Registration request device, search request device, data management device, secret search system, registration request method, registration request program, search request method, search request program, data management method, and data management program
By generating summary attribute conditions and connecting multiple attribute conditions using logical operator OR to generate encryption tags, the problems of data size and retrieval efficiency in the multi-user public key method are solved, and efficient retrieval processing is achieved.
Patent Information
- Application Number
- CN202280102674.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-28
- Publication Date
- 2025-07-25
AI Technical Summary
When the existing multi-user public key method designates multiple searchers without a hierarchical structure, the data size of the ciphertext and encryption tags becomes larger, resulting in increased retrieval processing costs, and the prior art cannot efficiently implement cryptographic retrieval.
By generating summary attribute conditions and connecting multiple attribute conditions using logical operator OR, encrypted tags are generated, the specification of searchers that can be decrypted and retrieved is realized, and the search efficiency is improved.
It realizes the data size stable when multiple searchers are designated, and improves the search efficiency of the multi-user public key method, solving the cost and processing speed problems in the prior art.
Smart Images

Figure CN120380720A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a stealth retrieval technique using public key encryption. Background Art
[0002] Stealth retrieval is a technique for performing retrieval in a state where encrypted data is encrypted. That is, stealth retrieval is a technique for performing retrieval without decrypting encrypted data.
[0003] In recent years, stealth retrieval has attracted attention as a security technique for protecting confidential information from being eavesdropped by malicious administrators or malware in cloud services. That is, stealth retrieval has attracted attention as a security technique for managing data in cloud services.
[0004] As processing in stealth retrieval, processing of each of a registrant, a retriever, and a data management device will be described. The registrant is a user who registers encrypted data. The retriever is a user who retrieves encrypted data.
[0005] The basic flow of the processing performed by the registrant is as follows.
[0006] First, the registrant encrypts data to generate a ciphertext. This ciphertext is used for decryption to restore the original data. Next, the registrant encrypts a keyword for stealth retrieval of the ciphertext. The encrypted keyword is called an encrypted tag. It is difficult to infer the keyword from the encrypted tag. Next, the registrant associates the encrypted tag with the ciphertext. The number of encrypted tags does not need to be one, and multiple encrypted tags can be associated with the ciphertext. Then, the registrant registers the ciphertext and the encrypted tag in the data management device.
[0007] The basic flow of the processing performed by the retriever is as follows.
[0008] First, the retriever selects a keyword to be retrieved. Next, the retriever randomizes the keyword using its own secret key. The randomized keyword is called a retrieval query. It is difficult to infer the secret key from the retrieval query. Next, the retriever requests retrieval from the data management device by sending the retrieval query to the data management device. Then, the retriever receives a ciphertext that matches the retrieval query from the data management device.
[0009] The basic flow of the processing performed by the data management device is as follows.
[0010] Multiple groups of ciphertexts and encrypted tags are registered in the data simple device.
[0011] First, the data management device receives a retrieval query. Next, the data management device performs a special operation on the retrieval query and each registered encrypted tag, and selects the encrypted tag that matches the retrieval query. That is, in the special operation, the keyword of the retrieval query can be compared with the keyword of each encrypted tag without decrypting the encrypted tag and the retrieval query. This special operation is called the hidden retrieval. Then, the data management device sends the ciphertext associated with the selected encrypted tag.
[0012] Regarding the hidden retrieval, there are two types: the public key method and the open key method.
[0013] In the public key method, the public encryption key technology is used to limit the registrant and the retriever.
[0014] In the open key method, the public key encryption technology is used to limit the retriever, but the registrant is not limited.
[0015] In multiple public key methods, the registrant and the retriever share the same secret key with each other.
[0016] In Patent Document 1, the registrant and the retriever have different secret keys, and the registrant can specify the retriever who can perform decryption and retrieval in the ciphertext and the encrypted tag respectively. Such a public key method is called a multi-user type public key method. That is, the multi-user type public key method has an access control function.
[0017] In the ordinary public key method, the registrant and the retriever have the same secret key. Therefore, the retriever can perform retrieval and decryption on all ciphertexts and encrypted tags respectively.
[0018] On the other hand, in the multi-user type public key method, the registrant and the retriever have different secret keys, and furthermore, each retriever has a different secret key. Even if a retriever has a secret key, if the conditions of the retriever specified in the ciphertext and the encrypted tag do not match, this retriever cannot perform decryption and retrieval.
[0019] Furthermore, in the multi-user type public key method, it is difficult for a malicious attacker to arbitrarily change the retriever specified in the ciphertext and the encrypted tag to another retriever. In this way, the multi-user type public key method achieves high security compared with the ordinary public key method.
[0020] Prior Art Documents
[0021] Patent Documents
[0022] Patent Document 1: Japanese Patent No. 6910477
[0023] Patent Document 2: Japanese Patent No. 6384149 Summary of the Invention
[0024] Problems to be Solved by the Invention
[0025] The following multi - user public key method is described in Patent Document 1: By using wildcards, a hierarchical structure can be recognized and retrievers who can decrypt and retrieve can be efficiently specified. For example, in a certain company, when this method is used to specify general staff as retrievers for ciphertext and encrypted tags, it is possible to efficiently specify that section chiefs or department heads, etc., who are the superiors of the general staff, can also decrypt and retrieve.
[0026] However, in this method, when multiple retrievers without a hierarchical structure need to be specified, the data size of the ciphertext and encrypted tags becomes large, so the retrieval process incurs costs. Or, since each retriever has multiple secret keys, there are also costs in terms of operation. For example, when it is necessary to specify that general staff A and general staff B in the same department and their superiors can decrypt and retrieve, the above - mentioned cost problems occur.
[0027] The following encryption method is described in Patent Document 2: By using logical operators such as OR, even if the conditions of the retrievers become complex, the data size does not increase.
[0028] However, this method can only specify retrievers who can decrypt the ciphertext and does not have the function of generating encrypted tags for performing stealth retrieval, so dealing with stealth retrieval becomes a problem. Furthermore, since this method is composed of public - key encryption technology, even if the above - mentioned problem is solved, the processing speed also becomes a problem.
[0029] An object of the present disclosure is to be able to specify, for retrievers who can decrypt and retrieve, using the logical operator OR, and even when such a specification is made, to implement a multi - user public key method with high retrieval efficiency.
[0030] Means for Solving the Problems
[0031] The registration request device of the present disclosure has: a summary condition generation unit that adds a superior attribute condition including at least any one of a plurality of attribute conditions indicating attributes capable of retrieving ciphertext to the plurality of attribute conditions to generate a summary attribute condition; and an encrypted tag generation unit that generates an encrypted tag representing a retrieval condition in which the attribute conditions included in the summary attribute condition generated by the summary condition generation unit are connected using the logical operator OR and is used to implement retrieval of the ciphertext.
[0032] Effects of the Invention
[0033] In the present disclosure, an encrypted tag representing a retrieval condition is generated. The retrieval condition connects a plurality of attribute conditions representing attributes capable of retrieving ciphertext using a logical operator OR, and further connects a superordinate attribute condition including at least any one of the plurality of attribute conditions using a logical operator OR. Thus, for a retriever who can perform decryption and retrieval, it is possible to specify using a logical operator OR, and even if such a specification is made, a multi-user type public key method with high retrieval efficiency can be realized. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] Figure 1 is a structural diagram of the stealth retrieval system 100 according to Embodiment 1.
[0035] Figure 2 is a structural diagram of the master key generation device 200 according to Embodiment 1.
[0036] Figure 3 is a structural diagram of the registration key generation device 300 according to Embodiment 1.
[0037] Figure 4 is a structural diagram of the user key generation device 400 according to Embodiment 1.
[0038] Figure 5 is a structural diagram of the registration request device 500 according to Embodiment 1.
[0039] Figure 6 is a structural diagram of the generation unit 520 according to Embodiment 1.
[0040] Figure 7 is a structural diagram of the retrieval request device 600 according to Embodiment 1.
[0041] Figure 8 is a structural diagram of the data management device 700 according to Embodiment 1.
[0042] Figure 9 is a flowchart of the overall process of the stealth retrieval system 100 according to Embodiment 1.
[0043] Figure 10 is a flowchart of the master key generation process according to Embodiment 1.
[0044] Figure 11 is a flowchart of the registration key generation process according to Embodiment 1.
[0045] Figure 12 is a flowchart of the user key generation process according to Embodiment 1.
[0046] Figure 13 is a diagram showing an example of the attribute information according to Embodiment 1.
[0047] Figure 14 It is a flowchart of the registration request process in Embodiment 1.
[0048] Figure 15 It is a flowchart of the registration operation process in Embodiment 1.
[0049] Figure 16 It is an explanatory diagram of the information stored in the storage unit 790 in Embodiment 1.
[0050] Figure 17 It is a flowchart of the retrieval request process in Embodiment 1.
[0051] Figure 18 It is a flowchart of the retrieval operation process in Embodiment 1.
[0052] Figure 19 It is a flowchart of the decryption operation process in Embodiment 1.
[0053] Figure 20 It is a flowchart of the deletion operation process in Embodiment 1.
[0054] Figure 21 It is a structural diagram of the registration request device 500 in Embodiment 2.
[0055] Figure 22 It is a structural diagram of the generation unit 520A in Embodiment 2.
[0056] Figure 23 It is a structural diagram of the retrieval request device 600 in Embodiment 2.
[0057] Figure 24 It is a structural diagram of the data management device 700 in Embodiment 2.
[0058] Figure 25 It is a flowchart of the overall process of the concealed retrieval system 100 in Embodiment 2.
[0059] Figure 26 It is a flowchart of the registration request process in Embodiment 2.
[0060] Figure 27 It is a flowchart of the retrieval request process in Embodiment 2.
[0061] Figure 28 It is a flowchart of the retrieval operation process in Embodiment 2.
[0062] Figure 29 It is a flowchart of the decryption operation process in Embodiment 2.
[0063] Figure 30 It is a structural diagram of the master key generation device 200 in Modification 1.
[0064] Figure 31 This is a structural diagram of the registration key generation device 300 of Variant Example 1.
[0065] Figure 32 This is a structural diagram of the user key generation device 400 of Variant Example 1.
[0066] Figure 33 This is a structural diagram of the registration request device 500 of Variant Example 1.
[0067] Figure 34 This is a structural diagram of the retrieval request device 600 of Variant Example 1.
[0068] Figure 35 This is a structural diagram of the data management device 700 of Variant Example 1. Detailed implementation
[0069] In the embodiments and the drawings, the same reference numerals are assigned to the same elements and corresponding elements. The descriptions of the elements assigned the same reference numerals are appropriately omitted or simplified. The arrows in the drawings mainly indicate the data flow or the processing flow.
[0070] Embodiment 1
[0071] According to Figures 1 - 20 The following method is described: For a retriever who can decrypt and retrieve ciphertext, a concealed retrieval is performed using the logical operator OR.
[0072] ***Description of the structure***
[0073] Refer to Figure 1 The structure of the concealed retrieval system 100 of Embodiment 1 is described.
[0074] The concealed retrieval system 100 includes a master key generation device 200, a registration key generation device 300, a user key generation device 400, a registration request device 500, a retrieval request device 600, and a data management device 700.
[0075] The devices of the concealed retrieval system 100 communicate with each other via the network 101.
[0076] Refer to Figure 2 The structure of the master key generation device 200 of Embodiment 1 is described.
[0077] The master key generation device 200 is a computer. The master key generation device 200 has hardware such as a processor 201, a memory 202, an auxiliary storage device 203, an input / output interface 204, and a communication device 205. These hardware components are connected to each other via signal lines.
[0078] The master key generation device 200 includes elements such as a reception unit 210, a generation unit 220, and an output unit 230. These elements are implemented by software.
[0079] In the auxiliary storage device 203, a master key generation program for causing a computer to function as the reception unit 210, the generation unit 220, and the output unit 230 is stored. The master key program is loaded into the memory 202 and executed by the processor 201.
[0080] Furthermore, an OS is stored in the auxiliary storage device 203. At least a part of the OS is loaded into the memory 202 and executed by the processor 201. OS is an abbreviation for Operating System. That is, the processor 201 executes the master key generation program while executing the OS.
