Multi-keyword searchable encryption method and system based on block chain

By adopting a blockchain-based multi-keyword searchable encryption method in cloud computing and big data processing environments, the problems of low efficiency, poor security and difficult search results in the prior art are solved, and efficient, safe and reliable multi-keyword search functions are realized.

CN120124089AActive Publication Date: 2025-06-10COMMUNICATION UNIVERSITY OF CHINA
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510243608.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-03
Publication Date
2025-06-10
Estimated Expiration
2045-03-03

AI Technical Summary

Technical Problem

The prior art is difficult to achieve efficient multi-keyword search in cloud computing and big data processing environments, and there are problems such as file injection attacks and search results verification.

Method used

A multi-keyword searchable encryption method based on blockchain is adopted, and the system parameters are generated through the trust center, the dictionary sets on the blockchain and cloud servers are updated, and the search results are verified using the counting Bloom filter lookup table to realize parallel search of multi-chain radial structure.

Benefits of technology

It realizes efficient multi-keyword search, ensures forward and backward security, and improves the reliability and fairness of search results through blockchain verification mechanism.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120124089A_ABST
    Figure CN120124089A_ABST
Patent Text Reader

Abstract

The invention provides a multi-keyword searchable encryption method and system based on a block chain, and belongs to the technical field of information security, and the method comprises the following steps: S1, a trust center takes a security parameter lambda as an input, and outputs a system parameter sigma; s2, updating a block chain end dictionary set Dic1 and a cloud server end dictionary set Dic2, sending an updated encrypted file to a cloud server, and sending an update set Up to a block chain; s3, the client generates a corresponding search token set; s4, the cloud server performs retrieval and sends a result to the client, and the client obtains the RCBF based on the result; s5, the block chain obtains the BCBF according to the search token, the BCBF and the block chain perform verification, and a verification result is sent to the client; and S6, if the verification is valid, the client performs screening and requests a real file. According to the method, the ciphertext retrieval efficiency is improved, the reliable and fair verification of the search result is realized, and the communication and calculation cost is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of information security, and particularly relates to a multi-keyword searchable encryption method and system based on blockchain. Background Art

[0002] With the increasing demands for information security and privacy protection, especially in environments such as cloud computing and big data processing, traditional encryption methods are facing huge challenges. These methods usually require decrypting the data after encryption before performing searches on it, resulting in a conflict between efficiency and privacy protection.

[0003] Searchable Symmetric Encryption (SSE) enables direct keyword searches on encrypted data, which can not only ensure data confidentiality but also improve query efficiency. Static SSE does not support document operations required in many practical applications, such as creation, update, and deletion. Therefore, researchers began to focus on Dynamic Searchable Symmetric Encryption (DSSE). However, in general DSSE schemes, when data is dynamically updated, an adversary can recover the retrieved keywords through file injection attacks, exposing the key information. Thus, to resist file injection attacks, forward security was proposed to ensure that it is impossible to determine whether newly added files contain previously retrieved keywords.

[0004] If forward security guarantees security during addition, then security during deletion is achieved by backward security. Backward security aims to prevent leakage related to deleted entities. Bost et al. proposed a formal definition of backward security. Ghareh Chamani et al. improved the previous results in terms of computational cost and security level and proposed three new schemes. When considering forward / backward security construction, it usually leads to a large communication overhead for updates, especially when considering both security forms simultaneously.

[0005] The verifiability of search results is another important research topic of SSE. Since the cloud server is untrusted and may return incorrect or incomplete results due to system failures or cost savings, it is necessary to verify the search results. In 2012, Chai proposed the concept of verifiable searchable symmetric encryption (VSSE) and constructed a verifiable SSE scheme based on word trees. Shi et al. proposed a multi-user SE scheme that supports dynamic updates and verification using B+ trees and counting Bloom filters. Wang et al. designed a VSE scheme using AVL trees, where the stored path information can verify the correctness and integrity of search results. Wu et al. constructed a verifiable multi-user forward-secure SE scheme that realizes the verification feature using multi-set hash functions. Most of the existing schemes creatively use some novel data structures to assist in verification, but they all assume that there is a trusted / specific entity to verify the search results. However, due to external / internal attacks or configuration errors, this assumption may not always hold in practical applications. Secondly, some verification mechanisms are still impractical in terms of performance. In recent research, some researchers have introduced blockchain-based methods into SE to verify search results, ensuring the fairness and reliability of verification.

