An Encrypted Graph Shortest Path Query Method Satisfying Dual Constraints of Labels and Hop Counts
By constructing encrypted graph indexes and optimizing adjacency tables, the problem of too large search space in large-scale graph data queries is solved, and fast and safe shortest path query is achieved.
Patent Information
- Application Number
- CN202510518762.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-24
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2045-04-24
AI Technical Summary
In the large-scale graph data query, the existing technology fails to effectively use labels for rapid screening and pruning, resulting in too large search space and serious waste of computing resources.
By constructing an encrypted graph index, using symmetry, determinism and homomorphic encryption algorithms to generate authorization tokens, users generate query tokens, cloud servers perform deep priority traversal and combine label and hop constraints to perform shortest path query, optimize the adjacency table to eliminate nodes that do not meet the conditions.
It realizes rapid positioning of nodes and pruning, reduces redundant data storage and transmission, improves query efficiency, and ensures data security. Users can quickly obtain the shortest path query results that meet the dual constraints.
Smart Images

Figure CN120090863B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of secure communication, and more specifically, relates to a method for querying the shortest path of an encrypted graph that satisfies both label and hop count constraints. Background Art
[0002] The rapid development of cloud computing has promoted the widespread application of the cloud data outsourcing model in fields such as social networks, recommendation systems, bioinformatics, transportation networks, and power networks. Although this model is cost-effective and efficient, it also brings data privacy and security issues. Shortest path queries and label-based query operations frequently occur in these fields, posing high requirements for query efficiency and privacy protection. For example, in a social network, quickly finding common contacts or the shortest path through labels; in a recommendation system, predicting items that a user may be interested in through labels to provide accurate recommendation services.
[0003] Chinese Patent Document CN118364138A discloses a method for querying Skyline paths in a labeled time series graph. The method first defines a labeled time series graph and Skyline paths in the labeled time series graph; then constructs an MP index structure, which is divided into MP vertex lookup and Mout set construction steps; then invents a method for querying labeled Skyline paths based on the MP index; finally, as the time series graph changes, the index in this method can also be dynamically updated. This method not only considers time factors but also can meet the diverse query needs of users.
[0004] Chinese Patent Document CN114707012A discloses a method and system for querying the shortest path of graph encryption that supports k unordered nodes, including an environment composed of a user module and a cloud service module; the user module processes graph data to calculate a secure index for graph encryption, generates a query token based on the k unordered nodes of the query, uploads the secure index and the query token to the cloud service module, and waits to decrypt the shortest path after receiving the query result, otherwise waits for the query result all the time; the cloud service module receives the secure index and the query token from the user module, searches the secure index using the query token, and returns the shortest path passing through the k unordered nodes.
[0005] In the scenario of ciphertext query, the dual constraints of label and hop count and pruning techniques have not been fully studied. Currently, in the process of querying large-scale graph data, due to the failure to effectively use labels for fast screening and pruning, the search space is too large, resulting in serious waste of computing resources. Summary of the Invention
[0006] The present invention aims to overcome at least one defect of the above-mentioned prior art, and provides a method for querying the shortest path of an encrypted graph that satisfies the double constraints of labels and hops, so as to solve the problems of large search space and complex calculation when using labels to query the shortest path in the prior art.
