Static encrypted graph shortest path searching method for multi-server parallel computing

Through multi-server parallel computing and graph segmentation technology, the execution of the shortest distance algorithm on ciphertext graphics is optimized, and the problem of large pre-computing overhead and privacy leakage of graph structures in the existing technology is solved, and efficient and secure graph searchable encrypted query is realized.

CN120238486APending Publication Date: 2025-07-01BEIJING INST OF TECH +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510336922.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-21
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

The existing graph searchable encryption technology is expensive in pre-computing, and there is a problem of privacy leakage of graph structures.

Method used

Using multi-server parallel computing technology, the ability to execute the shortest distance algorithm in real time on ciphertext graphs through graph segmentation and deep neural network optimization is realized, ensuring the privacy of graph structure and reducing pre-computation overhead.

Benefits of technology

While ensuring efficient query, it reduces pre-computation overhead, protects graph structure privacy, reduces storage overhead, and improves the security and application value of the solution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238486A_ABST
    Figure CN120238486A_ABST
Patent Text Reader

Abstract

A multi-server parallel computing static encrypted graph shortest path search method comprises a preprocessing algorithm, a graph encryption algorithm and a shortest distance / path query algorithm. An encrypted graph adjacency linked list is stored in a data encryption algorithm, an application-driven graph segmentation algorithm is adopted for the designed encryption algorithm, a logarithmic factor is added for a graph segmentation device according to theoretical analysis of the algorithm to further improve the segmentation device, overhead parameters are obtained by using deep learning, and the graph adjacency linked list is obtained. And finally, a higher-efficiency segmentation scheme for the graph under the shortest path is realized. The method has the beneficial effects that a Dijkstra loss function in a ciphertext state is obtained through analysis by using a deep neural network and a graph calculation theory, and the function is used for carrying out hybrid segmentation processing on a graph; by utilizing a multi-server parallel technology, the execution speed of the shortest distance query on the encrypted graph is improved, and the pre-calculation overhead is reduced compared with the prior art while the efficient query is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of searchable encryption, and particularly relates to a method for searching the shortest path of a static encrypted graph with multi-server parallel computing. Background Art

[0002] As an important branch in the field of searchable encryption, graph searchable encryption faces all the massive graph data of users. While ensuring the security of graph data outsourced to semi-honest servers, it can support users to perform relevant graph queries on encrypted data in the cloud, which has received extensive attention from the academic and industrial communities. Among them, designing a graph searchable encryption scheme that supports accurate shortest distance and path queries is still a research hotspot and pain point in this field. The shortest distance algorithm is not only the cornerstone of graph computing and a building block for more complex graph algorithms, but also has extensive applications itself. In scenarios such as military telecommunications network graphs, etc., the scheme is required to accurately and efficiently return the shortest distance and the shortest path itself between the query start and end nodes.

[0003] A series of existing works have proposed various graph searchable encryptions for accurate shortest distance / path queries in a static setting. However, these schemes have two problems. On the one hand, there is a huge overhead during precomputation. To support high efficiency during query, the above works need to calculate data related to the shortest distance and path between node pairs in the graph before precomputation, that is, before graph encryption, and then generate an encrypted database through different simplification means, balancing the computational overhead during query by increasing the precomputation overhead. On the other hand, there is a leakage of graph structure privacy. Relevant papers in 2022 proposed that when the server knows the plaintext graph information, it can use the recovered ciphertext shortest path tree during the query process to recover the corresponding relationship between ciphertext and plaintext nodes through subgraph isomorphism, thus leaking the user's query content and directly destroying the security requirements of searchable encryption. Using this attack method, all the above graph encryption schemes face huge security risks. Although the newly proposed PathGES can resist the above attacks, it sacrifices precomputation overhead and storage. Even for graphs with tens of thousands of nodes and edges, it requires more than 1 hour of encryption time and more than 30GB of storage overhead, which greatly increases the outsourcing cost and reduces the application value. Summary of the Invention

[0004] The purpose of this solution is to creatively propose a static encrypted graph shortest path search method for multi-server parallel computing in response to the problems of large pre-computation overhead and graph structure privacy leakage existing in the existing solutions. By using graph segmentation and multi-server parallel computing technologies, it accelerates the ability of the server cluster to execute the shortest distance algorithm on the encrypted graph in real time, reduces the pre-computation overhead while maintaining efficient queries, ensures that the graph structures are mutually unknowable during the server interaction process, cannot construct the shortest path tree, and can guarantee the graph structure privacy without huge storage overhead. In addition, this technical solution improves the loss function in the application-driven graph segmentation technology, collects the data of the Dijkstra algorithm in the ciphertext state, obtains a loss function more suitable for this application using a deep neural network, and uses this loss function to perform hybrid segmentation on the graph, further improving the query efficiency.

[0005] A static encrypted graph shortest path search method for multi-server parallel computing includes a preprocessing algorithm, a graph encryption algorithm, and a shortest distance / path query algorithm, which are specifically as follows:

[0006] Algorithm 1: Preprocessing algorithm

[0007] The preprocessing algorithm includes three sub-algorithms, namely loss function training, graph segmentation, and key generation; for different graphs, the loss function training is only executed once, that is, the obtained loss function is applicable to the ciphertext Dijkstra algorithm of any graph, and the graph segmentation algorithm and the key generation algorithm need to be executed separately;

[0008] Step 1, the loss function training is specifically as follows:

