Anonymity query method and device, electronic equipment and storage medium

By using query identifiers and inadvertent transmission protocols in the PIR scheme, the amount of data and computational complexity are reduced, solving the problem of increased computational complexity in the PIR scheme and achieving efficient covert queries.

CN115905238BActive Publication Date: 2026-06-30LINGSHU TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
LINGSHU TECH CO LTD
Filing Date
2022-12-12
Publication Date
2026-06-30

AI Technical Summary

Technical Problem

The computational complexity of the unintentionally transmitted PIR scheme increases linearly with the amount of data, and the query efficiency decreases sharply.

Method used

By defining a query identifier, which instructs the service provider to query the ciphertext sequence and location index sequence of the fragmented storage area, and combining it with the unintentional transmission protocol to obtain the target key for decryption, the amount of data and computational complexity are reduced.

Benefits of technology

Significantly reduce the amount of data queried, improve the query efficiency of the hidden query system, and ensure query anonymity and data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115905238B_ABST
    Figure CN115905238B_ABST
Patent Text Reader

Abstract

This application discloses a covert query method, apparatus, electronic device, and storage medium. In response to a query request for data to be queried, a query identifier for the data to be queried is determined. The query identifier is used to determine the fragmented storage area of ​​the data to be queried in the service provider's database. The query identifier is sent to the service provider, instructing the service provider to query and return the ciphertext sequence and corresponding location index sequence in the fragmented storage area corresponding to the query identifier. The fragmented storage area is an area where the service provider stores data in fragments based on the original location indexes of each data in the database. The ciphertext sequence and location index sequence are obtained, and the target ciphertext is determined from the ciphertext sequence based on the location index sequence. A covert key sequence sent by the service provider based on an unintentional transmission protocol is obtained, and the target key of the target ciphertext is determined from the covert key sequence. The target ciphertext is decrypted based on the target key to obtain the plaintext information of the data to be queried. This application reduces the amount of data queried and improves the query efficiency of the covert query system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to secure multi-party computation techniques, and more particularly to a method, apparatus, electronic device, and storage medium for covert querying. Background Technology

[0002] Hidden queries, also known as Private Information Retrieval (PIR), are a highly practical technique and application in secure multi-party computation. They can be used to protect both query conditions and query results. The goal is to ensure that when a query node submits a query request to a service node, the query is completed without the query conditions being known to the service node.

[0003] Oblivious Transfer (OT), also known as the forgetful transfer protocol, is an important method for covertly retrieving parts of a message from a message set. Oblivious Transfer Protocol Retrieval (PIR) is a common implementation of PIR schemes.

[0004] However, the computational complexity of the unintentionally transmitted PIR scheme increases linearly with the amount of data, and the query efficiency also decreases sharply. Summary of the Invention

[0005] This application provides a method, apparatus, electronic device, and storage medium for covert querying, in order to reduce the amount of data queried and improve the query efficiency of the covert query system.

[0006] In a first aspect, embodiments of this application provide a hidden query method, applied to a querying party, the hidden query method comprising:

[0007] In response to a query request for data to be queried, a query identifier for the data to be queried is determined; the query identifier is used to determine the sharded storage area of ​​the data to be queried in the service provider.

[0008] The query identifier is sent to the service provider, which instructs the service provider to query and return the encrypted sequence and the corresponding location index sequence in the sharded storage area corresponding to the query identifier; the sharded storage area is the area in which the service provider shards and stores each piece of data according to the original location index of each piece of data in the database.

[0009] Obtain the ciphertext sequence and the position index sequence, and determine the target ciphertext from the ciphertext sequence based on the position index sequence;

[0010] Obtain the hidden key sequence sent by the service provider based on the unintentional transmission protocol, and determine the target key of the target ciphertext from the hidden key sequence;

[0011] The target ciphertext is decrypted using the target key to obtain the plaintext information of the data to be queried.

[0012] Secondly, embodiments of this application provide a covert query method, applied to a service provider, the covert query method comprising:

[0013] Obtain the query identifier sent by the querying party; wherein the query identifier is determined by the querying party based on the hash value of the original location index of the data to be queried and the indistinguishable factor;

[0014] Based on the query identifier, retrieve the ciphertext sequence and the corresponding location index sequence stored in the segmented storage area corresponding to the query identifier;

[0015] The ciphertext sequence and the position index sequence are fed back to the querying party to instruct the querying party to determine the target ciphertext from the ciphertext sequence based on the position index sequence;

[0016] Based on the unintentional transmission protocol, a hidden key sequence is sent to the querying party to instruct the querying party to determine the target key from the hidden key sequence and decrypt the target ciphertext according to the target key to obtain the plaintext information of the data to be queried.

[0017] Thirdly, embodiments of this application also provide a covert query device, configured on the querying party, the covert query device comprising:

[0018] The query identifier determination module is used to determine the query identifier of the data to be queried in response to a query request for the data to be queried; the query identifier is used to determine the sharded storage area of ​​the data to be queried in the service provider;

[0019] The query identifier sending module is used to send the query identifier to the service provider, which instructs the service provider to query and return the encrypted sequence and the corresponding location index sequence in the sharded storage area corresponding to the query identifier; wherein, the sharded storage area is the area in which the service provider shards and stores each piece of data according to the original location index of each piece of data in the database.

[0020] The target ciphertext determination module is used to obtain the ciphertext sequence and the position index sequence, and determine the target ciphertext from the ciphertext sequence based on the position index sequence.

[0021] The target key determination module is used to obtain the hidden key sequence sent by the service provider based on the unintentional transmission protocol, and to determine the target key of the target ciphertext from the hidden key sequence;

[0022] The target ciphertext decryption module is used to decrypt the target ciphertext based on the target key to obtain the plaintext information of the data to be queried.

[0023] Fourthly, embodiments of this application also provide a concealed query device, configured on a service provider, the concealed query device comprising:

[0024] The query identifier acquisition module is used to acquire the query identifier sent by the querying party; wherein, the query identifier is determined by the querying party based on the hash value of the original location index of the data to be queried and the indistinguishable factor;

[0025] The data query module is used to query the ciphertext sequence and the corresponding location index sequence stored in the segmented storage area corresponding to the query identifier, based on the query identifier.

[0026] The data feedback module is used to feed back the ciphertext sequence and the position index sequence to the querying party, so as to instruct the querying party to determine the target ciphertext from the ciphertext sequence based on the position index sequence;

[0027] The hidden key sending module is used to send a hidden key sequence to the querying party based on an unintentional transmission protocol, so as to instruct the querying party to determine the target key from the hidden key sequence and decrypt the target ciphertext according to the target key to obtain the plaintext information of the data to be queried.

[0028] Fifthly, embodiments of this application also provide an electronic device, which includes:

[0029] One or more processors;

[0030] Storage device for storing one or more programs;

[0031] When one or more programs are executed by one or more processors, the one or more processors implement any of the covert query methods provided in the embodiments of this application.

[0032] Sixthly, embodiments of this application also provide a storage medium including computer-executable instructions, which, when executed by a computer processor, are used to perform any of the covert query methods provided in embodiments of this application.