[0007] The detailed technical solution of the present invention is as follows:
[0008] A method for querying the shortest path of an encrypted graph that satisfies the double constraints of labels and hops, the method includes:
[0009] S1. The data owner sends an authorization token to the user with a demand through a secure channel;
[0010] (1)
[0011] Among them, k1 is the key generated according to the symmetric encryption algorithm, k2 is the key generated according to the deterministic encryption algorithm, and sk is the private key in the key pair generated by the homomorphic encryption algorithm, which is used to decrypt the encrypted data;
[0012] S2. The data owner constructs an index for the original graph G, including a dictionary and an adjacency list, and sends the encrypted dictionary N and adjacency list P to the cloud server S;
[0013] S3. The user encrypts the query request using the key in the authorization token to generate a query token T, and sends it to the cloud server;
[0014] S4. After the cloud server S receives the query token T sent by the user, it performs a shortest path query on the encrypted dictionary N and encrypted adjacency list P sent by the data owner according to the information in T, and sends the query result to the user, including:
[0015] S41. The cloud server S first creates two empty dictionaries N1 and P1 and an empty set V1. N1 is used to store the information of encrypted nodes, P1 is used to store the updated adjacency list, and V1 is used to record the accessed nodes; subsequently, the cloud server S performs a query using the depth-first search DFS according to the start point information in the query token T, while being restricted by the hop number k; during the traversal process, when all accessible nodes have been traversed or the maximum hop number is reached, the query terminates, and finally the updated N1 and P1 are generated;
[0016] S42. In order to further optimize the query efficiency, the cloud server S checks the degree information of the nodes in N1 and identifies the nodes with a degree of 1: if the degree is 1 and it is not the query start point, the cloud server S performs node optimization processing through P1 to reduce redundant data and improve the query speed;
[0017] S43. The cloud server S queries the updated adjacency list P1, constructs all possible paths from the starting point to other nodes, and accumulates the weights of the edges when expanding the paths, finally generating a comparable set of paths paths;
[0018] S44. Finally, the cloud server S filters the paths in paths that meet the hop count constraint k: if there are feasible paths, compare the path weights, select the shortest path, and return it to the user; if there are no paths that meet the conditions, return a null value;
[0019] S5. After the user receives the query result sent by the cloud server S, use the key k1 in the authorization token to decrypt the nodes, obtain the plaintext result, and get the shortest path that meets the query conditions.
[0020] Preferably according to the present invention, the S1 specifically includes:
[0021] S1.1. The data owner generates a key k1 according to the symmetric encryption algorithm for subsequent node encryption; generates a key k2 according to the deterministic encryption algorithm for label encryption; and then generates a key pair (pk, sk) according to the homomorphic encryption algorithm, where pk is the public key for encrypting the weights of the nodes, and sk is the private key for decrypting the weights of the nodes.
[0022] S1.2. Form an authorization token containing the above keys , and send it to the user with a query request through a secure channel.
[0023] Preferably according to the present invention, the S2 specifically includes:
[0024] S2.1. The data owner first creates an empty dictionary N to store node information, including nodes, labels, and degrees; at the same time, creates an empty adjacency list P to record the adjacency relationships of each node and the weights of the edges;
[0025] S2.2. When processing the graph G, traverse all nodes, record their labels, and calculate the degrees of the nodes. The degree of a node refers to the sum of the in-degree and the out-degree; then, traverse the adjacent nodes of each node, record the adjacency relationships and the weights of the edges connected to the current node, and store them in the adjacency list P in the form of tuples; at the same time, update the dictionary N and the adjacency list P to ensure that the labels, degrees, and adjacency information of the nodes are kept up-to-date; repeat this process until all nodes in the graph G have been processed, finally generating a dictionary N containing the labels and degrees of each node, and an adjacency list P storing the adjacency relationships and weights;
[0026] S2.3. The data owner uses the symmetric encryption key k1 to encrypt the node information in the dictionary N and the adjacency list P, uses the deterministic encryption key k2 to encrypt the labels in the dictionary, and uses the public key pk generated by the homomorphic encryption algorithm to encrypt the weights in the adjacency list P; since the homomorphic encryption technology allows addition operations to be performed in the encrypted state, the weights can be directly added in the encrypted state; after completing all the above encryption operations, the encrypted dictionary N and the encrypted adjacency list P are finally obtained.
[0027] S2.4. The data owner sends the encrypted dictionary N and the adjacency list P to the cloud server S.
[0028] Preferably according to the present invention, the S3 specifically includes:
[0029] S3.1. The user encrypts the query request using the key in the authorization token to generate a query token :
[0030] (2)
[0031] where s is the starting point to be queried, w is the label to be queried, k is the limited hop count to be queried, is the value of s after symmetric encryption, is the value of w after deterministic encryption;
[0032] S3.2. The user sends the query token to the cloud server S.
