Symmetrical private information retrieval method, device, medium, program product and system

Through quantum state resource generation and collapse processing technology, the source generates quantum state resources for inadvertent key distribution, and collapses when detecting an intercept measurement attack, which solves the communication complexity and efficiency problems during retrieval of multiple databases in the prior art, and achieves efficient and secure information retrieval.

CN120429323APending Publication Date: 2025-08-05CHINA TELECOM CORP LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510152142.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-11
Publication Date
2025-08-05

AI Technical Summary

Technical Problem

When the source has multiple databases, existing symmetric private information retrieval methods require multiple inadvertent key distribution and post-processing methods, resulting in an increase in communication complexity between the source and the sink and a decrease in retrieval efficiency.

Method used

Using quantum state resource generation and collapse processing technology, the source generates quantum state resources for inadvertent key distribution, and performs collapse processing when an intercept measurement attack is detected. The sink retrieves information from multiple databases through one inadvertent key distribution and one post-processing method.

Benefits of technology

It reduces the communication complexity and retrieval cost between the source and the sink, and improves the security of data transmission, and realizes efficient information retrieval from multiple databases.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120429323A_ABST
    Figure CN120429323A_ABST
Patent Text Reader

Abstract

The invention provides a symmetric private information retrieval method and device, a medium, a program product and a system. According to the method, the limitation that the number D of databases of an information source is equal to 1 is broken through, and the retrieval frequency Q of an information sink is equal to D or 1lt; qlt; according to the method, information retrieval is realized under D, an inadvertent key distribution and post-processing method is not increased according to the number D of the databases and the retrieval times Q, that is, one inadvertent key distribution is matched with one post-processing method to help an information sink to complete Q times of information retrieval from the D databases, and collapse processing also improves the security in data transmission. Therefore, the problems that the communication complexity between the information source and the information sink is increased and the retrieval efficiency is influenced due to the careless key distribution of the symmetric private information retrieval method in the existing scheme are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of information retrieval. Specifically, it relates to a symmetric private information retrieval method, apparatus, medium, program product, and system. Background Art

[0002] SPIR (Symmetric Private Information Retrieval): It is a communication method that can protect the privacy of users from being obtained by the party holding the database and prevent the queried database from leaking data other than the information queried by the user.

[0003] The transfer of information at one time involves at least two parties. The party providing the information is called the information source, and the end point of information transfer is called the information sink. The information source and the information sink may not trust each other. The reason for the lack of trust is that the privacy of both parties may be leaked during the information transfer process. Symmetric private information retrieval is a communication mode where the information source (database holder) and the information sink (user) do not trust each other.

[0004] Existing symmetric private information retrieval methods limit the retrieval scenario of the information sink to the condition that the information source has only 1 database. If the information source has D (D > 1) databases and the information sink retrieves information from Q (1 < Q ≤ D) of them respectively, then oblivious key distribution will be executed Q times between the information source and the information sink, and the post-processing method will also be executed Q times. Q times of oblivious key distribution not only increases the communication complexity between the information source and the information sink, but also affects the retrieval efficiency, and is more likely to cause the information sink to pay a high retrieval cost.

[0005] That is, the oblivious key distribution of the existing symmetric private information retrieval method not only increases the communication complexity between the information source and the information sink, but also affects the retrieval efficiency. Summary of the Invention

[0006] The main purpose of the present application is to provide a symmetric private information retrieval method, apparatus, medium, program product, and system, so as to at least solve the problem that the oblivious key distribution of the existing symmetric private information retrieval method not only increases the communication complexity between the information source and the information sink, but also affects the retrieval efficiency.

[0007] To achieve the above object, according to one aspect of the present application, a symmetric private information retrieval method is provided. The method includes:

[0008] Oblivious key distribution step: The information source generates quantum state resources for retrieval;

[0009] [[ID=3

[0010] Collapse processing step: When an interception measurement attack is detected, the information source collapses the quantum state resource to obtain the processed quantum state resource, and the information source sends the processed quantum state resource to the information destination.

[0011] Optionally, during the step of inadvertent key distribution, the method further comprises:

[0012] The information source measures the particles received from the information sink using a measurement basis to obtain a first measurement result, where the measurement basis includes a Pauli basis, a Hadamard basis, and a Fourier basis;

[0013] The information source compares the first measurement result and the second detection result to check whether quantum entanglement exists, where the second detection result is the measurement result obtained by the information sink;

[0014] In the case of quantum entanglement, prompt information is generated to prompt that the particles are quantum entangled.

[0015] Optionally, in the case where an interception measurement attack is detected, collapsing the quantum state resource to obtain the processed quantum state resource includes:

[0016] The source is based on the first formula:

[0017]

[0018] determining the processed quantum state resource;

[0019] Among them, |W> X is the quantum state resource, and X, i and j are serial numbers respectively.

[0020] Optionally, the information source retrieves information from multiple databases based on the quantum state resource, including:

[0021] The source obtains a first position group and a second position group, where the first position group Na, Nb, Nc, ... is the information position retrieved by the sink in the searched Q station database Di, Dj, Dz, ..., and the second position group Ci, Cj, Cz, ... is the position of each 1-bit key inferred by Duke in the Q segment final key corresponding to Di, Dj, Dz, ...;

[0022] The source first shifts the Q segment key of the final key by Ci-Na, Cj-Nb, Cz-Nc, ... respectively, and then adds the shifted Q segment key to the information stored in the retrieved database Di, Dj, Dz, ... bit by bit to obtain the retrieval result, and sends the retrieval result to the destination.

