Image processing method and device, equipment, medium and product

By encrypting plaintext image sets and generating query trapdoors, combined with dynamic search tokens and hash verification codes, the privacy leakage and unverifiable results issues in image retrieval in multi-user scenarios are solved, achieving secure and reliable image querying.

CN120873218APending Publication Date: 2025-10-31HANGZHOU XINYUN SEMICON GRP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510975041.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-15
Publication Date
2025-10-31

AI Technical Summary

Technical Problem

Existing technologies struggle to achieve secure queries in multi-user scenarios, resulting in privacy breaches, unverifiable results, and low retrieval efficiency.

Method used

By encrypting a set of plaintext images to generate a query trapdoor, and then searching for images in a re-encrypted set of images, the target plaintext image is finally decrypted. Dynamic search tokens and hierarchical hash verification codes are used to ensure the security and reliability of the query.

Benefits of technology

It enables secure queries in multi-user scenarios, ensuring the reliability and accuracy of user query data, solving the problems of privacy protection and result verifiability, and improving retrieval efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120873218A_ABST
    Figure CN120873218A_ABST
Patent Text Reader

Abstract

The invention discloses an image processing method and device, equipment, a medium and a product. The method comprises the following steps: acquiring a plaintext image set, and encrypting the plaintext image set to obtain a re-encrypted image set; obtaining a query image, and generating a query trap door according to the query image; performing image retrieval in the re-encrypted image set based on the query trap door to obtain a target re-encrypted image; and decrypting the target re-encrypted image to obtain a target plaintext image. By means of the technical scheme, safe query in a multi-user scene can be achieved, and the reliability and correctness of user query data are guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of data encryption technology, and in particular to an image processing method, apparatus, device, medium and product. Background Technology

[0002] With the widespread adoption of cloud computing and artificial intelligence technologies, image retrieval technology is increasingly used in fields such as security monitoring, e-commerce, and medical imaging. However, existing technologies have significant shortcomings in areas such as privacy protection, retrieval efficiency, and result verifiability in multi-user scenarios. For example, traditional encrypted image retrieval schemes typically only support single-user environments, making it difficult to adapt to the needs of multi-user collaborative retrieval. Furthermore, cloud servers may return tampered or erroneous search results, leading to user privacy leaks or unreliable search results. Summary of the Invention

[0003] This invention provides an image processing method, apparatus, device, medium, and product to enable secure queries in multi-user scenarios and ensure the reliability and accuracy of user query data.

[0004] According to one aspect of the present invention, an image processing method is provided, comprising:

[0005] Obtain a set of plaintext images and encrypt the set of plaintext images to obtain a set of re-encrypted images;

[0006] Obtain the query image and generate a query trapdoor based on the query image;

[0007] Based on the query trap, image retrieval is performed in the set of re-encrypted images to obtain the target re-encrypted image;

[0008] The target re-encrypted image is decrypted to obtain the target plaintext image.

[0009] According to another aspect of the present invention, an image processing apparatus is provided, the apparatus comprising:

[0010] An encryption module is used to acquire a set of plaintext images and encrypt the set of plaintext images to obtain a set of re-encrypted images;

[0011] A generation module is used to acquire a query image and generate a query trapdoor based on the query image;

[0012] The retrieval module is used to perform image retrieval in the re-encrypted image set based on the query trap to obtain the target re-encrypted image;

[0013] The decryption module is used to decrypt the target re-encrypted image to obtain the target plaintext image.

[0014] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:

[0015] At least one processor; and

[0016] A memory communicatively connected to the at least one processor; wherein,

[0017] The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the image processing method according to any embodiment of the present invention.

[0018] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the image processing method according to any embodiment of the present invention.

[0019] According to another aspect of the present invention, embodiments of the present invention also provide a computer program product, the computer program product including a computer program, which, when executed by a processor, implements the image processing method described in any embodiment of the present invention.

[0020] This invention first obtains a set of plaintext images, encrypts the plaintext image set to obtain a re-encrypted image set, then obtains a query image, generates a query trapdoor based on the query image, performs image retrieval in the re-encrypted image set based on the query trapdoor to obtain the target re-encrypted image, and finally decrypts the target re-encrypted image to obtain the target plaintext image. This invention enables secure queries in multi-user scenarios, ensuring the reliability and accuracy of user query data.

[0021] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0022] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0023] Figure 1 This is a flowchart of an image processing method according to an embodiment of the present invention;

[0024] Figure 2This is a flowchart illustrating an image processing method according to an embodiment of the present invention;

[0025] Figure 3 This is a schematic diagram of the structure of an image processing device according to an embodiment of the present invention;

[0026] Figure 4 This is a schematic diagram of the structure of an electronic device that implements the image processing method of the present invention. Detailed Implementation

[0027] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0028] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and their derivatives, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0029] It is understood that before using the technical solutions disclosed in the various embodiments of this disclosure, users should be informed of the types, scope of use, and usage scenarios of the personal information involved in this disclosure in an appropriate manner in accordance with relevant laws and regulations, and user authorization should be obtained.

