the cloud platform;
[0074] Step 4, Query Phase: The cloud platform calls the Query algorithm to perform a privacy-preserving label-constrained K-step reachability query on the security index. By interacting with the computing service provider protocol using the designed secure subset verification protocol, an encrypted query result is obtained and sent to the user;
[0075] Step 5, Decryption Phase: The user calls the Decrypt algorithm to decrypt the query result returned by the cloud platform.
[0076] Figure 2 It is a schematic diagram of the system model, including: Key Generation Center, User, Cloud Platform, Computing Service Provider;
[0077] The Key Generation Center is responsible for generating and distributing keys; it executes the key generation algorithm to generate keys and distributes the generated keys to the user, cloud platform, and computing service provider;
[0078] As the owner of the graph data, the user executes the Graph Enc algorithm to establish a security index based on the directed labeled graph and outsources it to the cloud platform;
[0079] As the initiator of the query, for each label-constrained K-step reachability query, it executes the Token Gen algorithm to generate a query trapdoor and sends it to the cloud platform; after receiving the result from the cloud platform, it executes the decryption algorithm to obtain the final query result;
[0080] The cloud platform is responsible for storing the security index and responding to label-constrained K-step reachability queries;
[0081] The computing service provider is responsible for providing online secure computing services, including cooperating with the cloud platform and being responsible for decrypting and re-encrypting intermediate results.
[0082] Figure 3 To construct a two-hop index instance graph, based on the two-hop index to support fast queries, it is determined whether there is a path between two nodes that satisfies specific label and step constraints;
[0083] The method for constructing a two-hop index using the LK2H algorithm is as follows:
[0084] All nodes in the directed labeled graph G are sorted in descending order based on their degrees (i.e., the number of connections of the nodes) to optimize the search process and give priority to processing nodes with higher connection degrees;
[0085] For each node v, perform a forward and backward pruning breadth-first search BFS;
[0086] In the forward BFS, the algorithm starts from node v, explores all nodes reachable in one and two steps, and records the label information and the number of steps on the path;
[0087] The reverse BFS starts from the potential target nodes of node v, searches backward for the path to v, and further enriches the information in the index;
[0088] Through the forward and reverse BFSs, a comprehensive two-hop index is constructed, which contains the reachability information between each pair of nodes, as well as the labels and the number of steps on these paths;
[0089] It should be noted that this index can support fast queries to determine whether there is a path between two nodes that satisfies specific label and step constraints, which is beneficial to improving the efficiency and accuracy of label-constrained k-step reachability queries on graph data.
[0090] Figure 4 For the Key Gen algorithm graph, the key generation algorithm is executed by the key generation center, specifically including:
[0091] The key generation center uses the Key Gen algorithm to generate a set of keys K key ; Set the security parameter λ, and the key generation center executes the Key Gen algorithm, a key k, a key pair (pk, sk), a hash function H, and a set of hash values H;
[0092] Among them, the length of the key is determined by the security parameter λ; pk and sk are the public key and private key of BGN respectively, and H is used for the array comparison protocol;
[0093] The key generation center sends k, pk, and sk to the user, sends pk to the cloud platform, and sends sk and (H, H) to the computing service provider.
[0094] Figure 5 For the Graph Enc algorithm graph, the user executes the graph encryption algorithm and uploads the encrypted graph to the cloud platform, specifically including:
[0095] Given a directed labeled graph G and a set of keys K key , the user calls the Graph Enc algorithm to construct a secure index
[0096] Generate an index Δ = {Δout, Δin} for the directed labeled graph G; among them, Δout is the set of out entries; Δin is the set of in entries;
[0097] Initialize two dictionaries I out and I in , which are used to store the encrypted set of out entries Δout and the encrypted set of in entries Δin respectively;
[0098] For each node u ∈ V, its incoming entry set Δout(u) is encrypted; the hash function h(k, u||0) is computed by the algorithm to obtain T out,u , which is used to mark the position of Δout(u) in I out ;
[0099] For each entry (v, L u,v , d u,v ) ∈ Δout(u), the algorithm hides the node identifier by computing h(k, v); a list EL u,v is initialized to store the encrypted L u,v ;
[0100] For each label l ∈ L u,v , the algorithm computes h(k, l) to hide the label l, and encrypts l′ using BGN.Enc(pk, l) to obtain the encrypted hidden label [l′]; where, [] represents the data after BGN encryption;
[0101] For the distance d u,v , it is encrypted as [d u,v using BGN.Enc(pk, d u,v ), and (F v , EL u,v , [d u,v ) is added to I out [T out,u ; where, the generation process of I in is similar to I out ;
[0102] Output a secure index and send it to the cloud platform.
