Multi-source encrypted data Boolean query method and computer readable medium

By using the technology of generating system parameters and decomposing encrypted indexes in the multi-source encrypted data Boolean query method, the problems of low efficiency of encrypted data query and insufficient support for multi-source query in the existing technology are solved, and a secure and efficient multi-source encrypted data Boolean query is realized.

CN120223304AActive Publication Date: 2025-06-27WUHAN UNIV
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202510458808.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-14
Publication Date
2025-06-27
Estimated Expiration
2045-04-14

AI Technical Summary

Technical Problem

The prior art is inefficient in Boolean queries for encrypted data and is difficult to support multi-source data queries, with security and complexity challenges.

Method used

A secure and efficient multi-source encrypted data Boolean query method is designed, and system parameters are generated through the key generation center to generate keys for data owners, data users and cloud servers. The data owner constructs an encrypted index and decomposes it into four sub-indexes. The user obtains the key through authorization to query. Cloud server A processes the index and transmits it to cloud server B for boolean calculations, and finally returns the query result.

Benefits of technology

It realizes the efficient completion of Boolean queries for encrypted data without decryption, supports multi-source data query, improves query efficiency and security, and avoids unauthorized data access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223304A_ABST
    Figure CN120223304A_ABST
Patent Text Reader

Abstract

The invention discloses an encrypted data Boolean query method and a computer readable medium, and relates to the technical field of network and information security, the method comprises the following steps: a key generation center generates system parameters, and generates keys for a data owner, a data user and a cloud server; each data owner encrypts own data, generates an index for the encrypted data, and stores the encrypted data and the index in a cloud server A; after each data user obtains the authorization of the data owner, constructing a query request to initiate Boolean query to the cloud server A; and the cloud server A stores the encrypted data and the indexes, processes the related indexes according to the query request, sends the indexes to the cloud server B for further Boolean calculation, finds the data corresponding to the query by using the calculation result, and returns the data to the data user. Compared with a current encrypted data Boolean query method, the problems that the query efficiency is low and multi-source data query is not supported are mainly solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network and information security technologies, and in particular, to a secure and efficient multi-source encrypted data Boolean query method and a computer-readable medium. Background Art

[0002] The development of cloud computing technology has brought many conveniences to data processing. More and more enterprises and institutions choose to upload private data to the cloud to calculate and share data more conveniently and efficiently. However, hosting data on a cloud server means losing control of the data, and users cannot know whether their data has been stolen or modified. To solve the trust problem brought by storing data in the cloud, sensitive data is usually encrypted to prevent unauthorized access. However, ciphertext data is usually unreadable, and it is not only difficult but also very time-consuming to directly query ciphertext data. Traditional data retrieval methods need to decrypt all data to obtain plaintext data before querying. Whether decrypting and querying in the cloud or decrypting locally after downloading, it is impossible to ensure both security and efficiency at the same time. Therefore, it is necessary to complete the query without decrypting.

[0003] As a solution to ciphertext query, searchable encryption technology has been extensively studied in recent years, especially Boolean query. However, limitations in efficiency and functionality have hindered its widespread use in practical scenarios. To improve query efficiency, Boolean query is usually regarded as multiple conjunctive queries. The cloud server executes each conjunctive query separately and merges all query results as the final result. This method has poor support for complex queries and cannot handle the NOT operation in Boolean queries. While a complete Boolean query method usually involves complex cryptographic algorithms with high computational costs and is difficult to apply to large-scale data. In addition, querying data from multiple sources simultaneously is also an important application scenario for ciphertext query. Existing systems only consider a single data owner. To complete multi-source queries in them, a unified index needs to be constructed for the data of different data owners. However, this also means that once a user obtains authorization from one data owner, they can access the data of all other data owners. Summary of the Invention

[0004] Based on the above problems, the present invention proposes a secure and efficient multi-source encrypted data Boolean query method and a computer-readable medium, which solves the problems of low query efficiency and lack of support for multi-source data query in the Boolean query of encrypted data.

[0005] A secure and efficient multi-source encrypted data Boolean query method designed by the present invention includes the following steps:

[0006] S1: The key generation center generates system parameters and generates corresponding keys for the data owner, data user, and cloud server based on the generated system parameters;

[0007] S2: The data owner constructs an index for the data document, calculates the hash value of each keyword as a binary number, divides the index into four sub - indexes with the cooperation of two pseudo - random binary strings, encrypts each sub - index, and then sends it to cloud server A. The relationship between each bit of the sub - index and the original index is determined by the values of the corresponding bits of the two pseudo - random binary strings. Suppose the index has five bits, and the two pseudo - random binary strings are 10111 and 00010 respectively. Then the third bit of the sub - index is determined by the third bit '1' of 10111 and the third bit '0' of 00010.

