Quantum-key searchable encrypted document management method, device, and medium

By introducing quantum key technology into the searchable encryption scheme of the Bloom filter and using the correlation between the first array and the string array for further verification, the problem of false judgment in the Bloom filter is solved, and accurate keyword search is achieved.

CN121456916BActive Publication Date: 2026-04-07CAS QUANTUM NETWORK CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-01-06
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Existing searchable encryption schemes based on Bloom filters have a high false positive rate, leading to false positives and making it impossible to accurately determine whether keywords exist in the database.

Method used

By introducing quantum key distribution technology, the correlation between the first array, the first string array, and the second array can be used for further verification to avoid misjudgment.

Benefits of technology

It enables further validation of keywords after Bloom filter validation, ensuring the accuracy of query results, avoiding misjudgments, and guaranteeing the implementation of searchable encryption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121456916B_ABST
    Figure CN121456916B_ABST
Patent Text Reader

Abstract

This application relates to the field of quantum key technology, and discloses a searchable encryption document management method, device, and medium based on quantum keys. The method includes: receiving a query request carrying ciphertext with a query keyword; determining and verifying the target array bit corresponding to the ciphertext of the query keyword in a first array; querying the first string array associated with the target array bit based on the ciphertext of the query keyword; verifying the corresponding array bit in a second array indicated by the queried target key-value pair; obtaining the document ciphertext in the storage location of the second string array indicated by the target key-value pair and sending it to a first user, wherein the second string array includes at least one document ciphertext. This method achieves searchable encryption based on a Bloom filter while avoiding false positives.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of quantum key technology, and in particular to a searchable and encrypted document management method, device and medium based on quantum keys. Background Technology

[0002] Searchable Encryption (SE) is a cryptographic technique that supports keyword retrieval on ciphertext. Its core goal is to enable cloud servers to match user query keywords without decrypting the ciphertext, thereby returning the corresponding encrypted data. Bloom filters, an efficient probabilistic data structure often used to determine the existence of an element in a set, are therefore widely incorporated into searchable encryption schemes.

[0003] However, Bloom filters have a certain false positive rate, which means that searchable encryption schemes based on Bloom filters also have certain vulnerabilities. Summary of the Invention

[0004] This application provides a searchable encryption document management method, electronic device, and storage medium based on quantum key distribution, which can achieve searchable encryption based on Bloom filters while avoiding false positives.

[0005] This application provides a searchable encrypted document management method based on quantum key distribution, comprising: receiving a query request sent by a first user, wherein the query request carries ciphertext of a keyword to be queried, the ciphertext of the keyword to be queried being encrypted using a first key negotiated and determined by the first user and a second user, the second user being the user who uploaded the document; determining and verifying the target array position corresponding to the ciphertext of the keyword to be queried in a first array, wherein the first array is obtained by mapping stored keyword ciphertexts through a Bloom filter; if the target array position is verified, querying the first string array associated with the target array position based on the ciphertext of the keyword to be queried. In this process, the first string array includes at least one key-value pair. The key-value pair consists of the array position corresponding to the keyword ciphertext in the second array and the information of the storage location of the document ciphertext associated with the array position in the second array. The second array is obtained by mapping the stored document ciphertext through a Bloom filter. Based on the queried target key-value pair, the array position corresponding to the target key-value pair in the second array is verified. If the array position corresponding to the target key-value pair in the second array passes the verification, the document ciphertext in the storage location of the second string array indicated by the target key-value pair is obtained and sent to the first user. The second string array includes at least one document ciphertext.

[0006] This application also provides an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform a quantum key-based searchable encrypted document management method as provided in this application.

[0007] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the quantum key-based searchable encrypted document management method provided in this application.

[0008] The technical solution provided in this application has at least the following advantages:

[0009] By adding a second array and a first string array between the first array and the second string array storing the encrypted document, after verifying the keywords using the first array generated by the searchable encryption algorithm based on a Bloom filter, the second array can be retrieved using the key value formed by the array position of the keyword ciphertext in the second array and the information of the storage location of the encrypted document associated with the array position of the second array. This allows for further verification of the keywords using the second array, avoiding misjudgments caused by different keywords mapping to the same array position in the first array. Furthermore, the corresponding document can be found and returned to the user through the relationships between the first array, the first string array, the second array, and the second string array, ensuring the implementation of searchable encryption. Attached Figure Description

[0010] One or more embodiments are illustrated by way of example with reference numerals in the accompanying drawings. These illustrations do not constitute a limitation on the embodiments. Elements with the same reference numerals in the drawings are denoted as similar elements. Unless otherwise stated, the figures in the drawings are not to be limited by scale.

