Ciphertext spatial index construction method and device based on hierarchical order-preserving encryption

Through the combination of AR+ tree index and multi-level keys, rapid search and query of vector data in the ciphertext state is achieved, solving the security risks and inefficient data storage in the database, and improving data security and retrieval efficiency.

CN120386786AActive Publication Date: 2025-07-29CHINESE ACAD OF SURVEYING & MAPPING

Patent Information

Application Number
CN202510873515.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-27
Publication Date
2025-07-29
Estimated Expiration
2045-06-27

AI Technical Summary

Technical Problem

In the prior art, vector data is stored in plain text in the database with security risks, and traditional encryption methods lead to inefficient query efficiency, which cannot effectively take into account data security and retrieval efficiency.

Method used

The ciphertext spatial index construction method based on hierarchical order-preserved encryption is adopted. By creating an AR+ tree index, embedding security policies and generating multi-level keys, the indexed plaintext data is hierarchical order-preserved encryption, and the rapid retrieval and query in the ciphertext state is realized.

Benefits of technology

It improves the security and retrieval efficiency of spatial data, realizes fine-grained access control, reduces query time complexity and data processing complexity, and ensures the sequential characteristics and privacy of the data in the encrypted state.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120386786A_ABST
    Figure CN120386786A_ABST
Patent Text Reader

Abstract

The invention discloses a ciphertext spatial index construction method and device based on hierarchical order-preserving encryption, and relates to the field of ciphertext spatial indexing.The method comprises the steps that a security policy is embedded into nodes of an R + tree index, and the AR + tree index is obtained; generating a multi-level key based on an AR + tree index; performing hierarchical order-preserving encryption on the index plaintext data by adopting a multi-level key, and mapping the index plaintext data to a ciphertext interval; analyzing the query statement to obtain a query rectangle and a user access permission; performing hierarchical order-preserving encryption on a query rectangle based on an AR + tree index and a multi-level key, and calculating an intersection with a minimum bounding rectangle of each layer of nodes; the user access authority is verified, and all data IDs meeting conditions are screened out; determining an original data ciphertext based on the screened data ID; and decrypting the original data ciphertext by using an encryption algorithm used during original data encryption to obtain plaintext data. According to the method and the device, quick retrieval and query of the spatial index in the ciphertext state can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of constructing ciphertext space indexes, and particularly to a method and device for constructing a ciphertext space index based on hierarchical order-preserving encryption. Background Art

[0002] In the information age, geospatial data has been applied in all aspects of our lives and is quietly changing our lifestyle. As an important part of geospatial data, vector spatial data has been deeply integrated into daily life and social governance. For example, using the vector road network data of navigation maps to plan travel routes and travel modes; management departments optimizing the layout of smart cities with the help of vector layers such as building outlines and underground pipelines; emergency departments simulating the disaster impact range and formulating rescue plans based on administrative division vector data, etc. The application of vector data is improving our quality of life and ensuring our safety. With the advancement of networking and digitization, while data is convenient for sharing and application, it is also more likely to be stolen and tampered with during storage and transmission. The security of vector geospatial data is facing severe challenges.

[0003] To ensure the convenience and security of vector data during storage, spatial database technology has been widely applied. As a spatial database system (such as Oracle Spatial, PostGIS, etc.) that specifically manages spatial data (such as geographical locations, geometric figures), it has the capabilities of supporting multi-user concurrent editing and transaction control, being compatible with OGC (Open Geospatial Consortium) standards (such as WKT, Well-Known Text, GeoJSON, JavaScript Object Notation) to improve interoperability, and processing massive spatio-temporal data. With the progress of technology, the functions of spatial databases themselves are also constantly expanding. In the 1980s, database encryption technology emerged in the United States. Subsequently, many mainstream database management software also added encryption modules in new versions, and users can use the encryption functions provided by the database to protect data security. However, traditional database encryption technology often needs to encrypt the entire database or data table. During this process, some ordinary data will also be encrypted. When querying data, the entire database or data table needs to be decrypted before query operations can be performed, which brings problems of over-encryption and low efficiency. Especially for large-scale data, full-database or full-table encryption and decryption will consume a large amount of time. To balance data security and retrieval efficiency, it is urgent to research and apply new data protection methods.

[0004] At present, the commonly used vector data protection methods mainly include encryption technology, digital watermarking technology, access control technology, and confidentiality processing technology. Encryption technology is a typical technology for prior prevention. By using keys and encryption algorithms to cover up the original appearance of the data, the data becomes chaotic, and only users with the key can decrypt the data. Digital watermarking technology is a commonly used technology for post-facto investigation. By embedding information such as user identity and usage period in the original data, it is possible to trace the source of data dissemination after a data security problem occurs and protect the copyright of the data. Access control technology mainly controls the data range and data accuracy that different users can access by specifying access policies, verifying the identity, permissions, and environment of the access personnel, and is also an important technology for prior prevention. Confidentiality processing technology uses mathematical transformations and other methods to reduce the spatial position accuracy, elevation accuracy of the data, and remove sensitive attribute information. After confidentiality processing, the data can be used in public places.

[0005] The access control model is the basis for implementing access control. In order to adapt to the characteristics of vector data, researchers have improved the traditional access control model, mainly including extensions based on the Discretionary Access Control (DAC) model, extensions based on the Mandatory Access Control (MAC) model, extensions based on the Role-based Access Control (RABC) model, and some other access control models for specific scenarios. However, spatial access control mainly restricts data visitors. People without access rights cannot view the data, and users with different access rights view different levels of data. There is a lack of protection measures for the data itself, and the data is still stored in plaintext.