[0009] Given the algorithm Select ten datasets of different sizes for encryption and execute queries to obtain the log data during the query process; when the query algorithm traverses a certain node v, count and record the total time for processing node v, which includes obtaining this node from the Fibonacci heap, decrypting to obtain all the outgoing edge data of this point in segment F i , finally compare and update the distances from the starting point to the end points of all outgoing edges, and update the time of the Fibonacci heap; at the same time, record the number of incoming edges of each node v in each segment F i , denoted as each segment F i the total number of nodes in, denoted as n i ; and the total number of copies owned by each node in HP(n), denoted as r(v); define the calculation of the loss function and the communication loss function Calculate the overall computational overhead of F i after adding node v and its incoming edge e in segment F i , which can calculate F i after setting node v as the main node in segment Fi The overall communication overhead; Through the theoretical analysis of the algorithm, it can be obtained that is linearly correlated with i and linearly correlated with logn; is linearly correlated with r(v); Using the obtained log data above to train the deep neural network, we get and each parameter in the formula, and determine

[0010] Step 2, graph segmentation

[0011] The input of the graph segmentation algorithm is the graph G=(V, E), the number of segments n, and the formula obtained in Step 1 The output is the hybrid segmentation HP(n)=(F1,…,F n );

[0012] Step 3, key generation

[0013] Given the security parameter λ, the key generation algorithm enables the user to generate two keys of length 1 λ key set K={k p ,k0}, which are used as the keys of a pseudo-random permutation P(·) and a pseudo-random function F0(·) in this system respectively;

[0014] Algorithm 2: Graph encryption

[0015] The input of the graph encryption algorithm is the plaintext graph HP(n)=(F1,…,F n ) obtained by the data owner through hybrid segmentation processing and the key K={k p ,k0}, and the output is the encrypted graph stored on the n-server cluster respectively

[0016] Algorithm 3: Shortest distance / path query

[0017] When the user initiates a query q=(s, t), first generate τ q =(P(s), F0(s), P(t)) and send it to the server cluster; The query algorithm executed by the server cluster takes the encrypted graph Ω G and the query trapdoor τ q as the input, and outputs the shortest distance query result c q ;

[0018] The shortest distance / path query algorithm includes the following steps:

[0019] Step 1, the server cluster executes the PEval algorithm

[0020] Step 1.1, the server parses the received query trapdoor c q into (P(s), F0(s), P(t)), initializes the Fibonacci heap H and three dictionaries ξ, D key and path. Among them, ξ stores the shortest distances from the starting point s to other traversed nodes, path stores the corresponding path information, and D key stores the corresponding relationships of each component of the query trapdoor of the node;

[0021] Step 1.2, the server holds the segment to determine whether the end point t exists in this segment according to Enc_V and P(t). If it exists, calculate the shortest distances and paths from s to t and all nodes in S border and let traverse = {t} ∪ S border ; otherwise, only calculate the shortest distances and paths from s to all nodes in S border and let traverse = S border ;

[0022] Step 1.3, the server records the shortest distance from the node s to itself as ξ[P(s)] = 0. Using the current shortest distance ξ[P(s)] = 0 as the key, put the corresponding P(s) as the value into the Fibonacci heap, and record the corresponding relationship of the trapdoor component D key [P(s)] = F0(s);

[0023] Step 1.4, the server loops to execute the following steps until the heap is empty or traverse is empty:

[0024] Step 1.4.1, select the data P(u) with the smallest key from the Fibonacci heap and pop it. If P(u) ∈ travers, delete P(u) in traverse, and record the shortest distance and shortest path in ξ and path in ;

[0025] Step 1.4.2, find F0(u) in D key with P(u) as the index; with P(u) as the index, obtain the encrypted data enc_data of all outgoing edges corresponding to u in D E , and use H1(F0(u), j) to exclusive-or with the encrypted data block to obtain the decrypted data block data = (P(v j )||F0(v j )||<l j > S || S ); Record the trapdoor component relationship D key [P(v i )]=F0(v i );

[0026] Step 1.4.3, traverse all records (P(v j ) | < l j > S || S ), if the shortest distance of P(v i ) has not been recorded, directly set ξ[P(v i )] = ξ[P(u)] + <l i > x , record path[P(v i )] = ( S |<l i > x ) and use ξ[P(v i )] as the key to put the corresponding P(v i ) as the value into the Fibonacci heap; otherwise, if ξ[P(v i )]>ξ[P(u)]+<l i > x , update ξ[P(v i )]=ξ[P(u)]+<l i > x , record path[P(v i )]=( S |<l i > x ) and perform an operation to reduce the key value on the corresponding node in the Fibonacci heap;

[0027] After the above algorithm, the server calculates and locally obtains the shortest distances and paths from the starting point s to the nodes in the traverse set, which are recorded in ;

[0028] Step 2, the server cluster repeatedly executes the message leader aggregation algorithm and the IncEval algorithm until there is no new message passing, specifically as follows:

[0029] Step 2.1, the message leader aggregation algorithm

[0030] For each segment generated Fill in and send the shortest distance and path of node v therein to the server pair where its master node is located, and the corresponding server pair executes a size comparison protocol to obtain the shortest shortest distance / path result calculated for node v in all segments, and then send the updated result to the server pair corresponding to the segment where P(v) exists in its S border ;

[0031] Step 2.2, the IncEval algorithm

[0032] The IncEval algorithm executes an incremental algorithm of Dijkstra under ciphertext, and the specific process of repeated execution is the same as that of step 1.4 of the PEval algorithm;

[0033] The server first constructs a new Fibonacci heap, and then processes the shortest distance ξ'[P(u)] / path path'[P(u)] of each node P(u) received in the as follows; set ξ[P(u)] = ξ'[P(u)], record path[P(u)] = path'[P(u)], and put the corresponding P(u) as the value into the Fibonacci heap with ξ[P(u)] as the key; after obtaining the above Fibonacci heap, execute the same steps as step 1.4 of the PEval to obtain the shortest distances and paths of the nodes in the updated traverse set, which are recorded in ;

