Frequency-hidden semantic-safe fuzzy searchable ciphertext query method

By using the AES ciphertext permutation algorithm and frequency hiding algorithm in fuzzy ciphertext query, the problems of inefficiency, large storage overhead and frequency information leakage in the prior art are solved, and efficient and secure fuzzy ciphertext query is achieved.

CN120144640AActive Publication Date: 2025-06-13NANKAI UNIV
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510292432.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-12
Publication Date
2025-06-13
Estimated Expiration
2045-03-12

AI Technical Summary

Technical Problem

The existing fuzzy ciphertext query methods have problems with plaintext frequency information leakage caused by inefficiency, high storage overhead, and deterministic encryption algorithms.

Method used

The AES-based ciphertext permutation algorithm and frequency-hidden ciphertext generation algorithm are used to encrypt plaintext data through encrypted permutation mapping table, and frequency-hidden ciphertext is generated through random iv and random position sequences to ensure query efficiency and security.

Benefits of technology

Improve the efficiency and security of fuzzy ciphertext query, avoid frequency information leakage, reduce storage overhead, and improve scalability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120144640A_ABST
    Figure CN120144640A_ABST
Patent Text Reader

Abstract

The invention belongs to the field of searchable ciphertext query, is mainly applied to fuzzy searchable ciphertext query of a relational database, and particularly relates to a frequency hidden semantic security fuzzy searchable ciphertext query method. A random iv value with the same length as the ciphertext is randomly generated for each row of deterministic ciphertext of fuzzy query, and the iv value and the ciphertext are subjected to XOR to generate a random ciphertext. And generating a random position sequence by the iv and the random ciphertext on the basis of each column, and inserting the random position sequence into a corresponding byte position of the final ciphertext, so as to generate a frequency hidden ciphertext with semantic security for fuzzy query.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of searchable encrypted text queries, and is mainly applied to the fuzzy searchable encrypted text queries of relational databases. More specifically, it relates to a frequency-hiding semantically secure fuzzy searchable encrypted text query method. Background Art

[0002] The fuzzy query of a database refers to a technology for searching the content in a database through flexible conditions when the data is not completely accurately matched. It allows users to use incomplete, partially correct, or approximate inputs to find target data, and is often used to handle situations where the information is incomplete or incorrect. For example, in the MYSQL database, to fuzzy query the records whose user names contain "Xiaohong", a fuzzy query statement can be constructed by using the like function in the where statement of the SQL query, such as select * from table where name like "%Xiaohong".

[0003] In today's big data era, the Internet is filled with a large amount of private data information of users. To protect the data privacy and security of users, the data is usually stored in the database in encrypted text form. How to implement the fuzzy query of encrypted text data to meet the imprecise matching of encrypted text data, that is, the fuzzy query, has great value in practical applications.

[0004] Currently, the mainstream fuzzy encrypted text query methods are mainly divided into two types. One is to implement fuzzy queries based on keyword similarity, but this method requires quantifying the similarity between keywords, which will incur certain computational overhead, affecting the query search efficiency, and the search flexibility is also affected by the preset similarity threshold. The other is to implement fuzzy queries based on constructing a fuzzy set. Although this method does not introduce additional computational overhead, it usually requires more storage space to maintain the preset fuzzy keyword set. Moreover, if the fuzzy set is not complete, the query results may not be returned. If the constructed fuzzy set is large, it will also affect the fuzzy query efficiency to a certain extent.

[0005] Moreover, if the method supporting fuzzy encrypted text queries uses a deterministic encryption algorithm, the same plaintext will always generate the same ciphertext, and it is impossible to hide the frequency of the plaintext data. An attacker can recover most of the ciphertexts by obtaining the frequency information of the ciphertext, posing a great security risk to the data security of users. Therefore, when performing fuzzy queries on encrypted text data, it is necessary to consider the attack of plaintext data frequency leakage, and it is necessary to use an efficient and secure encryption algorithm that can hide the frequency of plaintext data to encrypt the user's plaintext data, and then complete the fuzzy searchable encrypted text query of the ciphertext on the basis of ensuring that the plaintext frequency is not leaked.

[0006] Therefore, it is necessary and practically valuable to study how to design a fuzzy ciphertext query method that is efficient and does not disclose the plaintext frequency information of users.