[0011] Figure 1 This is a flowchart of a quantum key-based searchable encrypted document management method provided in one embodiment of this application;

[0012] Figure 2 This is a schematic diagram illustrating the key negotiation and usage scenarios involved in the quantum key-based searchable encrypted document management method provided in one embodiment of this application;

[0013] Figure 3 This application Figure 1 A flowchart of step 102 of the quantum key-based searchable encrypted document management method provided in the illustrated embodiment;

[0014] Figure 4 This application Figure 1 Another flowchart of step 102 of the quantum key-based searchable encrypted document management method provided in the illustrated embodiment;

[0015] Figure 5 This application Figure 1 A flowchart of step 104 of the quantum key-based searchable encrypted document management method provided in the illustrated embodiment;

[0016] Figure 6 This is a schematic diagram of the structure of the second array and the second string array involved in the quantum key-based searchable encrypted document management method provided in one embodiment of this application;

[0017] Figure 7 This is a schematic diagram of the structure of the first array and the first string array involved in the quantum key-based searchable encrypted document management method provided in one embodiment of this application;

[0018] Figure 8 This is another flowchart of a quantum key-based searchable encrypted document management method provided in one embodiment of this application;

[0019] Figure 9 This is a partial flowchart of a quantum key-based searchable encrypted document management method provided in one embodiment of this application;

[0020] Figure 10 This is another partial flowchart of a quantum key-based searchable encrypted document management method provided in one embodiment of this application;

[0021] Figure 11 This is a schematic diagram of the structure of an electronic device provided in one embodiment of this application. Detailed Implementation

[0022] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the various embodiments of this application will be described in detail below with reference to the accompanying drawings. However, those skilled in the art will understand that many technical details have been presented in the various embodiments of this application to enable readers to better understand this application. However, the technical solutions claimed in this application can be implemented even without these technical details and various changes and modifications based on the following embodiments.

[0023] The division of the following embodiments is for ease of description and should not constitute any limitation on the specific implementation of this application. The various embodiments can be combined with and referenced by each other without contradiction.

[0024] Searchable encryption can be broadly categorized into Symmetric Searchable Encryption (SSE) and Public-key Encryption with Keyword Search (PEKS). Symmetric searchable encryption, based on symmetric cryptography, offers high computational efficiency and is suitable for single-user or trusted multi-user environments. Public-key searchable encryption, on the other hand, is based on public-key cryptography, supporting cross-user retrieval, but incurs greater computational overhead. Both require a trade-off between retrieval efficiency and privacy protection.

[0025] A Bloom filter is a probabilistic data structure that maps the elements to be stored to a Boolean array of length L using k independent hash functions, marking the corresponding positions as 1. During a query, the array positions are verified using the same hash function. If all positions are 1, the query element is determined to "possibly exist"; otherwise, the query element is determined to "definitely not exist", thus quickly filtering out invalid elements and reducing invalid traversals.

[0026] Therefore, by applying a Bloom filter to searchable encryption, it is possible to quickly determine whether a keyword belongs to a certain set.

[0027] However, searchable encryption schemes based on Bloom filters are prone to misjudgments due to the inherent false positives of Bloom filters, specifically, the possibility of false positives where elements that do not actually exist are identified as existing.

[0028] Further analysis revealed that the false positives of the Bloom filter stemmed from the fact that hash functions can produce the same output for different inputs. This means that different keywords 1 and 2 might be mapped to the same position 3 in the Boolean array. In this case, if keyword 1 exists in the database but keyword 2 does not, position 3 will be marked as "1" because keyword 1 exists in the database. Therefore, when querying keyword 2, position 3 will be found and the database will be determined to exist based on the mark of position 3 being 1, resulting in a false positive.

[0029] In other words, the false positives of searchable encryption schemes based on Bloom filters are due to the inability to distinguish which keyword caused the marker at that position to be formed after different keywords were mapped to the same position in the same Boolean array.

[0030] Based on this, this application provides a quantum key-based searchable encrypted document management method. By recording and maintaining the information of keywords mapped to each array bit, when determining the existence of a keyword using the mapped array bit, it is possible to further determine whether the content of the array bit was formed under the influence of the corresponding keyword based on the recorded information, thereby correctly determining whether the keyword is stored and avoiding misjudgments. For ease of understanding, the following will describe the quantum key-based searchable encrypted document management method provided in this application embodiment in conjunction with different processes.

[0031] In some embodiments, such as Figure 1 As shown, the quantum key-based searchable encrypted document management method includes the following steps:

[0032] Step 101: Receive a query request sent by the first user, wherein the query request carries the encrypted text of the keyword to be queried. The encrypted text of the keyword to be queried is obtained by encrypting it with a first key agreed upon by the first user and the second user, the user who uploaded the document.

[0033] Step 102: Determine the target array position corresponding to the ciphertext of the keyword to be queried in the first array and verify it. The first array is the stored keyword ciphertext obtained by mapping through a Bloom filter.

[0034] Step 103: If the target array position passes verification, query the first string array associated with the target array position according to the ciphertext of the keyword to be queried. The first string array includes at least one key-value pair. The key-value pair consists of the array position corresponding to the keyword ciphertext in the second array and the information of the storage location of the document ciphertext associated with the array position of the second array. The second array is obtained by mapping the stored document ciphertext through a Bloom filter.

[0035] Step 104: Based on the retrieved target key-value pair, verify the corresponding array position in the second array indicated by the target key-value pair.

