Privacy information retrieval method supporting dynamic updating of database

By using normalized public key, distributed decryption, matrix and vector multiplication optimization techniques and homomorphic ciphertext multiplication based on ciphertext blocking in the multi-key full-homomorphic encryption algorithm, the problems of high computational complexity and complex key management of the multi-key full-homomorphic encryption algorithm are solved, efficient privacy information retrieval and dynamic database updates are realized, and the security and flexibility of the system are enhanced.

CN120217435APending Publication Date: 2025-06-27NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510323099.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-19
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

The existing multi-key full-homomorphic encryption algorithm has high computational complexity in encryption, decryption and homomorphic operations, complex key management, and it is difficult for the PIR protocol to simultaneously optimize request size, response size and server computing overhead in a multi-user environment.

Method used

The private information retrieval method based on multi-key full homomorphic encryption is adopted, and the traffic of information exchange between entities is reduced by normalized public keys, distributed decryption is used to reduce the risk of single point failure, and optimization techniques for multiplying matrix and vectors are introduced to improve computing efficiency. The noise and traffic are reduced through extended algorithms and homomorphic ciphertext multiplication based on ciphertext blocks.

Benefits of technology

It effectively reduces the computational complexity and key management complexity, improves the computing efficiency of private information retrieval and the security of the system, supports dynamic database updates and multi-user retrieval, and enhances the flexibility and practicality of the method.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120217435A_ABST
    Figure CN120217435A_ABST
Patent Text Reader

Abstract

The invention discloses a privacy information retrieval method supporting dynamic updating of a database, which comprises the following steps of: constructing the database, and verifying the access authority of a user; dynamically updating the database, and disclosing a data storage state label for the user passing the access permission verification; a user inputs a position index of data to be queried in the database, generates an encrypted query by using the normalized public key and sends the encrypted query to the server; the server expands the received encryption inquiry to obtain a plurality of ciphertext vectors, performs calculation on the ciphertext vectors by adopting an optimization technique of matrix and vector multiplication and homomorphic ciphertext multiplication based on ciphertext partitioning to obtain a ciphertext result, and returns the ciphertext result to the user; and the user receives the ciphertext result returned by the server, performs joint decryption on the ciphertext result, and calculates to obtain database storage data corresponding to the query index, namely a final query result. According to the method, the security and the efficiency of privacy information retrieval are improved, and the method has flexibility and practicability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical fields of information security and data privacy protection, and particularly to a privacy information retrieval method supporting dynamic database updates. Background Art

[0002] The secure retrieval of encrypted data requires finding the required data according to the diverse needs of users on the premise that the data remains encrypted, so as to support the efficient retrieval of ciphertext data while protecting data privacy. The privacy retrieval functions of encrypted data in a multi-data source framework mainly include searchable encryption, private information retrieval (PIR), etc. Searchable encryption can encrypt data and keyword indexes, and when users search efficiently through keywords, the server responsible for storage cannot obtain the ciphertext data and keyword information from them. PIR allows users to query the data corresponding to a certain index in the server database, enabling the server to return the data without knowing which data in the database is queried, and does not limit the stored data in the database to be plaintext or ciphertext. Compared with searchable encryption, in the PIR protocol, users only need to encrypt the index, and the data storage form on the server side is diverse, which has more advantages in studying the privacy retrieval of encrypted data in a multi-data source framework.

[0003] Fully homomorphic encryption supports performing arbitrary operations on ciphertext data without decrypting it, and the final result is also ciphertext, thus realizing the protection of data privacy in the process of calculating and using indexes and database data, providing a more suitable idea for the PIR protocol. In 2009, Gentry (Gentry C. A fully homomorphic encryption scheme [D]. Stanford university, 2009.) first constructed a PIR protocol based on a fully homomorphic encryption scheme in his doctoral thesis, achieving sub-linear communication complexity. After that, PIR schemes based on fully homomorphic encryption have developed rapidly. Each scheme weighs three indicators: request size, response size, and server computing overhead, and designs rich and diverse and relatively fast PIR methods. Generally speaking, however, the overall overhead of PIR schemes is relatively large, and it is difficult to make all three indicators very small at the same time. For each query of users, all data in the database need to participate in the operation to generate corresponding responses. If there is data that does not participate in the operation during this process, it means that the user's query target is not among them, and information leakage has occurred.

[0004] The PIR protocol based on fully homomorphic encryption can effectively protect the index information while preventing the server from obtaining the retrieved data and the retrieval range. However, in real application scenarios, multi-source data often serves multiple independent and untrusted users, which requires the protocol to meet the privacy requirements of the data among the participating users while satisfying the privacy and security of information retrieval. Therefore, multi-key fully homomorphic encryption (MKFHE) is considered to support multi-user collaborative computing without mutual leakage of data privacy, enhancing the practicality of the protocol.

