Skip to main navigation Skip to search Skip to main content

SecDiv: Privacy-Preserving Diversity-Constrained Top-k Query Processing in the Cloud

  • Yinxing Zhang
  • , Guang Tang
  • , Qingwang Wang
  • , Songlei Wang*
  • , Zhiquan Liu
  • , Zhongyun Hua
  • *Corresponding author for this work
  • Kunming University of Science and Technology
  • Shenzhen University
  • Jinan University
  • Harbin Institute of Technology

Research output: Contribution to journalArticlepeer-review

Abstract

With the proliferation of cloud computing, outsourcing databases has become a common strategy for reducing on premise storage and computation costs. However, this approach raises serious privacy concerns, as sensitive data and query information may be exposed to the cloud. While existing top-k query methods have made progress in performance and privacy protection, they offer limited support for the more advanced requirement of diversity constrained queries. In light of this, we present SecDiv, the first privacy-preserving query system that supports diversity constraints over ciphertext in the cloud. SecDiv is built on a two-server distributed trust model and lightweight additive secret sharing, and hides data contents under an honest-but-curious, non-colluding adversary model to ensure that cloud servers learn no sensitive information. SecDiv comprises three customized secure components: SecDMap maps the structured database of the data owner into two secret-shared tables; SecQMap translates each SQL statement and its diversity constraints into vectors whose lengths match the database attributes, thereby hiding targeted attributes and literal values; and SecCQ performs secure filtering, ordering, and top-k selection in the cloud, centered on a secure most significant bit comparison implemented by a parallel-prefix adder. A formal security analysis is conducted to provide theoretical guarantees for the security of SecDiv. SecDiv is evaluated on three real datasets, with diversity constraints configured using top-k and category count conditions to emulate practical ranking scenarios. Compared with a plaintext baseline, SecDiv achieves identical results with 100% accuracy. Query latency remains practical, with second-level response times in typical settings, and communication overhead increases as expected. Overall, experimental results demonstrate that SecDiv attains a balanced trade-off among privacy, accuracy, and efficiency in real-world cloud service environments.

Original languageEnglish
JournalIEEE Transactions on Services Computing
DOIs
StateAccepted/In press - 2026
Externally publishedYes

Keywords

  • Privacy-preserving
  • additive secret sharing
  • cloud computing
  • diversity constraints
  • encrypted database outsourcing

Fingerprint

Dive into the research topics of 'SecDiv: Privacy-Preserving Diversity-Constrained Top-k Query Processing in the Cloud'. Together they form a unique fingerprint.

Cite this