[0081] The data obtained by executing the master key generation program is stored in a storage device such as the memory 202, the auxiliary storage device 203, a register in the processor 201, or a cache memory in the processor 201.
[0082] The auxiliary storage device 203 functions as a storage unit 290. However, other storage devices may also function as the storage unit 290 instead of or together with the auxiliary storage device 203.
[0083] The master key generation program can be recorded (stored) in a non-volatile recording medium such as an optical disc or a flash memory in a computer-readable manner.
[0084] Refer to Figure 3 The structure of the registration key generation device 300 according to Embodiment 1 will be described.
[0085] The registration key generation device 300 is a computer. The registration key generation device 300 includes hardware such as a processor 301, a memory 302, an auxiliary storage device 303, an input / output interface 304, and a communication device 305. These hardware components are connected to each other via signal lines.
[0086] The registration key generation device 300 includes elements such as a reception unit 310, a generation unit 320, and an output unit 330. These elements are implemented by software.
[0087] In the auxiliary storage device 303, a registration key generation program for causing a computer to function as the reception unit 310, the generation unit 320, and the output unit 330 is stored. The registration key generation program is loaded into the memory 302 and executed by the processor 301.
[0088] Furthermore, an OS is stored in the auxiliary storage device 303. At least a part of the OS is loaded into the memory 302 and executed by the processor 301. That is, while executing the OS, the processor 301 executes the registration key generation program.
[0089] Data obtained by executing the registration key generation program is stored in a storage device such as the memory 302, the auxiliary storage device 303, a register in the processor 301, or a cache memory in the processor 301.
[0090] The auxiliary storage device 303 functions as a storage unit 390. However, other storage devices may also function as the storage unit 390 instead of or together with the auxiliary storage device 303.
[0091] The registration key program can be recorded (stored) in a non-volatile recording medium such as an optical disc or a flash memory in a computer-readable manner.
[0092] Refer to Figure 4 The structure of the user key generation device 400 according to Embodiment 1 will be described.
[0093] The user key generation device 400 is a computer. The user key generation device 400 has hardware such as a processor 401, a memory 402, an auxiliary storage device 403, an input / output interface 404, and a communication device 405. These hardware components are connected to each other via signal lines.
[0094] The user key generation device 400 has elements such as a reception unit 410, a generation unit 420, and an output unit 430. These elements are implemented by software.
[0095] A user key generation program for causing the computer to function as the reception unit 410, the generation unit 420, and the output unit 430 is stored in the auxiliary storage device 403. The user key generation program is loaded into the memory 402 and executed by the processor 401.
[0096] Furthermore, an OS is stored in the auxiliary storage device 403. At least a part of the OS is loaded into the memory 402 and executed by the processor 401. That is, while executing the OS, the processor 401 executes the user key generation program.
[0097] Data obtained by executing the user key generation program is stored in a storage device such as the memory 402, the auxiliary storage device 403, a register in the processor 401, or a cache memory in the processor 401.
[0098] The auxiliary storage device 403 functions as a storage unit 490. However, other storage devices may also function as the storage unit 490 instead of or together with the auxiliary storage device 403.
[0099] The user key generation program can be recorded (stored) in a non-volatile recording medium such as an optical disc or a flash memory in a computer-readable manner.
[0100] Refer to Figure 5 and Figure 6 The structure of the registration request device 500 in Embodiment 1 will be described.
[0101] The registration request device 500 is a computer. The registration request device 500 has hardware such as a processor 501, a memory 502, an auxiliary storage device 503, an input / output interface 504, and a communication device 505. These hardware components are connected to each other via signal lines.
[0102] The registration request device 500 has elements such as a reception unit 510, a generation unit 520, and a request unit 530. The generation unit 520 has a summary condition generation unit 521, a random number generation unit 522, a ciphertext generation unit 523, a keyword generation unit 524, and an encrypted tag generation unit 525. These elements are implemented by software.
[0103] In the auxiliary storage device 503, a registration request program for causing the computer to function as the reception unit 510, the generation unit 520, and the request unit 530 is stored. The registration request program is loaded into the memory 502 and executed by the processor 501.
[0104] Furthermore, an OS is stored in the auxiliary storage device 503. At least a part of the OS is loaded into the memory 502 and executed by the processor 501. That is, the processor 501 executes the registration request program while executing the OS.
[0105] The data obtained by executing the registration request program is stored in a storage device such as the memory 502, the auxiliary storage device 503, a register in the processor 501, or a cache memory in the processor 501.
[0106] The auxiliary storage device 503 functions as a storage unit 590. However, other storage devices may also function as the storage unit 590 instead of or together with the auxiliary storage device 503.
[0107] The registration request program can be recorded (stored) in a non-volatile recording medium such as an optical disc or a flash memory in a computer-readable manner.
[0108] Refer to Figure 7 The structure of the retrieval request device 600 in Embodiment 1 will be described.
[0109] The retrieval request device 600 is a computer. The retrieval request device 600 has hardware such as a processor 601, a memory 602, an auxiliary storage device 603, an input / output interface 604, and a communication device 605. These hardware components are connected to each other via signal lines.
[0110] The retrieval request device 600 has elements such as a reception unit 610, a generation unit 620, a request unit 630, a decryption unit 640, and an output unit 650. These elements are implemented by software.
[0111] In the auxiliary storage device 603, there is stored a retrieval request program for causing the computer to function as the reception unit 610, the generation unit 620, the request unit 630, the decryption unit 640, and the output unit 650. The retrieval request program is loaded into the memory 602 and executed by the processor 601.
[0112] Furthermore, an OS is stored in the auxiliary storage device 603. At least a part of the OS is loaded into the memory 602 and executed by the processor 601. That is, the processor 601 executes the retrieval request program while executing the OS.
[0113] The data obtained by executing the retrieval request program is stored in a storage device such as the memory 602, the auxiliary storage device 603, a register in the processor 601, or a cache memory in the processor 601.
[0114] The auxiliary storage device 603 functions as a storage unit 690. However, other storage devices may also function as the storage unit 690 instead of or together with the auxiliary storage device 603.
[0115] The retrieval request program can be recorded (stored) in a non-volatile recording medium such as an optical disc or a flash memory in a computer-readable manner.
[0116] Refer to Figure 8 The structure of the data management device 700 according to Embodiment 1 will be described.
[0117] The data management device 700 is a computer. The data management device 700 has hardware such as a processor 701, a memory 702, an auxiliary storage device 703, an input / output interface 704, and a communication device 705. These hardware components are connected to each other via signal lines.
[0118] The data management device 700 has elements such as a reception unit 710, a registration unit 720, a retrieval unit 730, and an output unit 740. These elements are implemented by software.
[0119] In the auxiliary storage device 703, there is stored a data management program for causing a computer to function as a reception unit 710, a registration unit 720, a retrieval unit 730, and an output unit 740. The data management program is loaded into the memory 702 and executed by the processor 701.
[0120] Furthermore, an OS is stored in the auxiliary storage device 703. At least a part of the OS is loaded into the memory 702 and executed by the processor 701. That is, the processor 701 executes the data management program while executing the OS.
[0121] Data obtained by executing the data management program is stored in a storage device such as the memory 702, the auxiliary storage device 703, a register in the processor 701, or a cache memory in the processor 701.
[0122] The auxiliary storage device 703 functions as a storage unit 790. However, other storage devices may also function as the storage unit 790 instead of or together with the auxiliary storage device 703.
[0123] The data management program can be recorded (stored) in a non-volatile recording medium such as an optical disc or a flash memory in a computer-readable manner.
[0124] The processors 201, 301, 401, 501, 601, 701 are ICs that perform arithmetic processing and control other hardware. IC is an abbreviation for Integrated Circuit. For example, the processors 201, 301, 401, 501, 601, 701 are CPUs, DSPs, or GPUs. CPU is an abbreviation for Central Processing Unit. DSP is an abbreviation for Digital Signal Processor. GPU is an abbreviation for Graphics Processing Unit.
[0125] The memories 202, 302, 402, 502, 602, 702 are volatile storage devices. The memories 202, 302, 402, 502, 602, 702 are also referred to as main storage devices or main memories. For example, the memories 202, 302, 402, 502, 602, 702 are RAMs. RAM is an abbreviation for Random Access Memory. Data stored in the memories 202, 302, 402, 502, 602, 702 is saved in the auxiliary storage devices 203, 303, 403, 503, 603, 703 as needed.
[0126] The auxiliary storage devices 203, 303, 403, 503, 603, 703 are non-volatile storage devices. For example, the auxiliary storage devices 203, 303, 403, 503, 603, 703 are ROM, HDD, or flash memory. ROM is an abbreviation for Read Only Memory. HDD is an abbreviation for Hard Disk Drive. The data stored in the auxiliary storage devices 203, 303, 403, 503, 603, 703 is loaded into the memories 202, 302, 402, 502, 602, 702 as needed.
[0127] The input / output interfaces 204, 304, 404, 504, 604, 704 are ports for connecting input devices and output devices. For example, the input / output interfaces 204, 304, 404, 504, 604, 704 are USB terminals, the input devices are a keyboard and a mouse, and the output device is a display. USB is an abbreviation for Universal Serial Bus.
[0128] The communication devices 205, 305, 405, 505, 605, 705 are receivers and transmitters. For example, the communication devices 205, 305, 405, 505, 605, 705 are communication chips or NICs. NIC is an abbreviation for Network Interface Card.
[0129] In addition, the master key generation device 200 may also have multiple processors instead of the processor 201. The multiple processors share the role of the processor 201. Similarly, the registration key generation device 300 may also have multiple processors instead of the processor 301. The multiple processors share the role of the processor 301. Similarly, the user key generation device 400 may also have multiple processors instead of the processor 401. The multiple processors share the role of the processor 401. Similarly, the registration request device 500 may also have multiple processors instead of the processor 501. The multiple processors share the role of the processor 501. Similarly, the retrieval request device 600 may also have multiple processors instead of the processor 601. The multiple processors share the role of the processor 601. Similarly, the data management device 700 may also have multiple processors instead of the processor 701. The multiple processors share the role of the processor 701.
[0130] ***Description of the operation***
[0131] Refer to Figures 9 - 20 The operation of the stealth retrieval system 100 of Embodiment 1 will be described.
[0132] The operation steps of the stealth search system 100 according to Embodiment 1 are equivalent to the stealth search method according to Embodiment 1. In addition, the program for implementing the operation of the stealth search system 100 according to Embodiment 1 is equivalent to the stealth search program according to Embodiment 1.
[0133] Refer to Figure 9 The overall processing of the stealth search system 100 according to Embodiment 1 will be described.
[0134] ( Figure 9 (Step S110 of the master key generation process)
[0135] The master key generation device 200 generates a master key MK. The master key MK is used to generate the registration key EK.
[0136] Refer to Figure 10 The master key generation process according to Embodiment 1 ( Figure 9 (Step S110)) will be described.
[0137] The master key generation process is executed by the master key generation device 200.
[0138] The operation steps of the master key generation device 200 according to Embodiment 1 are equivalent to the master key generation method according to Embodiment 1. In addition, the program for implementing the operation of the master key generation device 200 according to Embodiment 1 is equivalent to the master key generation program according to Embodiment 1.
[0139] ( Figure 10 (Step S111 of the acceptance process)
[0140] The acceptance unit 210 accepts the key length BIT.
[0141] Specifically, the acceptance unit 210 accepts the key length BIT input to the master key generation device 200 via the input / output interface 204. However, the acceptance unit 210 may also accept the key length BIT from the application program. The key length BIT is the bit length of the master key MK.
[0142] ( Figure 10 (Step S112 of the generation process)
[0143] The generation unit 220 generates the master key MK.
[0144] Specifically, the generation unit 220 generates a random bit string having the same length as the key length BIT. The generated bit string is the master key MK. For example, when the key length BIT is 256 bits, the generation unit 220 generates a 256-bit random bit string. Thus, a 256-bit master key MK is obtained.