[0008] S3: The data user sends his own identity to the data owner, and the data owner generates a key dedicated to the data user to complete the authorization process;

[0009] S4: The data user constructs a query request according to the keywords involved in the query and the key of the data owner, and sends it to cloud server A;

[0010] S5: Cloud server A searches for the corresponding index according to the request of the data user, combines the indexes of different data owners corresponding to each keyword into a computable index, and hides the order characteristics of these indexes through permutation, and then sends it to cloud server B;

[0011] S6: Cloud server B performs a Boolean calculation using the index sent by cloud server A and returns the result to cloud server A;

[0012] S7: Cloud server A finds the corresponding data document according to the calculation result of cloud server B and returns it to the data user.

[0013] Furthermore, when the data owner adds a new data document, it constructs an addition request and sends it to cloud server A, and cloud server A completes the index update; when the data owner deletes a data document, it constructs a deletion request and sends it to cloud server A, and cloud server A completes the index update.

[0014] Furthermore, step S1 includes:

[0015] S1.1: The key generation center selects a bilinear group of prime order p There exists a group and an efficiently computable bilinear map e: g is a generator of

[0016] S1.2: The key generation center selects a pseudo-random generator PRG to generate pseudo-random binary strings, and selects two hash functions H1 and H2, which are respectively used to convert binary strings of any length into elements in the group and a single-bit binary number;

[0017] S1.3: The key generation center assigns an identity to each data owner in the system and generates two keys for it. The keys are elements in the integer group modulo p;

[0018] S1.4: The key generation center assigns an identity to each data user in the system.

[0019] S1.5: The key generation center generates a pair of public and private keys for asymmetric encryption, sends the private key to cloud server B, and sends the public key to all data owners and data users.

[0020] Furthermore, step S2 includes:

[0021] S2.1: The data owner constructs an index for his own document according to the keywords used for querying, calculates a binary index with a length equal to the number of documents for each keyword, and each bit in it represents the presence of the keyword in the corresponding document;

[0022] S2.2: The data owner selects two random keys k a,1 , and respectively uses the pseudo-random generator PRG based on these two keys to generate two binary strings r1 = [PRG(k a,1 )] 1…m 、r2 = [PRG(k a,2 )] 1…m , where is the set of rational numbers, and [PRG(k a,1 )] 1…m represents the 1st to mth bits of the pseudo-random binary string generated by the pseudo-random generator PRG using the key k a,1 ;

[0023] S2.3: The data owner uses the hash function H2 to calculate a hash value p i of a single-bit binary number for each keyword w i , and decomposes the index idx i corresponding to the keyword according to p i and the two binary strings r1 and r2 into four sub-indexes idx i,1 , idx i,2 , idx i,3 , idx i,4 , and each bit of the sub-index satisfies the condition: This satisfies the security requirements when the sub-indexes are stored on the cloud server. When the cloud server cannot distinguish the relationships between the indexes, from the perspective of the cloud server, these indexes are indistinguishable from randomly generated binary strings.

[0024] S2.4: The data owner calculates the encrypted index for each sub-index idx i,j and calculates a tag for each encrypted index where sk a,1 , sk a,2 are the keys generated by the key generation center for the data owner; that is, the data owner calculates an element in the group i based on the keyword w associated with each sub-index i and the number j ∈ [1, 4] using the hash function H1, and uses the group generator g and two keys sk distributed by the key generation center to perform bilinear mapping calculations. The two keys are respectively calculated to obtain two values, one of which is used as the tag tag a,1 of this sub-index, and the other is used as the key of the pseudo-random generator PRG to calculate a binary string, and the binary string and the sub-index are XORed to obtain the encrypted index eidx a,2 ; i,j i,j ;

[0025] S2.5: The data owner generates an index to indicate the deletion status of the document. Initially, each bit is 1, indicating that the document has not been deleted, and each bit is encrypted separately using the asymmetric encryption public key to prevent the cloud server A from learning the deletion status of the document when the index is stored on the cloud server A;

[0026] S2.6: The data owner sends the encrypted document, all "tag-encrypted index" pairs, the correspondence between each bit of the document and the index, the index indicating the deletion status, and its own identity to the cloud server A for storage.

[0027] Furthermore, step S3 includes:

[0028] S3.1: The data user sends its own identity to the data owner;

[0029] S3.2: The data owner selects a dedicated key for the data user from the group of integers modulo p, and sends the key, the two keys used by the data owner to generate the binary string, and the number of data documents owned by the data owner to the data user;

[0030] S3.3: The data owner calculates two derived keys based on the key generated for the user and the two keys distributed by the key generation center, and stores them on cloud server A so that cloud server A can find and decrypt relevant indexes according to the user's request.