[0103] Figure 6 For the Token Gen algorithm diagram, when the user initiates a query for label-constrained K-step reachability query, the query trapdoor generation algorithm is called to generate the query trapdoor τ u,v , specifically including:
[0104] By computing h(k, u||0) and h(k, v||1) through the algorithm, T out,u and T in,v are obtained respectively, which are used to locate in the index and
[0105] Initialize a list Q to store the encrypted label constraint set S; for each label l ∈ S, l′ is obtained by computing h(k, l) through the algorithm, and it is further encrypted as [l′] using BGN.Enc(pk, l′);
[0106] For the value of K, it is encrypted as [K] using BGN.Enc(pk, K);
[0107] Finally, the algorithm outputs a query trapdoor τ u,v ={T out,u , T in,v , Q, [K]} and sends it to the cloud platform.
[0108] Figure 7 For the Query algorithm graph, after receiving the query trapdoor τ u,v , the cloud platform calls the query algorithm to perform a privacy-preserving label-constrained K-step reachability query on the secure index, specifically including: using the secure index and the query trapdoor τ u,v as inputs, and outputting the encrypted query result [f * ;
[0109] First, parse τ u,v to obtain {T out,u , T in,v , Q, [K]}; Initialize the candidate set tmp to store encrypted path label and step value tuples;
[0110] Traverse each entry in I out [T out,u and I in [T in,v ;
[0111] If there exists (F t , EL u,t , [d u,t ) ∈ I out [T out,u and (F r , EL r,v , [d r,v ) ∈ I in [T in,v that satisfies F t = F r , then the algorithm merges EL u,t and EL r,v into EL u,v , and calculates the step numbers of [d u,t and [d r,u and [d i ;
[0112] Incorporate the tuple (EL i , [d i ) into the candidate set tmp, and determine whether the candidate set tmp satisfies the step constraint; Initialize an encrypted query result [f *, for each (EL i , [d i ) ∈ tmp, the algorithm computes ADD([1], g([K], [d i ) -1 ) to obtain [w i ;
[0113] Among them, if w i = 0, it indicates that K ≥ d i ; if w i = 1, it indicates that K < d i , indicating that the candidate set tmp satisfies the step constraint;
[0114] Call the secure subset verification protocol, compute SSV(EL i , Q) to obtain [f i , to determine whether it satisfies constraint;
[0115] By homomorphically adding [w i and [f i , obtain If then it means that the tuple (EL i , [d i ) satisfies the label and step constraints;
[0116] By computing to update [f * ; if there exists any (EL u,v , [d i ) ∈ tmp that satisfies and Dist ≥ D i , then f * = 0;
[0117] Finally, the algorithm outputs an encrypted query result [f * .
[0118] Figure 8 For the Decrypt algorithm graph, specifically including:
[0119] When the user receives an encrypted query result [f * from the cloud platform, call the Decrypt algorithm to obtain the query result; this algorithm decrypts [f * by calling BGN.Dec(sk, [f * ); if f * = 0, it means that the label constraint K-step reachability query returns true; otherwise, return false.
