Verifiable privacy information retrieval mechanism based on homomorphic encryption

By introducing a third-party verification and arbitration mechanism, combined with homomorphic encryption and zero-knowledge proof, the challenges of the PIR scheme in verifiability and accountability are resolved, compliance verification and dispute arbitration of questions and responses are achieved in a cloud computing environment, and the credibility and usability of the PIR scheme are improved.

CN120602069APending Publication Date: 2025-09-05HUNAN UNIV
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510719746.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-30
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

Existing Private Information Retrieval (PIR) schemes have made significant progress in protecting query privacy, but they face key challenges in verifiability and accountability. It is difficult to clearly distinguish the source of errors when query results are erroneous or inconsistent, which weakens credibility and usability.

Method used

A third-party verification and arbitration mechanism is introduced to ensure the compliance of inquiries and the correctness of responses through homomorphic encryption and zero-knowledge proof, and to provide clear responsibility when disputes occur, including proof of legitimacy of inquiries generated by data owners, response verification of cloud servers, and dispute arbitration.

Benefits of technology

While protecting query privacy, it improves the credibility and applicability of the PIR solution, ensures the compliance of inquiries and the correctness of responses, and provides efficient privacy protection and dispute accountability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602069A_ABST
    Figure CN120602069A_ABST
Patent Text Reader

Abstract

The invention discloses a verifiable privacy information retrieval mechanism based on homomorphic encryption. The method comprises the following steps: S1, after initialization is completed, a data owner generates a zero-knowledge proof while constructing a private information retrieval challenge, proves that a challenge structure is legal, and submits the proof to a trusted third party (TTP); s2, the server receives the inquiry verified by the TTP and then performs homomorphic calculation, generates an encrypted response and sends the result to the data owner and the TTP, and the TTP synchronously records response information; s3, the data owner carries out decryption and Hash comparison on a returned result, if an exception is found, an objection request can be submitted, and verification is carried out by the TTP in combination with challenge and response zero-knowledge proof; and S4, arbitration and responsibility tracing: the TTP judges the dispute based on a verification result, and determines a responsibility party. The method is suitable for private information retrieval scenes with high requirements on data security and integrity.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of private information retrieval, and in particular to a method for protecting intellectual property rights of private information retrieval based on verifiable homomorphic encryption. Background Art

[0002] With the rapid development of information technology and the advent of the big data era, the way data is generated, stored, and managed has undergone fundamental changes. As an efficient and flexible computing model, cloud computing has been widely adopted by individuals, businesses, and government agencies for data storage, processing, and maintenance. By migrating data to cloud computing platforms, users can significantly reduce costs, improve system availability, and streamline operations and maintenance processes. However, this model also brings new challenges: how to achieve secure, efficient, and privacy-friendly access to data in a cloud environment.

[0003] Private Information Retrieval (PIR) technology, as a cryptographic mechanism that can protect the access privacy of data owners, has received widespread attention in recent years. PIR allows data owners to retrieve data from cloud servers without revealing their query intentions. However, although existing PIR schemes have made significant progress in protecting query privacy, key challenges still exist in terms of verifiability and accountability. Most current PIR schemes focus on reducing communication complexity and computational overhead, while ignoring the difficult-to-attribute scenarios when disputes arise over results. When PIR query results are erroneous or inconsistent, existing schemes find it difficult to clearly distinguish the source of the error: whether the data owner generated an illegal query that does not comply with the protocol specifications, or whether the cloud server failed to properly maintain data integrity. This ambiguity significantly weakens the credibility and applicability of PIR schemes in practical deployments.

[0004] Furthermore, both cloud servers and data owners pose potential threats. Cloud servers may corrupt data due to software failures or hardware errors, or even intentionally delete rarely used data from the data owner to save storage space, concealing the fact that the data has been corrupted or deleted. Furthermore, cloud servers may become curious about the content of the data owner's data. On the other hand, data owners may construct query vectors that do not conform to the protocol, thereby obfuscating the source of errors when private information retrieval query results are incorrect or inconsistent.

[0005] While existing PIR schemes have made some progress in privacy protection, they still face numerous challenges in practical applications. For example, existing PIR schemes often lack effective verification mechanisms to ensure the accuracy and integrity of data returned by cloud servers, and they also fail to clearly identify who is responsible when disputes arise. This poses a serious challenge to the reliability and security of PIR schemes in the face of malicious cloud servers or data owners.