[0036] Step 105: If the corresponding array bit in the second array indicated by the target key-value pair passes the verification, obtain the document ciphertext in the storage location of the second string array indicated by the target key-value pair and send it to the first user, wherein the second string array includes at least one document ciphertext.

[0037] Therefore, by adding a second array and a first string array between the first array and the second string array storing the encrypted document, after verifying the keywords using the first array generated by the searchable encryption algorithm based on a Bloom filter, it is possible to continue querying the second array using the key value composed of the array position of the keyword encrypted text in the second array and the information of the storage location of the encrypted document associated with the array position of the second array. This allows for further verification of the keywords using the second array, avoiding misjudgments caused by different keywords mapping to the same array position in the first array. Furthermore, the corresponding document can be found and returned to the user through the association between the first array, the first string array, the second array, and the second string array, ensuring the implementation of searchable encryption.

[0038] For ease of understanding Figure 1 The steps of the illustrated embodiment will be explained below.

[0039] In step 101, both the first user and the second user are users who can access the system (or device, apparatus, server, platform, etc.) that provides the quantum key-based searchable encrypted document management method in the embodiments of this application. The first user refers to the user who accesses the system (or device, apparatus, server, platform, etc.) and performs operations that do not change the content of the stored documents, while the second user refers to the user who accesses the system (or device, apparatus, server, platform, etc.) and performs operations that change the content of the stored documents.

[0040] It should be noted that the same user may be the first user to access the site in some scenarios, while in other scenarios they may be the second user, depending on the user's current access needs.

[0041] It should also be noted that the embodiments of this application do not limit the first key, which can be a quantum key negotiated and determined by the first user (also known as the data user (DU)) and the second user (also known as the data owner (DO)) through a quantum key distribution network (QKD). The second user can correspond to multiple first users, for example, such as... Figure 2 As shown, the second user DO can negotiate and determine the first key with the first user DU1 through the QKD network. The second user, DO, can negotiate and determine the first key with the first user, DU2, through the QKD network. The second user DO can negotiate and determine the first key with the first user DU3 through the QKD network. Therefore, the quantum key determined through the above negotiation can then be used to interact with the cloud server (a hypothetical system based on searchable encrypted document management, capable of executing the quantum key-based searchable encrypted document management method provided in this application embodiment). Of course, the first key can also be a key determined through key system negotiation, etc.

[0042] For the first user, when they need to query certain keywords, they can encrypt the keywords they need to query using the corresponding first key, thereby obtaining the ciphertext of the keywords to be queried, and then initiate a query request based on the ciphertext of the keywords to be queried.

[0043] Furthermore, in some embodiments, to further enhance security, the first key can be updated periodically. The update cycle of the first key can be flexibly configured according to needs, business conditions, or scenarios. For example, the update cycle of the first key can be determined based on the cost of the key, the security decay of encrypting data multiple times with the same key, and the risk of data leakage after revoking user permissions. In this application, the method for determining the update cycle of the first key is not limited, and it can be determined using the following expression:

[0044] ;

[0045] in, For preset and , and The relevant functions, The update cycle for the first key. , and To determine the weight parameters based on business needs, application scenarios, etc. For the cost of the key, Security attenuation for encrypting data multiple times with the same key. The risk of data leakage after user permissions are revoked.

[0046] In step 102, since the first array is obtained by mapping the stored keyword ciphertext through a Bloom filter, the determination and verification of the target array bit will be determined in a corresponding manner using a searchable encryption algorithm based on a Bloom filter. Specifically, the ciphertext of the query keyword is mapped according to the hash algorithm given by the searchable encryption algorithm based on a Bloom filter. The mapping result is then moduloed by the length of the first array to determine the target array bit. Finally, it is determined whether the value at that target array bit is "1". If it is "1", the verification is considered successful; otherwise, the verification fails.

[0047] It should be noted that when the searchable encryption algorithm based on the Bloom filter has multiple hash algorithms, multiple array bits will be determined as target array bits. If all array bits in the target array bit are "1", the verification is considered successful; otherwise, the verification fails.

[0048] In some embodiments, the query request also carries ciphertext of the first user's identity identifier, which is obtained by encrypting the first user's identity identifier using a second key negotiated and determined by the first user and the second user. It should be noted that this application embodiment does not limit the second key; it can be a quantum key negotiated and determined by the first user and the second user through a quantum key distribution network. The second user can correspond to multiple first users, for example, such as... Figure 2 As shown, the second user DO can negotiate and determine the second key with the first user DU1 through the QKD network. The second user, DO, can negotiate and determine the second key with the first user, DU2, through the QKD network. The second user DO can negotiate and determine the second key with the first user DU3 through the QKD network. Therefore, the quantum key determined through the above negotiation can then interact with the cloud server (a hypothetical system based on searchable encrypted document management, capable of executing the quantum key-based searchable encrypted document management method provided in this application embodiment). Of course, the second key can also be a key determined through key system negotiation, etc.

