File Attribute Vector Encryption for Keyword Search
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing public-key encryption with keyword search methods suffer from low operation efficiency and uniform encryption security levels, leading to long encryption response times and poor security in file storage and search processes.
Innovation Solution
A file storage and search method using public-key encryption with keyword search that generates a file attribute vector based on access control attributes and keywords, encrypts it using a public-secret key pair, and transmits the encrypted vector and file to a storage server, allowing for flexible access control and multi-keyword search while improving security through differential encryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If existing public-key encryption with keyword search methods are used, then keyword search functionality is provided, but operation efficiency is low and encryption security levels are uniform
Solution Approach 1:
The patent applies local quality by implementing differential encryption where different files receive different encryption security levels based on their importance. High-importance files use stronger encryption algorithms and longer key lengths, while low-importance files use weaker encryption. This resolves the contradiction by making encryption security level non-uniform (improving reliability for critical files) while maintaining operational efficiency through selective application of encryption strength.
Solution Approach 2:
The patent changes encryption parameters dynamically based on file importance. The system adjusts key length, algorithm selection, and encryption rounds according to a predefined importance classification. This parameter adaptation improves operation efficiency by avoiding over-encryption of less critical files while ensuring high security for important files, thus resolving the contradiction between efficiency and security.
2Adaptability or versatility
If existing public-key encryption with keyword search methods are used, then multi-user access control is achieved, but encryption response time is long
Solution Approach 1:
The patent segments the encryption process into two phases: a preprocessing phase where public keys and encryption parameters are generated and stored, and a runtime phase where only lightweight encryption operations are performed. The system pre-generates multiple public keys corresponding to different importance levels and stores them for quick retrieval. This segmentation reduces encryption response time during file operations while maintaining multi-user access control capabilities.
Solution Approach 2:
The patent performs preliminary actions by pre-generating public keys, encryption parameters, and access control policies before actual file encryption operations. The system establishes encryption configurations for different importance levels in advance, so that during runtime, files can be quickly encrypted by selecting pre-prepared parameters rather than generating everything from scratch. This resolves the contradiction by reducing real-time encryption response time while preserving access control versatility.
3Ease of manufacture
If uniform encryption security levels are applied to all files, then implementation is simple, but security is poor for high-importance files
Solution Approach 1:
The patent introduces dynamics by making encryption security levels adaptive rather than static. The system automatically adjusts encryption strength based on file importance classification, transitioning from a static uniform encryption approach to a dynamic differentiated approach. This maintains implementation simplicity through automated classification and parameter selection while significantly improving security for high-importance files.
Data Source
AI summary
The invention provides a file storage method, a file search method and a file storage system based on public-key encryption with keyword search. The method comprises: receiving a user file storage request sent from a data possessor, acquiring access control attribute information for access to a user file, security level parameters and a keyword set of the user file, generating a file attribute vector of the user file by means of the access control attribute information and the keyword set, acquiring a public-secret key pair used for encrypting the file attribute vector from a pre-generated key space, encrypting the file attribute vector by means of a public key in the public-secret key pair to obtain a ciphertext corresponding to the file attribute vector, and transmitting the ciphertext corresponding to the file attribute vector and a ciphertext of the user file to a preset storage server.


