支持海量医疗数据语义搜索的可验证可搜索加密方案
网络出版日期: 2026-06-29
基金资助
国家自然科学基金资助项目(61902327);四川省自然科学基金面上项目(2025ZNSFSC0495)
版权
Verifiable searchable encryption scheme that supports semantic search over massive medical data
Online published: 2026-06-29
Copyright
随着云计算和医疗物联网的快速发展和广泛应用,海量医疗数据成为医疗领域的核心战略资源,云存储为其管理提供支撑的同时,带来了隐私保护与高效检索的双重挑战。现有可搜索加密方案存在海量数据检索效率低、缺乏语义关联、结果不可验证等问题,难以适配医疗数据的检索需求。本文提出支持海量医疗数据语义搜索的可验证可搜索加密方案。方案设计“粗匹配+精排序”二级检索架构,基于局部敏感哈希函数实现海量高维语义向量的快速粗匹配,设计隐私保护欧氏距离比较机制实现密文域内精准排序。方案设计公钥加密-私钥验证的批量验证机制,实现检索结果的正确性验证。通过改进矩阵型LWE(Learning With Errors)加密模式构建全流程密文域交互机制,实现医疗数据特征在抗量子环境下的机密特性,保障多主体协同下医疗数据与检索意图的隐私安全。性能分析与实验仿真表明,方案在100万数据量的搜索计算耗时不超过25秒,远低于其他线性扫描式的检索方案;在通信开销上,相较于其他同样支持向量检索的方案降低了50%,具备突出的性能优势,可有效适配海量医疗数据的隐私保护检索需求。
张经伟 , 孙飒 , 杨帅 , 吴颖 , 张晓均 . 支持海量医疗数据语义搜索的可验证可搜索加密方案[J]. 网络空间安全科学学报, 2026 . DOI: 10.20172/j.issn.2097-3136.260536
With the rapid development and wide application of cloud computing and the medical Internet of Things, massive medical data have become the core strategic resource in the medical field. While cloud storage supports the management of such data, it also brings the challenges of privacy protection and efficient retrieval. Existing searchable encryption schemes suffer from low retrieval efficiency over massive data, lack of semantic relevance, and unverifiable results, making it difficult to adapt to the retrieval requirements of medical data. This paper proposes a verifiable searchable encryption scheme that supports semantic search over massive medical data. The scheme designs a two-stage retrieval architecture of “coarse matching + fine ranking”. Fast coarse matching of massive high-dimensional semantic vectors is achieved based on locality-sensitive hashing, and accurate sorting in the ciphertext domain is achieved by designing privacy-preserving Euclidean distance comparison mechanism. A batch verification mechanism with public-key encryption and private-key verification is constructed to verify the correctness of retrieval results. Meanwhile, an improved matrix-based Learning with Errors (LWE) encryption mode is exploited to build a full-process ciphertext-domain interaction mechanism, which realizes the confidentiality of medical data features in a quantum-resistant environment, and guarantees the privacy security of medical data and retrieval intentions under multi-subject collaboration. Performance analysis and experimental simulations demonstrate the search computation time of the scheme is no more than 25 seconds for one million data items, which is much lower than existing linear-scan retrieval schemes. In terms of communication overhead, it is reduced by 50% compared with other schemes supporting vector retrieval. The proposed scheme has outstanding performance advantages and can effectively satisfy the privacy-preserving retrieval requirements of massive medical data.
表 2 不同模型明文与密文检索准确率(MAP)对比Table 2 The comparison of MAP between plaintext and ciphertext for different models |
| all-MiniLM- L6-v2 | all-MiniLM- L6-v1 | all-MiniLM- L12-v2 | msmarco-MiniLM- L-6-v3 | |
| 明文 | ||||
| 密文 |
表 3 计算开销比较Table 3 The computation overhead comparison |
| 算法 | 方案[28] | 方案[24] | 方案[23] | 本方案 |
| DataEnc | + | |||
| Trapdoor | ||||
| search | ||||
| verify | - | - |
| 1 |
谢晴晴, 宋亮晴, 冯霞. 面向医疗数据分享的轻量级且安全的搜索方案[J]. 通信学报, 2024, 45 (11): 206- 222.
