A dual-involuntary key-value query method and system for a trusted execution environment

CN122778431APending Publication Date: 2026-09-18INST OF SOFTWARE - CHINESE ACAD OF SCI
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610909675.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2026-02-09
Filing Date
2026-06-23
Publication Date
2026-09-18

AI Technical Summary

Technical Problem

[0006]本发明的目的在于提出一种面向可信执行环境的双重不经意键值查询方法及系统,以解决TEE场景下键值查询及动态更新过程易泄露访问模式且访问开销较高的技术问题,达到兼顾不经意访问保护与动态更新效率的结果

Benefits of technology

[0025] 1. Based on the capacity limit, the minimum degree of the B+ tree, and the threshold of the inadvertent access strategy, this invention configures an adaptive inadvertent storage structure and node type for each layer of the B+ tree. This allows layers with a smaller number of nodes to use a lower-overhead access method, while layers with a larger number of nodes can use Path ORAM storage. Compared to a solution that uses ORAM storage exclusively, this invention can reduce the access overhead for small to medium-sized data volumes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122778431A_ABST
    Figure CN122778431A_ABST
Patent Text Reader

Abstract

The application discloses a kind of dual carelessness key value query method and system for trusted execution environment, belong to information security technical field.The application is to solve the technical problem that key value query and dynamic updating process is easy to leak access mode in TEE scene and access overhead is higher, by configuring each layer adaptive carelessness storage structure and node type according to capacity upper limit, B+ tree minimum degree and carelessness access strategy threshold, dual carelessness key value index structure is constructed, and based on the index structure, layer-by-layer query access, target node access and node updating are carried out.The application can support efficient carelessness key value query and node dynamic updating.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of information security technology, specifically relating to a dual unintentional key-value query method and system for trusted execution environments. Background Technology

[0002] Key-value lookup refers to the process of locating and returning the associated data item (value) within a specific key-value mapping data structure for an input key. It is widely used in scenarios such as cloud computing, databases, and storage systems. To protect data privacy and user query privacy during key-value lookup, a Trusted Execution Environment (TEE) can be used to provide security protection, enabling sensitive computing to execute in a hardware-isolated environment. TEE can build a hardware-protected trusted execution region (Enclave) in an untrusted cloud platform, and ensure the confidentiality and integrity of code and data within the Enclave through hardware isolation and security mechanisms, preventing unauthorized access or tampering of sensitive data by the operating system, virtual machine monitor, and other applications.

[0003] Existing TEE implementations, such as Intel SGX and ARM TrustZone, typically protect enclave memory. However, recent research indicates that TEEs are still vulnerable to side-channel attacks. Attackers can infer the internal data structure layout and access patterns of the enclave through externally perceptible information such as memory access address sequences, cache behavior, and page fault signals. For example, different query conditions for a key may trigger specific memory access trajectories such as AVL tree traversal paths and hash table lookup sequences. Attackers can use statistical analysis or machine learning methods to guess the semantics of user queries or private data. To mitigate the risk of access pattern leakage, TEE-based key-value queries typically need to satisfy double obliviousness, ensuring that the internal memory access sequences and the exposed storage access patterns remain indistinguishable.

[0004] In existing technologies, unintentional index structures can be constructed based on Oblivious Random Access Machines (ORAM). When accessing logical data addresses, operations such as path reading, block shuffling, and write-back are performed to reduce the correlation between physical storage access patterns and logical access content. Simultaneously, during node access, pointer updates, and parent-child relationship maintenance, unintentional operators such as unintentional conditional assignment, linear scans, and unintentional sorting can be combined to ensure that both internal and external accesses during key-value queries exhibit data-independent characteristics. When constructing unintentional indexes based on ORAM, B+ trees have a lower height than AVL trees, reducing the number of ORAM access rounds and thus offering retrieval efficiency advantages in latency-sensitive scenarios.

[0005] However, constructing a doubly unintentional B+ tree in a TEE scenario still presents implementation challenges. AVL tree updates typically involve local rotations, making unintentionality relatively easy to achieve with minimal padding operations. In contrast, B+ tree insertions or deletions may trigger cross-level node splits, borrowing, or merging. If conventional B+ tree update methods are directly applied, node access paths, new node allocation, old node reclamation, and parent-child relationship maintenance processes may leak update location and structural change information. Over-padding or repeated accesses to hide this information could significantly increase redundant I / O and query latency. Therefore, how to leverage the low height advantage of B+ trees while ensuring doubly unintentional query access and dynamic node update processes, and implementing node splitting, borrowing, and merging without significantly increasing access overhead, is a key technical problem that needs to be solved. Summary of the Invention

[0006] The purpose of this invention is to propose a dual unintentional key-value query method and system for Trusted Execution Environments (TEEs) to solve the technical problems of easy leakage of access patterns and high access overhead in the key-value query and dynamic update process in TEE scenarios, so as to achieve a balance between unintentional access protection and dynamic update efficiency.

[0007] To achieve the above objectives, the present invention adopts the following technical solution.