[0120] Figure 9It is a protocol diagram for secure subset verification, which is used to verify the subset relationship between two encrypted integer sets. Specifically, it includes:
[0121] Based on BGN homomorphic encryption, a secure subset verification protocol (SSV) is designed. Among them, X and Y are two sets of integers encrypted by BGN, and their sizes are represented as |X| and |Y| respectively;
[0122] The described secure subset verification protocol takes X and Y as inputs and outputs an encrypted verification result [f]. If f = 0, it means Otherwise,
[0123] The basic idea of the secure subset verification protocol is to determine one by one whether each element in X is an element in Y. For the element [x i in X, the protocol gradually updates [f′ i to check whether x i is equal to an element in Y. Among them, 0 ≤ i < |X|;
[0124] If r i ′ = 0, it means [x i ∈ Y. After comparing all elements in X, the verification result [f] is calculated through the secure subset verification protocol The verification result after comparison is obtained through homomorphic addition operation to get the verification result [f].
Claims
1. A privacy-preserving label-constrained K-step reachability query method on a label graph, characterized in that: include: Step 1: Key generation phase: The key generation center generates various keys and distributes them to different users, cloud platforms, and computing service providers in the system model; Step 2: Graph encryption phase: Based on the directed label graph, the user calls the Graph Enc algorithm to build a secure index and sends it to the cloud platform for storage; Step 3, query trapdoor stage: When the user initiates a label-constrained K-step reachability query, the Token Gen algorithm is called to generate a query trapdoor and send it to the cloud platform; Step 4, Query phase: The cloud platform calls the Query algorithm to perform a privacy-preserving label-constrained K-step reachability query on the security index. It interacts with the computing service provider protocol using the designed security subset verification protocol to obtain the encrypted query result and sends it to the user. Step 5, Decryption phase: The user calls the Decrypt algorithm to decrypt the query results returned by the cloud platform.
2. The privacy-preserving label-constrained K-step reachability query method on a label graph according to claim 1, characterized in that: For step 1, the key generation phase specifically includes: The key generation center uses the Key Gen algorithm to generate the key set K key ; Set the security parameter λ, and the key generation center executes the Key Gen algorithm, a key k, a key pair (pk, sk), a hash function H and a set of hash values H; Among them, the length of the key is determined by the security parameter λ; pk and sk are the public key and private key of BGN respectively, and H is used for the array comparison protocol; The key generation center sends k, pk, and sk to the user, sends pk to the cloud platform, and sends sk and (H, H) to the computing service provider.
3. The privacy-preserving label-constrained K-step reachability query method on a label graph according to claim 2, characterized in that: For step 2, the graph encryption phase specifically includes: Given a directed labeled graph G and a key set K key , the user calls the Graph Enc algorithm to build a secure index Generate an index Δ={Δout,Δin} for the directed labeled graph G; where Δout is the set of outgoing entries; Δin is the set of incoming entries; Initialize two dictionaries I out and I in , used to store the encrypted outgoing entry set Δout and the encrypted incoming entry set Δin respectively; For each node u∈V, its entry set Δout(u) is encrypted; the hash function h(k,u||0) is calculated by the algorithm to obtain T out,u , used to mark Δout(u) at I out Position in For each entry (v, L u,v , d u,v )∈Δout(u), the algorithm hides the node identifier by calculating h(k,v); initialize a list EL u,v , used to store the encrypted L u,v ; For each label l∈L u,v , the algorithm calculates h(k, l) to hide the label l, and uses BGN.Enc(pk, l) to encrypt l′, and obtains the encrypted hidden label [l′]; where [] represents the data encrypted by BGN; For the distance d u,v , use BGN.Enc(pk, d u,v ) is encrypted as [d u,v ], and (F v , E.L. u,v ,[d u,v ]) Add to I out [T out,u ]; among them, I in The generation process is similar to I out ; Output a safe index And send it to the cloud platform.
4. The privacy-preserving label-constrained K-step reachability query method on a label graph according to claim 3, characterized in that: For step 3, the query trapdoor stage specifically includes: When a user initiates a query When , the Token Gen algorithm is called to generate the query trapdoor τ u,v ; By calculating h(k,u||0) and h(k,v||1) through the algorithm, we can get T out,u and T in,v , used to locate the index In and Initialize a list Q to store the encrypted label constraint set S; for each label l∈S, calculate h(k, l) through the algorithm to get l′, and use BGN.Enc(pk, l′) to further encrypt it to [l′]; For the K value, use BGN.Enc(pk, K) to encrypt it to [K]; Finally, the algorithm outputs a query trapdoor τ u,v ={T out,u , T in,v , Q, [K]} and sent to the cloud platform.