[0031] Further, step S4 includes:

[0032] S4.1: The data user represents the query to be made as a form of a keyword set W' and a Boolean expression f;

[0033] S4.2: The data user selects a random number as the key, uses a pseudo-random generator PRG to generate a binary string q, and replaces each keyword in W' according to each bit of this binary string. If it is 0, the two replaced keywords respectively correspond to the 1st and 2nd sub-indexes. If it is 1, the two replaced keywords respectively correspond to the 3rd and 4th sub-indexes. Finally, a new keyword set W is obtained; the replaced keywords no longer have practical meanings, but are the same as the values used when the data owner calculates the labels of the sub-indexes, so as to be used for subsequent cloud server calculations of labels;

[0034] S4.3: The data user calculates an N-dimensional vector p according to each keyword w in W' i where each bit is p[i] = H2(w i ), and replaces each variable a in f according to p and q j with (◇ j,1 a j,1 ∧◇ j,2 a j,2 ), where ◇ j,1 , to obtain {f 0,0 , f 0,1 , f 1,0 , f 1,1}, in each f c,d ,

[0035] Specifically: The data user calculates a one-bit binary number for each keyword in the original keyword set W' using the hash function H2, forms a vector p with these numbers, and replaces each variable in the Boolean expression f according to p and q to generate a new expression f 0,0 : For the j-th variable a in f j , if q[j] = 0 and p[j] = 0, it is replaced with (a j,1 ∧a j,2 ); if q[j] = 1 and p[j] = 0, it is replaced with if q[j] = 0 and p[j] = 1, it is replaced with If q[j] = 1 and p[j] = 1, then replace with

[0036] The data user replaces each variable in f according to p and q to generate a new expression f 0,1 : For the j-th variable a in f j , if q[j] = 0 and p[j] = 0, then replace with If q[j] = 1 and p[j] = 0, then replace with (a j,1 ∧a j,2 ); if q[j] = 0 and p[j] = 1, then replace with If q[j] = 1 and p[j] = 1, then replace with

[0037] The data user replaces each variable in f according to p and q to generate a new expression f 1,0 : For the j-th variable a in f j , if q[j] = 0 and p[j] = 0, then replace with If q[j] = 1 and p[j] = 0, then replace with If q[j] = 0 and p[j] = 1, then replace with If q[j] = 1 and p[j] = 1, then replace with (a j,1 ∧a j,2 );

[0038] The data user replaces each variable in f according to p and q to generate a new expression f 1,1 : For the j-th variable a in f j , if q[j] = 0 and p[j] = 0, then replace with If q[j] = 1 and p[j] = 0, then replace with If q[j] = 0 and p[j] = 1, then replace with (a j,1 ∧a j,2 ); if q[j] = 1 and p[j] = 1, then replace with

[0039] S4.4: The data user represents the set of Boolean expressions F = {f 0,0 , f 0,1 , f 1,0 , f 1,1} as a string and encrypts F using the public key of asymmetric encryption to obtain F';

[0040] S4.5: The data user selects a random number rk, then uses the keys of each data owner involved in the query to restore the two binary strings used when they decompose the index, and concatenates these binary strings to obtain two binary strings with lengths equal to the total number of documents of the data owners involved in the query. Then, these two binary strings are respectively XORed with a binary string of the same length calculated using rk as the key of the pseudo-random generator PRG to obtain r1 and r2;

[0041] S4.6: The data user generates a random permutation order π, permutes r1 and r2 respectively to disrupt the order of each bit, and encrypts the permuted {r1, r2} using the public key of the asymmetric encryption to obtain {r′1, r′2};

[0042] S4.7: The data user calculates the trapdoor for each keyword in the keyword set W. The trapdoor is calculated based on the hash value of the keyword and the key generated for the data user by each data owner during the authorization process. Based on the principle of bilinear mapping, cloud server A can find and decrypt the index related to the keyword through these trapdoors. Then, the data user sends the trapdoor, the identities of the data owners involved in the query, the encrypted boolean expression, {r′1, r′2}, rk, π, and its own identity to cloud server A.

[0043] Furthermore, step S5 includes:

[0044] S5.1: Cloud server A finds the derived key stored on cloud server A during the authorization process according to the identities of the data user and the data owners;

[0045] S5.2: Cloud server A finds all the encrypted indexes involved through the derived key and the trapdoor, decrypts them to obtain the index values without XOR calculation, then concatenates all the indexes corresponding to each keyword in the order of the data owners, and XORs them with the binary string calculated using rk as the key of the pseudo-random generator PRG to obtain a total index. At this time, although the index is no longer in the XOR encryption state, since these indexes are sub-indexes and cloud server A does not know the keywords corresponding to these indexes and the relationships between the indexes, cloud server A cannot learn any information from the indexes;

[0046] S5.3: Cloud server A finds the indexes of the record deletion status of each data owner involved in the query, and also concatenates these indexes into a total index d';

[0047] S5.4: Cloud server A permutes the total index of each keyword and d' using π, and then sends them together with the encrypted boolean expression and {r′1, r′2} to cloud server B.