[0008] A double-inadvertent key-value query method for trusted execution environments includes the following steps: Based on the capacity limit, the minimum degree of the B+ tree, and the threshold of the inadvertent access strategy, the adaptive inadvertent storage structure and node type of each layer are configured to obtain a dual inadvertent key-value index structure. Based on the query key, the double unintentional key-value index structure is accessed layer by layer, and the target entry is determined in the accessed nodes to obtain the value corresponding to the query key; Based on the update type and key-value pairs, the double unintentional key-value index structure is accessed layer by layer to obtain the target node and sibling nodes; Based on the update type, the target node and the sibling node are updated, and the layer where the root node is located is updated according to the change of the root node, resulting in the updated double unintentional key-value index structure.

[0009] Furthermore, based on the capacity limit, the minimum degree of the B+ tree, and the inadvertent access strategy threshold, the adaptive inadvertent storage structure and node type for each layer are configured to obtain a dual inadvertent key-value index structure, including: Determine the number of levels and the capacity of nodes at each level of the B+ tree based on the capacity limit and the minimum degree of the B+ tree. Based on the node capacity of each layer and the threshold of the inadvertent access policy, determine the storage form of the adaptive inadvertent storage structure of each layer; The node type of each layer is determined based on the storage format of the adaptive unintentional storage structure at each layer; An empty leaf node is written into the leaf layer adaptive unintentional storage structure, and the root node position and the layer in which the root node is located are recorded, resulting in a double unintentional key-value index structure.

[0010] Furthermore, based on the capacity limit and the minimum degree of the B+ tree, the number of levels of the B+ tree and the capacity of nodes at each level are determined, including: Determine the capacity of leaf level nodes based on the upper capacity limit and the minimum degree of the B+ tree; Based on the capacity of the leaf layer nodes and the minimum degree of the B+ tree, the capacity of the intermediate layer nodes is determined layer by layer until the capacity of the root layer nodes is obtained. Based on the capacity of the leaf layer nodes, the capacity of the intermediate layer nodes, and the capacity of the root layer nodes, determine the number of layers of the B+ tree and the capacity of each layer of nodes.

[0011] Furthermore, based on the node capacity of each layer and the threshold for the inadvertent access policy, the storage format of the adaptive inadvertent storage structure for each layer is determined, including: The capacity of each layer of nodes is compared with the threshold of the unintentional access policy to obtain the capacity comparison results of each layer. Based on the capacity comparison results of each layer, the adaptive unintentional storage structure of each layer is determined to be either array storage or path unintentional random access storage.

[0012] Furthermore, based on the storage format of the adaptive unintentional storage structure at each layer, the node types at each layer are determined, including: Define the leaf layer nodes as leaf node types; The pointer content of the intermediate layer is determined based on the storage format of the next layer of the intermediate layer's adaptive unintentional storage structure. Based on the pointer content, the intermediate layer node is determined to be of type array pointer intermediate node or path pointer intermediate node.

[0013] Further, based on the query key, the double unintentional key-value index structure is accessed layer by layer, and the target entry is determined in the accessed nodes to obtain the value corresponding to the query key, including: Based on the root node location, the layer where the root node is located, and the query key, the adaptive unintentional storage structure in the dual unintentional key-value index structure is accessed layer by layer to obtain the access nodes at each layer. Based on the query key, determine the target entry in each layer of access nodes; Based on the target entry, obtain the pointer to the next level node in the intermediate layer, and obtain the value corresponding to the query key in the leaf layer.

[0014] Furthermore, based on the root node position, the layer in which the root node resides, and the query key, the adaptive unintentional storage structure in the dual unintentional key-value index structure is accessed layer by layer to obtain the access nodes at each layer, including: Based on the layer where the root node is located, perform spurious accesses on the adaptive unintentional storage structure before the layer where the root node is located to obtain spurious access nodes. Based on the location of the root node, the adaptive unintentional storage structure of the layer where the root node is located is accessed to obtain the root node; Based on the node pointers in the access node of the previous level, the adaptive unintentional storage structure after the root node is accessed layer by layer to obtain the access nodes of each level.

[0015] Further, based on the query key, the target entry is determined in each layer of access nodes, including: Based on the query key, the entries in each access node are traversed to obtain the comparison results of each entry; Based on the comparison results, unintentional conditional assignments are made to the candidate entries to obtain the target entries.

[0016] Further, based on the target entry, the next-level node pointer is obtained in the intermediate layer, and the value corresponding to the query key is obtained in the leaf layer, including: When the target entry is located at an access node of type intermediate node of array pointer, the address of the next level node is determined according to the target entry; When the target entry is located at an access node of the path pointer intermediate node type, the next-level node address and path location information are determined based on the target entry. Access the next-level adaptive unintentional storage structure based on the next-level node address and path location information, and obtain the value corresponding to the query key in the leaf layer.

[0017] Furthermore, based on the update type and key-value pairs, the double unintentional key-value index structure is accessed layer by layer to obtain the target node and its sibling nodes, including: Based on the update type and key-value pairs, the double unintentional key-value index structure is accessed layer by layer to obtain the target node; Determine the access method for sibling nodes based on the update type and target node; Based on the sibling node access method, the double unintentional key-value index structure is accessed layer by layer to obtain the sibling nodes.