[0023] Optionally, before obtaining the first position group and the second position group, the method further includes:

[0024] The initial key of the quantum state resource is added bit by bit using a preset rule to synthesize the final key, wherein the preset rule includes

[0025] Optionally, during the step of oblivious key distribution, the method further includes: the destination retrieves information from the D station database, where D includes 2, 3, 4, 5..., and the number of retrievals Q≤D, and Q includes 1, 2, 3..., only one oblivious key distribution is required.

[0026] According to another aspect of the present application, a symmetric private information retrieval device is provided, the device comprising:

[0027] The first processing unit is configured to perform an oblivious key distribution step: a source generates a quantum state resource for retrieval;

[0028] A second processing unit is configured to execute the post-processing method steps: a signal source retrieves information from multiple databases based on the quantum state resource to reduce communication complexity and retrieval cost;

[0029] The third processing unit is used to perform a collapse processing step: when an interception measurement attack is detected, the information source collapses the quantum state resource to obtain the processed quantum state resource, and the information source sends the processed quantum state resource to the information destination.

[0030] According to another aspect of the present application, a computer-readable storage medium is provided, wherein the computer-readable storage medium includes a stored program, wherein when the program is executed, the device where the computer-readable storage medium is located is controlled to execute any one of the methods described.

[0031] According to another aspect of the present application, a computer program product is provided, comprising a computer program, wherein when the computer program is executed by a processor, any one of the methods described above is implemented.

[0032] According to another aspect of the present application, a symmetric private information retrieval system is provided, which includes: one or more processors, a memory, and one or more programs, wherein the one or more programs are stored in the memory and are configured to be executed by the one or more processors, and the one or more programs include methods for executing any one of the methods described.

[0033] Applying the technical solution of the present application, the information is retrieved from multiple databases by the information source based on the quantum state resources, so as to reduce the communication complexity and retrieval cost. And in the case of detecting an intercept measurement attack, the information source collapses the quantum state resources to obtain the processed quantum state resources, and the information source sends the processed quantum state resources to the information sink. Thus, the limitation that the number of databases D owned by the information source is 1 is broken through, and the information sink can also satisfy the information retrieval when the number of retrieval times Q = D or 1 < Q < D. The oblivious key distribution and post-processing method will not increase according to the number of databases D and the number of retrieval times Q. That is, 1 oblivious key distribution and 1 post-processing method help the information sink to complete Q information retrievals from D databases. The collapse processing also improves the security in data transmission, and further solves the problem that the oblivious key distribution of the symmetric private information retrieval method in the existing solution not only increases the communication complexity between the information source and the information sink, but also affects the retrieval efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] The accompanying drawings forming a part of this application are used to provide a further understanding of this application. The schematic embodiments and descriptions thereof of this application are used to explain this application and do not constitute an improper limitation to this application. In the drawings:

[0035] Figure 1 It shows a schematic flow chart of a symmetric private information retrieval method provided by an embodiment of this application;

[0036] Figure 2 It shows that in the post-processing process of the information sink provided by an embodiment of this application, only with a probability of (1 / X) n the schematic diagram of inferring the final key;

[0037] Figure 3 It shows the curve schematic diagram of the probability of detecting an external measurement retransmission attack varying with the number of |W> X particles;

[0038] Figure 4 It shows a structural block diagram of a symmetric private information retrieval device provided by an embodiment of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0039] It should be noted that, without conflict, the embodiments in this application and the features in the embodiments can be combined with each other. The following will describe this application in detail with reference to the drawings and in combination with the embodiments.

[0040] To enable those skilled in the art to better understand the solution of this application, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts shall fall within the scope of protection of this application.

[0041] It should be noted that the terms "first", "second", etc. in the description and claims of this application and the above-mentioned accompanying drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances for the embodiments of this application described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily need to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0042] As introduced in the background art, existing symmetric private information retrieval methods all limit the retrieval scenario of the receiver to the condition that the sender has only 1 database. If the sender has D (D>1) databases and the receiver retrieves information from Q (1<Q≤D) of them respectively, then oblivious key distribution will be executed Q times between the sender and the receiver, and the post-processing method will also be executed Q times. The Q times of oblivious key distribution not only increase the communication complexity between the sender and the receiver, but also affect the retrieval efficiency, and are more likely to cause the receiver to pay a high retrieval cost. To solve the problem that the oblivious key distribution of the symmetric private information retrieval method in the existing solution not only increases the communication complexity between the sender and the receiver, but also affects the retrieval efficiency, the embodiments of this application provide a symmetric private information retrieval method, device, medium, program product and system.

[0043] The technical solutions in the embodiments of this invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this invention.

[0044] In this embodiment, a symmetric private information retrieval method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0045] Figure 1 is a schematic flowchart of a symmetric private information retrieval method provided according to an embodiment of this application. As Figure 1 As shown, the method includes the following steps:

[0046] Step S101, oblivious key distribution step: a source generates a quantum state resource for retrieval;

[0047] OKD (Oblivious Key Distribution): During the key distribution process between the user and the party holding the database, the user can only infer with a certain probability that the key is 0 or 1, while the party holding the database can know all the keys; PPM (Post Processing Methods): After the oblivious key distribution, it can dilute the key inferred by the user to nearly 1 bit; K r (Raw Key, initial key): the key shared between the user and the database owner after the random key distribution is completed; K f (Final Key): The key between the user and the database owner after the initial key is processed by the post-processing method.

