Cloud service-oriented on-lattice attribute-based connection keyword search method
By designing an attribute-searchable encryption scheme based on a lattice cryptography system, the problems of multi-user, multi-keyword search and quantum computing threats in cloud services are solved, enabling multi-user ciphertext search and access control, and improving the security and efficiency of data sharing.
Patent Information
- Application Number
- CN202511486865.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-17
- Publication Date
- 2026-02-17
AI Technical Summary
Existing attribute-searchable encryption schemes cannot support multi-user connection searches for multiple keywords in cloud services, and cannot defend against quantum computing attacks.
The system employs a lattice cryptography system to design an attribute-searchable encryption scheme. It utilizes trapdoor generation algorithms and lattice basis generation algorithms to generate keys, and combines threshold secret sharing technology to achieve multi-user ciphertext search and access control. It supports concatenation keyword search and generates search trapdoors through a generalized lattice basis sampling algorithm.
It enables multi-user encrypted text search and access control in cloud service environments, can resist quantum computing attacks, supports keyword search, and improves the security and efficiency of data sharing.
Smart Images

Figure CN121542494A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of attribute-based encrypted access control, and more particularly to a lattice-based attribute base join keyword search method for cloud services. Background Technology
[0002] With the continuous development of information technology, people's demand for data search and sharing is increasing. To reduce local storage costs, data owners typically store data on cloud servers, making cloud service technology a focus of widespread attention in academia and industry. However, data stored on cloud servers faces a series of security issues. Attackers can illegally access sensitive data on cloud servers, causing privacy leaks during the access process. To achieve confidential data storage, data owners use encryption algorithms to process the data and store the generated ciphertext on the cloud server. While this solution can guarantee data confidentiality, it renders plaintext-based keyword search technology ineffective, reduces data availability, and hinders data sharing. Therefore, in cloud service scenarios, how to achieve data search and sharing while ensuring data confidentiality has become a critical issue that urgently needs to be addressed.
[0003] The concept of Public Key Encryption with Keyword Search (PEKS) was first proposed by Boneh et al. in 2004, enabling encrypted search of cloud data. Currently, most PEKS schemes are primarily designed for single-user scenarios, meaning only one user can search the encrypted data. In many practical applications, multi-user search scenarios are more common. For example, in cloud service environments, data users typically come from different fields (medical, manufacturing, research, etc.), and these users all need to perform encrypted searches of data on cloud servers, and may even require access control. In recent years, many searchable encryption primitives supporting multiple users have been proposed. Among them, attribute-based searchable encryption schemes not only support multi-user encrypted search but also enable access control, attracting widespread attention from researchers.
[0004] However, attribute-searchable encryption schemes also have significant limitations in the face of increasingly complex cloud data search needs. Firstly, data users may need to search for encrypted information containing multiple keywords at once, which attribute-searchable encryption schemes that only support single-keyword functionality cannot accomplish. Therefore, enabling attribute-searchable encryption schemes to support concatenated keywords is a challenge that urgently needs to be addressed.
[0005] Secondly, with the development of quantum computers, the emergence of Shor's quantum search algorithm has enabled the solution of classical hard assumptions such as discrete logarithms in polynomial time, seriously threatening the security of classical cryptographic algorithms. Most existing property-searchable encryption schemes are based on bilinear mappings for their underlying construction and cannot withstand quantum computing attacks. Lattice cryptography, as one of the important research directions in post-quantum cryptography, has attracted widespread attention from researchers. On the one hand, lattice cryptography mainly relies on matrix operations and linear operations, which have higher computational efficiency compared to modular exponentiation and pairing operations in bilinear mappings. This makes it more suitable for the design of encryption algorithms, trapdoor generation algorithms, and testing algorithms in multi-user searchable encryption schemes, reducing end-to-end latency. On the other hand, the security of lattice cryptography is usually based on error learning and the small integer solution hard assumption. Their average difficulty is equivalent to the worst-case lattice hard assumption, and current research considers them capable of withstanding quantum computing attacks. Therefore, designing property-searchable encryption schemes based on lattice cryptography holds promise for addressing the aforementioned challenges. Summary of the Invention
[0006] In view of this, embodiments of the present invention provide a lattice-based attribute-based join keyword search method for cloud services, in order to eliminate or improve one or more defects existing in the prior art.
