Encrypted spatial data query method and device, storage medium and computer equipment
Spatial data is encrypted through the R-tree structure and homomorphic encryption algorithm. Combined with Bloom filter and prefix 0-1 encoding, fast rectangle intersection judgment and efficient range membership determination technology are designed to solve the problems of access mode exposure and high overhead, and realize safe and efficient single-server spatial data query.
Patent Information
- Application Number
- CN202510513265.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-23
- Publication Date
- 2025-09-05
AI Technical Summary
While existing encryption mechanisms protect the security of spatial data content, the exposure of access patterns still poses potential security risks. In addition, existing solutions have high computing and communication overhead in real-time query scenarios, and their reliance on a dual-server model makes deployment complex.
The R-tree structure and homomorphic encryption algorithm are used to encrypt spatial data. Combined with Bloom filter and prefix 0-1 encoding, fast rectangle intersection judgment and efficient range membership judgment technology are designed to achieve access mode hiding through a single server.
While ensuring data confidentiality, it achieves efficient spatial data query, avoids the communication overhead and deployment complexity of the dual-server model, and realizes secure and efficient single-server access mode hiding.
Smart Images

Figure CN120597290A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security technology, and in particular to an encrypted space data query method and device, a storage medium, and a computer device. Background Art
[0002] With the rapid development of mobile internet, location-based services (LBS) have become widely popular. Spatial data query capabilities have become an indispensable core technology in practical applications. For example, platforms such as ArcGIS and Google Maps, with their powerful spatial data query capabilities, provide users with precise geographic information services, greatly improving the user experience. With growing concerns about privacy protection, achieving efficient querying on encrypted spatial data has become a key research topic.
[0003] Existing encryption mechanisms can effectively protect the content security of spatial data, but the exposure of access patterns may still pose potential security risks. Access patterns refer to the access behavior of data during the query process, including which data items are accessed, the frequency of access, and the order of access. As mentioned above, attackers can use inference attacks and other methods to extract sensitive information from leaked access patterns. To address this problem, researchers have proposed a series of solutions based on ORAM and PIR to further reduce the risk of access pattern leakage, but their high computational and communication overheads limit their application in real-time query scenarios. Based on this situation, existing studies have also explored relatively lightweight access pattern hiding schemes, but most schemes rely on a dual-server model to implement the access pattern hiding function, which will bring additional deployment costs and communication overhead. Therefore, there is an urgent need for an encrypted spatial data query method with relatively low computational and communication overheads and the ability to hide access patterns. Summary of the Invention
[0004] In view of this, the present invention provides an encrypted spatial data query method and device, a storage medium, and a computer device, which can achieve access mode hiding under a single server while ensuring the confidentiality of spatial data and the efficiency of query.
[0005] According to one aspect of the present invention, a method for querying encrypted spatial data is provided, comprising:
[0006] Storing encrypted R-tree structure data and index structure of spatial data of at least one data owner, wherein the encrypted R-tree structure data is obtained by the data owner encrypting the spatial data based on the R-tree index structure and the homomorphic encryption algorithm;
[0007] Receive a query token from a user, where the query token includes a first token portion and a second token portion determined based on a query scope;
[0008] A range query operation is performed based on the query token to obtain a target encrypted result set from the encrypted R-tree structure data and the index structure; and the target encrypted result set is returned to the user.
[0009] Furthermore, the data owner encrypts the spatial data based on an R-tree index structure and a homomorphic encryption algorithm, including:
[0010] Constructing an R-tree index structure Rt based on plaintext spatial data; the R-tree index structure Rt includes non-leaf nodes and leaf nodes;
[0011] Processing the non-leaf nodes using a Bloom filter and prefix 0-1 encoding to obtain processing results of each entry corresponding to the non-leaf node;
[0012] The leaf nodes are processed by using a Bloom filter and prefix coding to obtain an intermediate processing result of the leaf nodes; and the intermediate processing result of the leaf nodes is encrypted by using a SHE algorithm to obtain the encrypted R-tree structure data.
[0013] Furthermore, the Bloom filter and prefix coding are used to process the leaf node to obtain the leaf node intermediate processing result, including:
[0014] Obtain each data item P=(x, y) in the leaf node, where x represents the horizontal coordinate of the data item and y represents the vertical coordinate of the data item;
[0015] Perform prefix coding on each of the data items P to obtain a data coding set corresponding to the leaf node;
[0016] A hash function is used to calculate the data object hash value of the data encoding set, and the data object hash value is written into the Bloom filter (BF px ,BF py ) to obtain the intermediate processing result of the leaf node.
[0017] Further, determining a query token including the first partial token and the second partial token based on the query scope includes:
[0018] Get the query range R q =[R qx ,R qy ] and processing the range limits based on the prefix 0-1 code to obtain a range limit code set;
[0019] Calculate the hash value of the range limit code set using a hash function to obtain the first partial token T1;
[0020] Each object in the range-boundary encoding set is calculated using a hash function and then written into a Bloom filter (BF qx ,BF qy ), and encrypt each object written into the Bloom filter using a key to obtain the second part token T2;
[0021] The first partial token T1 and the second partial token T2 are combined and processed to obtain the query token T.
[0022] Furthermore, performing a range query operation based on the query token to obtain a target encrypted result set from the encrypted R-tree structure data and the index structure includes:
[0023] Executing the range query operation starting from the root node of the encrypted R-tree structure data based on the index structure;
[0024] If the currently queried node is a non-leaf node, a ciphertext intersection judgment is performed on the first part of the token T1 and the processing results of each entry corresponding to the non-leaf node according to the fast rectangular intersection judgment method to obtain a ciphertext intersection judgment result;
[0025] If the currently queried node is a leaf node, then performing security membership determination processing on the second part token T2 and the data items of each leaf node according to the efficient range membership determination method to obtain a ciphertext membership determination result;
[0026] The target encryption result set is obtained by combining the ciphertext intersection judgment result and the ciphertext member judgment result.