[0145] ( Figure 10 (Step S113 of the storage process)
[0146] The generation unit 220 stores the master key MK in the storage unit 290.
[0147] ( Figure 10 (Step S114 of output processing)
[0148] The output unit 230 outputs the master key MK.
[0149] For example, the output unit 230 uses the communication device 205 to send the master key MK to the registration key generation device 300.
[0150] ( Figure 9 (Step S120 of registration key generation processing)
[0151] The registration key generation device 300 generates a registration key EK using the master key MK. The registration key EK is used to encrypt data and associated keywords. In addition, the registration key EK is used to generate a user key UK.
[0152] Refer to Figure 11 for the registration key generation processing of Embodiment 1 ( Figure 9 (Step S120)).
[0153] The registration key generation processing is executed by the registration key generation device 300.
[0154] The operation steps of the registration key generation device 300 in Embodiment 1 correspond to the registration key generation method in Embodiment 1. In addition, the program for implementing the operation of the registration key generation device 300 in Embodiment 1 corresponds to the registration key generation program in Embodiment 1.
[0155] ( Figure 11 (Step S121 of reception processing)
[0156] The reception unit 310 receives the master key MK.
[0157] For example, the reception unit 310 uses the communication device 305 to receive the master key MK from the master key generation device 200. However, the reception unit 310 can also receive the master key MK input to the registration key generation device 300 via the input / output interface 304.
[0158] ( Figure 11 (Step S122 of generation processing)
[0159] The generation unit 320 generates a registration key EK using the master key MK.
[0160] Specifically, the generation unit 320 executes the function F_EK with the master key MK as the input. The value obtained by executing the function F_EK is the registration key.
[0161] An example of the function F_EK is a one-way function. A one-way function refers to a function for which it is difficult to calculate the input value based on the output value of the function. For example, a cryptographic hash function such as SHA256 or a function of a cryptographic method such as AES is used as the function F_EK. AES is an abbreviation for Advanced Encryption Standard.
[0162] The registration key EK can be represented as follows.
[0163] EK = F_EK(MK)
[0164] In addition, assuming that in the case where it is desired to update the registration key EK or the registration key EK that has already been generated due to the deciphering of the function F_EK to a new registration key EK', it is also possible to append a value such as the generation number i to the input of the function F_EK to generate the new registration key EK'. For example, the generation number i is information such as a consecutive number or a date and time. The reception unit 310 may also receive the generation number i together with the master key MK.
[0165] The registration key EK' generated in consideration of the generation number i can be represented as follows.
[0166] EK' = F_EK(MK||i)
[0167] Here, for data x and data y, "x||y" represents the concatenation of x and y.
[0168] ( Figure 11 (Step S123 of
[0169] The generation unit 320 stores the registration key EK in the storage unit 390.
[0170] ( Figure 11 (Step S124 of
[0171] The output unit 330 outputs the registration key EK.
[0172] For example, the output unit 330 uses the communication device 305 to send the registration key EK to the user key generation device 400 and the registration request device 500 respectively.
[0173] ( Figure 9 (Step S130 of
[0174] The user key generation device 400 uses the registration key EK to generate a user key UK. The user key UK is used to encrypt the search keyword. In addition, the user key UK is used to decrypt the ciphertext to restore the original data.
[0175] Refer toFigure 12 Explanation is given to the user key generation process of Embodiment 1 ( Figure 9 step S130).
[0176] The user key generation process is executed by the user key generation device 400.
[0177] The operation steps of the user key generation device 400 of Embodiment 1 correspond to the user key generation method of Embodiment 1. In addition, the program for implementing the operation of the user key generation device 400 of Embodiment 1 corresponds to the user key generation program of Embodiment 1.
[0178] ( Figure 12 step S131: reception process)
[0179] The reception unit 410 receives the registration key EK. Then, the reception unit 410 stores the registration key EK in the storage unit 490.
[0180] For example, the reception unit 410 receives the registration key EK from the registration key generation device 300 using the communication device 405. However, the reception unit 410 may also receive the registration key EK input to the user key generation device 400 via the input / output interface 404.
[0181] In the case where the registration key EK has already been stored in the storage unit 490, there is no need to receive the registration key EK. However, if there is an update of the registration key EK, the new registration key EK is appended.
[0182] In addition, the reception unit 410 receives the attribute information A.
[0183] Specifically, the reception unit 410 receives the attribute information A input to the user key generation device 400 via the input / output interface 404. However, the reception unit 410 may also receive the attribute information A from the application program.
[0184] The attribute information A is the attribute information of the searcher. In addition, the attribute information A relates to the permission control of decryption and search. The searcher is the user who conducts the search. That is, the searcher is the user of the search request device 600. The attributes of the user form a hierarchy. The attribute information represents the attribute values of each layer of the user. That is, the attribute information A represents the attribute values of each layer of the searcher.
[0185] Refer to Figure 13 for an example of the attribute information of Embodiment 1.
[0186] The attributes of the user form a hierarchy. In Figure 13 it, the attributes of the user form 3 hierarchies. The attribute of the first layer (the first attribute) represents the department. The attribute of the second layer (the second attribute) represents the section. The attribute of the third layer (the third attribute) represents the name.
[0187] In Embodiment 1, for the attributes of each layer, the wildcard "*" can be used. The wildcard "*" represents any string. That is, it is a special notation that matches any string.
[0188] The first attribute information is the attribute information with the name N1. N1 belongs to Di1 section of De1 department.
[0189] The second attribute information is the attribute information with the name N2. N2 belongs to Di1 section of De1 department.
[0190] The third attribute information is the attribute information with the name N3. N3 belongs to Di2 section of De1 department.
[0191] The fourth attribute information is the attribute information that belongs to Di1 section of De1 department and has the name as the wildcard "*". Since the name is the wildcard "*", this attribute information represents all the people who belong to Di1 section of De1 department. That is, this attribute information includes the first attribute information of N1 and the second attribute information of N2. In other words, this attribute information includes the attribute information related to N1 and N2, and is the attribute information at the upper level of these attribute information.
[0192] For example, the section chief of Di1 section of De1 department, who is equivalent to the supervisor of N1 and N2, corresponds to this attribute information.
[0193] The fifth attribute information is the attribute information that belongs to De1 department and has the section name and name as the wildcard "*". This attribute information represents all the people who belong to De1 department. That is, this attribute information includes not only the first attribute information of N1 and the second attribute information of N2, but also the third attribute information of N3 and the fourth attribute information of the section chief of Di1 section. In other words, this attribute information includes not only the attribute information related to N1, N2 and N3, but also the fourth attribute information of the section chief of Di1 section, and is the attribute information at the upper level of these attribute information.
[0194] For example, the department head of De1 department corresponds to this attribute information.
[0195] In Embodiment 1, the attributes of the user form layer L, and the attribute information has L attribute values. L is an integer greater than or equal to 1. That is, here, each layer is assigned one attribute value.
[0196] Furthermore, in Embodiment 1, when the wildcard "*" is set for the l-th attribute value representing the attribute of a certain l-th layer, all the attribute values after the (l + 1)-th are set to the wildcard "*". l is an integer greater than or equal to 1 and less than or equal to L.
[0197] At this time, the attribute information A can be expressed as follows.
[0198] A = (A_1, …, A_L)
[0199] A_1, …, A_L are attribute values. If A_l is the wildcard "*", then all of A_l+1 to A_L are the wildcard "*".
[0200] ( Figure 12 (Step S132 of generation processing)
[0201] The generation unit 420 generates a user key UK using the registration key EK and the attribute information A. Specifically, the generation unit 420 calculates the user key UK as follows.
[0202] First, the generation unit 420 concatenates all of A_1 to A_L for the attribute information A = (A_1, …, A_L). The value represented by the resulting bit string is called the concatenation value A&. That is, the concatenation value A& can be expressed as follows.
[0203] A& = A_1 || … || A_L
[0204] Next, the generation unit 420 executes the function F_UK with the registration key EK and the concatenation value A& as inputs. The resulting value is called the user key element uk. The function F_UK is a one-way function such as a hash function or a public key cryptosystem. The user key element uk can be expressed as follows.
[0205] uk = F_UK(EK || A&)
[0206] = F_UK(EK || A_1 || … || A_L)
[0207] Next, the generation unit 420 executes the function F_UKA with the registration key EK and the concatenation value A& as inputs. The resulting value is called the user key attribute uka. The function F_UKA is a one-way function such as a hash function or a public key cryptosystem. However, the function F_UKA is not the same function as the function F_UK. Assuming that the function F_UK is used as the function F_UKA, it is necessary to also concatenate constant values such as 0 to the input value of the function F_UK to generate a user key attribute uka different from the user key element uk. The user key attribute uka can be expressed as follows. uka = F_UKA(EK || A_1 || … || A_L)
[0208] = F_UKA(EK || A&)
[0209] Then, the generation unit 420 constructs a group of the user key element uk and the user key attribute uka as the user key UK. The user key UK can be expressed as follows.
[0210] UK = (uk, uka)
[0211] ( Figure 12 (Step S133 of storage processing)
[0212] The generation unit 420 stores the user key UK in the storage unit 490.
[0213] ( Figure 12 (Step S134 of output processing)
[0214] The output unit 430 outputs the user key UK.
[0215] For example, the output unit 430 uses the communication device 405 to send the user key UK to the retrieval request device 600.
[0216] After the user key generation process ( Figure 9 (Step S130)), the operation transfers to the step corresponding to the execution content. Specifically, in the case of data registration, the operation transfers to the process of step S140. In the case of data retrieval, the operation transfers to the process of step S160. In the case of data deletion, the operation transfers to the process of step S190.
[0217] ( Figure 9 (Step S140 of registration request processing)
[0218] The registration request device 500 generates encrypted data using the registration key EK. The encrypted data has a ciphertext CT and an encrypted tag set ETS. The encrypted tag set ETS has one or more encrypted tags ET.
[0219] The ciphertext CT is used to restore the plaintext data D contained in the ciphertext CT using the user key UK.
[0220] A keyword is set for the encrypted tag ET. The encrypted tag ET is used to determine whether the set keyword matches the retrieval keyword contained in the retrieval query. The retrieval query is generated by encrypting the retrieval keyword using the user key UK. The determination of whether they match is performed while maintaining the encrypted state.
[0221] Refer to Figure 14 The registration request processing of Embodiment 1 Figure 9 (Step S140) will be described.
[0222] The registration request processing is executed by the registration request device 500.
[0223] The operation steps of the registration request device 500 in Embodiment 1 correspond to the registration request method in Embodiment 1. In addition, the program for implementing the operation of the registration request device 500 in Embodiment 1 corresponds to the registration request program in Embodiment 1.
[0224] (Figure 14 Step S141: Acceptance Processing)
[0225] The acceptance department 510 accepts and registers the encryption key EK. Then, the acceptance department 510 stores the registration key EK in the storage department 590.
[0226] For example, the acceptance department 510 receives the registration key EK from the registration key generation device 300 using the communication device 505. However, the acceptance department 510 can also accept the registration key EK input to the registration request device 500 via the input / output interface 504.
[0227] If the registration key EK has already been stored in the storage department 590, there is no need to receive the registration key EK. However, if there is an update to the registration key EK, the new registration key EK is appended.
[0228] In addition, the acceptance department 510 accepts the plaintext data D and the attribute conditional expression Σ.
[0229] Specifically, the acceptance department 510 accepts the plaintext data D and the attribute conditional expression Σ input to the registration request device 500 via the input / output interface 504. However, the acceptance department 510 can also accept the plaintext data D and the attribute conditional expression Σ from the application program.
[0230] The plaintext data D is unencrypted data. The unique identifier ID(D) representing the plaintext data D is included as metadata in the plaintext data D.
[0231] The attribute conditional expression Σ is information related to attributes where each attribute condition X is connected by the logical operator OR. The attribute condition X is information that specifies the attribute information of the retriever who can decrypt the ciphertext or perform a stealth search on the encrypted tag. The attribute condition X has the same structure as the attribute information A used in the generation of the user key UK. That is, the attribute condition X is information related to permission control for decryption and retrieval and can be expressed as follows.