[0033] Preferably according to the present invention, the S41 specifically includes the following steps:
[0034] After the cloud server S receives the query token T sent by the user, the cloud server S first creates two empty dictionaries N1 and P1 and an empty set V1. N1 is used to store the encrypted node information, P1 is used to store the updated adjacency list, and V1 is used to record the accessed nodes.
[0035] The cloud server S processes according to the node in the query token T using depth - first search DFS; at the same time, the cloud server S uses the hop count k in the query token T sent by the user as a limiting condition to control the traversal depth of the current node; the cloud server S traverses all successor nodes of the current node and passes the current hop count, and at the same time performs the following operations:
[0036] (1)Hop count limit check: If the current hop count exceeds the maximum hop count k, stop recursively processing this branch;
[0037] (2)Access check: When the cloud server S traverses all successor nodes of the current node, it first checks whether the successor node has been accessed:
[0038] If the successor node already exists in the set V1, indicating that it has been accessed, the recursive processing of this successor node is directly skipped;
[0039] If the successor node has not been accessed, mark this successor node as accessed and add it to the set V1 to prevent duplicate processing; at the same time, obtain the ciphertext label of this successor node and compare it with the label in the query token T:
[0040] If the ciphertext labels match, add this successor node, its adjacency relationship and weight with the current node to the updated adjacency list P1, and store the encrypted label and degree information of this successor node in the dictionary N1;
[0041] If the ciphertext labels do not match, record the information of this successor node in N1, and set its node degree to 0, indicating that this node is not connected to other nodes in the query result; at the same time, according to the encrypted adjacency list P1, identify all nodes connected to this successor node, subtract the number of edges connected to this successor node from the degrees of these nodes, and update the degree values of these nodes in N1; on this basis, directly prune the edges related to this successor node in P1 to ensure that the adjacency relationship reflects the latest state and complete the synchronous update of P1, thereby simplifying the graph structure and improving the query efficiency;
[0042] Repeat the above process to process all successor nodes until all nodes are traversed or the hop count k limit is reached;
[0043] Through the above series of operations, the cloud server S finally generates and obtains two main results: N1 and P1; N1 is the updated encrypted node information dictionary, recording the ciphertext label of each node and the latest degree information of the node, reflecting the state of the node after screening and processing; P1 is the updated adjacency list, containing the latest adjacency relationships that meet the label and hop count conditions and their corresponding edge weights, providing the basic data structure for subsequent path queries.
[0044] Preferably according to the present invention, the S42 specifically includes the following steps:
[0045] To further accelerate the retrieval speed, the cloud server S first checks the hop count k in the query token T, and according to the hop value, controls whether to perform the optimization operation of nodes with degree 1: If k = 1, skip the optimization process of nodes with degree 1 and directly enter the next step S43; If , perform the following operations: The cloud server S first checks the degree information of the nodes in the current N1 table, identifies the nodes with degree 1, and processes these nodes with degree 1 one by one; when processing each node with degree 1, first check whether the current node is the starting point Enc(k1, s) in the query token T. If the current node is the starting point Enc(k1, s), directly retain the node, do not perform the removal or storage logic, and skip the pruning operation of this node; if the node with degree 1 is not the starting point Enc(k1, s), then check whether the unique adjacent node of this node is the starting point Enc(k1, s) in the query token T through P1:
[0046] a): If the unique adjacent node is the starting point Enc(k1, s) in the query token T, then directly delete this node from N1 and P1, and synchronously update N1 and P1;
[0047] b): If the unique adjacent node is not the starting point in the query token T, then the server S only removes the record of this node itself in P1, and at the same time retains the edges connected to this node in P1;
[0048] Until all the nodes with degree 1 are processed, the cloud server S obtains the updated result P1;
[0049] According to a preferred embodiment of the present invention, the S43 specifically includes the following steps:
[0050] During the query process, the cloud server S generates paths that meet the hop limit k starting from the query starting point Enc(k1, s): The server first initializes the path storage list paths to record the paths that meet the hop conditions, including the node sequence and the cumulative weight value. At the same time, it initializes the queue queue to manage the nodes to be processed and their path information; at the initial stage, the server stores the initial path in the queue and starts generating paths from the starting point; subsequently, the server takes out the current node from the queue, finds the adjacent nodes of the current node in the adjacency list P1, extracts the names of the adjacent nodes and the weights of the connected edges, and updates the path information: expand the node sequence, accumulate the weights, and store the updated path in the queue for further processing; during the path expansion process, the server calculates the hop count in real time. If the hop count reaches the maximum limit k, stop the expansion and store the path in the paths list.