[0049] Accordingly, such as Figure 3 As shown, step 102 can be achieved through the following steps:

[0050] Step 102a: Verify the first user based on the encrypted identity of the first user.

[0051] Step 102b: If the first user passes the verification, determine the target array position corresponding to the encrypted keyword in the first array and verify it.

[0052] This allows for the restriction of user access by setting up a user permission verification mechanism, thereby further enhancing security.

[0053] It should be noted that, to further enhance security, the second key can be updated periodically. The update cycle of the second key can be flexibly configured according to requirements, business conditions, or scenarios. For example, the update cycle can be determined based on the cost of the key, the security decay of encrypting data multiple times with the same key, and user permission update constraints. This application does not limit the method for determining the update cycle of the second key; it can be determined using the following expression:

[0054] ;

[0055] in, For preset and , and The relevant functions, This is the update cycle for the second key. , and To determine the weight parameters based on business needs, application scenarios, etc. For the cost of the key, Security attenuation for encrypting data multiple times with the same key. Constraints on updating user permissions.

[0056] In some embodiments, such as Figure 4 As shown, step 102 can be achieved through the following steps:

[0057] Step 102c: Based on the first access control policy set by the second user, detect whether the first user has query permission for the keyword to be queried, wherein the first access control policy is used to control access to the keyword.

[0058] Step 102d: If the first user has the query permission for the keyword to be queried, determine the target array position corresponding to the encrypted text of the keyword to be queried in the first array and verify it.

[0059] The first access control policy can be pre-stored or pre-configured so that it can be used for keyword permission verification later.

[0060] This allows for the restriction of user access to keywords by setting up a keyword permission verification mechanism, thereby further enhancing security.

[0061] Of course, the above are just examples. In some embodiments, permission verification may not be required, or other methods may be used for permission verification, which will not be listed here.

[0062] In step 103, at least one key-value pair included in the first string array contains information about the storage location of the document ciphertext associated with the array position corresponding to the keyword ciphertext in the second array and the array position of the second array. Therefore, after determining the ciphertext of the keyword to be queried, the ciphertext of the keyword to be queried can be used as a basis to perform a query in the first string array, thereby determining the corresponding key-value pair.

[0063] In step 104, the corresponding array position of the second array is mapped to the document using the corresponding hash function, and the mapping result is modulo the length of the second array to determine the corresponding position. The value of the position is modified to "1", so that the array position of the second array is also checked to determine whether it passes the verification by checking whether the value at the position is "1".

[0064] In some embodiments, such as Figure 5 As shown, step 104 can be achieved through the following steps:

[0065] Step 104a: Based on the second access control policy set by the second user, detect whether the first user has query permission for the document, wherein the second access control policy is used to control access to the document.

[0066] Step 104b: If the first user has query permissions for the document, verify the corresponding array position in the second array indicated by the target key-value pair based on the queried target key-value pair.

[0067] The second access control policy can be pre-stored or pre-configured so that it can be used for document permission verification later.

[0068] This allows for the restriction of user access to documents by setting up a document permission verification mechanism, thereby further enhancing security.

[0069] Of course, the above are just examples. In some embodiments, permission verification may not be required, or other methods may be used for permission verification, which will not be listed here.

[0070] In step 105, since the second string array contains the document ciphertext, the document ciphertext can be read from it by determining its storage location within the second string array. The document ciphertext associated with the array bits in the second array is obtained by encrypting it with a third key.

[0071] It should be noted that the embodiments of this application do not limit the third key, which can be a quantum key negotiated and determined by the first user and the second user through a quantum key distribution network. The second user can correspond to multiple first users, for example, such as... Figure 2 As shown, the second user DO can negotiate with the first user DU1 through the QKD network to determine the third key. The second user, DO, can negotiate and determine the third key with the first user, DU2, through the QKD network. The second user, DO, can negotiate with the first user, DU3, through the QKD network to determine the third key. Therefore, the quantum key determined through the above negotiation can then interact with the cloud server (a hypothetical system based on searchable encrypted document management, capable of executing the quantum key-based searchable encrypted document management method provided in this application embodiment). Of course, the third key can also be a key determined through key system negotiation, etc.

[0072] It should also be noted that, in some embodiments, to further enhance security, the third key can be updated periodically. The update cycle of the third key can be flexibly configured according to needs, business conditions, or scenarios. For example, the update cycle of the third key can be determined based on the cost of the key, the security decay of encrypting data multiple times with the same key, and the risk of data leakage after revoking user permissions. However, this application does not limit the method for determining the update cycle of the third key; it can be determined using the following expression:

[0073] ;

[0074] in, For preset and , and The relevant functions, The update cycle for the third key. , and To determine the weight parameters based on business needs, application scenarios, etc. For the cost of the key, Security attenuation for encrypting data multiple times with the same key. The risk of data leakage after user permissions are revoked.

[0075] For ease of understanding Figure 1 The illustrated embodiment will be described below in conjunction with Figure 6 and Figure 7 The structure of the arrays and string arrays shown is explained.