[0232] X = (X_1,..., X_L)
[0233] For example, assume that the first attribute information (De1, Di1, N1) related to N1 as shown in Figure 13 is specified as the attribute condition X. That is, assume X = (De1, Di1, N1).
[0234] At this time, a retriever with a user key UK generated based on either the first attribute information related to N1 or the fourth and fifth attribute information equivalent to the supervisor of N1 can decrypt the ciphertext with the specified attribute condition X and perform a search on the encrypted tag.
[0235] Furthermore, the attribute conditional expression Σ is data composed of multiple attribute conditions X. That is, it can be expressed using M or more attribute conditions X as follows. M is an integer of 1 or more.
[0236] Σ = (X1,..., XM)
[0237] For example, let the attribute conditional expression Σ be composed of the attribute condition X1 and the attribute condition X2. That is, let M = 2. Suppose that Figure 13 the first attribute information (De1, Di1, N1) related to N1 shown in is specified as the attribute condition X1, and the second attribute information (De1, Di1, N2) related to N2 is specified as the attribute condition X2. That is, let X1 = (De1, Di1, N1), X2 = (De1, Di1, N2), and Σ = (X1, X2).
[0238] At this time, a retriever who has the user key UK generated based on any one of the first attribute information related to N1, the second attribute information related to N2, and the fourth and fifth attribute information equivalent to the superiors of N1 and N2 can decrypt the ciphertext specified by the attribute conditional expression Σ and retrieve the encryption tag.
[0239] That is, when using the logical operator OR, the attribute conditional expression Σ = (X1,..., XM) can be regarded as the following logical expression.
[0240] Σ = X1 OR... OR XM
[0241] ( Figure 14 (Step S142 of the summary condition generation process)
[0242] The summary condition generation unit 521 generates a summary attribute condition σ based on the attribute conditional expression Σ. The summary attribute condition σ for the attribute conditional expression Σ has a plurality of attribute conditions Y obtained by adding one or more upper-level attribute conditions X' including at least any one of the plurality of attribute conditions X included in the attribute conditional expression Σ to the plurality of attribute conditions X. That is, the plurality of attribute conditions Y include the plurality of attribute conditions X and one or more upper-level attribute conditions X'.
[0243] That is, the summary attribute condition σ is information specifying the attribute information of a retriever who can decrypt the ciphertext or retrieve the encryption tag, and is a condition indicating the same retriever as the retriever specified by the attribute conditional expression Σ. The summary attribute condition σ can be expressed using J attribute conditions Y as follows. Here, J is an integer of 1 or more.
[0244] Σ = (Y1,..., YJ)
[0245] However, the upper levels are not repeated. For example, any attribute information includes attribute information consisting entirely of wildcards "*" (*, …, *) as the upper level. However, the aggregated attribute condition σ does not repeatedly include multiple attribute conditions X' representing the attribute information (*, …, *). That is, the attribute conditions Y1 to YJ are all different attribute conditions.
[0246] For example, let the attribute conditional expression Σ consist of attribute conditions X1, X2, and X3. That is, let J = 3. Using Figure 13 the attribute information shown, let the attribute condition X1 be (De1, Di1, N1), the attribute condition X2 be (De1, Di1, N2), and the attribute condition X3 be (De1, Di2, N3).
[0247] At this time, the upper-level attribute conditions that match the attribute condition X1 are included as follows.
[0248] (De1, Di1, *)
[0249] (De1, *, *)
[0250] (*, *, *)
[0251] In addition, the upper-level attribute conditions that match the attribute condition X2 are included as follows.
[0252] (De1, Di1, *)
[0253] (De1, *, *)
[0254] (*, *, *)
[0255] In addition, the upper-level attribute conditions that match the attribute condition X3 are included as follows.
[0256] (De1, Di2, *)
[0257] (De1, *, *)
[0258] (*, *, *)
[0259] Therefore, the aggregated attribute condition σ at this time consists of the following 7 attribute conditions Yj. Among them, j is an integer greater than or equal to 1 and less than or equal to 7.
[0260] Y1 = (De1, Di1, N1)
[0261] Y2 = (De1, Di1, N2)
[0262] Y3 = (De1, Di1, *)
[0263] Y4 = (De1, Di3, N3)
[0264] Y5 = (De1, Di2, *)
[0265] Y6 = (De1, *, *)
[0266] Y7 = (*, *, *)
[0267] ( Figure 14 (Step S143 of: Processing the ciphertext with a random number generation)
[0268] The random number generation unit 522 generates a random number s and a random number r. The random number generation unit 522 sets these two random numbers as the random numbers CR for ciphertext. That is, the random numbers CR for ciphertext can be expressed as follows.
[0269] CR = (s, r)
[0270] ( Figure 14 (Step S144 of: Ciphertext generation processing)
[0271] The ciphertext generation unit 523 generates a ciphertext CT using the registration key EK, the plaintext data D, the summary attribute condition σ, and the random numbers CR for ciphertext.
[0272] The ciphertext CT has J ciphertext elements CT_j, a ciphertext random number s, a ciphertext verification value CTV, and a ciphertext payload CTP. The j of the ciphertext element CT_j is an integer from 1 to J, and J is the number of attribute conditions Y included in the summary attribute condition σ. The ciphertext random number s is the random number s included in the random numbers CR for ciphertext. In addition, the unique identifier ID(D) of the plaintext data is included in the ciphertext CT as metadata. This unique identifier ID(D) can also be encrypted.
[0273] The ciphertext generation unit 523 calculates the ciphertext element C_j for each integer j from 1 to J as follows.
[0274] First, the ciphertext generation unit 523 concatenates the registration key EK and Yj included in the summary attribute condition σ. The value represented by the obtained bit string is called the concatenated value Yj'. Next, the ciphertext generation unit 523 executes the function F_UK with the concatenated value Yj' as the input. The obtained value is called the function value Yj". Next, the ciphertext generation unit 523 concatenates the function value Yj" and the ciphertext random number s. The value represented by the obtained bit string is called the concatenated value Yjs'. Next, the ciphertext generation unit 523 executes the function F_CT with the concatenated value Yjs' as the input. The obtained value is called the function value Yjs". Then, the ciphertext generation unit 523 calculates the exclusive OR of the function value Yjs" and the random number r. The obtained value is the ciphertext element C_j.
[0275] The function F_UK is in Figure 12The one-way function used in the processing of step S132. The function F_CT is a one-way function such as a hash function or a public-key cryptosystem.
[0276] In the ciphertext element C_j, the attribute condition Yj included in the aggregation attribute condition σ is set as the decryption condition. As a result, the decryption conditions set in the ciphertext CT are in a state where the attribute conditions Yj included in the aggregation attribute condition σ are connected by the logical operator OR.
[0277] The ciphertext generation unit 523 calculates the ciphertext verification value CTV as follows.
[0278] The ciphertext generation unit 523 executes the function F_CTV with the random number r as the input. The obtained value is the ciphertext verification value CTV. The function F_CTV is a one-way function such as a hash function or a public-key cryptosystem.
[0279] The ciphertext generation unit 523 calculates the ciphertext payload CTP as follows.
[0280] The ciphertext generation unit 523 executes the function ENC with the random number r as the key for the plaintext data D. The obtained value is the ciphertext payload CTP. The function ENC is a public-key cryptosystem such as AES that can restore the original plaintext data from the encrypted data.
[0281] In addition, the function that restores the original plaintext data from the output value of the function ENC and the key used in its calculation is set as the function DEC. That is, for a certain key KEY, the function DEC becomes DEC(KEY, ENC(KEY, D)) = D.
[0282] The ciphertext CT can be expressed as follows. However, in Embodiment 1, "+" means exclusive OR (XOR).
[0283] CT = (CT_1,..., CT_J, s, CTV, CTP)
[0284] CT_j = F_CT(F_UK(EK||Yj)||s)+r
[0285] CTV = F_CTV(r)
[0286] CTP = F_CTP(r,D)
[0287] ( Figure 14 (Step S145: Keyword generation process)
[0288] The keyword generation unit 524 generates a keyword group related to the plaintext data D. The keyword group is one or more keywords.
[0289] Specifically, the keyword generation unit 524 generates a keyword group based on the plaintext data D by performing morphological analysis or natural language processing on the plaintext data D. However, the keyword generation unit 524 may also receive, via the input / output interface 504, the keyword group input to the registration request device 500. In addition, the keyword generation unit 524 may also receive a keyword group from an application program.
[0290] The generated keyword group is referred to as the registration keyword set W.
[0291] In the first embodiment, it is assumed that the registration keyword set W consists of I registration keywords. I is an integer greater than or equal to 1. The registration keyword set W can be represented as follows.
[0292] W = (W_1,..., W_I)
[0293] ( Figure 14 (Step S146 of the random number generation process for tags)
[0294] The random number generation unit 522 generates a random number S and a random number R. The random number generation unit 522 sets these two random numbers as the encryption tag random numbers TR. That is, the encryption tag random numbers TR can be represented as follows.
[0295] TR = (S, R)
[0296] ( Figure 14 (Step S147 of the encryption tag generation process)
[0297] The encryption tag generation unit 525 generates an encryption tag set ETS using the registration key EK, the registration keyword set W, the summary attribute condition σ, and the encryption tag random numbers TR.
[0298] The encryption tag set ETS has I encryption tags ETi. The i of the encryption tag ETi is an integer greater than or equal to 1 and less than or equal to I, and I is the number of keywords included in the keyword set W.
[0299] The encryption tag ETi has J tag elements ETi_j, the encryption tag random number S, and the encryption tag verification value ETV. The j of the tag element ETi_j is an integer greater than or equal to 1 and less than or equal to J, and J is the number of attribute conditions Y included in the summary attribute condition σ. The encryption tag random number S is the random number S included in the encryption tag random numbers TR.
[0300] For each integer i, j where i = 1,..., I and j = 1,..., J, the encryption tag generation unit 525 calculates the tag element ETi_j as follows.
[0301] First, the encrypted label generation unit 525 concatenates the registration key EK and Yj included in the aggregated attribute condition σ. The value indicated by the obtained bit string is called the concatenated value Yj^. Next, the encrypted label generation unit 525 executes the function F_UK with the concatenated value Yj^ as the input. The obtained value is called the function value Yj^^. Next, the encrypted label generation unit 525 concatenates the function value Yj^^ and the keyword W_i. The value indicated by the obtained bit string is called the concatenated value YjW^. Next, the encrypted label generation unit 525 executes the function F_ET1 with the concatenated value YjW^ as the input. The obtained value is called the function value YjW^^. Next, the encrypted label generation unit 525 concatenates the function value YjW^^ and the encrypted label random number S. The value indicated by the obtained bit string is called the concatenated value YjWS^. Next, the encrypted label generation unit 525 executes the function F_ET2 with the concatenated value YjWS^ as the input. The obtained value is called the function value YjWS^^. Then, the encrypted label generation unit 525 calculates the exclusive OR of the function value YjWS^^ and the random number R. The obtained value is the label element ETi_j.
[0302] The function F_UK is a one-way function used in Figure 12 the process of step S132 and Figure 14 the process of step S144. The functions F_ET1 and F_ET2 are one-way functions such as hash functions or public key cryptosystems.
[0303] In the label element ETi_j, Yj included in the aggregated attribute condition σ is set as the retrieval condition. As a result, the retrieval condition set in the encrypted label ETi becomes a state in which the attribute conditions Yj included in the aggregated attribute condition σ are connected using the logical operator OR.
[0304] The encrypted label generation unit 525 calculates the encrypted label verification value ETV as follows.
[0305] The encrypted label generation unit 525 executes the function F_ETV with the random number R as the input. The obtained value is the encrypted label verification value ETV. The function F_ETV is a one-way function such as a hash function or a public key cryptosystem.
[0306] The encrypted label set ETS can be represented as follows.
[0307] ETS = (ET1,..., ETK, S, ETV)
[0308] ETi = (ETi_1,..., ETi_K)
[0309] ETi_j = F_ET2(F_ET1(F_UK(EK||Yj)||W_i)||S)+R
[0310] ETV = F_ETV(R)
[0311] ( Figure 14 (Step S148 of registration request processing)
[0312] The request unit 530 requests the data management device 700 to register a set of ciphertext CT and encrypted tags ETS, that is, encrypted data.