[0027] Furthermore, performing ciphertext intersection judgment on the processing results of the first part of the token T1 and each entry corresponding to the non-leaf node according to the fast rectangle intersection judgment method includes:
[0028] Get the processing results of each entry corresponding to the current non-leaf node Encode(I)=(BF x ,BF y ,ptr), where I represents the I-th entry, BF x and BF y Represents the two spatial attributes R of the minimum bounding rectangle R in the plaintext of entry I x and R y The results after writing the Bloom filter are written separately, and ptr represents the pointer to the corresponding child node;
[0029] Compare the hash value of the range limit code set in the first part token T1 with the processing result of the entry to determine whether there is a hash value of the range limit code set that makes all hash values in entry I in BF x and BF y The values of the positions in are all 1, and the ciphertext intersection judgment result is obtained.
[0030] Furthermore, performing a security membership determination process on the second portion of tokens T2 and the data items of each leaf node according to the efficient range membership determination method includes:
[0031] Get the leaf node intermediate processing result (BF px ,BF py ), where BFpx and BF py They represent the results of the leaf node data items being written into the Bloom filter after prefix encoding and hash function calculation;
[0032] Based on the second part token T2, the write Bloom filter (BF qx ,BF qy )
[0033] Bloom filter BF px and BF qx Perform the inner product operation on the content in to obtain the first inner product operation result; and perform the inner product operation on the Bloom filter BF py and BF qy Perform inner product operation on the content in to obtain the second inner machine operation result;
[0034] The first inner product calculation result and the second inner product calculation result are respectively substituted into a polynomial function constructed using the Lagrange interpolation method, and a multiplication operation is performed on the output of the polynomial function to obtain a safe member determination result.
[0035] According to another aspect of the present invention, there is provided an encrypted spatial data query device, comprising:
[0036] A data storage module, configured to store encrypted R-tree structure data and an index structure of spatial data of at least one data owner, wherein the encrypted R-tree structure data is obtained by the data owner encrypting the spatial data based on the R-tree index structure and a homomorphic encryption algorithm;
[0037] A receiving module, configured to receive a query token of a user, wherein the query token includes a first partial token and a second partial token determined based on a query scope;
[0038] The range query module is used to perform a range query operation based on the query token, obtain a target encrypted result set from the encrypted R-tree structure data and the index structure; and return the target encrypted result set to the user.
[0039] Furthermore, the device further includes an encryption processing module, and the encryption processing module includes:
[0040] An R-tree structure construction unit, configured to construct an R-tree index structure Rt based on plaintext spatial data; the R-tree index structure Rt includes non-leaf nodes and leaf nodes;
[0041] a first processing unit, configured to process the non-leaf nodes using a Bloom filter and prefix 0-1 encoding to obtain processing results of respective entries corresponding to the non-leaf nodes;
[0042] The second processing unit is used to process the leaf node using a Bloom filter and prefix coding to obtain an intermediate processing result of the leaf node; and to encrypt the intermediate processing result of the leaf node using a SHE algorithm to obtain the encrypted R-tree structure data.
[0043] Furthermore, the second processing unit is further configured to:
[0044] Obtain each data item P=(x, y) in the leaf node, where x represents the horizontal coordinate of the data item and y represents the vertical coordinate of the data item;
[0045] Perform prefix coding on each of the data items P to obtain a data coding set corresponding to the leaf node;
[0046] A hash function is used to calculate the data object hash value of the data encoding set, and the data object hash value is written into the Bloom filter (BF px ,BF py ) to obtain the intermediate processing result of the leaf node.
[0047] Furthermore, the process of determining the query token in the receiving module includes:
[0048] Get the query range R q =[R qx ,R qy ] and processing the range limits based on the prefix 0-1 code to obtain a range limit code set;
[0049] Calculate the hash value of the range limit code set using a hash function to obtain the first partial token T1;
[0050] Each object in the range-boundary encoding set is calculated using a hash function and then written into a Bloom filter (BFqx ,BF qy ), and encrypt each object written into the Bloom filter using a key to obtain the second part token T2;
[0051] The first partial token T1 and the second partial token T2 are combined and processed to obtain the query token T.
[0052] Furthermore, the range query module includes:
[0053] a query sequence determining unit, configured to execute the range query operation starting from the root node of the encrypted R-tree structure data based on the index structure;
[0054] an intersection judgment unit, configured to, if the currently queried node is a non-leaf node, perform ciphertext intersection judgment on the first portion of tokens T1 and the processing results of each entry corresponding to the non-leaf node according to a fast rectangular intersection judgment method to obtain a ciphertext intersection judgment result;
[0055] a member determination unit configured to, if the currently queried node is a leaf node, perform a secure member determination process on the second portion of the token T2 and the data item of each leaf node according to an efficient range membership determination method to obtain a ciphertext member determination result;
[0056] A combining unit is used to combine the ciphertext intersection judgment result and the ciphertext member judgment result to obtain the target encryption result set.
[0057] Furthermore, the intersection judgment unit is further configured to:
[0058] Get the processing results of each entry corresponding to the current non-leaf node Encode(I)=(BF x ,BF y ,ptr), where I represents the I-th entry, BF x and BF y Represents the two spatial attributes R of the minimum bounding rectangle R in the plaintext of entry I x and R y The results after writing the Bloom filter are written separately, and ptr represents the pointer to the corresponding child node;
[0059] Compare the hash value of the range limit code set in the first part token T1 with the processing result of the entry to determine whether there is a hash value of the range limit code set that makes all hash values in entry I in BF x and BF y The values of the positions in are all 1, and the ciphertext intersection judgment result is obtained.
[0060] Furthermore, the member determination unit is further configured to:
[0061] Get the leaf node intermediate processing result (BF px ,BF py ), where BFpx and BF py They represent the results of the leaf node data items being written into the Bloom filter after prefix encoding and hash function calculation;
[0062] Based on the second part token T2, the write Bloom filter (BF qx ,BF qy )
[0063] Bloom filter BF px and BF qx Perform the inner product operation on the content in to obtain the first inner product operation result; and perform the inner product operation on the Bloom filter BF py and BF qy Perform inner product operation on the content in to obtain the second inner machine operation result;
[0064] The first inner product calculation result and the second inner product calculation result are respectively substituted into a polynomial function constructed using the Lagrange interpolation method, and a multiplication operation is performed on the output of the polynomial function to obtain a safe member determination result.
