A Hidden Query Method and System Based on RSA Algorithm

By adopting an obscure query method based on RSA algorithm in private information retrieval, using asymmetric encryption and exclusive OR operations, the problem of difficult to achieve obscure query in private information retrieval in the prior art is solved, and efficient privacy protection is achieved.

CN113987582BActive Publication Date: 2025-05-02CCB FINTECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111334584.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-11
Publication Date
2025-05-02
Estimated Expiration
2041-11-11

AI Technical Summary

Technical Problem

The prior art is difficult to effectively implement hidden queries in privacy information retrieval, and cannot prevent the database server from knowing the relevant information of the user query statement, resulting in the inability to effectively protect user privacy.

Method used

The hidden query method based on RSA algorithm is adopted to provide asymmetric encryption and exclusive OR operations between nodes and data query nodes through data to ensure the obscurity during the query process. The specific steps include: the data query node generates random code and encrypts, the data provides node to decrypt and performs XOR operations with the queryable data, and the data query node again XOR to generate the final query result.

Benefits of technology

It realizes the obscureness of the entire query process, improves the level of user privacy protection, and ensures that the data service provider cannot know which query object is corresponding to.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113987582B_ABST
    Figure CN113987582B_ABST
Patent Text Reader

Abstract

The present application provides a hidden query method and system based on RSA algorithm, including: a data query node receives all queryable information and corresponding public keys sent by a data providing node, and generates a random code, encrypts the random code using the public key corresponding to the data to be queried to obtain a ciphertext, the data providing node uses each public key to decrypt the ciphertext to obtain the corresponding decrypted plaintext, and performs an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain the corresponding first XOR code, the data query node performs an XOR operation on the random code and each first XOR code to generate multiple second XOR codes, and the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried. An asymmetric key is used to encrypt an arbitrary random code, and all private keys are used to decrypt the encrypted random code to obtain the corresponding decrypted plaintext, and then all decrypted plaintexts are XORed with the corresponding data and random numbers, thereby improving the privacy in the hidden query process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security technology, and in particular to a hidden query method and system based on RSA algorithm. Background Art

[0002] Hidden query, also known as privacy information retrieval, means that the query party hides the keywords or customer ID information of the query object, and the data service provider provides matching query results but cannot know which specific query object it corresponds to. The data does not go out and can be calculated, eliminating the possibility of data caching. Private information retrieval (Private information retrieval), referred to as PIR, is a strategy adopted to protect the privacy of personal privacy on public network platforms. When a user retrieves information on the database, it will use certain methods to prevent the database server from knowing the relevant information of the user's query statement, thereby protecting the user's query privacy. The development and popularization of privacy information retrieval requires not only the continuous improvement of privacy confidentiality technology, but also the continuous enhancement of people's awareness of privacy protection. In current real life, privacy information retrieval has a large application space in fields such as medical databases and patent databases that have high requirements for retrieval privacy. Summary of the invention

[0003] In view of the problems in the prior art, the present application provides a hidden query method and system based on the RSA algorithm, which realizes the anonymity of the entire query by adopting the technical means of RSA asymmetric encryption.

[0004] In order to solve the above technical problems, this application provides the following technical solutions:

[0005] In a first aspect, the present application provides a hidden query method based on the RSA algorithm, which is executed by the data providing node, the data providing node includes all queryable data, each queryable data corresponds to a public-private key pair, each public-private key pair includes a public key and a private key, each queryable data corresponds to an identification information, and the hidden query method includes:

[0006] Sending all identification information and corresponding public keys to a data query node, wherein the data query node generates a random code and encrypts the random code using the public key corresponding to the data to be queried to obtain a first ciphertext;

[0007] Decrypting the first ciphertext using each public key to obtain a corresponding decrypted plaintext, and performing an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain a corresponding first XOR code;

[0008] All first XOR codes are sent to the data query node, so that the data query node performs an XOR operation on the random code and each first XOR code to generate a one-to-one corresponding second XOR code, wherein the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried.

