Data query method, device and multi-party secure database
By implementing a centralized node with a public interface for multiple databases using different privacy algorithms, the scalability and flexibility of multiple-party secure databases are improved, allowing diverse databases to integrate and communicate efficiently.
Patent Information
- Application Number
- CN202111126949.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-09-18
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2041-09-18
AI Technical Summary
The existing multi-party security database has shortcomings in terms of scalability, which is difficult to adapt to the data storage needs and privacy protection requirements of different institutions.
By introducing a disclosed first interface in the central node, each database is allowed to join the multi-party security database with its own privacy algorithm, and communicate with the central node through remote procedure calls, realizing the delivery of query instructions and results, and supporting joint queries of different databases.
It improves the scalability of multi-party security databases, allowing databases of different institutions to be flexibly joined without requiring exactly the same privacy algorithms and software code, enhancing the flexibility and adaptability of the system.
Smart Images

Figure CN113868295B_ABST
Abstract
Description
Technical Field
[0001] One or more embodiments of this specification relate to the field of computers, and in particular, to a data query method, apparatus, and multi-party secure database. Background Art
[0002] In some business scenarios, there is a need to jointly build a database using the data of multiple institutions, and the data of each institution may include or belong to private data. To solve the data security problem and privacy protection problem of the database built based on the data of multiple institutions, the concept of a multi-party secure database is correspondingly proposed. A multi-party secure database usually includes multiple databases and a central node for providing data query services to users. The data of different institutions is stored in different databases, and the data in different databases is mutually invisible, that is, one database cannot directly access the data in another database.
[0003] There is a hope for a new technical solution to make the multi-party secure database have better scalability. Summary of the Invention
[0004] One or more embodiments of this specification provide a data query method, apparatus, and multi-party secure database, which can improve the scalability of the multi-party secure database.
[0005] In a first aspect, a multi-party secure database is provided, including a central node and multiple databases. The central node has a publicly available first interface, and the multiple query engines corresponding to the multiple databases each include a second interface for interacting with the first interface. Among them, the central node can determine multiple target databases involved in the query request from the multiple databases according to the query request; and send a query instruction to the multiple target query engines corresponding to the multiple target databases through its first interface; the multiple target query engines can receive the query instruction from the second interface, execute the query instruction to obtain a query result; and send the query result to the first interface of the central node through its second interface.
[0006] In a possible implementation manner, the multiple databases belong to multiple groups; the databases belonging to the same group have the same privacy algorithm.
[0007] In a possible implementation manner, the databases belonging to the same group are provided by the same service provider.
[0008] In a possible implementation manner, metadata is stored in the central node, which is used to indicate the groups to which the multiple databases belong respectively, and to indicate the data information stored in the multiple databases.
[0009] In a possible implementation, the central node can receive a registration request from the current database. The registration request indicates at least the group to which the current database belongs, and the registration request is sent by the current database through its second interface. Further, the central node updates the metadata according to the registration request.
[0010] In a possible implementation, the query request includes a query statement and a first group identifier of a first group. The central node can determine a number of databases belonging to the first group according to the first group identifier, and determine a plurality of target databases from the number of databases according to the query statement.
[0011] In a possible implementation, the first interface sends the query instruction to the second interface of the target query engine through a remote procedure call. The second interface sends the query result to the first interface of the central node through a remote procedure call.
[0012] In a possible implementation, the privacy algorithms of the plurality of target databases include secure multi-party computation (MPC) methods corresponding to several operation modes allowed by them. The query request involves at least one of the several operation modes.
[0013] In a second aspect, a data query method for a multi-party secure database is provided. The multi-party secure database includes a central node and a plurality of databases. The central node has a public first interface, and each of the plurality of query engines corresponding to the plurality of databases includes a second interface for interacting with the first interface. The method includes: the central node determines a plurality of target databases involved in the query request from the plurality of databases according to the query request; the central node sends a query instruction to a plurality of target query engines corresponding to the plurality of target databases through its first interface; the plurality of target query engines receive the query instruction through their second interfaces and execute the query instruction to obtain a query result; the plurality of target query engines send the query result to the first interface of the central node through their second interfaces.