[0034] Preferably, the graph segmentation algorithm is specifically:

[0035] Step 1: Initialization

[0036] Represent the graph as a set of nodes and their corresponding incoming edge sets, that is, G = {(v, E v )|v ∈ V}; then according to the number of partitions, (v, E v ) are evenly distributed to n segments, and n initialized segments F1,…,F n ;

[0037] Step 2: Divide into large and small segments

[0038] use For the n segments F1,…,F obtained by initialization n Calculate the total computational loss cost i , calculate the global average computational cost For each segment F i , if cost i >cost, it is recorded as a large segment, otherwise it is a small segment; for each large segment F i ={(v,E v )|v∈V i }, set an empty segment F i ' and a set S i , try to change F i (v,E v ) Add F i ', and use Calculate the addition (v,E v )F i ', if the cost is less than the average cost, then (v,E v ) Add F i ', otherwise (v,E v ) Add S i After completing the above process, let F i ←F i ';

[0039] Step 3: Fill in the small section

[0040] For each large segment generated S i (v,E v ), try to put it into a small segment; the judgment standard is also whether the cost after putting it in is less than the average cost. If it meets the requirements, then in S i Delete this (v,E v ), and the (v,E v ) is added to the corresponding sub-paragraph;

[0041] Step 4: Split the incoming edge

[0042] For each large segment generated S i The remaining (v,E v ), for E v For each incoming edge (u,v) in n The one with the lowest total computational cost is put in; each time it is put in, segment F is updated i Total computational overhead;

[0043] Step 5, set the master node

[0044] For F1,…,F n , according to its current included nodes and incoming edges, readjust its structure to F i ={V i ,E i ,L i ,F i .in,F i .out}; where V i represents the set of all nodes included in segment F i ; E i is a dictionary, indexed by u∈V i , containing the set of outgoing edges {(u,v i )∈F i} within segment F i as the value; L i corresponds to the weight of each edge; F i .in is the set of incoming edge nodes of segment F i . If a node v has an incoming edge in other segments and this incoming edge does not exist within segment F i , then add it to F i .in; F i .out is the set of outgoing edge nodes of segment F i . If a node v has an incoming edge within this segment and this incoming edge does not exist in some other segment, then add it to F i .out; For v∈F i .in∪F i .out, assuming it exists within segments F1,…,F j , then use to calculate the communication overhead of segments F1,…,F j respectively, and select the segment with the smallest value and set the v in it as the master node.

[0045] Preferably, the graph encryption algorithm performs the following steps for each segment F i ∈HP(n):

[0046] Step 1, let F i ={V i ,E i ,L i ,F i .in,F i .out}, and the user initializes a dictionary D E and two sets Enc_V, S border , where D E It is the main ciphertext graph structure stored on the server and is used to save the out-edge information; Enc_V, S border It is used to indicate the direction of message passing;

[0047] Step 2, for each node u ∈ V i , encrypt it using P(·) to get P(u), and add it to Enc_V; then for its out-edges {(u, v j ) ∈ E i [u]}, set the plaintext information structure as data = (P(v j ) || F0(v j ) || <l j > S || S ), where P(v j ) and F0(v j ) are the encryptions of the out - edge destination v j using the pseudo - random permutation P(·) and the pseudo - random function F0(·), and are used to obtain the out - edge information of v j in Dijkstra; <l j > S is the weight of the corresponding edge in L i and is used for distance calculation, <·> S , S ∈ {0, 1} represents the secret - sharing share stored on server S in server pair i; S Store \(u\) on server \(S\) in the form of secret - sharing shares in server pair \(i\) for recording the shortest path; for each piece of data, use a hash function, input the key \(F0(u)\) and the count \(j\) to obtain a random number string to get the encrypted \(enc\_data\); store all \(enc\_data\) in dictionary \(D\) indexed by \(P(u)\). E in;

[0048] Step 3, for each node \(u\in\{F i .in\cup F i .out\}, encrypt it using \(P(\cdot)\) to get \(P(u)\), and add it to \(S\_border\).

[0049] Preferably, both the Dijkstra running process and the heap operation in the shortest - distance / path query algorithm involve the operation of two servers holding corresponding shares of additive secret sharing for size comparison. Suppose server \(S0\) holds \(x0\) and \(y0\), server \(S1\) holds \(x1\) and \(y1\), server \(S0\) locally calculates \(cmp0 = x0 - y0\), server \(S1\) locally calculates \(cmp1 = y1 - x1\), and then server \(S0\) and \(S1\) construct a comparison garbled circuit, taking \(cmp0\) and \(cmp1\) as inputs to get the comparison value \(x\).

[0050] The beneficial effects of the technical solution of the present invention are as follows: The loss function of Dijkstra in the ciphertext state is obtained by using deep neural network and graph - computing theory analysis, and the graph is processed by hybrid segmentation using this function; by using the multi - server parallel technology, the execution speed of the shortest - distance query on the encrypted graph is improved. While ensuring the query efficiency, the pre - calculation overhead is reduced compared with the prior art; the problem of graph - structure leakage is solved by using multiple servers, improving the security of the scheme, and greatly reducing the pre - calculation overhead and storage overhead compared with similar schemes. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] Figure 1 It is a schematic diagram of the system model involved in a method for searching the shortest path of a static encrypted graph with multi - server parallel computing according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0052] Next, the technical solutions of the present invention will be clearly and completely described in conjunction with the drawings in the present invention.