[0009] Furthermore, the hidden query method further includes:

[0010] Using a symmetric key to encrypt all the identification information and the corresponding public key to obtain a second ciphertext;

[0011] Correspondingly, all identification information and corresponding public keys are sent to the data query node, including:

[0012] The second ciphertext is sent to the data query node.

[0013] In a second aspect, the present application provides a hidden query method based on the RSA algorithm, which is executed by the data query node, and the hidden query method includes:

[0014] Receive all identification information and corresponding public keys sent by the data providing node;

[0015] Generate a random code, and use the public key corresponding to the data to be queried to encrypt the random code to obtain a first ciphertext;

[0016] Receive all first XOR codes sent by the data query node, wherein the data providing node uses each public key to decrypt the first ciphertext respectively to obtain the corresponding decrypted plaintext, and performs an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain the corresponding first XOR code;

[0017] An XOR operation is performed on the random code and each first XOR code to generate a one-to-one corresponding second XOR code, wherein the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried.

[0018] Further, the data providing node encrypts all the identification information and the corresponding public key using a symmetric key to obtain a second ciphertext, and the receiving of all the identification information and the corresponding public key sent by the data providing node includes:

[0019] Receive the second ciphertext sent by the data query node.

[0020] In a third aspect, the present application provides a hidden query method based on the RSA algorithm, wherein the data providing node includes all queryable data, each queryable data corresponds to a public-private key pair, each public-private key pair includes a public key and a private key, and each queryable data corresponds to an identification information, and the hidden query method includes:

[0021] The data providing node sends all identification information and the corresponding public key to the data query node;

[0022] The data query node generates a random code, and uses the public key corresponding to the data to be queried to encrypt the random code to obtain a first ciphertext;

[0023] The data providing node uses each public key to decrypt the first ciphertext sent by the data query node to obtain the corresponding decrypted plaintext, and performs an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain a corresponding first XOR code;

[0024] The data query node performs an XOR operation on the random code and each first XOR code sent by the data providing node to generate a one-to-one corresponding second XOR code, wherein the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried.

[0025] Furthermore, the hidden query method further includes:

[0026] Using a symmetric key to encrypt all the identification information and the corresponding public key to obtain a second ciphertext;

[0027] Correspondingly, the data providing node sends all identification information and corresponding public keys to the data query node, including:

[0028] The data providing node sends the second ciphertext to the data query node.

[0029] In a fourth aspect, the present application provides a data providing node, the data providing node including all queryable data, each queryable data corresponding to a public-private key pair, each public-private key pair including a public key and a private key, each queryable data corresponding to an identification information, the data providing node including:

[0030] The first data transmission module is used to send all identification information and corresponding public keys to a data query node, wherein the data query node generates a random code and encrypts the random code with the public key corresponding to the data to be queried to obtain a first ciphertext;

[0031] Decryption module: using each public key to decrypt the first ciphertext respectively to obtain the corresponding decrypted plaintext, and performing an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain the corresponding first XOR code;

[0032] The second data transmission module: sends all the first XOR codes to the data query node, so that the data query node performs an XOR operation on the random code and each first XOR code to generate a one-to-one corresponding second XOR code, wherein the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried.

[0033] In a fifth aspect, the present application provides a data query node, including:

[0034] The first data receiving module receives all identification information and corresponding public keys sent by the data providing node;

[0035] Random code encryption module: generates a random code, and uses the public key corresponding to the data to be queried to encrypt the random code to obtain a first ciphertext;

[0036] The second data receiving module receives all first XOR codes sent by the data query node, wherein the data providing node uses each public key to decrypt the first ciphertext to obtain the corresponding decrypted plaintext, and performs an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain the corresponding first XOR code;

[0037] Data query module: Perform an XOR operation on the random code and each first XOR code to generate a one-to-one corresponding second XOR code, wherein the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried.