[0006] However, the above-mentioned schemes can support basic single-keyword searches, while complex search expressions are an inevitable requirement for efficient searches in reality. Although there are some DSSE schemes that satisfy forward security or backward security and guarantee join queries, they lack non-join query methods and the former two lack verification mechanisms. Summary of the Invention

[0007] To solve the above technical problems, the present invention provides a blockchain-based multi-keyword searchable encryption method, which includes the following steps:

[0008] Step S1: The trusted center TC takes the security parameter λ as input and outputs the system parameter σ;

[0009] Step S2: According to the given documents, keywords, and the keys in σ, update the blockchain-side dictionary set Dic 1 and the cloud server-side dictionary set Dic 2 , generate a counting Bloom filter lookup table CBFList, send the updated encrypted file to the cloud server, and send the update set U p containing all the updates this time to the blockchain;

[0010] Step S3: The client, according to the keyword set (w 1 , w 2 ,…, wq ) Generate the corresponding set of search tokens searchtoken;

[0011] Step S4: The cloud server uses searchtoken and Dic 2 to perform a search and obtain the search result R search and send it to the client. The client decrypts and maps R search to obtain the RCBF for this search;

[0012] Step S5: The blockchain obtains the BCBF for this search based on searchtoken, uses RCBF and BCBF for verification, and sends the verification result to the client;

[0013] Step S6: If the verification result is valid, the client filters the target subset and finally requests the real file from the cloud server.

[0014] Advantageous effects:

[0015] 1. The present invention discloses a blockchain-based multi-keyword searchable encryption method, and designs a new index structure stored on the server. This multi-chain radial structure allows the server to perform dual parallelism. The first layer enables the server to search each chain corresponding to the token in parallel, and the second layer enables the cloud server to simultaneously find all corresponding ciphertexts when restoring the previous state, while maintaining forward security, and supports backward security by encrypting the search results.

[0016] 2. The present invention allows the client to only save the latest token of the keyword to be queried, greatly saving the storage cost of the client, realizing efficient multi-keyword search, and realizing conjunctive queries and disjunctive queries within an accurate range by using the blockchain and the counting Bloom filter for search result verification. On the basis of the search results of a large-scale database, further cross the results with the target subset of the client, and finally the required accurate file can be obtained. Description of the drawings

[0017] Figure 1 It is a schematic flowchart of a blockchain-based multi-keyword searchable encryption method of the present invention;

[0018] Figure 2 It is a timing diagram of a blockchain-based multi-keyword searchable encryption method in an embodiment of the present invention;

[0019] Figure 3 It is a structural block diagram of a blockchain-based multi-keyword searchable encryption system of the present invention. Detailed implementation manners

[0020] To make the objectives, technical solutions and advantages of the present invention more comprehensible, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only for explaining the present invention and are not intended to limit the present invention. In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.

[0021] The method of the present invention involves three entities: a client, a cloud server, and a blockchain. The client updates the file according to the updated trapdoor and sends the updated encrypted file to the cloud server. At the same time, the client generates a corresponding set of search tokens according to the keyword set to be queried this time and sends them to the cloud server and the blockchain. The cloud server parallelly searches for all matching data on the multi-chain radial structure according to the search tokens and returns the found results to the client. The client decrypts the results returned by the server into the form of ind||op, maps each entry in the decryption result into the form of RCBF, and then submits it to the blockchain. The blockchain compares and verifies the RCBF with the CBF evidence stored in itself to achieve the purpose of public verification. If the verification result returns as accepted, the client can further match the files in the target subset with the results in the RCBF to achieve the purpose of implementing conjunctive queries and disjunctive queries. Based on the information provided above, the client is responsible for updating the files and evidence, the cloud server is responsible for searching for relevant files, and the blockchain is responsible for storing evidence and verifying the search results.