[0007] There are two problems with existing fuzzy ciphertext query methods: 1. In terms of efficiency and storage, using fuzzy sets or calculating similarity leads to a large storage space occupation and low query efficiency for fuzzy queries. 2. In terms of security, using a deterministic encryption algorithm to encrypt plaintext will disclose the frequency information of the plaintext, resulting in certain security risks. Summary of the Invention

[0008] For this reason, the present invention proposes a semantically secure fuzzy searchable ciphertext query method based on frequency hiding. First, in terms of security and efficiency, this fuzzy ciphertext query method uses a ciphertext permutation algorithm based on AES to encrypt each of the 256 two-digit hexadecimal numbers from 00 to FF using the AES encryption algorithm, and sorts the encrypted AES ciphertext values in ascending order according to the numerical relationship. The order value of the smallest ciphertext value is 00, and the order value of the largest ciphertext value is FF. The order value of the AES ciphertext is used as the permutation mapping value of the original plaintext byte corresponding to this ciphertext, thereby obtaining the permutation mapping values of the 256 combinations of the original plaintext bytes from 00 to FF and the encryption permutation mapping table. The input string is encrypted and replaced according to this encryption permutation mapping table, that is, each byte of the string is replaced with the corresponding byte value, ensuring that the length of the ciphertext after encryption permutation is equal to the length of the user's original plaintext information, without introducing additional ciphertext length expansion, thus ensuring the efficiency and security of the fuzzy ciphertext query operation.

[0009] Secondly, in order to further ensure the security of fuzzy queries and prevent the frequency information leakage problem caused by the deterministic ciphertext permutation algorithm, this fuzzy ciphertext query method further uses a frequency-hiding ciphertext generation algorithm to randomly generate a random iv value of the same length as the permutation ciphertext for each row of the permutation ciphertext in the database fuzzy query, and perform an exclusive OR operation on this iv and the permutation ciphertext to generate a random ciphertext. Then, the iv and the random ciphertext are inserted into the corresponding byte positions of the final ciphertext based on a random position sequence randposition generated for each column, thereby generating a frequency-hiding ciphertext with semantic security for fuzzy queries.

[0010] Finally, use the ciphertext permutation algorithm to generate a fuzzy query trapdoor Tr for the fuzzy query content, and then use the frequency-hidden ciphertext fuzzy query algorithm to perform a frequency-hidden operation on the frequency-hidden ciphertext in the database to restore the original permutation ciphertext, and then perform a string match with the fuzzy query trapdoor Tr to achieve an efficient and semantically secure fuzzy query operation on the ciphertext data.

[0011] To achieve the above object, the present invention provides the following technical solutions:

[0012] A frequency-hiding semantically secure fuzzy searchable ciphertext query method, comprising the following steps:

[0013] Use the AES ciphertext permutation algorithm to perform byte substitution on the plaintext data according to the generated encryption permutation mapping table to generate a deterministic permutation ciphertext of the same length as the plaintext;

[0014] Randomly generate a random iv value of the same length as the permutation ciphertext for each row of the permutation ciphertext, perform exclusive OR on this iv and the permutation ciphertext to generate a random ciphertext, and insert the iv and the random ciphertext into the corresponding byte positions of the final ciphertext based on a random position sequence randposition generated for each column to generate a frequency-hiding ciphertext with semantic security;

[0015] For the frequency-hiding removed ciphertext fuzzy query algorithm, obtain the corresponding byte positions of the random iv and the random ciphertext in the final frequency-hiding ciphertext through a custom function that generates the random position sequence randposition, so as to recover the random iv and the random ciphertext, and then through their mutual exclusive OR, recover the original encrypted permutation ciphertext. Finally, use the ciphertext permutation algorithm to generate a fuzzy query trapdoor Tr for the fuzzy query content and perform string matching with the encrypted permutation ciphertext.

[0016] For further optimization of this technical solution, the AES ciphertext permutation algorithm uses the AES encryption algorithm to generate an encryption result for each byte from 00-FF, then sorts each byte according to the encryption result, and then uses the sorted values as the mapping of 00-FF in sequence, so as to generate an encryption permutation mapping table that maps each original byte to the ciphertext sorted value of that byte one by one; encrypt and replace the input string according to this encryption permutation mapping table, that is, replace each byte of the string with the corresponding byte value.