[0006] Therefore, how to solve the problem of plaintext storage of data in the database has become a technical problem that urgently needs to be solved in this field. Summary of the Invention

[0007] The purpose of this application is to provide a method and device for constructing a ciphertext space index based on hierarchical order-preserving encryption, which can achieve fast retrieval and query of the space index in the ciphertext state.

[0008] To achieve the above purpose, this application provides the following solutions.

[0009] In the first aspect, this application provides a method for constructing a ciphertext space index based on hierarchical order-preserving encryption. The method for constructing a ciphertext space index based on hierarchical order-preserving encryption includes the following steps.

[0010] Obtain spatial vector data; the spatial vector data includes a number of vector space objects.

[0011] Create an R+-tree index for the spatial vector data; the R+-tree index is used to ensure that the minimum bounding rectangles of each vector space object do not overlap and cover all feature instances.

[0012] Based on the R+-tree index, embed the security policy into the nodes of the R+-tree index to obtain an AR+-tree index, that is, an augmented R+ (AR+) tree index.

[0013] Based on the AR+-tree index, generate multiple-level keys; the number of keys is related to the number of parent nodes of the AR+-tree index.

[0014] Use the multiple-level keys to perform hierarchical order-preserving encryption on the index plaintext data and map the index plaintext data to the ciphertext interval.

[0015] Parse the query statement to obtain the query rectangle and the user access permission.

[0016] Based on the AR+-tree index and the multiple-level keys, perform hierarchical order-preserving encryption on the query rectangle and take the intersection with the minimum bounding rectangle (MBR) of each layer of nodes to obtain the result of the intersection.

[0017] Based on the result of the intersection, verify the user access permission, filter out all data IDs (Identifications) that meet the conditions, that is, filter out all unique identifiers of the data that meet the conditions, and put them into the result set.

[0018] Based on the data IDs in the result set, determine the ciphertext of the original data (Encrypted Extended Well-Known Binary, EEWKB).

[0019] Decrypt the ciphertext of the original data using the encryption algorithm used for encrypting the original data to obtain the plaintext data.

[0020] In a second aspect, the present application provides a computer device, including: a memory, a processor, and a computer program stored on the memory and executable on the processor, where the processor executes the computer program to implement the above-mentioned method for constructing a ciphertext space index based on hierarchical order-preserving encryption.

[0021] In a third aspect, the present application provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the above-mentioned method for constructing a ciphertext space index based on hierarchical order-preserving encryption.

[0022] According to the specific embodiments provided by the present application, the following technical effects are disclosed in the present application.

[0023] The present application provides a method and apparatus for constructing a ciphertext space index based on hierarchical order-preserving encryption. By obtaining spatial vector data and creating an R+-tree index for the spatial vector data, it can effectively organize the spatial vector data, ensuring that the minimum bounding rectangles of each vector space object do not overlap and cover all feature instances. This enables quick positioning to potentially relevant data regions during subsequent query processes, improving the efficiency of spatial data retrieval, laying an efficient data organization foundation for subsequent encryption and query operations, and reducing the query time complexity and data processing complexity. By embedding a security policy into the nodes of the R+-tree index based on the R+-tree index to obtain an AR+-tree index, the close combination of the security mechanism and data index is realized, enabling automatic control and protection of data according to the security policy during data storage, retrieval, and access processes, enhancing data security. By generating multiple-level keys based on the AR+-tree index, the security requirements of data with different security levels can be met. By performing hierarchical order-preserving encryption on the index plaintext data using the multiple-level keys and mapping the index plaintext data to a ciphertext interval, both data confidentiality and the order characteristics of the data after encryption are retained. Operations such as comparison and query can be directly performed in the encrypted domain without prior decryption of the data, thereby improving query efficiency and avoiding the exposure risk of data in the plaintext state, enhancing data security and privacy. By parsing the query statement to obtain the query rectangle and user access rights, the geometric range (query rectangle) of the query and the user's access right information can be accurately extracted, providing a clear basis for subsequent screening of eligible data according to the security policy and encryption mechanism, ensuring that only authorized users can access spatial data within a specific range, realizing fine-grained access control, and further enhancing data security. By performing hierarchical order-preserving encryption on the query rectangle based on the AR+-tree index and the multiple-level keys and taking the intersection with the minimum bounding rectangle of each layer of nodes to obtain a result, unnecessary data decryption and query operations can be reduced, improving query efficiency and ensuring the security of the query process, avoiding decryption and exposure of a large amount of irrelevant data during the query process. By verifying the user access rights based on the result, screening out all eligible data IDs and putting them into a result set, and determining the original data ciphertext based on the data IDs in the result set, it can be ensured that only data IDs that conform to the security policy and user rights are put into the result set, and at the same time, decryption attempts on a large amount of irrelevant ciphertext data are avoided, improving the system efficiency.By decrypting the original data ciphertext using the encryption algorithm used for encrypting the original data, the plaintext data is obtained. This realizes providing a more convenient data usage experience for legitimate users while ensuring data security, enabling users to obtain the required plaintext of spatial vector data within the authorized scope, meeting the requirements for data availability in practical applications. At the same time, the entire encryption and decryption process is based on the previous multi-level keys and security policies, ensuring the security and reliability of the decryption process. This application combines the AR+ tree based on the SV_MAC (spatial vector data mandatory access control model) access control model and the hierarchical order-preserving encryption technology based on the hypergeometric distribution to solve the problem of storing data in plaintext in the database, constructs an AR+ tree index structure embedded with access policies, and introduces randomness during the encryption process to ensure the security of encryption as much as possible. This design can operate on data in ciphertext state using order-preserving property, hiding the original data from users. At the same time, the application of the index enables data range screening and permission verification to be carried out simultaneously, reducing the storage space overhead and improving the retrieval efficiency, realizing fine-grained mandatory access control and efficient encrypted query of spatial data. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required to be used in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0025] Figure 1 FIG. is a schematic diagram of the technical process for constructing and applying a ciphertext space index integrating order-preserving encryption and AR+ tree provided by an embodiment of the present application.