[0048] In the process of the inadvertent key distribution step, the method further includes:

[0049] The information source measures the particles received from the information sink using a measurement basis to obtain a first measurement result, where the measurement basis includes a Pauli basis, a Hadamard basis, and a Fourier basis.

[0050] The Pauli basis is a set of bases used in quantum mechanics to describe spin systems. It consists of four basis vectors, one corresponding to each of the four possible spin states. The Hadamard basis is a commonly used basis in quantum computing. It is derived by applying a Hadamard gate to classical basis vectors and is used to perform superposition operations in quantum computing. The Fourier basis is a mathematical basis commonly used in signal processing and quantum computing. It is an orthogonal basis that can expand a signal or quantum state into a linear combination of Fourier bases.

[0051] The signal source compares the first measurement result and the second detection result to check whether quantum entanglement exists, where the second detection result is the measurement result obtained by the signal sink;

[0052] In the case of quantum entanglement, prompt information is generated to indicate that the particles are quantum entangled.

[0053] Specifically, in the presence of quantum entanglement, generating prompt information can help personnel better understand and utilize the properties of quantum entanglement. Quantum entanglement can enable applications beyond classical physics, such as quantum communication, quantum computing, and quantum key distribution. By leveraging quantum entanglement, quantum information processing tasks such as quantum teleportation, remote preparation of quantum entangled states, and ultra-dense quantum communication can be achieved, greatly improving the efficiency and security of information transmission and processing. Therefore, generating prompt information can help personnel better utilize the potential of quantum entanglement and promote the development and application of quantum technology.

[0054] Step S102, post-processing method step: the information source retrieves information from multiple databases based on the above quantum state resources to reduce communication complexity and retrieval cost;

[0055] The information source retrieves information from multiple databases based on the above quantum state resources, including:

[0056] The information source obtains the first position group and the second position group, wherein the first position group N a 、N b 、N c , ... is the destination in the searched Q station database D i 、D j 、D z , ... the information location retrieved, the second location group C i 、C j 、C z ,...is with D i 、D j 、D z ...the position of each 1-bit key inferred by Duke in the corresponding Q segment final key;

[0057] The source first shifts the Q segments of the final key by C i -N a 、C j -N b 、C z -N c , ... and then with the database being searched D i 、D j 、D z The information stored in , ... is added bit by bit to obtain the search result, and the search result is sent to the destination.

[0058] Specifically, before the sink retrieves the required information from the database sent by the source, an oblivious key distribution will be performed between the source and the sink to protect the privacy of the source and the sink in both directions during information retrieval. If the source's database capacity is N bits, then when the sink retrieves the i-th bit of information N from the source's N-bit database, iIn the process of oblivious key distribution, the probability of the sink obtaining a 1-bit shared key is limited to p∈(0,0.5], and the key bits of an oblivious key distribution are much larger than the database capacity of the sink. The excess key bits will be used to test the security of key distribution. The post-processing method is to act on the initial key K generated by oblivious key distribution. r Up, K r Divided into n lines of N-bit key segments K r1 , K r2 , K r3 ...、K rn , n is N pn OK, request N pn Satisfies close to 1, at this time the key bit inferred by the sink is also K r1 , K r2 , K r3 ...、K rn The final key K generated by bitwise addition f Diluted to nearly 1 bit. The destination key K f The 1-bit key inferred from the source will be the same as the i-th bit of information N that needs to be retrieved in the N-bit database of the source. i Encryption is performed, for example, the destination is in K f The j-th key is inferred to be 0, then K f The shift information ji will be sent to the source. The final key K f The source will shift it by ji bits (ji>0 left shift, ji<0 right shift) and add it to each bit of information in the database and then send it to the destination. The destination can use K f The j-th key obtained in the decryption is used to decrypt the i-th bit information N in the database i Therefore, symmetric private information retrieval or oblivious key distribution and post-processing methods have important significance for protecting the privacy of mutually untrusted information sources and destinations.

[0059] In one embodiment of the present application, before obtaining the first position group and the second position group, the method further includes: using a preset rule to perform a bitwise addition operation on the initial key of the quantum state resource to synthesize a final key, wherein the preset rule includes The final key is made more secure by synthesizing the final key multiple times using preset rules.

[0060] Step S103, collapse processing step: when an interception measurement attack is detected, the above-mentioned source collapses the above-mentioned quantum state resources to obtain the processed quantum state resources, and the above-mentioned source sends the processed quantum state resources to the destination.

[0061] In the above steps, the information source retrieves information from multiple databases based on the above quantum state resources to reduce the communication complexity and retrieval cost. And in the case of detecting an intercept measurement attack, the information source collapses the above quantum state resources to obtain the processed above quantum state resources, and the information source sends the processed above quantum state resources to the information sink, thus breaking through the limitation that the number of databases D = 1 possessed by the information source, and can also satisfy the information retrieval at the information sink when the retrieval times Q = D or 1 < Q < D. The oblivious key distribution and post-processing method will not increase according to the number of databases D and the retrieval times Q. That is, 1 oblivious key distribution and 1 post-processing method help the information sink to complete Q information retrievals from D databases. The collapse processing also improves the security in data transmission, and further solves the problem that the oblivious key distribution of the symmetric private information retrieval method in the existing solution not only increases the communication complexity between the information source and the information sink, but also affects the retrieval efficiency.

