Data query method and device based on multi-party secure computation

By using local keys to encrypt the data identification of the query target in the data query scenario of multi-party secure computing, and constructing an obfuscated identification set, the problem of obtaining the target data without leaking the query target is solved, and efficient secure data query and data privacy protection are achieved.

CN113886887BActive Publication Date: 2025-05-27SASI DIGITAL TECHNOLOGY (BEIJING) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111243069.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-10-25
Publication Date
2025-05-27
Estimated Expiration
2041-10-25

AI Technical Summary

Technical Problem

In the data query scenario of multi-party security calculation, how to obtain target data from a second party holding multiple pieces of data without leaking the query target, and ensure that data privacy is not leaked.

Method used

By encrypting the data identification of the query target with the local key and constructing an obfuscation identification set, the encrypted ciphertext and obfuscation identification set are provided to the second party. The second party uses its local key to encrypt the ciphertext and encrypts multiple pieces of data to provide it to the first party. The first party uses the inverse element of its key to decrypt it to obtain the encrypted ciphertext identified by the second key to the target data, thereby decrypting the target data.

Benefits of technology

It realizes that in a multi-party secure computing environment, a single round of communication can complete secure data query, improves data query efficiency, and ensures data privacy protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113886887B_ABST
    Figure CN113886887B_ABST
Patent Text Reader

Abstract

An embodiment of this specification provides a data query method and device based on multi-party secure computation. During the data query process, on the one hand, the first party provides a set of obfuscated identifiers composed of multiple data identifiers to the second party, and hides the target data identifier therein. For each data identifier in the set of obfuscated identifiers, the second party encrypts the service data with different keys to obtain respective data ciphertexts and provides them to the first party. On the other hand, the first party and the second party process the target data identifier corresponding to the query target through the first key, the second key, and the inverse element of the first key in sequence based on the concept of inverse element permutation key. The ciphertext of the target data identifier encrypted by the second key is obtained at the first party and used to decrypt the target data. This technical concept can reduce the number of communication rounds between data parties in the query process of multi-party secure computation and improve the data query efficiency of multi-party secure computation.
Need to check novelty before this filing date? Find Prior Art

Claims

1. A data query method based on multi-party secure computation, which is used for the first party to obtain target data from the second party holding multiple pieces of data without revealing the query target. The method includes: The first party encrypts the target data identifier corresponding to the query target using the first key locally to obtain the first target ciphertext, and provides the first target ciphertext and a set of obfuscated identifiers to the second party. Among them, the set of obfuscated identifiers includes N data identifiers corresponding to N pieces of data one by one, and the N data identifiers include the target data identifier set according to a predetermined manner; The second party encrypts the first target ciphertext using the second key locally to obtain the second target ciphertext, and respectively encrypts the N pieces of data using N data keys corresponding one by one to obtain N pieces of data ciphertexts. Among them, a single data key is determined by the encryption result of the corresponding single data identifier by the second key; The second party provides the second target ciphertext and N pieces of data ciphertexts to the first party; The first party decrypts the second target ciphertext using the inverse element of the first key to obtain the third target ciphertext encrypted by the second key for the target data identifier, and thus decrypts the target data ciphertext determined according to the predetermined manner in the N pieces of data ciphertexts according to the third target ciphertext to obtain the target data.

2. The method according to claim 1, wherein, The predetermined manner includes one of the following: the target data identifier is located at a predetermined position of the N data identifiers; the target data identifier has a predetermined value at a predetermined flag bit.

3. The method according to claim 1, wherein, The first party encrypts the target data identifier corresponding to the query target using the first key locally to obtain the first target ciphertext, which includes: Mapping the target data identifier to a first point on an elliptic curve; Performing a point multiplication operation on the first point according to the scalar corresponding to the first key to obtain a second point on the elliptic curve as the first target ciphertext.

4. The method according to claim 3, wherein, The second target ciphertext is obtained by performing a point multiplication operation on the second point according to the scalar corresponding to the second key to obtain a third point on the elliptic curve.

5. The method according to claim 3, wherein, A single data key is determined in the following manner: Mapping the corresponding single data identifier to a single point on an elliptic curve; Performing a point multiplication operation on the single point according to the scalar corresponding to the second key to obtain a point on the elliptic curve as a single key point; Determining the corresponding single data key based on the abscissa and / or ordinate of the single key point.

6. The method according to claim 1, wherein, The first party encrypts the target data identifier corresponding to the query target using the first key locally to obtain the first target ciphertext, which includes: Mapping the target data identifier to a first value in a finite field defined by a prime number Q; Performing a modular exponentiation operation on the first value based on the first key to obtain a second value in the finite field as the first target ciphertext.

7. The method according to claim 6, wherein, The second target ciphertext is obtained by performing modular exponentiation on the second value based on the second key to obtain a third value in the finite field.

8. The method according to claim 6, wherein, A single data key is determined by the following method: Mapping the corresponding single data identifier to a single value in the finite field; Performing modular exponentiation on the single value based on the second key to obtain a value in the finite field as the corresponding single data key.

9. The method according to claim 1, wherein, A single data ciphertext among the N data ciphertexts is the result of an exclusive-or operation between a single data key and the corresponding single data. The first party obtains the target data through an exclusive-or operation between the third target ciphertext and the data ciphertext corresponding to the target data identifier.