[0033] This application, in response to a query request for data to be queried, determines a query identifier for the data to be queried. The query identifier is used to determine the sharded storage area of ​​the data to be queried within the service provider's database. The query identifier is sent to the service provider, instructing it to query and return the ciphertext sequence and corresponding location index sequence within the sharded storage area corresponding to the query identifier. The sharded storage area is the area where the service provider shards and stores data based on the original location indexes of each data item in the database. By using the query identifier, only the data within the sharded storage area corresponding to the query identifier needs to be queried, significantly reducing the amount of data queried. The application obtains the ciphertext sequence and location index sequence, and determines the target ciphertext from the ciphertext sequence based on the location index sequence. The service provider cannot know the data being queried by the querying party, thus ensuring the security of the query. The method achieves the following: First, it ensures the concealment of the data. Since the obtained data is a ciphertext sequence, the querying party cannot access data other than the data to be queried, thus guaranteeing data security. Second, it obtains a hidden key sequence sent by the service provider based on an unintentional transmission protocol and determines the target key of the target ciphertext from this sequence. Obtaining the target key through unintentional transmission also achieves concealed key acquisition, protecting the information concealment of the querying party. Since only the key of the ciphertext sequence corresponding to the query identifier area needs to be queried, the data volume and computational complexity of the key transmission process based on the unintentional transmission protocol are significantly reduced, improving the efficiency of unintentional transmission and thus improving the efficiency of concealed query. Third, it decrypts the target ciphertext based on the target key to obtain the plaintext information of the data to be queried, achieving concealed data query. Therefore, the technical solution of this application solves the problem that the computational complexity of the unintentional transmission PIR scheme increases linearly with the increase of data volume, and the query efficiency decreases linearly, achieving the effect of reducing the amount of data queried and improving the query efficiency of the concealed query system. Attached Figure Description

[0034] Figure 1 This is a flowchart of a covert query method according to Embodiment 1 of this application;

[0035] Figure 2 This is a flowchart of a covert query method according to Embodiment 2 of this application;

[0036] Figure 3 This is a flowchart of a covert query method according to Embodiment 3 of this application;

[0037] Figure 4 This is a flowchart of a covert query method according to Embodiment 4 of this application;

[0038] Figure 5 This is a flowchart of a covert query method according to Embodiment 5 of this application;

[0039] Figure 6This is a schematic diagram of the structure of a covert query device according to Embodiment Six of this application;

[0040] Figure 7 This is a schematic diagram of the structure of a covert query device according to Embodiment 7 of this application;

[0041] Figure 8 This is a schematic diagram of the structure of an electronic device according to Embodiment 8 of this application. Detailed Implementation

[0042] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.

[0043] It should be noted that the terms "first" and "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0044] Example 1

[0045] Figure 1 This is a flowchart of a hidden query method provided in Embodiment 1 of this application. This embodiment can be applied to the situation of hidden querying data. The method can be executed by a hidden query device, which can be implemented in software and / or hardware and specifically configured in the querying party, such as a computer.

[0046] See Figure 1 The hidden query method shown is applied to the querying party and specifically includes the following steps:

[0047] S110. In response to a query request for data to be queried, determine the query identifier of the data to be queried; the query identifier is used to determine the sharded storage area of ​​the data to be queried in the service provider.

[0048] The data to be queried can be the data that a user needs to retrieve. The query request can be a request from the user to query the data to be queried, obtained by the querying party. Specifically, the query request may include a unique identifier for the data to be queried. For example, the unique identifier for the data to be queried can be a data name, a data label, or at least one of the original indexes in the database. When a user needs to query the data to be queried, they perform the query on the querying party's end. For example, the querying party enters the data name of the data to be queried, at which point the querying party obtains the user's query request and responds to it.

[0049] A query identifier can be the identifier of the data to be queried in a sharded storage area after the original stored data in the database has been sharded. It is used to determine the sharded storage area of ​​the data to be queried within the service provider's database. The querying party determines the original index of the data to be queried in the database based on the unique identifier in the query request, and then determines the query identifier of the data to be queried based on the service provider's sharding storage principles. The sharding storage principles are pre-stored by the querying party regarding the sharding principles used by the service provider to determine the query identifiers of the sharded storage areas. For example, a sharding storage principle could be to map the original index of the data using a sharding function, storing the data corresponding to the original indexes mapped to the same function value in the same sharded storage area, where the same mapped function value is the query identifier of that sharded storage area. Alternatively, a sharding storage principle could be to encode the original index of the data using encoding rules, storing the data corresponding to the original indexes with the same encoding in the same sharded storage area, where the same encoded value is the query identifier of that sharded storage area.

[0050] S120. Send the query identifier to the service provider, which instructs the service provider to query and return the ciphertext sequence and the corresponding location index sequence in the sharded storage area corresponding to the query identifier. The sharded storage area is the area in which the service provider shards and stores each piece of data according to the original location index of each piece of data in the database.

[0051] After determining the query identifier, the querying party sends it to the service provider. By sending the query identifier to the service provider, the service provider is instructed to retrieve the data corresponding to the query identifier. The ciphertext sequence can be a sequence of ciphertexts corresponding to the data stored in the segmented storage area corresponding to the query identifier. Correspondingly, the location index sequence can be a sequence of the original location indexes in the database corresponding to each ciphertext. The ciphertext sequence and the location index sequence are associated through sequence numbers; that is, the sequence number of the ciphertext and the sequence number of its corresponding location index are the same.

[0052] Specifically, the data stored in the sharded storage area includes ciphertext, the corresponding encryption key, and the original location index in the database. When the service provider shards the data, it can assign a corresponding key to each piece of data to encrypt it, obtaining the ciphertext. The ciphertext, the corresponding encryption key, and the original location index in the database are stored as a single data record in the sharded storage area corresponding to the query identifier. Data records within the same data record have the same sequence number. A sharded storage area is a region where the service provider shards the data according to the original location index of each piece of data in the database. Each sharded storage area corresponds to one query identifier and contains multiple data records.

[0053] S130. Obtain the ciphertext sequence and the position index sequence, and determine the target ciphertext from the ciphertext sequence based on the position index sequence.

[0054] The target ciphertext can be the ciphertext of the data corresponding to the data to be queried, used to obtain the data to be queried. The ciphertext sequence and location index sequence sent by the service provider are obtained. Matching is performed between the original location index of the data to be queried and each location index in the location index sequence. If a match is successful, the ciphertext corresponding to that location index is the ciphertext corresponding to the data to be queried, and this ciphertext is used as the target ciphertext.

[0055] In an optional embodiment, determining the target ciphertext from the ciphertext sequence based on the position index sequence includes: determining the target index based on the position index sequence and the original position index; and determining the ciphertext in the ciphertext sequence corresponding to the target index as the target ciphertext.

[0056] The original location index can be the location index in the database before the data is sharded and stored. The target index can be the sequence number of the location index that is the same as the original location index of the data to be queried. For example, the location indices in the location index sequence can be compared sequentially with the original location index. If they are the same, the sequence number of that location index is determined as the target index. Ciphertext with the same sequence number as the target index in the ciphertext sequence is determined as the target ciphertext.

[0057] By determining the target index based on the position index sequence and the original position index, the ciphertext corresponding to the target index in the ciphertext sequence is identified as the target ciphertext. The target index is determined based on the original position index, and then the target ciphertext is determined based on the target index. This achieves accurate determination of the target ciphertext, ensuring that the query information is not perceived by the service provider and that the querying party cannot obtain any information other than the query information, thus ensuring the anonymity of the query and the security of the data.

[0058] S140. Obtain the hidden key sequence sent by the service provider based on the unintentional transmission protocol, and determine the target key of the target ciphertext from the hidden key sequence.

[0059] An inadvertent transmission protocol can be a method for secretly obtaining a portion of information from a set of information. Specifically, inadvertent transmission protocols can include 1-out-of-2 and 1-out-of-n (where n is an integer greater than 2). That is, an inadvertent transmission protocol can obtain one piece of information from two pieces of information, or it can obtain one piece of information from n pieces of information, without the information provider knowing the specific information obtained by the information recipient. Furthermore, the information recipient can only obtain one piece of information, ensuring the anonymity of the information recipient and the security of the information provided by the information service provider.