[0022] Embodiment 1

[0023] As Figure 1 shown, a multi-keyword searchable encryption method based on blockchain provided by an embodiment of the present invention includes the following steps:

[0024] Step S1: The trusted center TC takes the security parameter λ as input and outputs the system parameter σ;

[0025] Step S2: According to the given document, keywords, and the keys in σ, update the dictionary set Dic 1 on the blockchain side and the dictionary set Dic 2 on the cloud server side, generate the counting Bloom filter lookup table CBFList, send the updated encrypted file to the cloud server, and send the update set U p containing all the updates this time to the blockchain;

[0026] Step S3: The client generates a corresponding set of search tokens searchtoken according to the keyword set (w 1 , w 2 , …, w q ) to be queried this time;

[0027] Step S4: The cloud server uses the searchtoken and Dic 2 to perform a search and obtain a search result R search and send it to the client. The client decrypts and maps R search to obtain the RCBF for this search;

[0028] Step S5: The blockchain obtains the BCBF for this search based on the searchtoken, uses the RCBF and BCBF for verification, and sends the verification result to the client;

[0029] Step S6: If the verification result is valid, the client filters the target subset and finally requests the real file from the cloud server.

[0030] In one embodiment, the above Step S1: The trust center TC takes the security parameter λ as input and outputs the system parameter σ, specifically including:

[0031] Step S11: The trust center TC generates a master key MK and the private key sk of the client based on λ; the private key sk and the master key MK are XOR - operated to generate sk′;

[0032] Step S12: h i are four different hash functions, i ∈ [1,4]. The input lengths of the hash functions are the same, the output results are different, but the result lengths are the same. F(·) is a pseudorandom function, Enc(·) / Dec(·) is a symmetric encryption / decryption algorithm, and the function F(·) is used to generate the encryption / decryption key of Enc(·) / Dec(·);

[0033] Step S13: Package F(·), Enc(·) / Dec(·), and MK into the system parameter σ=(h i ∈ [1,4], F(·), Enc(·) / Dec(·), MK).

[0034] The present invention encrypts data through hash functions, pseudorandom functions, and symmetric encryption / decryption algorithms, and uses the one - way property and collision - resistance of hash functions to protect the security and privacy of data.

[0035] In one embodiment, the above Step S2: According to the given document, keywords, and the key in σ, update the blockchain - side dictionary set Dic 1 and the cloud - server - side dictionary set Dic 2 , generate a counting Bloom filter lookup table CBFList, send the updated encrypted file to the cloud server, and send the update set U p containing all the updates this time to the blockchain, specifically including:

[0036] Step S21: The client obtains k and k' respectively through the function function based on sk and sk', and combines the current version number to obtain the latest token of the current version , where store it in the blockchain-side dictionary set Dic 1 , and the client and the cloud server interact with the blockchain to access and store the content of Dic 1 ;

[0037] Step S21 is shown in lines 1 - 4 of Algorithm 1 below.

[0038] Step S22: The client encrypts each keyword-index pair under the current version through the hash function h to obtain two encrypted binary tuples and , where the keyword-index pair is the binary tuple (w i and keyword w j consisting of j , f i );

[0039] h among the 4 hash functions constructed in Step S12 1 and h 2 take as input to obtain the first encrypted index binary tuple , h 3 and h 4 take (m, ) as input to obtain the second encrypted index binary tuple , where m is the serial number of this batch of files to be updated;

[0040] Step 22 is shown in lines 5 - 24 of Algorithm 1 below.