[0062] Among them, in the case of detecting an intercept measurement attack, collapsing the above quantum state resources to obtain the processed above quantum state resources includes:

[0063] The information source according to the first formula:

[0064]

[0065] determines the processed above quantum state resources;

[0066] Among them, |W> X is the above quantum state resource, and X, i, and j are serial numbers respectively.

[0067] In an embodiment of the present application, during the above oblivious key distribution step, the information sink retrieves information from D databases, where D includes 2, 3, 4, 5... and when the retrieval times Q ≤ D, and Q includes 1, 2, 3..., only one oblivious key distribution is required.

[0068] Specifically, the present application aims to expand the application scenario of symmetric private information retrieval from the information source having only one database to multiple databases by constructing a new oblivious key distribution method, and satisfy that 1 oblivious key distribution and 1 post-processing help the information sink to complete Q information retrievals from D databases.

[0069] In the new oblivious key distribution process, |W> carrying the key information X will be sent from the information sink Duke to the information source Bruce. When Bruce has D (D > 1) databases, the W quantum state |W> of X (X ≥ 3) particles X can enable Duke to have The probability of inferring X-1 bits of key information from the initial key Kr is 0, and the key information is 0 when measuring the base sequence Z1Z2Z3…Z X The W quantum state of particle X|W> X It has the following features:

[0070] X particles P1, P2, P3, ..., PX have the same probability 1 / X to be 1> after measurement in the measurement basis Z = {|0>, |1>}, |W> X In the measurement base sequence Z1Z2Z3…Z X The following measurement results are shown in Table 1.

[0071] Second formula:

[0072] Table 1

[0073]

[0074]

[0075] Bruce receives X-particles' |W> according to the newly constructed oblivious key distribution process as follows X The 2nd to Xth particles P2-P X Duke will judge that there is a 1 / X probability that Bruce will encode the particle P2-P according to the measurement result of the first particle P1 in the Z measurement basis. X The key information on is all 0.

[0076] (1) Duke will X The second particle to the Xth particle P2, P3, ..., P X Sent to the source: Bruce.

[0077] (2) Bruce transfers P2, P3, ..., P X Report to Duke. Duke and Bruce will discard the data corresponding to the particles that were not successfully received. X All particles in . For example, the sequence The second X-particle P X Bruce did not receive it, not only The particle P1 in will be discarded by Duke. The other particles P2, P3, ..., P received by Bruce X-1 It will also be discarded.

[0078] (3) In order to prevent the key leakage caused by the inadvertent key distribution between Bruce and Duke, Bruce can Some of the information received X Particles P2, P3, ..., P X Using the measurement basis sequence Z2Z3…Z X If the eavesdropper Eve passes P2, P3, ..., P to Bruce at Duke X When using interception measurement attack, |W> X will collapse directly into |100…0> X 、|010…0> X 、|001…0> X , ..., or |000…1> X , while |W> X In the measurement base sequence Z1…Z i- 1X i Z i+1 …Z j-1 X j Z j+1 …Z X (The measurement basis sequence contains only two X measurement bases and the rest are Z measurement bases) The following is expressed as follows, that is, the particles P1, ..., P measured by the measurement basis Z i-1 、P i+1 ,...,P j-1 、P j+1 ,...,P X When the measurement results are all |0>, the measurement particle P corresponding to the measurement basis X i 、P j All are |+> or all are |->.

[0079] As shown in the first formula, it collapses to |100…0> X 、|010…0> X 、|001…0> X 、...、|000…1> X |W> X In the measurement base sequence Z1…Z i-1 X i Z i+1 …Z j-1 X j Z j+1 …Z X The following expression is as shown in the third formula, that is, the particles P1, ..., P measured by the measurement base Z i-1 、P i+1 ,...,P j-1 、P j+1 ,...,P XWhen the measurement results are all |0>, the particles Pi and Pj corresponding to the measurement basis X may not all be |+> or |->. Eve intercepts and measures the particles P2, P3, ..., P sent by Duke to Bruce. X Then send it to Bruce with a probability of 1-(1 / X) that it can be detected.

[0080] The third formula

[0081] (4) Duke and Bruce both use the Z measurement basis for all particles P1, P2, P3, ..., P X Measurement, Bruce will be the initial key K r The 0 and 1 information in the image are respectively loaded on P2, P3, ..., P whose measurement results are |0> and |1> X Duke inferred that |W> based on the measurement result of P1 with a probability of 1 / X X P2, P3, ..., P X The initial key information is all 0, that is, the measurement result of P1 is |1>, P2, P3, ..., P X The measurement result is |0>.

[0082] (5) Corresponding to each database K being searched r It is divided into Q segments with n rows by Bruce, where n must satisfy N(1 / X) n ≈1, each line is N bits long and follows The final key K is synthesized by bitwise addition operation f , N is the capacity of each database. The database to be searched D i 、D j 、D z ,...(2≤i<j<z≤Q) corresponds to K f The N-bit key of the i, j, z, ... segment, Duke can f Infer a 1-bit 0 or 1 key.