[0060] The concealed key sequence can be a sequence in which the service provider conceals the key sequence using an unintentional transmission protocol. The key sequence can be a sequence of keys stored in the same segmented storage area as the query identifier. The target key can be the key corresponding to the target ciphertext, used to decrypt the target ciphertext to obtain the plaintext information of the data to be queried.

[0061] After obtaining the hidden key sequence sent by the service provider based on the unintentional transmission protocol, the querying party parses the target key sequence in the hidden key sequence according to the sequence number or original location index of the target ciphertext and obtains the target key.

[0062] S150. Decrypt the target ciphertext using the target key to obtain the plaintext information of the data to be queried.

[0063] The target ciphertext is decrypted using the target key to obtain the plaintext information of the data to be queried. For example, the target ciphertext can be encrypted using symmetric encryption, and the plaintext information of the data to be queried is obtained by decrypting the target ciphertext using the encryption algorithm and the target key.

[0064] The technical solution of this embodiment determines a query identifier for the data to be queried in response to a query request. This query identifier is then sent to the service provider, instructing them to query and return the ciphertext sequence and corresponding location index sequence in the sharded storage area corresponding to the query identifier. The sharded storage area is the region where the service provider shards and stores data based on the original location indexes of each data item in the database. By using the query identifier, only the data in the sharded storage area corresponding to the query identifier needs to be queried, significantly reducing the amount of data queried. The ciphertext sequence and location index sequence are obtained, and the target ciphertext is determined from the ciphertext sequence based on the location index sequence. The service provider cannot explicitly know the data queried by the client, ensuring the anonymity of the query. Furthermore, because the ciphertext sequence and location index sequence are obtained... The ciphertext sequence is obtained, preventing the querying party from accessing data other than the data to be queried, thus ensuring data security. A hidden key sequence sent by the service provider based on an unintentional transmission protocol is obtained, and the target key of the target ciphertext is determined from this sequence. Obtaining the target key through unintentional transmission also achieves unintentional key acquisition, protecting the querying party's information confidentiality. Since only the key of the ciphertext sequence corresponding to the query identifier area needs to be queried, the data volume and computational complexity of the key transmission process based on the unintentional transmission protocol are significantly reduced, improving the efficiency of unintentional transmission and consequently, the efficiency of unintentional query. The target ciphertext is decrypted using the target key to obtain the plaintext information of the data to be queried. This decryption process enables unintentional data querying. Therefore, the technical solution of this application solves the problem that the computational complexity of the unintentional transmission PIR scheme increases linearly with the increase of data volume, and the query efficiency decreases linearly, achieving the effect of reducing the amount of data queried and improving the query efficiency of the unintentional query system.

[0065] Example 2

[0066] Figure 2 This is a flowchart of a hidden query method provided in Embodiment 2 of this application. The technical solution of this embodiment is further refined based on the above technical solution.

[0067] Furthermore, the phrase "in response to a query request for data to be queried, determine the query identifier of the data to be queried" is further refined to: "According to the query request, obtain the original location index of the data to be queried; according to the preset hash algorithm, determine the hash value of the original location index; according to the indistinguishable factor and the hash value of the original location index, determine the query identifier of the data to be queried" to determine the query identifier.

[0068] See Figure 2 The method shown includes:

[0069] S210. Based on the query request, obtain the original location index of the data to be queried.

[0070] The query request includes a unique identifier for the data to be queried, and the original location index of the data to be queried is determined based on the unique identifier. For example, the querying party may store the original location indexes of all queried data from the service provider, along with their corresponding unique identifiers.

[0071] S220. Determine the hash value of the original location index according to the preset hash algorithm.

[0072] A hash algorithm is an irreversible encryption algorithm that can transform an input of arbitrary length into an output of fixed length. For example, a hash algorithm can be one of the following: division remainder method, folding method, digit analysis method, or random number method; this application does not specifically limit this. According to a preset hash algorithm, the original location index of the data to be queried is hashed to obtain the hash value of the original location index.

[0073] S230. Determine the query identifier of the data to be queried based on the hash value of the indistinguishable factor and the original location index.

[0074] The indistinguishability factor is a pre-set parameter that can be configured by technical personnel. For example, the indistinguishability factor can be 2. Based on the value of the indistinguishability factor, for example, t, the first t bits of the hash value of the original location index under a certain encoding rule are determined as the query identifier for the data to be queried.

[0075] For example, if the indistinguishability factor is 2, the hash value of the original location index is encoded in binary, and the storage area is divided into 4 partitions, then the query identifiers are 00, 01, 10, and 11. For example, the encoding rule can be multi-base encoding or character encoding, etc. For example, multi-base encoding can be binary encoding, quaternary encoding, octal encoding, and hexadecimal encoding, etc., and this application does not specifically limit this. For example, character encoding can be ASCII (a technical term, a character encoding method).

[0076] S240. Send the query identifier to the service provider, which instructs the service provider to query and return the encrypted sequence and corresponding location index sequence in the sharded storage area corresponding to the query identifier. The sharded storage area is the area in which the service provider shards and stores each piece of data according to the original location index of each piece of data in the database.

[0077] S250. Obtain the ciphertext sequence and the position index sequence, and determine the target ciphertext from the ciphertext sequence based on the position index sequence.

[0078] S260. Obtain the hidden key sequence sent by the service provider based on the unintentional transmission protocol, and determine the target key of the target ciphertext from the hidden key sequence.

[0079] S270. Decrypt the target ciphertext using the target key to obtain the plaintext information of the data to be queried.

[0080] The technical solution of this embodiment obtains the original location index of the data to be queried based on the query request, and the data to be queried can be accurately determined based on the original location index. A hash value of the original location index is determined according to a preset hash algorithm, and the original location index of the data to be queried is encrypted using the hash algorithm to ensure the security of the transmission process. A query identifier of the data to be queried is determined based on the indistinguishable factor and the hash value of the original location index. The service provider pre-segments the data in the database, and determines the query identifier of the segmented region based on the indistinguishable factor and the hash value of the original location index. The querying party determines the query identifier using the same method, which can reduce the number of traversals during the query and improve query efficiency. Since the computational complexity of the unintentionally transmitted PIR scheme increases linearly with the increase of data volume, and the query efficiency also decreases linearly, determining the query identifier reduces the amount of data to be queried, thus avoiding the linear increase in computational complexity of the unintentionally transmitted PIR scheme with the increase of data volume, thereby improving the query efficiency of the covert query system.

[0081] Example 3

[0082] Figure 3 This is a flowchart of a hidden query method provided in Embodiment 3 of this application. The technical solution of this embodiment is further refined based on the above technical solution.

[0083] Furthermore, the phrase "obtaining the hidden key sequence sent by the service provider based on the unintentional transmission protocol and determining the target key of the target ciphertext from the hidden key sequence" is refined to: "obtaining the auxiliary point sequence sent by the service provider and determining the target auxiliary point from the auxiliary point sequence according to the target index; generating a hidden index according to the first random number and the target auxiliary point and sending it to the service provider to instruct the service provider to generate and return the hidden key sequence corresponding to the key sequence according to the hidden index and the auxiliary point sequence; parsing the hidden key sequence according to the first random number and the target index to obtain the target key" to determine the target key.

[0084] See Figure 3 The method shown includes:

[0085] S310. In response to a query request for data to be queried, determine the query identifier of the data to be queried; the query identifier is used to determine the sharded storage area of ​​the data to be queried in the service provider.

[0086] S320. Send the query identifier to the service provider, which instructs the service provider to query and return the ciphertext sequence and the corresponding location index sequence in the sharded storage area corresponding to the query identifier. The sharded storage area is the area in which the service provider shards and stores each piece of data according to the original location index of each piece of data in the database.

[0087] S330 acquires the ciphertext sequence and the position index sequence, and determines the target ciphertext from the ciphertext sequence based on the position index sequence.