[0065] According to another aspect of the present invention, a storage medium is provided, wherein the storage medium stores at least one executable instruction, and the executable instruction enables a processor to execute operations corresponding to the above-mentioned encrypted space data query method.
[0066] According to another aspect of the present invention, a computer device is provided, comprising a processor, a memory, a communication interface, and a communication bus, wherein the processor, the memory, and the communication interface communicate with each other via the communication bus;
[0067] The memory is used to store at least one executable instruction, and the executable instruction enables the processor to perform operations corresponding to the above-mentioned encrypted space data query method.
[0068] By means of the above technical solution, the technical solution provided by the embodiment of the present invention has at least the following advantages:
[0069] The present invention provides a method and apparatus for querying encrypted spatial data, a storage medium, and a computer device. Compared to existing technologies, the present invention organizes spatial data based on an R-tree structure and encrypts the spatial data using a homomorphic encryption algorithm. The resulting encrypted R-tree structure data and index structure are stored in a cloud server, laying the data foundation for secure and efficient spatial data range queries. Furthermore, by receiving a user's query token, which comprises a first token portion and a second token portion determined based on the query range, a range query operation is performed based on the query token, and a target encrypted result set is obtained from the encrypted R-tree structure data and the index structure. This not only avoids reliance on a dual-server model but also addresses the issues of high communication overhead and complex deployment, thereby enabling secure and efficient spatial data range queries.
[0070] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are specifically listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0071] Various other advantages and benefits will become apparent to those skilled in the art upon reading the detailed description of the preferred embodiment below. The accompanying drawings are for illustration purposes only and are not to be considered as limiting the present invention. The same reference symbols are used throughout the drawings to represent the same components. In the drawings:
[0072] Figure 1 A schematic diagram showing a flow chart of an encrypted space data query method provided by an embodiment of the present invention;
[0073] Figure 2 A schematic diagram of constructing an R-tree index based on plaintext spatial data provided by an embodiment of the present invention is shown;
[0074] Figure 3 A schematic diagram showing a flow chart of another encrypted space data query method provided by an embodiment of the present invention;
[0075] Figure 4 A schematic diagram showing a flow chart of another encrypted spatial data query method provided by an embodiment of the present invention;
[0076] Figure 5 A schematic diagram showing a flow chart of another encrypted space data query method provided by an embodiment of the present invention;
[0077] Figure 6 A schematic diagram of a range query provided by an embodiment of the present invention is shown;
[0078] Figure 7A schematic structural diagram of an encrypted spatial data query device provided by an embodiment of the present invention is shown;
[0079] Figure 8 A schematic structural diagram of a computer device provided by an embodiment of the present invention is shown. DETAILED DESCRIPTION
[0080] Exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. Rather, these embodiments are provided to enable a more thorough understanding of the present disclosure and to fully convey the scope of the present disclosure to those skilled in the art.
[0081] The embodiment of the present invention provides an encrypted space data query method, which is applicable to cloud servers, such as Figure 1 As shown, the method includes:
[0082] 101. Storing encrypted R-tree structure data and index structure of spatial data of at least one data owner, wherein the encrypted R-tree structure data is obtained by the data owner encrypting the spatial data based on the R-tree index structure and a homomorphic encryption algorithm;
[0083] In an embodiment of the present invention, the current execution terminal stores encrypted R-tree structure data and index structure of the spatial data of at least one data owner. The original state of the spatial data of the data owner is plain text data, such as the spatial data in Table 1 below:
[0084] Table 1 Plain text of spatial dataset
[0085] <![CDATA[P emp ]]> <![CDATA[P0]]> <![CDATA[P1]]> <![CDATA[P2]]> <![CDATA[P3]]> <![CDATA[P4]]> <![CDATA[P5]]> <![CDATA[P6]]> <![CDATA[P7]]> <![CDATA[P8]]> <![CDATA[P9]]> <![CDATA[P 10 ]]> <![CDATA[P 11 ]]> <![CDATA[P 12 ]]> <![CDATA[P 13 ]]> x 4 2 2 5 3 2 8 6 7 11 13 14 11 13 y 2 1 3 7 9 7 3 4 5 1 3 1 7 6
[0086] It should be noted that before the spatial data is stored in the cloud server, the data owner also needs to encrypt the above spatial data based on the R-tree index structure and homomorphic encryption algorithm. The execution end of the encryption processing can be the current execution end or the client corresponding to the data owner. The embodiment of the present invention does not make specific limitations.
[0087] In this embodiment, before the above encryption process, the current execution end also needs to perform initialization processing, including:
[0088] (1) Public parameters are set, including the hash function key k, the hash function set size γ, and the Bloom filter size η. These parameters are not specifically limited in this embodiment. In this embodiment, to achieve the optimal FP rate, η is set to γ·n / ln2.
[0089] (2) Generate a hash function set based on the hash function set size γ
[0090] (3) Select a large prime number p according to the size of the hash function set γ and generate the Lagrange interpolation function F(·).
[0091] (4) Select a security parameter λ and generate a SHE key sk = KeyGen(λ).
[0092] (5) Set the size range of the R-tree node to [m,M].
[0093] The above initialization process can be adjusted appropriately according to user needs, and the embodiment of the present invention does not make specific limitations. emp , set the maximum node capacity M = 3, and construct the R-tree structure data as follows Figure 2 As shown, the constructed R-tree structure data is then encrypted.
[0094] 102. Receive a query token from a user, where the query token includes a first token portion and a second token portion determined based on a query scope;
[0095] In this embodiment of the present invention, the current execution end receives a user's query token. The query token is obtained by first applying to the data owner and then obtaining authorization from the data owner. After obtaining the query token, the user sends a spatial data query request to the cloud server, including the query token information.
[0096] It should be noted that in this embodiment, the query token is generated by the querying user and includes a first token portion and a second token portion determined based on a given query scope. The first token portion is used to query non-leaf nodes in the encrypted R-tree structured data, while the second token portion is used to query leaf nodes in the encrypted R-tree structured data.
[0097] 103. Perform a range query operation based on the query token to obtain a target encrypted result set from the encrypted R-tree structure data and the index structure; and return the target encrypted result set to the user.