[0030] Example 1

[0031] Existing technology 1, "An Intelligent Similar Image Recognition and Retrieval Method and System" (CN119068267A), proposes an intelligent similar image retrieval method based on the SuperPoint algorithm. This method extracts 512 feature points and generates a 216-dimensional description vector, combining it with the LightGlue algorithm to achieve efficient matching. This method utilizes a hierarchical retrieval mechanism, prioritizing the rapid location of similar images using a two-dimensional array, and only activating the similarity algorithm when no match is found. Its core lies in the efficient extraction and matching optimization of feature points.

[0032] The aforementioned existing technology uses the SuperPoint algorithm to automatically detect and extract key feature points from input images. Specifically, for each image, the system uses the SuperPoint algorithm to select 512 key feature points. These feature points reflect local information in the image and serve as the basis for subsequent matching. For each extracted key feature point, the SuperPoint algorithm generates a 256-dimensional description vector. This description vector can capture texture, edge, and other feature information of local regions, thus forming a complete set of feature vectors. Overall, each image is represented as a vectorized feature matrix with dimensions [512×256]. The vectorized features extracted from the image are stored in a dedicated vector database. During retrieval, the system searches the database for feature points that match the query image by performing an approximate nearest neighbor search for each feature vector. Each matched point is associated with its original image. To determine the most similar candidate image to the query image, the system performs a statistical analysis on each feature point matched from the vector database. Specifically, the system counts the votes for the matched feature points in each candidate image, and the image with the most votes is considered to have the highest similarity to the query image. Finally, the top N images with the most votes are selected as candidate results. After the candidate images are selected, existing technologies utilize the LightGlue algorithm to perform fine-grained matching on these pre-selected images. The LightGlue algorithm can improve the overall matching accuracy by further verifying the matching relationship of local features between images while maintaining high retrieval efficiency, ensuring that the final returned image results have high precision. Specifically, in terms of feature extraction, the SuperPoint algorithm is used to extract image key points and description vectors; in terms of retrieval, a two-dimensional array index table is constructed, the target array is searched first, and depth matching is used when no match is found; and joint retrieval of images and text is supported.

[0033] While existing technology 1 performs well in feature extraction and matching efficiency, its design focuses on single-user scenarios and has not been optimized for multi-user collaborative retrieval needs and security issues, resulting in problems such as lack of multi-user support, insufficient privacy protection, and unverifiable results.

[0034] (1) Lack of multi-user support: The scheme does not have a multi-user key distribution system. All users share the same encryption key or generate subkeys by deriving from a simple key. When multiple users search concurrently, it may cause data races or unauthorized access.

[0035] (2) Insufficient privacy protection: The scheme does not encrypt the 512-dimensional feature description vector extracted by the SuperPoint algorithm, allowing the cloud server to directly obtain the raw feature data. Attackers can reconstruct image content through statistical analysis or model reverse engineering (such as feature reverse engineering). The two-dimensional array index table on which hierarchical retrieval depends is stored in plaintext, exposing image correlations. User-generated query trapdoors do not introduce dynamic noise or obfuscation mechanisms, allowing the cloud server to build user profiles through long-term monitoring of retrieval records.

[0036] (3) Results are not verifiable: The encrypted images returned by the cloud server do not include verification information such as hash values ​​and digital signatures, making it impossible for users to determine whether the results have been tampered with. The verification process relies entirely on the cloud server's self-declaration (such as returning a "search successful" status code) and lacks a third-party auditing mechanism. For example, the cloud server may falsely claim "no matching results" when in fact it has skipped part of the search task due to insufficient computing resources.

[0037] Existing technology two, "Image Retrieval Method and Device" (CN119248954A), proposes a blockchain-based multi-user encrypted image retrieval scheme. It achieves multi-user key conversion through proxy re-encryption technology and utilizes watermarking to track malicious users. The system receives images submitted by users, extracts image feature vectors using a pre-trained deep learning model, and generates corresponding index identifiers. It retrieves target arrays associated with the index of the image to be retrieved from a pre-constructed two-dimensional array. This two-dimensional array stores grouped indexes of similar images in the image database, with each group corresponding to a target array. If no target array is found, the system uses a similarity comparison algorithm to perform a full database search. The algorithm compares the index of the image to be retrieved with all indices in the image database one by one, filtering out images with similarity exceeding a preset threshold. The system sorts the retrieved similar images from high to low similarity and prioritizes returning the top N results. User feedback is also recorded for subsequent index optimization.

[0038] The disadvantages of prior art 2 include:

[0039] (1) Insufficient retrieval efficiency: The solution relies on a pre-built two-dimensional array index (e.g., grouped by "product category"), but the array classification rules are based on historical data features and cannot dynamically adapt to newly added or feature-mutated images. If the image to be retrieved does not match the preset array, a full database similarity calculation needs to be triggered. However, the coverage of the preset array is limited, leading to an increased false negative rate.