[0014] In a possible implementation, the plurality of databases belong to a plurality of groups. Databases belonging to the same group have the same privacy algorithm.
[0015] In a possible implementation, databases belonging to the same group are provided by the same service provider.
[0016] In a possible implementation, metadata is stored in the central node, which is used to indicate the groups to which the plurality of databases belong respectively, and to indicate the data information stored in the plurality of databases.
[0017] In a possible implementation, it further includes: the central node receives a registration request from the current database, and at least the group to which the current database belongs is indicated in the registration request, and the registration request is sent by the current database through its second interface; the central node updates the metadata according to the registration request.
[0018] In a possible implementation, the query request includes a query statement and a first group identifier of a first group. The central node determines multiple target databases involved in the query request from the multiple databases, specifically including: the central node determines several databases belonging to the first group according to the first group identifier, and determines multiple target databases from the several databases according to the query statement.
[0019] In a possible implementation, the first interface sends the query indication to the second interface of the target query engine through a remote procedure call; the second interface sends the query result to the first interface of the central node through a remote procedure call.
[0020] In a possible implementation, the privacy algorithms of the multiple target databases include secure multi-party computation MPC methods corresponding to several operation modes allowed by them; the query request involves at least one of the several operation modes.
[0021] In a third aspect, a data query method for a multi-party secure database is provided. The multi-party secure database includes a central node and multiple databases. The central node has a publicly available first interface, and each of the multiple query engines corresponding to the multiple databases includes a second interface for interacting with the first interface. The method is applied to the central node. The method includes: determining multiple target databases involved in the query request from the multiple databases according to the query request; sending a query indication to the multiple target query engines corresponding to the multiple target databases through the first interface, so that the multiple target query engines execute the query indication to obtain a query result; receiving the query result sent by the multiple target query engines through their second interfaces through the first interface.
[0022] In a possible implementation, the query request includes a query statement and a first group identifier of a first group. The determining multiple target databases involved in the query request from the multiple databases according to the query request specifically includes: determining several databases belonging to the first group according to the first group identifier, and determining multiple target databases from the several databases according to the query statement.
[0023] In a possible implementation, it further includes: receiving a registration request from the current database, where the registration request at least indicates the group to which the current database belongs, and the registration request is sent by the current database through its second interface; updating the metadata stored in the central node according to the registration request.
[0024] In a fourth aspect, there is provided a data query device for a multi-party secure database. The multi-party secure database includes a central node and multiple databases. The central node has a publicly available first interface, and the multiple query engines corresponding to the multiple databases each include a second interface for interacting with the first interface. The device is applied to the central node. The device further includes: a task processing unit configured to determine multiple target databases involved in the query request from the multiple databases according to the query request; the first interface configured to send a query instruction to the multiple target query engines corresponding to the multiple target databases, so that the multiple target query engines execute the query instruction to obtain a query result; and receiving the query results sent by the multiple target query engines through their second interfaces.
[0025] In a possible implementation, the query request includes a query statement and a first group identifier of a first group; the task processing unit is specifically configured to determine several databases belonging to the first group according to the first group identifier, and determine multiple target databases from the several databases according to the query statement.
[0026] In a possible implementation, the first interface is further configured to receive a registration request from the current database, where the registration request at least indicates the group to which the current database belongs, and the registration request is sent by the current database through its second interface; the task processing unit is further configured to update the metadata stored in the central node according to the registration request.
[0027] In a fifth aspect, there is provided a computer-readable storage medium, on which a computer program is stored. When the computer program is executed in a computing device, the computing device executes the method according to any one of the third aspects.
[0028] In a sixth aspect, there is provided a computing device, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the method according to any one of the third aspects is implemented.