[0098] In an embodiment of the present invention, the current execution end performs a range query operation based on the first and second token portions of the query token. Specifically, the current execution end determines the user's desired entry from the encrypted R-tree structure data and index structure based on the first token portion, and determines the user's desired data from the encrypted R-tree structure data and index structure based on the second token portion, thereby obtaining a target encrypted result set. The current execution end returns the resulting target encrypted result set to the querying user end.
[0099] Furthermore, as a refinement and extension of the above embodiment, in order to ensure data security, another encrypted space data query method is provided, such as Figure 3 As shown, in step 101, the data owner encrypts the spatial data based on the R-tree index structure and the homomorphic encryption algorithm, including:
[0100] 201. Construct an R-tree index structure Rt based on the plaintext spatial data; the R-tree index structure Rt includes non-leaf nodes and leaf nodes;
[0101] In the embodiment of the present invention, the plaintext spatial data set shown in Table 1 in step 101 is constructed into an R-tree index structure Rt as shown in FIG. Figure 2 As shown, Figure 2 The R-tree index structure Rt includes a root node N7, two non-leaf nodes N5 and N6, and five leaf nodes N0, N1, N2, N3 and N4, which are not specifically limited in the embodiment of the present invention.
[0102] 202. Process the non-leaf node using a Bloom filter and prefix 0-1 encoding to obtain processing results of each entry corresponding to the non-leaf node;
[0103] In the embodiment of the present invention, the non-leaf nodes are processed by using Bloom filter and prefix 0-1 encoding. Specifically, given a non-leaf node N storing φ∈[m,M] entries={I0,…,I φ}, where each entry I = (R,ptr)∈N, R = [R x ,R y ] is the minimum bounding rectangle, which contains the range R of the two spatial attributes x =[x l ,x u ],R y =[y l ,y u ], ptr is a pointer to its child node. First, calculate the spatial attribute R x and R y The prefix 0-1 code of the range limit is obtained to obtain the code set Generate a Bloom filter BF of size η x and BF y For each object e in the above encoding set x ∈Ω x and e y ∈Ω y , using hash functions Calculate H j (k,e x ),H j (k,e y ) and set BFx [H j (k,e x )]=1,BF y [H j (k,e y )] = 1. Then, replace the plaintext minimum bounding rectangle R in entry I∈N with (BF x ,BF y ), that is, the processing result of the entry is Encode(I)=(BF x ,BF y ,ptr), where I represents the I-th entry, BF x and BF y Represents the two spatial attributes R of the minimum bounding rectangle R in the plaintext of entry I x and R y The results after writing the bloom filter are written separately, ptr represents the pointer to the corresponding child node; non-leaf node Encode(N)={Encode(I0),…,Encode(I φ )}.
[0104] 203. Use Bloom filter and prefix coding to process the leaf node to obtain the intermediate processing result of the leaf node; and use SHE algorithm to encrypt the intermediate processing result of the leaf node to obtain the encrypted R-tree structure data.
[0105] In the embodiment of the present invention, the leaf nodes are processed by using Bloom filter and prefix coding. Specifically, given a leaf node N leaf ={P0,…,P φ}, where each spatial data item P = (x, y) contains two spatial attributes x and y, where x represents the horizontal coordinate of the data item and y represents the vertical coordinate of the data item.
[0106] First, obtain each data item P = (x, y) in the leaf node;
[0107] Then, prefix encoding is performed on each data item P, and a data encoding set corresponding to a leaf node is generated for each object x, y∈P in the data item P.
[0108] Next, generate a Bloom filter BF of size η px ,BF py , encode the above data set Each object in Using hash functions Calculate H j (k,e px ),H j (k,epy )); and set BF px [ht j (k,e px )]=1,BF py [ht j (k,e py )]=1, that is, the intermediate processing result of the leaf node is obtained.
[0109] Subsequently, it should be noted that in this embodiment, the BF px ,BF py Encrypted ciphertext Bloom filter SHE.Enc(BF px ),SHE.Enc(BF py ), the plaintext space data P∈N leaf Encrypt and replace it with its ciphertext form SHE.Enc(P), that is, the processed ciphertext data item Encode(I p )=(SHE.Enc(BF px ),SHE.Enc(BF py ), SHE.Enc(P)), leaf node Get the final encrypted R-tree structure data.
[0110] Furthermore, as a refinement and extension of the above embodiment, in order to better hide the access mode and improve the security of spatial data, another encrypted spatial data query method is provided, such as Figure 4 As shown, in step 102, determining the query token including the first partial token and the second partial token based on the query scope includes:
[0111] 301. Get query range R q =[R qx ,R qy ] and processing the range limits based on the prefix 0-1 code to obtain a range limit code set;
[0112] In the embodiment of the present invention, the query token is generated by the query user. The query user needs to obtain the parameters set during the initialization process while obtaining the authorization of the data owner. The embodiment of the present invention does not make any specific limitation. The query user terminal obtains the query range R q =[R qx ,R qy ], where R qx =[x ql , x qu ], R qy =[y ql ,y quIn this embodiment, the query client first calculates R qx and R qy The prefix 0-1 code of the range limit is obtained to obtain the range limit code set The embodiments of the present invention are not specifically limited.
[0113] 302. Calculate the hash value of the range limit code set using a hash function to obtain the first partial token T1;
[0114] In the embodiment of the present invention, the query client uses a hash function Calculate the range limit encoding set of each object e∈{Ω qx ,Ω qy} to get the first part of the token That is, we get a matrix composed of the hash values of the prefix 0-1 encoding of the two spatial attributes, and each matrix The number of columns is γ, and the number of rows is the size of the corresponding range limit encoding set.
[0115] 303. Each object in the range boundary code set is calculated using a hash function and then written into a Bloom filter (BF qx ,BF qy ), and encrypt each object written into the Bloom filter using a key to obtain the second part token T2;
[0116] In the embodiment of the present invention, the query user terminal extracts the range R qx ,R qy The prefix code set Generate a Bloom filter BF of size η qx and BF qy , for each object in the prefix encoding set and Using hash functions Calculate H j (k,e qx ),H j (k,e qy ) and set BF qx [ht j (k,e qx )]=1,BF qy [ht j (k,e qy )]=1. Use the key sk to qx ,BF qy Encrypted ciphertext Bloom filter SHE.Enc(BF qx ),SHE.Enc(BF qy ), that is, the second part of the token T2 = {SHE.Enc(BFqx ),SHE.Enc(BF qy )}.