[0038] In a sixth aspect, the present application provides a hidden query system based on the RSA algorithm, including: a data providing node and a data query node;

[0039] The data providing node sends all identification information and corresponding public keys to the data query node;

[0040] The data query node generates a random code, and uses the public key corresponding to the data to be queried to encrypt the random code to obtain a first ciphertext;

[0041] The data providing node uses each public key to decrypt the first ciphertext respectively to obtain a corresponding decrypted plaintext, performs an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain a corresponding first XOR code, and sends the first XOR code to the data query node;

[0042] The data query node performs an XOR operation on the random code and each first XOR code to generate a one-to-one corresponding second XOR code, wherein the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried;

[0043] The data providing node includes all queryable data, each queryable data corresponds to a public-private key pair, each public-private key pair includes a public key and a private key, and each queryable data corresponds to an identification information.

[0044] In a seventh aspect, the present application provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the hidden query method when executing the program.

[0045] In an eighth aspect, the present application provides a computer-readable storage medium having a computer program stored thereon, which implements the hidden query method when executed by a processor.

[0046] It can be seen from the above technical scheme that the present application provides a hidden query method and system based on the RSA algorithm, the method includes: the data query node receives all the queryable information sent by the data providing node and its corresponding public key, and generates a random code, uses the public key corresponding to the data to be queried to encrypt the random code to obtain the first ciphertext, the data providing node uses each public key to decrypt the first ciphertext, obtains the corresponding decrypted plaintext, and performs an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain the corresponding first XOR code, the data query node performs an XOR operation on the random code and each first XOR code to generate a one-to-one corresponding second XOR code, wherein the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried. Use an asymmetric key to encrypt an arbitrary random code, use all private keys to decrypt the encrypted random code, obtain the corresponding decrypted plaintext, and then perform an XOR operation on all decrypted plaintexts with the corresponding data and random numbers, thereby improving the privacy of the hidden query process. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0048] Figure 1 It is a flow chart of a data providing node in a hidden query method based on an RSA algorithm in an embodiment of the present application.

[0049] Figure 2 It is a flow chart of a data query node in a hidden query method based on an RSA algorithm in an embodiment of the present application.

[0050] Figure 3 It is a flowchart of the RSA algorithm-based hidden query method in an embodiment of the present application.

[0051] Figure 4 It is a structural diagram of a data providing node in a hidden query method based on an RSA algorithm in an embodiment of the present application.

[0052] Figure 5 It is a structural diagram of a data query node in a hidden query method based on an RSA algorithm in an embodiment of the present application.

[0053] Figure 6 It is a structural diagram of the hidden query system based on the RSA algorithm in the embodiment of the present application.

[0054] Figure 7 It is a schematic diagram of the structure of an electronic device in an embodiment of the present application. DETAILED DESCRIPTION

[0055] In order to make the purpose, technical solution and advantages of the embodiments of the present application clearer, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0056] It should be noted that the hidden query method, system, electronic device and computer-readable storage medium based on the RSA algorithm disclosed in the present application can be used in the field of information security technology, and can also be used in any field outside the field of information security technology. The application field of the hidden query method, system, electronic device and computer-readable storage medium based on the RSA algorithm disclosed in the present application is not limited.

[0057] Hidden query, also known as privacy information retrieval, means that the query party hides the keywords or customer ID information of the queried object, and the data service provider provides matching query results but cannot know which specific query object it corresponds to. Data does not go out and can be calculated, eliminating the possibility of data caching, data leakage, and data trafficking. The present application provides a hidden query method, system, electronic device and computer-readable storage medium based on the RSA algorithm. The data query node receives all queryable information and corresponding public keys sent by the data providing node, and generates a random code. The random code is encrypted using the public key corresponding to the data to be queried to obtain the ciphertext. The data providing node uses each public key to decrypt the ciphertext to obtain the corresponding decrypted plaintext, and performs an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain the corresponding first XOR code. The data query node performs an XOR operation on the random code and each first XOR code to generate multiple second XOR codes. The second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried. An asymmetric key is used to encrypt an arbitrary random code, and all private keys are used to decrypt the encrypted random code to obtain the corresponding decrypted plaintext. All decrypted plaintexts are then XORed with the corresponding data and random numbers, thereby improving the privacy of the hidden query process.