[0041] Step S23: The client sends and to the cloud server to update the cloud server dictionary set Dic 2 ;

[0042] Step S24: While encrypting, the client encapsulates all the encrypted keyword-index pair information of the current keyword w j under the current version into a triple ( ) and stores it in the update set U p , where is the mapping of the update record of the keyword w j under the current version ; store the update set U pSent to the blockchain;

[0043] Among them, the version number is a randomly generated string of length λ, for example: F|Ig)%uLbwrX17GK<!nCfyiJvCsaS|H;kHg6+5 y, The subscript of represents the number of the version. Step S24 specifically includes the following sub-steps:

[0044] Step S241: Read out each update record from (DB(w j ), op), where DB(w ), represents the set of indexes ind related to w j in this update; op represents the add / delete operation of ind in this update; j

[0045] Step S242: According to , map the ind among them to according to its op type;

[0046] Step S243: After directly concatenating ind and op into a string, use a symmetric encryption algorithm to encrypt it to obtain the encrypted update record indop;

[0047] Step S244: Store the triple ( j ) covering all update records related to w ) into the set U p and send it to the blockchain;

[0048] Step S25: The blockchain saves the latest update record of the keyword w p to the counting Bloom filter lookup table CBFList according to U j to facilitate the verification operation in the subsequent stage.

[0049] Algorithm 1: Index construction algorithm

[0050] Client:

[0051] 1:

[0052] 2:

[0053] 3:

[0054] 4: and

[0055] 5:

[0056] 6:

[0057] 7: then

[0058] 8:set

[0059] 9:else

[0060] 10:

[0061] 11:end if

[0062] 12:

[0063] 13:

[0064] 14:

[0065] 15:

[0066] 16:

[0067] 17:

[0068] 18:

[0069] 19:

[0070] 20:

[0071] 21:

[0072] 22:end for

[0073] 23:

[0074] 24: end for

[0075] 25: Send to CS

[0076] 26: Send to CS

[0077] 27: Send to BC

[0078] The present invention aims to improve the data query efficiency by constructing an encrypted index structure.

[0079] In one embodiment, the above step S3: The client generates a corresponding search token set searchtoken according to the keyword set (w 1 , w 2 , …, w q ) queried this time, specifically including:

[0080] Step S31: The client obtains the version number from Dic 1 ; ;

[0081] Step S32: For each keyword w j , the client combines σ and to generate their respective corresponding search traps , and these search tokens constitute the search token set searchtoken;

[0082] Step S33: The client combines the keyword sequence number j and the corresponding search trap into a binary tuple ( ) j∈[1,q] , and sends it to the cloud server and the blockchain.

[0083] In one embodiment, the above step S4: The cloud server uses searchtoken and Dic 2 to perform a retrieval, obtains the search result R search and sends it to the client, and the client decrypts and maps R search to obtain the RCBF of this search, specifically including:

[0084] Step S41: After receiving the query request, the cloud server parses out the search tokens corresponding to each keyword from the binary tuple ( ) j∈[1,q] ; ;

[0085] Step S42: The cloud server performs a parallel search under the multi-chain radial index structure through the search tokens, specifically including:

[0086] Step S421: Obtain 1 through h , and use as the key value of Dic 2 ;

[0087] Step S422: Since is obtained by through h 2 XORed with , and is Dic2 's value;

[0088] Step S423: Obtain the database size in the state and the previous state of the link :

[0089] ⊕ (1)

[0090] Step S424: For each search record in the state, specifically including:

[0091] Step S4241: Each search record corresponds to a number m, where m ∈ [1, ;

[0092] Step S4242: (m, ) obtains 3 through h , and takes as the key value of Dic 2 ;

[0093] Step S4243: Since is obtained by XORing (m, ) through h 4 with , and is used as the value of Dic 2 ;

[0094] Step S4244: Obtain each search record in the state through the following formula (2): :

[0095] ⊕ (2)

[0096] Step S425: Merge into the result set of keyword w j according to the following formula (3):

[0097] ← (3)

[0098] Step S426: After searching each relevant chain, merge all search results into R search according to the following formulas (4) - (5), and perform a search for the previous state:​​

[0099] R search ← R search ∪ (4)

[0100] ← (5)

[0101] Step S425: For the next state , still execute Steps S421 - S426 until all the states on the chain are searched.

