Symmetrical searchable encryption method and device, electronic equipment and storage medium

Through the symmetric searchable encryption method, the mask is generated using one-time inadvertent writing algorithm and hash function, and the symmetric searchable encryption solution is solved, and the resource overhead and vulnerable in the industrial Internet is achieved, achieving secure and efficient data storage.

CN120597307APending Publication Date: 2025-09-05CHINA MOBILEHANGZHOUINFORMATION TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202410249358.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-03-05
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

Existing symmetric searchable encryption solutions are unusable in industrial Internet environments due to huge resource overhead and are vulnerable to non-adaptive file injection attacks.

Method used

The symmetric searchable encryption method is adopted, through collaboration between the client and the server, and the mask is generated using a one-time inadvertent writing algorithm and hash function, ensuring that the server cannot know the time and location of the file insertion, and only stores data blocks related to keywords to achieve opposite privacy and forward privacy.

Benefits of technology

It reduces the resource overhead of the server, improves security, and can withstand non-adaptive file injection attacks, and is suitable for actual industrial Internet environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120597307A_ABST
    Figure CN120597307A_ABST
Patent Text Reader

Abstract

The invention provides a symmetric searchable encryption method and device, electronic equipment and a storage medium, and belongs to the technical field of industrial internet security, and the method comprises the steps: obtaining a keyword, an operation type and a file identifier of a to-be-updated file; and according to the keyword, the operation type and the file identifier, obtaining a data block related to the keyword, sending the data block to a server for storage, and updating preset index storage to realize update encryption. According to the keyword, the operation type and the file identifier of the to-be-updated file, the data block only related to the keyword is determined so as to ensure that the server cannot know the specific insertion time of the searched file and the storage position of the file, the non-adaptive file injection attack can be coped with, the safety is improved, and the user experience is improved. And the server only needs to store the data blocks related to the keywords, so that the resource overhead is reduced, and the method can be suitable for an actual industrial internet environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of industrial Internet security technology, and in particular to a symmetric searchable encryption method, device, electronic device and storage medium. Background Art

[0002] Currently, the solutions to the non-adaptive file injection attack problem faced by symmetric searchable encryption schemes are mostly focused on the application of Oblivious Random Access Machine (ORAM) and its related variant Write-only Oblivious Random Access Machine (WoORAM).

[0003] ORAM is currently an important means of protecting access patterns, and can be used to hide access to real data blocks. WoORAM only needs to ensure that write physical access is indistinguishable. ORAM and WoORAM incur significant resource overhead when applied, making them unusable in real industrial Internet environments. Summary of the Invention

[0004] The present invention provides a symmetric searchable encryption method, device, electronic device and storage medium to solve the problem that the existing technology generates huge resource overhead and cannot be used in actual industrial Internet environments.

[0005] In a first aspect, the present invention provides a symmetric searchable encryption method applicable to a client, comprising:

[0006] Get the keyword, operation type and file identifier of the file to be updated;

[0007] According to the keyword, the operation type and the file identifier, a data block related to the keyword is obtained, the data block is sent to a server for storage and a preset index storage is updated to achieve updated encryption.

[0008] According to a symmetric searchable encryption method provided by the present invention, the server's storage structure includes a first array for storing the relationship between the keyword and the file, and a second array for storing the file identifier and the file data in the form of key-value pairs, wherein the first array and the second array both include a main area and a holding area; the index storage includes a first state map for representing the storage status of the main area and the holding area, and a second state map for storing the destination of the data block and the operation type; and obtaining the data block associated with the keyword based on the keyword, the operation type, and the file identifier includes:

[0009] performing an update operation corresponding to the operation type on each keyword according to the operation type, and during the update operation, if the keyword is a newly created keyword, determining positions of the keyword and the file identifier based on a predetermined encryption key, or selecting positions of the keyword and the file identifier from the first state map;

[0010] Obtaining a pre-pointer according to the positions of the keyword and the file identifier and the updated encryption key;

[0011] The data block related to the keyword is obtained according to the file identifier, the preamble pointer and the mask generated based on the hash function.

[0012] A symmetric searchable encryption method according to the present invention further includes:

[0013] In response to the update operation, executing a one-time oblivious write algorithm to refresh the master area in the server;

[0014] The step of executing the one-time inadvertent write algorithm includes:

[0015] A state vector is generated according to the second state map, and the state vector and a random number for updating a ciphertext are sent so that the server constructs a permutation matrix and a cleaning vector according to the state vector, and refreshes the main area according to the permutation matrix and the cleaning vector.