Xie Q Q, SONG L Q, FENG X. Lightweight and secure search scheme for medical data sharing[J]. Journal on Communications, 2024, 45 (11): 206- 222.
|
| 2 |
Wang H J, Ning J T, Huang X Y, et al. Secure fine-grained encrypted keyword search for e-healthcare cloud[J]. IEEE Transactions on Dependable and Secure Computing, 2019, 18 (3): 1307- 1319.
|
| 3 |
张晓均, 张经伟, 黄超, 等. 可验证医疗密态数据聚合与统计分析方案[J]. 软件学报, 2022, 33 (11): 4285- 4302.
ZHANG X J, ZHANG J W, HUANG C, et al. Verifiable encrypted medical data aggregation and statistical analysis scheme[J]. Journal of Software, 2022, 33 (11): 4285- 4302.
|
| 4 |
王政, 王经纬, 殷新春. 支持用户撤销的可搜索电子健康记录共享方案[J]. 计算机应用, 2024, 44 (2): 504- 511.
Wang Z, WANG J W, YIN X C. Searchable electronic health record sharing scheme with user revocation[J]. Journal of Computer Applications, 2024, 44 (2): 504- 511.
|
| 5 |
Bao Y Y, Qiu W D, Cheng X C. Secure and lightweight fine-grained searchable data sharing for IoT-oriented and cloud-assisted smart healthcare system[J]. IEEE Internet of Things Journal, 2021, 9 (4): 2513- 2526.
|
| 6 |
张鸿越, 郑晓坤, 吴阿新, 等. 在线医疗社交网络中支持用户撤销的数据隐私保护方案[J]. 网络空间安全科学学报, 2023, 1 (2): 22- 34.
ZHANG H Y, ZHENG X K, WU A X, et al. Data Privacy protection scheme for supporting user revocation in online medical social network[J]. Journal of Cybersecurity, 2023, 1 (2): 22- 34.
|
| 7 |
Lai C Z, Ma Z, Guo R, Zheng D. Secure medical data sharing scheme based on traceable ring signature and blockchain[J]. Peer-to-Peer Networking and Applications, 2022, 15 (3): 1562- 1576.
|
| 8 |
童心悦, 陈付龙, 王涛春, 等. 基于智能合约和CP-ABE的病理信息可追溯安全共享方案[J]. 网络空间安全科学学报, 2025, 3 (3): 102- 116.
TONG X Y, CHEN F L, WANG T C, et al. Traceable and secure sharing scheme for pathological information based on smart contracts and CP-ABE[J]. Journal of Cybersecurity, 2025, 3 (3): 102- 116.
|
| 9 |
王祥宇, 马鑫迪, 梁岩荣, 等. 开放大数据安全存储与检索系统[J]. 网络空间安全科学学报, 2024, 2 (3): 13- 26.
WANG X Y, MA X D, LIANG Y R, et al. Secure storage and retrieval system for open big data[J]. Journal of Cybersecurity, 2024, 2 (3): 13- 26.
|
| 10 |
Chen B W, Xiang T, He D B, et al. BPVSE: Publicly verifiable searchable encryption for cloud-assisted electronic health records[J]. IEEE Transactions on Information Forensics and Security, 2023, 18, 3171- 3184.
|
| 11 |
Xia Z, Xiong N N, Vasilakos A V, et al. EPCBIR: An efficient and privacy-preserving content-based image retrieval scheme in cloud computing[J]. Information Sciences, 2017, 387, 195- 204.
|
| 12 |
Yang W Y, Zhu Y S. A verifiable semantic searching scheme by optimal matching over encrypted data in public cloud[J]. IEEE Transactions on Information Forensics and Security, 2020, 16, 100- 115.
|
| 13 |
Siam A A, Shohan S. Privacy-preserving AI for encrypted medical imaging: A framework for secure diagnosis and learning[J]. arXiv preprint arXiv: 2507.21060, 2025.
|
| 14 |
Zhang Y, Ou W H, Shi Y F, et al. Deep medical cross-modal attention hashing[J]. World Wide Web, 2022, 25 (4): 1519- 1536.
|
| 15 |
顾一凡, 杨雪冰, 朱承璋, 等. 面向患者跨模态检索的图增强哈希网络模型 [J]. 计算机辅助设计与图形学学报, DOI: 10.3724/SP.J.1089.2024-00351.