[0048] Even further, step S6 includes:

[0049] S6.1: The cloud server B uses the private key of asymmetric encryption to decrypt the Boolean expression, decrypts {r′1,r′2} to obtain {r1,r2}, and then substitutes the total index corresponding to all keywords into the four Boolean expressions to calculate ridx1, ridx2, ridx3, and ridx4;

[0050] S6.2: The cloud server B uses the private key of asymmetric encryption to decrypt each bit of d', obtains d'', and calculates Sends ridx to the cloud server A.

[0051] Further, step S7 includes:

[0052] S7.1: The cloud server A uses π to perform an inverse permutation on ridx to obtain ridx′;

[0053] S7.2: The cloud server A splits ridx′ according to the number of documents of each data owner as the index of the query result of each data owner, and finds the documents corresponding to the positions where each bit of the index is 1 according to the corresponding relationship between the document and the sum of each bit of the index, and sends them to the data user.

[0054] Further, when the data owner adds a new document, according to the steps described in S2.1 - S2.4, calculates the encrypted index and the corresponding tag for the document separately, and then uses the public key of asymmetric encryption to encrypt the number 1 to obtain d new and sends the encrypted document, encrypted index, tag, d new and its own identity to the cloud server A;

[0055] The cloud server A finds the corresponding encrypted index for each tag, adds the encrypted index of the new document to the end, and records the corresponding relationship between the newly added bit and the newly added document;

[0056] The cloud server A finds the index recording the deletion status and adds d new to the end;

[0057] After the cloud server A completes the index update, the data owner synchronizes the updated number of documents to all authorized data users.

[0058] Further, when the data owner deletes a document, constructs a new binary index, sets the positions corresponding to the deleted documents to 0, and the remaining positions to 1, and encrypts each bit using the public key of asymmetric encryption to obtain the index d′, and then sends d′ and its own identity to the cloud server A;

[0059] The cloud server A finds the index recording the deletion status and replaces it with d′.

[0060] Based on the same inventive concept, the present invention also designs a computer-readable medium, on which a computer program is stored, and when the program is executed by a processor, the multi-source encrypted data Boolean query method described above is implemented.

[0061] The advantages of the present invention are as follows:

[0062] The present invention includes a key generation center, multiple data owners, multiple data users, and two cloud servers A and B. The key generation center generates system parameters and generates keys for the data owners, data users, and cloud servers; each data owner encrypts its own data document, generates an index for the encrypted document, and stores the encrypted document and the index on cloud server A; each data user obtains authorization from the data owner, constructs a query request, and initiates a Boolean query to cloud server A; cloud server A stores the encrypted document and the index, processes the involved index according to the query request, and then hands it over to cloud server B for further Boolean calculation, and uses the calculation result to find the data document corresponding to the query and returns it to the data user.

[0063] Compared with the traditional method, the present invention designs a bitmap-based encrypted index, maps the Boolean query to a logical operation on the index, so that the query efficiency is close to the plaintext query, and it has good performance under any form of complex query. The index is stored on the cloud server in the form of four decomposed sub-indexes, and only authorized users can use the index for query. At the same time, the simple structure design enables the index to be flexibly combined, so as to realize multi-source data query. And the user can perform a Boolean query on the data of multiple data owners at the same time, and the query process is safe and efficient, and it is impossible to query unauthorized data. BRIEF DESCRIPTION OF THE DRAWINGS

[0064] Figure 1 It is a schematic diagram of the model structure of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0065] The present invention will be further described below with reference to the drawings.

[0066] Embodiment 1

[0067] In this embodiment, it is considered that the key generation center is completely trustworthy, and the data owners, data users, cloud server A, and cloud server B are honest and curious, which means that they will honestly execute the predefined algorithms, but may try to access unauthorized data or learn more valuable information from the encrypted data and the calculation process. In addition, cloud server A and cloud server B will not collude.

[0068] As Figure 1 shown, a secure and efficient multi-source encrypted data Boolean query method provided by the present invention includes the following steps:

[0069] S1: The key generation center generates system parameters and generates corresponding keys for the data owner, data user, and cloud server based on the generated system parameters.

[0070] S2: The data owner constructs an index for the data document, calculates the hash value of each keyword as a binary number, divides the index into four sub - indexes with the cooperation of two pseudo - random binary strings, encrypts each sub - index, and then sends it to cloud server A. The relationship between each bit of the sub - index and the original index is determined by the values of the corresponding bits of the two pseudo - random binary strings.

[0071] S3: The data user sends his own identity to the data owner, and the data owner generates a key dedicated to the data user to complete the authorization process.

[0072] S4: The data user constructs a query request according to the keywords involved in the query and the key of the data owner, and sends it to cloud server A.

[0073] S5: Cloud server A searches for the corresponding index according to the request of the data user, combines the indexes of different data owners corresponding to each keyword into a computable index, and hides the order characteristics of these indexes through permutation, and then sends it to cloud server B.

[0074] S6: Cloud server B performs a Boolean calculation using the index sent by cloud server A and returns the result to cloud server A.

[0075] S7: Cloud server A finds the corresponding data document according to the calculation result of cloud server B and returns it to the data user.