[0102] Step S43: The cloud server merges the final search results on each independent chain into the search result set R search and sends R search to the client;

[0103] Step S44: The client decrypts each update record in R search into the form of ;

[0104] Step S45: The client simplifies the results into the Ind set according to the operation type in . The operation types are add or del, specifically including:

[0105] Step S451: The client intercepts according to the decrypted ;

[0106] Step S452: If , add to the Ind set;

[0107] Step S453: If , add to the del set;

[0108] Step S454: After processing each update record, simplify the Ind result set according to formula (6):

[0109] ← (6)

[0110] The multi - chain parallel retrieval of the present invention is that the cloud server uses the search token set searchtoken and the dictionary Dic 2 to perform iterative search on each chain and finally obtain the search result R search .

[0111] Step S46: The client maps Ind to the counting Bloom filter to obtain the RCBF reflecting the search results of this time;

[0112] Step S47: The client sends the RCBF to the blockchain for verification.

[0113] Algorithm 2: Search algorithm

[0114] 1:

[0115] 2:

[0116] 3: do

[0117] 4:

[0118] 5:

[0119] 6:

[0120] 7:

[0121] 8:

[0122] 9:

[0123] 10:

[0124] 11:

[0125] 12:

[0126] 13: end for

[0127] 14:

[0128] 15:

[0129] 16: end while

[0130] 17: end for

[0131] 18: Send to Client

[0132] In one embodiment, the above step S5: The blockchain obtains the BCBF of this search according to the searchtoken, uses the RCBF and the BCBF for verification, and sends the verification result to the client, specifically including:

[0133] Step S51: The blockchain reads out the CBF corresponding to this keyword from the CBFList according to each search token in the searchtoken set , j ;

[0134] Step S52: Add all the CBFs j to BCBF one by one;

[0135] Step S53: The blockchain compares BCBF with RCBF. If the two are equal, the verification is successful, and it sends Accept to the client. If they are not equal, the verification fails, and it sends Reject to the client.

[0136] Algorithm 3: Verification Algorithm

[0137] 1: BCBF

[0138] 2: for each st do

[0139] 3: BCBF BCBF + CBFList[st]

[0140] 4: end for

[0141] 5: if RCBF == BCBF then

[0142] 6: Accept

[0143] 7: else

[0144] 8: Reject

[0145] 9: end if

[0146] The data verification of the present invention is a process in which the blockchain verifies the refined search result Ind returned by the cloud server. The blockchain finds the corresponding CBF from the list CBFList according to the search token set searchtoken j and accumulates it to obtain BCBF. Then, according to RCBF mapped from the Ind set, the two are compared. If they are equal, the verification is successful, and Accept is sent to the client. If they are not equal, the verification fails, and Reject is sent to the client.

[0147] In one embodiment, step S6: If the verification result is valid, the client filters the target subset and finally requests the real file from the cloud server, specifically including:

[0148] Step S61: Determine whether the user's query type is a join query or a non-join query;

[0149] Step S62: If it is a join query, filter out the target index numbers through the Repeat algorithm; if it is a non-join query, filter out the target index numbers through the Check algorithm.

[0150] Step S63: Send the finally filtered target index number set Finalset to the cloud server to request the real file.

[0151] The target subset screening of the present invention is that the client further screens the target set according to the RCBF reflecting the characteristics of this search.

[0152] Figure 2 It is the timing diagram of the multi-keyword searchable encryption method based on blockchain in the embodiment of the present invention.

[0153] Embodiment II

[0154] As Figure 3 shown, the embodiment of the present invention provides a multi-keyword searchable encryption system based on blockchain, including the following modules:

[0155] The system parameter acquisition module 71 is used for the trusted center TC to take the security parameter λ as the input and output the system parameter σ.

[0156] The update module 72 is used to update the blockchain-side dictionary set Dic 1 and the cloud server-side dictionary set Dic 2 respectively according to the given document, keyword and the key in σ, generate the counting Bloom filter lookup table CBFList, send the updated encrypted file to the cloud server, and send the update set U p containing all the updates this time to the blockchain.

[0157] The search token generation module 73 is used for the client to generate the corresponding search token set searchtoken according to the keyword set (w 1 , w 2 , …, w q ) of this query.

[0158] The retrieval module 74 is used for the cloud server to retrieve using searchtoken and Dic 2 to obtain the search result R search and send it to the client concurrently. The client decrypts and maps R search to obtain the RCBF of this search.

