Ciphertext data sorting method, system and device, storage medium and program product

By using a pre-defined bitone sorting strategy and a Bitonic sorting network, combined with Paillier encryption and randomized blinding parameters, efficient ciphertext data sorting is achieved, solving the problems of low efficiency and data leakage in existing technologies and ensuring data privacy and security.

CN121098490APending Publication Date: 2025-12-09ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511238184.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-01
Publication Date
2025-12-09

AI Technical Summary

Technical Problem

Existing methods for sorting encrypted data are inefficient while ensuring data privacy and cannot effectively prevent data leakage, especially those based on fully homomorphic encryption, which have high computational overhead or lack efficient optimization schemes for sorting operations.

Method used

A pre-defined bitone sorting strategy is adopted, using the Paillier encryption algorithm to generate key shares and sorting the ciphertext data through the Bitonic sorting network. Combined with randomized blinding parameters and threshold decryption technology, the data is kept encrypted during the calculation process to avoid data leakage.

Benefits of technology

It achieves efficient sorting with O(n log2n) ciphertext comparison operations, improving ciphertext sorting efficiency and ensuring that data remains encrypted throughout the calculation and sorting process, thus avoiding the risk of data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121098490A_ABST
    Figure CN121098490A_ABST
Patent Text Reader

Abstract

The invention relates to a ciphertext data sorting method and system, computer equipment, a computer readable storage medium and a computer program product. The method comprises the following steps: a first server receives a first private key share and ciphertext data distributed by a data holder; through interaction with a second server, based on a preset double-tone sorting strategy, sorting the ciphertext data to obtain a ciphertext sorting result; and feeding back the ciphertext sorting result to the data holder to instruct the data holder to perform threshold decryption on the ciphertext sorting result in combination with the first server and the second server to obtain a sorting result of the original data set. According to the method, the preset double-tone sorting strategy is adopted, and the ciphertext sorting efficiency is improved. It is ensured that the data is always kept in an encrypted state in the calculation and sorting process, and the risk of data leakage is avoided. The method can be widely applied to encrypted database query, privacy protection machine learning, encrypted search and other scenes needing security sorting, and provides a solid foundation for subsequent multi-party calculation expansion.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security technology, and in particular to a method, system, computer device, computer-readable storage medium, and computer program product for sorting encrypted data. Background Technology

[0002] With the widespread adoption of cloud computing services and the surge in demand for data outsourcing, data holders are increasingly entrusting the processing of sensitive data to third-party servers. However, while this delegated computing model brings convenience, it also raises serious risks of privacy breaches.

[0003] To alleviate this contradiction, researchers have proposed secure computing schemes such as homomorphic encryption (HE). Among them, some homomorphic encryption (PHE) schemes are widely used for specific types of operations on encrypted data due to their high efficiency. Paillier encryption is a typical additive homomorphic encryption system, suitable for performing addition and scalar multiplication operations on ciphertext. However, since it does not inherently support nonlinear comparison operations, constructing secure ordering protocols remains a challenge.

[0004] Furthermore, existing sorting methods such as quicksort and mergesort rely on the input data values ​​for their operation path, thus failing to meet the requirement of data obliviousness and leaking the order information of the data during the execution process.

[0005] However, most current secure sorting protocols either rely on fully homomorphic encryption (FHE), which incurs extremely high computational costs, or lack efficient optimization schemes for the fundamental operation of sorting. Therefore, there is an urgent need for a sorting strategy that achieves efficient and scalable sorting operations while ensuring data privacy. Summary of the Invention

[0006] Therefore, it is necessary to provide a method, system, computer device, computer-readable storage medium, and computer program product for sorting encrypted data to address the above-mentioned technical problems. This method can improve the efficiency of encrypted data sorting, ensure that data remains encrypted throughout the calculation and sorting process, and avoid the risk of data leakage.

[0007] In a first aspect, this application provides a method for sorting encrypted data, the method being applied in a first server, the method comprising:

[0008] Receive the first private key share and ciphertext data distributed by the data holder; the data holder manages the public key, distributes the first private key share to the first server, and distributes the second private key share to the second server; the public key, the first private key share, and the second private key share are generated by the preset Paillier encryption algorithm; the ciphertext data is obtained by the data holder encrypting the original dataset using the public key;

[0009] By interacting with the second server, the encrypted data is sorted based on a preset bitone sorting strategy to obtain the encrypted sorting result;

[0010] The encrypted sorting result is fed back to the data holder, instructing the data holder to work with the first and second servers to perform threshold decryption on the encrypted sorting result based on the first private key share managed by the first server and the second private key share managed by the second server, so as to obtain the sorting result of the original dataset.

[0011] In one embodiment, the preset bitonic sorting strategy employs a three-level nested loop structure. Through interaction with a second server, the ciphertext data is sorted based on the preset bitonic sorting strategy to obtain the ciphertext sorting result, including:

[0012] Set the subsequence length to a set value;

[0013] Entering the first loop, if the current subsequence length is not greater than the total length of the ciphertext data, the comparison interval is set according to the current subsequence length; where p = s / 2, s represents the subsequence length, and p represents the comparison interval.

[0014] Enter the second loop and check if the current comparison interval is greater than zero;

[0015] If the current comparison interval is greater than zero, enter the third loop; traverse the ciphertext data according to the index, determine the pairs of elements to be sorted from the ciphertext data based on the current index and the current comparison interval; compare and sort the pairs of elements to be sorted by interacting with the second server.