[0017] For further optimization of this technical solution, the specific steps of the AES ciphertext permutation algorithm are as follows:

[0018] S1.1. Use UTF8 encoding for each character in the original plaintext;

[0019] S1.2. Use the AES256 encryption algorithm for encryption, use the encrypted AES ciphertext as the key value key, sort the key value key from smallest to largest, and then use the sorted order value of the AES ciphertext as the mapping of the plaintext bytes 00-FF, so as to generate an encryption mapping table table_SPF for the 256 combinations of the plaintext bytes 00-FF;

[0020] S1.3. Based on the encrypted permutation table table_SPF generated in S1.2, take the UTF8 encoding of the original plaintext name byte by byte, and map it one by one to the corresponding permutation ciphertext by looking up the encrypted mapping table table_SPF, thereby generating the deterministic encrypted permutation ciphertext C of the original plaintext name.

[0021] A further optimization of this technical solution also includes the following steps:

[0022] S1.4. Unification of the length of the deterministic ciphertext: Based on the deterministic permutation ciphertext generated in steps S1.1 - S1.3, using the length L of the longest ciphertext in C max as the standard, append 0s to the right of each ciphertext to generate a ciphertext C' with a unified length of L max ;

[0023] S1.5. Generate a random iv: For each ciphertext C' after appending 0s, randomly generate an iv with a length of L max , and the length of this iv is the same as the length of C';

[0024] S1.6. Generate the random ciphertext: Random ciphertext = Ciphertext C' ⊕ iv;

[0025] S1.7. Generate a random position sequence randposition: Use the key k and the attribute column name such as name to generate a random position sequence randposition with a length of 2L max for the name attribute column of the data table, where the first L max bits of randposition are the positions of iv in the final frequency - hidden ciphertext, and the last L max bits of randposition are the positions of the random ciphertext in the final frequency - hidden ciphertext;

[0026] S1.8. Generate a fuzzy query extended column name_FH_fuzzy_ext containing the frequency - hidden ciphertext: Initialize the final frequency - hidden ciphertext C final to NULL, and then according to the first L max bits of randposition, insert the values of iv into the corresponding byte positions of the final frequency - hidden ciphertext C final , and according to the last L max bits of randposition, insert the random ciphertext into the corresponding byte positions of the final frequency - hidden ciphertext C final to obtain the final frequency - hidden ciphertext C final , and finally put the frequency - hidden ciphertext C final into the fuzzy query extended column name_FH_fuzzy_ext.

[0027] For further optimization of this technical solution, the frequency-removing hidden ciphertext fuzzy query algorithm includes:

[0028] S2.1. The database client uses the AES-based ciphertext permutation algorithm to generate a query permutation ciphertext: The database client uses the encryption permutation function SPF() of the AES ciphertext permutation algorithm to encrypt and permute each byte of the UTF8 encoding of the query content one by one in units of bytes by looking up the encryption permutation table table_SPF, so as to obtain the query permutation ciphertext corresponding to the query content, that is, the fuzzy query trapdoor Tr.

[0029] S2.2. The database client sends an SQL fuzzy query statement containing the permutation ciphertext query condition: The database client sends the SQL query statement select id, encrpt_name fromtable where FH_fuzzy_search(secret key k, attribute column name, SPF(), name_FH_fuzzy_ext)=1, which contains the query condition SPF() of the encrypted permutation ciphertext, to the database server. Among them, "FH_fuzzy_search" is a user-defined fuzzy query function based on the frequency-removing hidden ciphertext fuzzy query algorithm.

[0030] For further optimization of this technical solution, it further includes the following steps:

[0031] S2.3. The database server parses and executes the SQL query statement: The database server parses the fuzzy query SQL statement by calling the user-defined fuzzy query function FH_fuzzy_search based on the frequency-removing hidden ciphertext fuzzy query algorithm, and generates a random position sequence randposition corresponding to the attribute column according to the secret key k and the attribute column name in the SQL statement.

[0032] S2.4. The database server recovers iv and the original deterministic encrypted permutation ciphertext C': The database server uses the value of randposition to fuzzy query the ciphertext data of each row in the extended column name_FH_fuzzy_ext of the data table to find iv, and after removing iv, the remaining ciphertext can be obtained. The remaining ciphertext ⊕ iv = C', so as to obtain the original deterministic encrypted permutation ciphertext C'.

[0033] S2.5. The database server performs matching and returns the ciphertext data: Perform string matching of the query permutation ciphertext SPF() on the deterministic encrypted permutation ciphertext C'. If it matches, the database server will return the ciphertext data in the ciphertext column that meets the query condition, such as the encrpt_name column, to the database client user.