[0053] The objective of the technical solution of the present invention is to address the problems of large pre-computation overhead and graph structure privacy leakage existing in the existing solutions. A static encrypted graph shortest path search scheme for multi-server parallel computing is creatively proposed. By using graph segmentation and multi-server parallel computing technologies, the ability of the server cluster to execute the shortest distance algorithm in real time on the encrypted graph is accelerated. While maintaining efficient querying, the pre-computation overhead is reduced, and it is ensured that the graph structures are mutually unknowable during the server interaction process, so that the shortest path tree cannot be constructed, and the graph structure privacy can be guaranteed without huge storage overhead. In addition, the loss function in the application-driven graph segmentation technology is improved in this technical solution. The data of the Dijkstra algorithm in the ciphertext state is collected, and a loss function more suitable for this application is obtained using a deep neural network. The graph is segmented in a mixed manner using this loss function, further improving the query efficiency.

[0054] A static encrypted graph shortest path search method for multi-server parallel computing includes the following five elements in the technical implementation process, specifically as follows:

[0055] Element 1: Graph, denoted by G. The graph G is composed of vertices and edges. The graph G includes directed graphs and undirected graphs, and the edges have a numerical weight.

[0056] Element 2: Graph segmentation. The graph G is segmented into a number n, and an n-partitioned mixed graph segmentation HP(n) = (F1,..., F n ), which divides the graph G into n segments F1,..., F n . Each segment F i is composed of subsets V i , E i and L i , where L i corresponds to the weight of each edge in E i . The graph segmentation satisfies and Use E v to represent the in-edge set of node v in graph G, and use to represent the in-edge set of node v in segment F i ;

[0057] If the in-edge set of node v is not completely included in any one segment, that is, for all i ∈ [1, n], then the node v is defined as a node cut in HP(n); conversely, if there exists a segment F i such that all the in-edges of a node v are included in this segment, that is, then the node v is defined as an edge cut; the node v in the segment having all the in-edges of the edge cut node is called the main node, and the repeated node v in other segments is called the redundant node;

[0058] In the hybrid segmentation, use F i .O = {v ∈ V i | v ∈ V j ∧ i ≠ j} to represent the set of boundary nodes of segment F i ; represent the set of boundary nodes of the graph segmentation HP(n); for the boundary node v in segment F i , if the node v has only incoming / outgoing edges in other segments, then use F i .in / F i .out to record this node;

[0059] Element three: Graph parallel computing. The graph parallel computing adopts the GRAPE parallel computing style centered on the graph. Given a query Q and a graph G, define the PIE algorithm to calculate the result Q(G) of query Q on graph G; the PIE algorithm includes the following three functional functions, specifically:

[0060] PEval is an ordered algorithm. Given a query Q and a graph G, the calculation result of PEval is Q(G);

[0061] IncEval is an ordered incremental algorithm. Given Q, G, Q(G) and an update ΔG to G, calculate an update ΔO to the old result Q(G), that is where represents updating G with ΔG;

[0062] Assemble is a functional function and is mainly responsible for collecting the partial results obtained by each server through local calculation of IncEval, and integrating these partial results to form the final result Q(G);

[0063] The PIE algorithm also has a message leading and aggregation algorithm for the intermediate results of the servers to transfer the intermediate results between different server pairs; the PIE algorithm defines a node set C i in each segment F i , and the nodes in this set have a state variable as the update parameter of segment F i , that is, the intermediate result obtained through the calculation and transfer of PEval and IncEval; the PIE algorithm also defines an aggregation function f aggr to aggregate the partial results between different servers to avoid conflicts.

[0064] Element Four: Server Cluster. The server cluster consists of server pairs in groups of two. Assume that each server is semi - honest and does not collude with each other. After the graph is partitioned, different segments are encrypted and stored in the corresponding server pairs, and all side lengths in the corresponding segments are stored as secret - sharing shares in the two servers included in the server pair. During the shortest - distance query process, the two servers in the server pair will jointly execute a secure comparison protocol through a garbled circuit based on the side - length sharing shares they decrypt, and different server pairs will interact and send intermediate calculation information.

[0065] Element Five: User. The user holds the graph data, is responsible for processing, encrypting the graph data, and uploading it to the corresponding server. It generates and holds all the keys in the scheme. At the same time, when the user needs to perform a query, it can generate the corresponding trapdoor, send it to the server cluster, and obtain the final result returned by the server. Finally, the user can recover the plaintext result.

[0066] Figure 1 This is the system architecture diagram designed for the present invention. In the present invention, the servers are semi - trusted and do not collude with each other. Considering that in practical applications, the servers are large - scale cloud service providers and will attach great importance to social credibility, so the servers will not collude.

[0067] A static - encryption graph shortest - path search method for multi - server parallel computing includes a pre - processing algorithm, a graph - encryption algorithm, and a shortest - distance / path query algorithm, which are specifically as follows:

[0068] Algorithm 1: Pre - processing Algorithm

[0069] The pre - processing algorithm includes three sub - algorithms, namely loss - function training, graph partitioning, and key generation. For different graphs, the loss - function training is only executed once, that is, the obtained loss function is applicable to the ciphertext Dijkstra algorithm of any graph. The graph - partitioning algorithm and the key - generation algorithm need to be executed separately.