[0083] N a 、N b 、N c , ... is Duke in the searched Q station database D i 、D j 、D z , the location of the information retrieved in ..., C i 、C j 、C z ,...is with D i 、D j 、D z , ...corresponding Q segment Kf The position of each 1-bit key inferred by Duke in the final key. Bruce K f The Q segment keys are shifted by C i -N a 、C j -N b 、C z -N c , ... and then with the database being searched D i 、D j 、D z The information stored in ,... is added bit by bit and sent to Duke, who will use the key inferred in (5) to complete the information retrieval.

[0084] In order to enable those skilled in the art to more clearly understand the technical solution of the present application, the implementation process of the symmetric private information retrieval method of the present application will be described in detail below with reference to specific embodiments.

[0085] This embodiment relates to a specific symmetric private information retrieval method. The oblivious key distribution scheme is applicable to the case where the source Bruce has D databases with N bits of capacity. The sink Duke initiates information retrieval on Q of the databases. Q*N bits of data will be retrieved through |W> X The key information carried by the quantum state is encrypted, and then combined with the post-processing method, Duke completes the information retrieval from the Q station database. 12 When , the method completes the two data retrievals of the third and seventh databases D3 and D7 through one oblivious key distribution and one post-processing method as follows:

[0086] Oblivious Key Distribution:

[0087] sequence The last particles P2 and P3 of each |W>3 are sent by Duke to Bruce, and Duke retains particle P1.

[0088] If transmission loss occurs on P2 or P3, all particles with |W>3 corresponding to the lost P2 or P3 will be discarded by Duke and Bruce.

[0089] In order to prevent key leakage during the inadvertent key distribution between Bruce and Duke, The randomly selected detection particles P1, P2, and P3 can detect the interception measurement retransmission attack with a probability of 67%.

[0090] Duke and Bruce both use the Z measurement basis for all particles P1, P2, P3, ..., P XMeasurement, Duke has a 1 / 3 probability of inferring the initial key K based on the measurement result of P1 r The initial key information is 0.

[0091] Post-processing method: K r Divided by Bruce into 2 sections with 25 lines, each line is 5*10 12 Bit length and according to The final key K is synthesized by bitwise addition operation f If the final key K in the corresponding encrypted databases D3 and D7 f The 1-bit keys deduced by Duke are the 52nd and 14th bits respectively. Duke will split the two K f Shifting 52-822 and 14-5 bits respectively, 822 and 5 are the information positions that Alcie retrieves in D3 and D7.

[0092] Search: Bruce will be two K f After shifting right by 770 bits and left by 9 bits respectively, the information stored in the retrieved databases D3 and D7 will be added bit by bit and sent to Duke, who uses the 52nd and 14th bits of the key to complete the decryption.

[0093] It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and that, although a logical order is shown in the flowcharts, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0094] When the number of searches Q is expanded to the same as the total number of databases, that is, Q=D=10, the invention realizes one inadvertent key distribution and one post-processing to complete the first to tenth databases D1, D2, D3, ..., D 10 10 data retrievals, the specific implementation examples are as follows:

[0095] The steps of inadvertent key distribution are similar and will not be described in detail here.

[0096] The post-processing method is to use the final key K in the first to tenth segments. f Duke deduced that if the 1-bit key is the 32nd, 563rd, 764th, ..., 2070th bit, then Duke will K f The first to tenth segments of the final key are shifted by 32-5477, 563-2, 764-6533, ..., 2070-461 bits respectively, 5477, 2, 6533, ..., 461 are Duke's 10 The location of the information retrieved from .

[0097] Query reference Q = 2 when the retrieval step, Bruce will K f The first to tenth segments of the key are shifted right by 5445 bits, left by 561 bits, right by 5769 bits, ..., left by 1609 bits, and then compared with the searched databases D1-D 10 The information stored in is added bit by bit and sent to Duke, who decrypts it using the 32nd, 563rd, 764th, ..., 2070th bit keys.

[0098] The method of this application has the following beneficial effects compared with conventional solutions:

[0099] Compared with the repeated oblivious key distribution and post-processing methods on multiple databases, the proposed oblivious key distribution process flexibly selects the quantum state of multi-particle W|W> X Carrying key 0 and 1 information from the sink Duke to the source Bruce can not only limit the number of inadvertent key distributions to 1 when the number of databases searched increases, but also limit the post-processing method to 1, and also increase the probability of detecting risks in the inadvertent key distribution process to close to 1.

[0100] Compared with the conventional information retrieval method that is only applicable to the case where the source has only one database, the oblivious key distribution method of this application is not only applicable to information retrieval when the number of databases at the destination is one, but also when the number of databases at the destination is D (D>1), the range of databases to be searched can be expanded from 1 to [2, D]. 12 When the number of databases D increases from 2 to 14, and the number of databases to be searched increases from 1 to 14, by flexibly selecting |W> X , 1 oblivious key distribution combined with 1 post-processing method makes N(1 / X) n ≈1 can meet the demand for expansion of the number of information destination retrieval databases. The process of selecting parameters for the inadvertent key distribution and post-processing method is shown in Table 2.