[0006] This paper proposes a verifiable private information retrieval mechanism based on homomorphic encryption. By introducing a third-party verification and adjudication mechanism, this mechanism protects query privacy while also ensuring compliance proof of queries, correctness verification of responses, and accountability for disputes. Summary of the Invention

[0007] The technical problem to be solved by the present invention is that although existing private information retrieval (PIR) solutions have made significant progress in protecting query privacy, they face key challenges in verifiability and accountability. Most existing solutions focus on reducing communication complexity and computational overhead, but ignore the scenarios where it is difficult to attribute responsibility when disputes arise. When PIR query results are erroneous or inconsistent, existing solutions find it difficult to clearly distinguish the source of the error: whether the data owner generated an illegal query that does not comply with the protocol specifications, or whether the cloud server failed to properly maintain data integrity. This ambiguity significantly weakens the credibility and usability of PIR solutions in actual deployments.

[0008] To solve the above technical problems, the present invention proposes a new private information retrieval solution with third-party verifiability and arbitrability. It is characterized by comprising the following steps:

[0009] A verifiable private information retrieval mechanism based on homomorphic encryption, characterized by:

[0010] After S1 initialization is completed, the data owner generates a privacy query for the target data block and constructs a proof of query validity using a zero-knowledge proof protocol to prove the validity of the query structure. The query and proof are then submitted to a trusted third party (TTP).

[0011] S2: The trusted third party verifies the legitimacy of the data owner's query and sends the verified query to the cloud server. The server performs homomorphic computation on the challenge, generates an encrypted response, and sends the result to the data owner and the trusted third party. The trusted third party then records the response information.

[0012] In S3, the data owner decrypts and compares the returned results with hashes. If any anomalies are found, the owner submits an objection request to a trusted third party, which then verifies the result using a zero-knowledge proof of the challenge and response.

[0013] In step S4, the trusted third party locally verifies the compliance of the data owner's arbitration request and the correctness of the cloud server's response. If both parties pass the verification, the arbitration request is rejected. If the verification fails, the source of the error can be clearly identified, providing a basis for dispute resolution.

[0014] Furthermore, the data owner in step S1 constructs a private information retrieval challenge method including: running a key generation algorithm to generate a public-private key pair, publishing the public key and saving the private key, generating a challenge vector based on the target data block, and encrypting each bit of the vector using the Paillier homomorphic encryption method to ensure the privacy of the challenge vector.

[0015] Furthermore, the data owner in step S1 generates a zero-knowledge proof for the encrypted challenge, including proving that a single ciphertext in the challenge satisfies binary properties, i.e., each encrypted plaintext bit is either 0 or 1. By constructing two branches of proof, corresponding to a true value and a pseudo-statement, respectively, the binary property of the challenge vector is proven without leaking the plaintext, and it is proved that the encrypted plaintext after the homomorphic sum of all ciphertexts is equal to 1, i.e., the sum of the plaintexts of the challenge vector is exactly 1, indicating that the challenge is a valid choice for a unique data block.

[0016] Furthermore, the data owner submits the encrypted challenge and the zero-knowledge proof method described in step S1, including: the data owner submits the encrypted challenge and the zero-knowledge proof to the TTP, the TTP verifies the legitimacy of the challenge, and if the verification is successful, sends the encrypted challenge to the server.

[0017] Furthermore, the server-generated encrypted response method described in step S2 includes: after the cloud server receives the challenge verified by the TTP, it calculates the ciphertext response corresponding to the data item requested by the data owner based on its locally stored data block collection, and returns the response result to the TTP and the data owner.

[0018] Furthermore, the method for the data owner in step S3 to decrypt and hash the result includes: the data owner uses the homomorphic private key generated in step S1 to decrypt the server's response result to obtain the target plaintext data block. If the data owner questions the integrity of the data block, the decrypted data block is sent to the TTP.

[0019] Furthermore, the trusted third party verification method described in step S3 combined with the zero-knowledge proof of challenge and response includes: the TTP uses the public key to encrypt the data block, and performs consistency judgment with the response result record received locally from the cloud server, so as to prevent malicious DO from slandering the honest cloud server. If the comparison is consistent, the hash value of the data block is calculated and compared with the hash set of the locally stored data blocks to determine whether the integrity of the data block is destroyed, and the comparison result is notified to the data owner.