[0076] Assuming that it is already stored 1 document, and the collection formed by these documents for For each of these documents In other words, it contains several keywords. Assume a set. The set of keywords contained in all documents ,gather for (i.e., assuming a collection of documents) Total of (one keyword), then the keyword This will create an inverted index. Keywords Appears in several documents middle.

[0077] Based on the above assumptions, the construction of the first array, the second string array, the second array, and the second string array will be explained below.

[0078] like Figure 6 As shown, initialize a A 2-bit Boolean array (BA) As the second array, Each array element in the array is initially set to 0. Then, the calculation is performed. ,Will ( Refers to numerical values exist Set the array bit (indicated by the pointer in the middle) to 1, and point that array bit to a string array (SA). (i.e., the second string array), will Values ​​inserted in sequence In the middle, record the serial number. .in, This indicates the modulo operation (the same applies below, so I won't go into detail again). satisfy:

[0079] ;

[0080] in, For As the key and with Encryption algorithms that run for encrypting objects , The aforementioned third key is a symmetric key negotiated between the second user and the first user through a QKD device.

[0081] At the same time, such as Figure 7 As shown, initialize a A 2-bit Boolean array (BA) As the first array, Each array element in the array is initially set to 0. Calculate... ,in, Indicates For encryption key pair keywords Encryption algorithm used The result obtained after encryption. For the calculated result... ,Will ( Refers to numerical values exist Set the array bit (indicated by the pointer in the middle) to 1, and point that array bit to a string array (SA). (i.e., the first string array), will Chinese keywords hash value and corresponding documents exist All locations and in The serial number in As a key-value pair Sequential insertion In the middle, record the serial number. .

[0082] Based on this, the first control access policy can be a set ACP-KW, with the following format: The second access control policy can be a set of ACP-D, the format of which is: ,in, l Indicates the first user The serial number, Keywords The serial number, To represent a document The serial number, , , , The total number of first users, is the total number of keywords, and m is the total number of documents.

[0083] Therefore, when the first user Need to search for keywords At that time, it will utilize the first key it possesses. Keywords Encryption is performed to obtain the ciphertext of the keyword to be queried. Then based on A query request is sent, and the cloud server (CS) (a hypothetical system based on searchable encrypted document management, capable of executing the quantum key-based searchable encrypted document management method provided in this application embodiment) finds the target array bits. And check if the value at that position is 1; if so, continue iterating. Pointing to Associated key-value pairs and according to Further find Pointing to Stored value and return to If any of the above queries fails, then the first user is not reached. The keyword does not exist.

[0084] If the cloud server has a user permission verification mechanism, and this user permission verification mechanism is implemented through the Access Control Policy (ACP) set ACP-U, the format of ACP-U can be:

[0085] ;

[0086] in, The first user Identity value; It is DO and The symmetric key negotiated through the QKD device is used to determine the identity of the cloud server. identity; This refers to the fine-grained definition of user operation permissions, which can be the number of accesses or the access time range, etc. DO stores the ACP-U on the cloud server for subsequent user permission verification. So, the first user... Also using a second key Generate identity identifier ciphertext Therefore, based on Send a query request. Simultaneously, the cloud server needs to check before performing the query. If the query complies with the first access control policy ACP-U, and does not comply, the corresponding reason will be returned; otherwise, the aforementioned query operation will continue.

[0087] In some embodiments, the query request carries at least two ciphertexts of the keywords to be queried, and the query request also carries a query logical relationship indicating the different ciphertexts of the keywords to be queried. The query logical relationship includes: both belonging to the same document, at least one belonging to a document, at least one belonging to a document and at least the other not belonging to a document, etc. Accordingly, such as Figure 8 As shown, a quantum key-based searchable encrypted document management method may include the following steps:

[0088] Step 801: Receive a query request sent by the first user, wherein the query request carries the ciphertext of the keyword to be queried. The ciphertext of the keyword to be queried is obtained by encrypting it with a first key agreed upon by the first user and the second user, the user who uploaded the document.

[0089] Step 802: Determine the target array position corresponding to the ciphertext of each keyword to be queried in the first array and verify it.

[0090] Step 803: If all the target array positions corresponding to the ciphertext of all the keywords to be queried in the first array have passed the verification, then query the first string array associated with the target array position respectively.

[0091] Step 804: Based on all the target key-value pairs retrieved, verify the corresponding array positions in the second array indicated by each target key-value pair.

[0092] Step 805: If the corresponding array bit in the second array indicated by the target key-value pair passes the verification, verify whether the encrypted document in the storage location of the second string array indicated by the target key-value pair conforms to the query logic relationship, and send the verified encrypted document to the first user.

[0093] This allows for the querying of multiple keywords based on a single query request, or the querying of keyword combinations based on certain logical relationships, thus improving query efficiency and user experience.

[0094] It is not difficult to see that Figure 8 The illustrated embodiments and Figure 1 The embodiments shown are largely the same, the main difference being the number of keywords queried. The steps will not be described in detail here.