[0005] There are two types of multi-key schemes in existing MKFHE algorithms: one is that the participating parties first encrypt the data with their respective different public keys, and then convert the ciphertext under the same key through a key conversion method; the other is to first convert the participating parties' keys into normalized public keys, and then perform encryption and homomorphic operations. The latter is more convenient, efficient, and easy to calculate when solving the problem that ciphertexts encrypted with different keys cannot be directly homomorphically operated. At the same time, there are also two different decryption methods in the MKFHE algorithm: sequential decryption starts from the first participating party, and the decryption results are sequentially passed and continued to decrypt. The operation is simple but there is a great risk of single-point failure; while distributed decryption is that each participating party independently calculates partial decryption results, and then aggregates and operates to obtain the final result, jointly completing the decryption, which can effectively protect the privacy of the private keys of each participating party, greatly reducing the risk of single-point failure, and is more efficient and has strong scalability.

[0006] Existing research has presented many relatively mature and efficient PIR schemes based on fully homomorphic encryption, such as the SealPIR (Angel S, Chen H, Laine K, et al. PIR with Compressed Queries and Amortized Query Processing. 2018 IEEE Symposium on Security and Privacy (SP), pp. 962 - 979.) scheme, which is based on the BFV homomorphic encryption algorithm. It has a small query size, short encryption query generation time and response result decryption time, and supports multiple queries. However, its response size is large and the computational overhead of encrypted queries is high. Although subsequent research, such as the OnionPIR (Mughees M H, Chen H, Ren L. OnionPIR: Response Efficient Single-Server PIR. 2021 ACM SIGSAC Conference on Computer and Communications Security, pp. 2292 - 2306.) scheme, designs a response-efficient single-server private information retrieval protocol within the basic framework of SealPIR, reducing the response size, there is still much room for optimization in PIR schemes based on fully homomorphic encryption. At the same time, there is no specific design scheme for private information retrieval based on multi-key fully homomorphic encryption in previous research. The method design still faces challenges and there are some problems to be solved:

[0007] (1) Computational complexity and key management. The computational complexity of multi-key fully homomorphic encryption algorithms is relatively high, especially during the encryption, decryption, and homomorphic operation processes, with large computational overhead and significant time consumption. Key management also becomes more complex because each participant holds an independent key, and effective key distribution, storage, and update mechanisms are required to prevent the leakage or abuse of private keys. In addition, improper key management may increase the communication efficiency degradation and system overhead.

[0008] (2) PIR protocol optimization and communication overhead. In the private information retrieval (PIR) protocol based on multi-key fully homomorphic encryption, how to balance the request size, response size, and server computational overhead is an important challenge. A large response size will increase the network transmission burden, while excessive computational overhead may affect system efficiency. More importantly, the communication overhead and latency brought by frequent encrypted data exchanges may pose pressure on the real-time performance and scalability of the system.

[0009] (3) Privacy protection and user trust. Although multi-key fully homomorphic encryption can effectively protect privacy, in scenarios involving multiple parties, ensuring the full protection of the data privacy of each participating party still poses challenges. Since the parties usually do not trust each other, how to enhance user trust through reasonable authentication and data sharing protocols to avoid man-in-the-middle attacks or data leakage has become a key issue in the design of the solution. Summary of the Invention

[0010] In view of this, the present application provides a privacy information retrieval method that supports dynamic updates of a database.

[0011] The present application discloses a privacy information retrieval method that supports dynamic updates of a database, which includes:

[0012] Step 1: Construct a database, and the database management system verifies the access rights of users.

[0013] Step 2: If the database needs to be dynamically updated, add corresponding storage status tags to the elements in the database, and disclose the storage status tags of the updated database to the users who have passed the access right verification.

[0014] Step 3: The user inputs the position index of the data to be queried in the database and generates an encrypted query for this position using a normalized public key, and sends the encrypted query to the server.

[0015] Step 4: The server expands the received encrypted query to obtain multiple ciphertext vectors, and uses the optimization technique of multiplying a matrix by a vector and the homomorphic ciphertext multiplication based on ciphertext blocks to calculate the ciphertext result and return it to the user.

[0016] Step 5: The user receives the ciphertext result returned by the server and performs joint decryption on it to calculate the database stored data corresponding to the query index, that is, the final query result.

[0017] Further, the constructing of the database includes:

[0018] Construct a database DB with a scale of n, and represent the database DB as a matrix M, and the element in the a-th row and b-th column of the matrix M is denoted as

[0019] Further, the database management system verifying the access rights of users includes:

[0020] Step 11: When a user first uses the database management system, enter a username and password for registration. Process the user password through a hashing algorithm and store the registered username and the processed user password in the database. When the user logs in to the database management system, enter the username and password on the login interface. The database management system queries the database, finds the record that matches the entered username, and obtains the stored hash value.

[0021] Step 12: Use the same hashing algorithm as in Step 11 to hash the user-entered password and compare it with the hash value stored in the database. If the two match, it indicates successful authentication; otherwise, the login fails. After successful authentication, the database management system creates a user session and provides access rights. In the database management system, the user's permissions are controlled by an access control list.

[0022] Further, the said Step 2 includes:

[0023] If the database needs to be dynamically updated currently, then use (DB r,c , +), (DB r,c , -), (DB r,c , *) to represent that the element DB r,c stored in the r-th row and c-th column of the current database is in the state of newly added, abolished, and unchanged data in the database respectively.