[0026] Figure 2 FIG. is a schematic diagram of the AR+ tree index division provided by an embodiment of the present application.

[0027] Figure 3 FIG. is a schematic diagram of the AR+ tree node information provided by an embodiment of the present application.

[0028] Figure 4 FIG. is an application environment diagram of a method for constructing a ciphertext space index based on hierarchical order-preserving encryption provided by an embodiment of the present application.

[0029] Figure 5 FIG. is a schematic diagram of the process of a method for constructing a ciphertext space index based on hierarchical order-preserving encryption provided by an embodiment of the present application.

[0030] Figure 6Schematic diagram of a computer device provided by an embodiment of the present application. Detailed implementation manners

[0031] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0032] To make the above objects, features, and advantages of the present application more obvious and understandable, the present application will be further described in detail below with reference to the accompanying drawings and specific implementation manners.

[0033] Spatial vector geographic data has characteristics such as high precision, easy storage, and lossless scaling. High-precision vector geographic data involves the precise geographical locations of sensitive areas and key targets, and reasonable and effective protection is required. The spatial database provides key support for the storage, query, analysis, and application of vector geographic data through a structured and efficient management method. Although the access control model of the spatial database restricts the access group to a certain extent, the plaintext data stored in the database still has the risk of leakage. In addition, the minimum protection granularity of the traditional spatial database is at the level of geographical entities, and it is impossible to distinguish and protect entity fragments of different security levels of the same entity.

[0034] Currently, some researchers have tried to use encryption technology to solve the problem of insecure plaintext storage. For example, the order-preserving encryption technology OPE (Order-Preserving Encryption, OPE) is used to encrypt the plaintext so that the ciphertext maintains the same numerical order as the plaintext, which is convenient for range query operations on data. However, order-preserving encryption requires mapping the plaintext data to a ciphertext interval with the same data format and corresponding size order, and there are applicability problems caused by format retention and order preservation. The traditional order-preserving encryption process uses a single key, and once the key is leaked, all data encrypted with this key will be in an insecure state.

[0035] Therefore, the present application proposes a ciphertext space index construction scheme based on order-preserving encryption and AR+ tree (Access R+ Tree). This scheme combines BCLO (an order-preserving encryption algorithm proposed by Boldyreva, Chenette, Lee, and O’Neill in 2009) order-preserving encryption with the SV_MAC access control model to achieve fine-grained mandatory access control and efficient encrypted query of spatial index data. The following introduces the technical process of constructing and applying the ciphertext space index by integrating order-preserving encryption and AR+ tree. (As Figure 1 shown).

[0036] Step 1: Create a regular R+ tree index for the spatial vector geographic data to ensure that the minimum bounding rectangles of each spatial vector object do not overlap and cover all feature instances.

[0037] Step 2: Based on the index partition in Step 1, comprehensively consider the data range of the R+ tree nodes and the coverage range of the security policy, decompose and embed the security policy into the nodes of the R+ tree to complete the construction of the AR+ tree.

[0038] Step 3: Based on the AR+ tree index structure created in Step 2, generate multi-level keys and perform hierarchical BCLO order-preserving encryption on the index plaintext data to satisfy the hierarchical division characteristics of the tree index structure, and map the index plaintext data to the ciphertext interval.

[0039] Step 4: Parse the SQL query statement to obtain the range of the query rectangle and the user access permission, which are used to match with the minimum bounding rectangle of the node and the set of security policies in Step 5.

[0040] Step 5: Based on the index structure generated in Step 2 and the multi-level keys generated in Step 3, perform hierarchical order-preserving encryption on the query rectangle and find the intersection with the minimum bounding rectangle of each layer of nodes to verify the user permission, filter out all eligible data IDs and put them into the result set; decrypt the original data EEWKB ciphertext corresponding to the ID and return the result to the user.

[0041] Furthermore, in Step 2, the embedding of the security policy specifically includes the following content.