[0070] Step 1, the loss - function training is specifically as follows:

[0071] Given the algorithm Select ten datasets of different sizes for encryption and execute the query to obtain the log data during the query process. When the query algorithm traverses a certain node v, count and record the total time for processing node v. This time includes obtaining the node from the Fibonacci heap, decrypting to obtain all the outgoing - edge data of this point in segment F i and finally comparing and updating the distances from the starting point to the end points of all outgoing edges, and updating the time of the Fibonacci heap. At the same time, record the number of incoming edges of each node v in each segment F i and denote it as each segment F i The total number of nodes in it is denoted as n i ; and the total number of copies owned by each node in HP(n) is denoted as r(v); define the calculation loss function and the communication loss function Calculate segment F i After adding the node v and its incoming edge e to F i The overall calculation overhead of F Can calculate segment F i After setting the node v as the master node in F i The overall communication overhead of F; Through the theoretical analysis of the algorithm, it can be obtained that And Are linearly related, and are linearly related to logn i Are linearly related; Is linearly related to r(v); Use the obtained log data above to train with a deep neural network to obtain And Each parameter in the formula, determine

[0072] Step 2, Graph segmentation

[0073] The input of the graph segmentation algorithm is the graph G=(V,E), the number of segments n, and the formula obtained in step 1 The output is the hybrid segmentation HP(n)=(F1,…,F n );

[0074] Step 3, Key generation

[0075] Given the security parameter λ, the key generation algorithm enables the user to generate two keys of length 1 λ Key set K={k p ,k0}, which are used as the keys of a pseudo-random permutation P(·) and a pseudo-random function F0(·) in this system respectively;

[0076] Algorithm 2: Graph encryption

[0077] The input of the graph encryption algorithm is the plaintext graph HP(n)=(F1,…,F n ) obtained by the data owner's hybrid segmentation processing and the key K={k p ,k0}, and the output is the encrypted graph stored on the n-server cluster respectively

[0078] Algorithm 3: Shortest distance / path query

[0079] When the user initiates a query q=(s,t), first generate τ q =(P(s), F0(s), P(t)) is sent to the server cluster; the query algorithm executed by the server cluster uses the encrypted graph Ω G and the query trapdoor τ q as inputs, and outputs the shortest distance query result c q ;

[0080] The shortest distance / path query algorithm includes the following steps:

[0081] Step 1, the server cluster executes the PEval algorithm

[0082] Step 1.1, the server parses the received query trapdoor c q into (P(s), F0(s), P(t)), initializes the Fibonacci heap H and three dictionaries ξ, D key and path. Among them, ξ stores the shortest distances from the starting point s to other traversed nodes, path stores the corresponding path information, and D key stores the corresponding relationships of the components of the query trapdoor of the nodes;

[0083] Step 1.2, the server holds the segment to determine whether the end point t exists in this segment according to Enc_V and P(t). If it exists, calculate the shortest distances and paths from s to t and all nodes in S border and let traverse = {t} ∪ S border ; otherwise, only calculate the shortest distances and paths from s to all nodes in S border and let traverse = S border ;

[0084] Step 1.3, the server records the shortest distance from node s to itself as ξ[P(s)] = 0. Using the current shortest distance ξ[P(s)] = 0 as the key, put the corresponding P(s) as the value into the Fibonacci heap, and record the corresponding relationship of the trapdoor components D key [P(s)] = F0(s);

[0085] Step 1.4, the server loops to execute the following steps until the heap is empty or traverse is empty:

[0086] Step 1.4.1, select the data P(u) with the smallest key from the Fibonacci heap and pop it. If P(u) ∈ traverse, then delete P(u) from traverse, and record the shortest distance and shortest path in the corresponding ξ and path ;

[0087] Step 1.4.2, find F0(u) in D key using P(u) as the index; using P(u) as the index, in D E Obtain the encrypted data enc_data corresponding to all the outgoing edges of u, and use H1(F0(u), j) to perform exclusive OR with the encrypted data block to obtain the decrypted data block data = (P(v j )||F0(v j )||<l j > S || S ); Record the trapdoor component relationship D key [P(v i )]=F0(v i );

[0088] Step 1.4.3, traverse all records (P(v j ) | < l j > S || S ), if the shortest distance of P(v i ) has not been recorded, directly set ξ[P(v i )] = ξ[P(u)] + <l i > x , record path[P(v i )] = ( S |<l i > x ) and use ξ[P(v i )] as the key to put the corresponding P(v i ) as the value into the Fibonacci heap; otherwise, if ξ[P(v i )]>ξ[P(u)]+<l i > x , update ξ[P(v i )]=ξ[P(u)]+<l i > x , record path[P(v i )]=( S |<l i > x ) and perform an operation to reduce the key value on the corresponding node in the Fibonacci heap;

[0089] After the above algorithm, the server calculates and locally obtains the shortest distances and paths from the starting point s to the nodes in the traverse set, and records them in ;

[0090] Step 2, the server cluster repeatedly executes the message leader aggregation algorithm and the IncEval algorithm until there is no new message passing, specifically as follows:

[0091] Step 2.1, the message leader aggregation algorithm

[0092] For each segment generated Fill in and send the shortest distance and path of node v among them to the server pair where its master node is located, and the corresponding server pair executes the size comparison protocol to obtain the shortest shortest distance / path result calculated for node v in all segments, and then send the updated result to the server pair corresponding to the segment where P(v) exists in its S border ;

[0093] Step 2.2, the IncEval algorithm

[0094] The IncEval algorithm executes an incremental algorithm of Dijkstra under ciphertext, and the specific process of repeated execution is the same as that of step 1.4 of the PEval algorithm;

[0095] The server first constructs a new Fibonacci heap, and then processes the shortest distance ξ'[P(u)] / path path'[P(u)] of each node P(u) received in the as follows; set ξ[P(u)] = ξ'[P(u)], record path[P(u)] = path'[P(u)], and put the corresponding P(u) as the value into the Fibonacci heap with ξ[P(u)] as the key; after obtaining the above Fibonacci heap, execute the same steps as step 1.4 of the PEval to obtain the shortest distances and paths of the nodes in the updated traverse set, and record them in ;

[0096] Preferably, the graph segmentation algorithm is specifically:

[0097] Step 1: Initialization

[0098] Represent the graph as a set of nodes and their corresponding incoming edges, that is, G = {(v, E v )|v ∈ V}; then according to the number of partitions, (v, E v ) are evenly distributed to n segments, and n initialized segments F1,…,F n ;