[0051] Compared with the prior art, the beneficial effects of the present invention are:
[0052] Through the pruning mechanism, the present invention can quickly locate nodes according to tags and perform pruning. At the same time, it optimizes the nodes with a pruning degree of 1, reducing the storage and transmission of redundant data. The data owner only needs to construct the basic information of the original graph and encrypt it, and then can securely send it to the cloud server, thereby reducing the storage cost. When processing a query request, the cloud server can quickly identify and eliminate the nodes that do not meet the conditions through the dual constraints of tags and hop counts, and perform the shortest path query, quickly responding and returning the results. Data security is guaranteed through multi-layer encryption technology and the authorization token mechanism. Users can obtain the shortest path query results that meet the dual constraint conditions more quickly, significantly improving the user experience. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] Figure 1 is a flowchart of a method for querying the shortest path of an encrypted graph that satisfies the dual constraints of tags and hop counts according to the present invention.
[0054] Figure 2 is the original graph G described in Embodiment 1 of the present invention.
[0055] Figure 3 is the dictionary and adjacency list of the original graph G described in Embodiment 1 of the present invention.
[0056] Figure 4 is the encrypted dictionary N and encrypted adjacency list P described in Embodiment 1 of the present invention.
[0057] Figure 5 is the updated dictionary N1 and adjacency list P1 described in Embodiment 1 of the present invention.
[0058] Figure 6 is the updated graph G' of the graph G after pruning the nodes that do not meet the tags described in Embodiment 1 of the present invention.
[0059] Figure 7 is the adjacency list P1 after pruning to a pruning degree of 1 described in Embodiment 1 of the present invention.
[0060] Figure 8 is the updated graph G'' of the graph G' after pruning to a pruning degree of 1 described in Embodiment 1 of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0061] The following further describes the present disclosure in conjunction with the drawings and embodiments.
[0062] Embodiment 1
[0063] This example provides a method for querying the shortest path of an encrypted graph that satisfies both label and hop count constraints, including the graph data owner, the user, and the cloud server. The graph data owner is the holder of the graph. Its main task is to send an authorization token to the user, construct a graph index based on the original graph G, and then send the encrypted graph index to the cloud server. The main task of the user is to receive the authorization token, generate a query request query=(S, Jinan, 3), that is, to find the shortest path starting from the starting point s that satisfies the dual constraints of the label "Jinan" and the hop count "3", encrypt the query request to generate a query token T, send it to the cloud server, and finally receive the ciphertext result sent by the cloud server and decrypt it to obtain the plaintext result of the query request. The cloud server is mainly responsible for receiving the encrypted data, processing the encrypted data according to the query token T sent by the user, calculating the encrypted result, and sending it to the user.
[0064] The specific steps are as Figure 1 follows:
[0065] S1. The data owner sends an authorization token to the user;
[0066] S2. The data owner constructs a graph index based on the original graph G and encrypts it and sends it to the cloud server;
[0067] S3. After receiving the authorization token, the user generates a query token T and sends it to the cloud server;
[0068] S4. The cloud server S performs a shortest path query according to the query token T and sends the query result to the user;
[0069] S5. The user receives the query result sent by the cloud server S and decrypts it to obtain the plaintext result.
[0070] Specifically, the S1 specifically includes:
[0071] S1.1: The data owner forms an authorization token and sends it to the user with a query request through a secure channel. The authorization token is as follows:
[0072] (1)
[0073] Among them, k1 is the key generated according to the symmetric encryption algorithm, k2 is the key generated according to the deterministic encryption algorithm, and sk is the private key in the key pair generated by the homomorphic encryption algorithm, which is used to decrypt the encrypted data.