[0040] (2) High computational cost: To reduce computational cost, the scheme standardizes and reduces the dimensionality of image feature vectors. However, dimensionality reduction leads to the loss of key features, requiring compensation for accuracy by increasing the search range, which in turn increases the computational cost. When the preset array is not hit, frame-by-frame similarity calculation is required for all images in the database.

[0041] (3) Multi-user retrieval scenarios are not supported: When users share the same retrieval interface and index pool, fine-grained access control cannot be implemented. When multiple users initiate requests simultaneously, the lack of resource scheduling strategies may lead to data contention.

[0042] In summary, the shortcomings of existing technologies are summarized as follows:

[0043] (1) Limitations of single-user scenarios: Traditional solutions rely on unified keys or static token mechanisms, which cannot achieve fine-grained access control for multiple users. This results in the linkability of trapdoors generated by different users querying the same image, posing risks of privacy leakage and unauthorized access.

[0044] (2) Lack of reliability of results: The data returned by the cloud server lacks a reliable verification mechanism. Users cannot verify the legality of the decryption key or the integrity of the result, making it difficult to defend against malicious tampering or transmission errors.

[0045] (3) Imbalance between efficiency and security: The encrypted retrieval process often uses fully homomorphic encryption or complex cryptographic protocols, which leads to excessive overhead in feature extraction, re-encryption and similarity calculation, and cannot meet the real-time retrieval needs of large-scale image databases.

[0046] Figure 1 This is a flowchart of an image processing method according to an embodiment of the present invention. This embodiment is applicable to verifiable and efficient image processing that supports multiple users. The method can be executed by the image processing device according to the present invention, which can be implemented in software and / or hardware, such as... Figure 1 As shown, the method specifically includes the following steps:

[0047] S101. Obtain the plaintext image set and encrypt the plaintext image set to obtain the re-encrypted image set.

[0048] It should be noted that the plaintext image set can be a collection of several unencrypted original images. The re-encrypted image set, on the other hand, can be a collection of images obtained by encrypting each plaintext image in the plaintext image set twice.

[0049] In this embodiment, the plaintext image set can be owned by a DO (Data Owner). The DO can first pre-encrypt each plaintext image in the set, and then send the pre-encrypted images to a PS (Proxy Server). The PS then re-encrypts the pre-encrypted images to further enhance the security and reliability of the image encryption. After re-encryption, the PS can send the re-encrypted image set to a CSP (Cloud Server Provider) for storage.

[0050] S102. Obtain the query image and generate a query trapdoor based on the query image.

[0051] It should be explained that the image to be queried can be the image that DU (Data User, image query user) wants to query.

[0052] As we know, a query trapdoor is a special query mechanism that allows users to query specific data without exposing sensitive information. It is typically implemented using encryption and decryption techniques to ensure that only authorized users can access the specific data.

[0053] Specifically, image query user DU can generate query trapdoors by processing the query image. For example, the processing may include operations such as image feature extraction, feature vector expansion, and feature vector splitting.

[0054] S103. Based on the query trapdoor, perform image retrieval in the re-encrypted image set to obtain the target re-encrypted image.

[0055] It should be noted that the target re-encrypted image can be a re-encrypted image retrieved from the set of re-encrypted images, and the image query user DU is currently searching for. For example, there can be one or more target re-encrypted images, and the specific number can be set by the user. This embodiment does not limit this.

[0056] Specifically, image query user DU can send a query trap to the cloud server CSP. The cloud server CSP then performs an image search within its stored set of re-encrypted images based on the query trap, obtaining re-encrypted images that match the image criteria being searched by image query user DU. For example, the target re-encrypted image could be the re-encrypted image in the set with the highest similarity to the image being searched by image query user DU. After finding the target re-encrypted image, the cloud server CSP can return it to the image query user DU.

[0057] S104. Decrypt the target re-encrypted image to obtain the target plaintext image.

[0058] The target plaintext image can be the plaintext image obtained by decrypting the target re-encrypted image.

[0059] Specifically, after receiving the target re-encrypted image, the image query user DU can decrypt the target re-encrypted image to obtain the plaintext image that the image query user DU is searching for.

[0060] This invention first obtains a set of plaintext images, encrypts the plaintext image set to obtain a re-encrypted image set, then obtains a query image, generates a query trapdoor based on the query image, performs image retrieval in the re-encrypted image set based on the query trapdoor to obtain the target re-encrypted image, and finally decrypts the target re-encrypted image to obtain the target plaintext image. This invention enables secure queries in multi-user scenarios, ensuring the reliability and accuracy of user query data.

[0061] Optionally, a set of plaintext images is obtained, and the set of plaintext images is encrypted to obtain a set of re-encrypted images, including:

[0062] Obtain a set of plaintext images, and encrypt each plaintext image in the set based on the first key to obtain a set of pre-encrypted images.

[0063] It should be noted that the first key can be generated by the KGC (Key Generation Center) and distributed to the data owner DO so that the data owner DO can pre-encrypt each plaintext image in the plaintext image set.