[0007] One aspect of the present invention provides a lattice-based attribute-based join keyword search method for cloud services, the method comprising the following steps:
[0008] Step (1): The Trusted Authority Center receives the system initialization request, generates the first dimension parameter, the second dimension parameter, the modulus parameter, the first Gaussian parameter, the second Gaussian parameter, the number of attributes, and the number of keywords. It uses the TrapGen algorithm in lattice cipher to generate the first common matrix and the first lattice basis matrix. It randomly selects the first common matrix, the second common matrix, the common attribute matrix, the common keyword matrix, and the third common matrix. The Trusted Authority Center sets the first lattice basis matrix as the master private key and keeps it. It sets the other parameters as public parameters and publishes them to other entities.
[0009] Step (2): The data owner and the data user submit a key application request to the Trusted Authority Center. For the data owner, the Trusted Authority Center uses the TrapGen algorithm in lattice cipher to generate a first public key matrix and a first private key matrix. The first public key matrix is used as the public key and the first private key matrix is used as the private key, and the data owner is sent to the data owner. For the data user, the Trusted Authority Center sets a first intermediate matrix and uses the SampleBasis algorithm in lattice cipher to generate a second private key vector. The second private key vector is used as the private key and sent to the data user.
[0010] Step (3): The data owner sets the access policy according to the threshold secret sharing method, randomly selects the encryption random vector, the first perturbation vector, the second perturbation vector, the third perturbation vector and the fourth perturbation vector, generates the first ciphertext, the second ciphertext, the third ciphertext and the fourth ciphertext, and uses the first ciphertext, the second ciphertext, the third ciphertext and the fourth ciphertext to form the keyword ciphertext, and uploads it to the cloud server.
[0011] Step (4): The data user calculates the first intermediate vector, selects a polynomial, sets the second intermediate vector, calls the generalized lattice basis sampling algorithm GenSamplePre in lattice cipher to generate the first trapdoor vector, uses the first trapdoor vector to form a search trapdoor, and uploads it to the cloud server.
[0012] Step (5): The cloud server sets the fourth ciphertext and calculates the third intermediate vector. For the user attribute set, access policy set and threshold value, if the number of intersection elements of the user attribute set and access policy set is greater than the threshold value, the search results are calculated using the first ciphertext, the first trapdoor vector, the second ciphertext, the third intermediate vector and the third ciphertext.
[0013] In some embodiments of the present invention, the common parameters in step (1) include a first dimension parameter, a second dimension parameter, a modulus parameter, a first Gaussian parameter, a second Gaussian parameter, the number of attributes, the number of keywords, a first common matrix, a second common matrix, a common attribute matrix, a common keyword matrix, a third common matrix, and a system attribute set. The master private key includes a first lattice basis matrix. The specific generation process is as follows:
[0014] Initialize the first dimension parameters Second dimension parameters Modulus parameters First Gaussian parameter Second Gaussian parameter Number of attributes Number of keywords The trapdoor generation algorithm in lattice cipher is employed. Generate the first common matrix and the first lattice basis matrix And randomly select the first common matrix Second common matrix .for Randomly select the common attribute matrix ,in Represents a set of system attributes. For Randomly select the common key matrix ,in Indicates the number of keywords. Select the third common matrix. ,in Denotes the third common submatrix, and .
[0015] The public parameters and master private key are constructed according to the following formula, and the public parameters are sent to other entities. The master private key is retained by a trusted authority center:
[0016] ;
[0017] .
[0018] In some embodiments of the present invention, in step (2), the public key of the data owner includes a first public key matrix, the private key of the data owner includes a first private key matrix, and the private key of the data user includes a second private key vector. The specific generation process is as follows:
[0019] For the data owner, the trapdoor generation algorithm in lattice cipher is used. Generate the first public key matrix and the first private key matrix The data owner's public and private keys are constructed according to the following formula. The public key is sent to other entities, and the private key is retained by the data owner:
[0020] ;
[0021] .