[0074] Specifically, the S2 specifically includes:
[0075] S2.1: The data owner, according to the data information of the original graph G, as Figure 2 follows;
[0076] S2.3: During the process of processing the original graph G, first traverse and process each node in the original graph G. For each node, record its label and calculate the degree of the node, that is, the sum of the in-degree and out-degree of the node. Subsequently, initialize an adjacency list as an empty list and create an empty dictionary. Then, traverse all the adjacent nodes of the current node, record these adjacent nodes and the weights of the edges connected to the current node. For each processed adjacent node, add the adjacent node and its weight to the adjacency list of the current node in the form of a tuple. At the same time, update the dictionary to ensure that the information of each node, including the label, degree, and adjacency list, is up-to-date. Repeat this process until all nodes in the graph have been processed. Finally, generate a dictionary containing the labels and degrees of each node, and an adjacency list representing the adjacency relationship and weights, as Figure 3 shown.
[0077] S2.4: The data owner encrypts the nodes in the dictionary and the adjacency list using the symmetric encryption key k1, encrypts the labels in the dictionary using the deterministic encryption key k2, and encrypts the weights in the adjacency list using the public key pk generated by the homomorphic encryption algorithm, as Figure 4 shown.
[0078] S2.5: The data owner sends the encrypted dictionary N and adjacency list P to the cloud server S.
[0079] Specifically, S3 specifically includes:
[0080] S3: The user encrypts the query request using the key in the authorization token to generate a query token , and finally the user sends the query token to the cloud server;
[0081] (2)
[0082] where s is the starting point to be queried, is the label to be queried, 3 is the limited hop count to be queried, is the symmetrically encrypted value of s, is the deterministically encrypted value of.
[0083] Specifically, S4 specifically includes:
[0084] S4.1: The cloud server S receives the query token T sent by the user and processes the encrypted dictionary N and encrypted adjacency list P sent by the data owner according to the information in T;
[0085] S4.2: The cloud server S first creates two empty dictionaries N1 and P1 and an empty set V1. N1 is used to store information about encrypted nodes, P1 is used to store the updated adjacency list, and V1 is used to record the visited nodes;
[0086] S4.3: The cloud server S processes according to the nodes in the query token T using depth - first search DFS. At the same time, the cloud server S uses the hop count k = 3 in the query token T sent by the user as a limiting condition, that is, the maximum number of edges, to control the traversal depth of the current node. The cloud server S traverses all successor nodes of the current node and passes the current hop count. If the current hop count exceeds the maximum hop count k = 3, the recursion stops. If the successor node of the current node has not been visited, it is marked as visited and added to the set V1. At the same time, the label information of the successor node is obtained. Check whether the ciphertext label of its successor node matches the label in the query request. If the ciphertext label matches the label in the query request, the successor node and its weight are added to the updated adjacency list P1, and its information is stored in the dictionary N1. If the ciphertext label does not match, the cloud server S performs the following operations:
[0087] a): The cloud server S sets the degree of the successor node in the encrypted dictionary N to 0, indicating that the node is not connected to other nodes in the query result. For example, the label , the label is , the labels of the above two nodes do not match the label in the query request. At this time and the degrees of
[0088] in the encrypted dictionary N are set to 0. and b): For the nodes connected to the successor node in the encrypted adjacency list P are identified and processed, that is, the nodes connected to in P are , the nodes connected to are and . For each of the above nodes, the cloud server updates its degree, subtracting the number of edges connected to the node.
[0089] c): For the above nodes, the edges connected to the successor node in the encrypted adjacency list P are trimmed, and the encrypted adjacency list P is updated.
[0090] This process is repeated until all nodes are traversed or the maximum hop count k = 3 is reached.
[0091] S4.4: Through the above series of operations, the cloud server S finally generates and obtains two main results: N1 and P1. As shown in Figure 5 Figure, after the above pruning operations on the original graph G, the graph data G' is as shown in Figure 6 Figure.