[0064] The pre-encrypted image set can be a set of all pre-encrypted images obtained by the data owner DO encrypting each plaintext image in the plaintext image set based on the first key.

[0065] Specifically, the Key Generation Center (KGC) generates a first key and distributes it to the data owner (DO). The data owner (DO) then uses the first key to encrypt each plaintext image in the plaintext image set, resulting in a pre-encrypted image set.

[0066] Each pre-encrypted image in the pre-encrypted image set is re-encrypted using the re-encryption key to obtain the re-encrypted image set.

[0067] It should be noted that the re-encryption key can be generated by the key generation center KGC and distributed to the proxy server PS so that the proxy server PS can re-encrypt each pre-encrypted image in the pre-encrypted image set.

[0068] Specifically, the key generation center KGC generates a re-encryption key and distributes it to the proxy server PS. The proxy server PS then re-encrypts each pre-encrypted image in the pre-encrypted image set based on the re-encryption key, resulting in a re-encrypted image set.

[0069] Optionally, obtain the query image and generate a query trapdoor based on the query image, including:

[0070] Feature extraction is performed on the query image to obtain the feature vector corresponding to the query image.

[0071] In this embodiment, the image query user DU can extract features from the query image using a CNN (Convolutional Neural Network) model to obtain the corresponding feature vector. It should be noted that the CNN model in this embodiment specifically refers to a deep learning model used for image feature extraction. It can automatically learn multi-level image features through structures such as convolutional layers and pooling layers, significantly improving retrieval accuracy. Its lightweight design is adapted to the computational resource limitations of plaintext terminals.

[0072] Based on the search token, a query trapdoor is generated according to the feature vector corresponding to the query image.

[0073] It should be noted that the search token can be generated by the Key Generation Center (KGC) and distributed to image query users (DUs) to enable them to perform image retrieval. It is important to note that each image query user (DU) has a unique search token.

[0074] In this embodiment, the Key Generation Center (KGC) generates a unique dynamic security search token for each image query user (DU). The search token contains a random factor, which makes the query traps generated by different image query users (DU) for the same image unlinkable, avoiding cross-user privacy leaks and ensuring dynamic permission separation and privacy isolation.

[0075] In practice, image query users (DUs) can extract features from the query image locally using a CNN model to obtain feature vectors. These feature vectors can then be expanded based on the search token, split, and finally a query trapdoor constructed before being sent to the cloud server (CSP).

[0076] Optionally, after obtaining the plaintext image set, the following may also be included:

[0077] For each plaintext image in the plaintext image set, feature extraction is performed to obtain the feature vector corresponding to each plaintext image.

[0078] Specifically, the data owner (DO) can use a CNN model to extract features from each plaintext image in the plaintext image set, obtaining the feature vector corresponding to each plaintext image.

[0079] An encrypted index is generated for each plaintext image based on its feature vector.

[0080] It should be noted that the encrypted index can be generated by the data owner (DO) first extracting feature vectors from the plaintext image using a CNN model, and then applying dimensionality expansion and splitting processes to the feature vectors.

[0081] Specifically, the data owner (DO) can locally extract features from each plaintext image in the plaintext image collection using a CNN model, obtaining a feature vector for each plaintext image. Then, the extracted feature vectors for each plaintext image can be expanded, split, and finally, an encrypted index for each plaintext image can be constructed. This encrypted index is then sent to the cloud server (CSP).

[0082] Establish a mapping relationship between the encrypted index corresponding to the plaintext image and the re-encrypted image obtained after re-encrypting the plaintext image.

[0083] Specifically, in the cloud server CSP, each plaintext image, after being encrypted twice, needs to establish a mapping relationship with the encryption index corresponding to the plaintext image to ensure that the corresponding re-encrypted image can be found through the encryption index.

[0084] Optionally, image retrieval is performed in the re-encrypted image set based on the query trapdoor to obtain the target re-encrypted image, including:

[0085] The similarity score for each re-encrypted image is determined based on the query trapdoor and the encryption index corresponding to each re-encrypted image.

[0086] The similarity score can be the score indicating the degree of similarity between the query image and the re-encrypted image.

[0087] Specifically, after receiving the query trapdoor, the cloud server CSP calculates the secure inner product between the query trapdoor and the encryption index corresponding to each re-encrypted image to obtain the similarity score corresponding to each re-encrypted image.

[0088] The target re-encrypted image is determined based on the similarity score corresponding to each re-encrypted image.

[0089] In this embodiment, after obtaining the similarity score corresponding to each re-encrypted image, the similarity scores of all re-encrypted images can be sorted, and then the top-K results are returned. The value of K can be set by the user according to actual needs; this embodiment does not limit this setting.

[0090] Optionally, the target re-encrypted image is decrypted to obtain the target plaintext image, including:

[0091] The second key is decrypted to obtain the third key, and the third key is then verified.

[0092] It should be noted that the second key can be generated by the key generation center KGC and distributed to the image query user DU, enabling the image query user DU to decrypt the target re-encrypted image. It should also be explained that the third key can be the content key obtained by decrypting the second key.