[0313] ( Figure 9 (Step S150 of registration operation processing)
[0314] The data management device 700 registers the encrypted data. The encrypted data has ciphertext CT and a set of encrypted tags ETS. The set of encrypted tags ETS has one or more encrypted tags ET.
[0315] Refer to Figure 15 for the registration operation processing of Embodiment 1( Figure 9 (Step S150) is described.
[0316] The registration operation processing is executed by the data management device 700.
[0317] The operation steps of the data management device 700 in Embodiment 1 correspond to the data management method in Embodiment 1. In addition, the program for implementing the operation of the data management device 700 in Embodiment 1 corresponds to the data management program in Embodiment 1.
[0318] ( Figure 15 (Step S151 of acceptance processing)
[0319] The acceptance unit 710 accepts the ciphertext CT and the set of encrypted tags ETS.
[0320] For example, the acceptance unit 710 receives the ciphertext CT and the set of encrypted tags ETS from the registration request device 500 using the communication device 705. However, the acceptance unit 710 can also accept the ciphertext CT and the set of encrypted tags ETS input to the data management device 700 via the input / output interface 704.
[0321] ( Figure 15 (Step S152 of registration processing)
[0322] The registration unit 720 stores the ciphertext CT and the set of encrypted tags ETS in the storage unit 790.
[0323] As Figure 16 shown, in the storage unit 790, the unique identifier ID(D), the ciphertext CT, and the set of encrypted tags ETS are stored in a corresponding state to each other.
[0324] ( Figure 9 (Step S160 of retrieval request processing)
[0325] The retrieval request device 600 generates a retrieval query SQ using the user key UK. The retrieval query SQ is used to perform a stealth retrieval on the encrypted tag ET.
[0326] Refer to Figure 17 The retrieval request process of Embodiment 1 ( Figure 9 step S150) will be described.
[0327] The retrieval request process is executed by the retrieval request device 600.
[0328] The operation steps of the retrieval request device 600 in Embodiment 1 correspond to the retrieval request method of Embodiment 1. In addition, the program for implementing the operation of the retrieval request device 600 in Embodiment 1 corresponds to the retrieval request program of Embodiment 1.
[0329] ( Figure 17 step S161: reception process)
[0330] The reception unit 610 receives the user key UK. Then, the reception unit 610 stores the user key UK in the storage unit 690.
[0331] For example, the reception unit 610 receives the user key UK from the user key generation device 400 using the communication device 605. However, the reception unit 610 may also receive the user key UK input to the retrieval request device 600 via the input / output interface 604.
[0332] In the case where the user key UK has already been stored in the storage unit 690, there is no need to receive the user key UK. However, if there is an update of the user key UK, the new user key UK is appended.
[0333] In addition, the reception unit 610 receives the retrieval keyword w.
[0334] Specifically, the reception unit 610 receives the retrieval keyword w input to the retrieval request device 600 via the input / output interface 604. However, the reception unit 610 may also receive the retrieval keyword w from the application program.
[0335] ( Figure 17 step S162: generation process)
[0336] The generation unit 620 generates a retrieval query SQ using the user key UK and the retrieval keyword w. Specifically, the generation unit 620 calculates the retrieval query SQ as follows.
[0337] First, the generation unit 620 extracts the user key element uk from the user key UK. Next, the generation unit 620A concatenates the user key element uk and the search keyword w. The value represented by the obtained bit string is called the concatenated value UKw^. Then, the generation unit 620 uses the concatenated value UKw^ as an input to execute the function F_ET1. The obtained value is the search query SQ.
[0338] The function F_ET1 is a one-way function used in Figure 14 the process of step S147.
[0339] The search query SQ can be represented as follows.
[0340] SQ = F_ET1(uk||w)
[0341] ( Figure 17 step S163 of
[0342] The request unit 630 uses the communication device 605 to send the search query SQ to the data management device 700.
[0343] ( Figure 9 step S170 of
[0344] The data management device 700 retrieves the encrypted data. The encrypted data has the ciphertext CT and the encrypted tag set ETS. The encrypted tag set ETS has one or more encrypted tags ET.
[0345] The data management device 700 performs a stealth search on the encrypted tag ET using the search query SQ. Thus, the data management device 700 determines whether the keyword included in the encrypted tag ET and the search keyword included in the search query SQ match. If they match, the data management device 700 extracts the ciphertext CT stored in association with the encrypted tag ET.
[0346] Refer to Figure 18 for the search operation process of Embodiment 1 ( Figure 9 step S170 of
[0347] The search operation process is executed by the data management device 700.
[0348] ( Figure 18 step S171 of
[0349] The reception unit 710 receives the search query SQ.
[0350] For example, the reception unit 710 uses the communication device 705 to receive the search query SQ from the search request device 600. However, the reception unit 610 may also receive the search query SQ input to the data management device 700 via the input / output interface 704.
[0351] ( Figure 18 Step S172 of Retrieval Processing)
[0352] The retrieval unit 730 performs a masked retrieval on each of the J tag elements ETi_j of the I encrypted tags ETi included in the encrypted tag set ETS through the retrieval query SQ. Thus, the retrieval unit 730 selects the encrypted tag set ETS that matches the retrieval query SQ.
[0353] The i of the encrypted tag ETi is an integer from 1 to I, and I is the number of encrypted tags ETi included in the encrypted tag set ETS. In addition, the j of the tag element ETi_j is an integer from 1 to J, and J is the number of tag elements ETi_j included in the encrypted tag ETi.
[0354] Specifically, the retrieval unit 730 processes the tag elements ETi_j of the encrypted tags ETi in the encrypted tag set ETS as follows.
[0355] First, the retrieval unit 730 concatenates the retrieval query SQ and the encrypted tag random number S included in the encrypted tag set ETS. The value indicated by the obtained bit string is called the concatenation value SQ^. Next, the retrieval unit 730 executes the function F_ET2 with the concatenation value SQ^ as the input. The obtained value is called the function value SQ^^. Next, the retrieval unit 730 calculates the exclusive OR of the function value SQ^^ and the encrypted tag ETi_j. The obtained value is called the calculated value Rij. Next, the retrieval unit 730 executes the function F_ETV with the calculated value Rij as the input. The obtained value is called the function value Vij. Then, the retrieval unit 730 confirms whether the value of the function value Vij and the encrypted tag verification value ETV included in the encrypted tag set ETS are the same.
[0356] If the values are the same, the unique identifier ID corresponding to the encrypted tag ETi_j is extracted.
[0357] The functions F_ET2 and F_ETV are one-way functions used in Figure 14 Step S147.
[0358] The function value SQ^^ and the calculated value Rij obtained through the above processing can be expressed as follows.
[0359] SQ^^ = F_ET2(SQ||S)
[0360] = F_ET2(F_ET1(F_UK(EK||A&)||w)||S)
[0361] Rij = SQ^^ + ETi_j
[0362] = F_ET2(F_ET1(F_UK(EK||A&)||w)||S)
[0363] + F_ET2(F_ET1(F_UK(EK||Yj)||W_i)||S)
[0364] + R
[0365] If “A& = Yj” and “w = W_i”, that is, if “the attribute information A included in the user key UK is equal to the attribute condition Yj included in the encryption tag ETi” and “the search keyword w is equal to the registered keyword W_i”, then “Rij = R”.
[0366] Therefore, at this time, “Vij = F_ETV(Rij) = F_ETV(R) = ETV”.
[0367] The set of unique identifiers ID extracted here is called the corresponding unique identifier set IDS.
[0368] ( Figure 18 Step S173 of (
[0369] The retrieval unit 730 extracts the ciphertext CT corresponding to the unique identifier ID included in the corresponding unique identifier set IDS from the storage unit 790. The set of the extracted ciphertext CT is called the encrypted retrieval result ERES.
[0370] If the corresponding unique identifier set IDS is an empty set, this step is omitted.
[0371] ( Figure 18 Step S174 of (
[0372] The output unit 740 sends the encrypted retrieval result ERES to the retrieval request device 600.
[0373] ( Figure 9 Step S180 of (
[0374] The retrieval request device 600 decrypts the encrypted data using the user key UK. The encrypted data is the ciphertext CT included in the encrypted retrieval result ERES.
[0375] Refer to Figure 19 The decryption operation process of Embodiment 1 ( Figure 9 Step S180 of (
[0376] The decryption operation process is executed by the retrieval request device 600.
[0377] ( Figure 19 Step S181 of (
[0378] The receiving unit 610 receives the encrypted retrieval result ERES.
[0379] For example, the receiving unit 610 receives the encrypted retrieval result ERES from the data management device 700 using the communication device 605. However, the receiving unit 610 may also receive the encrypted retrieval result ERES input to the retrieval request device 600 via the input / output interface 604.
[0380] ( Figure 19 (Step S182 of) decryption processing
[0381] The decryption unit 640 decrypts each ciphertext CT included in the encrypted retrieval result ERES using the user key UK to generate plaintext data D.
[0382] If the encrypted retrieval result ERES is an empty set, this step is omitted.
[0383] Specifically, the decryption unit 640 sets each ciphertext CT included in the encrypted retrieval result ERES as the target ciphertext CT. The decryption unit 640 processes and decrypts the ciphertext element CT_j related to each integer J of j = 1,..., J in the target ciphertext CT as follows. Here, j is an integer of 1 or more and J or less, and J is the number of ciphertext elements CT_j included in the ciphertext CT.
[0384] First, the decryption unit 640 concatenates the user key element uk included in the user key UK and the ciphertext random number s included in the ciphertext CT. The value indicated by the obtained bit string is called the concatenated value uk’^. Next, the decryption unit 640 executes the function F_CT using the concatenated value uk’ as the input. The obtained value is called the function value uk”. Next, the decryption unit 640 calculates the exclusive OR of the function value uk” and the ciphertext element CT_j. The obtained value is called the calculated value rj. Next, the decryption unit 640 executes the function F_CTV using the calculated value rj as the input. The obtained value is called the function value vj. Next, the decryption unit 640 confirms whether the function value vj and the value of the ciphertext verification value CTV included in the ciphertext CT are the same.
[0385] Then, assuming that the function value vj and the value of the ciphertext verification value CTV are the same, the decryption unit 640 executes the function DEC using the calculated value rj as the key for the ciphertext payload CTP. The obtained value is the plaintext data D.
[0386] The function F_CT and the function F_CTV are one-way functions used in Figure 14 (step S144).
[0387] The function value uk” and the calculated value rj obtained through the above processing can be expressed as follows.
[0388] uk” = F_CT(uk||s)
[0389] = F_CT(F_UK(EK||A&)||s)
[0390] rj = uk” + CT_j
[0391] = F_CT(F_UK(EK||A&)||s)
[0392] + F_CT(F_UK(EK||Yj)||s) + r
[0393] If “A& = Yj”, that is, if “the attribute information A included in the user key UK is equal to the attribute condition Yj included in the ciphertext CT”, then “rj = r”.
[0394] Therefore, at this time, “vj = F_CTV(rj) = F_CTV(r) = CTV”.
[0395] The set of plaintext data D obtained here is called the retrieval result RES.
[0396] ( Figure 19 (Step S183 of
[0397] The output unit 650 outputs all the plaintext data D included in the retrieval result RES.
[0398] Specifically, the output unit 650 displays all the plaintext data D on the display via the input / output interface 604. Assuming that the retrieval result RES is an empty set, that is, in the case where there is no encrypted tag ET that hits the retrieval, the output unit 650 displays a message indicating that there is no plaintext data D that hits the retrieval.
[0399] ( Figure 9 (Step S190 of
[0400] The data management device 700 deletes the encrypted data. The encrypted data is the ciphertext CT and the set of encrypted tags ETS corresponding thereto.
[0401] Refer to Figure 20 The deletion operation process of Embodiment 1 is described Figure 9 (Step S190 of
[0402] The deletion operation process is executed by the data management device 700.