[0092] S4.5: To further accelerate the retrieval speed, the cloud server S first checks the hop limit k in the query token T. At this time, k = 3, so pruning work with a degree of 1 can be carried out. Then, it checks the degree information of the nodes in the N1 table and identifies the nodes with a degree of 1, such as , . It can be seen that the above two nodes are not the starting points in the query token . Then, it checks whether the only adjacent node connected to the node with a degree of 1 through P1 is the starting point in the query token T :
[0093] a): If the connected adjacent node is the starting point in the query token T , then directly delete this node from N1 and P1. For example, if the connected node of is , then directly delete it and update N1 and P1.
[0094] b): If the connected node is not the starting point in the query token T. For example, at this time, the node with a degree of 1 . Delete its own record in P1 and retain the edge connected to this node in P1. For example, the adjacent edge in node is , then retain this edge.
[0095] Until all the nodes with a degree of 1 are processed, the cloud server S obtains the updated result P1, as shown in Figure 7 Figure. At this time, the graph data G' is updated to graph G'' after the above pruning operations, as shown in Figure 8 Figure.
[0096] S4.6: The cloud server S processes the updated adjacency list P1 using breadth - first search (BFS). First, the cloud server S initializes a list paths and a queue queue; then, the cloud server S puts into the queue. It can be seen that at this time, the adjacent node of in P1 is . Extract its node name to expand the path. At this time, the path is , and the weight is . At this time, the hop count is 1, so continue to expand the path. At this time, continue to search for the adjacent node of according to P1. It can be seen that it is And , first perform path expansion on . At this time, the path is , and the weight is . Then perform path expansion on . At this time, the path is , and the weight is . At this time, the hop count is 2 < 3, so continue the expansion. According to the above process, the generated paths are 、
[0097] . At this time, the hop count is 3 = 3, so it is put into paths.
[0098] S4.7: Finally, the cloud server S compares the path weights in paths, that is , so the shortest path is: , and send it to the user.
[0099] Specifically, the S5 specifically includes:
[0100] S5.1: The user receives the paths sent by the cloud server and decrypts them using the key k1 in the authorization token to obtain the shortest path from the starting point S within 3 hops with the identifier "Jinan" as S, D, B, C.
[0101] Obviously, the above embodiments of the present invention are merely examples for clearly explaining the technical solutions of the present invention, rather than limiting the specific implementation manners of the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the claims of the present invention shall be included within the protection scope of the claims of the present invention.
Claims
1. An encrypted graph shortest path query method that satisfies the dual constraints of labels and hop counts, characterized in that, The method includes: S1. The data owner sends an authorization token to the user in need through a secure channel; (1) where k1 is a key generated according to the symmetric encryption algorithm, k2 is a key generated according to the deterministic encryption algorithm, and sk is the private key in the key pair generated by the homomorphic encryption algorithm, which is used to decrypt the encrypted data; S2. The data owner constructs an index for the original graph G, including a dictionary and an adjacency list, and sends the encrypted dictionary N and adjacency list P to the cloud server S; S3. The user encrypts the query request using the key in the authorization token to generate a query token T and sends it to the cloud server; S4. After the cloud server S receives the query token T sent by the user, it performs a shortest path query on the encrypted dictionary N and encrypted adjacency list P sent by the data owner according to the information in T, and sends the query result to the user, including: S41. The cloud server S first creates two empty dictionaries N1 and P1 and an empty set V1. N1 is used to store information of encrypted nodes, P1 is used to store the updated adjacency list, and V1 is used to record the accessed nodes. Subsequently, the cloud server S performs a query using depth-first search (DFS) according to the starting point information in the query token T, while being restricted by the hop count k. During the traversal, when all accessible nodes have been traversed or the maximum hop count is reached, the query terminates, and finally, the updated N1 and P1 are generated; S41 specifically includes the following steps: After the cloud server S receives the query token T sent by the user, the cloud server S first creates two empty dictionaries N1 and P1 and an empty set V1. N1 is used to store information of