[0101] Table 2

[0102]

[0103]

[0104] Compared with the conventional information retrieval method applicable to the information source with only one database, the multi-particle W quantum state |W> X Carrying the key 0 and 1 information can still make the distribution of 0 and 1 in the final key generated by the post-processing method random, because the number of 0 key bits in each key segment of the Q-segmented final key is approximately N(1 / X) n See Figure 1, the key bits that are not guessed in the initial key are marked by the destination as the symbol "?". X The smaller the number of particles X is, the more random the distribution of 0 and 1 in the final key is.

[0105] Compared with the conventional information retrieval method applicable to the information source with only one database, the oblivious key distribution method created by this invention is more efficient in carrying 0 and 1 key information. X When the number of particles X in the quantum state increases, we can X In the measurement base sequence Z1…Z i-1 X i Z i+1 …Z j-1 X j Z j+1 …Z X The measurement characteristics under this condition make the probability of detection of the risk of inadvertent key distribution process flexibly close to Figure 2 The trend in the final close to 100%, that is In conventional oblivious key distribution, |0>, |1>, |+>, |-> are used as detection particles, which can only limit the probability of risk in the oblivious key distribution process to a fixed value of 25%.

[0106] The sink only has (1 / X) n The final key can be inferred probabilistically as Figure 2 As shown, the probability of detecting an external measurement retransmission attack varies with |W> X The particle number change process is as follows Figure 3 As shown, no further details will be given here.

[0107] The embodiments of the present application also provide a symmetric private information retrieval device. It should be noted that the symmetric private information retrieval device of the embodiments of the present application can be used to execute the symmetric private information retrieval method provided by the embodiments of the present application. The device is used to implement the above-mentioned embodiments and preferred implementation methods, and the details that have been explained will not be repeated here. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation by hardware, or a combination of software and hardware, is also possible and conceivable.

[0108] The following introduces the symmetric private information retrieval device provided in the embodiment of the present application.

[0109] Figure 4 This is a structural block diagram of a symmetric private information retrieval device provided according to an embodiment of the present application. Figure 4 As shown, the device includes:

[0110] The first processing unit 41 is used to execute the oblivious key distribution step: the source generates quantum state resources for retrieval;

[0111] The second processing unit 42 is used to execute the post - processing method step: the source retrieves information from multiple databases based on the above - mentioned quantum state resources to reduce communication complexity and retrieval cost;

[0112] The third processing unit 43 is used to execute the collapse processing step: in the case of detecting an intercept measurement attack, the above - mentioned source collapses the above - mentioned quantum state resources to obtain the processed above - mentioned quantum state resources, and the above - mentioned source sends the processed above - mentioned quantum state resources to the destination.

[0113] In the above device, the source retrieves information from multiple databases based on the above - mentioned quantum state resources to reduce communication complexity and retrieval cost, and in the case of detecting an intercept measurement attack, the above - mentioned source collapses the above - mentioned quantum state resources to obtain the processed above - mentioned quantum state resources, and the above - mentioned source sends the processed above - mentioned quantum state resources to the destination. Thus, it breaks through the limitation that the number of databases D = 1 possessed by the source, and can also satisfy the destination to achieve information retrieval when the number of retrieval times Q = D or 1 < Q < D. The oblivious key distribution and the post - processing method do not increase according to the number of databases D and the number of retrieval times Q. That is, 1 oblivious key distribution配合1次后处理方法帮助信宿完成从D台数据库中实现Q次信息检索,坍缩处理也提高了数据传输中的安全性,进而解决了现有方案的对称私有信息检索方法的不经意密钥分发不仅增加了信源与信宿之间的通信复杂度,也会影响检索效率的问题。

[0114] In an embodiment of the present application, the first processing unit includes a first processing module, a second processing module, and a generation module. The first processing module is used to measure the particles received from the destination using a measurement basis during the oblivious key distribution step to obtain a first measurement result. The above - mentioned measurement basis includes the Pauli basis, the Hadamard basis, and the Fourier basis. The second processing module is used to compare the above - mentioned first measurement result with a second detection result to check for the existence of quantum entanglement. The above - mentioned second detection result is the measurement result obtained by the destination. The generation module is used to generate a prompt message to prompt the existence of quantum entanglement in the case of the existence of quantum entanglement.

[0115] In an embodiment of the present application, the third processing unit includes a determination module; the determination module is used to determine the processed above - mentioned quantum state resources according to the first formula:

[0116]

[0117] Determine the processed above - mentioned quantum state resources; where, |W> X It should be noted that there seems to be an incomplete or incorrect expression in the translation of . It should be "That is, 1 oblivious key distribution is combined with 1 post - processing method to help the destination complete Q - time information retrieval from D databases. The collapse processing also improves the security in data transmission, thus solving the problem that the oblivious key distribution in the symmetric private information retrieval method of the existing solution not only increases the communication complexity between the source and the destination but also affects the retrieval efficiency."is the above quantum state resource, X, i and j are serial numbers respectively.

[0118] In one embodiment of the present application, the second processing unit includes a third processing module and a fourth processing module, the third processing module is used to obtain a first position group and a second position group, wherein the above-mentioned first position group Na, Nb, Nc,... is the information position retrieved by the destination in the retrieved Q station database Di, Dj, Dz,..., and the above-mentioned second position group Ci, Cj, Cz,... is the position of each 1-bit key inferred by Duke in the Q segment final key corresponding to Di, Dj, Dz,...; the fourth processing module is used to first shift the Q segment key of the above-mentioned final key by Ci-Na, Cj-Nb, Cz-Nc,... respectively, and then add it bit by bit with the information stored in the retrieved database Di, Dj, Dz,... to obtain the retrieval result, and send the above-mentioned retrieval result to the destination.