[0088] S340. Obtain the auxiliary point sequence sent by the service provider, and determine the target auxiliary point from the auxiliary point sequence according to the target index.

[0089] The auxiliary point sequence is a sequence of points generated by the service provider based on the unintentional transport protocol. Specifically, the service provider generates a second random number r2 and maps it to points on an elliptic curve using the formula Y = r2 * G to generate the auxiliary point sequence P = (P1, P2, ..., P...). n ), where G is the generator of the elliptic curve, and n can be the number of records in the segmented storage area, and the auxiliary point sequence is sent to the querying party. The querying party obtains the auxiliary point sequence and identifies the auxiliary points in the auxiliary point sequence with the same sequence number as the target index as the target auxiliary points.

[0090] S350. Generate a hidden index based on the first random number and the target auxiliary point, and send it to the service provider to instruct the service provider to generate and return the hidden key sequence corresponding to the key sequence based on the hidden index and the auxiliary point sequence.

[0091] The first random number is generated by the querying party and is used to conceal the index number of the target auxiliary point, so that the service provider cannot discover the content queried by the querying party. Specifically, the first random number can be generated by a random function.

[0092] The hidden index can be an index obtained after performing hidden calculations on the target auxiliary points. For example, the hidden index can be obtained using the following formula:

[0093] U = r1 * G + P idx

[0094] Where U is the hidden index, r1 is the first random number, and P idx Let G be the target auxiliary point, and G be the generator of the elliptic curve.

[0095] The querying party sends the generated hidden index to the service provider. The service provider, based on the hidden index and auxiliary point sequence, uses a preset formula to hide the key sequence, generating and returning the corresponding hidden key sequence.

[0096] S360. Based on the first random number and the target index, the hidden key sequence is parsed to obtain the target key.

[0097] The target key can be the key corresponding to the target index, i.e., the key of the target ciphertext, which can be used to decrypt the target ciphertext. Based on the first random number and the target index, the hidden key sequence is parsed using computational logic. If the parsed hidden key is the target key corresponding to the target index, the target key can be obtained; otherwise, parsing fails, ensuring that the querying party cannot obtain other keys.

[0098] S370. Decrypt the target ciphertext using the target key to obtain the plaintext information of the data to be queried.

[0099] The technical solution of this embodiment obtains the auxiliary point sequence sent by the service provider and determines the target auxiliary point from the auxiliary point sequence according to the target index; generates a hidden index based on the first random number and the target auxiliary point and sends it to the service provider to instruct the service provider to generate and return the hidden key sequence corresponding to the key sequence based on the hidden index and the auxiliary point sequence; and parses the hidden key sequence according to the first random number and the target index to obtain the target key. By obtaining the target key through unintentional transmission, the anonymity of the query by the querying party can be guaranteed, and the service provider cannot discover the content of the query by the querying party. At the same time, it ensures that the querying party cannot obtain other keys, thus ensuring the security of other keys. Since the key sequence is the key sequence of the ciphertext corresponding to the segmented storage area, the computational load of the unintentional transmission protocol is significantly reduced, improving the efficiency of the hidden key sequence transmission.

[0100] Example 4

[0101] Figure 4 This is a flowchart of a hidden query method provided in Embodiment 4 of this application. This embodiment can be applied to the situation of hidden querying of data. The method can be executed by a hidden query device, which can be implemented by software and / or hardware and specifically configured in the service provider, such as a computer.

[0102] See Figure 4 The hidden query method shown, when applied to the service provider, includes the following steps:

[0103] S410. Obtain the query identifier sent by the querying party; wherein the query identifier is determined by the querying party based on the hash value of the original location index of the data to be queried and the indistinguishable factor.

[0104] The original location index of data in a database can be an index after the database stores data according to data storage rules. The corresponding data can be accessed based on this original location index. To improve the efficiency of hidden queries, this application segments the data that may be subject to hidden queries and generates query identifiers for the segmented data, which are used to retrieve the corresponding data.

[0105] Specifically, a hash calculation can be performed on the original location index of the data to obtain the hash value of the original location index. Based on the value t of the indistinguishable factor, the first t characters in the hash value of the original location index are used as the query identifier.

[0106] S420. Based on the query identifier, query the ciphertext sequence and the corresponding location index sequence stored in the segmented storage area corresponding to the query identifier.

[0107] Based on the obtained query identifier of the query party, traverse the ciphertext in the sharded storage area corresponding to the query identifier, and generate a ciphertext sequence according to the sequence number in the sharded storage area; traverse the position index in the sharded storage area corresponding to the query identifier, and generate a position index sequence according to the sequence number in the sharded storage area.

[0108] S430. Feed back the ciphertext sequence and the position index sequence to the querying party to instruct the querying party to determine the target ciphertext from the ciphertext sequence based on the position index sequence.

[0109] The ciphertext sequence and the position index sequence are fed back to the querying party. The querying party stores the original position index of the data in the database; therefore, it can determine the target ciphertext from the ciphertext sequence based on the position index sequence. Specifically, the target index can be determined first from the position index sequence, and then the ciphertext in the ciphertext sequence corresponding to the target index can be identified as the target ciphertext.

[0110] S440. Based on the unintentional transmission protocol, a hidden key sequence is sent to the querying party to instruct the querying party to determine the target key from the hidden key sequence and to decrypt the target ciphertext according to the target key to obtain the plaintext information of the data to be queried.

[0111] The service provider, based on the query identifier, traverses the keys in the corresponding sharded storage area, generates a key sequence according to the sequence number in the sharded storage area, generates a hidden key sequence based on the unintentional transmission protocol, and sends the hidden key sequence to the querying party.

[0112] The querying party obtains the hidden key sequence sent by the service provider based on the unintentional transmission protocol, determines the target key from the hidden key sequence, and decrypts the target ciphertext according to the target key to obtain the plaintext information of the data to be queried.

[0113] The technical solution of this embodiment obtains a query identifier sent by the querying party. The query identifier is determined by the querying party based on the hash value and indistinguishability factor of the original location index of the data to be queried. Based on the query identifier, the ciphertext sequence and corresponding location index sequence stored in the corresponding segmented storage area are retrieved. The ciphertext sequence and location index sequence are fed back to the querying party, instructing them to determine the target ciphertext from the ciphertext sequence based on the location index sequence. By querying using the query identifier, only the data corresponding to the query identifier needs to be queried, reducing the amount of data queried. Sending the ciphertext sequence and corresponding location index sequence to the querying party protects the query's anonymity; the service provider cannot clearly know the data queried by the querying party, thus ensuring query anonymity. Furthermore, since the ciphertext sequence is sent, the data security is guaranteed. To ensure data security, this application employs an inadvertent transmission protocol. A hidden key sequence is sent to the querying party, instructing them to determine the target key from the sequence and decrypt the target ciphertext to obtain the plaintext of the query data. This inadvertent transmission also protects the querying party's information confidentiality and prevents other keys from being obtained, thus ensuring their security. Since only the hidden key sequence of the ciphertext sequence corresponding to the query identifier's area needs to be sent, computational complexity and data volume are significantly reduced, improving the efficiency of inadvertent transmission and consequently, the efficiency of covert queries. Therefore, this technical solution addresses the problem that the computational complexity of inadvertent transmission PIR schemes increases linearly with data volume, leading to a sharp decline in query efficiency. This achieves the goal of reducing the amount of data queried and improving the efficiency of the covert query system.

[0114] In an optional embodiment, before obtaining the query identifier sent by the querying party, the covert query method further includes: storing each piece of data in segments according to the original location index of each piece of data in the database.