10. A data query method based on multi-party secure computation, used by a first party to obtain target data from a second party holding multiple pieces of data without revealing the query target. The method comprises: Encrypting the target data identifier corresponding to the query target using a first key locally to obtain a first target ciphertext; Providing the first target ciphertext and a set of obfuscation identifiers to the second party, wherein the set of obfuscation identifiers includes N data identifiers corresponding one-to-one to N pieces of data, for the second party to provide a second target ciphertext obtained by encrypting the first target ciphertext using a second key locally, and N data ciphertexts obtained by encrypting the N pieces of data using N data keys corresponding one-to-one, wherein the N data identifiers include the target data identifier set according to a predetermined manner, and a single data key is determined by the encryption result of the second key on the corresponding single data identifier; Decrypting the second target ciphertext using the inverse element of the first key to obtain a third target ciphertext obtained by encrypting the target data identifier with the second key; Decrypting the target data ciphertext determined according to the predetermined manner among the N data ciphertexts according to the third target ciphertext to obtain the target data.

11. A data query method based on multi-party secure computation, used by a second party holding multiple pieces of data for the data query of the first party, to provide the target data to the first party without obtaining the query target of the first party and without revealing other data except the target data. The method comprises: Obtaining a first target ciphertext obtained by encrypting the target data identifier corresponding to the query target using a first key locally by the first party, and a set of obfuscation identifiers, wherein the set of obfuscation identifiers includes N data identifiers corresponding one-to-one to N pieces of data, and the N data identifiers include the target data identifier set according to a predetermined manner; Encrypting the first target ciphertext using a second key locally to obtain a second target ciphertext, and respectively encrypting the N pieces of data using N data keys corresponding one-to-one to obtain N data ciphertexts, wherein a single data key is determined by the encryption result of the second key on the corresponding single data identifier; Provide the second target ciphertext and N data ciphertexts to the first party, so that the first party can use the inverse element of the first key to decrypt the second target ciphertext to obtain the third target ciphertext encrypted by the second key for the target data identifier, and then decrypt the target data ciphertext determined in the predetermined manner from the N data ciphertexts according to the third target ciphertext to obtain the target data.

12. A data query system based on multi-party secure computation, including a first party for data query and a second party for providing data. The first party obtains target data from the second party holding multiple pieces of data without revealing the query target, and the second party does not disclose any other data except the target data. Wherein: The first party is configured to use the first key locally to encrypt the target data identifier corresponding to the query target to obtain a first target ciphertext, and provide the first target ciphertext and a set of obfuscation identifiers to the second party. The set of obfuscation identifiers includes N data identifiers corresponding one-to-one to N pieces of data, and the N data identifiers include the target data identifier set in a predetermined manner. The second party is configured to use the second key locally to encrypt the first target ciphertext to obtain a second target ciphertext, and respectively encrypt the N pieces of data with N data keys corresponding one-to-one to obtain N data ciphertexts, and then provide the second target ciphertext and the N data ciphertexts to the first party. A single data key is determined by the encryption result of the second key for the corresponding single data identifier. The first party is further configured to use the inverse element of the first key to decrypt the second target ciphertext to obtain the third target ciphertext encrypted by the second key for the target data identifier, and then decrypt the target data ciphertext determined in the predetermined manner from the N data ciphertexts according to the third target ciphertext to obtain the target data.

13. A data query device based on multi-party secure computation, provided in the first party for data query, and used to obtain target data from the second party holding multiple pieces of data without revealing the query target. The device includes: An encryption unit configured to use the first key locally to encrypt the target data identifier corresponding to the query target to obtain a first target ciphertext. A communication unit configured to provide the first target ciphertext and a set of obfuscation identifiers to the second party. The set of obfuscation identifiers includes N data identifiers corresponding one-to-one to N pieces of data, so that the second party can provide the second target ciphertext encrypted by using the second key locally for the first target ciphertext, and N data ciphertexts encrypted by using N data keys corresponding one-to-one to the N pieces of data. The N data identifiers include the target data identifier set in a predetermined manner, and a single data key is determined by the encryption result of the second key for the corresponding single data identifier. A first decryption unit configured to use the inverse element of the first key to decrypt the second target ciphertext to obtain the third target ciphertext encrypted by the second key for the target data identifier. A second decryption unit, configured to decrypt a target data ciphertext determined from N data ciphertexts according to the predetermined manner based on the third target ciphertext, to obtain target data.

14. A data query device based on multi-party secure computation, provided at a second party holding multiple pieces of data, for providing target data to a first party for a data query of the first party without obtaining the query target of the first party and without disclosing other data except the target data; the device includes a communication unit and an encryption unit, wherein: The communication unit is configured to: obtain a first target ciphertext obtained by the first party encrypting a target data identifier corresponding to the query target using a local first key, and a set of obfuscated identifiers, where the set of obfuscated identifiers includes N data identifiers corresponding one-to-one to N pieces of data, and the N data identifiers include the target data identifier set according to a predetermined manner; The encryption unit is configured to: encrypt the first target ciphertext using a local second key to obtain a second target ciphertext, and respectively encrypt the N pieces of data using N data keys corresponding one-to-one to obtain N data ciphertexts, where a single data key is determined by an encryption result of the second key for a corresponding single data identifier; The communication unit is further configured to: provide the first party with the second target ciphertext and the N data ciphertexts, for the first party to decrypt the second target ciphertext using an inverse element of the first key to obtain a third target ciphertext encrypted by the second key for the target data identifier, so as to decrypt a target data ciphertext determined from the N data ciphertexts according to the third target ciphertext to obtain target data.

15. A computer-readable storage medium, on which a computer program is stored, and when the computer program is executed in a computer, the computer is made to execute the method according to one of claims 10 and 11.

16. A computing device, including a memory and a processor, characterized in that an executable code is stored in the memory, and when the processor executes the executable code, the method according to one of claims 10 and 11 is implemented.

Citation Information

Patent Citations

  • Authentication key agreement method

    CN101710859A

  • Data query method, computing device and system

    CN109299149A