[0022] For data users, for ,if ,set up Otherwise, set ,in Indicates the number of user attributes. Represents a set of user attributes. Set the first intermediate matrix. The lattice basis generation algorithm in lattice cipher is adopted. Generate a second private key vector The private key for the data user is constructed according to the following formula and is retained by the data owner:
[0023] .
[0024] in Denotes the first common matrix. Denotes the first lattice basis matrix. This represents the first Gaussian parameter.
[0025] In some embodiments of the present invention, the encrypted data in step (3) includes a first encrypted text, a second encrypted text, a third encrypted text, and a fourth encrypted text, and the specific generation process is as follows:
[0026] Set access policies based on threshold secret sharing methods. ,in Represents a set of access policies. Indicates the threshold value. Randomly selects an encrypted random vector. First perturbation vector The second perturbation vector Third perturbation vector and the fourth perturbation vector .
[0027] The first ciphertext is generated according to the following formula:
[0028] ;
[0029] in, This indicates the first ciphertext. Denotes the first common vector. Represents an encrypted random vector. This represents the first perturbation vector.
[0030] The second ciphertext is generated according to the following formula:
[0031] ;
[0032] in, This indicates the second ciphertext. Denotes the first common matrix. Indicates keywords, Represents a set of keywords. Indicates the number of keywords. Represents the common key matrix, Represents an encrypted random vector. This represents the second perturbation vector.
[0033] The third ciphertext is generated according to the following formula:
[0034] ;
[0035] in, This indicates the third ciphertext. Represents the common attribute matrix, Represents an encrypted random vector. This represents the third perturbation vector.
[0036] The fourth ciphertext is generated according to the following formula:
[0037] ;
[0038] in, This indicates the fourth ciphertext. Describing the third common matrix, Represents an encrypted random vector. This represents the fourth perturbation vector.
[0039] The encrypted keyword is constructed according to the following formula and uploaded to the cloud server:
[0040] .
[0041] In some embodiments of the present invention, the search for the trapdoor in step (4) includes a first trapdoor vector, and the specific generation process is as follows:
[0042] Calculate the first intermediate vector ,in Denotes the second common matrix. Represents an encrypted random vector. This represents the fifth perturbation vector. For Selecting polynomials , making .for Set the second intermediate vector Invoking the generalized lattice basis sampling algorithm in lattice cipher. Generate the first trapdoor vector , making .
[0043] in Denotes the first common matrix. Indicates keywords, Represents a set of keywords. Represents the common key matrix, This represents the first intermediate matrix. Represents the common attribute matrix, This represents the second Gaussian parameter.
[0044] The following formula is used to construct a search trapdoor, which is then uploaded to the cloud server:
[0045] .
[0046] In some embodiments of the present invention, the keyword ciphertext search process in step (5) is as follows:
[0047] Set the fourth ciphertext .for ,if ,set up Otherwise, set And calculate the third intermediate vector. For user attribute sets Access strategy set and threshold value ,if If it returns 0, then it returns 0; otherwise, Select available sets ,in , The operation represents the number of elements in a set. This represents the intersection operation. The search is performed using the following formula:
[0048] ;
[0049] in, This indicates the first ciphertext. The Lagrange coefficient is defined as follows: , Represents the first trapdoor vector. This indicates the second ciphertext. Represents the third intermediate vector. This indicates the third ciphertext.
[0050] like The function returns 1 if the search trapdoor matches the ciphertext of the keyword, and 0 otherwise if the search trapdoor does not match the ciphertext of the keyword. This indicates the floor function. This represents absolute value operations.
[0051] Additional advantages, objects, and features of the invention will be set forth in part in the description which follows, and will also become apparent in part to those skilled in the art upon studying the text, or may be learned by practice of the invention. The objects and other advantages of the invention will become apparent from the description and the accompanying drawings.