[0076] S8: When the data owner adds a new data document, it constructs an addition request and sends it to cloud server A, and cloud server A completes the index update.

[0077] S9: When the data owner deletes a data document, it constructs a deletion request and sends it to cloud server A, and cloud server A completes the index update.

[0078] In one implementation, step S1 includes:

[0079] S1.1: The key generation center selects a bilinear group of prime order p There exists a group and a bilinear map e: g is a generator of

[0080] S1.2: The key generation center selects a pseudo - random generator PRG and two hash functions H1: H2: {0, 1} * →{0, 1};

[0081] S1.3: The key generation center assigns an identity oid i to each data owner DO i in the system, and generates two keys sk i,1 , where is the integer group modulo p;

[0082] S1.4: The key generation center assigns an identity uid i to each data user DU i in the system.

[0083] S1.5: The key generation center generates a pair of public and private keys pk B and sk B for asymmetric encryption, sends sk B to the cloud server B, and sends pk B to all data owners and data users.

[0084] In one implementation, step S2 includes:

[0085] S2.1: A certain data owner, denoted as DO a , constructs an index idx = {idx2, idx2, …, idx } for its m documents according to the keywords used for query: For each keyword n , calculates a binary index idx of length m, and each bit of the index satisfies i

[0086] S2.2: The data owner DO a selects two keys k a,1 , uses a pseudo-random generator to calculate two binary strings r1 = [PRG(k a,1 )] 1…m and r2 = [PRG(k a,2 )] 1…m . Where is the set of rational numbers, and [PRG(k a,1 )] 1…m represents the 1st to mth bits of the pseudo-random binary string generated by the pseudo-random generator PRG using the key k a,1 ;

[0087] S2.3: The data owner DO a calculates p i for each index idx i ∈idx as p i), and then construct a sub-index idx i,1 , idx i,2 , idx i,3 , idx i,4 . Each bit of the sub-index satisfies the condition: If and then idx i,1 [j] ∧ idx i,2 [j] = idx i [j], If and then idx i,3 [j] ∧ idx i,4 [j] = idx i [j]; If and then If and then That is, according to and being (0,0), (0,1), (1,0), (1,1) in four cases, determine the value of the sub-index according to one of the corresponding four construction methods above, and each bit of the index corresponds to different cases respectively.

[0088] S2.4: The data owner DO a calculates the encrypted index i,j for each sub-index idx and calculates the tag

[0089] for each encrypted index a S2.5: The data owner DO m generates an index to indicate the deletion status of the document, initially {1} B , and encrypts each of its bits with the asymmetric encryption public key pk a . Among them, {1} m is a binary string composed of m 1s;

[0090] S2.6: The data owner DO a sends the encrypted document, all "tag-encrypted index" pairs {tag i,j , eidx i,j}, the correspondence between the encrypted document and each bit of the index, and d a and its own identity uid a to the cloud server A for storage.

[0091] In one implementation, step S3 includes:

[0092] S3.1: The data user, denoted as DU i , sends his / her identity uid i to the data owner DO a ;

[0093] S3.2: The data owner DO a generates a secret key for the data user DU i and sends uk , k a , k a,1 , and the number m of the data documents he / she owns a,2 to the data user DU a ; i ;

[0094] S3.3: The data owner DO a calculates the secret keys and using oid a and uid i as markers and sends them to cloud server A for storage.

[0095] In one implementation, step S4 includes:

[0096] S4.1: For the data user, where the number of keywords in his / her query is denoted as N, and the identities of the data owners {DO1, DO2,..., DO x} involved in the query are denoted as R = {oid1, oid2,..., oid x}, and the number of documents of each data owner DO i is denoted as m i , the query is represented in the form of a set W' containing N keywords and a Boolean expression f(a1, a2,..., a N );

[0097] S4.2: The data user selects a random number rand, calculates q = [PRG(rand)] 1…N , and then replaces each keyword in W': if q[i] = 0, then replace the i-th keyword with w i ||1 and w i ||2; if q[i] = 1, then replace the i-th keyword with w i ||3 and w i ||4; to obtain a new set W containing 2N keywords;

[0098] S4.3: The data user calculates an N-dimensional vector p based on each keyword w i in W', where each bit is p[i] = H2(w i), and substitute each variable in f according to p and q to generate a new expression f 0,0 : For the j-th variable a in f j , if q[j]=0 and p[j]=0, substitute with (a j,1 ∧a j,2 ); if q[j]=1 and p[j]=0, substitute with If q[j]=0 and p[j]=1, substitute with If q[j]=1 and p[j]=1, substitute with

[0099] The data user substitutes each variable in f according to p and q to generate a new expression f 0,1 : For the j-th variable a in f j , if q[j]=0 and p[j]=0, substitute with If q[j]=1 and p[j]=0, substitute with (a j,1 ∧a j,2 ); if q[j]=0 and p[j]=1, substitute with If q[j]=1 and p[j]=1, substitute with