[0058] Based on the above content, the present application also provides a hidden query system for implementing the hidden query method provided in one or more embodiments of the present application. The hidden query system includes a data providing node and a data query node. The data query node can be communicatively connected with a client device. The client terminal device can be provided with multiple nodes. The hidden query system can specifically access the client terminal device through an application server.

[0059] Among them, the hidden query system includes a data providing node and a data query node. The data query node can receive information to be queried from a client terminal device. The data query node receives all queryable information sent by the data providing node and its corresponding public key, and generates a random code. The random code is encrypted using the public key corresponding to the data to be queried to obtain a first ciphertext. The data providing node uses each public key to decrypt the first ciphertext to obtain the corresponding decrypted plaintext, and performs an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain the corresponding first XOR code. The data query node performs an XOR operation on the random code and each first XOR code to generate a one-to-one corresponding second XOR code, wherein the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried.

[0060] It is to be understood that the client device may include a smart phone, a tablet electronic device, a portable computer, a desktop computer, a personal digital assistant (PDA), etc.

[0061] The above-mentioned client device may have a communication module (i.e., a communication unit) that can communicate with a remote server to achieve data transmission with the server. For example, the communication unit may send the information to be queried to the server of the data query node so that the data query node encrypts the random code according to the information to be queried; the communication unit may also send the encrypted random code to the data providing node. The communication unit may also receive the first XOR code sent by the data providing node. The server may include a single computer device, or a server cluster consisting of multiple servers, or a server structure of a distributed device.

[0062] The server and the client device may communicate with each other using any suitable network protocol, including network protocols that have not yet been developed on the date of filing this application. The network protocols may include, for example, TCP / IP, UDP / IP, HTTP, HTTPS, etc. Of course, the network protocols may also include, for example, RPC (Remote Procedure Call Protocol) and REST (Representational State Transfer) protocols used on top of the above protocols.

[0063] The hidden query method, system, electronic device and computer-readable storage medium provided by the present application, the data query node receives all the queryable information and the corresponding public key sent by the data providing node, and generates a random code, uses the public key corresponding to the data to be queried to encrypt the random code to obtain the ciphertext, the data providing node uses each public key to decrypt the ciphertext respectively, obtains the corresponding decrypted plaintext, and performs an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain the corresponding first XOR code, the data query node performs an XOR operation on the random code and each first XOR code to generate multiple second XOR codes, and the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried. An asymmetric key is used to encrypt an arbitrary random code, and all private keys are used to decrypt the encrypted random code to obtain the corresponding decrypted plaintext, and then all decrypted plaintexts are XORed with the corresponding data and random numbers, thereby improving the privacy of the hidden query process.

[0064] The details are described through the following multiple embodiments and application examples.

[0065] The present application provides an embodiment of a hidden query method based on an RSA algorithm, which is executed by the data providing node, wherein the data providing node includes all queryable data, each queryable data corresponds to a public-private key pair, each public-private key pair includes a public key and a private key, and each queryable data corresponds to an identification information, see Figure 1 , the hidden query method specifically includes the following contents:

[0066] Step S100: All identification information and corresponding public keys are sent to a data query node, wherein the data query node generates a random code and encrypts the random code using the public key corresponding to the data to be queried to obtain a first ciphertext.

[0067] In step 100, each identification information corresponds to a public-private key pair, which is generated using the RSA asymmetric encryption algorithm. The identification information of all queryable data and its corresponding public key are sent to the data query node. The data query node extracts the public key corresponding to the data to be queried, and uses the public key to encrypt a randomly generated random code to obtain the first ciphertext. For example, the data providing node contains two queryable data D1 and D1, whose corresponding identification information is ID1 and ID2, whose corresponding public keys are n1, e and n2, e respectively, and whose corresponding private keys are d1 and d2 respectively. The data providing node sends e, n1, n2, ID1 and ID2 to the data query node; the data query node arbitrarily selects a random code r, and uses the public key e, n1 corresponding to the data to be queried to encrypt the random code r to obtain the first ciphertext r. e mod n1, the first ciphertext r e mod n1 is sent to the data providing node.