[0018] Furthermore, based on the update type and target node, the access method for sibling nodes is determined, including: When the update type is insert, the empty node is identified as the sibling node access object; When the update type is deletion, the sibling node access object is determined based on the adjacency relationship of the target node, and the sibling node access method is obtained.

[0019] Further, based on the update type, the target node and the sibling node are updated, and the layer where the root node resides is updated according to the root node change, resulting in an updated double unintentional key-value index structure, including: Based on the update type, the target node is modified to obtain the modified target node; The entries in the modified target node and its sibling nodes are merged to obtain merged entries; Based on the merged entries, the entries are reassigned to obtain the reassigned entries; The target node and its sibling nodes are reconstructed based on the reassignment entries, and the layer containing the root node is updated according to the changes in the root node, resulting in the updated double unintentional key-value index structure.

[0020] Furthermore, based on the update type, the target node is modified to obtain the modified target node, including: When the update type is insert, the key-value pair is written to the target node, resulting in the modified target node; When the update type is delete, the key-value pair is deleted from the target node, resulting in the modified target node.

[0021] Further, based on the merged entries, entries are reallocated to obtain reallocated entries, including: Count the number of valid entries in the merged entries; Based on the number of valid entries, assign movement positions to the merged entries; The merged entries are randomly sorted according to the movement positions to obtain the redistributed entries.

[0022] Further, the target node and its sibling nodes are reconstructed based on the reassignment entries, and the layer containing the root node is updated according to the root node changes, resulting in an updated double unintentional key-value index structure, including: Based on the reassignment entries and sibling relationships, the target node and its sibling nodes are reconstructed to obtain the reconstructed tree structure. The changes in the root node are determined based on the reconstructed tree structure. The layer containing the root node is updated based on the changes in the root node, resulting in the updated double unintentional key-value index structure.

[0023] A double-inadvertent key-value query system for trusted execution environments includes: The index configuration module is used to configure the adaptive inadvertent storage structure and node type of each layer according to the capacity limit, the minimum degree of the B+ tree and the inadvertent access strategy threshold, so as to obtain a dual inadvertent key-value index structure. The key-value query module is used to access the double unintentional key-value index structure layer by layer according to the query key, and determine the target entry in the accessed nodes to obtain the value corresponding to the query key; The node access module is used to access the double unintentional key-value index structure layer by layer according to the update type and key-value pairs to obtain the target node and sibling nodes; The node update module is used to update the target node and the sibling node according to the update type, and update the layer where the root node is located according to the root node change, so as to obtain the updated double unintentional key-value index structure.

[0024] The present invention has achieved the following beneficial effects.

[0025] 1. Based on the capacity limit, the minimum degree of the B+ tree, and the threshold of the inadvertent access strategy, this invention configures an adaptive inadvertent storage structure and node type for each layer of the B+ tree. This allows layers with a smaller number of nodes to use a lower-overhead access method, while layers with a larger number of nodes can use Path ORAM storage. Compared to a solution that uses ORAM storage exclusively, this invention can reduce the access overhead for small to medium-sized data volumes.

[0026] 2. This invention is based on a dual unintentional key-value index structure. It accesses the index structure layer by layer according to the query key and determines the target entry in the accessed nodes. This ensures that the node access and entry selection during the query process maintain an unintentional access form that is compatible with the query key. This can reduce the risk of query information being leaked by the internal memory access sequence and external storage access mode of the TEE.

[0027] 3. This invention accesses the double unintentional key-value index structure layer by layer according to the update type and key-value pairs to obtain the target node and sibling nodes, and completes the node update and the update of the root node's layer based on the target node and sibling nodes. This enables the entry modification, node splitting, borrowing, merging and node reconstruction processes caused by B+ tree insertion and deletion to be incorporated into a unified update process, supporting dynamic updates of the double unintentional key-value index structure.

[0028] 4. This invention combines a low-height B+ tree index structure with an adaptive unintentional storage structure, which can reduce the number of index access levels while taking into account the access mode protection during query access, node pointer maintenance, and node dynamic update. It is suitable for application scenarios in trusted execution environments that require both key-value query privacy and data update capabilities. Attached Figure Description

[0029] Figure 1 This is a schematic diagram of a double unintentional key-value index structure based on a B+ tree; Figure 2 This is a schematic diagram of a double unintentional key-value lookup process; Figure 3 This is a schematic diagram of a double unintentional key-value update process. Detailed Implementation

[0030] The following will provide an exemplary explanation of the specific implementation of the key technical modules described in the invention, but this explanation is not intended to limit the scope of the invention.

[0031] This invention provides a double unintentional key-value query method for trusted execution environments. The method relies on a double unintentional key-value index structure for execution. The double unintentional key-value index structure includes an adaptive unintentional storage structure and a B+ tree structure. The adaptive unintentional storage structure is used to store nodes at different levels of the B+ tree and provide unintentional access to the nodes. The B+ tree structure is used to store key-value information and routing information.