[0020] Compared with the prior art, the advantages of the present invention are:

[0021] 1. By introducing a third-party verification and arbitration mechanism, this invention achieves two-way supervision of the behavior of cloud servers and data owners while protecting the query privacy of data owners. This solves the problem of existing PIR solutions that make it difficult to clearly determine the responsibility when disputes occur, and improves the credibility and applicability of PIR solutions in actual deployment.

[0022] 2. This invention integrates cutting-edge cryptographic technologies such as verifiable computing and zero-knowledge proof to ensure the compliance of queries and the correctness of responses, while achieving efficient privacy protection without leaking query indexes.

[0023] 3. The present invention is applicable to private information retrieval scenarios in a single cloud environment, has wide applicability, and can provide theoretical and practical support for secure data access in a multi-party game environment. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] Figure 1 Schematic diagram of a specific embodiment of the present invention.

[0025] Figure 2 This is a functional description diagram of the three core entities in a specific embodiment of the present invention.

[0026] Figure 3 This is a diagram of the data owner DO calculation overhead experiment in a specific embodiment of the present invention.

[0027] Figure 4 This is a diagram of the TTP calculation overhead experiment in a specific embodiment of the present invention.

[0028] Figure 5 This is a diagram of the CS calculation overhead experiment in a specific embodiment of the present invention. DETAILED DESCRIPTION

[0029] The present invention will be further described below in conjunction with the accompanying drawings and specific preferred embodiments, but the scope of protection of the present invention is not limited thereby.

[0030] The system of the present invention is applicable to cloud computing environments, such as Figure 2 As shown in the figure, it is mainly composed of the following three core entities: Data Owner (DO): has access rights to cloud-stored data, initiates private information retrieval requests, and obtains target data blocks without revealing the query intention; Cloud Server (CS): is responsible for storing complete data files and responding to encrypted query requests from data owners; Trusted Third Party (TTP): has verification capabilities but does not participate in the data retrieval process, and is responsible for verifying the compliance of queries and responses, handling disputes, and adjudicating responsibilities.

[0031] During the system initialization phase, the data owner divides the original data file into several data blocks of equal length, which are denoted as m1, m2, ..., m n , and calculate the hash value H(m i ). The data owner submits the hash set to TTP for record. Subsequently, DO executes the key generation algorithm, which includes the following steps: randomly select two large prime numbers p and q, calculate the modulus N = pq, and further define

[0032]

[0033] Define the Paillier homomorphic encryption function E(m) = g m r N modN 2 ,in is a random number. Generate a public-private key pair (pk, sk), where pk = (N, g) and sk = λ. The public key is publicly available for challenge encryption, while the private key is kept by the DO for data decryption.

[0034] In the challenge generation and compliance verification phase, DO constructs a sparse challenge vector Q = (q1, q2, ..., q n ), only one bit is 1, and the rest are 0. The vector is encrypted by Paillier to obtain the ciphertext vector C=(c1,c2,…,c n ), where c i =E(q i ). DO then constructs a zero-knowledge proof and executes the following two zero-knowledge proof protocols to ensure the compliance of the challenge.

[0035] The ZKBit protocol proves that each challenge ciphertext is only encrypted with 0 or 1. The data owner has a i Perform the following operations to randomly select two random numbers For the case where the plaintext value is 0, a true commitment is generated.

[0036]

[0037] For the case where the plaintext value is 1, a true commitment is generated.

[0038]

[0039] Simulate another path of commitment (i.e. not the real path),

[0040]

[0041] where e sim and z sim is a random value

[0042] Compute the challenge e = H(c||a0||a1) and split it into e0, e1, satisfying e0+e1 = e mod q

[0043] Calculating True Path Response Output Proof

[0044] π bit =(a0,a1,e0,e1,z0,z1) (6)

[0045] The ZKSum protocol proves that the sum of all ciphertexts equals 1, that is, only one data block is queried. The query ciphertext vector C = (c1, c2, ..., c n ) Homomorphic aggregation is C = ∏c i mod N 2 , the data owner randomly selects a random number Generate Commitment

[0046] A=g 1 ·s N modN 2 (7)

[0047] Calculate the challenge, e = H(C||A), and use the random number ρ used for encryption to calculate the response z = ρ·s e modN, output proof

[0048] π sum =(A,z,e) (8)

[0049] Both protocols use the Fiat-Shamir transform to make the interaction process non-interactive, improving efficiency. The DO submits the ciphertext challenge and proof to the TTP. The TTP verifies the binary nature of the challenge and the correctness of the sum. If verification passes, it forwards the ciphertext challenge to the cloud server CS.