5. The privacy-preserving label-constrained K-step reachability query method on a label graph according to claim 2, characterized in that: For step 4, the query phase specifically includes: when the cloud platform receives the query trap τ u,v After that, the Query algorithm is called to perform a privacy-preserving label-constrained K-step reachability query on the secure index; and query trap τ u,v As input, and output the encrypted query result [f * ]; First, analyze τ u,v To obtain {T out,u , T in,v , Q, [K]}; Initialize the candidate set tmp to store the encrypted path label and step value tuple; Traversal I out [T out,u ] and I in [T in,v ] for each entry; If there is (F t , E.L. u,t ,[d u,t ])∈I out [T out,u ] and (F r , E.L. r,v ,[d r,v ])∈I in [T in,v ]Satisfy F t =F r , then the algorithm will EL u,t and EL r,v Merge to EL u,v , and calculate [d u,t ] and [d r,u ] and [d i ]; The tuple (EL i ,[d i ]) is incorporated into the candidate set tmp, and the candidate set tmp is judged whether it satisfies the step number constraint; an encrypted query result [f * ], for each (EL i ,[d i ])∈tmp, the algorithm calculates ADD([1], g([K], [d i ]) -1 ) obtain [w i ]; Among them, if w i =0, indicating K≥d i ; if w i =1, indicating K <d i , indicating that the step number constraint is satisfied for the candidate set tmp.
6. The privacy-preserving label-constrained K-step reachability query method on a label graph according to claim 5, characterized in that: The query phase also includes: calling the secure subset verification protocol, calculating SSV (EL i , Q) obtain [f i ] to determine whether it satisfies constraint; By adding [w i ] and [f i ] Homomorphic addition, we get if It means tuple (EL i ,[d i ]) satisfy the constraints of label and number of steps; By calculation To update [f * ]; If there is any (EL u,v ,[d i ])∈tmp satisfies And Dist ≥ D i , then f * =0; Finally, the algorithm outputs an encrypted query result [f * ].
7. The privacy-preserving label-constrained K-step reachability query method on a label graph according to claim 6, characterized in that: Verify the protocol for the secure subset described in step 4, including: Based on BGN homomorphic encryption, a secure subset verification protocol is designed, which takes X and Y as input and outputs an encrypted verification result [f]; X and Y are two sets of integers encrypted by BGN, and their sizes are represented as X and Y respectively; If f = 0, it means otherwise, By determining whether each element in X is an element in Y one by one, for an element in X [x i ], the protocol gradually updates [f′ i ] to check x i Is equal to an element in Y; where 0≤i<|X|.
8. The privacy-preserving label-constrained K-step reachability query method on a label graph according to claim 7, characterized in that: For step 5, the decryption phase specifically includes: When a user receives an encrypted query result from the cloud platform [f * ], the Decrypt algorithm is called to obtain the query result; the algorithm calls BGN.Dec(sk,[f * ]) to decrypt [f * ]; if f * =0, it means that the label-constrained K-step reachability query returns true; otherwise, it returns false.
9. The privacy-preserving label-constrained K-step reachability query method on a label graph according to claim 1, characterized in that: include: The key generation center is responsible for generating and distributing keys; Used to execute the key generation algorithm to generate keys and distribute the generated keys to users, cloud platforms, and computing service providers in the system model; As the owner of graph data, users execute the Graph Enc algorithm to build a secure index based on a directed label graph and outsource it to the cloud platform; As the query initiator, it executes the Token Gen algorithm for each label-constrained K-step reachability query, generates a query trapdoor and sends it to the cloud platform; after receiving the result from the cloud platform, it executes the decryption algorithm to obtain the final query result; The cloud platform is responsible for storing the security index and responding to label-constrained K-step reachability queries; The computing service provider is responsible for providing online secure computing services, including cooperating with the cloud platform, and is responsible for decrypting and re-encrypting intermediate results.