[0093] Specifically, after receiving the target re-encrypted image returned by the cloud server CSP, the image query user DU can perform decryption calculations using the second key to obtain the content key. After obtaining the content key, the image query user DU executes a verification process to confirm the correctness of its decryption.

[0094] If the third key is successfully verified, the target re-encrypted image is decrypted based on the third key to obtain the target plaintext image.

[0095] Specifically, if the third key verification is successful, that is, the decryption content key is correct, then the image query user DU uses the content key to decrypt the target re-encrypted image and obtain the target plaintext image.

[0096] Figure 2 This is a flowchart illustrating an image processing method according to an embodiment of the present invention. Figure 2 As shown, the image processing method of this invention mainly involves five entities: data owner DO, image query user DU, cloud server CSP, key generation center KGC, and proxy server PS.

[0097] Among them, DO is the owner of the plaintext image data, responsible for extracting image features, building and generating the corresponding image encryption index, encrypting the image data, sending the encrypted image data to PS for proxy re-encryption, and sending the encryption index to CSP for storage.

[0098] CSP performs data storage and retrieval tasks, storing encrypted image information and corresponding encrypted index information of the generated images, matching the encrypted index according to the query trapdoor to obtain the corresponding search results, and finally returning the search results.

[0099] DU is the queryer of image data. It generates a corresponding query trap based on the query keywords and sends it to CSP. It also decrypts the pre-decrypted encrypted image information obtained by CSP to obtain the plaintext image information.

[0100] PS is a proxy server that performs proxy re-encryption. It re-encrypts the encrypted image generated by DO and sends the encrypted image information to CSP for storage.

[0101] KGC is a fully trusted entity that manages and generates system public parameters and master keys, and generates keys for DO and DU.

[0102] Specifically, the image processing method of this invention mainly consists of the following seven algorithms: setup, KeyGen, BuildIndex, Encrypt, Trapdoor, Search, and Decrypt, which are described in detail below:

[0103] I. Initialization phase (setup(λ)→(pk,mk)):

[0104] Given the security parameter λ, the key generation center KGC generates the master key mk and public parameters pk, as shown in the following formula:

[0105]

[0106] Where g is a generator, The values ​​are randomly selected. The partitioning matrix S is a randomly generated (2n+1)-dimensional binary vector, and {U1,U2} are two randomly generated (2n+1)×(2n+1)-dimensional invertible binary matrices. mk is the system master key, and pk is the common parameter.

[0107] II. Key Distribution Phase (KeyGen(λ)→(pk,sk)):

[0108] For the input security parameter λ, KGC generates corresponding keys for DO, DU, and PS respectively. For DO, KGC randomly selects u∈Z. p Generate key (sk) DO =u,pk DO =g u (i.e., the first key mentioned above); for DU, KGC randomly selects z∈Z p Generate key (i.e., the second key mentioned above); simultaneously, a unique search token is generated for each user DU to enable multi-user queries. First, a token of length K ≤ n is randomly selected, and a random vector of length K is generated: Tok u ={l1,l2,...,l K}, where the random numbers satisfy And Tok u Distribute to DU, at this time Tok u A unique search token for DU-side users. Finally, for the proxy server PS, a proxy re-encryption key is generated. (i.e., the aforementioned re-encryption key).

[0109] III. Encrypted Index Construction (BuildIndex(m) → I) c ):

[0110] For each plaintext image, DO first extracts an n-dimensional feature vector I from the plaintext image using a CNN model, and then applies a dimensionality expansion and splitting process to the feature vector to generate the final encrypted index I. c The specific process is as follows:

[0111] (1) Image Feature Extraction: The data owner DO extracts features from its plaintext image information locally using a CNN model, and obtains the feature vector I = {d1, d2, ..., d...} n}

[0112] (2) Feature vector expansion: For the extracted feature vector I, it is expanded to (2n+1) bits. For each randomly selected Y, i ∈(n,2n+1), the (n+Y)th digit of vector I i +1) The entry is set to a random number ε i By setting the (2n+1)th position to a random offset t, the final eigenvector I is expanded to...

[0113] (3) Eigenvector splitting: For each dimension, according to the splitting matrix S, the expanded eigenvectors are split... Split into two random vectors {I′, I″}, according to the following rules. If S[i] = 0, then If S[i] = 1, then Where τ is a random number, satisfying Finally, we obtain the split feature vectors {I′,I″}.

[0114] (4) Encryption Index Construction: The split feature vectors {I′,I″} are used to construct the final encryption index through the invertible matrix {U1,U2}. and I c Send to CSP.

[0115] IV. Image Encryption Stage (Encrypt(m,sk)→CT):

[0116] The encryption phase is mainly divided into the DO user-side encryption algorithm DO-Encrypt and the PS-side proxy server re-encryption algorithm PS-Encrypt.