[0095] For ease of understanding Figure 8 The illustrated embodiment is described below in conjunction with the foregoing. Figure 6 , Figure 7 The corresponding example provides an explanation of the first array, the first string array, the second array, and the second string array.

[0096] For example, the first user When you need to search for keywords When using the second key generate ,use Process separately The keywords in the text will yield { },in, , The following will not be listed one by one. Then the first user is based on 、{ A query request is sent to the cloud server, which also indicates the corresponding query logic relationship, using keywords. and keywords Taking a query as an example, the query logic relationship can include: , and The "and" signifies an AND logical relationship, i.e., the query keyword. and keywords Documents that both exist; "or" indicates an OR logical relationship, i.e., query keywords. and keywords Documents containing at least one of the specified terms; "not" indicates a non-logical relationship, i.e., the query keyword. Existence but keywords Document not found.

[0097] Accordingly, the cloud server received 、{ After that, first check Does it conform to set ACP-U? If so, find them respectively. , ...corresponding to the target array positions and checking if the values ​​in these array positions are all 1. If all values ​​are 1, then iterate through... , ...pointing to of , ...Assuming the query logical relation bits include Then the cloud server will search and If there is a consistent document value, return 1; otherwise, return 0. Assume the query logical relationships include... Then the cloud server will search and If a corresponding document value exists, return 1; otherwise, return 0. Assume the query logical relation includes... Then the cloud server will search Does it contain a set? If a document value is not found in the table, return 1 if it is found, otherwise return 0.

[0098] Therefore, as can be seen from the above examples, the quantum key-based searchable encrypted document management method provided in this application embodiment can provide rich keyword query capabilities, and in addition to supporting general query methods, it can also support Boolean queries.

[0099] For example, if the default query logic is always an AND relationship, then the first user... When you need to search for keywords When using the second key generate ,use Process separately The keywords in the text will yield { },in, , The following will not be listed one by one. Then the first user is based on 、{ A query request is sent to the cloud server.

[0100] Accordingly, the cloud server received 、{ After that, first check Does it conform to set ACP-U? If so, find them respectively. , ...corresponding to the target array positions and checking if the values ​​in these array positions are all 1. If all values ​​are 1, then iterate through... , ...pointing to of , ...Assuming the query logical relation bits include Then the cloud server will search , If there are overlapping document values, return 1; otherwise, return 0.

[0101] Therefore, as can be seen from the above examples, the quantum key-based searchable encrypted document management method provided in this application embodiment can provide rich keyword query capabilities, and in addition to supporting general query methods, it can also support joint queries.

[0102] Of course, the above are just examples. In some embodiments, there may be other query logic relationships, which will not be listed here.

[0103] In some embodiments, such as Figure 9 As shown, a quantum key-based searchable encrypted document management method may include the following steps:

[0104] Step 901: Receive an add request sent by the second user, wherein the add request carries the document to be added.

[0105] Step 902: Determine the corresponding array position of the document to be added in the second array based on the encrypted text of the document to be added.

[0106] Step 903: Adjust the value of the corresponding array position of the document to be added in the second array to the target value, and write the ciphertext of the document to be added into the second string array corresponding to the corresponding array position of the document to be added in the second array.

[0107] Step 904: Based on the ciphertext of each keyword in the document to be added, determine the corresponding array position of each keyword in the first array.

[0108] Step 905: The information of the array position corresponding to the document to be added in the second array and the storage position of the second string array corresponding to the array position of the document to be added in the second array are taken as a key-value pair and written into the first string array associated with the array position of each keyword in the corresponding document to be added in the first array.

[0109] In some embodiments, such as Figure 10 As shown, a quantum key-based searchable encrypted document management method may include the following steps:

[0110] Step 1001: Receive a deletion request sent by the second user, wherein the deletion request carries the document to be deleted.

[0111] Step 1002: Determine the corresponding array position of the document to be deleted in the second array based on the encrypted text of the document to be deleted.

[0112] Step 1003: Verify the corresponding array position of the document to be deleted in the second array.

[0113] Step 1004: If the corresponding array position of the document to be deleted in the second array passes the verification, determine the corresponding array position of the ciphertext of each keyword in the document to be deleted in the first array based on the ciphertext of each keyword in the document to be deleted.

[0114] Step 1005: In the first string array associated with the array position corresponding to each keyword in the first array of the document to be deleted, delete the key-value pair represented by the information of the storage position of the corresponding array position of the document to be deleted in the second array of the second string array.

[0115] By providing mechanisms for adding and deleting documents, it can better meet users' content modification requirements and satisfy their flexible and ever-changing needs, thereby further enhancing the user experience.

[0116] Understandable Figure 9 and Figure 10 The embodiments shown are the add and delete operations corresponding to the query operations provided in the foregoing embodiments. The relevant features are corresponding and will not be repeated here. The following descriptions are mainly for ease of understanding and will be combined with... Figure 6 and Figure 7 The examples shown, including the first array, the second array, the first string array, and the second string array, provide examples of the relevant process implementation.