[0032] Specifically, the Adaptive Unintentional Storage Structure (AOStore) includes array storage and Path ORAM storage formats. Array storage corresponds to linear scan access, and Path ORAM storage corresponds to Path ORAM access. The Adaptive Unintentional Storage Structure includes an AOStore Client and an AOStore Server. The AOStore Server stores data blocks in an untrusted region, while the AOStore Client accepts access calls and returns the accessed data blocks to the upper-layer program; this client is located in a trusted region. Unintentional access to the Adaptive Unintentional Storage Structure includes a start access phase and a finish access phase. The start access phase reads the target data block from the Adaptive Unintentional Storage Structure based on access information and returns it to the calling program. The finish access phase writes the target data block back to the Adaptive Unintentional Storage Structure after the calling program has completed its operations on the target data block.

[0033] Specifically, B+ tree structures include three node types: Internal Node Type-A, Internal Node Type-O, and Leaf Node Type-L. Internal Node Type-A is suitable when the current layer is an intermediate layer and the next layer uses array storage. Its stored pathfinding information includes the minimum key value of the child node and pointer information; the pointer information includes the child node's address in the array. Internal Node Type-O is suitable when the current layer is an intermediate layer and the next layer uses Path ORAM storage. Its stored pathfinding information includes the minimum key value of the child node and pointer information; the pointer information includes the child node's address and position in the Path ORAM. Leaf Node Type-L is used for the leaf layer and stores key-value pair information.

[0034] Step S1: Based on the capacity limit, the minimum degree of the B+ tree, and the threshold of the unintentional access strategy, configure the adaptive unintentional storage structure and node type for each layer to obtain a dual unintentional key-value index structure.

[0035] Specifically, the capacity limit is N, the minimum degree of the B+ tree is t, and the threshold for the unintentional access strategy is [value missing]. Unintentional access policy threshold This can be obtained through a comparative experiment of linear scanning and Path ORAM access. Step S1 outputs the completed double unintentional key-value index structure.

[0036] In an optional embodiment of the present invention, step S1 may include: Step S11: Determine the number of levels of the B+ tree and the capacity of each node based on the capacity limit and the minimum degree of the B+ tree.

[0037] Step S12: Determine the storage form of each layer's adaptive unintentional storage structure based on the node capacity of each layer and the unintentional access policy threshold.

[0038] Step S13: Determine the node type of each layer based on the storage form of the adaptive unintentional storage structure of each layer.

[0039] Step S14: Write an empty leaf node into the leaf layer adaptive unintentional storage structure, and record the root node position and the layer where the root node is located, to obtain a double unintentional key-value index structure.

[0040] Specifically, the root node is located at RootPointer, and the layer where the root node resides is... During initialization, an empty leaf node is used as the root node, and the root node is inserted into the leaf layer adaptive unintentional storage structure.

[0041] In an optional embodiment of the present invention, step S11 may include: Step S111: Determine the capacity of the leaf layer nodes based on the capacity limit and the minimum degree of the B+ tree.

[0042] Specifically, the capacity of the leaf layer nodes can be determined according to the following formula: in, Indicates the number of leaf level nodes; Indicates the maximum capacity; This represents the minimum degree of a B+ tree.

[0043] Step S112: Based on the capacity of the leaf layer nodes and the minimum degree of the B+ tree, determine the capacity of the intermediate layer nodes layer by layer until the capacity of the root layer nodes is obtained.

[0044] Specifically, the capacity of intermediate layer nodes can be determined layer by layer according to the following formula: in, Indicates the number of nodes in the current layer; Indicates the number of nodes in the next level below the current level; This represents the minimum degree of a B+ tree.

[0045] Step S113: Determine the number of layers and the node capacity of each layer of the B+ tree based on the capacity of the leaf layer nodes, the capacity of the intermediate layer nodes, and the capacity of the root layer nodes.

[0046] Specifically, the B+ tree has L levels, and the capacity of each node is L / L. ,in, This represents the maximum number of nodes from level 1 to level L.

[0047] In an optional embodiment of the present invention, step S12 may include: Step S121: Compare the capacity of each layer node with the threshold of the unintentional access policy to obtain the capacity comparison results of each layer.

[0048] Step S122: Based on the capacity comparison results of each layer, determine the adaptive unintentional storage structure of each layer as either array storage or path unintentional random access storage.

[0049] Specifically, when the capacity of the nodes in this layer is less than or equal to the threshold of the unintentional access policy, the adaptive unintentional storage structure of this layer is determined to be an array storage form; when the capacity of the nodes in this layer is greater than the threshold of the unintentional access policy, the adaptive unintentional storage structure of this layer is determined to be a Path ORAM storage form.

[0050] In an optional embodiment of the present invention, step S13 may include: Step S131: Determine the leaf layer node as a leaf node type.

[0051] Specifically, the leaf node type is Leaf Node Type-L.

[0052] Step S132: Determine the pointer content of the intermediate layer based on the storage format of the next layer of the intermediate layer's adaptive unintentional storage structure.

[0053] Specifically, when the next layer adaptive unintentional storage structure is in array storage form, the pointer content of the intermediate layer includes Address; when the next layer adaptive unintentional storage structure is in Path ORAM storage form, the pointer content of the intermediate layer includes Address and Position.