[0159] The verification module 75 is used for the blockchain to verify using RCBF and searchtoken and send the verification result to the client.

[0160] A screening module 76, configured to, if the verification result is valid, screen a target subset by the client, and finally request a real file from the cloud server.

[0161] A blockchain-based multi-keyword searchable encryption device, comprising one or more electronic devices, wherein the one or more electronic devices are configured to implement a blockchain-based multi-keyword searchable encryption method, system and device.

[0162] An electronic device, comprising: one or more processors; a memory for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors are caused to implement a blockchain-based multi-keyword searchable encryption method, system and device.

[0163] The above are only specific embodiments of the present invention, enabling those skilled in the art to understand or implement the present application. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the broadest scope consistent with the principles and novel features claimed herein.

Claims

1. A multi-keyword searchable encryption method based on blockchain, characterized in that: include: Step S1: The trusted center TC takes the security parameter λ as input and outputs the system parameter σ; Step S2: According to the given document, keyword and key in σ, update the blockchain dictionary set Dic1 and the cloud server dictionary set Dic2 respectively, generate the counting bloom filter lookup table CBFList, send the updated encrypted file to the cloud server, and send the update set U containing all the updates to the cloud server. p Send to blockchain; Step S3: The client searches for a keyword set (w1, w2, ..., w q ) Generate a corresponding search token set searchtoken; Step S4: The cloud server uses searchtoken and Dic2 to search and obtain the search result R search And send it to the client, the client responds to R search Perform decryption mapping to obtain the RCBF of this search; Step S5: The blockchain obtains the BCBF of this search based on the search token, verifies it using the RCBF and BCBF, and sends the verification result to the client; Step S6: If the verification result is valid, the client screens the target subset and finally requests the real file from the cloud server.

2. The multi-keyword searchable encryption method based on blockchain according to claim 1 is characterized in that: The step S1: the trust center TC takes the security parameter λ as input and outputs the system parameter σ, specifically including: Step S11: The trust center TC generates a master key MK and a private key sk of the client based on λ; the private key sk and the master key MK are subjected to an XOR operation to generate sk′; Step S12: h i are four different hash functions, i∈[1,4], the input lengths of the hash functions are the same, the output results are different, but the result lengths are the same, F(·) is a pseudo-random function, Enc(·) / Dec(·) is a symmetric encryption and decryption algorithm, and the function F(·) is used to generate the encryption and decryption keys of Enc(·) / Dec(·); Step S13: Encapsulate F(·), Enc(·) / Dec(·) and MK into system parameters σ=(h i ∈[1,4], F(·),Enc(·) / Dec(·), MK).

3. The multi-keyword searchable encryption method based on blockchain according to claim 2 is characterized in that: Step S2: According to the given document, keyword and key in σ, update the blockchain dictionary set Dic1 and the cloud server dictionary set Dic2 respectively, generate the counting bloom filter lookup table CBFList, send the updated encrypted file to the cloud server, and send the update set U containing all the updates this time. p Sent to the blockchain, including: Step S21: The client obtains k and k' respectively according to sk and sk' through the function function, and combines the current version number Get the latest token for the current version ,in Store the content in the blockchain dictionary set Dic1. The client and cloud server access the content of Dic1 by interacting with the blockchain. Step S22: The client Encrypt each keyword index pair in the current version through the hash function h to obtain two encrypted tuples and , where the keyword index pair is the document identifier f to be updated this time i and keyword w j The binary group (w j , f i ); Step S23: The client and Send to the cloud server to update the cloud server dictionary set Dic2; Step S24: While encrypting, the client sends the current keyword w j In the current version All encrypted keyword index information under is encapsulated into a triple ( ) and store it in the update set U p Among them, The keyword w j In the current version The following updates the mapping of the record; the set U will be updated p Send to blockchain; Step S25: Blockchain based on U p , replace the keyword w j The latest update record is saved in the counting bloom filter lookup table CBFList.