[0016] According to a symmetric searchable encryption method provided by the present invention, before obtaining the keyword, operation type and file identifier of the file to be updated, the method further includes:

[0017] Determine the initialized encryption key, the first dictionary array corresponding to the main area, and the second dictionary array corresponding to the holding area, initialize the global variables, the first state map, and the second state map to zero, and determine the starting point and random number of the storage list for each keyword to complete the initialization of the encryption algorithm.

[0018] According to a symmetric searchable encryption method provided by the present invention, after sending the data block to the server for storage and updating the preset index storage, the method further includes:

[0019] Get search keywords;

[0020] Determine the location of the data block to be searched and the token key according to the search keyword;

[0021] Obtaining a search token according to the position of the data block to be searched and the token key;

[0022] The search token and the random number used to generate the mask are sent to the server to initiate a search operation.

[0023] In a second aspect, the present invention further provides a symmetric searchable encryption method applicable to a server, comprising:

[0024] Obtaining data blocks sent by the client and storing the data blocks;

[0025] The data block is determined by the client according to a keyword, an operation type, and a file identifier of the file to be updated, and is related to the keyword.

[0026] A symmetric searchable encryption method according to the present invention further includes:

[0027] In response to a search operation initiated by the client, obtaining a search token and a random number for generating a mask;

[0028] Determining the first position of the search keyword according to the position of the data block to be searched in the search token, and removing the mask of the data block to be searched at the first position according to the random number to obtain the ciphertext of the file identifier and the pointer to the next data block to be searched;

[0029] Decrypting the pointer according to the token key in the search token to obtain the position of the next data block to be searched and the token key corresponding to the next data block to be searched;

[0030] All of the file identifiers are sent to the client to complete the search.

[0031] In a third aspect, the present invention further provides a symmetric searchable encryption device, comprising:

[0032] An acquisition module is used to obtain the keyword, operation type and file identifier of the file to be updated;

[0033] The encryption module is used to obtain a data block related to the keyword according to the keyword, the operation type and the file identifier, send the data block to the server for storage and update the preset index storage to achieve updated encryption.

[0034] In a fourth aspect, the present invention provides an electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the steps of any one of the above-described symmetric searchable encryption methods are implemented.

[0035] In a fifth aspect, the present invention further provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of any of the above-described symmetric searchable encryption methods.

[0036] The symmetric searchable encryption method, device, electronic device and storage medium provided by the present invention determine the data blocks related only to the keywords based on the keywords, operation type and file identifier of the file to be updated, so as to ensure that the server cannot know the specific time when the searched file is inserted and the storage location of the file. It can cope with non-adaptive file injection attacks, improves security, and the server only needs to store data blocks related to the keywords, reducing resource overhead, and can be applied to actual industrial Internet environments. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] In order to more clearly illustrate the technical solutions in the present invention or the prior art, a brief introduction is given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0038] Figure 1 It is a flowchart of the symmetric searchable encryption method provided by the present invention;

[0039] Figure 2 It is a schematic diagram of the structure of the symmetric searchable encryption device provided by the present invention;

[0040] Figure 3 This is a flow chart of a symmetric searchable encryption method based on a symmetric searchable encryption system provided by the present invention;

[0041] Figure 4 It is a structural schematic diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION

[0042] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.

[0043] It should be noted that, in the description of the present invention, the terms "comprise," "include," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus comprising a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. Without further limitation, the phrase "comprises a..." does not preclude the presence of additional identical elements in the process, method, article, or apparatus comprising the elements. Terms such as "upper" and "lower" indicate positions or relationships based on those shown in the accompanying drawings and are intended solely to facilitate the description of the present invention and simplify the description. They are not intended to indicate or imply that the devices or elements referred to must have a specific orientation, be constructed, or operate in a specific orientation, and are therefore not to be construed as limitations on the present invention. Unless otherwise expressly specified or limited, the terms "mounted," "connected," and "connected" should be broadly construed, for example, to mean fixed, removable, or integral; mechanical or electrical; direct or indirect through an intermediary; or internal communication between two elements. For those skilled in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.

[0044] The terms "first," "second," and so forth, used herein are used to distinguish similar objects, not to describe a specific order or precedence. It should be understood that such terms are interchangeable where appropriate, allowing embodiments of the present invention to be implemented in an order other than that illustrated or described herein. Furthermore, the terms "first," "second," and so forth generally distinguish objects of a single type, and do not limit the number of objects. For example, the first object may be one or more. Furthermore, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates an "or" relationship between the connected objects.