[0034] S2.6. The database client decrypts and obtains the original plaintext using the decryption key: The database client user decrypts the returned ciphertext using the symmetric encryption key key_AES stored on the client, thereby obtaining all the plaintext data that meets the fuzzy query conditions.

[0035] Different from the prior art, the above technical solution has the following beneficial effects:

[0036] 1. It improves the query efficiency of the current fuzzy query of ciphertext data;

[0037] 2. It improves the computational overhead and storage overhead of the current fuzzy query of ciphertext data;

[0038] 3. It solves the problem of frequency information leakage caused by encrypted data during the fuzzy query process;

[0039] 4. It improves the scalability of the fuzzy query of encrypted data. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] Figure 1 Schematic diagram of a semantically secure fuzzy searchable ciphertext query method for frequency hiding;

[0041] Figure 2 Schematic diagram of generating an extended column for fuzzy query of ciphertext with frequency hiding;

[0042] Figure 3 Schematic diagram of generating an encryption permutation representation based on the AES ciphertext permutation algorithm;

[0043] Figure 4 Schematic diagram of a fuzzy query of ciphertext with frequency hiding. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0044] To elaborate in detail on the technical content, structural features, achieved objectives, and effects of the technical solution, the following is a detailed description in conjunction with specific embodiments and accompanied by the drawings.

[0045] To prevent attackers from obtaining the user's plaintext frequency information through the user's ciphertext and restoring the user's data, resulting in the leakage of the user's privacy information, security processing for frequency hiding is performed on each row of encrypted permutation ciphertext for fuzzy query. The main implementation method of the semantically secure fuzzy searchable ciphertext query method based on frequency hiding is as follows: For each row of deterministic ciphertext in the fuzzy query, a random iv value of the same length as the ciphertext is randomly generated, and the iv and the ciphertext are XORed to generate a random ciphertext. Then, based on each column, a random position sequence randposition (whose value is the position information where the iv and the random ciphertext are inserted) is generated for the iv and the random ciphertext and inserted into the corresponding byte positions of the final ciphertext, thereby generating a semantically secure ciphertext with frequency hiding for fuzzy query.

[0046] The main implementation process of the fuzzy searchable ciphertext query method with frequency hiding is as follows:

[0047] First, the generation from user plaintext data to ciphertext data (this step is also used to return the ciphertext data corresponding to the original plaintext that meets the fuzzy query conditions in the subsequent steps): To prevent the data stored by the user on the database from being leaked, before the user sends their data to the database server for storage, the user first encrypts the original plaintext columns of their plaintext data, such as the plaintext data table containing the user's name, ID number, mobile phone number, etc., using the AES encryption algorithm. Taking the name column as an example, a 256-bit symmetric encryption key key_AES is used for encryption, and the generated ciphertext replaces the plaintext, thus forming a ciphertext column, such as the encrypted name column encrpt_name.

[0048] Second, the frequency-hiding ciphertext fuzzy query extension column with semantic security: While generating the ciphertext column above, for the attribute columns such as name, ID number, and mobile phone number in the database that need to perform fuzzy queries, a frequency-hiding ciphertext generation algorithm is used to generate frequency-hiding ciphertext fuzzy query extension columns respectively. Taking the frequency-hiding ciphertext fuzzy query extension column name_FH_fuzzy_ext of the name as an example, the fuzzy query condition is matched with the data in the extension column name__FH_fuzzy_ext through the de-frequency-hiding ciphertext fuzzy query algorithm, and then the corresponding ciphertext data in the ciphertext column such as the encrpt_name column that meets the fuzzy query condition is returned to the user. Then the user decrypts it using the symmetric encryption key key_AES stored on the client side to obtain all the plaintext data that meets their fuzzy query conditions.

[0049] The semantic-secure fuzzy searchable ciphertext query method based on frequency hiding consists of two entities: the database client and the database server. To achieve a secure fuzzy query against frequency leakage attacks, the database client sends the SQL fuzzy query statement selectid, encrpt_name fromtable where FH_fuzzy_search(secret key k, attribute column name, SPF('Liu'), name_FH_fuzzy_ext)=1; containing the user-defined function FH_fuzzy_search to the database server. Among them, "FH_fuzzy_search" is a user-defined fuzzy query function based on the de-frequency-hiding ciphertext fuzzy query algorithm, and "SPF" is a user-defined encryption permutation function based on the AES ciphertext permutation algorithm. This "attribute column name" is the name of the attribute field to be queried, such as name. The database server parses the query SQL statement and executes the fuzzy ciphertext query request of the client.