[0042] The nodes of the R+ Tree record two parts of information: the minimum bounding rectangle of the node and the pointer to the child node or the leaf node data item. The AR+ tree is an extension of the R+ tree, which introduces access control information in the index node, facilitates subsequent query operations, can simultaneously implement data retrieval and permission verification, and improves query efficiency. In the construction process of the AR+ tree, a set of security policies (specific security policies are defined by the user himself) is added to each node. The root node receives all policies and stores them in the label_set of the root node. The intermediate nodes and leaf nodes generate their own policy sets by recursively decomposing the label_set set of the parent node. All policies will be stored in the parent node, and the child node performs an intersection operation according to its own minimum bounding rectangle range and the policy coverage range to obtain the security policy suitable for the current node. Take Figure 2Take the intermediate node R1 as an example. R1 contains three leaf nodes, namely R3, R4, and R5. Among them, the leaf nodes R4 and R5 are within the coverage of policy M2 and have a level of secret, while R3 is within the coverage of policy M1 and also has a level of secret. The difference is that policy M2 only contains the leaf nodes R4 and R5, and M2 is completely within the coverage of R1. Policy M1 contains not only the leaf node R3 but also the leaf node R6, and the coverage of M1 spans two child nodes. When decomposing the policy, it is necessary to take the intersection of policy M1 and the child node R1 to obtain the security policy of R1 itself. The index partitioning of the AR+ tree and the node information (including the policy decomposition example) are respectively as Figure 2 and Figure 3 shown. is the minimum bounding rectangle of the root node area. The root node contains two child nodes, R1 and R2, and three security regions cover all the data. The root node index stores the minimum bounding rectangle MBR of the node, the child node number, and the policy set label_set; the policy of the intermediate node is inherited from the parent node and needs to be decomposed according to the security label range covering the current area; the leaf node stores the identifier of the spatial element instance, the minimum bounding rectangle, and the associated policy number.

[0043] Furthermore, in step 3, the generation of multi-level keys specifically includes the following steps.

[0044] To improve the security of order-preserving encryption, the present application designs a multi-level key generation method by utilizing the hierarchical characteristics of the index tree. The so-called multi-level means that different keys will be generated according to the parent node, different keys are used at different levels, and different encryption keys are used for different parent nodes at the same level. In this way, even if one of the keys is cracked, the attacker cannot obtain all the plaintext data, and the data encrypted by other keys remains in a secure state. The key at the root node is generated randomly, and the keys of the child nodes are derived through the pseudo-random function PRF. The number of child node keys is the same as the number of parent nodes, and is specifically generated through the following formula.

[0045] (1).

[0046] Wherein, is the encryption key of the current node, is the pseudo-random function, is the parent node key, is the ID of the current node, is the policy set of the node.

[0047] The key at the root node Randomly generated, the key of the child node is derived from the key of the parent node. The keys generated at each level are recorded in the key table KeyMap, and the corresponding level of key can be retrieved from the key table for encrypting the range data of the query rectangle during subsequent query operations.

[0048] Furthermore, in step 3, the parameter passing mechanism specifically includes the following content.

[0049] When performing BCLO order-preserving encryption on each level of nodes, 4 input parameters are required: the key K, the plaintext interval of the parent node, the ciphertext interval of the parent node, and the data to be encrypted. Therefore, the corresponding parameters need to be passed to the data node to be encrypted. The key can be generated by formula (1), the ciphertext interval of the parent node is known data after encryption, and the plaintext interval of the parent node needs to be obtained through the reverse order-preserving encryption process, and the specific process is shown in formula (2).

[0050] (2).

[0051] Among them, is the plaintext interval of the intermediate node; is the ciphertext interval of the parent node; is the ciphertext interval of the intermediate node; is the order-preserving encryption algorithm based on the hypergeometric distribution.

[0052] Furthermore, in step 3, the hierarchical order-preserving encryption specifically includes the following content.

[0053] Order-preserving encryption can keep the ciphertext in the same numerical order as the plaintext. Although this feature facilitates querying data in the ciphertext state, it will expose the plaintext order. Since the ciphertext strictly retains the plaintext order, attackers can infer the plaintext information by analyzing the statistical characteristics of the ciphertext (such as numerical distribution, spacing pattern, etc.), which may cause the problem of information leakage. To solve this problem and improve the security of order-preserving encryption as much as possible, this application adopts the BCLO order-preserving encryption algorithm. The BCLO algorithm uses the pseudo-random function TapeGen to generate a pseudo-random bit stream, introducing randomness during the encryption process, so that attackers cannot infer the key or plaintext by observing the ciphertext pattern.

[0054] To dynamically adapt to the hierarchical division characteristics of the tree-shaped index structure, this application proposes a hierarchical order-preserving encryption HOPE (Hierarchical Order-Preserving Encryption) method based on the construction of an elastic order-preserving ciphertext mapping interval. The core idea is to maintain the same spatial partitioning logic as the plaintext index in the ciphertext space by recursively encrypting layer by layer, using the ciphertext range of the parent node as the input domain for encrypting the child node. The specific implementation steps of HOPE are as follows.

[0055] (1) Root node encryption: The root node represents the range of all data to be encrypted. Let its plaintext coordinate range be , and through the order-preserving encryption algorithm BCLO based on the hypergeometric distribution, the data can be mapped from the plaintext interval to the ciphertext interval. The mapping formula is as follows.

[0056] (3).

[0057] Among them, is the ciphertext space of the root node; is the key at the root node; is the plaintext space of the root node.

[0058] In the plaintext state, the minimum circumscribed rectangle area represented by each level of nodes is a subset of its upper-level parent node and the sibling nodes do not overlap with each other. To ensure that the ciphertext intervals at each level still maintain the same subordination relationship after encryption, the length of the ciphertext interval needs to satisfy , where is the expansion factor. In this embodiment, let .

[0059] (2) Child node dynamic recursive encryption: The encryption formula for child nodes is as follows.

[0060] (4).

[0061] Among them, is the ciphertext space of the child node; is the encryption key of the current node; is the plaintext interval of the current node.