encrypted nodes, P1 is used to store the updated adjacency list, and V1 is used to record the accessed nodes; The query token T includes a node , where the is the symmetrically encrypted value of the starting point s to be queried; The cloud server S processes according to the nodes in the query token T using depth - first search DFS; meanwhile, the cloud server S controls the traversal depth of the current node according to the hop count k in the query token T sent by the user; the cloud server S traverses the current node of all its successor nodes, passes the current hop count, and simultaneously performs the following operations: (1) Hop count limit check: If the current hop count exceeds the maximum hop count k, stop recursively processing this branch; (2) Access check: When the cloud server S traverses all successor nodes of the current node, it first checks whether the successor node has been accessed: If the successor node already exists in the set V1, indicating that it has been accessed, directly skip the recursive processing of this successor node; If the successor node has not been accessed, mark this successor node as accessed and add it to the set V1. At the same time, obtain the ciphertext label of this successor node and compare it with the label in the query token T: If the ciphertext labels match, add this successor node and its adjacency relationship and weight with the current node to the updated adjacency list P1, and store the encrypted label and degree information of this successor node in the dictionary N1; If the ciphertext labels do not match, record the information of this successor node in N1 and set its node degree to 0, indicating that this node is not connected to other nodes in the query result. At the same time, according to the encrypted adjacency list P1, identify all nodes connected to this successor node, subtract the number of edges connected to this successor node from the degrees of these nodes, and update the degree values of these nodes in N1. On this basis, directly prune the edges related to this successor node in P1 to ensure that the adjacency relationship reflects the latest state and complete the synchronous update of P1; Repeat the above process to process all successor nodes until all nodes are traversed or the hop count k limit is reached; Through the above series of operations, the cloud server S finally generates and obtains two main results: N1 and P1; N1 is the updated encrypted node information dictionary, which records the ciphertext tags of each node and the latest degree information of the node, reflecting the status of the nodes after screening and processing; P1 is the updated adjacency list, which contains the latest adjacency relationships that meet the label and hop count conditions and their corresponding edge weights, providing the basic data structure for subsequent path queries; S42. The cloud server S checks the degree information of the nodes in N1 and identifies the nodes with degree 1: if the degree is 1 and it is not the query starting point, the cloud server S performs node optimization processing through P1; S43. The cloud server S queries the updated adjacency list P1, constructs all possible paths from the starting point to other nodes, and accumulates the weights of the edges when expanding the paths, finally generating a comparable path set paths; S44. Finally, the cloud server S filters the paths that meet the hop count constraint k in paths: if there are feasible paths, compare the path weights, select the shortest path, and return it to the user; if there are no paths that meet the conditions, return a null value; S5. After receiving the query result sent by the cloud server S, the user decrypts the nodes using the key k1 in the authorization token to obtain the plaintext result and obtain the shortest path that meets the query conditions.
2. The shortest path query method for an encrypted graph that satisfies the dual constraints of labels and hop counts according to claim 1, wherein, The specific steps of S1 include: S1.
1. The data owner generates a key k1 according to the symmetric encryption algorithm for subsequent node encryption; generates a key k2 according to the deterministic encryption algorithm for label encryption; and then generates a key pair (pk, sk) according to the homomorphic encryption algorithm, where pk is the public key for encrypting the node weights and sk is the private key for decrypting the node weights; S1.
2. Form an authorization token containing the above key and send it to the user with a query request through a secure channel.
3. A method for querying the shortest path of an encrypted graph that satisfies both label and hop count constraints according to claim 1, characterized in that, The specific steps of S2 include: S2.
1. The data owner first creates an empty dictionary N to store node information, including nodes, labels, and degrees; at the same time, creates an empty adjacency list P to record the adjacency relationships of each node and the edge weights; S2.