[0100] The data user substitutes each variable in f according to p and q to generate a new expression f 1,0 : For the j-th variable a in f j , if q[j]=0 and p[j]=0, substitute with If q[j]=1 and p[j]=0, substitute with If q[j]=0 and p[j]=1, substitute with If q[j]=1 and p[j]=1, substitute with (a j,1 ∧a j,2 );

[0101] The data user substitutes each variable in f according to p and q to generate a new expression f 1,1 : For the j-th variable a in f j , if q[j]=0 and p[j]=0, substitute with If q[j]=1 and p[j]=0, substitute with If q[j]=0 and p[j]=1, substitute with (a j,1 ∧a j,2 ); if q[j]=1 and p[j]=1, substitute with

[0102] S4.4: The data user sets the set of Boolean expressions F = {f0,0 , f 0,1 , f 1,0 , f 1,1} is represented as a string and the public key pk of the asymmetric encryption is used B Encrypt F to obtain F';

[0103] S4.5: The data user selects a random number rk and uses the key {k i , k i,1 , k i,2} of each data owner DO involved in the query to calculate and to obtain and Then calculate and

[0104] S4.6: The data user generates a random permutation order π, permutes r1 and r2 respectively to shuffle the order of each bit, and uses the public key pk of the asymmetric encryption B to encrypt the permuted {r1, r2} to obtain {r′1, r′2};

[0105] S4.7: The data user calculates the trapdoor for each keyword w in the keyword set W k where where Send to the cloud server A. Where uid is the identity of the data user and uk i is the key generated by the data owner DO i for the data user during the authorization process.

[0106] In one implementation, step S5 includes:

[0107] S5.1: The cloud server A obtains (T, R, F′, {r′1, r′2}, rk, π, uid), and finds the corresponding key according to uid and each oid in R i find the corresponding key

[0108] S5.2: For each T k ∈ T, for each in it, calculate find the corresponding encrypted index calculate Then calculate where m i is the number of data documents of the data owner DO i , and the cloud server A can obtain m according to the length of i ​;

[0109] S5.3: Cloud server A finds the corresponding d for each oid in R i and calculates d = (d1||d2||…||d i ); x

[0110] S5.4: Cloud server A uses π to permute each e k to obtain e′ k , uses π to permute d to obtain d', and sends to cloud server B. Permutation means adjusting the position of each bit in the index according to an order π. For example, if π is [2,3,5,1,4], it means moving the original first bit to the second position, the second bit to the third position, the third bit to the fifth position, the fourth bit to the first position, and the fifth bit to the fourth position. For example, "abcde" becomes "dabec" after the above permutation.

[0111] In one implementation, step S6 includes:

[0112] S6.1: Cloud server B uses the asymmetric encryption private key sk B to decrypt F' and {r′1,r′2} to obtain F = {f 0,0 ,f 0,1 ,f 1,0 ,f 1,1} and {r1,r2}, and substitutes all e′ k ∈e into the four Boolean expressions f 0,0 ,f 0,1 ,f 1,0 ,f 1,1 respectively to calculate ridx1, ridx2, ridx3, ridx4;

[0113] S6.2: Cloud server B decrypts each bit of d' using the asymmetric encryption private key sk B to obtain d”, calculates , and sends ridx to cloud server A.

[0114] In one implementation, step S7 includes:

[0115] S7.1: Cloud server A uses π to inversely permute ridx to obtain ridx′;

[0116] S7.2: Cloud server A splits ridx′ into {ridx′1,ridx′2,…,ridx′ x ​}, as the index of the query results of each data owner, and according to the correspondence between the document and each bit of the index, find the documents corresponding to the positions where the value is 1 in each result index and send them to the data user.

[0117] In one embodiment, step S8 includes:

[0118] S8.1: The data owner, denoted as DO a , add a new document D new When, according to the steps described in S2.1 - S2.4, for and calculate the encrypted index and the corresponding tag Use the public key pk of asymmetric encryption B to encrypt the number 1 to get d new , and send the encrypted document and to cloud server A;

[0119] S8.2: Cloud server A finds the corresponding encrypted index for each tag i , add eidx i to its end, and record the correspondence between the newly added bit and the newly added document;

[0120] S8.3: Cloud server A finds the index d a according to oid a , add d new to the end of d a ;

[0121] S8.4: After cloud server A completes the index update, the data owner synchronizes the updated number of documents m a to all authorized data users.

[0122] In one embodiment, step S9 includes:

[0123] S9.1: The data owner, denoted as DO a , when deleting a document, construct a new binary index, where the positions corresponding to the deleted documents are set to 0, and the remaining positions are set to 1, and use the public key pk of asymmetric encryption B to encrypt each bit to get the index d' a , then send d' a and oid a to cloud server A;

[0124] S9.2: Cloud server A finds the index d a according to oid a , and replace d a with d' a .