[0062] The encryption key of the child node is generated according to formula (1). Based on the property that the order of the order-preserving encryption ciphertext is the same as that of the plaintext, after the child node is encrypted, it should satisfy the constraint . At the same time, to enhance security, the length of the child node ciphertext interval should satisfy , and resist frequency analysis attacks through the expansion factor .

[0063] (3) Leaf node hierarchical encryption: There are several intermediate nodes in front of the leaf node except the root node. Each level of intermediate nodes recursively executes the encryption operation in the previous step to generate the corresponding encryption key. Assume that the path from the root node to a certain leaf node is , and the corresponding key sequence is , then the calculation formula for the ciphertext at the leaf node is as follows.

[0064] (5).

[0065] Among them, is the ciphertext space of the leaf node; is the key at the leaf node; is the abscissa value of the coordinate to be encrypted; is the plaintext interval of the parent node, obtained by substituting into formula (2) is the ciphertext interval of the parent node.

[0066] (4) Verification of order-preserving property and consistency of ciphertext mapping intervals: To ensure that the data after encryption at each level conforms to the characteristics of order-preserving encryption, it is necessary to verify the constraint conditions level by level, ensuring that the numerical order of the plaintext interval is correctly mapped to the ciphertext interval. If a certain node violates this constraint condition after encryption, the dynamic re-encryption process is triggered to adjust the key or expansion factor until the condition is met.

[0067] Furthermore, in step 5, the query rectangle encryption specifically includes the following content.

[0068] Through the operations in steps 1 to 3, the construction of the AR+ tree and the order-preserving encryption of the plaintext have been completed, and the ciphertext state query of the encrypted data can be performed on this basis. To adapt to the AR+ tree construction method and order-preserving encryption method described above and achieve efficient and secure queries, this application specifically designs a set of range retrieval methods, mainly including layer-by-layer encryption of the query window and matching verification of security policies and user permissions. The query rectangle in the query conditions submitted by the user is a two-dimensional space range, and its range is set as . When executing the retrieval logic, the system needs to decompose it into independent coordinate intervals and on the x-axis and y-axis respectively for encryption. The specific operation process of the spatial retrieval is as follows.

[0069] (1) Root node processing: To cooperate with the hierarchical logic of the foregoing method, the range query also needs to be executed in the hierarchical order. First, verify whether the user has the permission to access the data in the data table. Check whether the policy_map of the root node contains the policy allowing access. If the user permission is insufficient, the query is directly terminated to avoid invalid execution of subsequent operations. Secondly, if there is data in the data table that the user has the right to access, obtain the root node encryption keys and from the key table KeyMap, and perform the reverse order-preserving mapping on the root node ciphertext space to obtain the plaintext space . Thirdly, find the intersection of the query rectangle and the plaintext MBR of the root node. If there is no intersection between the two, return an empty result; if there is an intersection, return the intersection result to , and let , obtain the overlapping area between the query rectangle and the root node MBR, and use it as the query window for the next level to continue the retrieval. Finally, obtain the encryption key of the child node corresponding to the root node from the KeyMap and . Pass the cropped query window, user permission label, root node ciphertext space , root node plaintext space , key and to the next level node.

[0070] (2)Recursive processing of child nodes: Assume that the current processing node is at the i th layer. First, encrypt the recursively cropped query rectangle, using the current layer key and , the ciphertext of the parent node MBR and plaintext passed in the previous level processing as inputs, encrypt the query window to obtain the corresponding ciphertext window , and compare the ciphertext window with the ciphertext MBR of the current node to filter out the set of intersecting child nodes . Then, traverse each node in the set to verify whether it contains the policy that allows access to this user permission label policy_map , retain the nodes with permission matching, and delete the nodes with insufficient access permissions from the set . Finally, traverse the set of filtered child nodes , obtain the keys corresponding to each child node from the KeyMap and , and crop the overlapping area between the query rectangle and the ciphertext MBR of this child node as the query window for the next level. For each element in the set , push the corresponding key, parent node plaintext space, and parent node ciphertext space onto the stack as function inputs, and repeat the operations of child node processing until the child node is a leaf node.

[0071] (3)Leaf node processing: Through the above query window comparison and cropping and permission verification, it can be determined that the leaf node meets the query conditions. Therefore, there is no need to perform window cropping and permission verification operations in the leaf node, and directly record the data ID corresponding to the qualified leaf node in the result set.

[0072] (4)Result decryption: Traverse the result set obtained in the previous step, find the corresponding original data ciphertext for each data ID, perform the encryption algorithm used in the original data encryption respectively to decrypt and obtain the plaintext data, and return the queried plaintext data to the user.

[0073] This application realizes fine-grained access control for the ciphertext state of database index fields by integrating AR+trees and hierarchical order-preserving encryption. Compared with existing methods, it has the following two advantages.

[0074] (1)It solves the risk of plaintext exposure when the database stores spatial vector data, allowing users to perform data query operations in the ciphertext state.

[0075] Spatial vector data is characterized by large data volume and complex structure and is often stored in a spatial database. In addition to storing vector data, the spatial database also supports indexing and query operations on vector data. Storing data in the database enables multi-person sharing of data, and spatial data can be queried in real time through the API (Application Programming Interface) without the need to perform data transmission operations for each user. To ensure the secure storage of vector data in the database, numerous access control models have been designed to restrict users' query permissions, departments, locations, query times, etc., strictly limiting the data content that different users can access and effectively guaranteeing the security during the storage process of vector data. However, the data stored in the database is the original data, and users can see the true face of the data, still posing a risk of data leakage.