[0024] Further, the said Step 3 includes:

[0025] The j-th user U j inputs an inquiry index idx ∈ {0, 1, …, n - 1} at the user end, that is, user U j queries the idx-th record in the database, j ∈ [1, K]; user U j converts the index idx to (idx0, idx1), where is the number of rows and columns of the database; idx0 is the row coordinate of the database data corresponding to the index idx in the database matrix, and idx1 is the column coordinate of the database data corresponding to the index idx in the database matrix;

[0026] User U j uses the unified public key pk to generate an encrypted inquiry Query j = (query row , query col ), where is the encrypted value of the query row coordinate, is the encrypted value of the query column coordinate, and user U j sends Query j to the server, and The polynomial - form encodings are idx0 and idx1 respectively, and MKFHE.Enc(·) is an encryption algorithm based on multi - key fully homomorphic encryption.

[0027] Furthermore, step 4 includes:

[0028] Step 41: The server receives the encrypted query Query j sent by user U j =(query row , query col ), and expands query through the expansion algorithm row to obtain the ciphertext Expand(·) represents the expansion algorithm; Expand query col through the expansion algorithm to obtain the ciphertext

[0029] Step 42: The server calculates the ciphertext row vector where M is the database matrix;

[0030] Step 43: The server calculates the ciphertext result c k , c col,k by computing chunksHEMult(v cMult,k , F), and then performs summation using homomorphic addition where c cMult contains 2F ciphertexts (c cMult,0 , c cMult,1 , …, c cMult,2F-1 ), chunksHEMult(·) is the homomorphic ciphertext multiplication based on ciphertext chunking, and F is the chunk size;

[0031] Step 44: The server returns the ciphertext c cMult to the user in response to the user's query.

[0032] Furthermore, step 41 includes:

[0033] The expansion algorithm Expand(·) requires the homomorphic operation Sub(ct,k): First, for ct=(ct0(x),ct1(x)), replace x with x k , and transform it into ct′=(ct0(x k ),ct1(x k ))). At this time, the corresponding decryption key changes to s(x k); Then process the ciphertext ct' with the key conversion algorithm to obtain the ciphertext ct'' with the decryption key s(x). At this time, ct'' becomes the encryption of the message m(x k )

[0034] Through the extension algorithm, according to Obtain the ciphertext The specific process is as follows: Input the query query = MKFHE.Enc(x idx ) and the size of the database Find the smallest m = 2 l , such that And initialize the ciphertext vector ciphertexts = [query]; For j = 0, 1,..., l - 1, perform an outer iteration loop: First, perform an inner iteration loop. For k = 0, 1,..., 2 j - 1, run c0 ← ciphertexts[k], assign to c1, assign c0 + Sub(c0, N / 2 j + 1) to c' k , assign c1 + Sub(c1, N / 2 j + 1) to After the inner iteration loop finishes running, set ciphertexts to Continue to execute the next outer iteration loop; After the outer iteration loop finishes running, assign m -1 mod t to inverse; For Set c row,j = inverse · ciphertexts[j], and output a set of ciphertexts

[0035] Furthermore, the step 42 includes:

[0036] Through the homomorphic linear transformation algorithm The process of calculating the product of the matrix M and the vector to obtain the ciphertext row vector v is as follows:

[0037] Input the matrix M and the vector Find the l-th diagonal vector m of the matrix M l =(M 0,l , M 1,l+1 ,…, M n-l-1,n-1 , M n-l,0 ,…, M n-1,l-1 ), 0 ≤ l < n, initialize the ciphertext row vector v, and for l = 1 to n - 1, respectively execute Assign to v, where Rot(·) represents the ciphertext rotation operation, Add(·) represents the homomorphic addition, and finally return the output ciphertext row vector v.

[0038] Further, the step 43 includes:

[0039] Input two homomorphically encrypted ciphertexts v k , c col,k and the block size F, perform the ciphertext block operation, and let the weight Decompose the ciphertext v k into F blocks v w , v 0,0 , …, v 0,1 , …, v 0,F-1 satisfying v k = v 0,0 + 2 w v 0,1 + … + 2 (F -1)w v 0,F-1 mod q, perform the plaintext-ciphertext multiplication operation, and take v 0,i = (v 0,i,0 , v 0,i,1 ), i = 0, 1, …, F - 1 as the plaintext to multiply with the ciphertext c col,k to obtain the ciphertext vector c cMult,k = (c cMult,k,0 , c cMult,k,1 , …, c cmult,k,2i , c cMult,k,2i+1 , …, c cMult,k,2F-1 ), where c cMult,k,2i = v 0,i,0 c col,k , c cMult,k,2i+1 = v 0,i,1 c col,k , i = 1, 2, …, F - 1, mod is the remainder function, and q is the ciphertext space modulus;

[0040] Then perform the summation using homomorphic addition to output the ciphertext where c cMult contains 2F ciphertexts (c cMult,0 , c cMult,1 , …, c cMult,2F-1 ).

[0041] Further, the step 5 includes:

[0042] The user receives the query ciphertext result c cMult = (c cMult,0 , c cmult,1 , …, c cmult,2F-1) And input it into the chunksDec algorithm to generate the final decryption result. The chunksDec algorithm first performs a block decryption operation to decrypt each ciphertext of c cMult to obtain m cmult,i = MKFHE.Dec(sk, c cMult,i ), where i = 0, 1, …, 2F - 1. Calculate Reconstruct to form a new ciphertext ct = (ct0, ct1), and perform the decryption operation again m cMult = MKFHE.Dec(sk, ct) to obtain the final message output m cMult , which is the database data DB corresponding to the query index idx idx . MKFHE.Dec(·) is a decryption algorithm based on multi-key fully homomorphic encryption, chunksDec is a homomorphic ciphertext decryption algorithm based on ciphertext block division, and sk is the user's private key.