[0125] Embodiment 2

[0126] Based on the same inventive concept, the present invention also provides a computer-readable medium, on which a computer program is stored, and when the program is executed by a processor, the method described in Embodiment 1 is implemented.

[0127] Since the device introduced in Embodiment 2 of the present invention is a computer-readable medium used for implementing the multi-source encrypted data Boolean query method in Embodiment 1 of the present invention, based on the method introduced in Embodiment 1 of the present invention, those skilled in the art can understand the specific structure and variations of the electronic device, so it will not be elaborated here. Any electronic device adopted by the method in Embodiment 1 of the present invention falls within the scope of protection of the present invention.

[0128] The specific embodiments described herein are merely illustrative of the spirit of the present invention. Those skilled in the art to which the present invention pertains can make various modifications or supplements to the described specific embodiments or use similar means for substitution, but will not deviate from the spirit of the present invention or exceed the scope defined by the appended claims.

Claims

1. A Boolean query method for multi-source encrypted data, characterized in that: The following steps are involved: S1: The key generation center generates system parameters and generates corresponding keys for data owners, data users and cloud servers based on the generated system parameters; S2: The data owner builds an index for the data document and calculates a binary hash value for each keyword. The index is divided into four sub-indexes with two pseudo-random binary strings, and each sub-index is encrypted and sent to cloud server A. The relationship between each bit of the sub-index and the original index is determined by the value of the corresponding bit of the two pseudo-random binary strings. S3: The data user sends his or her identity to the data owner, and the data owner generates a key dedicated to the data user to complete the authorization process; S4: The data user constructs a query request based on the keywords involved in the query and the key of the data owner, and sends it to cloud server A; S5: Cloud server A searches for the corresponding index according to the data user's request, combines the indexes of different data owners corresponding to each keyword into a computable index, hides the sequential features of these indexes by permutation, and sends it to cloud server B; S6: Cloud server B performs Boolean calculation using the index sent by cloud server A and returns the result to cloud server A; S7: Cloud server A finds the corresponding data document based on the calculation result of cloud server B and returns it to the data user.

2. The multi-source encrypted data Boolean query method according to claim 1, characterized in that: When the data owner adds a new data document, he constructs an add request and sends it to cloud server A, which completes the index update. When the data owner deletes a data document, he constructs a deletion request and sends it to cloud server A, which then completes the index update.

3. The multi-source encrypted data Boolean query method according to claim 1, characterized in that: Step S1 includes: S1.1: The key generation center selects a bilinear group of order p There is a group and a bilinear map S1.2: The key generation center selects a pseudo-random generator PRG to generate a pseudo-random binary string, and selects two hash functions H1 and H2 to convert a binary string of any length into a group The elements in and a binary digit; S1.3: The key generation center generates a DO for each data owner in the system. i Assign an identity oid i , and generate two keys for it in is the group of integers modulo p; S1.4: The key generation center is for each data user DU in the system i Assign an identity uid i ; S1.5: The key generation center generates a pair of public and private keys pk for asymmetric encryption B and sk B , the private key sk B Send to cloud server B, and send the public key pk B Sent to all data owners and data users.

4. The multi-source encrypted data Boolean query method as claimed in claim 3, characterized in that: Step S2 includes: S2.1: Data owner, denoted as DO a , based on the keywords used for the query For your own m documents Construct index idx = {idx2, idx2, ..., idx n }: For each keyword Compute a binary index idx of length m i , each bit of the index satisfies S2.2: The data owner selects two keys Use a pseudo-random generator to calculate two binary strings r1 = [PRG (k a,1 )] 1…m , r2=[PRG(k a,2 )] 1…m ,in is a set of rational numbers, [PRG(k a,1 )] 1…m Indicates that the pseudo-random generator PRG uses the key k a,1 Bits 1 to m of the generated pseudo-random binary string; S2.3: The data owner has a unique key for each index idx i ∈idx calculate p i =H2(w i ), then build the sub-index idx i,1 、idx i,2 、idx i,3 、idx i,4 , each bit of the sub-index satisfies the condition: S2.4: The data owner is for each sub-index idx i,j Calculate the encrypted index And calculate the label for each encrypted index Among them sk a,1 ,sk a,2 is the key generated by the key generation center for the data owner, and g is the group The generator of S2.5: The data owner generates an index to indicate the deletion status of the document, initially {1} m , use the asymmetric encryption public key pk for each bit B Encrypt and get d a , where {1} m is a binary string consisting of m 1s; S2.6: The data owner will send the encrypted document and all the "tag-encryption index" pairs {tag i,j ,eidx i,j }, the correspondence between the encrypted document and each bit of the index, and d a And its own identity is sent to cloud server A for storage.