[0119] In one embodiment of the present application, the apparatus further includes a fourth processing unit configured to, before obtaining the first position group and the second position group, perform a bitwise addition operation on the initial key of the quantum state resource using a preset rule to synthesize a final key, wherein the preset rule includes

[0120] In one embodiment of the present application, during the above-mentioned oblivious key distribution step, the destination retrieves information from the D station database, where D includes 2, 3, 4, 5..., and the number of retrievals Q≤D, and Q includes 1, 2, 3..., only one oblivious key distribution is required.

[0121] The symmetric private information retrieval device includes a processor and a memory. The first, second, and third processing units are stored in the memory as program units, and the processor executes the program units stored in the memory to implement corresponding functions. The modules are all located in the same processor; alternatively, the modules can be located in different processors in any combination.

[0122] The processor includes a kernel, which retrieves the corresponding program unit from memory. One or more kernels can be configured, and kernel parameters can be adjusted to address the problem of inadvertent key distribution in existing symmetric private information retrieval methods, which not only increases the communication complexity between the source and the destination but also affects retrieval efficiency.

[0123] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.

[0124] An embodiment of the present invention provides a computer-readable storage medium, which includes a stored program. When the program is executed, the device where the computer-readable storage medium is located is controlled to execute the symmetric private information retrieval method.

[0125] An embodiment of the present invention provides a processor, which is used to run a program, wherein the program executes the symmetric private information retrieval method when running.

[0126] An embodiment of the present invention provides a device comprising a processor, a memory, and a program stored in the memory and executable on the processor. When the processor executes the program, the following steps are implemented: an oblivious key distribution step in which a source generates a quantum state resource for retrieval; a post-processing method step in which the source retrieves information from multiple databases based on the quantum state resource to reduce communication complexity and retrieval costs; and a collapse processing step in which, upon detecting an interception measurement attack, the source collapses the quantum state resource to obtain the processed quantum state resource, and the source sends the processed quantum state resource to a destination. The device herein may be a server, a PC, a PAD, a mobile phone, or the like.

[0127] The present application also provides a computer program product, which, when executed on a data processing device, is suitable for executing a program initialized with at least the following method steps: an oblivious key distribution step: a source generates quantum state resources for retrieval; a post-processing method step: the source retrieves information from multiple databases based on the above-mentioned quantum state resources to reduce communication complexity and retrieval costs; a collapse processing step: in the event of an interception measurement attack being detected, the above-mentioned source collapses the above-mentioned quantum state resources to obtain the processed quantum state resources, and the above-mentioned source sends the processed quantum state resources to the destination.

[0128] The present application also provides a symmetric private information retrieval system, which includes: one or more processors, a memory, and one or more programs. Among them, the above one or more programs are stored in the above memory and are configured to be executed by the above one or more processors. The above one or more programs include those for executing any of the above methods. The information source retrieves information from multiple databases based on the above quantum state resources to reduce communication complexity and retrieval costs. And in the case of detecting an intercept measurement attack, the above information source collapses the above quantum state resources to obtain the processed above quantum state resources, and the above information source sends the processed above quantum state resources to the information sink, thereby breaking through the limitation that the number of databases D owned by the information source is 1, and it can also satisfy the information retrieval of the information sink when the number of retrieval times Q = D or 1 < Q < D. The oblivious key distribution and post-processing method will not increase according to the number of databases D and the number of retrieval times Q. That is, 1 oblivious key distribution配合1次后处理方法 helps the information sink to complete Q times of information retrieval from D databases. The collapse processing also improves the security in data transmission, thereby solving the problem that the oblivious key distribution of the symmetric private information retrieval method in the existing solution not only increases the communication complexity between the information source and the information sink, but also affects the retrieval efficiency.

[0129] Obviously, those skilled in the art should understand that the above modules or steps of the present invention can be implemented by a general-purpose computing device. They can be concentrated on a single computing device or distributed on a network composed of multiple computing devices. They can be implemented by program codes executable by the computing device. Thus, they can be stored in a storage device and executed by the computing device. And in some cases, the steps shown or described can be executed in a different order from here, or they can be separately made into individual integrated circuit modules, or multiple modules or steps among them can be made into a single integrated circuit module to implement. In this way, the present invention is not limited to any specific combination of hardware and software.

[0130] Those skilled in the art should understand that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.

[0131] It should be noted that there is an unclear expression "配合1次后处理方法" in the translation of , which needs to be further clarified in the original text for a more accurate translation.The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0132] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0133] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps for the function specified in one or more boxes.

[0134] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.

[0135] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.

[0136] A computer-readable medium includes permanent and non-permanent, removable and non-removable media, and information storage can be achieved by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information accessible by a computing device. As defined herein, a computer-readable medium does not include transitory computer-readable media, such as modulated data signals and carrier waves.

[0137] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, commodity or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the existence of additional identical elements in the process, method, commodity or device comprising the element.