[0029] Through the methods and devices provided in one or more embodiments of this specification, by taking the first interface used for interacting with the database in the central node as a common protocol layer and making it publicly available, each service provider can provide a database adopting a certain privacy algorithm according to its own business needs. For a single database, its service provider only needs to ensure that the second interface configured for interacting with the first interface has been set in the query engine corresponding to the database, and then the database can join the multi-party secure database to which the central node belongs and communicate with the central node, so that the database can receive the query instruction corresponding to the query request involving the database from the central node, and after jointly executing the query instruction with other databases in the multi-party secure database using the privacy algorithm it adopts to obtain the query result, return the query result to the central node. In other words, this multi-party secure database does not require that the central node and multiple databases must be provided by a single service provider, does not require that all databases in the multi-party secure database must adopt the same privacy algorithm, and does not even require completely disclosing the software codes actually used by the central node and each database, which is conducive to expanding the existing multi-party secure database, that is, this multi-party secure database has better scalability. Brief Description of the Drawings
[0030] To more clearly illustrate the technical solutions of the embodiments of this specification, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0031] Figure 1 It is the architecture diagram of the multi-party secure database provided exemplarily in the embodiments of this specification;
[0032] Figure 2 It is the schematic diagram of adding a database in the multi-party secure database in the embodiments of this specification;
[0033] Figure 3 It is the schematic diagram of a data query method for the multi-party secure database provided in the embodiments of this specification;
[0034] Figure 4 It is the schematic diagram of a data query device for the multi-party secure database provided in the embodiments of this specification. Detailed Embodiments
[0035] The following will describe in detail each non-limiting embodiment provided in this specification in conjunction with the drawings.
[0036] When the central node of the multi-party secure database receives a data query request initiated by a user, and the query request involves multiple data stored in multiple databases, each database involved in the query request can perform corresponding secure multi-party computations on the multiple data, obtain the query result, and return the query result to the user through the central node. It should be specifically noted that since the multi-party secure database provides a data query service to the user through the central node, and the secure multi-party computations need to be performed by multiple databases involved in the query request to obtain the corresponding query result, it can also be said that the multi-party secure database logically constitutes a new type of virtual database.
[0037] If the scalability of the multi-party secure database is relatively good, then the extensiveness of its application will be greatly improved.
[0038] In the embodiments of this specification, at least one multi-party secure database, a data query method, and a device for the multi-party secure database are provided. The multi-party secure database has better scalability.
[0039] Figure 1 It is the architecture diagram of the multi-party secure database exemplarily provided in the embodiments of this specification. As Figure 1 shown, the multi-party secure database includes a central node 10 and multiple databases. The central node 10 has a public first interface (i.e., interface P1), which is used to support the interaction between the central node 10 and multiple databases. Each of the multiple query engines corresponding to the multiple databases includes a second interface (i.e., interface P2) for interacting with interface P1; for example, the multiple databases include database A1, database A2, database A3, database B1, and database B2, and the query engines Q1 - Q5 corresponding to the multiple databases in the foregoing example all include interface P2.
[0040] By making the interface P1 used for interacting with the database in the central node 10 public as the Public Protocol layer, each service provider can provide a database adopting a certain privacy algorithm according to its own business requirements. For a single database, its service provider only needs to ensure that the interface P2 for interacting with the interface P1 has been configured in the query engine corresponding to the database, and the database can then join the multi-party secure database to which the central node 10 belongs and communicate with the central node 10, so that the database can receive a query instruction corresponding to a query request involving the database from the central node 10, and after jointly executing the query instruction with other databases in the multi-party secure database using the privacy algorithm it adopts to obtain a query result, return the corresponding query result to the central node 10. In other words, the multi-party secure database does not require that the central node and multiple databases must be provided by a single service provider, does not require that all databases in the multi-party secure database must adopt the same privacy algorithm, and does not even need to fully disclose the software code actually used by the central node and each database, which is beneficial to expanding the multi-party secure database, that is, the multi-party secure database has better scalability.
[0041] In a more specific example, the interface P1 can specifically communicate with the query engine corresponding to the database through remote procedure calls. For example, the interface P1 can send a query instruction to the interface P2 of the target query engine through remote procedure calls. Similarly, the interface P2 can communicate with the central node 10 through remote procedure calls. For example, the interface P2 can send a query result to the interface P2 of the central node through remote procedure calls. More specifically, the remote procedure call depends on the session established between the central node 10 and the query engine. The service provider of the database can deploy interface functions including message start session for establishing a session, message run session dag for activating a session, and messageend session for ending a session, etc. in the query engine corresponding to the database based on the public interface P1 to form the interface P2 including the foregoing example interface functions, so that the interface P1 can call the interface functions in the interface P2 according to the actual business requirements of the central node 10, and the interface P2 can make a callback to the interface P1 according to the business requirements of its affiliated query engine.