[0050] The specific implementation process of the semantic secure fuzzy query method with frequency hiding mainly includes two parts: generating the frequency-hiding ciphertext fuzzy query extended column name_FH_fuzzy_ext based on the frequency-hiding ciphertext generation algorithm and performing the fuzzy query on the frequency-hiding ciphertext fuzzy query extended column based on the de-frequency-hiding ciphertext fuzzy query algorithm, as Figure 1 shown.

[0051] (1) Generate the fuzzy query extended column name_FH_fuzzy_ext containing frequency-hiding ciphertext

[0052] Generating the fuzzy query extended column name_FH_fuzzy_ext containing frequency-hiding ciphertext is carried out by the user at the database client, and then the client sends the generated ciphertext data to the database server for subsequent fuzzy searchable ciphertext queries. The following is a process of how to generate the fuzzy query extended column containing frequency-hiding ciphertext from the data in the plaintext attribute name column, as Figure 2 shown.

[0053] Among them, steps ①-③ are the specific implementation of the ciphertext permutation algorithm based on AES, which first performs deterministic permutation encryption on the plaintext data. To prevent the problem that the same plaintext is encrypted into the same ciphertext due to deterministic permutation encryption, thereby revealing the frequency of the plaintext data, further frequency hiding processing is performed on the ciphertext after deterministic permutation encryption in steps ④-⑧, and steps ④-⑧ are the specific implementation of the frequency-hiding ciphertext generation algorithm. Next, taking the data 'Liu Zheli' in the plaintext name column as an example, the main implementation process is described:

[0054] ① UTF8 encoding: Each character in the original plaintext 'Liu Zheli' is encoded using UTF8 respectively: UTF8(Liu) UTF8(Zhe) UTF8(Li). The result UTF8(Liu) of a single character such as 'Liu' after UTF8 encoding occupies 3 bytes, for example, UTF8(Liu) = 0xE58898.

[0055] ② Generate the encryption permutation table based on the AES ciphertext permutation algorithm: Since a Chinese character is 3 bytes, and each byte such as 0xE5 is represented by 2 hexadecimal digits, and there are 16 2 (256) combinations of 2 hexadecimal digits from 00-FF. Each of these 256 combinations of 2 hexadecimal digits is encrypted using the AES256 encryption algorithm, and the encrypted AES ciphertext is used as the key value key. The key values key are sorted in ascending order according to the numerical relationship. The sequence value of the smallest ciphertext value is 00, and the sequence value of the largest ciphertext value is FF. Then, the sequence value of the AES ciphertext is used as the permutation mapping value of the corresponding plaintext byte, thereby generating the permutation mapping values of the 256 combinations of plaintext bytes 00-FF and the encryption permutation mapping table table_SPF, as Figure 3 shown.

[0056] ③Generate the deterministic permutation ciphertext according to the encryption substitution table: According to the encryption mapping table table_SPF generated in ②, the UTF-8 encoding of the original plaintext name in the name column is mapped one by one to the corresponding permutation ciphertext in bytes, such as 0xE5, by looking up the encryption mapping table table_SPF, so as to generate the deterministic encryption permutation ciphertext C of the original plaintext name.

[0057] ④Unify the length of the deterministic ciphertext: On the basis of generating the deterministic permutation ciphertext in the above steps ①-③, with the length L of the longest ciphertext in C max as the standard, fill 0 on the right side of each ciphertext to generate the ciphertext C' with a unified length of L max .

[0058] ⑤Generate a random iv: Randomly generate an iv with a length of L for each ciphertext C' after filling 0, and the length of this iv is the same as the length of C'. max

[0059] ⑥Generate the random ciphertext: The random ciphertext = ciphertext C' ⊕ iv.

[0060] ⑦Generate a random position sequence randposition: Use the key k and the attribute column name such as name to generate a random position sequence randposition with a length of 2L for the name attribute column of the data table. The first L bits of randposition max are the positions of iv in the final frequency hidden ciphertext, and the last L bits of randposition max are the positions of the random ciphertext in the final frequency hidden ciphertext. max

[0061] ⑧Generate the fuzzy query extended column name_FH_fuzzy_ext containing the frequency hidden ciphertext: Initialize the final frequency hidden ciphertext C final to NULL, and then according to the first L bits of randposition max , insert the values of iv into the corresponding byte positions of the final frequency hidden ciphertext C final . According to the last L bits of randposition max , insert the random ciphertext into the corresponding byte positions of the final frequency hidden ciphertext C final to obtain the final frequency hidden ciphertext C final . Finally, put the frequency hidden ciphertext C final into the fuzzy query extended column name_FH_fuzzy_ext.