[0115] Sharded storage allows for the partitioning of data within a database into different regions, reducing the amount of data retrieval required for subsequent queries. Specifically, different shard identifiers are obtained by mapping the original location indexes of each data point in the database. Data with the same shard identifier is then stored within the same shard region, thus achieving sharded storage.

[0116] By sharding and storing data according to the original location index of each data in the database, the amount of subsequent data lookup queries can be reduced. It is not necessary to query all data in the database; only the data stored in the sharded storage area needs to be queried, which greatly reduces the amount of data query. At the same time, by sharding and storing data according to the original location index of each data in the database, a mapping relationship between the storage location of the sharded data and the original location index can be established, ensuring the correctness of the data query results.

[0117] In one optional embodiment, each piece of data is stored in shards according to its original location index in the database, including: obtaining the original location index of the data stored in the database; determining the hash value of the original location index according to a preset hash algorithm; and determining the query identifier of the data stored in the database in the sharded storage area according to the indistinguishable factor and the hash value of the original location index.

[0118] The service provider pre-segments the data stored in the database according to the segmentation storage rules of the segmented storage area, and determines the query identifier for each piece of data after segmentation.

[0119] The database stores data as records (ID) i , data i ), where ID i For the original location index, data i The data to be stored is (i = 1, 2, ..., N), where N is the number of records stored in the database. The data to be read from the database is... i Original location index ID i Get the original location index of the data stored in the database.

[0120] The preset hash algorithm can be a pre-defined hash algorithm that can be used to encrypt the original location index. A hash calculation is performed on the original location index to obtain its hash value.

[0121] For example, the hash value of the original location index can be obtained by the following formula:

[0122] H i =hash(ID) i );

[0123] Among them, ID i The original location index is given by H, where hash() is the hash function. i The hash value of the original location index.

[0124] The indistinguishability factor can be a pre-defined value used to determine the query identifier. Based on the indistinguishability factor and the hash value of the original location index, the query identifier for the data stored in the database within the sharded storage area is determined. For example, if the indistinguishability factor is t, the first t bits of the hash value of the original location index are used as the query identifier.

[0125] Specifically, query identifier H i-t For H i The first t characters under the preset encoding rules. H i_t (i = 1, 2, ..., N) Data with the same information is stored in the same partitioned storage area corresponding to the same query identifier, H i_t The corresponding data is (C) i ,k i ,loc i ), where C i For ciphertext, k i For the key, loc i The original location index is i, where i is the sequence number in the sharded storage area corresponding to the query identifier.

[0126] Assuming the result after partitioning is: F = {f1, ..., f m}, where m is the number of fragments. Where N is the total number of data in the database, that is, the total number of data to be stored in shards.

[0127] If the number of partitioned storage regions m = 4 and t = 2, then under the condition that the data stored in the database is uniformly distributed, H i In binary encoding, there are four cases: H1=00, H2=01, H3=10, and H4=11. This means the data is divided into four storage areas (H1, H2, H3, and H4) for fragmented storage.

[0128]

[0129]

[0130]

[0131]

[0132] in,

[0133] By obtaining the original location index of the stored data in the database, determining the hash value of the original location index according to a preset hash algorithm, and determining the query identifier of the stored data in the sharded storage area based on the indistinguishable factor and the hash value of the original location index, the data in the database can be sharded and stored in the database. When querying based on the query identifier, only the data corresponding to the query identifier needs to be queried, reducing the amount of data queried. In subsequent unintentional transmission, only the hidden key sequence of the ciphertext sequence corresponding to the data in the sharded storage area corresponding to the query identifier needs to be sent. The computational complexity of unintentional transmission is greatly reduced, and the amount of data transmitted is also greatly reduced, improving the efficiency of unintentional transmission and thus improving the efficiency of hidden queries.

[0134] Example 5

[0135] Figure 5 This is a flowchart of a hidden query method provided in Embodiment 5 of this application. The technical solution of this embodiment is further refined based on the above technical solution.

[0136] Furthermore, the phrase "sending the hidden key sequence to the querying party based on the unintentional transmission protocol" is refined as follows: "Sending an auxiliary point sequence to the querying party to instruct the querying party to determine the target auxiliary point from the random auxiliary point sequence according to the target index, and to generate and return the hidden index according to the first random number and the target auxiliary point; generating the hidden key sequence corresponding to the key sequence according to the hidden index and the auxiliary point sequence, and returning it to the querying party to instruct the querying party to parse the obtained hidden key sequence according to the first random number and the target index to obtain the target key," thereby generating the hidden key sequence and realizing the communication process of the key sequence based on the unintentional transmission protocol.

[0137] See Figure 5 The method shown includes:

[0138] S510. Obtain the query identifier sent by the querying party; wherein the query identifier is determined by the querying party based on the hash value of the original location index of the data to be queried and the indistinguishable factor.

[0139] S520. Based on the query identifier, query the ciphertext sequence and the corresponding location index sequence stored in the segmented storage area corresponding to the query identifier.

[0140] S530. Feed back the ciphertext sequence and the position index sequence to the querying party, so as to instruct the querying party to determine the target ciphertext from the ciphertext sequence based on the position index sequence.

[0141] S540. Send an auxiliary point sequence to the querying party to instruct the querying party to determine the target auxiliary point from the auxiliary point random sequence based on the target index, and to generate and return a hidden index based on the first random number and the target auxiliary point.

[0142] The service provider obtains the key sequence, maps the second random number to points on an elliptic curve, generates an auxiliary point sequence, and sends it to the querying party. The querying party obtains the auxiliary point sequence sent by the service provider, determines the target auxiliary point from the auxiliary point sequence based on the target index, generates a hidden index based on the first random number and the target auxiliary point, and sends it to the service provider.

[0143] S550. Based on the hidden index and auxiliary point sequence, generate the hidden key sequence corresponding to the key sequence and feed it back to the querying party to instruct the querying party to parse the obtained hidden key sequence according to the first random number and the target index to obtain the target key.

[0144] The service provider, based on the acquired concealment index, the generated auxiliary point sequence, and the preset concealment rules, conceals all keys in the key sequence, generating corresponding concealed keys. All concealed keys form a concealed key sequence, which is then fed back to the querying party. The concealment rules can be a function operation performed on the concealment index and the generated auxiliary point sequence. The querying party, based on the inverse operation of the preset concealment rules, and using a first random number and the target index, parses the acquired concealed key sequence to obtain the target key. Again, the inverse operation of the concealment rules can be the inverse operation of the function operation performed on the concealment index and the generated auxiliary point sequence.

[0145] In one optional embodiment, generating a hidden key sequence corresponding to the key sequence based on the hidden index and the auxiliary point sequence includes: hiding each key in the key sequence based on the hidden index and the auxiliary point sequence using a hidden function to obtain the corresponding hidden key sequence.

[0146] The concealment function is a mathematical mapping function that conceals the key. It is used to conceal each key in the key sequence based on the concealment index and the auxiliary point sequence, so as to obtain the corresponding concealed key sequence.

[0147] Specifically, the hidden key is generated based on the hidden index and the sequence of auxiliary points using the following hidden function:

[0148] v i =r2*(Up) i )+k i ;

[0149] Among them, v i r2 is the hidden key; r2 is the second random number, P i Let U be an auxiliary point, and k be a hidden index. iUse the hidden key as the key. Generate a hidden key sequence based on the hidden keys of all keys.

[0150] Accordingly, the querying party uses the following formula, and based on the first random number and the target index, to parse the obtained hidden key sequence to obtain the target key:

[0151] k idx =v idx -r1*Y;

[0152] Where, k idx For the target key, v idx R1 is the hidden key corresponding to the target index, r1 is the first random number, and Y is the auxiliary point sequence.

[0153] By using the hidden index and auxiliary point sequence, and based on the hidden function, each key in the key sequence is hidden to obtain the corresponding hidden key sequence. This is used to ensure that the querying party can only obtain the target key using the first random number and the target index, thus ensuring the security of other keys.