[0054] Step S133: Based on the pointer content, determine the intermediate layer node as either an array pointer intermediate node type or a path pointer intermediate node type.

[0055] Specifically, the intermediate node type of the array pointer is Internal Node Type-A, and the intermediate node type of the path pointer is Internal Node Type-O.

[0056] In an optional embodiment of the present invention, it is assumed that the initialization parameter is the capacity limit. Minimum degree of B+ tree and the threshold for unintentional access policies Based on the capacity limit N and the minimum degree t of the B+ tree, the maximum number of nodes at each level can be obtained. The number of levels in a B+ tree .

[0057] In an optional embodiment of the present invention, based on the maximum number of nodes in each layer and unintentional access policy threshold The configuration methods for the adaptive unintentional storage structure and node types at each layer are as follows: (1) The leaf layer adopts Leaf Node Type-L, and the node capacity 69904 is greater than Therefore, PathORAM storage is adopted; (2) The fourth layer is an intermediate layer and the next layer is a Path ORAM storage format, therefore Internal NodeType-O is used, and the node capacity 4368 is greater than Therefore, Path ORAM storage is adopted; (3) The third layer is an intermediate layer and the next layer is a Path ORAM storage format, therefore Internal NodeType-O is used, and the node capacity 272 is less than or equal to Therefore, array storage is used; (4) The second layer is an intermediate layer and the next layer is stored in array form, so Internal Node Type-A is adopted, and the node capacity is 16 less than or equal to 16. Therefore, array storage is used; (5) The first layer is an intermediate layer and the next layer is stored in array form, so Internal Node Type-A is adopted and the node capacity is less than or equal to 1. Therefore, an array storage format is used.

[0058] In an optional embodiment of the present invention, the double unintentional key-value index structure based on a B+ tree is as follows: Figure 1 As shown, the maximum number of levels in a B+ tree The current layer number is 4. The theoretical maximum number of nodes in the first three layers is less than or equal to... Therefore, an array storage method is used; the number of nodes in the last two layers is greater than Therefore, Path ORAM storage is used. The 5th layer is the leaf layer, so LeafNode Type-L is used; the child node layers of the 3rd and 4th layers are stored in Path ORAM, so Internal NodeType-O is used; the child node layers of the 1st and 2nd layers are stored in array, so Internal Node Type-A is used.

[0059] In an optional embodiment of the present invention, an empty leaf node is initialized as the root node, and the empty leaf node is inserted into... In the middle, the root node position RootPointer and the layer where the root node is located are recorded simultaneously. When RootPointer includes and hour, Indicates the root node address. This indicates the location information of the root node in PathORAM.

[0060] Step S2: Based on the query key, access the double unintentional key-value index structure layer by layer, determine the target entry in the accessed nodes, and obtain the value corresponding to the query key.

[0061] Specifically, the query key is k, and the value corresponding to the query key is v. Step S2 is used to retrieve the corresponding value v in the double unintentional key-value index structure based on the query key k.

[0062] In an optional embodiment of the present invention, step S2 may include: Step S21: Based on the root node position, the layer where the root node is located, and the query key, access the adaptive unintentional storage structure in the dual unintentional key-value index structure layer by layer to obtain the access nodes of each layer.

[0063] Specifically, the layer-by-layer access starts from level 1 and proceeds from top to bottom until level L is reached. For level i, the adaptive unintentional storage structure of that level is accessed to obtain the B+ tree node of that level.

[0064] Step S22: Determine the target entry in each access node according to the query key.

[0065] Specifically, when determining the target entry in the access node, a linear scan is performed on all entries of the access node, and the target entry corresponding to the query key k is obtained by comparing them through an unintentional conditional assignment operator.

[0066] Step S23: Based on the target entry, obtain the pointer to the next layer node in the intermediate layer and obtain the value corresponding to the query key in the leaf layer.

[0067] Specifically, if the accessed node is an intermediate layer node, the pointer information of the child node where the query key k is located is obtained according to the target entry; if the accessed node is a leaf layer node, the value v corresponding to the query key k is obtained according to the target entry.

[0068] In an optional embodiment of the present invention, step S21 may include: Step S211: Based on the layer where the root node is located, perform spurious access to the adaptive unintentional storage structure before the layer where the root node is located to obtain spurious access nodes.

[0069] Specifically, for the first Layer, when When the current layer has not yet accessed the layer where the root node is located, a fake address is used to perform a fake access to the adaptive unintentional storage structure of the current layer.

[0070] Step S212: Based on the location of the root node, access the adaptive unintentional storage structure of the layer where the root node is located to obtain the root node.

[0071] Specifically, for the first Layer, when At that time, RootPointer is used to access the adaptive unintentional storage structure of the current layer.

[0072] Step S213: Based on the node pointers in the accessed nodes of the previous layer, access the adaptive unintentional storage structure after the root node layer layer by layer to obtain the accessed nodes of each layer.