[0043] Due to the adoption of the above technical solutions, the present application has the following advantages:

[0044] 1. The present application proposes an optimized method for private information retrieval based on multi-key fully homomorphic encryption (MKFHE), aiming to study the security design and attack protection methods of the private information retrieval (PIR) scheme for encrypted data in a multi-data source framework based on the multi-key fully homomorphic encryption algorithm against the background of secure access to massive data.

[0045] 2. The method of the present application provides a theoretical algorithm and solution technology for the private retrieval of encrypted data from multiple data sources. It selects a suitable type of MKFHE scheme and uses a normalized public key, saving the communication volume of information exchange between entities, being more convenient, efficient, and easy to calculate; adopts a distributed decryption method, reducing the risk of single-point failure and effectively protecting the privacy of the private keys of each participating party. In the design of the PIR method, an optimization technique of multiplying a matrix by a vector is introduced to improve the calculation efficiency; an extended algorithm is adopted to improve the operability of the ciphertext and reduce the user's communication volume; homomorphic ciphertext multiplication based on ciphertext block division is utilized to reduce noise and ensure the correctness of the decryption result of the method; it has an effective access control mechanism to ensure that only authorized users can perform retrieval, and is finely managed in a scenario involving multiple parties, further enhancing the security and flexibility of the system; it can hide both access information and retrieval information simultaneously, support database dynamic update and multi-user retrieval, enhancing the flexibility and practicality of the method. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] To more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments described in the embodiments of the present application. For those of ordinary skill in the art, other accompanying drawings can also be obtained based on these drawings.

[0047] Figure 1 It is a schematic diagram of the interaction between the database (DB) server and the user in the embodiments of the present application;

[0048] Figure 2 It is a schematic flowchart of a privacy information retrieval method supporting dynamic database update in the embodiments of the present application;

[0049] Figure 3(a) is a schematic diagram of the database before update in the embodiments of the present application;

[0050] Figure 3(b) is a schematic diagram of the database after update in the embodiments of the present application. Detailed implementation manners

[0051] The present application will be further described in conjunction with the accompanying drawings and embodiments. The described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art shall fall within the scope protected by the embodiments of the present application.

[0052] The technical problems solved by the present application involve the following aspects:

[0053] (1) Design and optimization of the privacy information retrieval scheme. Against the background of the secure access of massive data, based on the multi-key fully homomorphic encryption algorithm, study the secure design and attack protection methods of the encrypted data privacy retrieval scheme in the multi-data source framework, improve the computing performance, and reduce the communication overhead of the scheme.

[0054] (2) Improvement of system flexibility and practicality. Support the dynamic update of the database, ensure that the system can flexibly perform operations of adding, deleting, querying, and modifying the database, improve the scalability, and effectively cope with the dynamic changes of data content and structure to adapt to the changing application requirements.

[0055] (3) Design of security guarantee and protection mechanism. For the multi-user environment, design a system model for multiple users, ensure the security of the privacy retrieval algorithm, prevent various attacks and threats, especially protect the user data privacy under complex structures.

[0056] (4) Implementation of access control and permission management. Implement refined access control and permission management to ensure that each user can only access the sensitive data authorized to them, avoid illegal access and data leakage in the multi-user environment, and improve the security and controllability of the system.

[0057] See Figure 2 This application provides an embodiment of a privacy information retrieval method that supports dynamic database updates, which is applicable to the scenario of secure query of multi-user data in a multi-data source framework.

[0058] See Figure 1 A database (DB) server (hereinafter referred to as the server): A computer or system dedicated to storing, managing, and providing database services. Its main responsibility is to process requests from a database management system (DBMS) and provide services such as data storage, retrieval, and update for clients (such as application programs, users). The database server has powerful functions in computing and storage. In this method, the database is denoted as DB = {(i, DB[i])|0 ≤ i ≤ n - 1}, which stores n entries. To simplify the subsequent discussion of the PIR method design, it is assumed that the value of DB[i] is a positive integer, not just a bit. After the user sends an encrypted query, the DB server will provide a response to the querying user.

[0059] In addition, this method supports dynamic updates of the database. Only the data DB stored in the r - row and c - column of the original database matrix at the database end needs to be r,c marked with storage status tags "+", "-", "*", and (DB r,c , +), (DB r,c , -), (DB r,c , *) are used to indicate that the current database - end element DB r,c is in the state of newly added, abolished, and unchanged, respectively. Since the newly added tags only represent the status information of the data corresponding to the position and do not contain specific data values, they can be made public to users who meet the access restriction conditions, facilitating users to make inquiries based on this set of storage status tags.

[0060] User: The client or entity that initiates a data query, expecting to retrieve specific information from the database without letting the database service provider know the content of the queried data. The main goal of the user is to ensure query privacy, that is, to protect their own privacy while obtaining the data. In this method, multiple query users (1 ≤ j ≤ K) do not collude, can directly query the DB server, and obtain the desired results from the DB server. At the same time, when the user requests the corresponding data DB[j] from the DB, they do not want to disclose the queried index value idx to the DB server.