[0042] In a more specific example, different databases may have different privacy algorithms, and databases with the same privacy algorithm can be grouped into the same group. For example, the databases A1, A2, and A3 in the foregoing example have the same privacy algorithm and can be grouped into the same group A; the databases B1 and B2 in the foregoing example have the same privacy algorithm and can be grouped into the same group B. The privacy algorithm of a single database may specifically include the MPC methods corresponding to several operation modes allowed by the database. The several operation modes may include one or more of the following various operation modes: connection operation, comparison operation, IN operation, and aggregation operation; the connection operation is, for example, "inner join" or "cross join", the comparison operation is, for example, "<", "<=", "=", "!=", ">=", or ">", and the aggregation operation is, for example, "MIN", "MAX", "SUM", or "AVG", etc.
[0043] Among the privacy algorithms of any two databases belonging to different groups, the same operation mode may correspond to different MPC methods. For example, the operation modes allowed by the databases in group A and group B both include the IN operation. When multiple target databases in group A or multiple target databases in group B execute the query instructions they receive respectively, the query plan that actually needs to be jointly executed by the multiple target databases may include logical operations belonging to the IN operation, and the multiple target databases need to use the Private Set Intersection (PSI) technology to complete this logical operation; however, the databases in group A and group B may use different PSIs. Specifically, the databases in group A may use the PSI based on naive hashing, and the databases in group B may use the PSI based on DH over a finite field, the PSI based on DH over an elliptic curve, or other forms of PSI.
[0044] All databases in a single group can be provided by the same service provider, so as to ensure that the multiple databases in a single group adopt exactly the same privacy algorithm. Correspondingly, in order to distinguish different groups, the group identifier of a single group may specifically include the identifier of the service provider that provides the databases in this group, such as the name of the service provider. In addition, a single service provider may provide multiple databases that adopt different privacy algorithms. For example, the databases in group A and group B may have the same service provider, but the databases in group A and the databases in group B adopt different privacy algorithms; assuming that databases with the same privacy algorithm correspond to the same version number, and databases with different privacy algorithms correspond to different version numbers, then the group identifier of a single group, in addition to the identifier of the corresponding service provider, may also include the version number corresponding to the databases in this group.
[0045] The central node 10 can specifically process the query request from the data requester to obtain a query plan, and send the query instruction obtained based on this query plan to the multiple target databases involved in this query request through the interface P1. More specifically, the central node 10 can obtain the query plan corresponding to the query statement in the query request by parsing the query request. This query plan may include several logical operations to be executed and the execution order corresponding to these several logical operations. Among them, the query statement can be specifically implemented using the Structured Query Language (SQL). Of course, it may also be implemented using other language formats supported by the multi-party secure database.
[0046] In a possible implementation manner, the central node 10 stores the metadata of the multi-party secure database. This metadata is at least used to indicate the groups to which the multiple databases in the multi-party secure database belong respectively and the data information stored in these multiple databases. This data information is, for example, the table names of several database tables respectively stored in the multiple databases, the content information of each database table, and the security information of each database table, etc.; among them, the content information of a single database table is, for example, the field names of several fields included in this database table, and the security information of a single database table is, for example, the operation methods allowed for several fields included in this database table. Correspondingly, when the central node 10 receives a query request from the data requester, it can determine the multiple target databases involved in the query request from multiple groups according to the metadata it stores.
[0047] In a more specific example, the query request may include the group identifier of the group it involves. The central node 10 may determine several databases belonging to the group involved in the query request based on this group identifier. For example, it determines several databases belonging to the group involved in the query request based on the metadata it stores and this group identifier; then it determines multiple target databases from the several databases according to the query statement. For example, it determines multiple target databases from the several databases based on the metadata it stores and the query statement. For instance, assume that database A1 stores data tables named ant1 and ant2, database A2 stores data tables named isv1 and isv2, database A3 stores a data table named special_item_list1, database B1 stores a data table named L1, and database B2 stores a data table named L2; then the metadata stored in the central node 10 may be, for example, the mapping relationship shown in Table 1 below.