[0099] Step 2: Divide into large and small segments

[0100] use For the n segments F1,…,F obtained by initialization n Calculate the total computational loss cost i , calculate the global average computational cost For each segment F i , if cost i >cost, it is recorded as a large segment, otherwise it is a small segment; for each large segment F i ={(v,E v )|v∈V i }, set an empty segment F i ' and a set S i , try to change F i (v,E v ) Add F i ', and use Calculate the addition (v,E v )F i ', if the cost is less than the average cost, then (v,E v ) Add F i ', otherwise (v,E v ) Add S i After completing the above process, let F i ←F i ';

[0101] Step 3: Fill in the small section

[0102] For each large segment generated S i (v,E v ), try to put it into a small segment; the judgment standard is also whether the cost after putting it in is less than the average cost. If it meets the requirements, then in S i Delete this (v,E v ), and the (v,E v ) is added to the corresponding sub-paragraph;

[0103] Step 4: Split the incoming edge

[0104] For each large segment generated S i The remaining (v,E v ), for E v For each incoming edge (u,v) in n The one with the lowest total computational cost is put in; each time it is put in, segment F is updated i The total computational overhead;

[0105] Step 5, set the master node

[0106] For F1, …, F n , according to its current included nodes and incoming edges, readjust its structure to F i = {V i , E i , L i , F i .in, F i .out}; where V i represents the set of all nodes included in segment F i ; E i is a dictionary, indexed by u ∈ V i , and contains the set of outgoing edges {(u, v i ) ∈ F i} within segment F i as its value; L i corresponds to the weight of each edge; F i .in is the set of incoming edge nodes of segment F i . If a node v has an incoming edge in other segments and this incoming edge does not exist within segment F i , then add it to F i .in; F i .out is the set of outgoing edge nodes of segment F i . If a node v has an incoming edge within this segment and this incoming edge does not exist in some other segment, then add it to F i .out; For v ∈ F i .in ∪ F j .out, assuming it exists within segments F1, …, F j , then use to calculate the communication overhead of segments F1, …, F i respectively, and select the segment with the minimum value and set the v in it as the master node. Only the master node incurs communication overhead.

[0107] Preferably, the graph encryption algorithm performs the following steps for each segment F i ∈ HP(n):

[0108] Step 1, let F i = {V i , E i , L i , F i .in, F E .out}, and the user initializes a dictionary D border and two sets Enc_V, S E , where D border It is the main ciphertext graph structure stored on the server, used to save the out-edge information; Enc_V, S border It is used to indicate the direction of message passing;

[0109] Step 2, for each node u ∈ V i , encrypt it using P(·) to get P(u), and add it to Enc_V; then for its out-edges {(u, v j ) ∈ E i [u]}, set the plaintext information structure as data = (P(v j ) || F0(v j ) || <l j > S || S ), where P(v j ) and F0(v j ) are the encryptions of the out-edge end point v j using the pseudo-random permutation P(·) and the pseudo-random function F0(·), and are used to obtain the out-edge information of v j in Dijkstra; <l j > S is the weight of the corresponding edge in L i and is used for distance calculation, <·> S , S ∈ {0, 1} represents the secret sharing share stored on server S in server pair i; S Store \(u\) on server \(S\) in the form of secret - shared shares for server pair \(i\) to record the shortest path; for each piece of data, use a hash function, input the key \(F0(u)\) and the count \(j\) to obtain a random number string to get the encrypted \(enc\_data\); store all \(enc\_data\) in the dictionary \(D\) indexed by \(P(u)\). E In;

[0110] Step 3, for each node \(u\in\{F i .in\cup F i .out\}, encrypt it using \(P(\cdot)\) to get \(P(u)\) and add it to \(S\_border\).

[0111] Preferably, both the Dijkstra running process and the heap operation in the shortest - distance / path query algorithm involve the operation of two servers holding the corresponding shares of additive secret sharing for size comparison. Suppose server \(S0\) holds \(x0\) and \(y0\), server \(S1\) holds \(x1\) and \(y1\). Server \(S0\) locally calculates \(cmp0 = x0 - y0\), server \(S1\) locally calculates \(cmp1 = y1 - x1\), and then server \(S0\) and \(S1\) construct a comparison garbled circuit and use \(cmp0\) and \(cmp1\) as inputs to get the comparison value \(x\).

[0112] To solve the pre - calculation overhead and structural privacy leakage problems, this patent proposes a static - encryption graph shortest - path search method for multi - server parallel computing. By using graph partitioning and multi - server parallel graph - computing technologies, it accelerates the operation of the Dijkstra algorithm on the server while preventing any server from recovering the shortest - path tree. Specifically, this technical solution no longer requires pre - calculating the shortest distances and path information between node pairs in the graph, but obtains a query speed that meets the actual application requirements by accelerating the real - time execution of the shortest - distance algorithm through multi - server parallelism. At the same time, the graph - partitioning technology is used to distribute the graph to different servers for storage, and during the interaction process, the shortest paths calculated by the server are protected from being obtained by other servers, so that any server cannot construct a complete shortest - path tree, thereby protecting the structural privacy of the graph. This method enables this technical solution to have a small storage overhead, a low pre - calculation cost, and high query performance, and can protect the graph - structure security.

[0113] The key technologies and innovations of the present invention are as follows: (1) Conducted theoretical analysis on Dijkstra in the ciphertext state, improved the loss function design of the application-driven graph segmentation technology, and obtained a formula through neural network training on a large dataset. (2) Utilized the multi-server parallel graph computing technology to greatly improve the efficiency of executing the Dijkstra algorithm on the ciphertext graph. While ensuring efficient queries, there is no longer a need for pre-computing data related to the shortest distances / paths between node pairs, greatly saving the pre-computation overhead. (3) Utilized the multi-server architecture to protect the shortest paths obtained from local computing from being leaked to other servers during server communication, preventing any server from constructing a shortest path tree, thereby protecting the graph structure privacy. At the same time, compared with the same-effect solutions, due to the absence of pre-computation and a large amount of padding, the computing overhead and storage overhead during pre-computation are greatly reduced.