[0117] (1) DO-Encrypt Algorithm: The image data owner DO uses the first key locally to pair the plaintext image data M = {M1, M2, ... M}. i Encrypt the data to generate a ciphertext image dataset CM = {CM1, CM2, ..., CM}. i} (i.e., the aforementioned set of pre-encrypted images). Specifically, for each plaintext image M iEncrypt (i∈[1,n]) to obtain CM i =Enc ck (M i In addition, the following calculations are performed:

[0118] C1 = pk s =g us

[0119] C2=ck·e(g,h) s

[0120] C3 = g H(ck)

[0121] CM = {CM1, CM2, ..., CM} i};

[0122] The final ciphertext output is as follows:

[0123] CT = {C1, C2, C3, CM};

[0124] Where s is a secret value randomly generated by DO, and the CT is finally sent to the proxy server PS.

[0125] (2) PS-Encrypt Algorithm: After the proxy server PS receives the pre-encrypted image C sent by DO, it uses the re-encryption key tk to re-encrypt it, and performs the following calculation:

[0126]

[0127] The final output of the proxy-re-encrypted ciphertext is as follows:

[0128] CT′=(C1′,C2,C3,CM);

[0129] The encrypted ciphertext CT′ is finally uploaded to the CSP side for storage.

[0130] The technical solution of this invention embeds a layered hash verification code verification tag generated by two factors, namely the user's private key and the cloud server's public key, during the proxy re-encryption stage. This supports automatic triggering of hash chain verification when the user's DU terminal decrypts the image query, verifying whether the returned data has been tampered with or the key has been replaced. It can identify data tampering or illegal key replacement, ensuring the authenticity of the results in highly sensitive scenarios. By combining the ciphertext tag with the hash chain, the one-way trust dependence on the cloud server is broken.

[0131] V. Trapsdoor Generation Phase (Trapdoor(Q)→T) Q ):

[0132] Similar to the BuildIndex algorithm, image query user DU first processes the query image m through a CNN model.q Extract the feature vector Q, and use the search token Tok of DU to apply a dimensionality expansion and splitting process to the feature vector to generate the final encrypted query trapdoor T. Q Then it is uploaded to the CSP side for retrieval.

[0133] (1) Image feature extraction: The image query user DU performs feature extraction on the queried image information locally using a CNN model, and obtains the feature vector Q = {q1,q2,...,q}. n}

[0134] (2) Feature vector expansion: For the extracted feature vector Q, the feature vector is expanded to become a (2n+1)-bit feature vector. Select a random scaling factor r≠0, and the search token Tok of the image query user DU. u ={l1,l2,...,l K},in Expand the eigenvector Q to For all other positions of v∈[n+1,2n], set them to 0, and set the 2n+1th position to the constant term 1.

[0135] (3) Eigenvector splitting: The splitting process is the reverse of the BuildIndex algorithm. Using the splitting matrix S, the expanded vectors are split... Split into two vectors {Q′, Q″}, according to the following rules:

[0136] If S[i] = 0, then

[0137]

[0138] Where τ is a random number, satisfying

[0139] If S[i] = 1, then

[0140]

[0141] Finally, we obtain the split eigenvectors {Q′,Q″}.

[0142] (4) Trapdoor construction: The split feature vectors {Q′,Q″} are used to construct the trapdoor query information to be sent to the CSP through the invertible matrix {U1,U2}.

[0143] The technical solution of this invention constructs random user search tokens through random factor injection and dynamically allocates the token embedding trapdoor position using a pseudo-random function. This ensures that the query trapdoors generated by different users for the same image are not linked, solving the problem of cross-privacy leakage in multi-user scenarios. It also dynamically associates user identity with the ciphertext index to achieve fine-grained access control and prevent unauthorized searches. Breaking through the limitations of traditional single-user key systems, it achieves dynamic permission separation and privacy isolation for multiple users in ciphertext retrieval.

[0144] VI. Image Retrieval Stage (Search(I)) c ,T Q →CT):

[0145] CSP receives trapdoor information T Q Then, with the encrypted index information I of each re-encrypted image. ci A secure inner product is calculated to obtain a similarity score. The scores obtained from all re-encrypted image information are then sorted, and the top-K results are returned. Their final similarity score will be I0. ci ·T Q The specific calculation is as follows:

[0146]

[0147] Where rQ·I is the original similarity. t represents the redundancy, and t represents the offset.

[0148] The technical solution of this invention adopts a lightweight CNN for plaintext feature extraction. A lightweight model is used on the data owner (DO) side to reduce computational overhead, and on the image query user (DU) side to efficiently construct query information. It adopts encrypted similarity matching with secure inner product calculation, combined with partial re-encryption on the proxy server and cloud load balancing, to achieve efficient retrieval with sublinear time complexity. It balances privacy and efficiency and solves the problem of high computational complexity in traditional encrypted retrieval.