[0117] 304. Combine the first partial token T1 and the second partial token T2 to obtain the query token T.
[0118] In an embodiment of the present invention, the querying user terminal finally merges the first part token T1 obtained in the above step 302 and the second part token T2 obtained in step 303 to obtain the query token T = (T1, T2), so that the querying user sends the token T = (T1, T2) to the cloud server.
[0119] Furthermore, as a refinement and extension of the above embodiment, in order to achieve safe and efficient spatial data range query while reducing computational overhead, another encrypted spatial data query method is provided, such as Figure 5 As shown, in step 103, a range query operation is performed based on the query token to obtain a target encrypted result set from the encrypted R-tree structure data and the index structure, including:
[0120] 401. Execute the range query operation starting from the root node of the encrypted R-tree structure data based on the index structure;
[0121] In an embodiment of the present invention, the current execution end starts to perform the range query operation based on the root node of the encrypted R-tree structure data after encryption processing from step 201 to step 203 based on the index structure; that is, the order of the range query operation is: root node → non-leaf node → leaf node, which is not specifically limited in the embodiment of the present invention.
[0122] 402. If the currently queried node is a non-leaf node, perform a ciphertext intersection determination on the first portion of tokens T1 and the processing results of each entry corresponding to the non-leaf node according to a fast rectangular intersection determination method to obtain a ciphertext intersection determination result.
[0123] In this embodiment of the present invention, the complexity and high computational overhead of determining the intersection between the query range and the node range in a tree structure in an encrypted state are addressed. A Fast Rectangle Intersection Detection (FRID) technique is designed based on Bloom filters and prefix 0-1 encoding. This technique verifies the intersection between the minimum bounding rectangle of non-leaf nodes in an R-tree structure and the query range, significantly improving query efficiency and reducing computational and storage overhead while ensuring privacy.
[0124] The above-mentioned fast rectangle intersection determination method FRID mainly includes three steps: rectangle encoding, data mapping and intersection determination.
[0125] The first step is rectangular encoding: for the rectangular range R = [R x ,R y ],R x =[x l ,x u ],R y =[y l ,y u ], and the query range R to be judged to intersect with R q =[R qx ,R qy ],R qx =[x ql ,x qu ],R qy =[y ql ,y qu ]. q , calculate the prefix 0-1 code of each range limit respectively, and get the code set and To distinguish For common objects between the two, the current implementation adds an extra bit before each object in the encoding set. Add bit 1, Add bit 0. This step is performed by default after the prefix 0-1 encoding and will not be repeated later.
[0126] The second step is data mapping: generating a Bloom filter BF of size η x and BF y , and generate a hash function set of size γ Then each object in the collection e x ∈Ω x Write BF separately x , e y ∈Ω y Write BF y . That is, calculate All hash values H in j (e x ),H j (e y )(1≤j≤γ), and BF x [H j (e x )] and BF y [H j (e y )] is set to 1. In the present invention, The hash function used in the encryption will be the key-based hash function HMAC to provide privacy protection.
[0127] The third step is intersection judgment: calculate each object eq ∈{Ω qx ,Ω qy} hash value. If the object exists Its hash value corresponds to BF x The positions are all set to 1, and there are objects Its hash value corresponds to BF y The positions in are all set to 1, which proves that the given rectangular range R q It intersects with R.
[0128] Since the hash value has been written into the Bloom filter in the data encryption stage in the embodiment of the present invention, the current execution end can directly obtain the processing results of each entry corresponding to the current non-leaf node Encode(I)=(BF x ,BF y ,ptr), where I represents the I-th entry, BF x and BF y Represents the two spatial attributes R of the minimum bounding rectangle R in the plaintext of entry I x and R y The results after writing the bloom filter are written separately, and ptr represents the pointer to the corresponding child node; the token is judged according to the fast rectangle intersection judgment technology And each entry Encode(I)=(BF x ,BF y ,ptr)∈Encode(N) to perform ciphertext intersection judgment.
[0129] Compare the hash value of the range limit code set in the first part token T1 with the processing result of the entry to determine whether there is a hash value of the range limit code set that makes all hash values in entry I in BF x and BF y The values of the positions in are all 1, that is, Is there a row whose hash values are in BF? x The values of the positions in are all 1. Similarly, Is there a row whose hash values are in BF? y The values of the positions in are all 1, thereby obtaining the ciphertext intersection judgment result.
[0130] 403. If the currently queried node is a leaf node, perform security membership determination on the second portion of the token T2 and the data item of each leaf node according to an efficient range membership determination method to obtain a ciphertext membership determination result.
[0131] In this embodiment of the present invention, an Efficient Range Membership Verification (ERMV) technique is designed based on Bloom filters and Lagrange interpolation functions to address the high communication overhead and complex deployment of traditional dual-server models for implementing access mode protection. This technique can be well combined with homomorphic encryption algorithms to achieve secure and efficient membership verification under ciphertext. The above-mentioned Efficient Range Membership Verification ERMV technique mainly includes two steps: data mapping and membership verification.
[0132] The first step is data mapping: given spatial data P = (x, y) and query range R = [R x ,R y ],R x =[x l ,x u ],R y =[y l ,y u ], generate a Bloom filter BF of size η px ,BF py ,BF rx ,BF ry . Using a given set of hash functions Write each of the above objects into the corresponding Bloom filter. Since the increase of range R will lead to more objects that need to be written into the Bloom filter, which will have a negative impact on the algorithm performance, we can use prefix coding to perform simple processing on P and R before writing. That is, for x∈P, assuming its binary length |x| = l, extract its prefix coding set That is, constantly replace the bits in x with *. For y∈P, perform the above operation to obtain the set For the query range R=[R x ,R y ], respectively extract the x and R y The minimum set of prefix objects and Afterwards, and Each object in is written into BF separately px and BF py ,Will and Each object in is written into BF separately rx and BF ry .