[0138] From the above description, it can be seen that the above embodiments of the present application achieve the following technical effects:

[0139] 1) The symmetric private information retrieval method of the present application retrieves information from multiple databases by the information source based on the above quantum state resources, so as to reduce the communication complexity and retrieval cost. And in the case of detecting an intercept measurement attack, the above information source collapses the above quantum state resources to obtain the processed above quantum state resources, and the above information source sends the processed above quantum state resources to the information sink, thus breaking through the limitation that the number of databases D = 1 possessed by the information source, and can also satisfy the information retrieval of the information sink when the retrieval times Q = D or 1 < Q < D. The oblivious key distribution and post-processing method will not increase according to the number of databases D and the retrieval times Q, that is, 1 oblivious key distribution cooperates with 1 post-processing method to help the information sink complete Q information retrievals from D databases. The collapse processing also improves the security in data transmission, thereby solving the problem that the oblivious key distribution of the symmetric private information retrieval method in the existing scheme not only increases the communication complexity between the information source and the information sink, but also affects the retrieval efficiency.

[0140] 2) The symmetric private information retrieval device of the present application retrieves information from multiple databases by the information source based on the above quantum state resources, so as to reduce the communication complexity and retrieval cost. And in the case of detecting an intercept measurement attack, the information source collapses the above quantum state resources to obtain the processed above quantum state resources, and the information source sends the processed above quantum state resources to the information sink, thereby breaking through the limitation that the number of databases D owned by the information source is 1, and can also satisfy the information retrieval of the information sink when the retrieval times Q = D or 1 < Q < D. The oblivious key distribution and post-processing method will not increase according to the number of databases D and the retrieval times Q, that is, 1 oblivious key distribution and 1 post-processing method help the information sink to complete Q information retrievals from D databases. The collapse processing also improves the security in data transmission, thus solving the problem that the oblivious key distribution of the symmetric private information retrieval method in the existing solution not only increases the communication complexity between the information source and the information sink, but also affects the retrieval efficiency.

[0141] The above are only the preferred embodiments of the present application and are not used to limit the present application. For those skilled in the art, the present application can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A symmetric private information retrieval method, characterized in that: include: Oblivious key distribution steps: the source generates quantum state resources for retrieval; Post-processing method steps: the information source retrieves information from multiple databases based on the quantum state resource to reduce communication complexity and retrieval cost; Collapse processing step: When an interception measurement attack is detected, the information source collapses the quantum state resource to obtain the processed quantum state resource, and the information source sends the processed quantum state resource to the information destination.

2. The method according to claim 1, characterized in that During the oblivious key distribution step, the method further comprises: The information source measures the particles received from the information sink using a measurement basis to obtain a first measurement result, where the measurement basis includes a Pauli basis, a Hadamard basis, and a Fourier basis; The information source compares the first measurement result and the second detection result to check whether quantum entanglement exists, where the second detection result is the measurement result obtained by the information sink; In the case of quantum entanglement, prompt information is generated to prompt that the particles are quantum entangled.

3. The method according to claim 1, characterized in that In the case where an interception measurement attack is detected, the quantum state resource is collapsed to obtain the processed quantum state resource, including: The source is based on the first formula: determining the processed quantum state resource; Among them, |W> X is the quantum state resource, and X, i and j are serial numbers respectively.

4. The method according to claim 3, characterized in that The information source retrieves information from multiple databases based on the quantum state resource, including: The information source obtains a first position group and a second position group, wherein the first position group N a 、N b 、N c , ... is the destination in the searched Q station database D i 、D j 、D z , ... the information location retrieved, the second location group C i 、C j 、C z ,...is with D i 、D j 、D z ...the position of each 1-bit key inferred by Duke in the corresponding Q segment final key; The source first shifts the Q segments of the final key by C i -N a 、C j -N b 、C z -N c , ... and then with the database being searched D i 、D j 、D z The information stored in , ... is added bit by bit to obtain a search result, and the search result is sent to the destination.

5. The method according to claim 4, characterized in that Before acquiring the first position group and the second position group, the method further includes: The initial key of the quantum state resource is added bit by bit using a preset rule to synthesize the final key, wherein the preset rule includes 6. The method according to any one of claims 1 to 5, characterized in that During the oblivious key distribution step, the method further comprises: The sink retrieves information from the database of D stations, where D includes 2, 3, 4, 5..., and the number of retrievals Q≤D, where Q includes 1, 2, 3..., only one oblivious key distribution is required.

7. A symmetric private information retrieval device, characterized in that: include: The first processing unit is configured to perform an oblivious key distribution step: a source generates a quantum state resource for retrieval; A second processing unit is configured to execute the post-processing method steps: a signal source retrieves information from multiple databases based on the quantum state resource to reduce communication complexity and retrieval cost; The third processing unit is used to perform a collapse processing step: when an interception measurement attack is detected, the information source collapses the quantum state resource to obtain the processed quantum state resource, and the information source sends the processed quantum state resource to the information destination.

8. A computer-readable storage medium, characterized in that The computer-readable storage medium includes a stored program, wherein when the program is executed, the device where the computer-readable storage medium is located is controlled to execute the method according to any one of claims 1 to 6.

9. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.

10. A symmetric private information retrieval system, characterized in that: include: One or more processors, a memory, and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs include instructions for executing the method of any one of claims 1 to 6.

Citation Information

Cited By

  • A method, device and system for verifiable private information retrieval with minimal storage

    CN122660849A