[0016] Once the index traversal is complete, the third loop terminates, and the comparison interval is updated; where p = p / 2;

[0017] If the current comparison interval is zero, end the second loop and update the subsequence length; where s = s × 2;

[0018] If the length of the current subsequence is greater than the total length of the ciphertext data, end the first loop and output the ciphertext sorting result.

[0019] In one embodiment, comparing and sorting pairs of elements to be sorted by interacting with a second server includes:

[0020] Generate randomized blinding parameters;

[0021] The random blinding parameter is used to process the pairs of elements to be sorted to generate blinded ciphertext;

[0022] Based on the first private key share, the blinded ciphertext is partially decrypted to obtain the first part of the decrypted data;

[0023] The first server sends the unsorted element pair, blinded ciphertext, the first part of the decrypted data, and the random mask to the second server so that the second server can determine the sorting direction of the unsorted element pair, and based on the unsorted element pair, blinded ciphertext, the first part of the decrypted data, and the random mask, determine the element data after sorting according to the sorting direction, and return the element data to the first server.

[0024] In one embodiment, the randomization blinding parameter includes random bits, a first random number, and a second random number. Based on the randomization blinding parameter, the pairs of elements to be sorted are processed to generate blinded ciphertext, including:

[0025] When the random bits are zero, blinded ciphertext is generated using a first preset formula; wherein the first preset formula is:

[0026]

[0027] When the random bits are not zero, blinded ciphertext is generated using a second preset formula; wherein the second preset formula is:

[0028]

[0029] In the formula, Indicates blinded ciphertext, and This represents two elements in a pair of elements to be sorted, where r1 represents the first random number and r2 represents the second random number.

[0030] Where r1∈{0,1} σ r2 satisfies the following conditions:

[0031]

[0032] In the formula, N is the modulus.

[0033] In one embodiment, the second server performs the following steps:

[0034] Based on the second private key share, the blinded ciphertext is partially decrypted to obtain the second part of the decrypted data.

[0035] Based on the first part of the decrypted data and the second part of the decrypted data, determine the target decrypted data;

[0036] When the sorting direction is ascending, and In this case, the sorted element data is determined according to the third preset formula; wherein, the third preset formula is:

[0037]

[0038] When the sorting direction is descending, and In this case, the sorted element data is determined according to the fourth preset formula; wherein, the fourth preset formula is:

[0039]

[0040] In the formula, C represents the target decrypted data. and This represents the sorted element data. This indicates the element that appears first in the sort order. This indicates the element that appears later in the sort order. and Indicates a random mask. and This represents two elements in a pair of elements to be sorted.

[0041] In one embodiment, the second server determines the sorting direction of the pairs of elements to be sorted based on a Boolean value; wherein, if `direc` = true, the sorting direction of the pairs of elements to be sorted is ascending order, and if `direc` = false, the sorting direction of the pairs of elements to be sorted is descending order; wherein `direc` represents a Boolean value, which is determined by a fifth preset formula; the fifth preset formula is:

[0042]

[0043] In the formula, i represents the current index traversed in the third loop, and s represents the current subsequence length.

[0044] Secondly, this application also provides a encrypted data sorting system, the system including a data holder, a first server, and a second server, wherein:

[0045] The data holder generates a public key, a first private key share, and a second private key share. The first private key share is distributed to the first server, and the second private key share is distributed to the second server. The public key, the first private key share, and the second private key share are generated by a preset Paillier encryption algorithm. The original dataset is encrypted using the public key to obtain ciphertext data, which is then sent to the first server.

[0046] The first server receives the first private key share and ciphertext data distributed by the data holder; it interacts with the second server to sort the ciphertext data based on a preset bitonic sorting strategy to obtain the ciphertext sorting result; and it feeds back the ciphertext sorting result to the data holder.

[0047] The data holder is also used to collaborate with the first and second servers to perform threshold decryption on the ciphertext sorting result based on the first private key share managed by the first server and the second private key share managed by the second server, in order to obtain the sorting result of the original dataset.

[0048] Thirdly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the method described in the first aspect above.

[0049] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the method described in the first aspect above.

[0050] Fifthly, this application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the method described in the first aspect above.

[0051] The aforementioned encrypted data sorting method, system, computer device, computer-readable storage medium, and computer program product involve the following steps: A first server receives a first private key share and encrypted data distributed by a data holder; the data holder manages a public key and distributes the first private key share to the first server and a second private key share to the second server; the public key, the first private key share, and the second private key share are generated using a preset Paillier encryption algorithm; the encrypted data is obtained by the data holder encrypting the original dataset using the public key; through interaction with the second server, the encrypted data is sorted based on a preset bitonic sorting strategy to obtain the encrypted sorting result; the encrypted sorting result is fed back to the data holder, instructing the data holder to collaborate with the first and second servers to perform threshold decryption of the encrypted sorting result based on the first private key share managed by the first server and the second private key share managed by the second server, to obtain the sorting result of the original dataset. By employing a preset bitonic sorting strategy and based on the data-independent parallel sorting structure of the Bitonic sorting network, the sorting process requires only O(n log n) time. 2This n-fold ciphertext comparison operation outperforms traditional general computation schemes based on FHE, improving ciphertext sorting efficiency. It ensures data remains encrypted throughout the computation and sorting process, avoiding the risk of data leakage. It can be widely applied to scenarios requiring secure sorting, such as encrypted database queries, privacy-preserving machine learning, and encrypted search, and provides a solid foundation for subsequent multi-party computation extensions. Attached Figure Description

[0052] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0053] Figure 1 This is a diagram illustrating the application environment of a ciphertext data sorting method in one embodiment.