[0133] The second step is member determination: based on the hash function set The size of γ, choose a large prime number p, and use the Lagrange interpolation method to construct the polynomial function F(x) at the point set {(0,0),(1,0),…,(γ-1,0),(γ,1)}. The formula is as follows:
[0134] F(x)=a0+a1x+a2x 2 +…+a γ x γ mod p
[0135] Prefix encoding also converts the range membership determination problem into a set intersection problem. If the object x is in the range R x Among them, there are And the intersection contains only one object. Therefore, only the Bloom filter BF px ,BF rx and BF py ,BF ry Perform inner product operations respectively and get ∈ x ,∈ y , the formula is as follows:
[0136]
[0137] Where ° represents the inner product operation.
[0138] Then calculate θ = F(∈ x )·F(∈ y ), if θ=1, then prove x∈R x And y∈R y , that is, the spatial data P is a member of the query range R. On the contrary, if θ=0, the spatial data P is not a member of the query range R.
[0139] To make the description clearer, a simple example will be used to illustrate the above process. Given an object e=4(1002), extract the prefix code set of object e. For the query range R = [3, 6] ([0112, 1102]), the minimum prefix code set that can cover R because There exists a unique common object 10* that makes the values of γ positions in the Bloom filter simultaneously 1, so that the polynomial function value is 1, and it is concluded that e∈R.
[0140] Since the hash value has been written into the Bloom filter in the data encryption stage in the embodiment of the present invention, the current execution end can directly obtain the leaf node intermediate processing result (BF px ,BF py ), where BF px and BF pyThey represent the results of the leaf node data items being written into the Bloom filter after prefix encoding and hash function calculation;
[0141] Based on the second part token T2, the write Bloom filter (BF qx ,BF qy )
[0142] Bloom filter BF px and BF qx Perform the inner product operation on the content in to obtain the first inner product operation result; and perform the inner product operation on the Bloom filter BF py and BF qy Perform inner product operation on the content in to obtain the second inner machine operation result;
[0143] Substitute the first inner product calculation result and the second inner product calculation result into the polynomial function constructed using the Lagrange interpolation method, and perform a multiplication operation on the output of the polynomial function to obtain the safety member determination result. Specifically:
[0144] For leaf node Encode(N leaf ), according to the efficient range member determination method, the second part of the token T2 = {SHE.Enc (BF qx ),SHE.Enc(BF qy )} and the data item Encode(I p )=(SHE.Enc(BF px ),SHE.Enc(BF py ), SHE.Enc(P)) performs secure membership determination, relying on the homomorphic characteristics of the encryption mechanism. The calculation process of the ciphertext determination result SHE.Enc(θ) can be obtained as shown in the following formula:
[0145]
[0146] SHE.Enc(θ)=F(SHE.Enc(∈ x ))·F(SHE.Enc(∈ y ))=SHE.Enc(F(∈ x )·F(∈ y ))
[0147] 404. Combine the ciphertext intersection determination result and the ciphertext member determination result to obtain the target encryption result set.
[0148] In the embodiment of the present invention, the current execution end calculates SHE.Enc(P)·SHE.Enc(θ) and adds the ciphertext whose calculation result is SHE.Enc(1) to the target encryption result set. Since the unmatched data item judgment result SHE.Enc(θ) is SHE.Enc(0), it will be eliminated after the homomorphic multiplication operation, while the matched data item judgment result is SHE.Enc(1), and the result after the homomorphic multiplication operation remains the same.
[0149] It should be noted that, in this embodiment, since all operations in the range query algorithm are performed in the SHE ciphertext state, the cloud server cannot know the member determination result of the data item, and thus cannot locate the specific result position, thereby achieving the purpose of hiding the access mode. Figure 6 As shown, a query example is provided for the query range R q =[[4,7],[6,8]] constructs a token and performs a range query on the encrypted R-tree structure data Rt.
[0150] Experimental verification validated the performance of this method, comparing it with the latest hidden access pattern query solutions. The results show that the proposed method maintains the lowest range query overhead as both the result set and data set sizes increase. Furthermore, the Bloom filter combined with the prefix 0-1 encoding mechanism employed in this method significantly improves performance in terms of both time and storage overhead compared to other encryption algorithms.
[0151] An embodiment of the present invention provides an encrypted spatial data query method. Compared to existing technologies, this method organizes spatial data based on an R-tree structure and encrypts the spatial data using a homomorphic encryption algorithm. The resulting encrypted R-tree structure data and index structure are stored in a cloud server, laying a data foundation for secure and efficient spatial data range queries. Furthermore, by receiving a user's query token, which includes a first token and a second token determined based on the query range, a range query operation is performed based on the query token, and a target encrypted result set is obtained from the encrypted R-tree structure data and the index structure. This method not only avoids reliance on a dual-server model but also addresses the issues of high communication overhead and complex deployment, achieving secure and efficient spatial data range queries.
[0152] As the above Figure 1 The embodiment of the present invention provides an encrypted space data query device, such as Figure 7 As shown, the device includes:
[0153] A data storage module 51 is used to store encrypted R-tree structure data and index structure of spatial data of at least one data owner, wherein the encrypted R-tree structure data is obtained by the data owner encrypting the spatial data based on the R-tree index structure and the homomorphic encryption algorithm;
[0154] A receiving module 52 is configured to receive a query token from a user, wherein the query token includes a first partial token and a second partial token determined based on a query scope;
[0155] The range query module 53 is configured to perform a range query operation based on the query token, obtain a target encrypted result set from the encrypted R-tree structure data and the index structure, and return the target encrypted result set to the user.
[0156] Furthermore, the device further includes an encryption processing module, and the encryption processing module includes:
[0157] An R-tree structure construction unit, configured to construct an R-tree index structure Rt based on plaintext spatial data; the R-tree index structure Rt includes non-leaf nodes and leaf nodes;
[0158] a first processing unit, configured to process the non-leaf nodes using a Bloom filter and prefix 0-1 encoding to obtain processing results of respective entries corresponding to the non-leaf nodes;
[0159] The second processing unit is used to process the leaf node using a Bloom filter and prefix coding to obtain an intermediate processing result of the leaf node; and to encrypt the intermediate processing result of the leaf node using a SHE algorithm to obtain the encrypted R-tree structure data.