4. The multi-keyword searchable encryption method based on blockchain according to claim 3 is characterized in that: Step S3: The client searches for a keyword set (w1, w2, ..., w q ) Generate the corresponding search token set searchtoken, including: Step S31: The client obtains the version number from Dic1 ; Step S32: For each keyword w j , the client combines σ and Generate the corresponding search token , these search tokens form a search token set searchtoken; Step S33: The client sends the keyword serial number j and the corresponding search token Combined into two groups ( ) j∈[1,q] , sent to the cloud server and blockchain.

5. The multi-keyword searchable encryption method based on blockchain according to claim 4 is characterized in that: Step S4: The cloud server uses searchtoken and Dic2 to search and obtain the search result R search And send it to the client, the client responds to R search Decryption mapping is performed to obtain the RCBF of this search, including: Step S41: After receiving the query request, the cloud server selects the binary ( ) j∈[1,q] Parse the search tokens corresponding to each keyword ; Step S42: The cloud server performs parallel searches in a multi-chain radial index structure by searching for tokens; Step S43: The cloud server sends the final search results on each independent chain Merge into search result set R search and R search Send to the client; Step S44: The client sends R search Each update record in is decrypted into form; Step S45: The client The operation type in the result is simplified into an Ind set, where the operation type is add or del; Step S46: The client maps Ind to the counting Bloom filter to obtain the RCBF reflecting the search result of this time; Step S47: The client sends the RCBF to the blockchain for verification.

6. The multi-keyword searchable encryption method based on blockchain according to claim 4 is characterized in that: Step S5: The blockchain obtains the BCBF of the current search based on the search token, uses the RCBF and BCBF for verification, and sends the verification result to the client, specifically including: Step S51: The blockchain generates a search token based on each search token in the searchtoken set. , read the CBF corresponding to this keyword from CBFList j ; Step S52: All CBF j Add them one by one to BCBF; Step S53: The blockchain compares BCBF and RCBF. If they are equal, the verification is successful and Accept is sent to the client. If they are not equal, the verification fails and Reject is sent to the client.

7. The multi-keyword searchable encryption method based on blockchain according to claim 6 is characterized in that: Step S6: If the verification result is valid, the client screens the target subset and finally requests the real file from the cloud server, specifically including: Step S61: determining whether the user's query type is a connection query or a non-connection query; Step S62: If it is a connection query, the target index number is screened out by the Repeat algorithm; if it is a non-connection query, the target index number is screened out by the Check algorithm; Step S63: Send the final filtered target index number set Finalset to the cloud server to request the real file.

8. A multi-keyword searchable encryption system based on blockchain, characterized in that: Includes the following modules: The system parameter acquisition module is used for the trust center TC to take the security parameter λ as input and output the system parameter σ; The update module is used to update the blockchain dictionary set Dic1 and the cloud server dictionary set Dic2 according to the given document, keyword and key in σ, generate the counted Bloom filter lookup table CBFList, send the updated encrypted file to the cloud server, and send the update set U containing all the updates to the cloud server. p Send to blockchain; Generate a search token module, which is used by the client to generate a search token based on the keyword set (w1, w2, ..., w q ) Generate a corresponding search token set searchtoken; The retrieval module is used by the cloud server to search using searchtoken and Dic2 to obtain the search result R search And send it to the client, the client responds to R search Perform decryption mapping to obtain the RCBF of this search; Verification module, used to verify the blockchain using RCBF and searchtoken, and send the verification results to the client; The filtering module is used to filter the target subset by the client if the verification result is valid, and finally request the real file from the cloud server.

9. A multi-keyword searchable encryption device based on blockchain, characterized in that: The method comprises one or more electronic devices, wherein the one or more electronic devices are used to implement the method according to any one of claims 1 to 7.

10. An electronic device, characterized in that: include: one or more processors; A memory for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Verifiable semantic security multi-keyword search method in cloud storage

    CN109450935A

  • Attribute set-based searchable encryption method with forward and backward privacy

    CN117596085A

  • Data searchable encryption method based on on-chain and off-chain collaboration

    CN117896160A

  • Block chain assisted verifiable multi-keyword search encryption method

    CN118487828A

  • Verifiable wildcard ciphertext retrieval method based on TCBF-UBBT

    CN118690073A