[0052] Those skilled in the art will understand that the objectives and advantages achievable with the present invention are not limited to those specifically described above, and that the above and other objectives achievable with the present invention will become clearer from the following detailed description. Attached Figure Description
[0053] The accompanying drawings, which are provided to further illustrate the invention and form part of this application, are not intended to limit the scope of the invention.
[0054] Figure 1 This is a schematic diagram of one embodiment of the lattice-based attribute-based join keyword search method for cloud services according to the present invention;
[0055] Figure 2 This is a schematic diagram of the architecture of one embodiment of the lattice-based attribute-based join keyword search method for cloud services according to the present invention. Detailed Implementation
[0056] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the embodiments and accompanying drawings. Here, the illustrative embodiments and descriptions of this invention are used to explain the invention, but are not intended to limit the invention.
[0057] like Figure 1 As shown, this invention proposes a lattice-based attribute-based join keyword search method for cloud services, the steps of which include:
[0058] Step (1): The Trusted Authority Center receives the system initialization request, generates the first dimension parameter, the second dimension parameter, the modulus parameter, the first Gaussian parameter, the second Gaussian parameter, the number of attributes, and the number of keywords. It uses the TrapGen algorithm in lattice cipher to generate the first common matrix and the first lattice basis matrix. It randomly selects the first common matrix, the second common matrix, the common attribute matrix, the common keyword matrix, and the third common matrix. The Trusted Authority Center sets the first lattice basis matrix as the master private key and keeps it. It sets the other parameters as public parameters and publishes them to other entities.
[0059] Step (2): The data owner and the data user submit a key application request to the Trusted Authority Center. For the data owner, the Trusted Authority Center uses the TrapGen algorithm in lattice cipher to generate a first public key matrix and a first private key matrix. The first public key matrix is used as the public key and the first private key matrix is used as the private key, and the data owner is sent to the data owner. For the data user, the Trusted Authority Center sets a first intermediate matrix and uses the SampleBasis algorithm in lattice cipher to generate a second private key vector. The second private key vector is used as the private key and sent to the data user.
[0060] Step (3): The data owner sets the access policy according to the threshold secret sharing method, randomly selects the encryption random vector, the first perturbation vector, the second perturbation vector, the third perturbation vector and the fourth perturbation vector, generates the first ciphertext, the second ciphertext, the third ciphertext and the fourth ciphertext, and uses the first ciphertext, the second ciphertext, the third ciphertext and the fourth ciphertext to form the keyword ciphertext, and uploads it to the cloud server.
[0061] Step (4): The data user calculates the first intermediate vector, selects a polynomial, sets the second intermediate vector, calls the generalized lattice basis sampling algorithm GenSamplePre in lattice cipher to generate the first trapdoor vector, uses the first trapdoor vector to form a search trapdoor, and uploads it to the cloud server.
[0062] Step (5): The cloud server sets the fourth ciphertext and calculates the third intermediate vector. For the user attribute set, access policy set and threshold value, if the number of intersection elements of the user attribute set and access policy set is greater than the threshold value, the search results are calculated using the first ciphertext, the first trapdoor vector, the second ciphertext, the third intermediate vector and the third ciphertext.
[0063] like Figure 2 As shown, the lattice-based attribute-based join keyword search method for cloud services proposed in this invention involves four participating entities: a trusted authority center, a data owner, a data user, and a cloud server.
[0064] The trusted authority center is responsible for initializing the system and generating keys for data senders and receivers. For data owners, the key generation center calculates their public and private keys based on public parameters. For data users, the key generation center similarly calculates their private keys based on public parameters, attributes, and the master key.
[0065] The data owner possesses a series of data files and extracts keywords from them. After receiving the public and private keys from the key generation center, the data owner invokes an encryption algorithm and embeds an access policy to encrypt the keywords, obtaining ciphertext that can only be accessed by a specific data recipient. Finally, the data owner uploads the ciphertext to a cloud server.
[0066] Data users possess their own attributes, which can be used to generate their private keys at the key generation center. When a data user has a search request, they invoke a trapdoor generation algorithm to calculate a search trapdoor and send it to the cloud server. If the attributes meet the access conditions (i.e., the user attributes conform to the access policy) and the search trapdoor matches the keyword ciphertext, the data user retrieves the search results from the cloud server.