[0403] ( Figure 20 (Step S191 of
[0404] The receiving unit 710 receives a unique identifier ID(D).
[0405] Specifically, the receiving unit 710 receives the unique identifier ID(D) input to the data management device 700 via the input / output interface 704. However, the receiving unit 710 may also receive the unique identifier ID(D) from an application program. In addition, the receiving unit 710 may also receive the unique identifier ID(D) from the registration request device 500 and the retrieval request device 600 using the communication device 705.
[0406] The unique identifier ID(D) is obtained through the result of the retrieval request process ( Figure 9 step S160), the retrieval operation process ( Figure 9 step S170), and the decryption operation process ( Figure 9 step S180).
[0407] ( Figure 20 step S192: deletion process)
[0408] The receiving unit 710 deletes the ciphertext CT and the encrypted tag set ETS corresponding to the unique identifier ID(D) from the storage unit 790.
[0409] ***Effects of Embodiment 1***
[0410] As described above, the stealth retrieval system 100 of Embodiment 1 can implement a multi-user type stealth retrieval method only based on public key cryptography technology. That is, it can implement a multi-user type stealth retrieval method without using public key cryptography technology. Thereby, data registration and retrieval can be performed at high speed.
[0411] The stealth retrieval system 100 of Embodiment 1 can use the logical operator OR to simultaneously set multiple attribute conditions set in the ciphertext and the encrypted tag. As a result, even for attribute conditions using the logical operator OR, it is possible to easily specify the retrievers who can perform decryption and retrieval. Furthermore, when specifying attribute conditions using the logical operator OR, compared with the existing multi-user type public key method, not only can the data sizes of the ciphertext and the encrypted tag be reduced, but also decryption and retrieval can be performed efficiently. Moreover, since it is not necessary to distribute multiple user secret keys to the retrievers, an increase in operation load can be prevented.
[0412] The stealth retrieval system 100 according to Embodiment 1 adds a higher-level attribute condition X' that includes at least any one of the specified attribute conditions to the specified attribute condition X to generate a summary attribute condition σ. Then, the stealth retrieval system 100 sets a retrieval condition that connects the attribute conditions Y (= attribute conditions X, X') included in the summary attribute condition σ using a logical operator OR for the ciphertext and the encrypted tag. Thus, it is possible to implement the following multi-user type public key method: by using wildcards, it is possible to recognize the hierarchical structure and efficiently specify the retrievers who can perform decryption and retrieval.
[0413] Embodiment 2
[0414] The difference between Embodiment 2 and Embodiment 1 is that the ciphertext CT that can be retrieved using the encrypted attribute information is screened first, thereby efficiently decrypting the ciphertext CT and retrieving the encrypted tag ET. In Embodiment 2, this difference will be described, and the description of the same parts will be omitted.
[0415] ***Description of the structure***
[0416] Part of the structure of the registration request device 500, part of the structure of the retrieval request device 600, and part of the structure of the data management device 700 are different from those in Embodiment 1.
[0417] Refer to Figure 21 and Figure 22 The structure of the registration request device 500 according to Embodiment 2 will be described.
[0418] The registration request device 500 has a generation unit 520A instead of the generation unit 520 in Embodiment 1. Specifically, as Figure 22 shown, the generation unit 520A has a ciphertext generation unit 523A instead of the ciphertext generation unit 523, has an encrypted tag generation unit 525A instead of the encrypted tag generation unit 525, and further additionally has an attribute element generation unit 526.
[0419] Refer to Figure 23 The structure of the retrieval request device 600 according to Embodiment 2 will be described.
[0420] The retrieval request device 600 has a generation unit 620A instead of the generation unit 620 in Embodiment 1, has a decryption unit 640A instead of the decryption unit 640, and further additionally has a screening unit 660.
[0421] Refer to Figure 24 The structure of the data management device 700 according to Embodiment 2 will be described.
[0422] The data management device 700 has a search unit 730A instead of the search unit 730 of the first embodiment, and further has a screening unit 750 additionally.
[0423] ***Description of the operation***
[0424] Refer to Figures 25 - 29 The operation of the stealth search system 100 of the second embodiment will be described.
[0425] The operation steps of the stealth search system 100 of the second embodiment correspond to the stealth search method of the second embodiment. In addition, the program for implementing the operation of the stealth search system 100 of the second embodiment corresponds to the stealth search program of the second embodiment.
[0426] Refer to Figure 25 The overall processing of the stealth search system 100 of the second embodiment will be described.
[0427] The processing of step S110, step S120, step S130, step S150, and step S190 is the same as that of the first embodiment.
[0428] Refer to Figure 26 The registration request process of the second embodiment ( Figure 25 step S140A) will be described.
[0429] The processing of step S140A corresponds to Figure 9 step S140. The processing of step S141, step S142, step S143, step S145, step S146, and step S148 is the same as that of the first embodiment.
[0430] ( Figure 26 step S142A of
[0431] The attribute element generation unit 526 generates an encrypted aggregated attribute condition Eσ using the aggregated attribute condition σ.
[0432] Specifically, the attribute element generation unit 526 calculates the encrypted aggregated attribute condition Eσ as follows. The encrypted aggregated attribute condition Eσ has J encrypted attribute conditions Eσ_j. j is an integer from 1 to J, and J is the number of attribute conditions included in the aggregated attribute condition σ.
[0433] First, for each integer j from j = 1 to J, the attribute element generation unit 526 concatenates the registration key EK and Yj included in the aggregated attribute condition σ. The value indicated by the obtained bit string is called the concatenated value Yj'. Then, the ciphertext generation unit 523 executes the function F_UKA using the concatenated value Yj' as the input. The obtained value is Eσ_j.
[0434] The function F_UKA is inFigure 12 The one-way function used in step S132 of
[0435] The encrypted aggregated attribute condition Eσ can be expressed as follows.
[0436] Eσ = (Eσ1,..., EσJ)
[0437] Eσj = F_UKA(EK || Yj)
[0438] ( Figure 26 Step S144A of
[0439] The ciphertext generation unit 523A generates a ciphertext CT using the registration key EK, the plaintext data D, the aggregated attribute condition σ, the encrypted aggregated attribute condition Eσ, and the ciphertext random number CR.
[0440] The ciphertext CT has J ciphertext elements CT_j, J ciphertext attributes CTA_j, a ciphertext random number s, a ciphertext verification value CTV, and a ciphertext payload CTP. j is an integer from 1 to J, and J is the number of attribute conditions Y included in the aggregated attribute condition σ. In addition, the unique identifier ID(D) of the plaintext data is included in the ciphertext CT as metadata of the plaintext data D. This unique identifier ID(D) may also be encrypted.
[0441] The ciphertext element CT_j, the ciphertext random number s, the ciphertext verification value CTV, and the ciphertext payload CTP are the same as those in Embodiment 1.
[0442] The ciphertext generation unit 523A sets the ciphertext attribute CTA_j as follows.
[0443] For each integer j from 1 to J, the ciphertext generation unit 523A sets the encrypted attribute condition Eσj included in the encrypted aggregated attribute condition Eσ as the ciphertext attribute CTA_j.
[0444] The ciphertext CT can be expressed as follows. However, in Embodiment 2, "+" means exclusive OR (XOR).
[0445] CT = (CT_1,..., CT_J, CTA_1,..., CTA_J, s, CTV, CTP)
[0446] CT_j = F_CT(F_UK(EK || Yj) || s) + r
[0447] CTA_j = Eσj
[0448] = F_UKA(EK || Yj)
[0449] CTV = F_CTV(r)
[0450] CTP = F_CTP(r, D)
[0451] ( Figure 26 (Step S147A of the encryption label generation process)
[0452] The encryption label generation unit 525A generates an encryption label set ETS using the registration key EK, the registration keyword set W, the summary attribute condition σ, the encrypted summary attribute condition Eσ, and the random number TR for the encryption label.
[0453] The encryption label set ETS has I encryption labels ETi and J encryption label attributes ETA_j. The i of the encryption label ETi is an integer from 1 to I or less, and I is the number of keywords included in the keyword set W. The j of the encryption label attribute ETA_j is an integer from 1 to J or less, and J is the number of attribute conditions included in the summary attribute condition σ.
[0454] The encryption label ETi is the same as that in Embodiment 1.
[0455] The encryption label generation unit 525A calculates the encryption label attribute ETA_j as follows.
[0456] For each integer j where j = 1,..., J, the encryption label generation unit 525A sets the encryption attribute condition Eσj included in the encrypted summary attribute condition Eσ as the encryption label attribute ETA_j.
[0457] The encryption label set ETS can be represented as follows.
[0458] ETS = (ET1,..., ETI, ETA_1,..., ETA_J, S, ETV)
[0459] ETi = (ETi_1,..., ETi_J)
[0460] ETi_j = F_ET2(F_ET1(F_UK(EK || Yj) || Wi) || S) + R
[0461] ETA_j = Eσj
[0462] = F_UKA(EK || Yj)
[0463] ETV = F_ETV(R)
[0464] Refer to Figure 27 For the retrieval request processing in Embodiment 2( Figure 25 (Step S160A) is described.
[0465] The processing of step S160A is equivalent to Figure 9 Step S160. Steps S161 and S163 are the same as those in Embodiment 1.
[0466] ( Figure 27 Step S162A of (
[0467] The generation unit 620A generates a retrieval query SQ using the user key UK and the retrieval keyword w. The retrieval query SQ has a retrieval query element sq and a retrieval query attribute sqa.
[0468] The generation unit 620A calculates the retrieval query element sq as follows.
[0469] First, the generation unit 620A extracts the user key element uk from the user key UK. Next, the generation unit 620A concatenates the user key element uk and the retrieval keyword w. The value represented by the obtained bit string is called the concatenation value w^. Then, the generation unit 620A executes the function F_ET1 with the concatenation value w^ as the input. The obtained value is the retrieval query element sq.
[0470] The generation unit 620A sets the user key attribute uka of the user key UK as the retrieval query attribute sqa.
[0471] The retrieval query SQ can be expressed as follows.
[0472] SQ = (sq, sqa)
[0473] sq = F_ET1(uk||w)
[0474] = F_ET1(F_UK(EK||A&)||w)
[0475] sqa = uka
[0476] = F_UKA(EK||A&)
[0477] Refer to Figure 28 for the retrieval operation processing of Embodiment 2 ( Figure 25 step S170A) is described.
[0478] The processing of step S170A corresponds to Figure 9 step S170. Steps S171, step S173, and step S174 are the same as those in Embodiment 1.
[0479] ( Figure 28 Step S172A of (
[0480] The screening unit 750 screens the encrypted tag set ETS using the retrieval query attribute sqa included in the retrieval query SQ.
[0481] Specifically, the screening unit 750 searches for the encrypted tag attributes ETA_j of each encrypted tag set ETS that match the retrieval query attribute sqa. The screening unit 750 extracts the unique identifier ID(D) included as metadata of the encrypted tag set ETS of the matching encrypted tag attribute ETA_j and the integer j that is the suffix of ETA_j. The set of groups of the extracted unique identifier ID(D) and integer j is called the screened encrypted tag set ETSID.
[0482] The screened encrypted tag set ETSID can be expressed as follows. Here, K is an integer of 1 or more, which is the number of the extracted integers j. In addition, j_1 to j_K are integers of 1 or more and J or less, representing the extracted integers j.
[0483] ETSID = {(ID(D1), j_1), …, (ID(DK), j_K)}
[0484] That is, (ID(Dk), j_k) included in the screened encrypted tag set ETSID means that only the retrieval query SQ and special operations are performed on the tag elements ET1_(j_k) to ETI_(j_k) of the encrypted tag set ETS corresponding to the unique identifier ID(Dk). That is, the object of the special operation is only screened to the encrypted tag set ETS corresponding to the unique identifier ID(Dk) in the encrypted tag set ETS. Furthermore, regarding the I encrypted tags ETi included in the screened encrypted tag set ETS, the objects of the special operation are respectively only screened to the tag elements ETi_(j_k) indicated by the integer j_k among the J tag elements ETi_j.