[0045] Figure 1 This is a flow chart of the symmetric searchable encryption method provided by the present invention, such as Figure 1 As shown, the present invention provides a symmetric searchable encryption method, applicable to a client, including but not limited to the following steps:

[0046] Step S100, obtaining the keyword, operation type and file identifier of the file to be updated;

[0047] Step S200: obtaining a data block related to the keyword according to the keyword, the operation type and the file identifier, sending the data block to a server for storage and updating a preset index storage to achieve updated encryption.

[0048] Specifically, in the existing ORAM scheme and its variants, forward privacy has always been a research focus. Traditional forward privacy requires that the server cannot know whether the updated file matches the previously searched keyword, which can be written as:

[0049] L update (op,w,ind)=L'(op,ind,|w|);

[0050] Among them, L update is the leak function, op is the operation identifier, ind is the update file identifier, and w is the keyword.

[0051] This invention proposes the concept of "toward privacy," which ensures that the server cannot know the specific time when the searched file was inserted or the file's storage location. Symmetric Searchable Encryption (SSE) ensures security when the server does not know whether the searched file is a previously updated file.

[0052] In order to achieve opposite privacy, the encryption process of the present invention is as follows:

[0053] L update (op,w,ind)=L′(|w|);

[0054] L search (w) = L″;

[0055] That is, the adversarial privacy only leaks the keyword size during the update operation, and nothing is leaked except the search pattern during the search operation, where L′ and L″ are stateless.

[0056] It can be seen that the privacy leakage function L of the present invention is u p date The forward privacy leakage function is smaller than that in the ORAM scheme and its variants, and the ORAM scheme and its variants do not restrict the search leakage function. The present invention achieves both forward privacy and forward privacy.

[0057] It can be understood that the present invention determines the data blocks related only to the keywords based on the keywords, operation types and file identifiers of the files to be updated, so as to ensure that the server cannot know the specific time when the searched files are inserted and the storage location of the files. It can cope with non-adaptive file injection attacks and improve security. The server only needs to store data blocks related to the keywords, which reduces resource overhead and can be applied to actual industrial Internet environments.

[0058] Based on the above embodiment, as an optional embodiment, the storage structure of the server includes a first array for storing the relationship between the keyword and the file and a second array for storing the file identifier and the file data in the form of key-value pairs, wherein the first array and the second array both include a main area and a holding area; the index storage includes a first state map for representing the storage status of the main area and the holding area and a second state map for storing the destination of the data block and the operation type; and obtaining the data block related to the keyword according to the keyword, the operation type and the file identifier includes:

[0059] Step S210: performing an update operation corresponding to the operation type on each keyword according to the operation type. During the update operation, if the keyword is a newly created keyword, determining the positions of the keyword and the file identifier based on a predetermined encryption key, or selecting the positions of the keyword and the file identifier from the first state map.

[0060] Step S220, obtaining a pre-pointer according to the positions of the keyword and the file identifier and the updated encryption key;

[0061] Step S230: Obtain the data block related to the keyword according to the file identifier, the preamble pointer, and the mask generated based on the hash function.

[0062] Specifically, the server has two arrays MapW and MapF. The first array MapW stores the relationship between keywords and files, and is divided into a main area of ​​N blocks and a holding area of ​​M blocks. Each data block contains w, id, and pre, where w is the keyword contained in the file with identifier id, and pre is the previous data block corresponding to w. The second array MapF stores the file identifier as a key and the file data as a value. Similarly, file storage is also divided into a main area and a holding area. The former has N' blocks, and the latter has M' blocks. Each data block will not be stored directly in the main area, but will be stored through the storage area.

[0063] The client maintains two state maps, the first state map sM and the second state map sH, to indicate whether the slots in the main area and the holding area are full or empty. In addition, the second state map sH includes sH.des and sH.sta. sH.des stores the destination of the data block in the holding area, while sH.sta stores the operation type to indicate whether the operation is an add or delete.

[0064] In steps S210-S230, when a client updates a file, it first generates a unified identifier and performs an update operation on each keyword in the file. In the update operation, the client takes the keyword w, the operation type op, and the file identifier id as input. First, the client selects an empty random position fnl from the first state map sM in the state graph format, so that the input w-id pair occupies this random position fnl.

[0065] If the keyword w is added for the first time, that is, it does not exist in the file to be updated, the client initializes key and pos with null values, where key is the encryption key and pos is the current storage location of the latest w-id pair. The current key and pos are then combined into a pre-pointer and stored in the data block, allowing the client to use the file identifier id, pre-pointer, and mask to calculate the data block. The key is refreshed with a new random number, and pos is set to fnl.