[0048]
[0049] Table 1. Continuing to assume that the query request specifically includes the following example query statement:
[0050]
[0051] For the query statement of the foregoing example, the central node 10 may perform syntax analysis on this query statement to obtain the table names ant1, isv1, and special_item_list from this query statement, and then determine database A1, database A2, and database A3 belonging to group A based on the mapping relationship shown in the foregoing Table 1 example and the group identifier "A" in the query request. Furthermore, based on the foregoing table names it obtained, it determines database A1, database A2, and database A3 as the target databases involved in this query request. In addition, it should be particularly noted that the table names of the data tables in the foregoing Table 1 example are all different. However, since data of different institutions is stored in different databases, there may be data tables with the same table name but different data contents in different databases. For example, database B1 may also contain a data table named ant1, but this data table may have completely different data contents from the data table named ant1 stored in database A1.
[0052] In another more specific example, the mapping table names corresponding to the table names of the data tables in the query statement can also be defined in the metadata stored by the central node 10, that is, the aforementioned data information can also include the mapping table names corresponding to the table names of the data tables in the query statement; in this way, there is no need to include the group identifier of the group involved in the query request, but the central node 10 directly determines multiple target databases in the group involved in the query request from multiple groups according to the query statement and the metadata it stores. For example, for the table names ant1, isv1, and special_item_list, their corresponding mapping table names can be defined as L3, L4, and L5 in turn on the basis of the aforementioned Table 1. The central node 10 can publicly disclose the mapping table names without disclosing the table names of the data tables stored in each database. Then the query statement includes the mapping table names L3, L4, and L5 but does not include the table names ant1, isv1, and special_item_list; the central node 10 can determine the databases A1, A2, and A3 storing the data tables with the table names ant1, isv1, and special_item_list in turn as the target databases based on the mapping relationships between L3 and ant1, L4 and isv1, and L5 and special_item_list defined in the metadata database.
[0053] For the metadata stored in the central node 10, when a new database requests to join the multi-party secure database, or when a new data table is added or a data table is deleted in a certain database in the multi-party secure database, the central node 10 can update it. In a more specific example, when a new database C1 requests to join the multi-party secure database, the central node 10 can receive a registration request from the database C1. The registration request at least indicates the group to which the database C1 belongs. For example, the registration request includes the group identifier of the group to which the database C1 belongs or indicates the privacy algorithm that the database C1 has; the query engine corresponding to the database C1 has deployed the corresponding interface P2 according to the publicly disclosed interface P1 in the central node 10, and the registration request is sent by the database C1 through the interface P2 in its corresponding query engine. Correspondingly, the central node 10 can update the metadata it stores according to the registration request from the database C1. For example, a mapping relationship between the identifier of the database C1 and the group identifier of the group to which it belongs is newly added to the metadata.
[0054] Before the service provider adds the database it provides to the multi-party secure database, it can also register the corresponding group with the central node 10 in advance. For example, please refer to Figure 2, the service provider of the central node 10 is service provider M1. Service provider M2 expects to add the aforementioned database C1 that adopts a certain privacy algorithm to the multi-party secure database, and service provider M2 has not added other databases that adopt this privacy algorithm to the multi-party secure database before providing database C1. Then, service provider M2 can use any possible implementation method, such as negotiating with service provider M1 and having service provider M1 configure the central node 10, or service provider M2 invoking other public interfaces of the central node 10, to register the group to which database C1 belongs with the central node 10. Specifically, for example, register the group identifier of the group to which database C1 belongs or the privacy algorithm adopted by database C1 with the central node 10. Correspondingly, when the central node 10 receives a registration request from database C1, it can execute the update of the metadata stored in it according to the registration request from database C1 only when it is determined based on the registration request that the group to which database C1 belongs has been registered in the central node 10, thereby completing the addition of database C1 to the multi-party secure database.