[0485] In other words, in this step, the encrypted tag attribute ETA_(j_k) used in the result of the tag elements ET1_(j_k) to ETI_(j_k) that matches the retrieval query attribute sqa is extracted. Then, in the next step, a process is performed to confirm whether each keyword W_1 to W_I included in the tag elements ET1_(j_k) to ETI_(j_k) matches the retrieval keyword w included in the retrieval query element sq.
[0486] Here, the tag element ETi_(j_k), the retrieval query element sq, the encrypted tag attribute ETA_(j_k), and the retrieval query attribute sqa can be expressed as follows.
[0487] ETi_(j_k) = F_ET2(F_ET1(F_UK(EK||Yj_k)||w_i)||S) + R
[0488] sq = F_ET1(F_UK(EK||A&)||w)
[0489] ETA_(j_k) = F_UKA(EK||Yj_k)
[0490] sqa = F_UKA(EK||A&)
[0491] More precisely, it is shown that if the encrypted tag attribute ETA_(j_k) and the retrieval query attribute sqa are equal, then the concatenation value A& of the attribute condition Yj_k included in the tag element ETi_(j_k) and the attribute information included in the retrieval query element sq is equal.
[0492] ( Figure 28 Step S172B of (
[0493] The retrieval unit 730A performs a stealth retrieval on the tag elements ETi_(j_k) of the encrypted tag set ETS corresponding to the filtered encrypted tag set ETSID through the retrieval query SQ. Thus, the retrieval unit 730A selects the encrypted tag set ETS that matches the retrieval query SQ.
[0494] The i of the encrypted tag ETi is an integer greater than or equal to 1 and less than or equal to I, where I is the number of encrypted tags ETi included in the encrypted tag set ETS. In addition, j_k of the tag element ETi_(j_k) is an integer greater than or equal to 1 and less than or equal to J, which is a value included in the filtered encrypted tag set ETSID.
[0495] Specifically, the retrieval unit 730A sets each (ID(Dk), j_k) included in the filtered encrypted tag set ETSID as the target (ID(Dk), j_k). The retrieval unit 730A sets each encrypted tag set ETS corresponding to the unique identifier ID(Dk) in the target (ID(Dk), j_k) as the target encrypted tag set ETS. For the I encrypted tags ETi included in the target encrypted tag set ETS, the retrieval unit 730A respectively sets the tag element ETi_(j_k) indicated by the integer j_k in the J tag elements ETi_j as the target tag element ETi_(j_k). Then, the retrieval unit 730A performs the following processing on the target tag element ETi_(j_k).
[0496] First, the retrieval unit 730A connects the retrieval query element sq included in the retrieval query SQ and the encrypted tag random number S included in the set of encrypted tags ETS corresponding to the unique identifier ID (Dk). The value represented by the obtained bit string is called the connection value sq^. Next, the retrieval unit 730A executes the function F_ET2 with the connection value sq^ as the input. The obtained value is called the function value sq^^. Next, the retrieval unit 730A calculates the exclusive OR of the function value sq^^ and the encrypted tag ETi_(j_k). The obtained value is called the calculated value Rijk. Next, the retrieval unit 730A executes the function F_ETV with the calculated value Rijk as the input. The obtained value is called the function value Vijk.
[0497] Then, the retrieval unit 730A confirms whether the value of the function value Vijk is the same as the value of the encrypted tag verification value ETV included in the set of encrypted tags ETS. If the values are the same, the unique identifier ID corresponding to the tag element ETi_(j_k) is extracted.
[0498] The function value sq^^ and the calculated value Rijk obtained through the above processing can be expressed as follows.
[0499] sq^^ = F_ET2(sq||S)
[0500] = F_ET2(F_ET1(F_UK(EK||A&)||w)||S)
[0501] Rijm = sq^^ + ETi_(j_k)
[0502] = F_ET2(F_ET1(F_UK(EK||A&)||w)||S)
[0503] + F_ET2(F_ET1(F_UK(EK||Yj_k)||W_i)||S)
[0504] + r
[0505] If "A& = Yj_k" and "w = W_i", that is, if "the attribute information A included in the user key UK is equal to the attribute condition Yj_k included in the encrypted tag ETi" and "the retrieval keyword w is equal to the registered keyword W_i", then "Rijk = R".
[0506] Therefore, at this time, "Vijk = F_ETV(Rijk) = F_ETV(R) = ETV".
[0507] The set of the unique identifiers ID extracted here is called the corresponding unique identifier set IDS.
[0508] Refer to Figure 29Description of the decryption operation process of Embodiment 2 ( Figure 25 Step S180A).
[0509] The process of Step S180A is equivalent to Figure 9 Step S180. Steps S181 and S183 are the same as those in Embodiment 1.
[0510] ( Figure 29 Step S182A in
[0511] : Screening process)
[0512] If the encrypted search result ERES is an empty set, this step is omitted.
[0513] Specifically, the screening unit 660 uses the user key UK to generate a screening result ERES' that converts each ciphertext CT included in the encrypted search result ERES into a screened ciphertext CT'.
[0514] First, the screening unit 660 searches for the ciphertext attribute CTA_j included in the ciphertext CT that is consistent with the user key attribute uka included in the user key UK. Here, j is an integer greater than or equal to 1 and less than or equal to J, and J is the number of ciphertext elements CTA_j included in the ciphertext CT. Then, the ciphertext element CT_j, the ciphertext random number s, and the ciphertext verification value CTV corresponding to the ciphertext attribute CTA_j that is consistent with the user key attribute uka are extracted. Then, the screening unit 660 combines the extracted ciphertext attribute CTA_j, ciphertext element CT_j, ciphertext random number s, and ciphertext verification value CTV, and sets them as the screened ciphertext CT'. This screened ciphertext CT' is appended to the screening result ERES'.
[0515] At this time, the screened ciphertext CT' can be expressed as follows.
[0516] CT' = (CTA_j, CT_j, s, CTV)
[0517] Here, the ciphertext element CT_j and the user key element uk, and the ciphertext attribute CTA_j and the user key attribute uka can be expressed as follows.
[0518] CT_j = F_CT(F_UK(EK||Yj_k)||s) + r
[0519] uk = F_UK(EK||A&)
[0520] CTA_j = F_UKA(EK||Yj_k)
[0521] uka = F_UKA(EK||A&)
[0522] That is, it is shown that if the ciphertext attribute CTA_j and the user key attribute uka are equal, the attribute condition Yj_k included in the ciphertext element CT_j and the attribute information A& included in the user key element uk are equal. As a result, instead of performing the stealth retrieval process on all the ciphertext elements CT_j, it is only necessary to perform the stealth retrieval process on the ciphertext element CT_j corresponding to the ciphertext attribute CTA_j that matches the user key attribute uka.
[0523] ( Figure 29 (Step S182B of decryption processing)
[0524] The decryption unit 640A uses the user key UK to decrypt the plaintext data D from each screened ciphertext CT' included in the screening result ERES'.
[0525] If the screening result ERES' is an empty set, this step is omitted.
[0526] Specifically, the decryption unit 640A processes and decrypts the screened ciphertext CT' of the screening result ERES' as follows.
[0527] First, the decryption unit 640A concatenates the user key element uk included in the user key UK and the ciphertext random number s included in the screened ciphertext CT'. The value indicated by the obtained bit string is called the concatenated value uk^. Next, the decryption unit 640A executes the function F_CT with the concatenated value uk^ as the input. The obtained value is called the function value uk^^. Next, the decryption unit 640A calculates the exclusive OR of the function value uk^^ and the ciphertext element CT_j included in the screened ciphertext CT'. The obtained value is called the calculated value rj. Next, the decryption unit 640A executes the function F_CTV with the calculated value rj as the input. The obtained value is called the function value vj. Next, the decryption unit 640A confirms whether the value of the function value vj and the value of the ciphertext verification value CTV included in the ciphertext CT are consistent.
[0528] Then, assuming that the values of the function value vj and the ciphertext verification value CTV are consistent, the decryption unit 640A executes the function DEC with the calculated value rj as the key for the ciphertext payload CTP. The obtained value is the plaintext data D.
[0529] The function value uk^^ and the calculated value rj obtained through the above processing can be expressed as follows.
[0530] uk^^ = F_CT(uk||s)
[0531] = F_CT(F_UK(EK||A&)||s)
[0532] rj = uk^^ + CT_j
[0533] = F_CT(F_UK(EK || A&) || s)
[0534] + F_CT(F_UK(EK || Yj) || s) + r
[0535] If “A& = Yj”, that is, if “the attribute information A included in the user key UK is equal to the attribute condition Yj included in the ciphertext CT”, then “rj = r”.
[0536] Therefore, at this time, “vj = F_CTV(rj) = F_CTV(r) = CTV”.
[0537] In addition, in step S182A, the integer j where “the attribute information A included in the user key UK is equal to the attribute condition Yj included in the ciphertext CT” has been screened. Therefore, different from Embodiment 1, the decryption process can be performed at high speed.
[0538] ***Effects of Embodiment 2***
[0539] As described above, the privacy retrieval system 100 of Embodiment 2 includes the encrypted tag attribute ETA_j including the encrypted attribute condition Eσj that sets the attribute condition instead of the keyword and is encrypted in the encrypted tag set ETS. Thus, the ciphertext CT set with the retrievable attribute condition can be efficiently screened. That is, the data to be retrieved can be screened. As a result, compared with Embodiment 1, the retrieval can be performed at high speed.
[0540] Similarly, the privacy retrieval system 100 of Embodiment 2 includes the ciphertext attribute CTA_j including the encrypted attribute condition Eσj in the ciphertext CT. Thus, the ciphertext CT set with the decryptable attribute condition can be efficiently screened. That is, the data to be decrypted can be screened. As a result, compared with Embodiment 1, the decryption can be performed at high speed.
[0541] ***Other Structures***
[0542] <Modification Example 1>
[0543] In Embodiments 1 and 2, each functional structural element is implemented by software. However, as Modification Example 1, each functional structural element can also be implemented by hardware. Regarding this Modification Example 1, the differences from Embodiments 1 and 2 will be described.
[0544] Refer to Figure 30 The structure of the master key generation device 200 of Modification Example 1 will be described.
[0545] In the case where each functional structural element is implemented by hardware, the master key generation device 200 has an electronic circuit 206 instead of the processor 201, the memory 202, and the auxiliary storage device 203. The electronic circuit 206 is a dedicated circuit that implements the functions of each functional structural element of the master key generation device 200 and the functions of the memory 202 and the auxiliary storage device 203.
[0546] Refer to Figure 31 The structure of the registration key generation device 300 of Modification 1 will be described.
[0547] In the case where each functional structural element is implemented by hardware, the registration key generation device 300 has an electronic circuit 306 instead of the processor 301, the memory 302, and the auxiliary storage device 303. The electronic circuit 306 is a dedicated circuit that implements the functions of each functional structural element of the registration key generation device 300 and the functions of the memory 302 and the auxiliary storage device 303.
[0548] Refer to Figure 32 The structure of the user key generation device 400 of Modification 1 will be described.
[0549] In the case where each functional structural element is implemented by hardware, the user key generation device 400 has an electronic circuit 406 instead of the processor 401, the memory 402, and the auxiliary storage device 403. The electronic circuit 406 is a dedicated circuit that implements the functions of each functional structural element of the user key generation device 400 and the functions of the memory 402 and the auxiliary storage device 403.
[0550] Refer to Figure 33 The structure of the registration request device 500 of Modification 1 will be described.
[0551] In the case where each functional structural element is implemented by hardware, the registration request device 500 has an electronic circuit 506 instead of the processor 501, the memory 502, and the auxiliary storage device 503. The electronic circuit 506 is a dedicated circuit that implements the functions of each functional structural element of the registration request device 500 and the functions of the memory 502 and the auxiliary storage device 503.
[0552] Refer to Figure 34 The structure of the retrieval request device 600 of Modification 1 will be described.
[0553] In the case where each functional structural element is implemented by hardware, the retrieval request device 600 has an electronic circuit 606 instead of the processor 601, the memory 602, and the auxiliary storage device 603. The electronic circuit 606 is a dedicated circuit that implements the functions of each functional structural element of the retrieval request device 600 and the functions of the memory 602 and the auxiliary storage device 603.