[0066] The client uses the file identifier, the prefix pointer, and the mask to calculate the data block. The mask is generated by a hash function that takes a random number as input. The client also marks the holding area for the corresponding data block as existing data and records the final location of the data block in the main area. Finally, the client sends the data block to the server, and the server stores the received data block in the corresponding location in the holding area.

[0067] It can be understood that the present invention provides a solution for determining data blocks, and the server only needs to store data blocks related to keywords, which reduces resource overhead and can be applied to actual industrial Internet environments.

[0068] Based on the above embodiment, as an optional embodiment, the present invention provides a symmetric searchable encryption method, further comprising:

[0069] In response to the update operation, executing a one-time oblivious write algorithm to refresh the master area in the server;

[0070] The step of executing the one-time inadvertent write algorithm includes:

[0071] A state vector is generated according to the second state map, and the state vector and a random number for updating a ciphertext are sent so that the server constructs a permutation matrix and a cleaning vector according to the state vector, and refreshes the main area according to the permutation matrix and the cleaning vector.

[0072] Specifically, each time the client performs an update operation, it triggers the server's OneTimeWrite algorithm, also known as a one-time oblivious write algorithm. In this algorithm, L data blocks in the primary zone are sequentially re-encrypted, where L = N / M, where N is the number of primary zones and M is the number of holding zones.

[0073] The client generates a state vector vec according to the second state map sH, where vec i Indicates the destination of the i-th block and sends the state vec and four random numbers used to update the ciphertext to the server.

[0074] The server constructs a permutation matrix I and a cleaning vector CleanVec of size L×M based on the state vector vec. For each block j with target i, I(i, j) is set to 1.

[0075] In the clean vector CleanVec, position i in the main area will also be overwritten by a block in the holding area, which is generated by obliviously reading each column of I with a vector of size M. After L oblivious reads, L blocks are secretly read and replaced, obtaining the replacement result.

[0076] The server performs an OR operation on the corresponding L blocks in the main area and each element in the clean vector CleanVec to obtain the clean result. It then performs an AND operation on the replacement result and the clean result, storing the AND result in the main area. After M inadvertent reads, the main area is completely refreshed with the blocks in the hold area.

[0077] It can be understood that the present invention provides a technical solution of a one-time inadvertent write algorithm, which can further improve data security by refreshing the main area of ​​the server through the one-time inadvertent write algorithm.

[0078] Based on the above embodiment, as an optional embodiment, before obtaining the keyword, operation type and file identifier of the file to be updated, the following steps are further included:

[0079] Determine the initialized encryption key, the first dictionary array corresponding to the main area, and the second dictionary array corresponding to the holding area, initialize the global variables, the first state map, and the second state map to zero, and determine the starting point and random number of the storage list for each keyword to complete the initialization of the encryption algorithm.

[0080] Specifically, during initialization, the client initializes an encryption key k for symmetric encryption and two dictionary arrays, Main and Hold, for the main and hold areas, respectively. The global variable cyc is initialized to 0, representing the current write location within the hold area. The first state map sM and the second state map sH are also set to 0. For each keyword, the client initializes Cur[W].pos and Cur[W].key to store the starting point of the result list and a random number, respectively. The result list is the list of w-id entries, and cur[w].pos is the location of the latest entry. Main and Hold are then transmitted to the server in ciphertext form.

[0081] It can be understood that the present invention provides a technical solution for client initialization, and the server only needs to store data blocks related to keywords, which reduces resource overhead and can be applied to actual industrial Internet environments.

[0082] Based on the above embodiment, as an optional embodiment, after sending the data block to the server for storage and updating the preset index storage, the method further includes:

[0083] Get search keywords;

[0084] Determine the location of the data block to be searched and the token key according to the search keyword;

[0085] Obtaining a search token according to the position of the data block to be searched and the token key;

[0086] The search token and the random number used to generate the mask are sent to the server to initiate a search operation.

[0087] Specifically, during the search process, the client searches Cur[w] based on the keyword w to determine the position pos and key of the latest block. The pos and key are combined into Token and Ser and sent to the server. Ser is the latest r' that can be used to generate the mask. m The server determines the first position of the keyword w based on pos and removes the mask by using a hash function with Ser and its index as input to obtain the ciphertext of the file identifier and the pointer to the next block. The server decrypts the pointer with the Token key to obtain the pos and key of the next block. The above process is repeated until pos and key are empty. All file identifiers are sent to the client and decrypted using the private key. The client can retrieve the desired file from the server using the file identifier.

[0088] It is understandable that the present invention provides a technical solution for search operations, which eliminates the need to delete previous nodes and add new nodes during the search process, thereby improving the search speed and making the search process simpler.