[0073] Specifically, for the first Layer, when When accessing a target node, the node pointer in the access node of the previous layer is used to access the current layer's adaptive unintentional storage structure. When the current layer's adaptive unintentional storage structure uses array storage, the Address of the data block where the target node is located is provided during access; when the current layer's adaptive unintentional storage structure uses Path ORAM storage, the Address and Position of the data block where the target node is located are provided during access, along with the new position information, New Position.

[0074] In an optional embodiment of the present invention, step S22 may include: Step S221: Based on the query key, traverse the entries in each access node to obtain the comparison results of each entry.

[0075] Step S222: Based on the comparison results, unintentional conditional assignments are made to the candidate entries to obtain the target entries.

[0076] Specifically, the unintentional conditional assignment operator is used to assign values ​​to variables based on the condition flag. Assign a value. When flag is true, the variable... Assigning a value to a variable When flag is false, no actual assignment is performed. Unintentional conditional assignment operators can be implemented using the CMOV x86 instruction.

[0077] In an optional embodiment of the present invention, step S23 may include: Step S231: When the target entry is located in an access node of type intermediate node of array pointer, determine the address of the next level node according to the target entry.

[0078] Specifically, when the access node is Internal Node Type-A, the child node pointer information corresponding to the target entry is Address.

[0079] Step S232: When the target entry is located at an access node of the path pointer intermediate node type, determine the next-level node address and path location information based on the target entry.

[0080] Specifically, when the accessed node is Internal Node Type-O, the child node pointer information corresponding to the target entry is Address and Position, and the Position is updated to New Position.

[0081] Step S233: Access the next-level adaptive unintentional storage structure based on the next-level node address and path location information, and obtain the value corresponding to the query key in the leaf layer.

[0082] Specifically, after each layer of adaptive unintentional storage structure is accessed, the accessed node is written back to that layer of adaptive unintentional storage structure.

[0083] In an optional embodiment of the present invention, the query process is as follows: Figure 2 As shown, the query process is as follows: (1) The first layer, because Therefore, fake visits are filled in. This is a fake address; (2) The second layer, due to Therefore, the address of the RootPointer is used. access To obtain the node, a linear scan of all entries in the node is then performed to obtain pointers to its child nodes. ; (3) The third layer, because Therefore, the pointer accessed from the previous level is used. access To obtain the node, a linear scan of all entries in the node is then performed to obtain pointers to its child nodes. and rerandomize its path to ; (4) The 4th floor, due to Therefore, the pointer accessed from the previous level is used. access To obtain the node and randomize its position. Then, a linear scan of all entries in the node is performed to obtain pointers to its child nodes. and rerandomize its path to ; (5) The 5th floor, because Therefore, the pointer accessed from the previous level is used. access To obtain the node and modify its location information. Then, a linear scan of all entries in the node is performed to obtain the value. .

[0084] Step S3: Based on the update type and key-value pairs, access the double unintentional key-value index structure layer by layer to obtain the target node and sibling nodes.

[0085] Specifically, the update type is Key-value pairs include keys Sum Step S3 is used to obtain the target node and its corresponding sibling node on the path to be updated before updating the double unintentional key-value index structure.

[0086] In an optional embodiment of the present invention, step S3 may include: Step S31: Based on the update type and key-value pairs, access the double unintentional key-value index structure layer by layer to obtain the target node.

[0087] Specifically, the layer-by-layer access is the same as the query access process in step S2, starting from the first layer and proceeding downwards sequentially to the next layer. The layer is used to obtain the node on the path where the key-value pair is located as the target node.

[0088] Step S32: Determine the access method for sibling nodes based on the update type and target node.

[0089] Step S33: According to the sibling node access method, access the double unintentional key-value index structure layer by layer to obtain the sibling node.

[0090] Specifically, while accessing the target node at each layer, an additional sibling node is accessed to fill in the node splits, borrows, or merges caused by the update.

[0091] In an optional embodiment of the present invention, step S32 may include: Step S321: When the update type is insert, the empty node is identified as the sibling node access object.

[0092] Specifically, when updating type During the insertion operation, each level accesses an empty node as a sibling node and sets that empty node as the right sibling.

[0093] Step S322: When the update type is deletion, determine the sibling node access object based on the adjacency relationship of the target node, and obtain the sibling node access method.

[0094] Specifically, when updating type When performing a deletion operation, the left sibling of the target node is accessed first; if the left sibling does not exist, the right sibling of the target node is accessed.

[0095] In an optional embodiment of the present invention, the update process is as follows: Figure 3 As shown. In the insertion operation, each layer accesses a target node. and access an empty node. Since the first layer is empty, the target node read in the first layer is... and sibling nodes All are empty; starting from the second level, since the nodes at each level are not empty, the target node... Not empty.

[0096] Specifically, assuming the nodes read by each layer are: the first layer The second layer The third layer The fourth floor Fifth floor ,in, Indicates an empty entry.

[0097] Step S4: Update the target node and the sibling node according to the update type, and update the layer where the root node is located according to the change of the root node, to obtain the updated double unintentional key-value index structure.

[0098] Specifically, step S4 starts from the first The tree structure is updated layer by layer from bottom to top, and after the tree structure update is completed, the layer containing the root node is updated according to the changes in the root node. .