[0067] Cloud servers support data storage and access control functions, and can store encrypted keywords with access policies. When a cloud server receives a search trap from a user, it checks whether the user's attributes match the access policy. If the user's attributes match the access policy, the cloud server will execute a test algorithm and send the search results to the user.
[0068] The specific procedures for steps (1), (2), (3), (4), and (5) are as follows:
[0069] Step (1): Initialize the first dimension parameters of the trusted authority center. Second dimension parameters Modulus parameters First Gaussian parameter Second Gaussian parameter Number of attributes Number of keywords It employs a trapdoor generation algorithm from lattice ciphers. Generate the first common matrix and the first lattice basis matrix And randomly select the first common matrix Second common matrix .for The trusted and authoritative center randomly selects public attribute matrices. ,in Represents a set of system attributes. For The trusted and authoritative center randomly selects public keyword matrices. ,in This indicates the number of keywords. Then, the trusted authority center selects a third common matrix. ,in Denotes the third common submatrix, and Finally, the trusted authority center will provide the aforementioned public parameters. The master private key is sent to other entities. Retained by a trusted and authoritative center.
[0070] Step (2): After receiving key generation requests from the data owner and data user, the Trusted Authority Center generates a public and private key for the data owner and a private key for the data user. For the data owner, the Trusted Authority Center uses a trapdoor generation algorithm from lattice ciphers. Generate the first public key matrix and the first private key matrix , data owner's public key and private key Return it to the data owner.
[0071] For data users, for ,if Trusted and authoritative center setup Otherwise, set ,in Indicates the number of user attributes. This represents a set of user attributes. Subsequently, the trusted authority center sets up the first intermediate matrix. It employs the lattice basis generation algorithm from lattice cipher. Generate a second private key vector , will give the data user's private key Returned to the data user.
[0072] Step (3): The data owner sets the access policy according to the threshold secret sharing method. ,in Represents a set of access policies. Indicates the threshold value. Randomly selects an encrypted random vector. First perturbation vector The second perturbation vector Third perturbation vector and the fourth perturbation vector Generate the first, second, third, and fourth ciphertexts using the following formula:
[0073] ;
[0074] ;
[0075] ;
[0076] ;
[0077] in, This indicates the first ciphertext. Denotes the first common vector. Represents an encrypted random vector. This represents the first perturbation vector. This indicates the second ciphertext. Denotes the first common matrix. Indicates keywords, Represents a set of keywords. Indicates the number of keywords. Represents the common key matrix, This represents the second perturbation vector. This indicates the third ciphertext. Represents the common attribute matrix, This represents the third perturbation vector. This indicates the fourth ciphertext. Describing the third common matrix, This represents the fourth perturbation vector. Finally, the data owner constructs the data ciphertext. Uploaded to the cloud server.
[0078] Step (4): Data user calculates the first intermediate vector. ,in Denotes the second common matrix. Represents an encrypted random vector. This represents the fifth perturbation vector. For Data users select polynomials , making .for Data user sets a second intermediate vector Subsequently, the data user invoked the generalized lattice basis sampling algorithm in lattice cipher. Generate the first trapdoor vector , making .
[0079] in Denotes the first common matrix. Indicates keywords, Represents a set of keywords. Represents the common key matrix, This represents the first intermediate matrix. Represents the common attribute matrix, This represents the second Gaussian parameter. Finally, the data users constitute a search trapdoor. Uploaded to the cloud server.
[0080] Step (5): Set the fourth ciphertext on the cloud server .for ,if Cloud server settings Otherwise, set And calculate the third intermediate vector. For user attribute sets Access strategy set and threshold value ,if The cloud server returns 0; otherwise, Select available cloud server sets ,in , The operation represents the number of elements in a set. This represents the intersection operation. The search is performed using the following formula:
[0081] ;
[0082] in, This indicates the first ciphertext. The Lagrange coefficient is defined as follows: , Represents the first trapdoor vector. This indicates the second ciphertext. Represents the third intermediate vector. This indicates the third ciphertext.