[0149] VII. Image Decryption Stage (Decrypt(CT,sk)→M):

[0150] After receiving the encrypted search result CT′, the image query user DU uses their private key sk DU The content key ck (i.e., the third key mentioned above) can be obtained by performing the following decryption calculation on the second key (i.e., the second key mentioned above):

[0151]

[0152] The image query user DU performs a verification process to determine the correctness of its decrypted ck′. The verification algorithm is shown in the following formula:

[0153] C′3=g H(ck′) ;

[0154] If the above formula is true, then the decryption key ck is correct, and the image information can be decrypted using this key:

[0155] M = Dec ck (CM);

[0156] The final result is the plaintext image retrieved by the image query user DU.

[0157] Compared to existing technologies, the efficient, secure, and verifiable multi-user image retrieval scheme in a cloud environment proposed in this invention systematically solves the challenges of synergistic optimization of privacy protection, result reliability, and efficiency. Specific technical effects are as follows:

[0158] (1) Strong privacy protection capabilities in multi-user scenarios

[0159] Unlinkability of Trapdoors: By using a dynamic user search token generation algorithm, a unique security token is assigned to each image query user (DU), and a random factor is embedded in the construction of the query trapdoor. This ensures that different image query users (DU) are indistinguishable from the query trapdoors generated for the same image, thus solving the risk of user behavior association caused by repeated trapdoors in traditional solutions.

[0160] Fine-grained access control: Based on a search token-bound encrypted indexing mechanism, it enables dynamic matching of user permissions with data granularity.

[0161] (2) End-to-end verifiable result integrity guarantee

[0162] Improved tamper detection accuracy: By embedding a layered hash verification code in the proxy re-encryption stage and generating ciphertext labels through two factors, the hash chain verification is automatically triggered when the image query user DU decrypts the data, which can 100% identify malicious filtering or tampering behavior of cloud servers on critical data.

[0163] (3) Synergistic breakthrough in security and retrieval efficiency

[0164] A lightweight CNN model is used, which has a faster feature extraction speed and improves the efficiency of constructing encrypted indexes; some encrypted calculations are transferred to the proxy server, and the data owner DO only needs to perform lightweight calculations; secure inner product calculation is used to ensure both efficiency and retrieval accuracy.

[0165] Example 2

[0166] Figure 3This is a schematic diagram of an image processing device according to an embodiment of the present invention. This embodiment is applicable to verifiable and efficient image processing supporting multiple users. The device can be implemented in software and / or hardware, and can be integrated into any device that provides image processing functionality, such as… Figure 3 As shown, the image processing device specifically includes: an encryption module 201, a generation module 202, a retrieval module 203, and a decryption module 204.

[0167] The encryption module 201 is used to acquire a set of plaintext images and encrypt the set of plaintext images to obtain a set of re-encrypted images.

[0168] The generation module 202 is used to acquire a query image and generate a query trapdoor based on the query image;

[0169] The retrieval module 203 is used to perform image retrieval in the re-encrypted image set based on the query trap to obtain the target re-encrypted image;

[0170] The decryption module 204 is used to decrypt the target re-encrypted image to obtain the target plaintext image.

[0171] Optionally, the encryption module 201 is specifically used for:

[0172] Obtain a set of plaintext images, and encrypt each plaintext image in the set of plaintext images based on a first key to obtain a set of pre-encrypted images;

[0173] Each pre-encrypted image in the pre-encrypted image set is re-encrypted based on the re-encryption key to obtain a re-encrypted image set.

[0174] Optionally, the generation module 202 is specifically used for:

[0175] Feature extraction is performed on the query image to obtain the feature vector corresponding to the query image;

[0176] Based on the search token, a query trapdoor is generated according to the feature vector corresponding to the query image.

[0177] Optionally, the device further includes:

[0178] The feature extraction unit is used to extract features for each plaintext image in the plaintext image set to obtain a feature vector corresponding to each plaintext image.

[0179] The generation unit is used to generate an encrypted index corresponding to each plaintext image based on the feature vector corresponding to each plaintext image;

[0180] The establishment unit is used to establish a mapping relationship between the encrypted index corresponding to the plaintext image and the re-encrypted image obtained after re-encrypting the plaintext image.

[0181] Optionally, the retrieval module 203 is specifically used for:

[0182] The similarity score for each re-encrypted image is determined based on the query trapdoor and the encryption index corresponding to each re-encrypted image.

[0183] The target re-encrypted image is determined based on the similarity score corresponding to each of the re-encrypted images.

[0184] Optionally, the decryption module 204 is specifically used for:

[0185] The second key is decrypted to obtain the third key, and the third key is then verified.

[0186] If the third key is successfully verified, the target re-encrypted image is decrypted based on the third key to obtain the target plaintext image.

[0187] The above-mentioned products can perform the image processing methods provided in any embodiment of the present invention, and have the corresponding functional modules and beneficial effects of performing the methods.