[0117] Assuming a document to be added The set of keywords is Then first calculate , ,Will Set to 1 (if) If the value is already 1, then it remains unchanged; if If the value is 0, change it to 1), and point the array bit to... (Wakahara Then use the original Otherwise, add one. ),Will Values ​​inserted in sequence In the middle, record the serial number. Next, regarding ,calculate For the calculated ,Will Set to 1 (if) If the value is already 1, then it remains unchanged; if If the value is 0, change it to 1), and point the array bit to... (Wakahara Then use the original Otherwise, add one. ),Will Chinese keywords hash value and corresponding documents exist The position in the middle and in The serial number in As a key-value pair Sequential insertion (If the original) The string array it points to There exists For key-value pairs, append to the value. ), and record the serial number. .

[0118] Assuming the document to be deleted The set of keywords is Then first calculate , ,exist Search Check if it is 1 (if it was originally 0, the document does not exist and cannot be deleted), and query the pointers of the array bits. ,turn up Value and serial number (If not found, the document does not exist and cannot be deleted.) Next, regarding... ,calculate For the calculated ,exist Search (Generally, it is 1), and then query the pointer of that array bit. ,Will Chinese keywords hash value and corresponding documents exist The position in the middle and in The serial number in key-value pairs delete.

[0119] As can be seen from the above description, in some embodiments, the quantum key-based searchable encryption document management method provided in this application can achieve fine-grained management permission control by setting user permission verification, document permission verification and / or keyword permission verification; in some embodiments, quantum keys can be used as keys and key update mechanisms to further protect the security of searchable encryption.

[0120] The steps of the various methods described above are only for clarity. In practice, they can be combined into one step or some steps can be split into multiple steps. As long as they include the same logical relationship, they are all within the scope of protection of this application. Adding insignificant modifications or introducing insignificant designs to the algorithm or process, but without changing the core design of the algorithm and process, are also within the scope of protection of this application.

[0121] This application also provides an electronic device, such as... Figure 11 As shown, it includes: at least one processor 1101; and a memory 1102 communicatively connected to at least one processor 1101; wherein the memory 1102 stores instructions executable by at least one processor 1101, the instructions being executed by at least one processor 1101 to enable at least one processor 1101 to perform the method described in any of the above method embodiments.

[0122] The memory 1102 and processor 1101 are connected via a bus. This bus can include any number of interconnecting buses and bridges, connecting various circuits of one or more processors 1101 and memory 1102. The bus can also connect various other circuits, such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. A bus interface provides an interface between the bus and the transceiver. The transceiver can be a single element or multiple elements, such as multiple receivers and transmitters, providing a unit for communicating with various other devices over a transmission medium. Data processed by processor 1101 is transmitted over a wireless medium via an antenna, which further receives data and transmits it to processor 1101.

[0123] Processor 1101 is responsible for managing the bus and general processing, and can also provide various functions, including timing, peripheral interfaces, voltage regulation, power management, and other control functions. Memory 1102 can be used to store data used by processor 1101 during operation.

[0124] This application also provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it implements the above-described method embodiments.

[0125] That is, those skilled in the art will understand that all or part of the steps in the methods of the above embodiments can be implemented by a program instructing related hardware. This program is stored in a storage medium and includes several instructions to cause a device (which may be a microcontroller, chip, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, a portable hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0126] Those skilled in the art will understand that the above embodiments are specific embodiments for implementing this application, and in practical applications, various changes can be made to them in form and detail without departing from the spirit and scope of this application.

Claims

1. A searchable and encrypted document management method based on quantum key distribution, characterized in that, include: The system receives a query request sent by a first user, wherein the query request carries the encrypted text of the keyword to be queried, and the encrypted text of the keyword to be queried is obtained by encrypting it with a first key determined by the first user and the second user, wherein the second user is the user who uploaded the document. The target array position corresponding to the ciphertext of the keyword to be queried in the first array is determined and verified, wherein the first array is obtained by mapping the stored keyword ciphertext through a Bloom filter; If the target array position passes verification, a query is performed in the first string array associated with the target array position based on the ciphertext of the keyword to be queried. The first string array includes at least one key-value pair, which consists of the array position corresponding to the keyword ciphertext in the second array and the information of the storage location of the document ciphertext associated with the array position in the second array. The second array is obtained by mapping the stored document ciphertext through a Bloom filter. Based on the retrieved target key-value pair, verify the corresponding array position in the second array indicated by the target key-value pair; If the corresponding array bit in the second array indicated by the target key-value pair passes verification, the encrypted document in the storage location of the second string array indicated by the target key-value pair is obtained and sent to the first user, wherein the second string array includes at least one encrypted document.

2. The quantum key-based searchable encrypted document management method according to claim 1, characterized in that, The query request also carries the encrypted identity of the first user, wherein the encrypted identity of the first user is obtained by encrypting it with a second key agreed upon by the first user and the second user. The step of determining and verifying the target array position corresponding to the ciphertext of the keyword to be queried in the first array includes: The first user is verified based on the encrypted identity of the first user. If the first user passes the verification, the target array position corresponding to the encrypted text of the keyword to be queried in the first array is determined and verified.