[0089] The symmetric searchable encryption method provided by the present application is described below. The symmetric searchable encryption method described below and the symmetric searchable encryption method described above can be referenced to each other.

[0090] The present invention also provides a symmetric searchable encryption method, applicable to a server, comprising:

[0091] Obtaining data blocks sent by the client and storing the data blocks;

[0092] The data block is determined by the client according to a keyword, an operation type, and a file identifier of the file to be updated, and is related to the keyword.

[0093] It can be understood that the server in the present invention only needs to store data blocks related to keywords, which reduces resource overhead and can be applied to actual industrial Internet environments.

[0094] Based on the above embodiment, as an optional embodiment, the present invention provides a symmetric searchable encryption method, further comprising:

[0095] In response to a search operation initiated by the client, obtaining a search token and a random number for generating a mask;

[0096] Determining the first position of the search keyword according to the position of the data block to be searched in the search token, and removing the mask of the data block to be searched at the first position according to the random number to obtain the ciphertext of the file identifier and the pointer to the next data block to be searched;

[0097] Decrypting the pointer according to the token key in the search token to obtain the position of the next data block to be searched and the token key corresponding to the next data block to be searched;

[0098] All of the file identifiers are sent to the client to complete the search.

[0099] Specifically, during the search process, the client searches Cur[w] based on the keyword w to determine the position pos and key of the latest block. The pos and key are combined into Token and Ser and sent to the server. Ser is the latest r' that can be used to generate the mask. mThe server determines the first position of the keyword w based on pos and removes the mask by using a hash function with Ser and its index as input to obtain the ciphertext of the file identifier and the pointer to the next block. The server decrypts the pointer with the Token key to obtain the pos and key of the next block. The above process is repeated until pos and key are empty. All file identifiers are sent to the client and decrypted using the private key. The client can retrieve the desired file from the server using the file identifier.

[0100] It is understandable that the present invention provides a technical solution for search operations, which eliminates the need to delete previous nodes and add new nodes during the search process, thereby improving the search speed and making the search process simpler.

[0101] It should be noted that the execution entity of the symmetric searchable encryption method provided by the present invention can be a server or a computer device, such as a mobile phone, a tablet computer, a laptop computer, a PDA, an in-vehicle electronic device, a wearable device, an ultra-mobile personal computer (UMPC), a netbook or a personal digital assistant (PDA), etc.

[0102] The symmetric searchable encryption device provided by the present application is described below. The symmetric searchable encryption device described below and the symmetric searchable encryption method described above can be referenced to each other.

[0103] Figure 2 This is a principle block diagram of the symmetric searchable encryption device provided by this application, such as Figure 2 As shown, the present application also provides a symmetric searchable encryption device, corresponding to the symmetric searchable encryption method applicable to the client, including:

[0104] An acquisition module 210 is used to acquire a keyword, an operation type, and a file identifier of a file to be updated;

[0105] The encryption module 220 is configured to obtain a data block related to the keyword according to the keyword, the operation type and the file identifier, send the data block to the server for storage and update the preset index storage to achieve updated encryption.

[0106] As an embodiment, the storage structure of the server includes a first array for storing the relationship between the keyword and the file, and a second array for storing the file identifier and the file data in the form of key-value pairs, wherein the first array and the second array both include a main area and a holding area; the index storage includes a first state map for representing the storage status of the main area and the holding area, and a second state map for storing the destination of the data block and the operation type; the encryption module 220 is further configured to:

[0107] performing an update operation corresponding to the operation type on each keyword according to the operation type, and during the update operation, if the keyword is a newly created keyword, determining positions of the keyword and the file identifier based on a predetermined encryption key, or selecting positions of the keyword and the file identifier from the first state map;

[0108] Obtaining a pre-pointer according to the positions of the keyword and the file identifier and the updated encryption key;

[0109] The data block related to the keyword is obtained according to the file identifier, the preamble pointer and the mask generated based on the hash function.

[0110] As an embodiment, the encryption module 220 is further configured to:

[0111] In response to the update operation, executing a one-time oblivious write algorithm to refresh the master area in the server;

[0112] The step of executing the one-time inadvertent write algorithm includes:

[0113] A state vector is generated according to the second state map, and the state vector and a random number for updating a ciphertext are sent so that the server constructs a permutation matrix and a cleaning vector according to the state vector, and refreshes the main area according to the permutation matrix and the cleaning vector.