[0062] (2) Fuzzy query on the extended column name_FH_fuzzy_ext of frequency-hidden ciphertext

[0063] When the database client wants to perform a fuzzy query on the extended column name_FH_fuzzy_ext of frequency-hidden ciphertext stored on the database server, the specific implementation process is as follows Figure 4 shown.

[0064] Among them, the first step is to generate a query permutation ciphertext based on the AES ciphertext permutation algorithm, that is, the fuzzy query trapdoor Tr. The second step is to initiate a fuzzy query request using the custom fuzzy query function FH_fuzzy_search. The third to sixth steps are the specific implementation of the frequency-hidden ciphertext fuzzy query algorithm based on frequency removal, which perform frequency removal and fuzzy query processing operations on the frequency-hidden ciphertext in the extended column. The specific implementation process includes the following 6 steps:

[0065] ① The database client uses the AES-based ciphertext permutation algorithm to generate a query permutation ciphertext: The database client uses the encryption permutation function SPF('Liu') of the AES-based ciphertext permutation algorithm to encrypt and permute each byte of the UTF8 encoding of the query content such as 'Liu' one by one through looking up the encryption permutation table table_SPF, so as to obtain the query permutation ciphertext corresponding to the query content, that is, the fuzzy query trapdoor Tr.

[0066] ② The database client sends an SQL fuzzy query statement containing the permutation ciphertext query condition: The database client sends the SQL query statement select id, encrpt_name from table where FH_fuzzy_search(secret key k, attribute column name, SPF('Liu'), name_FH_fuzzy_ext)=1; this SQL query statement containing the encrypted permutation ciphertext query condition SPF('Liu') to the database server, where "FH_fuzzy_search" is a user-defined fuzzy query function based on the frequency-hidden ciphertext fuzzy query algorithm based on frequency removal.

[0067] ③ The database server parses and executes the SQL query statement: The database server parses the fuzzy query SQL statement by calling the custom fuzzy query function FH_fuzzy_search of the frequency-hidden ciphertext fuzzy query algorithm based on frequency removal, and generates a random position sequence randposition corresponding to the attribute column according to the secret key k and the attribute column name in the SQL statement.

[0068] ④The database server restores the iv and the original deterministic encrypted permutation ciphertext C': The database server uses the value of randposition to perform a fuzzy query in the data table to find the iv in each ciphertext data in the extended column name_FH_fuzzy_ext. After removing the iv, the remaining ciphertext can be obtained. XOR the remaining ciphertext with the iv = C', thereby obtaining the original deterministic encrypted permutation ciphertext C'.

[0069] ⑤The database server performs a matching operation to return the ciphertext data: Perform a string match on the queried permutation ciphertext SPF('Liu') on the deterministic encrypted permutation ciphertext C'. If there is a match, the database server will return the ciphertext data in the ciphertext column that meets the query conditions, such as the ciphertext data in the encrpt_name column, to the database client user.

[0070] The database client decrypts using the decryption key to obtain the original plaintext: The database client user uses the symmetric encryption key key_AES stored on the client to decrypt the returned ciphertext, thereby obtaining all the plaintext data that meets the fuzzy query conditions.

[0071] The present invention provides a ciphertext permutation algorithm based on AES and a fuzzy ciphertext security query algorithm based on frequency hiding to ensure the efficiency and resistance to frequency leakage attacks during fuzzy ciphertext queries. The method includes:

[0072] Regarding the ciphertext permutation algorithm based on AES: The plaintext data is byte-replaced according to the generated encryption permutation mapping table through the AES ciphertext permutation algorithm to generate a deterministic permutation ciphertext of the same length as the plaintext. The present invention uses the ciphertext permutation algorithm based on AES to perform deterministic permutation encryption on the original plaintext data without introducing additional ciphertext length expansion, thereby ensuring the efficiency and security of the ciphertext fuzzy query operation.