[0050] In the cloud server response generation phase, CS generates a query based on the received challenge ciphertext C and generates a query based on the locally stored data block {m i} Perform the following homomorphic operations:

[0051]

[0052] The response ciphertext R is actually the encryption result of the target data block. CS sends it to DO and TTP, and TTP records this response.

[0053] During the decryption and dispute resolution phase, after receiving the ciphertext response, DO uses the private key to decrypt and obtain the plaintext data block m j If DO has doubts about the correctness of the result, it can initiate an arbitration request to TTP. After receiving the arbitration request, TTP performs the following verification process. First, it uses DO’s public key to verify the plaintext mj Encrypt, obtain R′, verify whether it is consistent with the local record response ciphertext R; compare m j The hash value of the query is compared with the hash set originally submitted by the DO to confirm the data integrity. If any step is inconsistent, the TTP can determine that the error is due to the DO's forged query or the CS's dishonest calculation, and thus make a fair judgment.

[0054] In this example, simulation experiments validated this technical solution. A prototype system for this method was implemented using the Python language, and detailed experimental testing was conducted in a typical single-cloud environment. The experimental platform used the Windows 11 operating system and the hardware configuration included an AMD Ryzen 7 5800H @ 3.20GHz processor, Samsung DDR4 3200MHz 16GB memory, and WDC SN730 SSD storage. Python version 3.9 was used as the development and testing language platform to ensure the versatility and reproducibility of the method implementation.

[0055] Computational Overhead Verification,In terms of computational performance, the operation phases of three types of entities,,data owners (DO), cloud servers (CS), and third-party verifiers (TTP),are evaluated respectively.

[0056] Data owners: Their primary computational overhead lies in challenge vector generation, zero-knowledge proof (ZKBit, ZKSum) generation, and response decryption. Experimental results show that challenge generation time increases linearly with the number of data blocks. Challenge encryption is the primary bottleneck (taking over 10 seconds for 200 data blocks), while the generation times of ZKBit and ZKSum remain small or constant. Third-party verifiers: TTP verification tasks include verifying ZKBit and ZKSum proofs and checking the consistency of the results. Experimental data shows that ZKBit verification time increases linearly with the number of data blocks, while ZKSum verification time remains nearly constant (approximately 0.002 seconds). This difference in verification efficiency is attributed to the cohesive structure of ZKSum's design, making it suitable for deployment in computing-constrained environments. Cloud servers: The cloud primarily performs response computation. Experiments demonstrate that response computation time increases linearly with the number of data blocks, increasing from 1.5 seconds to 12 seconds from 20 to 200 blocks, demonstrating manageable computational complexity. The above experiments verified that the protocol of the present invention achieved a relatively balanced distribution of computing tasks among the three parties, showing good engineering deployability.

[0057] Communication overhead evaluation: The communication process of the protocol of the present invention is divided into three stages: the DO submits a query and proof to the TTP, the TTP forwards the query vector to the CS, and the CS returns the response result to the DO. Measurements show that the data owner's communication overhead scales linearly with the query dimension, primarily focusing on sending the Paillier ciphertext vector and the corresponding ZK proof. TTP communication volume also depends linearly on the query dimension, but is relatively light. CS communication load is minimal, requiring only the return of the target ciphertext block. Therefore, while ensuring security, the present invention significantly reduces communication pressure on the cloud server side, making it suitable for low-bandwidth or edge environments.

[0058] Error detection capability verification: To test the present invention's ability to detect illegal query vectors, the applicant designed three types of attack samples, including non-Boolean ciphertext, non-unique selection vectors, and forged ZK proofs, and conducted 100 rounds of simulation experiments in a 64-dimensional query vector space. The experimental results show that TTP successfully identified and rejected illegal requests in all test rounds, with an error recognition rate of 100% and an average verification time of no more than 0.16 seconds, indicating that the proposed protocol has strong robustness and arbitrability without affecting efficiency.