[0054] Figure 2 This is a flowchart illustrating a method for sorting encrypted data in one embodiment;

[0055] Figure 3 This is a schematic diagram of multi-terminal interaction in one embodiment;

[0056] Figure 4 This is a flowchart illustrating the encrypted data sorting steps in one embodiment;

[0057] Figure 5 This is a flowchart illustrating the encrypted data sorting method in another embodiment;

[0058] Figure 6 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation

[0059] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0060] It should be noted that the terms "first," "second," etc., used in this application can be used to describe various elements, but these elements are not limited by these terms. These terms are only used to distinguish the first element from the second element. The terms "comprising" and "having," and any variations thereof, used in this application, are intended to cover non-exclusive inclusion. The term "multiple" used in this application refers to two or more. The term "and / or" used in this application refers to one of the embodiments, or any combination of multiple embodiments.

[0061] The encrypted data sorting method provided in this application embodiment can be applied to, for example, Figure 1 In the application environment shown, data holder 102 generates a public key, a first private key share, and a second private key share based on a preset Paillier encryption algorithm. The first private key share is distributed to the first server 104, and the second private key share is distributed to the second server 106. Data holder 102 encrypts the original dataset using the public key and sends the ciphertext data to either the first server 104 or the second server 106. The first server 104 or the second server 106 processes the ciphertext data using the ciphertext data sorting method provided in this embodiment, and sends the sorting result back to data holder 102 for decryption, obtaining the sorted result of the original dataset.

[0062] In this system, data holder 102, first server 104, and second server 106 interact with each other via a communication network. Data holder 102 can be a terminal or a server. Terminals can be, but are not limited to, various personal computers, laptops, smartphones, tablets, drones, low-altitude aircraft, IoT devices, and portable wearable devices. IoT devices can be smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, projection devices, etc. Portable wearable devices can be smartwatches, smart bracelets, head-mounted displays, etc. Head-mounted displays can be virtual reality (VR) devices, augmented reality (AR) devices, smart glasses, etc. Servers (first server 102 or second server 104) can be independent physical servers, server clusters or distributed systems composed of multiple physical servers, or cloud servers providing cloud computing services.

[0063] In one exemplary embodiment, such as Figure 2 As shown, a method for sorting encrypted data is provided, which can be applied to... Figure 1 Taking the first server 104 as an example, the explanation includes the following steps:

[0064] Step 202: Receive the first private key share and ciphertext data distributed by the data holder; the data holder manages the public key, distributes the first private key share to the first server, and distributes the second private key share to the second server; the public key, the first private key share, and the second private key share are generated by the preset Paillier encryption algorithm; the ciphertext data is obtained by the data holder encrypting the original dataset using the public key.

[0065] In this process, the data holder uses a preset Paillier encryption algorithm to generate a public key pk and private keys sk1 and sk2. The private key is securely divided into two threshold key shares, namely the first private key share and the second private key share, which are stored on two mutually independent and trusted servers, namely the first server S1 and the second server S2. The preset Paillier encryption algorithm can be the (2,2)-threshold Paillier encryption algorithm.

[0066] Given the original dataset v = (x1, x2, ..., x...) to be sorted n The data holder uses the public key pk to access each element in the original dataset. Encrypt each element into ciphertext to obtain the ciphertext. and all encrypted ciphertext data It is transmitted to the first server S1 (in a specific implementation, it can also be transmitted to the second server S2).

[0067] The preset Paillier encryption algorithm is specifically expressed as follows: Where N = qp, g = N+1, and q and p are arbitrarily chosen large prime numbers.

[0068] Step 204: By interacting with the second server, the encrypted data is sorted based on a preset bitone sorting strategy to obtain the encrypted sorting result.

[0069] The process involves the first server determining the element pairs to be sorted based on a preset bitone sorting strategy, and then transmitting these pairs to the second server via a preset interaction protocol. The second server determines the current sorting direction and, based on that direction, returns the sorted data to the first server. Through multiple interactions, the final encrypted sorting result is determined. Optionally, the second server holds a Boolean value `direc`, where `direc = true` indicates that the encrypted data is sorted in ascending order, and `direc = false` indicates that the encrypted data is sorted in descending order.

[0070] It is understandable that the preset bitonic sorting strategy is based on a fixed bitonic sorting network topology. The first server S1 and the second server S2 sort the ciphertext data according to the fixed bitonic sorting network topology to obtain the ciphertext sorting result.

[0071] Step 206: Feedback the ciphertext sorting result to the data holder, instructing the data holder to work with the first server and the second server to perform threshold decryption on the ciphertext sorting result based on the first private key share managed by the first server and the second private key share managed by the second server, so as to obtain the sorting result of the original dataset.

[0072] After all comparison operations are completed, the first server S1 possesses the encrypted sorted result. The data holder, in conjunction with the first server S1 and the second server S2, performs threshold decryption to obtain the final sorted result. <y1,y2,...,y n >

[0073] Furthermore, after the sorting is complete, the data holder recovers the plaintext result through joint decryption, and then performs decryption on each ciphertext. implement: Where PDec represents server S j Use the threshold key sk it holds j (i.e., the first private key share or the second private key share) for ciphertext TDec performs partial decryption, meaning it merges the partial decryption results generated by the two servers to recover the plaintext y. i .