3. The quantum key-based searchable encrypted document management method according to claim 2, characterized in that, The method further includes: The update cycle for the second key is determined based on the cost of the key, the security decay of encrypting data multiple times with the same key, and the user permission update constraints, so as to update the second key.

4. The quantum key-based searchable encrypted document management method according to claim 2, characterized in that, The step of determining and verifying the target array position corresponding to the ciphertext of the keyword to be queried in the first array includes: If the first user passes the verification, the system checks whether the first user has the right to query the keyword according to the first access control policy set by the second user. The first access control policy is used to control access to the keyword. If the first user has query permission for the keyword to be queried, determine the target array position corresponding to the encrypted text of the keyword to be queried in the first array and verify it; And / or, The step of verifying the corresponding array position in the second array indicated by the queried target key-value pair includes: Based on the second access control policy set by the second user, it is detected whether the first user has the permission to query the document, wherein the second access control policy is used to control access to the document; If the first user has query permissions for the document, the corresponding array position in the second array indicated by the target key-value pair is verified based on the retrieved target key-value pair.

5. The quantum key-based searchable encrypted document management method according to any one of claims 1 to 4, characterized in that, The number of encrypted texts containing the keywords to be queried in the query request is not less than 2, and the query request also carries a query logic relationship indicating the different encrypted texts containing the keywords to be queried. The query logic relationship includes: both belonging to the same document, at least one belonging to the document, and at least one belonging to the document and at least the other not belonging to the document. The step of determining and verifying the target array position corresponding to the ciphertext of the keyword to be queried in the first array includes: The corresponding target array position in the first array for each of the ciphertexts of the keywords to be queried is determined and verified; If the target array position passes verification, the query is performed in the first string array associated with the target array position based on the ciphertext of the keyword to be queried, including: If all the encrypted texts of the keywords to be queried pass verification in the target array positions corresponding to the first array, then queries are performed in the first string array associated with the target array positions respectively; The step of verifying the corresponding array position in the second array indicated by the queried target key-value pair includes: Based on all the target key-value pairs retrieved, verify the corresponding array positions in the second array indicated by each target key-value pair; If the corresponding array bit in the second array indicated by the target key-value pair passes verification, the document ciphertext in the storage location of the second string array indicated by the target key-value pair is obtained and sent to the first user, including: If the corresponding array bit in the second array indicated by the target key-value pair passes the verification, verify whether the encrypted document in the storage location of the second string array indicated by the target key-value pair conforms to the query logic relationship, and send the verified encrypted document to the first user.

6. The quantum key-based searchable encrypted document management method according to any one of claims 1 to 4, characterized in that, The method further includes: Receive an add request sent by the second user, wherein the add request carries the document to be added; Based on the ciphertext of the document to be added, determine the array position of the document to be added in the second array; Adjust the value of the array position corresponding to the document to be added in the second array to the target value, and write the ciphertext of the document to be added into the second string array corresponding to the array position corresponding to the document to be added in the second array; Based on the ciphertext of each keyword in the document to be added, determine the corresponding array position of each keyword in the first array; The information of the array position corresponding to the document to be added in the second array and the storage position of the array position corresponding to the document to be added in the second array in the second string array are taken as a key-value pair and written into the first string array associated with the array position corresponding to the ciphertext of each keyword in the document to be added in the first array.

7. The quantum key-based searchable encrypted document management method according to any one of claims 1 to 4, characterized in that, The method further includes: Receive a deletion request sent by the second user, wherein the deletion request carries the document to be deleted; Based on the encrypted text of the document to be deleted, determine the array position of the document to be deleted in the second array; Verify the array position corresponding to the document to be deleted in the second array; If the array position corresponding to the document to be deleted in the second array passes the verification, the array position corresponding to the ciphertext of each keyword in the document to be deleted in the first array is determined according to the ciphertext of each keyword in the document to be deleted. In the first string array associated with the corresponding array position of each keyword in the document to be deleted in the first array, the corresponding array position of the document to be deleted in the second array is deleted, and the key-value pair represented by the information of the storage position of the corresponding array position of the document to be deleted in the second string array is deleted.

8. The quantum key-based searchable encrypted document management method according to any one of claims 1 to 4, characterized in that, The encrypted document associated with the array bits in the second array is obtained by encrypting it with a third key; The method further includes: The update cycle of the first key and / or the third key is determined based on the cost of the key, the security decay of encrypting data multiple times with the same key, and the risk of data leakage after revoking user permissions.

9. An electronic device, characterized in that, include: At least one processor; as well as, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, enables the at least one processor to perform the quantum key-based searchable encrypted document management method as described in any one of claims 1 to 8.

10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the quantum key-based searchable encrypted document management method as described in any one of claims 1 to 8.

Citation Information

Patent Citations

  • Large-data-volume secret key duplication removal method and system based on Bloom filter

    CN113590606A

  • Symmetrical searchable encryption method and device, equipment and medium

    CN117786751A