[0061] The security model of the method described in this application is: users and DB servers are semi-honest, that is, users and DB servers are honest and curious (honest-but-curious), and there is no collusion between the DB server and any other third party. Specifically, users and DB servers will faithfully follow the protocol and perform corresponding operations, perform encryption, decryption, calculation and other tasks within the scope specified by the protocol, and ensure the normal operation of the system. However, although they will honestly perform the operations in the protocol, they may still be curious during the execution process and try to obtain more information in addition to the data they need by analyzing the received ciphertext or query information.

[0062] The MKFHE scheme used in this application is described as follows: it specifically includes 5 algorithms, namely the initialization algorithm MKFHE.Setup, the key generation algorithm MKFHE.KeyGen, the encryption algorithm MKFHE.Enc, the homomorphic operation algorithm MKFHE.Eval, and the decryption algorithm MKFHE.Dec. Among them, MKFHE.Setup sets system parameters for building a framework for multi-party homomorphic encryption; MKFHE.KeyGen generates public-private key pairs and computational keys for each participant (i.e., querying user), and converts these public keys into normalized public keys by performing specific operations (such as summation) on the public keys of all participants, so that the ciphertext size is reduced and is independent of the number of participants; MKFHE.Eval provides homomorphic addition (EvalADD) and homomorphic multiplication (EvalMult) operations on ciphertexts, performs specified homomorphic operations on the two input ciphertexts, and obtains the resultant ciphertext; MKFHE.Dec adopts a distributed decryption method, that is, all participating users use their own private keys to calculate partial decryption results, and finally summarize the calculation to obtain the complete decryption result, reducing the risk of single point failure and protecting the privacy of the private keys of each participant.

[0063] The technical solution of the embodiment of the present application specifically includes the following steps:

[0064] S1: Database construction and access rights verification stage;

[0065] S2: database dynamic update stage;

[0066] S3: initialization and user query phase;

[0067] S4: DB server query and response phase;

[0068] S5: The stage where the user obtains the final query result.

[0069] Preferably, the specific implementation of S1 includes the following sub-steps:

[0070] S1.1: Database construction and matrix arrangement:

[0071] S1.1.1: Construct a database DB of size n. Let each record in the database be DB i , i = 0, 1, …, n - 1;

[0072] S1.1.2: Use the database matrix arrangement method to arrange the database of n elements into matrix M:

[0073]

[0074] S1.2: Access permission verification:

[0075] S1.2.1: When the user first uses the system, register. The user is required to select a unique username and set a password that meets the strength requirements (such as including uppercase and lowercase letters, numbers, and special characters, etc.). Process the user password through a hashing algorithm (such as bcrypt, SHA - 256, etc.). Store the registered username and the processed user password in the database.

[0076] S1.2.2: When logging in, the user enters the username and password on the login interface. The system queries the database, finds the record that matches the entered username, and obtains the stored password hash value. Then, use the same hashing algorithm to hash the password entered by the user and compare it with the hash value stored in the database. If the two match, it indicates that the authentication is successful; otherwise, the login fails.

[0077] S1.2.3: After the verification passes, the system can create a user session (such as generating a session ID) and provide access permissions. In the system, the user's permissions are usually controlled by an access control list (ACL).

[0078] Preferably, the schematic diagram of S2 is shown in Figures 3(a) and 3(b). The specific implementation includes the following sub - steps:

[0079] S2.1: Determine whether the database needs to be dynamically updated:

[0080] S2.1.1: Determine whether the current system needs to support dynamic update of the database. If so, add a set of storage status tags “ +, -, * ”, which respectively represent the addition, abolition, and unchanged status of the data at the corresponding position. That is, for the element DB stored in the r - th row and c - th column of the current database matrix r,c , use (DB r,c , +), (DB r,c , -), (DB r,c , *) to represent the data whose status at this element is newly added, abolished, and unchanged at the database end respectively.

[0081] S2.2: Update the database:

[0082] S2.2.1: When new data needs to be added to the database, the server will sequentially place the new elements at the end of the original database and attach a storage status label "+", that is, it is represented as (DB r,c , +).

[0083] S2.1.2: When a certain data in the database needs to be abolished, the database server will change the storage status label to "-" to mark this data as invalid, that is, it is represented as (DB r,c , -).

[0084] S2.2: The data in other positions of the database remains in the (DB r,c , *) state unchanged.

[0085] S2.3: Public storage status label:

[0086] S2.3.1: Publicize a set of updated labels of the database to users who have passed the access permission verification, so that users can send inquiries based on this set of storage status labels.

[0087] Preferably, the specific implementation of S3 includes the following sub-steps:

[0088] S3.1: System initialization:

[0089] S3.1.1: The system calls the key generation algorithm MKFHE.Setup to set parameters such as security parameters and the number of participating users (K≥1), generate different public-private key pairs for each user, generate a computing key, and publicly obtain the normalized public key pk for encryption after performing a certain operation on all the public keys of the participating users.