[0074] For example, refer to Figure 3 The data holder generates a public key pk and a private key sk to encrypt the data. Key share sk1 is sent to cloud server S1, and key share sk2 is sent to cloud server S2. Cloud servers S1 and S2 perform encrypted sorting to obtain the encrypted sorted result. The cloud server S1 will encrypt and sort the results. The result is returned to the data holder. The data holder, in conjunction with S1 and S2, performs threshold decryption on the encrypted sorting result to obtain the final sorted result. <y1,y2,...,y n >

[0075] In the above-described method for sorting encrypted data, the first server receives a first private key share and encrypted data distributed by the data holder; the data holder manages a public key, distributes the first private key share to the first server, and distributes a second private key share to the second server; the public key, the first private key share, and the second private key share are generated by a preset Paillier encryption algorithm; the encrypted data is obtained by the data holder encrypting the original dataset using the public key; through interaction with the second server, the encrypted data is sorted based on a preset bitonic sorting strategy to obtain the encrypted sorting result; the encrypted sorting result is fed back to the data holder, instructing the data holder to collaborate with the first and second servers to perform threshold decryption of the encrypted sorting result based on the first private key share managed by the first server and the second private key share managed by the second server, to obtain the sorting result of the original dataset. Through this method, using a preset bitonic sorting strategy and based on the data-independent parallel sorting structure of the Bitonic sorting network, the sorting process only requires O(n log n) time. 2This n-fold ciphertext comparison operation outperforms traditional general computation schemes based on FHE, improving ciphertext sorting efficiency. It ensures data remains encrypted throughout the computation and sorting process, avoiding the risk of data leakage. It can be widely applied to scenarios requiring secure sorting, such as encrypted database queries, privacy-preserving machine learning, and encrypted search, and provides a solid foundation for subsequent multi-party computation extensions.

[0076] In one exemplary embodiment, the preset bitone sorting strategy employs a three-level nested loop structure, such as... Figure 3 As shown, step 204 includes:

[0077] Step 402: Set the subsequence length to a set value.

[0078] Step 402 is the initialization step of the Bitonic sorting process. By initializing variables, the length of the subsequence to be sorted is set to a predetermined value. This predetermined value can be 2 or 1. Assuming the subsequence length is 1, during the first sorting, the process will jump directly out of the second loop and cannot enter the third loop for sorting, which will increase the computational load of the sorting process. This embodiment uses a predetermined value of 2 as an example.

[0079] Step 404: Enter the first loop. If the current subsequence length is not greater than the total length of the ciphertext data, set the comparison interval according to the current subsequence length; where p = s / 2, s represents the subsequence length, and p represents the comparison interval.

[0080] In this process, the first loop merges the subsequences of length s. When s ≤ n, the subsequent steps are executed, where n represents the number of data elements, i.e., the total length of the ciphertext data; the current comparison interval is set to p = s / 2.

[0081] Step 406: Enter the second loop and determine whether the current comparison interval is greater than zero.

[0082] In the second loop, elements are compared and paired according to the current comparison interval p. When p > 0, the subsequent steps are executed.

[0083] Step 408: If the current comparison interval is greater than zero, enter the third loop; traverse the ciphertext data according to the index, and determine the pairs of elements to be sorted from the ciphertext data based on the current index and the current comparison interval; compare and sort the pairs of elements to be sorted by interacting with the second server.

[0084] When p>0, the third loop is entered, and each index i∈{0,1,…,n-1} is traversed. The comparison pair of the current element i is calculated as j←i⊕p, thereby determining the pair of elements to be sorted (i,j). The first server interacts with the second server to perform encrypted comparison and sorting of the pair of elements to be sorted.

[0085] In one optional implementation, the first server determines the current sorting direction. Specifically, if the condition (i&s) = 0 is met, then the process is called... The protocol interacts with the second server; otherwise, it calls... The protocol interacts with a second server. Specifically, the 2-SSORT protocol is used to exchange two ciphertexts. Perform the following processing: Where, if direct = true, then (P,Q) = (min(x) i ,x j ),max(x i ,x j Otherwise (P,Q)=(max(x)) i ,x j ),min(x i ,x j )).

[0086] In one alternative implementation, the first server sends the processed data of the pairs of elements to be sorted to the second server. The second server determines the current sorting direction, sorts the data of the pairs of elements to be sorted according to the sorting direction, and returns the sorting result to the first server. The first server parses the data returned by the second server to determine the sorting result of the pairs of elements to be sorted.

[0087] Step 410: After completing the traversal by index, end the third loop and update the comparison interval; where p = p / 2.

[0088] If the current index i > n-1, then the index traversal is considered complete. At this point, the third loop ends, the comparison interval p = p / 2 is updated, and the process returns to step 406 to continue the second loop.

[0089] Step 412: If the current comparison interval is zero, end the second loop and update the subsequence length; where s = s × 2.

[0090] The comparison interval is an integer, and only the integer part is retained during the update process. If the current comparison interval p = 0, the second loop ends, the subsequence length s = s × 2 is updated, and the process returns to step 404 to continue the first loop.

[0091] Step 414: If the length of the current subsequence is greater than the total length of the ciphertext data, end the first loop and output the ciphertext sorting result.

[0092] If s > n is detected, the first loop ends and the ciphertext sorting result is output.

[0093] In this embodiment, the first server and the second server perform encrypted sorting based on a preset bitone sorting strategy, which can ensure that the data remains encrypted throughout the calculation and sorting process, thus avoiding the risk of data leakage.

[0094] In an exemplary embodiment, the comparison and sorting of pairs of elements to be sorted through interaction with a second server includes: generating random blinding parameters; processing the pairs of elements to be sorted based on the random blinding parameters to generate blinded ciphertext; partially decrypting the blinded ciphertext according to a first private key share to obtain a first part of decrypted data; sending the pairs of elements to be sorted, the blinded ciphertext, the first part of decrypted data, and a random mask to the second server, so that the second server determines the sorting direction of the pairs of elements to be sorted, and determines the element data sorted according to the sorting direction based on the pairs of elements to be sorted, the blinded ciphertext, the first part of decrypted data, and the random mask, and returns the element data to the first server.