[0554] Refer toFigure 35 The structure of the data management apparatus 700 in Modification 1 will be described.
[0555] When each functional structural element is implemented by hardware, the data management apparatus 700 has an electronic circuit 706 instead of the processor 701, the memory 702, and the auxiliary storage device 703. The electronic circuit 706 is a dedicated circuit that implements the functions of each functional structural element of the data management apparatus 700 and the functions of the memory 702 and the auxiliary storage device 703.
[0556] As the electronic circuits 206, 306, 406, 506, 606, 706, a single circuit, a composite circuit, a programmed processor, a parallel-programmed processor, a logic IC, a GA, an ASIC, an FPGA are envisioned. GA is an abbreviation for Gate Array. ASIC is an abbreviation for Application Specific Integrated Circuit. FPGA is an abbreviation for Field-Programmable Gate Array.
[0557] Each functional structural element can be implemented by one electronic circuit 206, 306, 406, 506, 606, 706, or multiple electronic circuits 206, 306, 406, 506, 606, 706 can be dispersed to implement each functional structural element.
[0558] <Modification 2>
[0559] As Modification 2, it is also possible that some of the functional structural elements are implemented by hardware and the other functional structural elements are implemented by software.
[0560] The processors 201, 301, 401, 501, 601, 701, the memories 202, 302, 402, 502, 602, 702, and the electronic circuits 206, 306, 406, 506, 606, 706 are referred to as processing circuits. That is, the functions of each functional structural element are implemented by the processing circuits.
[0561] In addition, the "section" in the above description can also be rewritten as "circuit", "process", "step", "processing", or "processing circuit".
[0562] The embodiments and modifications of the present disclosure have been described above. It is also possible to combine several of these embodiments and modifications. In addition, any one or several of the embodiments and modifications can be partially implemented. Further, the present disclosure is not limited to the above embodiments and modifications, and various changes can be made as needed.
[0563] Description of Reference Numerals
[0564] 100: Concealed Retrieval System; 101: Network; 200: Master Key Generation Device; 201: Processor; 202: Memory; 203: Auxiliary Storage Device; 204: Input / Output Interface; 205: Communication Device; 210: Reception Unit; 220: Generation Unit; 230: Output Unit; 290: Storage Unit; 300: Registration Key Generation Device; 301: Processor; 302: Memory; 303: Auxiliary Storage Device; 304: Input / Output Interface; 305: Communication Device; 310: Reception Unit; 320: Generation Unit; 330: Output Unit; 390: Storage Unit; 400: User Key Generation Device; 401: Processor; 402: Memory; 403: Auxiliary Storage Device; 404: Input / Output Interface; 405: Communication Device; 410: Reception Unit; 420: Generation Unit; 430: Output Unit; 490: Storage Unit; 500: Registration Request Device; 501: Processor; 502: Memory; 503: Auxiliary Storage Device; 504: Input / Output Interface; 505: Communication Device; 510: Reception Unit; 520: Generation Unit; 520A: Generation Unit; 521: Aggregation Condition Generation Unit; 522: Random Number Generation Unit; 523: Ciphertext Generation Unit; 523A: Ciphertext Generation Unit; 524: Keyword Generation Unit; 525: Encryption Label Generation Unit; 525A: Encryption Label Generation Unit; 526: Attribute Element Generation Unit; 530: Request Unit; 590: Storage Unit; 600: Retrieval Request Device; 601: Processor; 602: Memory; 603: Auxiliary Storage Device; 604: Input / Output Interface; 605: Communication Device; 610: Reception Unit; 620: Generation Unit; 620A: Generation Unit; 630: Request Unit; 640: Decryption Unit; 640A: Decryption Unit; 650: Output Unit; 660: Screening Unit; 690: Storage Unit; 700: Data Management Device; 701: Processor; 702: Memory; 703: Auxiliary Storage Device; 704: Input / Output Interface; 705: Communication Device; 710: Reception Unit; 720: Registration Unit; 730: Retrieval Unit; 740: Output Unit; 750: Screening Unit; 790: Storage Unit.
Claims
1. A registration request device, the registration request device having: A summary condition generation unit that adds a superior attribute condition including at least any one of a plurality of attribute conditions representing attributes capable of retrieving ciphertext to the plurality of attribute conditions to generate a summary attribute condition; and An encrypted tag generation unit that generates an encrypted tag, the encrypted tag representing a retrieval condition obtained by connecting the attribute conditions included in the summary attribute condition generated by the summary condition generation unit using a logical operator OR, and used to implement retrieval of the ciphertext.
2. The registration request device according to claim 1, wherein The encrypted tag generation unit uses the attribute conditions included in the summary attribute condition as object attribute conditions respectively, and uses one or more keywords for retrieving the ciphertext as object keywords respectively, and generates the encrypted tag including tag elements in which the object attribute conditions and the object keywords are set and encrypted.
3. The registration request device according to claim 2, wherein The encrypted tag generation unit generates the encrypted tag including an exclusive OR of a bit string in which the object attribute conditions and the object keywords are set and encrypted and a random number R.
4. The registration request device according to claim 3, wherein The encrypted tag generation unit generates the encrypted tag including a tag verification value obtained by performing a one-way function with the random number R as an input.
5. The registration request device according to any one of claims 2 to 4, wherein The encrypted tag generation unit uses the attribute conditions included in the summary attribute condition as object attribute conditions respectively, and generates an encrypted tag attribute including encrypted attribute conditions in which the object attribute conditions are set without setting the keywords.
6. The registration request device according to any one of claims 1 to 5, wherein The registration request device further has a ciphertext generation unit that encrypts plaintext data after setting a decryption condition obtained by connecting the attribute conditions included in the summary attribute condition using a logical operator OR, thereby generating the ciphertext.
7. A retrieval request device that requests retrieval from a data management device, the data management device using a plurality of ciphertexts as object ciphertexts respectively, and storing encrypted tags corresponding to the object ciphertexts, the encrypted tags representing retrieval conditions obtained by connecting each of the attribute conditions representing attributes capable of retrieving the object ciphertexts and a superior attribute condition including at least any one of the plurality of attribute conditions using a logical operator OR, and used to implement retrieval of the ciphertext, wherein The retrieval request device has a request unit that sends an encrypted retrieval query in which attribute information representing the attributes of a retriever is set to the data management device, and requests the ciphertexts among the plurality of ciphertexts for which the attribute information satisfies the retrieval conditions indicated by the corresponding encrypted tags.
8. A data management device, the data management device having: An acceptance unit that accepts a search query in which attribute information indicating the attributes of a searcher is set and encrypted; and A search unit that searches, from a storage device, for ciphertexts in which the attribute information set in the search query accepted by the acceptance unit satisfies the search conditions indicated by an encryption tag. The storage device stores multiple ciphertexts as target ciphertexts, and stores, corresponding to each target ciphertext, an encryption tag that represents a search condition in which each of multiple attribute conditions indicating attributes capable of retrieving the target ciphertext and a superordinate attribute condition including at least any one of the multiple attribute conditions are connected using a logical operator OR, and that is used to implement the search for the ciphertexts.
9. A stealth search system having a registration request device, a search request device, and a data management device, wherein The registration request device includes: An aggregated condition generation unit that, taking multiple ciphertexts as target ciphertexts, adds a superordinate attribute condition including at least any one of multiple attribute conditions indicating attributes capable of retrieving the target ciphertexts to the multiple attribute conditions to generate an aggregated attribute condition; And An encryption tag generation unit that generates an encryption tag that represents a search condition in which the attribute conditions included in the aggregated attribute condition generated by the aggregated condition generation unit are connected using a logical operator OR, and that is used to implement the search for the ciphertexts, The search request device includes a request unit that sends a search query in which attribute information indicating the attributes of a search executor is set and encrypted to the data management device, and requests ciphertexts among the multiple ciphertexts in which the attribute information satisfies the search conditions indicated by the corresponding encryption tag, The data management device includes: An acceptance unit that accepts the search query sent by the request unit; and A search unit that searches, from a storage device, for ciphertexts in which the attribute information set in the search query accepted by the acceptance unit satisfies the search conditions indicated by the encryption tag. The storage device stores, corresponding to the target ciphertexts, the encryption tags generated by the encryption tag generation unit for the target ciphertexts.
10. A registration request method, wherein A computer adds a superordinate attribute condition including at least any one of multiple attribute conditions indicating attributes capable of retrieving ciphertexts to the multiple attribute conditions to generate an aggregated attribute condition, The computer generates an encryption tag that represents a search condition in which the attribute conditions included in the aggregated attribute condition are connected using a logical operator OR, and that is used to implement the search for the ciphertexts.
11. A registration request program that causes a computer to function as a registration request device, the registration request device performing the following processes: An aggregated condition generation process of adding a superordinate attribute condition including at least any one of multiple attribute conditions indicating attributes capable of retrieving ciphertexts to the multiple attribute conditions to generate an aggregated attribute condition; and Encryption label generation process, which generates an encryption label. The encryption label represents a retrieval condition obtained by connecting the attribute conditions included in the summary attribute conditions generated by the above-mentioned summary condition generation process using the logical operator OR, and is used to implement the retrieval of the ciphertext.
12. A retrieval request method, which requests retrieval from a data management device. The data management device uses multiple ciphertexts as target ciphertexts respectively, and stores encryption labels corresponding to the target ciphertexts. The encryption label represents a retrieval condition obtained by connecting each of the multiple attribute conditions representing the attributes capable of retrieving the target ciphertext and a superior attribute condition including at least any one of the multiple attribute conditions using the logical operator OR, and is used to implement the retrieval of the ciphertext. Among them, The computer sends a retrieval query in which attribute information representing the attributes of the retrieval executor is set and encrypted to the data management device, and requests the ciphertexts among the multiple ciphertexts whose attribute information satisfies the retrieval condition indicated by the corresponding encryption label.
13. A retrieval request program, which requests retrieval from a data management device. The data management device uses multiple ciphertexts as target ciphertexts respectively, and stores encryption labels corresponding to the target ciphertexts. The encryption label represents a retrieval condition obtained by connecting each of the multiple attribute conditions representing the attributes capable of retrieving the target ciphertext and a superior attribute condition including at least any one of the multiple attribute conditions using the logical operator OR, and is used to implement the retrieval of the ciphertext. Among them, The retrieval request program causes the computer to function as a retrieval request device. The retrieval request device performs the following request processing: sending a retrieval query in which attribute information representing the attributes of the retrieval executor is set and encrypted to the data management device, and requesting the ciphertexts among the multiple ciphertexts whose attribute information satisfies the retrieval condition indicated by the corresponding encryption label.
14. A data management method, in which, The computer accepts a retrieval query in which attribute information representing the attributes of the retrieval executor is set and encrypted, The computer retrieves from the storage device the ciphertexts whose attribute information set in the retrieval query satisfies the retrieval condition indicated by the encryption label. The storage device uses multiple ciphertexts as target ciphertexts respectively, and stores the encryption labels corresponding to the target ciphertexts. The encryption label represents the retrieval condition obtained by connecting each of the multiple attribute conditions representing the attributes capable of retrieving the target ciphertext and a superior attribute condition including at least any one of the multiple attribute conditions using the logical operator OR, and is used to implement the retrieval of the ciphertext.
15. A data management program, which causes the computer to function as a data management device. The data management device performs the following processing: Acceptance processing, accepting a retrieval query in which attribute information representing the attributes of the retrieval executor is set and encrypted; and A retrieval process retrieves, from a storage device, ciphertexts in which the attribute information set in the retrieval query accepted by the acceptance process satisfies the retrieval conditions indicated by the encryption tags. The storage device stores multiple ciphertexts as respective target ciphertexts, and stores the encryption tags corresponding to the target ciphertexts. The encryption tag represents a retrieval condition in which each of multiple attribute conditions indicating attributes capable of retrieving the target ciphertexts and a superior attribute condition including at least any one of the multiple attribute conditions are connected using a logical operator OR, and is used to implement retrieval of the ciphertexts.