[0090] S3.2: The user sends an inquiry to the server:

[0091] S3.2.1: The j-th user U j (j∈[1,K]) inputs an inquiry index idx∈{0,1,…,n - 1}, that is, the user U j expects to query the idx-th record in the database;

[0092] S3.2.2: The user U j converts the index idx to (idx0, idx1), that is, locates the position of the element expected to be queried in the database arrangement matrix M in the form of row and column coordinates, where

[0093] S3.2.3: The user U j uses the unified public key pk to generate an encrypted inquiry Query j =(query row ,querycol ), where is the encrypted value of the expected query row coordinate, and j is the encrypted value of the expected query column coordinate. Subsequently, user U j sends Query

[0094] Preferably, the specific implementation of S4 includes the following sub-steps:

[0095] S4.1: The DB server queries the user's question:

[0096] S4.1.1: The DB server receives the encrypted question Query k from user U j , runs the expansion algorithm to expand the question into 2 ciphertext vectors: expanded query row to obtain the ciphertext expanded query col to obtain the ciphertext According to the following implementation process of the expansion algorithm, the corresponding ciphertext c row and ciphertext c col can be obtained.

[0097] The expansion algorithm Expand is specifically described as follows:

[0098] The expansion algorithm Expand requires a relatively special homomorphic operation Sub(ct, k): First, for ct = (ct0(x), ct1(x)), replace x with x k , and transform it into ct' = (ct0(x k ), ct1(x k )). At this time, the corresponding decryption key changes to s(x k ); for consistency, then use the key conversion algorithm to process the ciphertext ct', and obtain the ciphertext ct'' with the decryption key s(x). At this time, ct'' becomes the encryption of the message m(x k ).

[0099] The expansion algorithm is expressed as (c0, c1,..., c n-1 ) ← Expand(query, n), and the specific process is as follows: Input the question query = MKFHE.Enc(x idx ) and the size n of the database. First, find the smallest m = 2 l such that m ≥ n, and initialize the ciphertext vector ciphertexts = [query] with the question query. Subsequently, for j = 0, 1,..., l - 1, perform an outer iteration loop: First, perform an inner iteration loop. For k = 0, 1,..., 2 j - 1, run c′ k ← c0 + Sub(c0, N / 2 j + 1), c′ k+2j ← c1 + Sub(c1, N / 2 j + 1). After the inner iteration loop finishes running, set Continue to execute the next outer iteration loop. After the outer iteration loop finishes running, assign m -1 mod t to inverse. Then for j = 0, 1, …, n - 1, set c j = inverse · ciphertexts[j]. Finally, output a set of ciphertexts c = (c0, c1, …, c n-1 ).

[0100]

[0101]

[0102] S4.1.2: The DB server calls the homomorphic addition MKFHE.EvalADD and the homomorphic multiplication MKFHE.EvalMult to calculate the ciphertext row vector where The efficiency of this process can be enhanced by using the optimization techniques for matrix-vector multiplication described below. The optimization techniques for matrix-vector multiplication mainly involve linear transformation and are specifically described as follows:

[0103] Some HE schemes based on the ring learning with errors (RLWE) assumption utilize the structure of the Galois group to implement the rotation operation on the plaintext slots, denoted as Rot(ct; l), which transforms the ciphertext ct of into ρ(m; l): = (m l , …, m n-1 , m0, …, m l-1 ). Here, l can be positive or negative, and rotation (-l) is the same as (n - l).

[0104] A method for calculating any linear transformation on an encrypted vector used in this application can represent matrix-vector multiplication by combining rotation and constant multiplication operations. For a certain matrix 0 ≤ l < n, define the l-th diagonal vector of U Then m · U = ∑ 0≤l<n (ρ(m; l) ⊙ u l ). Here, ⊙ represents the component-wise multiplication between vectors. Given the ciphertext ct of the matrix U ∈ R n×n and the vector m, the homomorphic linear transformation algorithm describes how to calculate the ciphertext of the desired vector m · U.

[0105] Optimization techniques for multiplying a matrix by a vector, namely the homomorphic linear transformation algorithm, denoted as ct′←LinTrans(ct; U). The specific process is as follows: Input the plaintext matrix U and the ciphertext vector ct. First, find l diagonal vectors of U, and perform homomorphic multiplication CMult on ct and u0 to initialize the ciphertext vector ct′. Subsequently, for l = 1 to n - 1, execute ct′←Add(ct′, CMult(Rot(ct; l); u l ))), where Rot(·) represents the ciphertext rotation operation, Add(·) represents the homomorphic addition, and finally return the output ciphertext vector ct′.

[0106]

[0107] S4.1.3: The DB server adopts homomorphic ciphertext multiplication based on ciphertext blocks to calculate and obtain Then, perform summation using homomorphic addition where c cMult contains 2F ciphertexts (c cMult,0 , c cMult,1 , …, c cMult,2F-1 ). Among them, c cMult,k ←chunksHEMult(v k , c col,k , F) can be obtained through the implementation process of c cMult ←chunksHEMult(c0, c1, F) given below.