[0076] To solve the problem of plaintext storage in the database, this application introduces order-preserving encryption technology. Order-preserving encryption is a special encryption technology whose core feature is that the encrypted ciphertext can maintain the same order relationship as the plaintext. For example, if the plaintext numbers satisfy a < b, then the encrypted ciphertext E(a) < E(b) still holds. This feature is achieved through specific mathematical algorithms, allowing range queries, sorting, etc. to be directly performed on the ciphertext without decryption, especially suitable for scenarios that require protecting data privacy but rely on order analysis (such as index queries in the database). This application combines AR+trees with order-preserving encryption, uses indexing to improve retrieval efficiency, and realizes fine-grained access to data through the AR+tree and SV_MAC mandatory access control model. By integrating spatial retrieval and permission verification into one, subtrees or data items that users have no right to access can be filtered in real time during the query process, avoiding the establishment of an R+tree for security policies, and improving both time and space efficiency. SV_MAC realizes fine-grained access control by splitting the geometric distribution of spatial objects into multiple sub-blocks and assigning independent security labels to each sub-block. This mechanism not only covers all vector data but also avoids redundant authorization determination through dynamic cropping technology, thus taking into account system performance while ensuring security.

[0077] (2)This application proposes a multi-level key generation method for the security requirements of order-preserving encryption and the tree-shaped index structure, making the encrypted data more secure.

[0078] The data is divided into multiple encryption units according to the index tree hierarchical structure and the belonging parent nodes. Each encryption unit needs to generate a dedicated encryption key during encryption, that is, each encryption key is only responsible for encrypting part of the data. The theft of a single key only exposes part of the data, avoiding the security risk of "total loss" in the traditional single-key system. An attacker needs to crack all keys simultaneously to obtain the complete information, which greatly increases the attack cost and ensures the overall security of the data.

[0079] Points on the plane are represented by a pair of coordinates. The spatial coordinates are jointly composed of the x coordinate value and the y coordinate value. During encryption, x and y are encrypted separately, and the x-axis key and the y-axis key are generated by different PRF branches to ensure the independence of the encryption processes in the two dimensions and avoid the risk of key cross-leakage.

[0080] The method for constructing a ciphertext space index based on hierarchical order-preserving encryption provided by the embodiments of the present application can be applied to, for example Figure 4In the application environment shown. Among them, the terminal 102 communicates with the server 104 through the network. The data storage system can store the data that the server 104 needs to process. The data storage system can be set separately, integrated on the server 104, or placed on the cloud or other servers. The terminal 102 can send the obtained spatial vector data to the server 104, and the spatial vector data includes several vector space objects; after receiving the spatial vector data, for the spatial vector data, the server 104 creates an R+-tree index for the spatial vector data; the R+-tree index is used to ensure that the minimum bounding rectangles of each vector space object do not overlap and cover all feature instances; based on the R+-tree index, a security policy is embedded into the nodes of the R+-tree index to obtain an AR+-tree index; based on the AR+-tree index, a multi-level key is generated; the number of keys is related to the number of parent nodes of the AR+-tree index; the multi-level key is used to perform hierarchical order-preserving encryption on the index plaintext data, and map the index plaintext data to the ciphertext interval; the query statement is parsed to obtain the query rectangle and the user access permission; based on the R+-tree index and the multi-level key, the query rectangle is subjected to hierarchical order-preserving encryption and the intersection is obtained with the minimum bounding rectangle of each layer of nodes to obtain the obtained result; based on the obtained result, the user access permission is verified, all eligible data IDs are filtered out and put into the result set; based on the data IDs in the result set, the original data ciphertext is determined; the encryption algorithm used when the original data is encrypted is respectively executed on the original data ciphertext to decrypt and obtain the plaintext data. The server 104 can feedback the obtained plaintext data to the terminal 102. In addition, in some embodiments, the method for constructing a ciphertext space index based on hierarchical order-preserving encryption can also be implemented independently by the server 104 or the terminal 102. For example, the terminal 102 can directly construct a ciphertext space index based on hierarchical order-preserving encryption for the spatial vector data, or the server 104 can obtain the spatial vector data from the data storage system and construct a ciphertext space index based on hierarchical order-preserving encryption for the spatial vector data.

[0081] Among them, the terminal 102 can be, but is not limited to, various desktop computers, laptop computers, smart phones and tablet computers. The server 104 can be implemented by an independent server or a server cluster composed of multiple servers, and can also be a cloud server.

[0082] In an exemplary embodiment, as Figure 5 shown, a method for constructing a ciphertext space index based on hierarchical order-preserving encryption is provided. This method is executed by a computer device, and can specifically be executed independently by a computer device such as a terminal or a server, or jointly executed by a terminal and a server. In the embodiments of the present application, this method is applied to Figure 4Taking server 104 in [description] as an example, it includes the following steps S1 to S10.

[0083] S1: Obtain spatial vector data; the spatial vector data includes a number of vector spatial objects.

[0084] S2: Create an R+-tree index for the spatial vector data; the R+-tree index is used to ensure that the minimum bounding rectangles of each vector spatial object do not overlap and cover all feature instances.

[0085] S3: Based on the R+-tree index, embed the security policy into the nodes of the R+-tree index to obtain an AR+-tree index.

[0086] S4: Generate multi-level keys based on the AR+-tree index; the number of keys is related to the number of parent nodes of the AR+-tree index.