[0055] For the aforementioned query indication, it is obtained based on the query plan corresponding to the query request, and it is an indicative message used to instruct multiple target databases to jointly execute the query plan. More specifically, the query indication can be a single message that contains the query plan and is sent to multiple target databases; or the query indication can be obtained by decomposing the query plan based on a predetermined rule to obtain multiple messages corresponding to and different from multiple target databases, and these multiple messages are sent to the corresponding multiple target databases.
[0056] For the aforementioned query result, it depends on the process of multiple target query engines executing the query indication, that is, it depends on the process of multiple target query engines jointly executing the query plan. The query result may specifically be obtained by one of the multiple target query engines. The target query engine that obtains the query result can send the query result to the central node 10 through its configured interface P2, so that the central node 10 can return the query result to the data requester that sent the query request. Or, different query results may be obtained by each of the multiple target query engines, and the multiple target query engines send the query results to the central node 10 through their interfaces P2 respectively. The central node 10 merges the query results from the multiple target query engines and returns the merged query result to the data requester that sent the query request.
[0057] It should be particularly noted that although the multi-party secure database provided in the embodiments of this specification has been described exemplarily in the foregoing in combination with Figure 1 it can be understood that Figure 1The exemplary multi-party secure database is only used to assist in describing the technical solutions provided in the embodiments of this specification. Obviously, the multi-party secure database in the actual business scenario may include more or fewer groups, and each group may include more or fewer databases.
[0058] Based on the same concept as the foregoing method embodiments, embodiments of this specification also provide a data query method for a multi-party secure database. The multi-party secure database includes a central node and multiple databases. The central node has a public interface P1, and each of the multiple query engines corresponding to the multiple databases includes an interface P2 for interacting with the interface P1. As Figure 3 shown, the method may include some or all of the following steps 301 to 307. For example, for the data query method executed by the central node, it may be steps 301, 203, and 307 in the following respective steps.
[0059] First, in step 301, the central node 10 determines multiple target databases involved in the query request from the multiple databases. Among them, in Figure 3 the multiple target databases are exemplified as database A1, database A2, and database A3 belonging to group A.
[0060] Next, in step 303, the central node 10 sends a query instruction to the multiple target query engines corresponding to the multiple target databases through its interface P1.
[0061] Next, in step 305, the multiple target query engines receive the query instruction through their interface P2 and execute the query instruction to obtain a query result.
[0062] Finally, in step 307, the central node 10 receives the query results from the multiple target query engines through its interface P1. Among them, the query results are sent by the multiple target query engines through their interface P2.
[0063] Based on the same concept as the foregoing respective embodiments, embodiments of this specification also provide a data query device for a multi-party secure database. The multi-party secure database includes a central node 10 and multiple databases. The central node 10 has a public first interface 401, and each of the multiple query engines corresponding to the multiple databases includes a second interface for interacting with the first interface 401. The device is deployed in the central node 10. As Figure 4As shown, the device further includes: a task processing unit 403 configured to determine a plurality of target databases involved in the query request from the plurality of databases according to the query request; the first interface 401 configured to send a query instruction to a plurality of target query engines corresponding to the plurality of target databases, so that the plurality of target query engines receive the query instruction through their second interfaces and execute the query instruction to obtain a query result; and configured to receive the query results sent by the plurality of target query engines through their second interfaces.
[0064] In a possible implementation manner, the query request includes a query statement and a first group identifier of a first group. The task processing unit 403 is specifically configured to determine a plurality of databases belonging to the first group according to the first group identifier, and determine a plurality of target databases from the plurality of databases according to the query statement.
[0065] In a possible implementation manner, the first interface 401 is further configured to receive a registration request from the current database, where the registration request at least indicates the group to which the current database belongs, and the registration request is sent by the current database through its second interface. The task processing unit 403 is further configured to update the metadata stored in the central node according to the registration request.
[0066] Those skilled in the art should be able to realize that in one or more of the above examples, the functions described in this specification can be implemented by hardware, software, firmware, or any combination thereof. When implemented using software, the computer programs corresponding to these functions can be stored in a computer-readable medium or transmitted as one or more instructions / codes on a computer-readable medium, so that when the computer programs corresponding to these functions are executed by a computer, the methods described in any embodiment of this specification can be implemented by the computer.