[0059] The above description is merely a preferred embodiment of the present invention and does not constitute any form of limitation to the present invention. Although the present invention has been disclosed above based on preferred embodiments, it is not intended to limit the present invention. Therefore, any simple modifications, equivalent variations, and modifications made to the above embodiments based on the technical essence of the present invention without departing from the content of the technical solution of the present invention shall fall within the scope of protection of the technical solution of the present invention.

Claims

1. A verifiable private information retrieval mechanism based on homomorphic encryption, characterized by: include: After S1 initialization is completed, the data owner generates a privacy query for the target data block and constructs a proof of query validity using a zero-knowledge proof protocol to prove the validity of the query structure. The query and proof are then submitted to a trusted third party (TTP). S2: The trusted third party verifies the legitimacy of the data owner's query and sends the verified query to the cloud server. The server performs homomorphic computation on the challenge, generates an encrypted response, and sends the result to the data owner and the trusted third party. The trusted third party also records the response information. In S3, the data owner decrypts and compares the returned results with hashes. If any anomalies are found, the owner submits an objection request to a trusted third party, which then verifies the result using a zero-knowledge proof of the challenge and response. S4, the trusted third party locally verifies the compliance of the data owner's arbitration request and the correctness of the cloud server's response. If both parties pass the verification, the arbitration request will be rejected. If the verification fails, the source of the error can be clearly pointed out, providing a basis for dispute resolution.

2. The verifiable private information retrieval mechanism based on homomorphic encryption according to claim 1 is characterized in that: The initialization method described in step S1 includes: the data owner first divides the data file into multiple data blocks of equal size, calculates the hash value of each block, and generates a hash set of the entire data block. In order to support the subsequent arbitration process that may occur, the data owner submits the hash set to a third party for filing.

3. The verifiable private information retrieval mechanism based on homomorphic encryption according to claim 1 is characterized in that: The method for generating a privacy query in step S1 includes: the data owner runs a key generation algorithm to generate a public-private key, publishes the public key, and uses the public key to encrypt each bit of the challenge vector according to the Paillier homomorphic encryption method to form an encrypted challenge vector.

4. The verifiable private information retrieval mechanism based on homomorphic encryption according to claim 1 is characterized in that: The use of the zero-knowledge proof protocol to construct the challenge validity proof in step S1 includes: proving that a single ciphertext in the challenge vector satisfies the binary property and that the sum of the ciphertexts is a certain fixed value, that is, each encrypted plaintext is 0 or 1, and the plaintext encrypted after the homomorphic sum of all ciphertexts in the challenge vector is equal to 1.

5. The verifiable private information retrieval mechanism based on homomorphic encryption according to claim 1 is characterized in that: The homomorphic computing method performed by the server in step S2 includes: based on the properties of Paillier homomorphic encryption, the server uses the public key disclosed by the data owner to perform homomorphic summation calculation on the challenge vector to generate the encrypted response.

6. The verifiable private information retrieval mechanism based on homomorphic encryption according to claim 1 is characterized in that: The method for the data owner to decrypt the returned result in step S3 includes: using the homomorphic private key to decrypt the encrypted response from the server according to the Paillier homomorphic encryption method to obtain the original data block.

7. The verifiable private information retrieval mechanism based on homomorphic encryption according to claim 1 is characterized in that: The method for verifying the compliance of the data owner's arbitration request and the correctness of the cloud server's response in step S4 includes: after the trusted third party receives the data block decrypted by the data owner, it uses the data owner's public key to encrypt the data block and compares it with the locally recorded server response result. If there is any inconsistency, the arbitration request is rejected; otherwise, a hash function is used to generate a hash summary, which is compared with the hash record recorded during initialization to determine whether the integrity of the data block is destroyed.

8. The homomorphic encryption-based verifiable private information retrieval mechanism according to claim 1 is characterized in that: The privacy query generation mechanism described in step S1 is applicable to any binary query vector in private information retrieval scenarios with high data security and integrity requirements.

Citation Information

Cited By

  • Supervisable privacy information retrieval method and device, storage medium and program product

    CN121744390A

  • Method, device, storage medium and program product for retrievable privacy information

    CN121744390B

  • A method, device and system for verifiable private information retrieval with minimal storage

    CN122660849A