[0114] As an embodiment, it also includes:

[0115] An initialization module is used to determine the initialized encryption key, the first dictionary array corresponding to the main area, and the second dictionary array corresponding to the holding area, initialize the global variables, the first state map, and the second state map to zero, and determine the starting point and random number of the storage list for each keyword to complete the initialization of the encryption algorithm.

[0116] As an embodiment, it also includes:

[0117] The search module is used to obtain a search keyword; determine the location of the data block to be searched and the token key based on the search keyword; obtain a search token based on the location of the data block to be searched and the token key; and send the search token and a random number used to generate a mask to the server to initiate a search operation.

[0118] It should be noted that the symmetric searchable encryption device provided by the present invention can execute the symmetric searchable encryption method described in any of the above embodiments during specific operation, and has the technical effect corresponding to the method, which will not be described in detail in this embodiment.

[0119] The present invention also provides a symmetric searchable encryption system, including a client and a server, wherein the client is used to execute the acquisition of the keyword, operation type and file identifier of the file to be updated; based on the keyword, the operation type and the file identifier, a data block related to the keyword is obtained, the data block is sent to the server for storage and the preset index storage is updated to achieve updated encryption; the server is used to execute the acquisition of the data block sent by the client and store the data block; wherein the data block is determined by the client based on the keyword, operation type and file identifier of the file to be updated, and is related to the keyword.

[0120] Figure 3 This is a flow chart of the symmetric searchable encryption method based on the symmetric searchable encryption system provided by the present invention, such as Figure 3 As shown, as an optional embodiment, a symmetric searchable encryption method is implemented based on a symmetric searchable encryption system, specifically including the following steps:

[0121] Step 1: Clarify the concept of opposite-direction privacy.

[0122] In the existing ORAM scheme and its variants, forward privacy has always been a research focus. Traditional forward privacy requires that the server cannot know whether the updated file matches the previously searched keyword, which can be written as:

[0123] L update (op,w,ind)=L'(op,ind,|w|);

[0124] Among them, L update is the leak function, op is the operation identifier, ind is the update file identifier, and w is the keyword.

[0125] This invention proposes the concept of "toward privacy," which ensures that the server cannot know the specific time when the searched file was inserted or the file's storage location. Symmetric Searchable Encryption (SSE) ensures security when the server does not know whether the searched file is a previously updated file.

[0126] In order to achieve opposite privacy, the encryption process of the present invention is as follows:

[0127] L update (op,w,ind)=L′(|w|);

[0128] L search (w) = L″;

[0129] That is, the adversarial privacy only leaks the keyword size during the update operation, and nothing is leaked except the search pattern during the search operation, where L′ and L″ are stateless.

[0130] It can be seen that the privacy leakage function L of the present invention is u p date The forward privacy leakage function is smaller than that in the ORAM scheme and its variants, and the ORAM scheme and its variants do not restrict the search leakage function. The present invention achieves both forward privacy and forward privacy.

[0131] Step 2: Set up the storage structure.

[0132] The server has two arrays, MapW and MapF. MapW stores the relationship between keywords and files and is divided into a main area of ​​N blocks and a holding area of ​​M blocks. Each block contains w, id, and pre, where w is the keyword contained in the file with identifier id, and pre is the previous block corresponding to w. MapF stores the file identifier as the key and the file data as the value. Similarly, file storage is also divided into a main area and a holding area. The former has N′ blocks and the latter has M′ blocks. Each block will not be stored directly in the main area, but will be stored through the save area.

[0133] For index storage, two state maps sM and sH are maintained in the client to indicate whether the slots in the main area and the holding area are full or empty. In addition, sH.des stores the destination of the blocks in the holding area, and sH.sta stores the operation type to indicate whether the operation is an add or delete. In addition, the client stores the target map Cur for each keyword. The client should store four random numbers rh, RH′, rm, and RM′ for re-encrypting the data. Index storage is similar, and the client also needs to store the same data for file storage.

[0134] Step 3: Initialize the algorithm.

[0135] During initialization, the client initializes an encryption key k for symmetric encryption and two dictionary arrays, Main and Hold, for the main and hold areas, respectively. The global variable cyc is initialized to 0, representing the current write position within the hold area. The state maps sM and sH are also set to 0. For each key, the client initializes Cur[W].pos and Cur[W].key to store the starting point of the result list and a random number, respectively. Main and Hold are then transmitted to the server in ciphertext form.

[0136] Step 4: Update the algorithm.