GU Y F, YANG X B, ZHU C Z, et al. Graph enhanced hashing networks for cross-modal patient retrieval[J]. Journal of Computer-Aided Design & Computer Graphics, DOI: 10.3724/SP.J.1089.2024-00351.
|
| 16 |
丁国辉, 张琦, 房士超, 等. 多模态检索在医学领域的研究综述[J]. 计算机工程与应用, 2023, 59(1): 26-36.
DING G H, ZHANG Q , FANG S C, et al. review of multi-modal retrieval in medicine[J]. Computer Engineering and Applications, 2023, 59(1): 26-36.
|
| 17 |
Nie X L, Zhang A Q, Wang Y, et al. SMKA: Secure multi-key aggregation with verifiable search for IoMT[J]. Computer Communications, 2025, 231, 108012.
|
| 18 |
Indyk P, Motwani R. Approximate nearest neighbors: Towards removing the curse of dimensionality[C]//Proceedings of the 30th Annual ACM Symposium on Theory of Computing, New York: ACM, 1998: 604-613.
|
| 19 |
Yuan J, Tian Y. Practical privacy-preserving MapReduce-based k-means clustering over large-scale dataset[J]. IEEE Transactions on Cloud Computing, 2017, 7 (2): 568- 579.
|
| 20 |
Song D X, Wagner D, Perrig A. Practical techniques for searches on encrypted data[C]//Proceedings of the 2000 IEEE Symposium on Security and Privacy. Los Alamitos: IEEE Computer Society, 2000: 44-55.
|
| 21 |
Xu G Q, Qi C, Dong W Y, et al. A privacy-preserving medical data sharing scheme based on blockchain[J]. IEEE Journal of Biomedical and Health Informatics, 2022, 27 (2): 698- 709.
|
| 22 |
Yang X D, Li X X, Chen A J, et al. Blockchain-based searchable proxy re-encryption scheme for EHR security storage and sharing[J]. Journal of Physics: Conference Series, 2021, 1828 (1): 012120.
|
| 23 |
Chen D J, Liao Z Y, Xie Z D, et al. MFSSE: Multi-keyword fuzzy ranked symmetric searchable encryption with pattern hidden in mobile cloud computing[J]. IEEE Transactions on Cloud Computing, 2024, 12 (4): 1042- 1057.
|
| 24 |
王祥宇, 马建峰, 苗银宾. 高效隐私保护的多用户图像外包检索方案[J]. 通信学报, 2019, 40 (2): 31- 39.
Wang X Y, MA J F, MIAO Y B. Efficient privacy-preserving image retrieval scheme over outsourced data with multi-user[J]. Journal on Communications, 2019, 40 (2): 31- 39.
|
| 25 |
Liao J X, Yang D, Li T H, et al. Fusion feature for LSH-based image retrieval in a cloud datacenter[J]. Multimedia Tools and Applications, 2016, 75, 15405- 15427.
|
| 26 |
Su Y X, Wang X A, Du W D, et al. A secure data fitting scheme based on CKKS homomorphic encryption for medical IoT[J]. Journal of High Speed Networks, 2023, 29 (1): 41- 56.
|
| 27 |
Boneh D, Di Crescenzo G, Ostrovsky R, et al. Public key encryption with keyword search[C]//International Conference on the Theory and Applications of Cryptographic Techniques. Berlin: Springer, 2004: 506-522.
|
| 28 |
Liu J L, Wei Z K, Qin J, et al. Verifiable key-aggregate searchable encryption with a designated server in multi-owner setting[J]. IEEE Transactions on Services Computing, 2023, 16 (6): 4233- 4247.
|
| 29 |
Rahman M S, Khalil I, Moustafa N, et al. A blockchain-enabled privacy-preserving verifiable query framework for securing cloud-assisted industrial Internet of Things systems[J]. IEEE Transactions on Industrial Informatics, 2021, 18 (7): 5007- 5017.
|
| 30 |
Gao H C, Huang H P, Xue L Y, et al. Blockchain-enabled fine-grained searchable encryption with cloud–edge computing for electronic health records sharing[J]. IEEE Internet of Things Journal, 2023, 10 (20): 18414- 18425.
|
| 31 |
Bajaj P, Campos D, Craswell N, et al. MS MARCO: A human generated machine reading comprehension dataset[J/OL]. 2018 [2026-03-22], DOI: 10.48550/arXiv.1611.09268.
|
/
| 〈 |
|
〉 |