[0095] The first server generates random blinding parameters according to a preset blinding strategy and encrypts the elements to be sorted into blinded ciphertext. Based on the first private key share sk1, it partially decrypts the blinded ciphertext to obtain the first part of decrypted data. The server then sends the pairs of elements to be sorted, the blinded ciphertext, the first part of decrypted data, and a random mask to the second server. The second server determines the sorting direction of the pairs of elements to be sorted and, based on the pairs of elements to be sorted, the blinded ciphertext, the first part of decrypted data, and the random mask, determines the element data after sorting according to the sorting direction and returns the element data to the first server. The first server performs post-processing on the element data based on the random mask to determine the comparison result of the pairs of elements to be sorted.

[0096] In this embodiment, the first server and the second server interact through blinded ciphertext, so that the second server cannot know the real pairs of elements to be sorted, ensuring that the data remains encrypted throughout the calculation and sorting process, thus avoiding the risk of data leakage.

[0097] In an exemplary embodiment, the randomization blinding parameter includes random bits, a first random number, and a second random number. Based on the randomization blinding parameter, the pairs of elements to be sorted are processed to generate blinded ciphertext, including:

[0098] When the random bits are zero, blinded ciphertext is generated using a first preset formula; wherein the first preset formula is:

[0099]

[0100] When the random bits are not zero, blinded ciphertext is generated using a second preset formula; wherein the second preset formula is:

[0101]

[0102] In the formula, Indicates blinded ciphertext, and This represents two elements in a pair of elements to be sorted, where r1 represents the first random number and r2 represents the second random number.

[0103] Where r1∈{0,1} σ r2 satisfies the following conditions:

[0104]

[0105] In the formula, N is the modulus.

[0106] Among them, the first server S1 is for the pairs of elements to be sorted. (i.e., the aforementioned embodiments) Generate random bits π ∈ {0, 1} and random numbers r1 and r2. If π = 0, then otherwise Decryption of the calculation part And send Give it to the second server S2. and This represents a random mask, which corresponds to... and The encrypted random mask is used to hide the correspondence between the result and the original input, break the data correlation, and improve the security of ciphertext sorting.

[0107] In one exemplary embodiment, the second server performs the following steps:

[0108] Based on the second private key share, the blinded ciphertext is partially decrypted to obtain the second part of the decrypted data.

[0109] Based on the first part of the decrypted data and the second part of the decrypted data, determine the target decrypted data;

[0110] When the sorting direction is ascending, and In this case, the sorted element data is determined according to the third preset formula; wherein, the third preset formula is:

[0111]

[0112] When the sorting direction is descending, and In this case, the sorted element data is determined according to the fourth preset formula; wherein, the fourth preset formula is:

[0113]

[0114] In the formula, C represents the target decrypted data. and This represents the sorted element data. This indicates the element that appears first in the sort order. This indicates the element that appears later in the sort order. and Indicates a random mask. and This represents two elements in a pair of elements to be sorted.

[0115] Among them, the second server S2 calculates Recalculate If the sorting direction is ascending and but If the sorting direction is descending and but The second server S2 will calculate and Send to the first server S1.

[0116] In one alternative implementation, the second server S2, if directc = true and but If direct = false and but

[0117] In an exemplary embodiment, the second server determines the sorting direction of the pairs of elements to be sorted based on a Boolean value; wherein, if `direc` = true, the sorting direction of the pairs of elements to be sorted is ascending order, and if `direc` = false, the sorting direction of the pairs of elements to be sorted is descending order; wherein `direc` represents a Boolean value, which is determined by a fifth preset formula; the fifth preset formula is:

[0118]

[0119] In the formula, i represents the current index traversed in the third loop, and s represents the current subsequence length.

[0120] In one exemplary embodiment, refer to Figure 5The encrypted data sorting method includes four stages: system initialization, data encryption and uploading, Bitonic sorting, and sorting completion and decryption. Specifically, it includes the following steps:

[0121] 1. The data holder generates a public key pk and private key shares sk1 and sk2.

[0122] 2. Send the private key share sk1 to the first server.

[0123] 3. Send the private key share sk2 to the second server.

[0124] 4. Obtain the original data v = (x1, x2, ..., x n ).

[0125] 5. Encrypt the original data using the public key (pk) to obtain the ciphertext data.

[0126] 6. The data holder will transmit the encrypted sequence. Uploaded to the first server.

[0127] 7. The first server initializes the subsequence length s = 2, enters the first loop, and executes the following steps when s ≤ n, setting the current comparison interval to p = s / 2.

[0128] 8. Enter the second loop. When p > 0, execute the subsequent steps. Enter the third loop, traverse each index i ∈ {0, 1, ..., n-1}, and calculate the comparison pair of the current element i as j ← i ⊕ p.

[0129] 9. For the pair of elements (i,j) to be sorted, if the condition (i&s) = 0 is satisfied, then call... The protocol interacts with the second server.

[0130] 10. If the condition (i&s) = 0 is not met, call... The protocol interacts with the second server.

[0131] 11. The second server returns to the first server. and

[0132] 12. The ciphertext of the first server updating positions i and j is... and

[0133] 13. After exiting the third loop, update the comparison interval p = p / 2.