[0160] Furthermore, the second processing unit is further configured to:
[0161] Obtain each data item P=(x, y) in the leaf node, where x represents the horizontal coordinate of the data item and y represents the vertical coordinate of the data item;
[0162] Perform prefix coding on each of the data items P to obtain a data coding set corresponding to the leaf node;
[0163] A hash function is used to calculate the data object hash value of the data encoding set, and the data object hash value is written into the Bloom filter (BF px ,BF py ) to obtain the intermediate processing result of the leaf node.
[0164] Furthermore, the process of determining the query token in the receiving module 52 includes:
[0165] Get the query range R q=[R qx ,R qy ] and processing the range limits based on the prefix 0-1 code to obtain a range limit code set;
[0166] Calculate the hash value of the range limit code set using a hash function to obtain the first partial token T1;
[0167] Each object in the range-boundary encoding set is calculated using a hash function and then written into a Bloom filter (BF qx ,BF qy ), and encrypt each object written into the Bloom filter using a key to obtain the second part token T2;
[0168] The first partial token T1 and the second partial token T2 are combined and processed to obtain the query token T.
[0169] Furthermore, the range query module 53 includes:
[0170] a query sequence determining unit, configured to execute the range query operation starting from the root node of the encrypted R-tree structure data based on the index structure;
[0171] an intersection judgment unit, configured to, if the currently queried node is a non-leaf node, perform ciphertext intersection judgment on the first portion of tokens T1 and the processing results of each entry corresponding to the non-leaf node according to a fast rectangular intersection judgment method to obtain a ciphertext intersection judgment result;
[0172] a member determination unit configured to, if the currently queried node is a leaf node, perform a secure member determination process on the second portion of the token T2 and the data item of each leaf node according to an efficient range membership determination method to obtain a ciphertext member determination result;
[0173] A combining unit is used to combine the ciphertext intersection judgment result and the ciphertext member judgment result to obtain the target encryption result set.
[0174] Furthermore, the intersection judgment unit is further configured to:
[0175] Get the processing results of each entry corresponding to the current non-leaf node Encode(I)=(BF x ,BF y ,ptr), where I represents the I-th entry, BF x and BF y Represents the two spatial attributes R of the minimum bounding rectangle R in the plaintext of entry I x and R yThe results after writing the Bloom filter are written separately, and ptr represents the pointer to the corresponding child node;
[0176] Compare the hash value of the range limit code set in the first part token T1 with the processing result of the entry to determine whether there is a hash value of the range limit code set that makes all hash values in entry I in BF x and BF y The values of the positions in are all 1, and the ciphertext intersection judgment result is obtained.
[0177] Furthermore, the member determination unit is further configured to:
[0178] Get the leaf node intermediate processing result (BF px ,BF py ), where BFpx and BF py They represent the results of the leaf node data items being written into the Bloom filter after prefix encoding and hash function calculation;
[0179] Based on the second part token T2, the write Bloom filter (BF qx ,BF qy )
[0180] Bloom filter BF px and BF qx Perform the inner product operation on the content in to obtain the first inner product operation result; and perform the inner product operation on the Bloom filter BF py and BF qy Perform inner product operation on the content in to obtain the second inner machine operation result;
[0181] The first inner product calculation result and the second inner product calculation result are respectively substituted into a polynomial function constructed using the Lagrange interpolation method, and a multiplication operation is performed on the output of the polynomial function to obtain a safe member determination result.
[0182] An embodiment of the present invention provides an encrypted spatial data query device. Compared to existing technologies, this device organizes spatial data based on an R-tree structure and encrypts the spatial data using a homomorphic encryption algorithm. The resulting encrypted R-tree structure data and index structure are stored in a cloud server, laying a data foundation for secure and efficient spatial data range queries. Furthermore, by receiving a user's query token, which includes a first token and a second token determined based on the query range, a range query operation is performed based on the query token, and a target encrypted result set is obtained from the encrypted R-tree structure data and the index structure. This not only avoids reliance on a dual-server model but also addresses the issues of high communication overhead and complex deployment, achieving secure and efficient spatial data range queries.
[0183] According to one embodiment of the present invention, a storage medium is provided, wherein the storage medium stores at least one executable instruction. The computer-executable instruction can execute the encrypted space data query method in any of the above method embodiments.
[0184] Figure 8 A schematic structural diagram of a computer device provided according to an embodiment of the present invention is shown. The specific embodiment of the present invention does not limit the specific implementation of the computer device.
[0185] like Figure 8 As shown, the computer device may include: a processor (processor) 602 , a communication interface (Communications Interface) 604 , a memory (memory) 606 , and a communication bus 608 .
[0186] The processor 602 , the communication interface 604 , and the memory 606 communicate with each other via a communication bus 608 .
[0187] The communication interface 604 is used to communicate with other devices such as clients or other servers.
[0188] The processor 602 is configured to execute the program 610 , and specifically to execute the relevant steps of the above-mentioned encrypted space data query method.
[0189] Specifically, the program 610 may include program codes, which include computer operation instructions.
[0190] Processor 602 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement embodiments of the present invention. The one or more processors included in a computer device may be of the same type, such as one or more CPUs, or may be of different types, such as one or more CPUs and one or more ASICs.
[0191] The memory 606 is used to store the program 610. The memory 606 may include a high-speed RAM memory, and may also include a non-volatile memory (non-volatile memory), such as at least one disk memory.
[0192] The program 610 may be specifically configured to enable the processor 602 to perform the following operations:
[0193] Storing encrypted R-tree structure data and index structure of spatial data of at least one data owner, wherein the encrypted R-tree structure data is obtained by the data owner encrypting the spatial data based on the R-tree index structure and the homomorphic encryption algorithm;
[0194] Receive a query token from a user, where the query token includes a first token portion and a second token portion determined based on a query scope;
[0195] A range query operation is performed based on the query token to obtain a target encrypted result set from the encrypted R-tree structure data and the index structure; and the target encrypted result set is returned to the user.
[0196] Obviously, those skilled in the art will appreciate that the various modules or steps of the present invention described above can be implemented using a general-purpose computing device, centralized on a single computing device, or distributed across a network of multiple computing devices. Alternatively, they can be implemented using program code executable by a computing device, which can then be stored in a storage device and executed by the computing device. In some cases, the steps shown or described can be performed in a different order than that shown, or can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. Thus, the present invention is not limited to any particular combination of hardware and software.