[0067] An embodiment of this specification also provides a computer-readable storage medium, on which computer programs / instructions are stored. When the computer programs / instructions are executed in a computing device, the computing device executes the method executed by the central node 10 in any embodiment of this specification.
[0068] An embodiment of this specification also provides a computing device, including a memory and a processor. A computer program / instructions is stored in the memory. When the processor executes the computer program / instructions, the method executed by the central node 10 in any embodiment of this specification is implemented.
[0069] Each embodiment in this specification is described in a progressive manner. For the same or similar parts in each embodiment, reference can be made to each other. The key points of each embodiment are the differences from other embodiments. Therefore, some embodiments may be described relatively simply, and for the relevant parts, reference can be made to the descriptions of other embodiments.
[0070] The specific embodiments of this specification have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the drawings do not necessarily require the particular order or sequential order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0071] The specific implementation manners described above further elaborate on the purpose, technical solutions, and beneficial effects of the present invention. It should be understood that the above are only the specific implementation manners of the present invention and are not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made on the basis of the technical solutions of the present invention shall be included in the protection scope of the present invention.
Claims
1. A multi-party secure database includes a central node and multiple databases. The multiple databases belong to multiple groups. Databases belonging to the same group have the same privacy algorithm, and databases belonging to different groups have different privacy algorithms. The central node has a first interface that serves as a common protocol layer and is publicly available. Each of the multiple query engines corresponding to the multiple databases includes a second interface for interacting with the first interface. Among them, the central node can determine multiple target databases involved in the query request from the multiple databases, and the multiple target databases belong to the same group; and send a query instruction to multiple target query engines corresponding to the multiple target databases through its first interface; the multiple target query engines can receive the query instruction from the second interface and execute the query instruction to obtain a query result; and send the query result to the first interface of the central node through its second interface.
2. The multi-party secure database according to claim 1, wherein Databases belonging to the same group are provided by the same service provider.
3. The multi-party secure database according to claim 1, wherein, Metadata is stored in the central node, which is used to indicate the groups to which the multiple databases belong respectively, and to indicate the data information stored in the multiple databases.
4. The multi-party secure database according to claim 3, wherein The central node can receive a registration request from the current database. The registration request at least indicates the group to which the current database belongs, and the registration request is sent by the current database through its second interface; and the central node updates the metadata according to the registration request.
5. The multi-party secure database according to claim 1, wherein, The query request includes a query statement and a first group identifier of a first group. The central node can determine several databases belonging to the first group according to the first group identifier, and determine multiple target databases from the several databases according to the query statement.
6. The multi-party secure database according to any one of claims 1-5, wherein, The first interface sends the query instruction to the second interface of the target query engine through remote procedure call; The second interface sends the query result to the first interface of the central node through remote procedure call.
7. The multi-party secure database according to any one of claims 1-5, wherein The privacy algorithms of the multiple target databases include secure multi-party computation MPC methods corresponding to several allowed operation modes respectively. The query request involves at least one of the several operation modes.
8. A data query method for a multi-party secure database. The multi-party secure database includes a central node and multiple databases. The multiple databases belong to multiple groups. Databases belonging to the same group have the same privacy algorithm, and databases belonging to different groups have different privacy algorithms. The central node has a first interface that serves as a common protocol layer and is publicly available. Each of the multiple query engines corresponding to the multiple databases includes a second interface for interacting with the first interface, and includes: The central node determines multiple target databases involved in the query request from the multiple databases, and the multiple target databases belong to the same group; The central node sends a query instruction to multiple target query engines corresponding to the multiple target databases through its first interface; The multiple target query engines receive the query instruction through their second interfaces and execute the query instruction to obtain a query result; Multiple target query engines send query results to the first interface of the central node through their second interfaces.
9. The method according to claim 8, wherein, Databases belonging to the same group are provided by the same service provider.