[0134] 14. After exiting the second loop, update the subsequence length s = s × 2.

[0135] 15. The first server returns the encrypted sorting result to the data holder.

[0136] 16. The data holder, together with the first and second servers, recovers the plaintext based on the private key shares sk1 and sk2.

[0137] 17. Obtain the plaintext sorting result. <y1,y2,...,y n >

[0138] In an exemplary embodiment, the encrypted data sorting method provided in this application will be described with reference to an example. Specifically, the encrypted data sorting method includes the following steps:

[0139] Step 1: Initialization and Data Encryption: The data holder first selects two large prime numbers q and p, calculates the modulus N = qp, and calculates sk = lcm(p-1, q-1). A public key pk = (N, g) is selected, where N = qp and g = N+1. The data holder generates a random number and encrypts the original data using the following formula:

[0140] Initial plaintext data [4,1,5,6]; Initial encrypted data for:

[0141] 2112653153387344185217159457771837005567681137428811236484055635180735631850341783983722722412514771854070408763553935029646558327047026404664125243891169579945007950609427634831922219697586395595010408509884824693091020908820771857166196651982054707588623412635168743883397122915880610317166151818966266936349018550900351770405717944481931400336974337688706386261254717469753223146463089707502205695676635750714465087522446829119270983933034564917717130006395466431038945535200554871713246195801816629017227767119533573762708752485140531505935707803693034436443366605353038994120455064095076956389162303910189871346

[0143] 6406414964592700114595350155027798556293864266021446870440343795423616266275799850503477998316603002290584443257406388747584535430847685713820209972682548853369509982566904286364965135511444881396886221710863223325889648620004713862646753047569754854896989402769211514101625170243991685809054078233685038269970467518739521593995023125096890151240271205957139014973691148761467618537052913075532374387864107688013914378099406833878801297974224970698084143566773866955601239180938633855589188704983506144844341840849951517354033643015751335370782544369975237717473999872290819548378557140707453285034689366476240774840

[0145] 5271395914791081165852476412946589492688533308345263220821796223292537463077749305581666636791694560540097783976011999956480576695554796135776830587679631037267131366414545395263580385593575550279014931474965551333849130564411492852721619588054963841217781230892787598956270529360020789257605512232915017128879951491400140669816176913269795933027232547137587557403208125267639696303192295101958466872057107597025044664368486021673097293338298479290059446530078093433700743433624016538162496357730951497596754030719866017577441847534094339684768343912917275986160278409375520337757514121349919596268709060189498772667

[0147]

[0149] Step 2: The data holder encrypts the dataset. The data is transmitted to cloud server S1, with one portion of the private key (sk1) sent to S1 and the other portion (sk2) sent to cloud server S2. The global sorting direction is preset to `dirc=true`, indicating that the final result is in ascending order.

[0150] Step 3: Ciphertext Sorting Based on the Bitonic Network: S1 sorts the encrypted array according to the Bitonic network topology. Perform data-independent nested loop sorting:

[0151] The outer loop increments from 2 to n with the subsequence length s;

[0152] Inner loop sets the comparison interval And for all indices i∈{0,1,…,n-1}, calculate the comparison pair j←i⊕p to determine the direction: ​The 2-SSORT sub-protocol of this embodiment is invoked to interact with the cloud server S2 to perform ciphertext comparison and condition exchange.

[0153] Step 4, Decryption: S1 returns the sorting result in the encrypted state. The data is given to the data holder, who uses their own private key share to partially decrypt the data. The data is then combined using a threshold combination decryption formula to decrypt the final ciphertext result, thus obtaining the plaintext data.

[0154] Experimental output:

[0155] S1 returns the sorting result in the dense state as follows:

[0156] [,

[0157] 2112653153387344185217159457771837005567681137428811236484055635180735631850341783983722722412514771854070408763553935029646558327047026404664125243891169579945007950609427634831922219697586395595010408509884824693091020908820771857166196651982054707588623412635168743883397122915880610317166151818966266936349018550900351770405717944481931400336974337688706386261254717469753223146463089707502205695676635750714465087522446829119270983933034564917717130006395466431038945535200554871713246195801816629017227767119533573762708752485140531505935707803693034436443366605353038994120455064095076956389162303910189871346,

[0158] 5271395914791081165852476412946589492688533308345263220821796223292537463077749305581666636791694560540097783976011999956480576695554796135776830587679631037267131366414545395263580385593575550279014931474965551333849130564411492852721619588054963841217781230892787598956270529360020789257605512232915017128879951491400140669816176913269795933027232547137587557403208125267639696303192295101958466872057107597025044664368486021673097293338298479290059446530078093433700743433624016538162496357730951497596754030719866017577441847534094339684768343912917275986160278409375520337757514121349919596268709060189498772667, ]

[0160] The data holder's decryption result is: [1,4,5,6].

[0161] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages in other steps. It is understood that the steps in different embodiments can be freely combined as needed, and all non-contradictory solutions formed by such combinations are within the scope of protection of this application.

[0162] Based on the same inventive concept, this application also provides a encrypted data sorting system for implementing the encrypted data sorting method described above. The solution provided by this system is similar to the implementation described in the above method; therefore, the specific limitations in one or more encrypted data sorting system embodiments provided below can be found in the limitations of the encrypted data sorting method described above, and will not be repeated here.

[0163] In one exemplary embodiment, such as Figure 1 As shown, a encrypted data sorting system is provided, including: a data holder 102, a first server 104, and a second server 106, wherein:

[0164] Data holder 102 is used to generate a public key, a first private key share, and a second private key share, distribute the first private key share to the first server 104, and distribute the second private key share to the second server 106; the public key, the first private key share, and the second private key share are generated by a preset Paillier encryption algorithm; the original dataset is encrypted according to the public key to obtain ciphertext data, and the ciphertext data is sent to the first server 104.