[0068] The RSA algorithm is a commonly used asymmetric encryption algorithm. The algorithm is based on a number theory fact: it is very easy to multiply two large prime numbers, but it is extremely difficult to factorize the product at that time. Therefore, the product can be made public as an encryption key, that is, a public key, and the two large prime numbers are combined into a private key. The public key can be published for anyone to use, while the private key is owned by oneself for decryption. The decryptor has the private key and publishes the public key generated by the private key calculation to the encryptor. Encryption uses the public key for encryption and sends the ciphertext to the decryptor, who uses the private key to decrypt and decode the ciphertext into plaintext.

[0069] Step S200: Decrypt the first ciphertext using each public key to obtain a corresponding decrypted plaintext, and perform an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain a corresponding first XOR code.

[0070] It is understandable that, since the data providing node does not know which set of public keys the data query node uses to encrypt the random code, the data providing node needs to use the private keys of all queryable data to decrypt the first ciphertext to obtain the corresponding decrypted plaintext, and perform an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain the corresponding first XOR code. For example, the data providing node uses all private keys d1 and d2 to decrypt the first ciphertext r e Mod n1 is used to decrypt, and the corresponding decryption result k1=r is obtained. d1mod n1=r,k2=r d2 mod n2, and then decrypt the result k1 = r d1 mod n1, k2 = r d2 mod n2 and the corresponding number can be queried data D1 and D2 for XOR operation Send E1 and E2 to the data query node.

[0071] Step S300: Send all first XOR codes to the data query node, so that the data query node performs XOR operations on the random code and each first XOR code to generate one-to-one corresponding second XOR codes, wherein the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried.

[0072] From the above description, it can be seen that the hidden query method provided by the embodiment of the present application is that the data query node receives all the queryable information and the corresponding public key sent by the data providing node, and generates a random code, and uses the public key corresponding to the data to be queried to encrypt the random code to obtain the ciphertext, and the data providing node uses each public key to decrypt the ciphertext to obtain the corresponding decrypted plaintext, and performs an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain the corresponding first XOR code, and the data query node performs an XOR operation on the random code and each first XOR code to generate multiple second XOR codes, and the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried. An asymmetric key is used to encrypt an arbitrary random code, and all private keys are used to decrypt the encrypted random code to obtain the corresponding decrypted plaintext, and then all decrypted plaintexts are XORed with the corresponding data and random numbers, thereby improving the privacy of the hidden query process.

[0073] In one embodiment of the hidden query method provided in the present application, a preferred method for querying data is provided, and the hidden query specifically includes the following contents:

[0074] Using a symmetric key to encrypt all the identification information and the corresponding public key to obtain a second ciphertext;

[0075] Correspondingly, the step 100 specifically further includes the following contents:

[0076] The second ciphertext is sent to the data query node.

[0077] It can be understood that the data providing node uses a symmetric key to encrypt all identification information and its corresponding public key to obtain a second ciphertext, and sends the second ciphertext to the data query node. The data query node uses a symmetric key to decrypt the second ciphertext to obtain all identification information and its corresponding public key. For example, the data providing node contains two queryable data D1 and D1, whose corresponding identification information is ID1 and ID2, whose corresponding public keys are n1, e and n2, e respectively, and whose corresponding private keys are d1 and d2 respectively. The data providing node uses a symmetric key to decrypt e, n1, n2, ID1 and ID2 Encrypt to get the second ciphertext E, symmetric key The SM4 algorithm is used to obtain the second ciphertext E and send it to the data query node.

[0078] The SM4 algorithm is a block cipher algorithm. Its block length is 128 bits, and the key length is also 128 bits. Both the encryption algorithm and the key expansion algorithm use a 32-round nonlinear iterative structure, and perform encryption operations in units of words (32 bits). Each iterative operation is a round of transformation function F. The structure of the SM4 algorithm encryption / decryption algorithm is the same, but the round keys used are opposite, where the decryption round key is the reverse order of the encryption round key.