[0083] like The cloud server returns 1 if the search trapdoor matches the ciphertext of the keyword, and 0 otherwise if the search trapdoor does not match the ciphertext of the keyword. This indicates the floor function. This represents absolute value operations.
[0084] The beneficial effects of the present invention include at least the following:
[0085] 1. This invention proposes a lattice-based attribute-based join keyword search method for cloud services, which not only realizes multi-user encrypted search, access control and join keyword search, but also resists quantum computing attacks.
[0086] 2. This invention is based on lattice algebra structures and employs the trapdoor generation algorithm TrapGen, the lattice basis generation algorithm SampleBasis, and the generalized forward sampling algorithm GenSamplePre from lattice cryptography to achieve key generation and multi-user ciphertext search. Specifically, the private keys of the data owner and the data user are generated by the TrapGen algorithm and the SampleBasis algorithm, respectively, and the user's search trapdoor is calculated using the GenSamplePre algorithm, thereby enabling multi-user ciphertext search.
[0087] 3. This invention implements an access control structure through a threshold secret sharing technique based on Lagrange interpolation polynomials, thereby achieving access control for data users. Furthermore, it expands the keywords in the encryption algorithm and trapdoor generation algorithm from one to multiple, thus supporting connection keyword search in cloud service environments.
[0088] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. For those skilled in the art, various modifications and variations of the embodiments of the present invention are possible. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A cloud service oriented lattice-based attribute-based connection keyword search method, characterized in that, The steps of the method include: Step (1): The Trusted Authority Center receives the system initialization request, generates the first dimension parameter, the second dimension parameter, the modulus parameter, the first Gaussian parameter, the second Gaussian parameter, the number of attributes, and the number of keywords. It uses the TrapGen algorithm in lattice cipher to generate the first common matrix and the first lattice basis matrix. It randomly selects the first common matrix, the second common matrix, the common attribute matrix, the common keyword matrix, and the third common matrix. The Trusted Authority Center sets the first lattice basis matrix as the master private key and keeps it. It sets the other parameters as public parameters and publishes them to other entities. Step (2): The data owner and the data user submit a key application request to the Trusted Authority Center. For the data owner, the Trusted Authority Center uses the TrapGen algorithm in lattice cipher to generate a first public key matrix and a first private key matrix. The first public key matrix is used as the public key and the first private key matrix is used as the private key, and the data owner is sent to the data owner. For the data user, the Trusted Authority Center sets a first intermediate matrix and uses the SampleBasis algorithm in lattice cipher to generate a second private key vector. The second private key vector is used as the private key and sent to the data user. Step (3): The data owner sets the access policy according to the threshold secret sharing method, randomly selects the encryption random vector, the first perturbation vector, the second perturbation vector, the third perturbation vector and the fourth perturbation vector, generates the first ciphertext, the second ciphertext, the third ciphertext and the fourth ciphertext, and uses the first ciphertext, the second ciphertext, the third ciphertext and the fourth ciphertext to form the keyword ciphertext, and uploads it to the cloud server. Step (4): The data user calculates the first intermediate vector, selects a polynomial, sets the second intermediate vector, calls the generalized lattice basis sampling algorithm GenSamplePre in lattice cipher to generate the first trapdoor vector, uses the first trapdoor vector to form a search trapdoor, and uploads it to the cloud server. Step (5): The cloud server sets the fourth ciphertext and calculates the third intermediate vector. For the user attribute set, access policy set and threshold value, if the number of intersection elements of the user attribute set and access policy set is greater than the threshold value, the search results are calculated using the first ciphertext, the first trapdoor vector, the second ciphertext, the third intermediate vector and the third ciphertext. 