[0099] In an optional embodiment of the present invention, step S4 may include: Step S41: Based on the update type, modify the entries of the target node to obtain the modified target node.

[0100] Step S42: Merge the entries in the modified target node and its sibling nodes to obtain merged entries.

[0101] Specifically, entry merging is performed based on the left-right relationship between the target node and its sibling nodes.

[0102] Step S43: Reassign entries based on the merged entries to obtain reassigned entries.

[0103] Step S44: Reconstruct the target node and sibling nodes according to the redistribution entries, and update the layer where the root node is located according to the root node changes, to obtain the updated double unintentional key-value index structure.

[0104] In an optional embodiment of the present invention, step S41 may include: Step S411: When the update type is insert, write the key-value pair to the target node to obtain the changed target node.

[0105] Specifically, when the target node is a leaf-level node, the entries written are key-value pairs; when the target node is an intermediate-level node, the entries written are the smallest key of the child node.

[0106] Step S412: When the update type is deletion, delete the key-value pair from the target node to obtain the changed target node.

[0107] Specifically, when the target node is a leaf node, the deleted entries are key-value pairs; when the target node is an intermediate node, the deleted entries are the smallest keys of the child nodes.

[0108] In an optional embodiment of the present invention, step S43 may include: Step S431: Count the number of valid entries for merging.

[0109] Specifically, the number of valid entries can be counted through linear scanning.

[0110] Step S432: Assign movement positions to the merged entries based on the number of valid entries.

[0111] Step S433: Randomly sort the merged entries according to the moved positions to obtain the redistributed entries.

[0112] Specifically, unintentional sorting moves merged entries based on the move positions assigned to them.

[0113] In an optional embodiment of the present invention, step S44 may include: Step S441: Based on the reassignment entries and sibling relationships, reconstruct the target node and sibling nodes to obtain the reconstructed tree structure.

[0114] Specifically, based on the left-right order of the reassignment entries and the sibling relationship between the target node and its sibling nodes, the target node and its sibling nodes are rebuilt, and the current layer update is completed.

[0115] Step S442: Determine the changes in the root node based on the reconstructed tree structure.

[0116] Specifically, changes to the root node include root node splitting, root node deletion, and root node remaining unchanged.

[0117] Step S443: Update the layer where the root node is located according to the changes in the root node to obtain the updated double unintentional key-value index structure.

[0118] Specifically, if the current level is the root node level, and the update causes the root node to split, then the level of the root node is set to [level]. If the update results in the deletion of the root node, then set the level of the root node to [level]. Otherwise, the layer containing the root node remains unchanged. Indicates the layer where the root node is located.

[0119] In an optional embodiment of the present invention, for the fifth layer, a linear scan is first performed towards the target node. Insert a new entry to the target node. from Become Then with the brother node Entries are merged to obtain When sibling nodes When empty, an extra empty entry can be removed.

[0120] In an optional embodiment of the present invention, when redistributing entries for the 5th layer merged entries, the number of valid entries is counted as 4 using a linear scan. When the number of valid entries exceeds the capacity limit, the merged entries are redistributed to two nodes. Position allocation is performed using a linear scan to obtain... In this set, the first item represents the entry information, and the second item represents the assigned position. By reordering the entries according to their assigned positions through unintentional sorting, we obtain... .

[0121] In an optional embodiment of the present invention, when reconstructing nodes in the 5th layer, node information is retained and the nodes are split into new nodes. and The update information is then passed upwards, and the minimum key of the new node is 6. Subsequent layers continue to update nodes. Specifically, layer 4 inserts new child node information but does not create a new node; subsequent layers do not need to insert new child node information and do not have any actual split nodes. The updated node structure is as follows: Layer 1 The second layer The third layer The fourth floor Fifth floor .

[0122] In an optional embodiment of the present invention, since updating the tree structure does not cause the root node to split, the layer where the root node is located remains unchanged. .

[0123] This invention also provides a dual unintentional key-value query system for trusted execution environments, used to execute the above method, including: The index configuration module is used to configure the adaptive inadvertent storage structure and node type of each layer according to the capacity limit, the minimum degree of the B+ tree and the inadvertent access strategy threshold, so as to obtain a dual inadvertent key-value index structure. The key-value query module is used to access the double unintentional key-value index structure layer by layer according to the query key, and determine the target entry in the accessed nodes to obtain the value corresponding to the query key; The node access module is used to access the double unintentional key-value index structure layer by layer according to the update type and key-value pairs to obtain the target node and sibling nodes; The node update module is used to update the target node and the sibling node according to the update type, and update the layer where the root node is located according to the root node change, so as to obtain the updated double unintentional key-value index structure.

[0124] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of this disclosure. This disclosure is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and embodiments are to be considered exemplary only, and this disclosure is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope.