[0165] The first server 104 is used to receive the first private key share and ciphertext data distributed by the data holder 102; by interacting with the second server 106, it sorts the ciphertext data based on a preset bitonic sorting strategy to obtain the ciphertext sorting result; and feeds back the ciphertext sorting result to the data holder 102.

[0166] Data holder 102 is also used to collaborate with first server 104 and second server 106 to perform threshold decryption on the ciphertext sorting result based on the first private key share managed by first server 104 and the second private key share managed by second server 106, so as to obtain the sorting result of the original dataset.

[0167] The aforementioned encrypted data sorting device employs a preset bitone sorting strategy, based on the data-independent parallel sorting structure of the Bitonic sorting network, enabling the sorting process to be performed in O(n log n) time. 2 This n-fold ciphertext comparison operation outperforms traditional general computation schemes based on FHE, improving ciphertext sorting efficiency. It ensures data remains encrypted throughout the computation and sorting process, avoiding the risk of data leakage. It can be widely applied to scenarios requiring secure sorting, such as encrypted database queries, privacy-preserving machine learning, and encrypted search, and provides a solid foundation for subsequent multi-party computation extensions.

[0168] In an exemplary embodiment, the preset bitone sorting strategy employs a three-level nested loop structure. The first server 104 is further configured to set the subsequence length to a predetermined value; enter the first loop, and if the current subsequence length is not greater than the total length of the ciphertext data, set a comparison interval based on the current subsequence length; where p = s / 2, s represents the subsequence length, and p represents the comparison interval; enter the second loop, and determine if the current comparison interval is greater than zero; if the current comparison interval is greater than zero, enter the third loop; sequentially traverse the ciphertext data according to the index, and determine the pairs of elements to be sorted from the ciphertext data based on the current index and the current comparison interval; through interaction with the second server 106, compare and sort the pairs of elements to be sorted; if the traversal according to the index is complete, end the third loop and update the comparison interval; where p = p / 2; if the current comparison interval is equal to zero, end the second loop and update the subsequence length; where s = s × 2; if the current subsequence length is greater than the total length of the ciphertext data, end the first loop and output the ciphertext sorting result.

[0169] In an exemplary embodiment, the first server 104 is further configured to generate random blinding parameters; process the pair of elements to be sorted based on the random blinding parameters to generate blinded ciphertext; partially decrypt the blinded ciphertext according to the first private key share to obtain a first part of decrypted data; and send the pair of elements to be sorted, the blinded ciphertext, the first part of decrypted data, and the random mask to the second server 106, so that the second server 106 determines the sorting direction of the pair of elements to be sorted, and determines the element data sorted according to the sorting direction based on the pair of elements to be sorted, the blinded ciphertext, the first part of decrypted data, and the random mask, and returns the element data to the first server 104.

[0170] In an exemplary embodiment, the first server 104 is further configured to generate blinded ciphertext using a first preset formula when the random bits are zero; wherein the first preset formula is:

[0171]

[0172] When the random bits are not zero, blinded ciphertext is generated using a second preset formula; wherein the second preset formula is:

[0173]

[0174] In the formula, Indicates blinded ciphertext, and This represents two elements in a pair of elements to be sorted, where r1 represents the first random number and r2 represents the second random number.

[0175] Where r1∈{0,1} σ r2 satisfies the following conditions:

[0176]

[0177] In the formula, N is the modulus.

[0178] In an exemplary embodiment, the second server 106 is further configured to partially decrypt the blinded ciphertext according to the second private key share to obtain a second decrypted data; determine the target decrypted data based on the first decrypted data and the second decrypted data; and sort the data in ascending order. In this case, the sorted element data is determined according to the third preset formula; wherein, the third preset formula is:

[0179]

[0180] When the sorting direction is descending, and In this case, the sorted element data is determined according to the fourth preset formula; wherein, the fourth preset formula is:

[0181]

[0182] In the formula, C represents the target decrypted data. and This represents the sorted element data. This indicates the element that appears first in the sort order. This indicates the element that appears later in the sort order. and Indicates a random mask. and This represents two elements in a pair of elements to be sorted.

[0183] In an exemplary embodiment, the second server 106 is further configured to determine the sorting direction of the pairs of elements to be sorted based on a Boolean value; wherein, if `direc` = true, the sorting direction of the pairs of elements to be sorted is ascending order; if `direc` = false, the sorting direction of the pairs of elements to be sorted is descending order; wherein `direc` represents a Boolean value, which is determined by a fifth preset formula; the fifth preset formula is:

[0184]

[0185] In the formula, i represents the current index traversed in the third loop, and s represents the current subsequence length.

[0186] Each module in the aforementioned encrypted data sorting system can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of a computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of each module.

[0187] In one exemplary embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 6 As shown, this computer device includes a processor, memory, input / output (I / O) interfaces, and a communication interface. The processor, memory, and I / O interfaces are connected via a system bus, and the communication interface is also connected to the system bus via the I / O interfaces. The processor provides computational and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides the environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The I / O interfaces are used for exchanging information between the processor and external devices. The communication interface is used for communication with external terminals via a network connection. When executed by the processor, the computer program implements a method for sorting encrypted data.

[0188] Those skilled in the art will understand that Figure 6 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0189] In one exemplary embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the encrypted data sorting method as described in any of the above embodiments.