[0137] When a client updates a file, it first generates a unified identifier and performs an update operation for each keyword in the file. In the update operation, the client takes the keyword w, the operation type op, and the file identifier id as input. First, the client selects an empty random position fnl from the state graph sM, which will be occupied by the new w-id pair. If w is being added for the first time, the client initializes key and pos with null values, where key is the encryption key and pos is the current position of the most recent keyword w. The current key and pos are combined to form a predicate pointer and stored in the data block. Next, the key is refreshed with a new random number, and pos is set to fnl. The value of the data block stored on the server is calculated by the client using the file identifier id, the predicate pointer, and a mask. The mask is generated by a hash function that takes a random number as input. The client also marks the corresponding data block's holding area as existing data and records the final position of the data block in the main area. Finally, the client sends the data block to the server, which stores it at the corresponding location in the holding area.

[0138] Each update triggers the OneTimeWrite algorithm, also known as a one-time oblivious write algorithm. In this algorithm, L blocks in the main zone are sequentially re-encrypted, where L = N / M. The client generates a vector vec based on the state map sH, where veci represents the destination of the i-th block. The client then sends vec and four random numbers used to update the ciphertext to the server. Based on vec, the server constructs an L×M permutation matrix I and a clean vector CleanVec. For each block j with destination i, I(i, j) is set to 1. In CleanVec, position i in the main zone is overwritten with a block from the holding zone. The blocks in the holding zone are treated as vectors of size M, and each column of I is obliviously read to generate a block. After L oblivious reads, L blocks are secretly read and permuted, resulting in the permutation result. Next, the server performs an OR operation on the corresponding L blocks in the main zone and each element in CleanVec to obtain the cleansing result. Finally, an AND operation is performed on the replacement result and the cleanup result, and the AND operation result is stored in the main area. After M times of inadvertent reading, the main area is completely refreshed by the blocks in the holding area.

[0139] Step 5: Search algorithm determination.

[0140] During the search process, the client searches for Cur[w] based on the keyword w to determine the position pos and key of the latest block. pos and key are then combined into Token and Ser and sent to the server. Ser is the latest r'm that can be used to generate the mask. The server then determines the first position of the keyword w based on pos, and removes the mask by executing a hash function that takes Ser and its index as input to obtain the ciphertext of the file identifier and the pointer to the next block. The server decrypts the pointer with the key of Token to obtain the pos and key of the next block. Next, the server repeats this process until pos and key are empty. All file identifiers are sent to the client and decrypted using the private key. Finally, the desired file is retrieved from the server using the file identifier.

[0141] Using the Enron email dataset publicly available online for testing, the present invention is approximately 10 times faster than Fides in terms of file update speed and 10 times faster than S 3 ORAM is 26 times faster and S 3While ORAM's update speed increases with database capacity, this approach doesn't present a similar problem. In terms of search performance, the present invention is approximately five times faster than Fides. While traditional Fides requires deleting previous nodes and adding new ones during the search process, the present invention requires similar additional operations. The communication bandwidth between the server and client is only one-third that of the traditional Fides approach. Furthermore, the present invention provides enhanced security, protecting against non-adaptive file injection attacks.

[0142] In summary, this invention addresses the problem that traditional symmetric searchable encryption schemes are difficult to resist against non-adaptive file injection attacks and provides a new symmetric searchable encryption method based on oblivious read and write and Software Guard Extensions (SGX). By clarifying the concept of opposite privacy and setting a storage structure that implements oblivious read and write, this invention improves traditional oblivious read and write to serve as a symmetric searchable encryption scheme, thus realizing a new symmetric searchable encryption scheme that can resist file injection attacks and can cope with non-adaptive file injection attacks.

[0143] Figure 4 Schematic diagram of the structure of the electronic device provided by the present invention, such as Figure 4 As shown, the electronic device may include: a processor 410, a communication interface 420, a memory 430, and a communication bus 440, wherein the processor 410, the communication interface 420, and the memory 430 communicate with each other via the communication bus 440. The processor 410 may call the logic instructions in the memory 430 to execute the symmetric searchable encryption method, which includes:

[0144] Get the keyword, operation type and file identifier of the file to be updated;

[0145] According to the keyword, the operation type and the file identifier, a data block related to the keyword is obtained, the data block is sent to a server for storage and a preset index storage is updated to achieve updated encryption.

[0146] In addition, the logic instructions in the above-mentioned memory 430 can be implemented in the form of a software functional unit and can be stored in a computer-readable storage medium when sold or used as an independent product. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0147] In another aspect, the present invention further provides a computer program product, comprising a computer program stored on a non-transitory computer-readable storage medium, wherein the computer program comprises program instructions. When the program instructions are executed by a computer, the computer is capable of performing the symmetric searchable encryption method provided in each of the above embodiments, the method comprising:

[0148] Get the keyword, operation type and file identifier of the file to be updated;

[0149] According to the keyword, the operation type and the file identifier, a data block related to the keyword is obtained, the data block is sent to a server for storage and a preset index storage is updated to achieve updated encryption.