[0188] Example 3

[0189] Figure 4 A schematic diagram of an electronic device 30 that can be used to implement embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0190] like Figure 4As shown, the electronic device 30 includes at least one processor 31 and a memory, such as a read-only memory (ROM) 32 or a random access memory (RAM) 33, communicatively connected to the at least one processor 31. The memory stores computer programs executable by the at least one processor. The processor 31 can perform various appropriate actions and processes based on the computer program stored in the ROM 32 or loaded from storage unit 38 into the RAM 33. The RAM 33 can also store various programs and data required for the operation of the electronic device 30. The processor 31, ROM 32, and RAM 33 are interconnected via a bus 34. An input / output (I / O) interface 35 is also connected to the bus 34.

[0191] Multiple components in electronic device 30 are connected to I / O interface 35, including: input unit 36, such as keyboard, mouse, etc.; output unit 37, such as various types of monitors, speakers, etc.; storage unit 38, such as disk, optical disk, etc.; and communication unit 39, such as network card, modem, wireless transceiver, etc. Communication unit 39 allows electronic device 30 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0192] Processor 31 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 31 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 31 performs the various methods and processes described above, such as image processing methods:

[0193] Obtain a set of plaintext images and encrypt the set of plaintext images to obtain a set of re-encrypted images;

[0194] Obtain the query image and generate a query trapdoor based on the query image;

[0195] Based on the query trap, image retrieval is performed in the set of re-encrypted images to obtain the target re-encrypted image;

[0196] The target re-encrypted image is decrypted to obtain the target plaintext image.

[0197] In some embodiments, the image processing method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 38. In some embodiments, part or all of the computer program may be loaded and / or mounted on electronic device 30 via ROM 32 and / or communication unit 39. When the computer program is loaded into RAM 33 and executed by processor 31, one or more steps of the image processing method described above may be performed. Alternatively, in other embodiments, processor 31 may be configured to perform the image processing method by any other suitable means (e.g., by means of firmware).

[0198] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0199] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0200] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0201] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0202] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0203] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.

[0204] In one embodiment, the present invention further includes a computer program product, which includes a computer program that, when executed by a processor, implements the image processing method of any embodiment of the present invention.

[0205] In implementing the computer program product, computer program code for performing the operations of this invention can be written in one or more programming languages ​​or a combination thereof. Programming languages ​​include object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as C or similar languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0206] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0207] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. An image processing method, characterized in that, include: Obtain a set of plaintext images and encrypt the set of plaintext images to obtain a set of re-encrypted images; Obtain the query image and generate a query trapdoor based on the query image; Based on the query trap, image retrieval is performed in the set of re-encrypted images to obtain the target re-encrypted image; The target re-encrypted image is decrypted to obtain the target plaintext image.

2. The method according to claim 1, characterized in that, Obtain a set of plaintext images and encrypt the set of plaintext images to obtain a set of re-encrypted images, including: Obtain a set of plaintext images, and encrypt each plaintext image in the set of plaintext images based on a first key to obtain a set of pre-encrypted images; Each pre-encrypted image in the pre-encrypted image set is re-encrypted based on the re-encryption key to obtain a re-encrypted image set.

3. The method according to claim 1, characterized in that, Acquiring a query image and generating a query trapdoor based on the query image includes: Feature extraction is performed on the query image to obtain the feature vector corresponding to the query image; Based on the search token, a query trapdoor is generated according to the feature vector corresponding to the query image.

4. The method according to claim 2, characterized in that, After obtaining the plaintext image set, the following is also included: For each plaintext image in the plaintext image set, feature extraction is performed to obtain a feature vector corresponding to each plaintext image; An encrypted index is generated for each plaintext image based on the feature vector corresponding to each plaintext image; Establish a mapping relationship between the encrypted index corresponding to the plaintext image and the re-encrypted image obtained after re-encrypting the plaintext image.

5. The method according to claim 4, characterized in that, Based on the query trapdoor, image retrieval is performed in the re-encrypted image set to obtain the target re-encrypted image, including: The similarity score for each re-encrypted image is determined based on the query trapdoor and the encryption index corresponding to each re-encrypted image. The target re-encrypted image is determined based on the similarity score corresponding to each of the re-encrypted images.

6. The method according to claim 1, characterized in that, Decrypting the target re-encrypted image to obtain the target plaintext image includes: The second key is decrypted to obtain the third key, and the third key is then verified. If the third key is successfully verified, the target re-encrypted image is decrypted based on the third key to obtain the target plaintext image.

7. An image processing apparatus, characterized in that, include: An encryption module is used to acquire a set of plaintext images and encrypt the set of plaintext images to obtain a set of re-encrypted images; A generation module is used to acquire a query image and generate a query trapdoor based on the query image; The retrieval module is used to perform image retrieval in the re-encrypted image set based on the query trap to obtain the target re-encrypted image; The decryption module is used to decrypt the target re-encrypted image to obtain the target plaintext image.

8. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the image processing method according to any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the image processing method according to any one of claims 1-6.

10. A computer program product comprising a computer program that, when executed by a processor, implements the image processing method according to any one of claims 1-6.

Citation Information

Patent Citations

  • Intelligent similar image recognition and retrieval method and system

    CN119068267A

  • Image retrieval method and device

    CN119248954A