[0190] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps of the encrypted data sorting method as described in any of the above embodiments.

[0191] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps of the encrypted data sorting method as described in any of the above embodiments.

[0192] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data must comply with relevant regulations.

[0193] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.

[0194] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0195] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A method for sorting encrypted data, characterized in that, The method is applied in a first server, and the method includes: The system receives a first private key share and encrypted data distributed by a data holder; the data holder manages a public key, distributes the first private key share to the first server, and distributes a second private key share to the second server; the public key, the first private key share, and the second private key share are generated by a preset Paillier encryption algorithm; the encrypted data is obtained by the data holder encrypting the original dataset using the public key. By interacting with the second server, the encrypted data is sorted based on a preset bitone sorting strategy to obtain the encrypted sorting result; The encrypted sorting result is fed back to the data holder, instructing the data holder to work with the first server and the second server to perform threshold decryption on the encrypted sorting result based on the first private key share managed by the first server and the second private key share managed by the second server, so as to obtain the sorting result of the original dataset.

2. The method according to claim 1, characterized in that, The preset bitone sorting strategy adopts a three-level nested loop structure. The step of sorting the ciphertext data based on the preset bitone sorting strategy through interaction with the second server to obtain the ciphertext sorting result includes: Set the subsequence length to a set value; Entering the first loop, if the current subsequence length is not greater than the total length of the ciphertext data, the comparison interval is set according to the current subsequence length; where p = s / 2, s represents the subsequence length, and p represents the comparison interval. Enter the second loop and check if the current comparison interval is greater than zero; If the current comparison interval is greater than zero, enter the third loop; traverse the ciphertext data sequentially according to the index, determine the pairs of elements to be sorted from the ciphertext data based on the current index and the current comparison interval; compare and sort the pairs of elements to be sorted by interacting with the second server. Once the index traversal is complete, the third loop terminates, and the comparison interval is updated; where p = p / 2; If the current comparison interval is zero, the second loop terminates and the subsequence length is updated; where s = s × 2; If the length of the current subsequence is greater than the total length of the ciphertext data, the first loop ends and the ciphertext sorting result is output.

3. The method according to claim 2, characterized in that, The step of comparing and sorting the pairs of elements to be sorted by interacting with the second server includes: Generate randomized blinding parameters; The pairs of elements to be sorted are processed based on the random blinding parameters to generate blinded ciphertext; Based on the first private key share, the blinded ciphertext is partially decrypted to obtain the first part of decrypted data; The unsorted element pair, the blinded ciphertext, the first part of the decrypted data, and the random mask are sent to the second server so that the second server can determine the sorting direction of the unsorted element pair, and based on the unsorted element pair, the blinded ciphertext, the first part of the decrypted data, and the random mask, determine the element data sorted according to the sorting direction, and return the element data to the first server.

4. The method according to claim 3, characterized in that, The randomization blinding parameters include random bits, a first random number, and a second random number. The step of processing the unsorted element pair based on the randomization blinding parameters to generate blinded ciphertext includes: When the random bits are zero, blinded ciphertext is generated using a first preset formula; wherein the first preset formula is: When the random bits are not zero, blinded ciphertext is generated using a second preset formula; wherein the second preset formula is: In the formula, Indicates blinded ciphertext, and This represents two elements in a pair of elements to be sorted, where r1 represents the first random number and r2 represents the second random number. Where r1∈{0,1} σ r2 satisfies the following conditions: In the formula, N is the modulus.

5. The method according to claim 4, characterized in that, The second server performs the following steps: Based on the second private key share, the blinded ciphertext is partially decrypted to obtain the second part of decrypted data; Based on the first part of the decrypted data and the second part of the decrypted data, the target decrypted data is determined; The sorting direction is ascending order, and In this case, the sorted element data is determined according to a third preset formula; wherein, the third preset formula is: The sorting direction is descending, and In this case, the sorted element data is determined according to the fourth preset formula; wherein, the fourth preset formula is: In the formula, C represents the target decrypted data. and This represents the sorted element data. This indicates the element that appears first in the sort order. This indicates the element that appears later in the sort order. and Indicates a random mask. and This represents two elements in a pair of elements to be sorted.

6. The method according to claim 4, characterized in that, The second server determines the sorting direction of the pairs of elements to be sorted based on a Boolean value; wherein, if `direc = true`, the sorting direction of the pairs of elements to be sorted is ascending order, and if `direc = false`, the sorting direction of the pairs of elements to be sorted is descending order; wherein `direc` represents a Boolean value, which is determined by a fifth preset formula; the fifth preset formula is: In the formula, i represents the current index traversed in the third loop, and s represents the current subsequence length.

7. A encrypted data sorting system, characterized in that, The system includes a data holder, a first server, and a second server, wherein: The data holder is used to generate a public key, a first private key share, and a second private key share, distribute the first private key share to the first server, and distribute the second private key share to the second server; the public key, the first private key share, and the second private key share are generated by a preset Paillier encryption algorithm; the original dataset is encrypted according to the public key to obtain ciphertext data, and the ciphertext data is sent to the first server; The first server is used to receive a first private key share and ciphertext data distributed by the data holder; by interacting with the second server, it sorts the ciphertext data based on a preset bitonic sorting strategy to obtain a ciphertext sorting result; and feeds back the ciphertext sorting result to the data holder. The data holder is also used to collaborate with the first server and the second server to perform threshold decryption on the ciphertext sorting result based on the first private key share managed by the first server and the second private key share managed by the second server, so as to obtain the sorting result of the original dataset.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.