[0154] The technical solution of this embodiment sends an auxiliary point sequence to the querying party, instructing the querying party to determine the target auxiliary point from the random sequence of auxiliary points according to the target index, and to generate and return a hidden index based on a first random number and the target auxiliary point. Based on the hidden index and the auxiliary point sequence, a hidden key sequence corresponding to the key sequence is generated and returned to the querying party, instructing the querying party to parse the obtained hidden key sequence according to the first random number and the target index to obtain the target key. By sending the key sequence to the querying party without transmission, the querying party can only obtain the required target key based on the target index, and cannot decrypt other keys, thus ensuring the security of other keys. At the same time, the service provider cannot obtain the key queried by the querying party, thus ensuring the anonymity of the query.

[0155] Example 6

[0156] Figure 6 The diagram shown is a schematic representation of a hidden query device according to Embodiment Six of this application. This embodiment is applicable to situations where applications are being updated and is configured on the querying side. The specific structure of the hidden query device is as follows:

[0157] The query identifier determination module 610 is used to determine the query identifier of the data to be queried in response to a query request for the data to be queried; the query identifier is used to determine the sharded storage area of ​​the data to be queried in the service provider.

[0158] The query identifier sending module 620 is used to send the query identifier to the service provider, which instructs the service provider to query and return the ciphertext sequence and the corresponding location index sequence in the sharded storage area corresponding to the query identifier. The sharded storage area is the area in which the service provider shards and stores each piece of data according to the original location index of each piece of data in the database.

[0159] The target ciphertext determination module 630 is used to acquire the ciphertext sequence and the position index sequence, and determine the target ciphertext from the ciphertext sequence based on the position index sequence;

[0160] The target key determination module 640 is used to obtain the hidden key sequence sent by the service provider based on the unintentional transmission protocol, and to determine the target key of the target ciphertext from the hidden key sequence;

[0161] The target ciphertext decryption module 650 is used to decrypt the target ciphertext according to the target key to obtain the plaintext information of the data to be queried.

[0162] In this embodiment, the query identifier determination module 610 determines the query identifier of the data to be queried in response to a query request. The query identifier sending module 620 sends the query identifier to the service provider, instructing the service provider to query and return the ciphertext sequence and corresponding position index sequence in the sharded storage area corresponding to the query identifier. The sharded storage area is the area where the service provider shards and stores each piece of data according to the original position index of each piece of data in the database. By using the query identifier, only the data in the sharded storage area corresponding to the query identifier needs to be queried, which greatly reduces the amount of data queried. The target ciphertext determination module 630 obtains the ciphertext sequence and position index sequence, and determines the target ciphertext from the ciphertext sequence based on the position index sequence. The service provider cannot know the data queried by the querying party, which can ensure the anonymity of the query. Meanwhile, since the obtained data is a ciphertext sequence, the querying party cannot obtain data other than the data to be queried, ensuring data security. The target key determination module 640 obtains the hidden key sequence sent by the service provider based on an unintentional transmission protocol, and determines the target key of the target ciphertext from the hidden key sequence. Based on unintentional transmission, obtaining the target key also achieves unintentional key acquisition, protecting the information confidentiality of the querying party. Since only the key of the ciphertext sequence corresponding to the query identifier area needs to be queried, the data volume and computational complexity of the key transmission process based on the unintentional transmission protocol are significantly reduced, improving the efficiency of unintentional transmission and thus improving the efficiency of unintentional query. The target ciphertext decryption module 650 decrypts the target ciphertext based on the target key to obtain the plaintext information of the data to be queried. Obtaining the plaintext of the data to be queried through decryption achieves unintentional data query. Therefore, the technical solution of this application solves the problem that the computational complexity of the unintentional transmission PIR scheme increases linearly with the increase of data volume, and the query efficiency decreases linearly, achieving the effect of reducing the amount of data queried and improving the query efficiency of the unintentional query system.

[0163] Optionally, the query identifier determination module 610 includes:

[0164] The original location index acquisition unit is used to obtain the original location index of the data to be queried based on the query request.

[0165] The hash value determination unit is used to determine the hash value of the original location index according to a preset hash algorithm.

[0166] The query identifier determination unit is used to determine the query identifier of the data to be queried based on the indistinguishable factor and the hash value of the original location index.

[0167] Optionally, the target ciphertext determination module 630 includes:

[0168] The target index determination unit is used to determine the target index based on the position index sequence and the original position index.

[0169] The ciphertext sequence matching unit is used to identify the ciphertext in the ciphertext sequence that corresponds to the target index as the target ciphertext.

[0170] Optionally, the target key determination module 640 includes:

[0171] The target auxiliary point determination unit is used to obtain the auxiliary point sequence sent by the service provider and determine the target auxiliary point from the auxiliary point sequence according to the target index;

[0172] The hidden index sending unit is used to generate a hidden index based on a first random number and a target auxiliary point, and send it to the service provider to instruct the service provider to generate and return a hidden key sequence corresponding to the key sequence based on the hidden index and the auxiliary point sequence.

[0173] The hidden key sequence parsing unit is used to parse the hidden key sequence based on the first random number and the target index to obtain the target key.

[0174] The concealed query device provided in this application embodiment can execute the concealed query method provided in any embodiment of this application, and has the corresponding functional modules and beneficial effects for executing the concealed query method.

[0175] Example 7

[0176] Figure 7 The diagram shown is a schematic representation of a stealth query device according to Embodiment 7 of this application. This embodiment is applicable to situations where applications are being updated and is configured on the client side. The specific structure of the stealth query device is as follows:

[0177] The query identifier acquisition module 710 is used to acquire the query identifier sent by the querying party; wherein, the query identifier is determined by the querying party based on the hash value of the original location index of the data to be queried and the indistinguishable factor;

[0178] The data query module 720 is used to query the ciphertext sequence and the corresponding location index sequence stored in the segmented storage area corresponding to the query identifier, based on the query identifier.

[0179] The data feedback module 730 is used to feed back the ciphertext sequence and the position index sequence to the querying party, so as to instruct the querying party to determine the target ciphertext from the ciphertext sequence according to the position index sequence;

[0180] The hidden key sending module 740 is used to send a hidden key sequence to the querying party based on an unintentional transmission protocol, so as to instruct the querying party to determine the target key from the hidden key sequence and decrypt the target ciphertext according to the target key to obtain the plaintext information of the data to be queried.

[0181] The technical solution of this embodiment obtains the query identifier sent by the querying party through a query identifier acquisition module. The query identifier is determined by the querying party based on the hash value of the original location index of the data to be queried and an indistinguishable factor. The data query module queries the ciphertext sequence and corresponding location index sequence stored in the corresponding sharded storage area based on the query identifier. The data feedback module feeds back the ciphertext sequence and location index sequence to the querying party, instructing the querying party to determine the target ciphertext from the ciphertext sequence based on the location index sequence. By querying using the query identifier, only the data corresponding to the query identifier needs to be queried, reducing the amount of data queried. Sending the ciphertext sequence and corresponding location index sequence to the querying party protects the query's anonymity; the service provider cannot clearly know the data queried by the querying party, thus ensuring query anonymity. Furthermore, since the data sent is... The encrypted sequence ensures the security of data transmission and prevents the querying party from obtaining data other than the data to be queried, thus guaranteeing data security. A hidden key sending module, based on an unintentional transmission protocol, sends a hidden key sequence to the querying party, instructing them to determine the target key from the hidden key sequence and decrypt the target ciphertext using the target key to obtain the plaintext information of the data to be queried. Similarly, sending the hidden key sequence to the querying party through unintentional transmission also achieves the concealed transmission of the key, protecting the confidentiality of the querying party's information and ensuring that other keys besides the target key cannot be obtained, thus guaranteeing the security of other keys. Since only the hidden key sequence of the ciphertext sequence corresponding to the query identifier area needs to be sent, the computational complexity is significantly reduced, and the amount of data transmitted is also significantly reduced, improving the efficiency of unintentional transmission and thus improving the efficiency of concealed queries. Therefore, the technical solution of this application solves the problem that the computational complexity of the unintentional transmission PIR scheme increases linearly with the increase of data volume, and the query efficiency decreases linearly, achieving the effect of reducing the amount of data queried and improving the query efficiency of the concealed query system.