5. The safe and efficient Boolean query method for multi-source encrypted data as claimed in claim 4, characterized in that: Step S4 includes: S4.1: Data user, the number of keywords in the query is denoted as N, and the data owners involved in the query are {DO1, DO2, …, DO x } is denoted as R = {oid1, oid2, …, oid x }, each data owner DO i The number of documents is denoted as m i , the query is represented as a set W' containing N keywords and a Boolean expression f(a1, a2, ..., a N ) in the form of S4.2: The data user selects a random number rand and calculates q = [PRG (rand)] 1…N , and then replace each keyword in W': if q[i] = 0, replace the i-th keyword with w i ||1 and w i ||2; If q[i]=1, replace the i-th keyword with w i ||3 and w i ||4; Get a new set W containing 2N keywords; S4.3: Data users calculate the value of each keyword w in W' i Calculate an N-dimensional vector p, each of which is p[i] = H2(w i ), and transform each variable a in f according to p and q j Replace with (◇ j,1 a j,1 ∧◇ j,2 a j,2 ),in Get {f 0,0 ,f 0,1 ,f 1,0 ,f 1,1 }, in each f c,d middle, S4.4: The data user sets the Boolean expression set F = {f 0,0 ,f 0,1 ,f 1,0 ,f 1,1 } is represented as a string and encrypted using the asymmetric public key pk B Encrypt F to get F'; S4.5: The data user selects a random number rk and uses each data owner DO involved in the query i The key {k i,1 ,k i,2 }calculate and get and Then calculate and S4.6: The data user generates a random permutation sequence π, permutes r1 and r2 respectively to disrupt the order of each bit, and uses the asymmetric encryption public key pk B Encrypt and permutate {r1, r2} to obtain {r1′, r2′}; S4.7: Data user for each keyword w in the keyword set W k Calculating trapdoors in Will Sent to cloud server A, where uid is the identity of the data user, uk i DO for the data owner during the authorization process i A key generated for the user of the data.

6. The multi-source encrypted data Boolean query method according to claim 5, characterized in that: Step S5 includes: S5.1: Cloud server A obtains (T, R, F′, {r1′, r2′}, rk, π, uid), and calculates the oid according to uid and each oid in R. i Find the corresponding key where UK' i,1 ,uk' i,2 DO for the data owner during the authorization process i Calculated derived key and OID i and uid as tags are stored on cloud server A; S5.2: Cloud server A has a k ∈T, for each calculate turn up Corresponding encrypted index calculate Then calculate Where m i Is the data owner DO i The number of data documents, cloud server A can The length of m is obtained i ; S5.3: Cloud server A for each oid in R i Find the corresponding d i , calculate d = (d1||d2||…||d x ); S5.4: Cloud server A sends a k Use π to permute to get e′ k , use π to replace d to get d', Send to cloud server B.

7. The multi-source encrypted data Boolean query method according to claim 6, characterized in that: Step S6 includes: S6.1: Cloud server B uses asymmetric encryption private key sk B Decrypt F' and {r1', r2'} to get F = {f 0,0 ,f 0,1 ,f 1,0 ,f 1,1 } and {r1,r2}, and all e′ k ∈e Substitute into the four Boolean expressions f 0,0 ,f 0,1 ,f 1,0 ,f 1,1 Calculate ridx1, ridx2, ridx3, and ridx4 respectively; S6.2: Cloud server B uses asymmetric encryption private key sk B Decrypt each bit of d' to get d", calculate Send ridx to cloud server A.

8. The multi-source encrypted data Boolean query method according to claim 2, characterized in that: Data owner, denoted as DO a , add a new document D new When , follow the steps described in S2.1-S2.4, and Calculate encrypted index and the corresponding labels Use asymmetric encryption public key pk B Encrypt the number 1 to get d new , the encrypted document and Send to cloud server A; Cloud server A has a i Find the corresponding encrypted index and set eidx i Add it to the end and record the correspondence between the newly added one and the newly added document; Cloud Server A according to oid a Find index d a , d new Add to d a The last; After cloud server A completes the index update, the data owner will update the number of documents m a Synchronize to all authorized data users.

9. The multi-source encrypted data Boolean query method according to claim 2, characterized in that: Data owner, denoted as DO a When a document is deleted, a new binary index is constructed, in which the positions corresponding to the deleted documents are set to 0 and the remaining positions are set to 1, and the asymmetric encryption public key pk is used. B Encrypt each bit to get index d a ′, then d a ′ and oid a Send to cloud server A; Cloud Server A according to oid a Find index d a , using d' a Replace d a .

10. A computer readable medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the multi-source encrypted data Boolean query method as described in any one of claims 1-9 is implemented.

Citation Information

Patent Citations

  • Fuzzy keyword search method oriented to multi-server and multi-user

    CN108062485A

  • Searchable encryption method based on semantic sorting of keywords

    CN109063509A

  • Forward and backward secure and verifiable Boolean query method for ciphertext data

    CN112800445A

  • Multi-keyword symmetric searchable encryption method in hidden mode, terminal and server

    CN117763593A

  • Image retrieval method and system supporting sharing of multiple data sources

    CN119788424A