[0150] In another aspect, the present invention further provides a non-transitory computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the method for performing the symmetric searchable encryption method provided in the above embodiments is implemented. The method includes:

[0151] Get the keyword, operation type and file identifier of the file to be updated;

[0152] According to the keyword, the operation type and the file identifier, a data block related to the keyword is obtained, the data block is sent to a server for storage and a preset index storage is updated to achieve updated encryption.

[0153] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.

[0154] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, or of course, by hardware. Based on this understanding, the essence of the above technical solution or the part that contributes to the existing technology can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or certain parts of the embodiments.

[0155] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A symmetric searchable encryption method, characterized in that: Applicable to clients, including: Get the keyword, operation type and file identifier of the file to be updated; According to the keyword, the operation type and the file identifier, a data block related to the keyword is obtained, the data block is sent to a server for storage and a preset index storage is updated to achieve updated encryption.

2. The symmetric searchable encryption method according to claim 1, characterized in that: The storage structure of the server includes a first array for storing the relationship between the keyword and the file and a second array for storing the file identifier and the file data in the form of a key-value pair, wherein the first array and the second array both include a main area and a holding area; the index storage includes a first state map for representing the storage state of the main area and the holding area and a second state map for storing the destination of the data block and the operation type; The obtaining, according to the keyword, the operation type, and the file identifier, a data block related to the keyword, comprises: performing an update operation corresponding to the operation type on each keyword according to the operation type, and during the update operation, if the keyword is a newly created keyword, determining positions of the keyword and the file identifier based on a predetermined encryption key, or selecting positions of the keyword and the file identifier from the first state map; Obtaining a pre-pointer according to the positions of the keyword and the file identifier and the updated encryption key; The data block related to the keyword is obtained according to the file identifier, the preamble pointer and the mask generated based on the hash function.

3. The symmetric searchable encryption method according to claim 2, wherein: Also includes: In response to the update operation, executing a one-time oblivious write algorithm to refresh the master area in the server; The step of executing the one-time inadvertent write algorithm includes: A state vector is generated according to the second state map, and the state vector and a random number for updating a ciphertext are sent so that the server constructs a permutation matrix and a cleaning vector according to the state vector, and refreshes the main area according to the permutation matrix and the cleaning vector.

4. The symmetric searchable encryption method according to claim 2, wherein: Before obtaining the keyword, operation type and file identifier of the file to be updated, the method further includes: Determine the initialized encryption key, the first dictionary array corresponding to the main area, and the second dictionary array corresponding to the holding area, initialize the global variables, the first state map, and the second state map to zero, and determine the starting point and random number of the storage list for each keyword to complete the initialization of the encryption algorithm.

5. The symmetric searchable encryption method according to claim 1, wherein: After sending the data block to the server for storage and updating the preset index storage, the method further includes: Get search keywords; Determine the location of the data block to be searched and the token key according to the search keyword; Obtaining a search token according to the position of the data block to be searched and the token key; The search token and the random number used to generate the mask are sent to the server to initiate a search operation.

6. A symmetric searchable encryption method, characterized in that For servers, including: Obtaining data blocks sent by the client and storing the data blocks; The data block is determined by the client according to a keyword, an operation type, and a file identifier of the file to be updated, and is related to the keyword.

7. A symmetric searchable encryption method according to claim 6, characterized in that: Also includes: In response to a search operation initiated by the client, obtaining a search token and a random number for generating a mask; Determining the first position of the search keyword according to the position of the data block to be searched in the search token, and removing the mask of the data block to be searched at the first position according to the random number to obtain the ciphertext of the file identifier and the pointer to the next data block to be searched; Decrypting the pointer according to the token key in the search token to obtain the position of the next data block to be searched and the token key corresponding to the next data block to be searched; All of the file identifiers are sent to the client to complete the search.

8. A symmetric searchable encryption device, characterized in that: include: An acquisition module is used to obtain the keyword, operation type and file identifier of the file to be updated; The encryption module is used to obtain a data block related to the keyword according to the keyword, the operation type and the file identifier, send the data block to the server for storage and update the preset index storage to achieve updated encryption.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the steps of the symmetric searchable encryption method according to any one of claims 1 to 7 are implemented.

10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the symmetric searchable encryption method according to any one of claims 1 to 7 are implemented.

Citation Information

Cited By

  • A verifiable range searchable symmetric encryption method for large-scale datasets

    CN122457326A