[0114] After using the technical solution of the present invention, users can segment and encrypt their own graph data and outsource it to the server cluster system. Subsequently, users can generate corresponding query traps to request the shortest distances and paths from the server cluster. The server can efficiently execute the Dijkstra algorithm on the ciphertext graph and return accurate results to the users.

Claims

1. A method for searching the shortest path of a static encrypted graph with multi-server parallel computing, characterized in that: The shortest path search method includes a preprocessing algorithm, a graph encryption algorithm, and a shortest distance / path query algorithm, which are as follows: Algorithm 1: Preprocessing algorithm The preprocessing algorithm includes three sub-algorithms, namely, a loss function training algorithm, a graph segmentation algorithm and a key generation algorithm; for different graphs, the loss function training algorithm is only executed once, that is, the obtained loss function is applicable to the ciphertext Dijkstra algorithm of any graph, and the graph segmentation algorithm and the key generation algorithm need to be executed separately; The loss function training algorithm is specifically: given algorithm Select ten datasets of different sizes, encrypt them and execute queries to obtain log data during the query process; when the query algorithm traverses to a certain node v, count and record the total time of processing node v, which includes obtaining the node from the Fibonacci heap, decrypting the point in segment F i Finally, compare and update the distance from the starting point to all the outgoing edge endpoints, and update the time of the Fibonacci heap; at the same time, record each segment F i The number of incoming edges of each node v in is denoted by Each segment F i The total number of nodes in is denoted as n i ; and the total number of copies each node has in HP(n), denoted as r(v); define the calculation loss function And the communication loss function Calculation segment F i After adding the inbound node v and its inbound edge e to F i The overall computational cost of Able to calculate segment F i After setting node v as the master node in F i The overall communication overhead of and Linearly related, with logn i Linear correlation; Linearly related to r(v); using the deep neural network to train the log data obtained above, we get and The various parameters in the formula determine loss=0.17; The input of the graph segmentation algorithm is the graph G = (V, E), the number of segments n and the formula obtained in step 1 The output is a mixed partition HP(n) = (F1,…,F n ); The key generation algorithm is given a security parameter λ, and the user generates two keys of length 1. λ Key set K = {k p ,k0}, respectively, as the keys of a pseudo-random permutation P(·) and a pseudo-random function F0(·) in this system; Algorithm 2: Graph encryption algorithm The input of the graph encryption algorithm is the plaintext graph HP(n) = (F1, ..., F n ) and key K = {k p ,k0}, the output is an encrypted graph stored on the n server pairs cluster Algorithm 3: Shortest distance / path query algorithm When a user initiates a query q=(s,t), τ is first generated q =(P(s), F0(s), P(t)) is sent to the server cluster; the query algorithm executed by the server cluster is encrypted with the graph Ω G and query trap τ q As input, output the shortest distance query result c q .

2. A method for searching the shortest path of a static encrypted graph using multi-server parallel computing as claimed in claim 1, characterized in that: The graph segmentation algorithm is specifically: Step 1: Initialization The graph is represented as a set of nodes and their corresponding incoming edges, that is, G = {(v,E v )|v∈V}; then according to the number of splits, (v,E v ) are evenly distributed to n segments, and n initialized segments F1,…,F n ; Step 2: Divide into large and small segments use For the n segments F1,…,F obtained by initialization n Calculate the total computational loss cost i , calculate the global average computational cost For each segment F i , if cost i >cost, it is recorded as a large segment, otherwise it is a small segment; for each large segment F i ={(v,E v )|v∈V i }, set an empty segment F i ' and a set S i , try to change F i (v,E v ) Add F i ', and use Calculate the addition (v,E v )F i ', if the cost is less than the average cost, then (v,E v ) Add F i ', otherwise (v,E v ) Add S i After completing the above process, let F i ←F i '; Step 3: Fill in the small section For each large segment generated S i (v,E v ), try to put it into a small segment; the judgment standard is also whether the cost after putting it in is less than the average cost. If it meets the requirements, then in S i Delete this (v,E v ), and the (v,E v ) is added to the corresponding sub-section; Step 4: Split the incoming edge For each large segment generated S i The remaining (v,E v ), for E v For each incoming edge (u,v) in n The one with the lowest total computational cost is put in; each time it is put in, segment F is updated i The total computational cost of Step 5: Set up the master node For F1,…,F n , according to its current nodes and incoming edges, re-adjust its structure to F i = {V i ,E i ,L i ,F i .in,F i .out}; where V i Indicates segment F i The set of all nodes contained in E i is a dictionary with u∈V i Index, contained in segment F i The outgoing edge set {(u,v i )∈F i } is the value; L i Corresponds to the weight of each edge; F i .in is segment F i The set of incoming edge nodes of a segment, if a node v has an incoming edge in other segments, and the incoming edge does not exist in segment F i If it is in F i .in; F i .out is segment F i If a node v has an incoming edge in this segment and the incoming edge does not exist in any other segment, then add it to F i .out; for v∈F i .in∪F i .out, assuming it exists in segments F1,…,F j If inside, use Calculate segments F1,…,F separately j The communication overhead is reduced, and the smallest segment is selected, and v is set as the master node.