[0087] S5: Perform hierarchical order-preserving encryption on the index plaintext data using the multi-level keys, and map the index plaintext data to the ciphertext interval.

[0088] S6: Parse the query statement to obtain the query rectangle and the user access rights.

[0089] S7: Perform hierarchical order-preserving encryption on the query rectangle based on the AR+-tree index and the multi-level keys, and find the intersection with the minimum bounding rectangle of each layer of nodes to obtain the result of the search.

[0090] S8: Based on the result of the search, verify the user access rights, filter out all eligible data IDs, and put them into the result set.

[0091] S9: Based on the data IDs in the result set, determine the original data ciphertext.

[0092] S10: Decrypt the original data ciphertext using the encryption algorithm used for original data encryption to obtain the plaintext data.

[0093] As an optional implementation, in step S3, based on the R+-tree index, embed the security policy into the nodes of the R+-tree index to obtain an AR+-tree index, which specifically includes the following content.

[0094] S31: Determine the node data range of the R+-tree index and the security policy coverage range.

[0095] S32: Decompose the security policy based on the security policy coverage range to obtain a number of security policies.

[0096] S33: Based on the node data range of the R+-tree index, embed the security policy into the nodes of the R+-tree index to obtain an AR+-tree index.

[0097] As an alternative implementation, in step S4, based on the AR+ tree index, a multi-level key is generated, which specifically includes the following content.

[0098] S41: Based on the AR+ tree index, a number of pseudo-random bitstreams are generated using a pseudo-random function.

[0099] S42: Based on the number of pseudo-random bitstreams, a multi-level key is generated.

[0100] As an alternative implementation, in step S5, the multi-level key is used to perform hierarchical order-preserving encryption on the index plaintext data, mapping the index plaintext data to a ciphertext interval, which specifically includes the following content.

[0101] S51: Based on the index plaintext data, the plaintext interval of the root node, the plaintext interval of the child nodes, and the plaintext interval of the leaf nodes are determined; the plaintext interval of the root node is directly defined by global parameters; the plaintext intervals of the child nodes and the leaf nodes are both intervals obtained by decrypting the ciphertext interval of the parent node; the ciphertext interval of the parent node is known data after encryption.

[0102] S52: Encrypt the root node using an order-preserving encryption algorithm based on the hypergeometric distribution, mapping the plaintext interval of the root node to a ciphertext interval.

[0103] S53: Use a dynamic recursive algorithm to encrypt the child nodes, mapping the plaintext intervals of the child nodes to ciphertext intervals.

[0104] S54: Based on the path from the root node to the leaf node, encrypt the leaf node, mapping the plaintext interval of the leaf node to a ciphertext interval.

[0105] The present application also provides an application scenario, which applies the above-mentioned method for constructing a ciphertext space index based on hierarchical order-preserving encryption. Specifically: The method for constructing a ciphertext space index based on hierarchical order-preserving encryption provided in this embodiment can be applied to the scenario of constructing a ciphertext space index. The scenario of constructing a ciphertext space index includes: an AR+ tree construction link, a hierarchical BCLO order-preserving encryption link, the range of a query rectangle, a user access permission link, and a matching link; First, create a conventional R+ tree index for the spatial vector geographic data to ensure that the minimum bounding rectangles of each spatial vector object do not overlap and cover all feature instances; Based on the index division, comprehensively consider the data range of the R+ tree nodes and the coverage range of the security policy, decompose and embed the security policy into the nodes of the R+ tree to complete the construction of the AR+ tree; Secondly, based on the created AR+ tree index structure, generate multiple-level keys and perform hierarchical BCLO order-preserving encryption on the index plaintext data to meet the hierarchical division characteristics of the tree-shaped index structure and realize mapping the index plaintext data to the ciphertext interval; Then, parse the SQL query statement to obtain the range of the query rectangle and the user access permission; Finally, based on the generated index structure and the generated multiple-level keys, perform hierarchical order-preserving encryption on the query rectangle and take the intersection with the minimum bounding rectangle of each layer of nodes to verify the user permission, filter out all eligible data IDs and put them into the result set; Perform a decryption operation on the original data ciphertext corresponding to the ID using the algorithm used during encryption and return the result to the user.

[0106] In an exemplary embodiment, a computer device is provided. The computer device can be a server or a terminal, and its internal structure diagram can be as Figure 6 shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store spatial vector data. The input / output interface of the computer device is used for the processor to exchange information with external devices. The communication interface of the computer device is used to communicate with external terminals through a network connection. When the computer program is executed by the processor, it implements a method for constructing a ciphertext space index based on hierarchical order-preserving encryption.

[0107] Those skilled in the art can understand that Figure 6The structure shown is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0108] In an exemplary embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the above method embodiments are implemented.

[0109] In an exemplary embodiment, a computer-readable storage medium is provided, storing a computer program, and when the computer program is executed by a processor, the above method embodiments are implemented.

[0110] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.

[0111] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memories can include read-only memory (ROM), magnetic tapes, floppy disks, flash memories, optical memories, high-density embedded non-volatile memories, resistive random access memories (ReRAM), magnetoresistive random access memories (MRAM), ferroelectric random access memories (FRAM), phase change memories (PCM), graphene memories, etc. Volatile memories can include random access memory (RAM) or external cache memories, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.

[0112] The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.

[0113] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0114] Specific examples are used in this article to elaborate on the principles and implementation manners of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application; at the same time, for those of ordinary skill in the art, according to the idea of the present application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present application.