[0182] Optional, the covert query device also includes:

[0183] The sharded storage module is used to shard and store each piece of data according to the original location index of each piece of data in the database.

[0184] Optional, sharded storage modules include:

[0185] The original location index acquisition unit is used to acquire the original location index of the data stored in the database;

[0186] The hash calculation unit is used to determine the hash value of the original location index according to a preset hash algorithm.

[0187] The query identifier determination unit is used to determine the query identifier of the data stored in the database in the sharded storage area based on the indistinguishable factor and the hash value of the original location index.

[0188] Optionally, the covert key sending module 740 includes:

[0189] The auxiliary point sequence sending unit is used to send an auxiliary point sequence to the querying party to instruct the querying party to determine the target auxiliary point from the random sequence of auxiliary points according to the target index, and to generate and return a hidden index according to the first random number and the target auxiliary point.

[0190] The hidden key sequence feedback unit is used to generate a hidden key sequence corresponding to the key sequence based on the hidden index and the auxiliary point sequence, and feed it back to the querying party to instruct the querying party to parse the obtained hidden key sequence based on the first random number and the target index to obtain the target key.

[0191] The selected hidden key sequence feedback unit includes:

[0192] The hidden key sequence generation subunit is used to hide each key in the key sequence based on the hidden index and auxiliary point sequence and the hidden function to obtain the corresponding hidden key sequence.

[0193] The concealed query device provided in this application embodiment can execute the concealed query method provided in any embodiment of this application, and has the corresponding functional modules and beneficial effects for executing the concealed query method.

[0194] Example 8

[0195] Figure 8 This is a schematic diagram of the structure of an electronic device provided in Embodiment 8 of this application, as shown below. Figure 8 As shown, the electronic device includes a processor 810, a memory 820, an input device 830, and an output device 840; the number of processors 810 in the electronic device can be one or more. Figure 8 Taking a processor 810 as an example; the processor 810, memory 820, input device 830, and output device 840 in an electronic device can be connected via a bus or other means. Figure 8 Taking the example of a connection between China and Israel via a bus.

[0196] The memory 820, as a computer-readable storage medium, can be used to store software programs, computer-executable programs, and modules, such as the program instructions / modules corresponding to the covert query method in the embodiments of this application (e.g., query identifier determination module 610, query identifier sending module 620, target ciphertext determination module 630, target key determination module 640, and target ciphertext decryption module 650). The processor 810 executes various functional applications and data processing of the electronic device by running the software programs, instructions, and modules stored in the memory 820, thereby implementing the aforementioned covert query method.

[0197] The memory 820 may primarily include a program storage area and a data storage area. The program storage area may store the operating system and at least one application program required for a given function; the data storage area may store data created based on terminal usage. Furthermore, the memory 820 may include high-speed random access memory and non-volatile memory, such as at least one disk storage device, flash memory, or other non-volatile solid-state storage device. In some instances, the memory 820 may further include memory remotely located relative to the processor 810, which can be connected to the electronic device via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.

[0198] Input device 830 can be used to receive input character information and generate key signal inputs related to user settings and function control of the electronic device. Output device 840 may include display devices such as a display screen.

[0199] Example 9

[0200] Embodiment 9 of this application provides a storage medium containing computer-executable instructions. When executed by a computer processor, the computer-executable instructions are used to perform a covert query method applied to a querying party. The method includes: in response to a query request for data to be queried, determining a query identifier for the data to be queried; the query identifier is used to determine a fragmented storage area of ​​the data to be queried in a service provider; sending the query identifier to the service provider, instructing the service provider to query and return the ciphertext sequence and the corresponding location index sequence in the fragmented storage area corresponding to the query identifier, wherein the fragmented storage area is an area where the service provider fragments and stores each piece of data according to the original location index of each piece of data in the database; obtaining the ciphertext sequence and the location index sequence, and determining the target ciphertext from the ciphertext sequence according to the location index sequence; obtaining a covert key sequence sent by the service provider based on an unintentional transmission protocol, and determining the target key of the target ciphertext from the covert key sequence; and decrypting the target ciphertext according to the target key to obtain the plaintext information of the data to be queried.

[0201] Embodiment 9 of this application also provides a storage medium containing computer-executable instructions. When executed by a computer processor, the computer-executable instructions are used to perform a covert query method applied to a service provider. The method includes: obtaining a query identifier sent by a querying party; wherein the query identifier is determined by the querying party based on the hash value of the original location index of the data to be queried and an indistinguishable factor; querying the ciphertext sequence and the corresponding location index sequence stored in the segmented storage area corresponding to the query identifier based on the query identifier; feeding back the ciphertext sequence and the location index sequence to the querying party to instruct the querying party to determine the target ciphertext from the ciphertext sequence based on the location index sequence; and sending a covert key sequence to the querying party based on an unintentional transmission protocol to instruct the querying party to determine the target key from the covert key sequence and decrypt the target ciphertext based on the target key to obtain the plaintext information of the data to be queried.

[0202] Of course, the computer-executable instructions provided in the embodiments of this application are not limited to the method operations described above, but can also perform related operations in the covert query method provided in any embodiment of this application.

[0203] Based on the above description of the implementation methods, those skilled in the art can clearly understand that this application can be implemented using software and necessary general-purpose hardware, and of course, it can also be implemented using hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as a computer floppy disk, read-only memory (ROM), random access memory (RAM), flash memory, hard disk, or optical disk, etc., including several instructions to cause an electronic device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments of this application.

[0204] It is worth noting that in the embodiments of the search device described above, the various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of each functional unit are only for easy differentiation and are not used to limit the scope of protection of this application.

[0205] Note that the above are merely preferred embodiments and the technical principles employed in this application. Those skilled in the art will understand that this application is not limited to the specific embodiments described herein, and various obvious changes, readjustments, and substitutions can be made without departing from the scope of protection of this application. Therefore, although this application has been described in detail through the above embodiments, this application is not limited to the above embodiments, and may include many other equivalent embodiments without departing from the concept of this application, the scope of which is determined by the scope of the appended claims.

Claims

1. A hidden query method, characterized in that, Applied to the query side, including: In response to a query request for data to be queried, a query identifier for the data to be queried is determined; the query identifier is used to determine the sharded storage area of ​​the data to be queried in the service provider. The query identifier is sent to the service provider, which instructs the service provider to query and return the encrypted sequence and the corresponding location index sequence in the sharded storage area corresponding to the query identifier; wherein, the sharded storage area is the area in which the service provider shards and stores each piece of data according to the original location index of each piece of data in the database; The ciphertext sequence and the position index sequence are obtained, and the target ciphertext is determined from the ciphertext sequence based on the position index sequence. The target ciphertext refers to the ciphertext in the ciphertext sequence whose sequence number is the same as the target index. The target index is the sequence number of the position index in the position index sequence that is the same as the original position index of the data to be queried. The ciphertext sequence is a sequence of ciphertexts corresponding to the data stored in the sharded storage area corresponding to the query identifier, generated according to the sequence number order in the sharded storage area. The position index sequence is a sequence of the original position index in the database corresponding to each ciphertext, generated according to the sequence number order in the sharded storage area. Obtain a hidden key sequence sent by the service provider based on an unintentional transmission protocol, and determine the target key of the target ciphertext from the hidden key sequence; wherein, the hidden key sequence is a sequence of keys stored in the same segmented storage area as the query identifier; The target ciphertext is decrypted using the target key to obtain the plaintext information of the data to be queried.