Claims

1. A double unintentional key-value query method for trusted execution environments, characterized in that, Includes the following steps: Based on the capacity limit, the minimum degree of the B+ tree, and the threshold of the inadvertent access strategy, the adaptive inadvertent storage structure and node type of each layer are configured to obtain a dual inadvertent key-value index structure. Based on the query key, the double unintentional key-value index structure is accessed layer by layer, and the target entry is determined in the accessed nodes to obtain the value corresponding to the query key; Based on the update type and key-value pairs, the double unintentional key-value index structure is accessed layer by layer to obtain the target node and sibling nodes; Based on the update type, the target node and the sibling node are updated, and the layer where the root node is located is updated according to the change of the root node, resulting in the updated double unintentional key-value index structure.

2. The method as described in claim 1, characterized in that, Based on the capacity limit, the minimum degree of the B+ tree, and the inadvertent access policy threshold, the adaptive inadvertent storage structure and node type for each layer are configured to obtain a dual inadvertent key-value index structure, including: Determine the number of levels and the capacity of nodes at each level of the B+ tree based on the capacity limit and the minimum degree of the B+ tree. Based on the node capacity of each layer and the threshold of the inadvertent access policy, determine the storage form of the adaptive inadvertent storage structure of each layer; The node type of each layer is determined based on the storage format of the adaptive unintentional storage structure at each layer; An empty leaf node is written into the leaf layer adaptive unintentional storage structure, and the root node position and the layer in which the root node is located are recorded, resulting in a double unintentional key-value index structure.

3. The method as described in claim 2, characterized in that, Based on the node capacity of each layer and the threshold for the inadvertent access policy, the storage format of the adaptive inadvertent storage structure for each layer is determined, including: The capacity of each layer of nodes is compared with the threshold of the unintentional access policy to obtain the capacity comparison results of each layer. Based on the capacity comparison results of each layer, the adaptive unintentional storage structure of each layer is determined to be either array storage or path unintentional random access storage.

4. The method as described in claim 2, characterized in that, Based on the storage format of the adaptive unintentional storage structure at each layer, determine the node types for each layer, including: Define the leaf layer nodes as leaf node types; The pointer content of the intermediate layer is determined based on the storage format of the next layer of the intermediate layer's adaptive unintentional storage structure. Based on the pointer content, the intermediate layer node is determined to be of type array pointer intermediate node or path pointer intermediate node.

5. The method as described in claim 1, characterized in that, Based on the query key, the double unintentional key-value index structure is accessed layer by layer, and the target entry is determined in the accessed nodes to obtain the value corresponding to the query key, including: Based on the root node location, the layer where the root node is located, and the query key, the adaptive unintentional storage structure in the dual unintentional key-value index structure is accessed layer by layer to obtain the access nodes at each layer. Based on the query key, determine the target entry in each layer of access nodes; Based on the target entry, obtain the pointer to the next level node in the intermediate layer, and obtain the value corresponding to the query key in the leaf layer.

6. The method as described in claim 5, characterized in that, Based on the root node location, the level of the root node, and the query key, the adaptive unintentional storage structure in the double unintentional key-value index structure is accessed layer by layer to obtain the access nodes at each level, including: Based on the layer where the root node is located, perform spurious accesses on the adaptive unintentional storage structure before the layer where the root node is located to obtain spurious access nodes. Based on the location of the root node, the adaptive unintentional storage structure of the layer where the root node is located is accessed to obtain the root node; Based on the node pointers in the access node of the previous level, the adaptive unintentional storage structure after the root node is accessed layer by layer to obtain the access nodes of each level.

7. The method as described in claim 5, characterized in that, Based on the query key, the target entry is determined in each access node at each level, including: Based on the query key, the entries in each access node are traversed to obtain the comparison results of each entry; Based on the comparison results, unintentional conditional assignments are made to the candidate entries to obtain the target entries.

8. The method as described in claim 1, characterized in that, Based on the update type, the target node and the sibling node are updated, and the layer where the root node is located is updated according to the change of the root node, resulting in an updated double unintentional key-value index structure, including: Based on the update type, the target node is modified to obtain the modified target node; The entries in the modified target node and its sibling nodes are merged to obtain merged entries; Based on the merged entries, the entries are reassigned to obtain the reassigned entries; The target node and its sibling nodes are reconstructed based on the reassignment entries, and the layer containing the root node is updated according to the changes in the root node, resulting in the updated double unintentional key-value index structure.

9. The method as described in claim 8, characterized in that, Based on the merged entries, entries are reallocated to obtain reallocated entries, including: Count the number of valid entries in the merged entries; Based on the number of valid entries, assign movement positions to the merged entries; The merged entries are randomly sorted according to the movement positions to obtain the redistributed entries.

10. A dual unintentional key-value query system for trusted execution environments, characterized in that, include: The index configuration module is used to configure the adaptive inadvertent storage structure and node type of each layer according to the capacity limit, the minimum degree of the B+ tree and the inadvertent access strategy threshold, so as to obtain a dual inadvertent key-value index structure. The key-value query module is used to access the double unintentional key-value index structure layer by layer according to the query key, and determine the target entry in the accessed nodes to obtain the value corresponding to the query key; The node access module is used to access the double unintentional key-value index structure layer by layer according to the update type and key-value pairs to obtain the target node and sibling nodes; The node update module is used to update the target node and the sibling node according to the update type, and update the layer where the root node is located according to the root node change, so as to obtain the updated double unintentional key-value index structure.