Claims

1. A method for constructing a ciphertext space index based on hierarchical order-preserving encryption, characterized in that The method for constructing a ciphertext space index based on hierarchical order-preserving encryption includes: Obtain spatial vector data; the spatial vector data includes a number of vector space objects; Create an R+-tree index for the spatial vector data; the R+-tree index is used to ensure that the minimum bounding rectangles of each vector space object do not overlap and cover all feature instances; Based on the R+-tree index, embed a security policy into the nodes of the R+-tree index to obtain an AR+-tree index; Based on the AR+-tree index, generate multi-level keys; the number of keys is related to the number of parent nodes of the AR+-tree index; Use the multi-level keys to perform hierarchical order-preserving encryption on the index plaintext data and map the index plaintext data to a ciphertext interval; Parse the query statement to obtain a query rectangle and user access permissions; Perform hierarchical order-preserving encryption on the query rectangle based on the AR+-tree index and the multi-level keys, and find the intersection with the minimum bounding rectangle of each layer of nodes to obtain a result; Based on the result, verify the user access permissions, filter out all eligible data IDs, and put them into a result set; Based on the data IDs in the result set, determine the original data ciphertext; Decrypt the original data ciphertext using the encryption algorithm used during encryption to obtain plaintext data.

2. The method for constructing a ciphertext space index based on hierarchical order-preserving encryption according to claim 1, wherein Based on the R+-tree index, embed a security policy into the nodes of the R+-tree index to obtain an AR+-tree index, specifically including: Determine the node data range of the R+-tree index and the security policy coverage range; Decompose the security policy based on the security policy coverage range to obtain a number of security policies; Based on the node data range of the R+-tree index, embed the security policy into the nodes of the R+-tree index to obtain an AR+-tree index.

3. The method for constructing a ciphertext space index based on hierarchical order-preserving encryption according to claim 1, wherein Based on the AR+-tree index, generate multi-level keys, specifically including: Based on the AR+-tree index, use a pseudo-random function to generate a number of pseudo-random bitstreams; Based on the number of pseudo-random bitstreams, generate multi-level keys.

4. The method for constructing a ciphertext space index based on hierarchical order-preserving encryption according to claim 3, wherein The expression for generating the multi-level keys is: ; Among them, is the encryption key of the current node, is a pseudo-random function, is the key of the parent node, is the ID of the current node, is the set of policies of the node.

5. The method for constructing a ciphertext space index based on hierarchical order-preserving encryption according to claim 1, wherein Use the multi-level keys to perform hierarchical order-preserving encryption on the index plaintext data and map the index plaintext data to a ciphertext interval, specifically including: Based on the index plaintext data, determine the plaintext interval of the root node, the plaintext interval of the child nodes, and the plaintext interval of the leaf nodes; the plaintext interval of the root node is directly defined by global parameters; the plaintext intervals of the child nodes and the leaf nodes are both intervals obtained by decrypting the ciphertext interval of the parent node; the ciphertext interval of the parent node is known data after encryption; Encrypt the root node using the order-preserving encryption algorithm based on the hypergeometric distribution and map the plaintext interval of the root node to a ciphertext interval; Use a dynamic recursive algorithm to encrypt the child nodes and map the plaintext interval of the child nodes to a ciphertext interval; Based on the path from the root node to the leaf node, encrypt the leaf nodes and map the plaintext interval of the leaf nodes to a ciphertext interval.

6. The method for constructing a ciphertext space index based on hierarchical order-preserving encryption according to claim 5, wherein The formula for encrypting the root node using the order-preserving encryption algorithm based on the hypergeometric distribution and mapping the plaintext interval of the root node to a ciphertext interval is: ; Among them, is the ciphertext space of the root node; is the order-preserving encryption algorithm based on the hypergeometric distribution; is the key at the root node; is the plaintext space of the root node.

7. The method for constructing a ciphertext space index based on hierarchical order-preserving encryption according to claim 5, wherein The encryption formula for using a dynamic recursive algorithm to encrypt the child nodes is: ; Among them, is the ciphertext space of the child node; is the order-preserving encryption algorithm based on the hypergeometric distribution; is the encryption key of the current node; is the plaintext interval of the current node.

8. The method for constructing a ciphertext space index based on hierarchical order-preserving encryption according to claim 5, wherein The encryption formula for encrypting leaf nodes is as follows: ; Among them, is the ciphertext space of leaf nodes; is the order-preserving encryption algorithm based on the hypergeometric distribution; is the key at the leaf node; is the abscissa value of the coordinate to be encrypted; is the plaintext interval of the parent node; is the ciphertext interval of the parent node.

9. A computer device, comprising: A memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the processor executes the computer program to implement the method for constructing a ciphertext space index based on hierarchical order-preserving encryption according to any one of claims 1-8.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the method for constructing a ciphertext space index based on hierarchical order-preserving encryption according to any one of claims 1-8.

Citation Information

Patent Citations

  • Average-complexity ideal-security order-preserving encryption

    CN104657673A

  • Security semantic perception search method for dynamic spatial data in Internet of Vehicles

    CN113254743A

  • Vector data network transmission local encryption and decryption method based on multistage spatial index

    CN113901159A

  • Spatial database encryption method, equipment and medium

    CN119089479A

  • Order-preserving encryption method and apparatus

    US20240220648A1

Cited By

  • Data security processing method of smart campus management platform

    CN120611403A

  • Data security processing method of smart campus management platform

    CN120611403B