2. When processing graph G, traverse all nodes, record their labels, and calculate the degree of the nodes. The degree of a node is the sum of the in-degree and out-degree; then, traverse the adjacent nodes of each node, record the adjacency relationships and the weights of the edges connected to the current node, and store them in the adjacency list P in the form of tuples; at the same time, update the dictionary N and the adjacency list P to ensure that the labels, degrees, and adjacency information of the nodes are kept up-to-date; repeat this process until all nodes in graph G are processed, finally generating a dictionary N containing the labels and degrees of each node, and an adjacency list P storing the adjacency relationships and weights; S2.
3. The data owner uses the symmetric encryption key k1 to encrypt the node information in the dictionary N and the adjacency list P, uses the deterministic encryption key k2 to encrypt the labels in the dictionary, and uses the public key pk generated by the homomorphic encryption algorithm to encrypt the weights in the adjacency list P. Homomorphic encryption technology allows addition operations to be performed in the encrypted state, and the weights can be directly added in the encrypted state. After completing all the above encryption operations, the encrypted dictionary N and the encrypted adjacency list P are finally obtained. S2.
4. The data owner sends the encrypted dictionary N and the adjacency list P to the cloud server S.
4. A method for querying the shortest path of an encrypted graph that satisfies the double constraints of tags and hop counts according to claim 1, characterized in that, The specific steps of S3 are as follows: S3.
1. The user encrypts the query request using the key in the authorization token Generate a query token : (2) Where s is the starting point to be queried, w is the label to be queried, and k is the limited number of hops to be queried. is the symmetrically encrypted value of s. is the deterministically encrypted value of w. S3.
2. The user sends the query token to the cloud server S.
5. A method for querying the shortest path of an encrypted graph that satisfies both label and hop count constraints according to claim 1, wherein The specific steps of S42 are as follows: To further accelerate the retrieval speed, the cloud server S first checks the hop count k in the query token T. According to the hop value, it controls whether to perform the optimization operation for nodes with degree 1: If k = 1, it skips the optimization process for nodes with degree 1 and directly proceeds to the next step S4.5; if , perform the following operations: The cloud server S first checks the degree information of the nodes in the current N1 table, identifies the nodes with degree 1, and processes these nodes with degree 1 one by one; when processing each node with degree 1, it first checks whether the current node is the starting point Enc(k1, s) in the query token T. If the current node is the starting point Enc(k1, s), it directly retains the node without performing the removal or storage logic and skips the pruning operation for this node; if the node with degree 1 is not the starting point Enc(k1, s), it checks whether the unique adjacent node of this node is the starting point Enc(k1, s) in the query token T through P1: a): When the unique adjacent node is the starting point Enc(k1, s) in the query token T, directly delete the node from N1 and P1, and synchronously update N1 and P1. b): When the unique adjacent node is not the starting point in the query token T, the server S only removes the record of the node itself in P1, while retaining the edges connected to the node in P1. Until all the degree-1 nodes are processed, the cloud server S obtains the updated result P1.
6. The shortest path query method for encrypted graphs satisfying both label and hop count constraints according to claim 1, characterized in that The specific steps of S43 are as follows: During the query process, the cloud server S starts from the query starting point Enc(k1, s) and generates paths that meet the hop limit k. The server first initializes the path storage list paths to record the paths that meet the hop conditions, including the node sequence and the cumulative weight. At the same time, it initializes the queue queue to manage the nodes to be processed and their path information. In the initial stage, the server deposits the initial path into the queue and starts generating paths from the starting point. Subsequently, the server takes out the current node from the queue, finds the adjacent nodes of the current node in the adjacency list P1, extracts the names of the adjacent nodes and the weights of the connected edges, updates the path information for path expansion: expands the node sequence, accumulates the weights, and deposits the updated path into the queue for further processing. During the path expansion process, the server calculates the hop count in real time. If the hop count reaches the maximum limit k, it stops expanding and stores the path in the paths list.
Citation Information
Patent Citations
Graph encryption shortest path query method and system supporting k disordered nodes
CN114707012A
Method for querying Skyline path in time sequence diagram with label
CN118364138A
Quantum cryptography network dynamic routing method
CN103001875A
Elastic large-bandwidth splitting method and device, electronic equipment and storage medium
CN114338557A