10. The method according to claim 8, wherein, The central node stores metadata for indicating the groups to which the multiple databases respectively belong, and for indicating the data information stored in the multiple databases.
11. The method according to claim 10, further comprising: The central node receives a registration request from the current database, the registration request at least indicating the group to which the current database belongs, and the registration request is sent by the current database through its second interface; The central node updates the metadata according to the registration request.
12. The method according to claim 8, wherein, The query request includes a query statement and a first group identifier of a first group; the central node determines multiple target databases involved in the query request from the multiple databases, specifically including: the central node determines several databases belonging to the first group according to the first group identifier, and determines multiple target databases from the several databases according to the query statement.
13. The method according to any one of claims 8 - 12, wherein, The first interface sends the query instruction to the second interface of the target query engine through remote procedure call; the second interface sends the query result to the first interface of the central node through remote procedure call.
14. The method according to any one of claims 8 - 12, wherein, The privacy algorithms of the multiple target databases include secure multi-party computation MPC methods respectively corresponding to several operation modes allowed by them; the query request involves at least one of the several operation modes.
15. A data query method for a multi-party secure database, the multi-party secure database including a central node and multiple databases, the multiple databases belonging to multiple groups, databases belonging to the same group having the same privacy algorithm, and databases belonging to different groups having different privacy algorithms; the central node has a first interface that serves as a common protocol layer and is publicly available, and the multiple query engines corresponding to the multiple databases each include a second interface for interacting with the first interface, and the method is applied to the central node and includes: Determine multiple target databases involved in the query request from the multiple databases, the multiple target databases belonging to the same group; Send a query instruction to multiple target query engines corresponding to the multiple target databases through the first interface, so that the multiple target query engines execute the query instruction to obtain a query result; Receive the query results sent by the multiple target query engines through their second interfaces through the first interface.
16. The method according to claim 15, wherein, The query request includes a query statement and a first group identifier of a first group; the determining of the multiple target databases involved in the query request from the multiple databases specifically includes: determining several databases belonging to the first group according to the first group identifier, and determining multiple target databases from the several databases according to the query statement.
17. The method according to claim 15, further comprising: Receive a registration request from the current database, where the registration request at least indicates the group to which the current database belongs, and the registration request is sent by the current database through its second interface; Update the metadata stored in the central node according to the registration request.
18. A data query device for a multi-party secure database, the multi-party secure database including a central node and multiple databases, the multiple databases belonging to multiple groups, databases belonging to the same group having the same privacy algorithm, and databases belonging to different groups having different privacy algorithms; the central node has a first interface that serves as a common protocol layer and is publicly available, and the multiple query engines corresponding to the multiple databases each include a second interface for interacting with the first interface. The device is applied to the central node and further includes: A task processing unit configured to determine, according to a query request, multiple target databases involved in the query request from the multiple databases, the multiple target databases belonging to the same group; The first interface is configured to send a query instruction to multiple target query engines corresponding to the multiple target databases, so that the multiple target query engines execute the query instruction to obtain a query result; And receive the query results sent by the multiple target query engines through their second interfaces.
19. The apparatus according to claim 18, wherein, The query request includes a query statement and a first group identifier of the first group; the task processing unit is specifically configured to determine several databases belonging to the first group according to the first group identifier, and determine multiple target databases from the several databases according to the query statement.
20. The device according to claim 18, wherein, The first interface is further configured to receive a registration request from the current database, where the registration request at least indicates the group to which the current database belongs, and the registration request is sent by the current database through its second interface; The task processing unit is further configured to update the metadata stored in the central node according to the registration request.
21. A computer-readable storage medium having a computer program stored thereon, and when the computer program is executed in a computing device, the computing device executes the method according to any one of claims 15-17.
22. A computing device including a memory and a processor, where a computer program is stored in the memory, and when the processor executes the computer program, the method according to any one of claims 15-17 is implemented.
Citation Information
Patent Citations
Multi-party data joint query method and device, server and storage medium
CN111382174A
Query optimization method, device and system for multi-party security database
CN112860738A
Data query method, device and system for multi-party security database
CN112860752A
Information processing method, service platform, device for information processing and multi-party security computing system
CN113094744A