[0197] The foregoing description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Those skilled in the art will readily appreciate that various modifications and variations of the present invention are possible. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention shall be included within the scope of protection of the present invention.
Claims
1. A method for querying encrypted spatial data, applicable to a cloud server, characterized in that: include: Storing encrypted R-tree structure data and index structure of spatial data of at least one data owner, wherein the encrypted R-tree structure data is obtained by the data owner encrypting the spatial data based on the R-tree index structure and the homomorphic encryption algorithm; Receive a query token from a user, where the query token includes a first token portion and a second token portion determined based on a query scope; Performing a range query operation based on the query token to obtain a target encrypted result set from the encrypted R-tree structure data and the index structure; And return the target encryption result set to the user.
2. The method according to claim 1, characterized in that The data owner encrypts the spatial data based on the R-tree index structure and the homomorphic encryption algorithm, including: Constructing an R-tree index structure Rt based on plaintext spatial data; the R-tree index structure Rt includes non-leaf nodes and leaf nodes; Processing the non-leaf nodes using a Bloom filter and prefix 0-1 encoding to obtain processing results of each entry corresponding to the non-leaf node; The leaf nodes are processed by using a Bloom filter and prefix coding to obtain an intermediate processing result of the leaf nodes; and the intermediate processing result of the leaf nodes is encrypted by using a SHE algorithm to obtain the encrypted R-tree structure data.
3. The method according to claim 2, characterized in that The Bloom filter and prefix coding are used to process the leaf node to obtain an intermediate processing result of the leaf node, including: Obtain each data item P=(x, y) in the leaf node, where x represents the horizontal coordinate of the data item and y represents the vertical coordinate of the data item; Perform prefix coding on each of the data items P to obtain a data coding set corresponding to the leaf node; A hash function is used to calculate the data object hash value of the data encoding set, and the data object hash value is written into the Bloom filter (BF px ,BF py ) to obtain the intermediate processing result of the leaf node.
4. The method according to claim 1, wherein Determining a query token including the first partial token and the second partial token based on the query scope includes: Get the query range R q =[R qx ,R qy ] and processing the range limits based on the prefix 0-1 code to obtain a range limit code set; Calculate the hash value of the range limit code set using a hash function to obtain the first partial token T1; Each object in the range-boundary encoding set is calculated using a hash function and then written into a Bloom filter (BF qx ,BF qy ), and encrypt each object written into the Bloom filter using a key to obtain the second part token T2; The first partial token T1 and the second partial token T2 are combined and processed to obtain the query token T.
5. The method according to claim 1, wherein The performing a range query operation based on the query token to obtain a target encrypted result set from the encrypted R-tree structure data and the index structure includes: Executing the range query operation starting from the root node of the encrypted R-tree structure data based on the index structure; If the currently queried node is a non-leaf node, a ciphertext intersection judgment is performed on the first part of the token T1 and the processing results of each entry corresponding to the non-leaf node according to the fast rectangular intersection judgment method to obtain a ciphertext intersection judgment result; If the currently queried node is a leaf node, then performing security membership determination processing on the second part token T2 and the data items of each leaf node according to the efficient range membership determination method to obtain a ciphertext membership determination result; The target encryption result set is obtained by combining the ciphertext intersection judgment result and the ciphertext member judgment result.
6. The method according to claim 5, characterized in that The method of performing ciphertext intersection judgment on the first part of the token T1 and the processing results of each entry corresponding to the non-leaf node according to the fast rectangular intersection judgment method includes: Get the processing results of each entry corresponding to the current non-leaf node Encode(I)=(BF x ,BF y ,ptr), where I represents the I-th entry, BF x and BF y Represents the two spatial attributes R of the minimum bounding rectangle R in the plaintext of entry I x and R y The results after writing the Bloom filter are written separately, and ptr represents the pointer to the corresponding child node; Compare the hash value of the range limit code set in the first part token T1 with the processing result of the entry to determine whether there is a hash value of the range limit code set that makes all hash values in entry I in BF x and BF y The values of the positions in are all 1, and the ciphertext intersection judgment result is obtained.
7. The method according to claim 5, characterized in that The step of performing security membership determination on the second portion of tokens T2 and the data item of each leaf node according to the efficient range membership determination method includes: Get the leaf node intermediate processing result (BF px ,BF py ), where BFpx and BF py They represent the results of the leaf node data items being written into the Bloom filter after prefix encoding and hash function calculation; Based on the second part token T2, the write Bloom filter (BF qx ,BF qy ) Bloom filter BF px and BF qx Perform the inner product operation on the content in to obtain the first inner product operation result; and perform the inner product operation on the Bloom filter BF py and BF qy Perform inner product operation on the content in to obtain the second inner machine operation result; The first inner product calculation result and the second inner product calculation result are respectively substituted into a polynomial function constructed using the Lagrange interpolation method, and a multiplication operation is performed on the output of the polynomial function to obtain a safe member determination result.
8. An encrypted space data query device, characterized in that: include: A data storage module, configured to store encrypted R-tree structure data and an index structure of spatial data of at least one data owner, wherein the encrypted R-tree structure data is obtained by the data owner encrypting the spatial data based on the R-tree index structure and a homomorphic encryption algorithm; A receiving module, configured to receive a query token of a user, wherein the query token includes a first partial token and a second partial token determined based on a query scope; A range query module, configured to perform a range query operation based on the query token, and obtain a target encrypted result set from the encrypted R-tree structure data and the index structure; And return the target encryption result set to the user.
9. A storage medium, characterized in that: The storage medium stores at least one executable instruction, and the executable instruction executes an operation corresponding to the encrypted space data query method according to any one of claims 1 to 7.
10. A computer device, characterized in that: comprising a processor, a memory, a communication interface and a communication bus, wherein the processor, the memory and the communication interface communicate with each other via the communication bus; The memory is used to store at least one executable instruction, and the executable instruction enables the processor to execute an operation corresponding to the encrypted space data query method according to any one of claims 1 to 7.