[0108] Among them, the homomorphic ciphertext multiplication based on ciphertext blocks is denoted as c cMult ←chunksHEMult(c0, c1, F), and it is necessary to sequentially execute 2 processes: ciphertext block division and plaintext-ciphertext multiplication. The specific process is as follows: Input two homomorphically encrypted ciphertexts c0, c1 and the block size F. First, perform the ciphertext block division operation. Let the weight Decompose the ciphertext c0 into F blocks c w , c 0,0 , …, c 0,1 , …, c 0,F-1 in base 2, satisfying c0 = c 0,0 + 2 w c 0,1 + … + 2 (F-1)w c 0,F-1 mod q. Then, perform the plaintext-ciphertext multiplication operation. Take c 0,i = (c 0,i,0 , c 0,i,1 ), i = 0, 1, …, F - 1 as the plaintext and multiply it by the ciphertext c1 to obtain the ciphertext vector c cMult = (c cMult,0 , c cMult,1 , …, ccMult,2F-1 ), where c cMult,2i = c 0,i,0 c1, c cMult,2i+1 = c 0,i,1 c1, i = 1, 2, …, F - 1. Finally, 2F ciphertexts c cMult = (c cMult,0 , c cMult,1 , …, c cMult,2F-1 ) are output.

[0109]

[0110]

[0111] S4.2: DB server response:

[0112] S4.2.1: The DB server returns the ciphertext c cMult to the user to respond to the user's query.

[0113] Preferably, the specific implementation of S5 includes the following sub - steps:

[0114] S5.1: Multiple users jointly decrypt the response to obtain the final query result:

[0115] S5.1.1: The user receives the query ciphertext result c cMult returned by the server - side, and uses the homomorphic ciphertext decryption algorithm based on ciphertext chunking to jointly decrypt the response, and calculates the database - stored data DB idx ← chunksDec(sk, c cMult ), that is, the final query result.

[0116] Among them, since the previous homomorphic ciphertext multiplication based on ciphertext chunking, chunksHEMult, cuts the ciphertext with a large coefficient into ciphertext chunks with a small coefficient and performs the plain - text and ciphertext multiplication operation by treating the ciphertext chunks as plaintext. Therefore, to decrypt the ciphertext c cMult to obtain m0m1, 2 decryptions are required, that is, three processes of decryption, reconstruction, and decryption are executed in sequence, which is called the homomorphic ciphertext decryption algorithm based on ciphertext chunking: m ← chunksDec(sk, c cMult ). The specific process is as follows: Input a group of ciphertexts c cMult = (c cMult,0 , c cMult,1 , …, c cMult,2F-1 ). First, perform the chunk decryption operation to decrypt each ciphertext of c cMult to get m cMult,i = MKFHE.Dec(sk, c cMult,i), i = 0, 1, …, 2F - 1. Then calculate Reconstruct to form a new ciphertext ct = (ct0, ct1). Finally, perform the decryption operation m again cMult = MKFHE.Dec(sk, ct), to obtain the final message output m cMult , that is, the database data DB corresponding to the index idx idx

[0117]

[0118] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application and not to limit them. Although the present application has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: modifications or equivalent replacements can still be made to the specific implementation manners of the present application, and any modification or equivalent replacement that does not depart from the spirit and scope of the present application should be covered by the protection scope of the claims of the present application.

Claims

1. A privacy information retrieval method supporting dynamic database update, characterized in that: include: Step 1: Build a database, and the database management system verifies the user's access rights; Step 2: If the database needs to be updated dynamically, add corresponding storage status tags to the elements in the database, and make the updated storage status tags of the database public to users who have passed the access rights verification; Step 3: The user enters the location index of the data to be queried in the database, and uses the normalized public key to generate an encrypted query for the location, and sends the encrypted query to the server; Step 4: The server expands the received encryption query to obtain multiple ciphertext vectors, and uses the optimization technique of matrix-vector multiplication and homomorphic ciphertext multiplication based on ciphertext block to calculate the ciphertext result and return it to the user; Step 5: The user receives the ciphertext result returned by the server and performs joint decryption on it to calculate the database storage data corresponding to the query index, that is, the final query result.

2. The method according to claim 1, characterized in that The construction of the database comprises: Build a database DB of size n and represent the database DB as Matrix M, the element in the ath row and bth column of matrix M is denoted as DB a,b , 3. The method according to claim 1, characterized in that The database management system verifies the user's access rights, including: Step 11: When the user uses the database management system for the first time, he / she enters the user name and password to register, processes the user password through a hash algorithm, and stores the registered user name and the processed user password in the database; when the user logs into the database management system, he / she enters the user name and password on the login interface, and the database management system queries the database, finds the record matching the entered user name, and obtains the stored hash value; Step 12: Use the same hash algorithm as step 11 to hash the password entered by the user and compare it with the hash value stored in the database; if the two match, the authentication is successful; otherwise, the login fails; after the authentication is successful, the database management system creates a user session and provides access rights. In the database management system, the user's permissions are controlled by the access control list.

4. The method according to claim 1, characterized in that: The step 2 comprises: If you need to dynamically update the database, use (DB r,c ,+),(DB r,c ,-),(DB r,c , *) represent the element DB stored in the rth row and cth column of the current database r,c The status is the data that is newly added to the database, abolished, or remains unchanged.