[0073] Regarding the secure fuzzy ciphertext query algorithm based on frequency hiding: The present invention respectively designs a ciphertext generation algorithm for frequency hiding and a fuzzy ciphertext query algorithm for removing frequency hiding. For the ciphertext generation algorithm for frequency hiding, the present invention randomly generates a random iv value of the same length as the permuted ciphertext for each row of the permuted ciphertext, and performs exclusive OR of this iv and the permuted ciphertext to generate a random ciphertext. Then, the iv and the random ciphertext are inserted into the corresponding byte positions of the final ciphertext based on a random position sequence randposition generated for each column, generating a semantically secure frequency-hiding ciphertext. For the fuzzy ciphertext query algorithm for removing frequency hiding, the present invention obtains the corresponding byte positions of the random iv and the random ciphertext in the final frequency-hiding ciphertext through a custom function for generating the random position sequence randposition, thereby recovering the random iv and the random ciphertext. Then, through their exclusive OR with each other, the original encrypted permuted ciphertext is recovered. Finally, the ciphertext permutation algorithm is used to generate a fuzzy query trapdoor Tr for the fuzzy query content and perform string matching with the encrypted permuted ciphertext, thereby realizing a semantically secure and efficient fuzzy ciphertext query.

[0074] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or terminal device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or terminal device. Without further limitation, elements defined by the statement "including..." or "comprising..." do not exclude the existence of additional elements in the process, method, article or terminal device including the said elements. In addition, in this article, "greater than", "less than", "more than" are understood as not including the present number; "above", "below", "within" are understood as including the present number.

[0075] Although the above embodiments have been described, those skilled in the art can make additional changes and modifications once they learn the basic creative concept. Therefore, the above description is only the embodiments of the present invention, and does not limit the patent protection scope of the present invention. Any equivalent structure or equivalent process transformation made by using the specification and drawings of the present invention, or directly or indirectly applied in other related technical fields, is equally included in the patent protection scope of the present invention.

Claims

1. A frequency-hidden semantically secure fuzzy searchable ciphertext query method, characterized in that: The following steps are involved: The AES ciphertext replacement algorithm is used to replace the bytes of the plaintext data according to the generated encryption replacement mapping table to generate a deterministic replacement ciphertext with the same length as the plaintext; By randomly generating a random IV value with the same length as the permutation ciphertext for each row of permutation ciphertext, XORing the IV and the permutation ciphertext to generate a random ciphertext, and inserting the IV and the random ciphertext into the corresponding byte position of the final ciphertext based on a random position sequence RandPosition generated for each column, a frequency-hidden ciphertext with semantic security is generated; For the ciphertext fuzzy query algorithm without frequency hiding, the corresponding byte positions of random iv and random ciphertext in the final frequency hidden ciphertext are obtained by generating a custom function of the random position sequence randposition, thereby recovering the random iv and random ciphertext, and then recovering the original encrypted permuted ciphertext through their mutual XOR. Finally, the ciphertext permutation algorithm is used to generate a fuzzy query trap Tr for the fuzzy query content and perform string matching with the encrypted permuted ciphertext.

2. The frequency-hidden semantically secure fuzzy searchable ciphertext query method according to claim 1, characterized in that: The AES ciphertext permutation algorithm encrypts the 256 2-digit hexadecimal numbers 00-FF using the AES256 encryption algorithm, and sorts the encrypted AES ciphertext values ​​in ascending order according to the numerical relationship, with the sequence value of the smallest ciphertext value being 00 and the sequence value of the largest ciphertext value being FF; the sequence value of the AES ciphertext is used as the permutation mapping value of the original plaintext byte corresponding to the ciphertext, thereby obtaining the permutation mapping values ​​of the 256 combinations of the original plaintext bytes 00-FF and the encrypted permutation mapping table table_SPF.

3. The frequency-hidden semantically secure fuzzy searchable ciphertext query method according to claim 2, characterized in that: The specific steps of the AES ciphertext replacement algorithm are as follows: S1.

1. Use UTF8 encoding for each character in the original plaintext; S1.

2. Use the AES256 encryption algorithm to encrypt, use the encrypted AES ciphertext as the key value, sort the key values ​​from small to large, and then use the sequence value after sorting the AES ciphertext as the mapping of plaintext bytes 00-FF, thereby generating an encryption mapping table table_SPF of 256 combinations of plaintext bytes 00-FF; S1.

3. According to the encryption substitution table table_SPF generated in S1.2, the UTF8 encoding of the original plaintext name is taken as bytes, and it is mapped one by one to the corresponding substitution ciphertext by looking up the encryption mapping table table_SPF, thereby generating the deterministic encrypted substitution ciphertext C of the original plaintext name.

4. The frequency-hidden semantically secure fuzzy searchable ciphertext query method according to claim 3, characterized in that: The following steps are also included: S1.