3. A method for searching the shortest path of a static encrypted graph using multi-server parallel computing as claimed in claim 1, characterized in that: The graph encryption algorithm performs encryption on each segment F i ∈HP(n) performs the following steps: Step 1: Let F i = {V i ,E i ,L i ,F i .in,F i .out}, the user initializes a dictionary D E and two sets Enc_V, S border , where D E It is the main ciphertext graph structure stored on the server, used to store outgoing edge information; Enc_V, S border Used to indicate the direction of message delivery; Step 2: For each node u∈V i , encrypt with P(·) to get P(u), add it to Enc_V; then for its outgoing edge {(u,v j )∈E i [u]}, set the plaintext information structure to data = (P (v j )||F0(v j )||<l j > S || S ), where P(v j ) and F0(v j ) is the pseudo-random permutation P(·) and pseudo-random function F0(·) for the outgoing edge endpoint v j The encryption of is used to obtain v in Dijkstra j Outbound edge information; <l j > S YesL i The corresponding edge weight in is used for distance calculation, <·> S ,S∈{0,1} represents the secret share stored on server S in server pair i; S Store u in the form of a secret sharing share on the server S in the server pair i to record the shortest path; use a hash function for each piece of data, input the key F0(u) and the count j to get a random number string to get the encrypted enc_data; store all enc_data in the dictionary D with P(u) as the index E middle; Step 3: For each node u∈{F i .in∪F i .out}, encrypt it with P(·) to get P(u), and add it to S_border.

4. A method for searching the shortest path of a static encrypted graph using multi-server parallel computing as claimed in claim 1, characterized in that: The shortest distance / path query algorithm specifically comprises the following steps: Step 1: The server cluster executes the PEval algorithm Step 1.1, the server receives the query trap c q Parse to (P(s), F0(s), P(t)), initialize Fibonacci heap H and three dictionaries ξ, D key And path. Among them, ξ stores the shortest distance from the starting point s to other traversal nodes, path stores the corresponding path information, D key The corresponding relationship between the query trap components of the storage node; Step 1.2, the server holds segment Ω Fi ={D E ,Enc_V,S border }, according to Enc_V and P(t), determine whether the end point t exists in the segment. If so, calculate s to t and S border The shortest distance and path of all nodes in S, let traverse = {t}∪S border ; otherwise, just calculate s to S border The shortest distance and path of all nodes in , let traverse = S border ; Step 1.3, the server records the shortest distance from node s to itself as ξ[P(s)] = 0, takes the current shortest distance ξ[P(s)] = 0 as the key, puts the corresponding P(s) as the value into the Fibonacci heap, and records the corresponding relationship D of the trapdoor components key [P(s)] = F0(s); Step 1.4, the server loops and executes the following steps until the heap is empty or the traverse is empty: Step 1.4.1, select the data P(u) with the smallest key from the Fibonacci heap and pop it. If P(u)∈travers, delete P(u) in traverse and record the corresponding ξ and the shortest distance and shortest path in path in C i . middle; Step 1.4.2, use P(u) as the index in D key Find F0(u) in D; use P(u) as the index, E The encrypted data enc_data corresponding to all outgoing edges of u is obtained, and the decrypted data block data is obtained by using H1(F0(u),j) and XOR with the encrypted data block. j )||F0(v j )|| <l j > S || S ); record the trapdoor component relationship D key [P(v i )]=F0(v i ); Step 1.4.3, traverse all records (P(v j )| <l j > S || S ), if P(v i ) has not been recorded before, then directly set ξ[P(v i )]=ξ[P(u)]+ <l i > x , record path[P(v i )]=( S | <l i > x ), and ξ[P(v i )] as a key to convert the corresponding P(v i ) is put into the Fibonacci heap as a value; otherwise, if ξ[P(v i )]>ξ[P(u)]+ <l i > x , update ξ[P(v i )]=ξ[P(u)]+ <l i > x , record path[P(v i )]=( S | <l i > x ), and perform a key value reduction operation on the corresponding node in the Fibonacci heap; After the above algorithm, the server calculates the local calculation to obtain the shortest distance and path from the starting point s to the nodes in the traverse set, and records it in middle; Step 2: The server cluster executes the message leader aggregation algorithm and IncEval algorithm in a loop until no new messages are transmitted, as follows: Step 2.1, message leading aggregation algorithm For each segment generated The shortest distance and path of node v are filled and sent to the server pair where its main node is located. The corresponding server pair performs the size comparison protocol to compare the shortest distance / path results of all segments calculated for node v, and then sends the updated results to P(v) in its S border The server pair corresponding to the segment; Step 2.2, IncEval algorithm The IncEval algorithm executes an incremental Dijkstra algorithm under a ciphertext, and the specific process of the loop execution is consistent with step 1.4 of the PEval algorithm; The server first constructs a new Fibonacci heap and then receives the information The shortest distance ξ'[P(u)] / path path'[P(u)] of each node P(u) is processed as follows; Set ξ[P(u)] = ξ'[P(u)], record path[P(u)] = path'[P(u)], and put the corresponding P(u) as the value into the Fibonacci heap with ξ[P(u)] as the key; after obtaining the above Fibonacci heap, execute the steps consistent with the PEval1.4 step to obtain the shortest distance and path of the nodes in the updated traverse set, and record them in middle.

5. The method for searching the shortest path of a static encrypted graph using multi-server parallel computing as claimed in claim 1, characterized in that: The Dijkstra running process and heap operation in the shortest distance / path query algorithm both involve the operation of comparing the corresponding shares of additive secret sharing held by two servers. Suppose server S0 holds x0 and y0, and server S1 holds x1 and y1. Server S0 locally calculates cmp0=x0-y0, and server S1 locally calculates cmp1=y1-x1. Then servers S0 and S1 construct a comparison obfuscation circuit and use cmp0 and cmp1 as input to obtain the comparison value x.