5. The method according to claim 1, characterized in that The step 3 comprises: The jth user U j Input the query index idx∈{0,1,…,n-1} in the user terminal, that is, user U j Query the idx-th record in the database, j∈[1,K]; user U j Convert the index idx to (idx0,idx1), is the number of rows and columns of the database; idx0 is the row coordinate of the database data corresponding to the index idx in the database matrix, and idx1 is the column coordinate of the database data corresponding to the index idx in the database matrix; UserU j Generate encrypted query using unified public key pk j =(query row ,query col ),in To query the encrypted value of the row coordinates, To query the encrypted value of the column coordinate, user U j Query j Send to the server, and They are polynomial encodings of idx0 and idx1 respectively, and MKFHE.Enc(·) is an encryption algorithm based on multi-key fully homomorphic encryption.

6. The method according to claim 5, characterized in that The step 4 comprises: Step 41: The server receives user U j Encrypted query sent j =(query row ,query col ), by extending the algorithm Extending the query row Get the ciphertext By extending the algorithm Extending the query col Get the ciphertext Expand(·) indicates the expansion algorithm; Step 42: The server calculates the ciphertext row vector in M is the database matrix; Step 43: The server calculates chunksHEMult(v k ,c col,k ,F) Get the ciphertext result c cMult,k , Then use homomorphic addition to sum where c cMult Contains 2F ciphertexts (c cMult,0 ,c cMult,1 ,…,c cMult,2F-1 ), chunksHEMult(·) is the homomorphic ciphertext multiplication based on ciphertext blocks, and F is the block size; Step 44: The server sends the ciphertext c cMult Return to the user in response to the user's query.

7. The method according to claim 6, characterized in that The step 41 comprises: The expansion algorithm Expand(·) requires the homomorphic operation Sub(ct,k): first replace x with x for ct = (ct0(x), ct1(x)) k , which is transformed into ct′=(ct0(x k ),ct1(x k )), the corresponding decryption key changes to s(x k ); then use the key conversion algorithm to process the ciphertext ct′, and obtain the ciphertext ct″ with the decryption key s(x). At this time, ct″ becomes the decryption key of the message m(x k ) encryption; By extending the algorithm, according to Get the ciphertext The specific process is: input query = MKFHE.Enc (x idx ) and the size of the database Find a minimum m=2 l , so that Initialize the ciphertext vector ciphertexts = [query] with query; perform an outer iteration loop for j = 0, 1, ..., l-1: first perform an inner iteration loop, for k = 0, 1, ..., 2 j -1 Run c0←ciphertexts[k], Assign to c1, c0+Sub(c0,N / 2 j +1) Assign value to c′ k , c1+Sub(c1,N / 2 j +1) Assign to After the inner iteration loop is finished, set ciphertexts to Continue to execute the next outer iteration loop; after the outer iteration loop is completed, m -1 mod t is assigned to inverse; for Setting c row,j = inverse·ciphertexts[j], output a set of ciphertexts 8. The method according to claim 6, characterized in that The step 42 comprises: Through the homomorphic linear transformation algorithm Calculate the matrix M and vector The process of multiplying to obtain the ciphertext row vector v is: Input matrix M and vector Find the matrix M Diagonal vectors Initialize the ciphertext row vector v, Execute from n to n-1 respectively. Assign it to v, where Rot(·) represents the ciphertext rotation operation, Add(·) represents homomorphic addition, and finally returns the output ciphertext row vector v.

9. The method according to claim 6, characterized in that The step 43 comprises: Input two homomorphically encrypted ciphertexts v k ,c col,k and block size F, perform ciphertext block operation, let weight The ciphertext v k Do 2 w Decompose into F blocks v 0,0 ,v 0,1 ,…,v 0,F-1 , satisfying v k =v 0,0 +2 w v 0,1 +…+2 (F -1)w v 0,F-1 mod q, perform plaintext and ciphertext multiplication, and convert v 0,i =(v 0,i,0 ,v 0,i,1 ),i=0,1,…,F-1 as plaintext and ciphertext c col,k Multiply them together to get the ciphertext vector c cMult,k =(c cMult,k,0 ,c cMult,k,1 ,…,c cMult,k,2i ,c cMult,k,2i+1 ,…,c cMult,k,2F-1 ), where c cMult,k,2i =v 0,i,0 c col,k , c cMult,k,2i+1 =v 0,i,1 c col,k ,i=1,2,…,F-1, mod is the remainder function, q is the modulus of the ciphertext space; Then use homomorphic addition to sum and output the ciphertext where c cMult Contains 2F ciphertexts (c cMult,0 ,c cMult,1 ,…,c cMult,2F-1 ).

10. The method according to claim 1, characterized in that The step 5 comprises: The user receives the query ciphertext result c returned by the server cMult =(c cMult,0 ,c cMult,1 ,…,c cMult,2F-1 ) and input it into the chunksDec algorithm to generate the final decryption result; the chunksDec algorithm first performs a block decryption operation on c cMult Decrypt each ciphertext m cMult,i =MKFHE.Dec(sk,c cMult,i ),i=0,1,…,2F-1, calculate Reconstruct the new ciphertext ct = (ct0, ct1) and perform the decryption operation m again cMult =MKFHE.Dec(sk,ct), get the final message output m cMult , that is, query the database data DB corresponding to the index idx idx , MKFHE.Dec(·) is a decryption algorithm based on multi-key fully homomorphic, chunksDec is a homomorphic ciphertext decryption algorithm based on ciphertext block, and sk is the user's private key.