2. The method according to claim 1, characterized in that, The step of determining the query identifier of the data to be queried in response to a query request includes: Based on the query request, obtain the original location index of the data to be queried; The hash value of the original location index is determined according to a preset hash algorithm; The query identifier of the data to be queried is determined based on the indistinguishable factor and the hash value of the original location index.

3. The method according to claim 1, characterized in that, Determining the target ciphertext from the ciphertext sequence based on the position index sequence includes: The target index is determined based on the location index sequence and the original location index; The ciphertext in the ciphertext sequence that corresponds to the target index is determined as the target ciphertext.

4. The method according to claim 1, characterized in that, The process of obtaining the hidden key sequence sent by the service provider based on the unintentional transmission protocol and determining the target key of the target ciphertext from the hidden key sequence includes: Obtain the sequence of auxiliary points sent by the service provider, and determine the target auxiliary point from the sequence of auxiliary points based on the target index; A hidden index is generated based on the first random number and the target auxiliary point, and sent to the service provider to instruct the service provider to generate and return a hidden key sequence corresponding to the key sequence based on the hidden index and the auxiliary point sequence. The hidden key sequence is parsed based on the first random number and the target index to obtain the target key.

5. A hidden query method, characterized in that, Applied to the service provider, the method includes: Obtain the query identifier sent by the querying party; wherein the query identifier is determined by the querying party based on the hash value of the original location index of the data to be queried and the indistinguishable factor; Based on the query identifier, query the ciphertext sequence and the corresponding position index sequence stored in the segmented storage area corresponding to the query identifier; The ciphertext sequence and the position index sequence are fed back to the querying party to instruct the querying party to determine the target ciphertext from the ciphertext sequence based on the position index sequence. The target ciphertext refers to the ciphertext in the ciphertext sequence whose sequence number is the same as the target index. The target index is the sequence number of the position index in the position index sequence that is the same as the original position index of the data to be queried. The ciphertext sequence is a sequence of ciphertexts corresponding to the data stored in the sharded storage area corresponding to the query identifier, generated according to the sequence number order in the sharded storage area. The position index sequence is a sequence of the original position index in the database corresponding to each ciphertext, generated according to the sequence number order in the sharded storage area. Based on the unintentional transmission protocol, a hidden key sequence is sent to the querying party to instruct the querying party to determine the target key from the hidden key sequence and decrypt the target ciphertext according to the target key to obtain the plaintext information of the data to be queried; wherein, the hidden key sequence is a sequence formed by keys stored in the same segmented storage area as the query identifier.

6. The method according to claim 5, characterized in that, Before obtaining the query identifier sent by the querying party, the method further includes: The data is segmented and stored according to the original location index of each data in the database.

7. The method according to claim 6, characterized in that, The step of storing each piece of data in segments based on its original location index in the database includes: Retrieve the original location index of the data stored in the database; The hash value of the original location index is determined according to a preset hash algorithm; Based on the indistinguishable factor and the hash value of the original location index, the query identifier of the data stored in the database in the sharded storage area is determined.

8. The method according to claim 5, characterized in that, The method of sending a hidden key sequence to the querying party based on an unintentional transmission protocol includes: Send an auxiliary point sequence to the querying party to instruct the querying party to determine a target auxiliary point from the random sequence of auxiliary points based on the target index, and to generate and return a hidden index based on a first random number and the target auxiliary point; Based on the hidden index and the auxiliary point sequence, a hidden key sequence corresponding to the key sequence is generated and fed back to the querying party to instruct the querying party to parse the obtained hidden key sequence according to the first random number and the target index to obtain the target key.

9. The method according to claim 8, characterized in that, The step of generating a hidden key sequence corresponding to the key sequence based on the hidden index and the auxiliary point sequence includes: Based on the hidden index and the auxiliary point sequence, each key in the key sequence is hidden using a hidden function to obtain the corresponding hidden key sequence.

10. A concealed query device, characterized in that, Configuration on the query side includes: The query identifier determination module is used to determine the query identifier of the data to be queried in response to a query request for the data to be queried; the query identifier is used to determine the sharded storage area of ​​the data to be queried in the service provider; The query identifier sending module is used to send the query identifier to the service provider, and to instruct the service provider to query and return the encrypted sequence and the corresponding position index sequence in the sharded storage area corresponding to the query identifier; wherein, the sharded storage area is the area in which the service provider shards and stores each piece of data according to the original position index of each piece of data in the database; A target ciphertext determination module is used to acquire the ciphertext sequence and the position index sequence, and determine the target ciphertext from the ciphertext sequence based on the position index sequence; wherein, the target ciphertext refers to the ciphertext in the ciphertext sequence whose sequence number is the same as the target index, and the target index is the sequence number of the position index in the position index sequence that is the same as the original position index of the data to be queried; the ciphertext sequence is a sequence of ciphertexts corresponding to the data stored in the sharded storage area corresponding to the query identifier, generated according to the sequence number order in the sharded storage area; the position index sequence is a sequence of the original position index in the database corresponding to each ciphertext, generated according to the sequence number order in the sharded storage area; The target key determination module is used to obtain a hidden key sequence sent by the service provider based on an unintentional transmission protocol, and to determine the target key of the target ciphertext from the hidden key sequence; wherein, the hidden key sequence is a sequence of keys stored in the same segmented storage area as the query identifier; The target ciphertext decryption module is used to decrypt the target ciphertext according to the target key to obtain the plaintext information of the data to be queried.

11. A concealed query device, characterized in that, Configuration on the service provider includes: The query identifier acquisition module is used to acquire the query identifier sent by the querying party; wherein, the query identifier is determined by the querying party based on the hash value of the original location index of the data to be queried and the indistinguishable factor; The data query module is used to query the ciphertext sequence and the corresponding location index sequence stored in the segmented storage area corresponding to the query identifier based on the query identifier; The data feedback module is used to feed back the ciphertext sequence and the position index sequence to the querying party, so as to instruct the querying party to determine the target ciphertext from the ciphertext sequence according to the position index sequence; wherein, the target ciphertext refers to the ciphertext in the ciphertext sequence whose sequence number is the same as the target index, and the target index is the sequence number of the position index in the position index sequence that is the same as the original position index of the data to be queried; the ciphertext sequence is a sequence of ciphertexts corresponding to the data stored in the sharded storage area corresponding to the query identifier, generated according to the sequence number order in the sharded storage area; the position index sequence is a sequence of the original position index in the database corresponding to each ciphertext, generated according to the sequence number order in the sharded storage area; The hidden key sending module is used to send a hidden key sequence to the querying party based on an unintentional transmission protocol, so as to instruct the querying party to determine the target key from the hidden key sequence and decrypt the target ciphertext according to the target key to obtain the plaintext information of the data to be queried; wherein, the hidden key sequence is a sequence formed by keys stored in the same segmented storage area as the query identifier.

12. The apparatus according to claim 11, characterized in that, The concealed query device further includes: The sharded storage module is used to shard and store each piece of data according to the original location index of each piece of data in the database.

13. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the covert query method as described in any one of claims 1-4, and / or implements the covert query method as described in any one of claims 5-9.

14. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the program implements the covert query method as described in any one of claims 1-4, and / or implements the covert query method as described in any one of claims 5-9.

Citation Information

Patent Citations

  • Method and apparatus for casual transmission using trusted environment

    CN115244524A