4. Unification of deterministic ciphertext length: Based on the deterministic permutation ciphertext generated in steps S1.1-S1.3, the length L of the longest ciphertext in C is used to unify the length of the deterministic permutation ciphertext. max Based on the above, add 0 to the right side of each ciphertext to generate a uniform length of L max The ciphertext C'; S1.5, Generate a random iv: For each ciphertext C' filled with zeros, randomly generate an iv with a length of L max The length of iv is the same as that of C'; S1.

6. Generate random ciphertext: random ciphertext = ciphertext C'⊕iv; S1.7, Generate a random position sequence randposition: Use the key k and the attribute column name, such as name, which is the name attribute column of the data table to generate a length of 2L max The random position sequence randposition, where the first L of randposition max The position of iv in the final frequency-hidden ciphertext, and the last L of randposition max The bit is the position of the random ciphertext in the final frequency hidden ciphertext; S1.

8. Generate a fuzzy query extension column name_FH_fuzzy_ext containing frequency hidden ciphertext: Initialize the final frequency hidden ciphertext C final is NULL, then according to the first L of randposition max bits, insert the value of iv into the final frequency hidden ciphertext C final The corresponding byte position is based on the last L of randposition. max bits, insert the random ciphertext into the final frequency hidden ciphertext C final The corresponding byte position of , thereby obtaining the final frequency hidden ciphertext C final , and finally hide the frequency ciphertext C final Put it into the fuzzy query extension column name_FH_fuzzy_ext.

5. The frequency-hidden semantically secure fuzzy searchable ciphertext query method according to claim 1, characterized in that: The ciphertext fuzzy query algorithm for removing frequency hiding includes: S2.

1. The database client generates a query replacement ciphertext using an AES-based ciphertext replacement algorithm: The database client uses an encryption replacement function SPF() based on the AES ciphertext replacement algorithm to perform one-to-one encryption replacement of all bytes of the UTF8 encoding of the query content by looking up the encryption replacement table table_SPF in units of bytes, thereby obtaining the query replacement ciphertext corresponding to the query content, that is, the fuzzy query trapdoor Tr; S2.

2. The database client sends an SQL fuzzy query statement containing a query condition for a permuted ciphertext: The database client sends select id, encrpt_name fromtable where FH_fuzzy_search (key k, attribute column name, SPF(), name_FH_fuzzy_ext) = 1, an SQL query statement containing a query condition SPF() for encrypted permuted ciphertext to the database server, where "FH_fuzzy_search" is a user-defined fuzzy query function based on a ciphertext fuzzy query algorithm for frequency hiding.

6. The frequency-hidden semantically secure fuzzy searchable ciphertext query method according to claim 5, characterized in that: The following steps are also included: S2.3, the database server parses and executes the SQL query statement: the database server parses the fuzzy query SQL statement by calling the custom fuzzy query function FH_fuzzy_search based on the de-frequency hidden ciphertext fuzzy query algorithm, and generates a random position sequence randposition corresponding to the attribute column according to the key k and the attribute column name in the SQL statement; S2.4, the database server recovers iv and the original deterministic encrypted replacement ciphertext C': the database server uses the value of randposition to find iv in each row of ciphertext data in the fuzzy query extension column name_FH_fuzzy_ext in the data table, and after removing iv, the remaining ciphertext can be obtained, and the remaining ciphertext ⊕ iv = C', thereby obtaining the original deterministic encrypted replacement ciphertext C'; S2.5, the database server performs string matching and returns ciphertext data: the queried replacement ciphertext SPF() is matched with the deterministic encrypted replacement ciphertext C'. If a match is found, the database server returns the ciphertext columns that meet the query conditions, such as the ciphertext data in the encrpt_name column, to the database client user; S2.

6. The database client uses the decryption key to decrypt and obtain the original plaintext: The database client user uses the symmetric encryption key key_AES stored on the client to decrypt the returned ciphertext, thereby obtaining all plaintext data that meets the fuzzy query conditions.

Citation Information

Patent Citations

  • Sequence cipher based search encryption method in cloud storage environment

    CN107454059A

  • Data mining method, device and system and storage medium

    CN115238284A

  • Novel encryption processes based upon irrational numbers and devices to accomplish the same

    US20140112469A1

  • Leakage-Free Order-Preserving Encryption

    US20180019866A1

  • Systems and methods for privacy-assured similarity joins over encrypted datasets

    US20180157703A1