2.The cloud service oriented attribute-based connection keyword search method over lattice according to claim 1, wherein, The generation of public parameters and master private key in step (1): initializing a first dimension parameter , a second dimension parameter , a modulus parameter , a first Gaussian parameter , a second Gaussian parameter , a number of attributes , a number of keywords , using a trapdoor generation algorithm in lattice cryptography generating a first public matrix and a first lattice basis matrix , and randomly selecting a first public matrix and a second public matrix , for , randomly selecting a public attribute matrix , wherein represents a set of system attributes, for , randomly selecting a public keyword matrix , wherein represents a number of keywords, selecting a third public matrix , wherein represents a third public sub-matrix, and ; The public parameters and master private key are constructed according to the following formula, and the public parameters are sent to other entities. The master private key is retained by a trusted authority center: ; 。 3.The cloud service oriented attribute-based connection keyword search method over lattice according to claim 1, wherein, The generation of data owner and data user keys in step (2): For a data owner, a trapdoor generation algorithm in lattice cryptography is employed generating a first public key matrix and a first private key matrix , a public key and a private key of the data owner are formed according to the following formula, the public key is sent to other entities, and the private key is kept by the data owner: ; ; For data users, for If , set ; otherwise, set , wherein represents the number of user attributes, represents a user attribute set, set the first intermediate matrix , generate the second private key vector using the lattice base generation algorithm in the lattice cryptography , and the private key of the data user is composed according to the following formula, which is retained by the data owner: ; wherein denotes a first common matrix, denotes a first lattice matrix, denotes a first Gaussian parameter. 4.The cloud service oriented attribute-based connection keyword search method over lattice according to claim 1, wherein, The generation of the keyword ciphertext in step (3) includes a first ciphertext, a second ciphertext, a third ciphertext, and a fourth ciphertext: Setting access policy according to threshold secret sharing method , wherein represents a set of access policies, represents a threshold value, a random encryption random vector , a first perturbation vector , a second perturbation vector , a third perturbation vector and a fourth perturbation vector ; The first ciphertext is generated according to the following formula: ; wherein, represents a first ciphertext, represents a first public vector, represents an encrypted random vector, represents a first perturbation vector; The second ciphertext is generated according to the following formula: ; wherein, denotes a second ciphertext, denotes a first public matrix, denotes a keyword, denotes a set of keywords, denotes a number of keywords, denotes a public keyword matrix, denotes an encrypted random vector, denotes a second perturbation vector; The third ciphertext is generated according to the following formula: ; wherein, denotes a third ciphertext, denotes a public attribute matrix, denotes an encrypted random vector, denotes a third perturbation vector; The fourth ciphertext is generated according to the following formula: ; wherein, denotes a fourth ciphertext, denotes a third public matrix, denotes an encrypted random vector, denotes a fourth perturbation vector; The encrypted keyword is constructed according to the following formula and uploaded to the cloud server: 。 5. The cloud service oriented attribute-based connection keyword search method over lattice according to claim 1, wherein, The generation of the trapdoor in step (4) is as follows: computing a first intermediate vector wherein denotes a second public matrix, denotes an encrypted random vector, denotes a fifth perturbation vector, for a polynomial is chosen such that for a second intermediate vector is set a first trapdoor vector is generated such that ; wherein denotes a first common matrix, denotes a keyword, denotes a set of keywords, denotes a common keyword matrix, denotes a first intermediate matrix, denotes a common attribute matrix, denotes a second Gaussian parameter; The following formula is used to construct a search trapdoor, which is then uploaded to the cloud server: 。 6. The lattice-based attribute-based join keyword search method for cloud services according to claim 1, characterized in that, The keyword ciphertext search process in step (5): Set the fourth ciphertext ,for ,if ,set up Otherwise, set And calculate the third intermediate vector. For user attribute sets Access strategy set and threshold value ,if Returns 0; otherwise, Select available sets ,in , The operation represents the number of elements in a set. The intersection operation is performed using the following formula: ; in, This indicates the first ciphertext. The Lagrange coefficient is defined as follows: , Represents the first trapdoor vector. This indicates the second ciphertext. Represents the third intermediate vector. This indicates the third ciphertext; like The function returns 1 if the search trapdoor matches the ciphertext of the keyword, and 0 otherwise if the search trapdoor does not match the ciphertext of the keyword. This indicates the floor function. This represents absolute value operations.