[0079] The present application provides an embodiment of a hidden query method based on the RSA algorithm, which is executed by the data query node, see Figure 2 , the hidden query method specifically includes the following contents:

[0080] Step S400: Receive all identification information and corresponding public keys sent by the data providing node.

[0081] It can be understood that after the data query node receives all the identification information and the corresponding public key sent by the data providing node, it determines the public key corresponding to the data to be queried. For example, the data query node receives all the identification information ID1 and ID2 and the corresponding public keys e, n1 and e, n2 sent by the data providing node, and selects the public key e, n1 corresponding to the data D1 to be queried.

[0082] Step S500: Generate a random code, and use the public key corresponding to the data to be queried to encrypt the random code to obtain a first ciphertext.

[0083] It can be understood that the data query node arbitrarily selects a random code, encrypts the random code using the public key corresponding to the data to be queried to obtain the first ciphertext, and sends the first ciphertext to the data providing node. For example, the data query node arbitrarily selects a random code r, encrypts the random code r using the public key e,n1 corresponding to the data to be queried to obtain the first ciphertext r e mod n1, the first ciphertext r emod n1 is sent to the data providing node.

[0084] Step S600: Receive all first XOR codes sent by the data query node, wherein the data providing node uses each public key to decrypt the first ciphertext respectively to obtain the corresponding decrypted plaintext, and performs an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain the corresponding first XOR code.

[0085] It can be understood that, since the data providing node does not know which set of public keys the data query node uses to encrypt the random code, the data providing node needs to use the private keys of all queryable data to decrypt the first ciphertext to obtain the corresponding decrypted plaintext, and perform an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain the corresponding first XOR code. The data providing node sends all the first XOR codes to the data query node. For example, the data providing node uses all private keys d1 and d2 to decrypt the first ciphertext r e Mod n1 is used for decryption, and the corresponding decryption result k1=r is obtained. d1 mod n1=r,k2=r d2 mod n2, and then decrypt the result k1 = r d1 mod n1=r,k2=r d2 mod n2 and the corresponding number can be queried data D1 and D2 for XOR operation The data query node receives all first XOR codes E1, E2 sent by the data providing node.

[0086] Step S700: performing an XOR operation on the random code and each first XOR code to generate a one-to-one corresponding second XOR code, wherein the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried.

[0087] It can be understood that the data query node uses the previously generated random code and each first XOR code to perform an XOR operation to obtain the corresponding second XOR code, and the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried. For example, the data query node uses the random code r to perform an XOR operation with E1 and E2 respectively to obtain The second XOR code R1 corresponds to the public key of the data to be queried D1, and the data query node extracts the query data D1=R1.

[0088] From the above description, it can be seen that the secret query method provided by the embodiment of the present application is that the data query node receives all the queryable information and the corresponding public key sent by the data providing node, and generates a random code, and uses the public key corresponding to the data to be queried to encrypt the random code to obtain the ciphertext, and the data providing node uses each public key to decrypt the ciphertext to obtain the corresponding decrypted plaintext, and performs an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain the corresponding first XOR code, and the data query node performs an XOR operation on the random code and each first XOR code to generate multiple second XOR codes, and the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried. An asymmetric key is used to encrypt an arbitrary random code, and all private keys are used to decrypt the encrypted random code to obtain the corresponding decrypted plaintext, and then all decrypted plaintexts are XORed with the corresponding data and random numbers, thereby improving the privacy of the hidden query process.

[0089] In one embodiment of the hidden query method provided in the present application, a preferred method for querying data is provided, wherein the data providing node uses a symmetric key to encrypt all the identification information and the corresponding public key to obtain a second ciphertext, and the step S400 specifically further includes the following content:

[0090] Step 221: Receive the second ciphertext sent by the data query node.

[0091] It can be understood that the data providing node uses a symmetric key to encrypt all identification information and its corresponding public key to obtain a second ciphertext, and sends the second ciphertext to the data query node. The data query node uses a symmetric key to decrypt the second ciphertext to obtain all identification information and its corresponding public key. For example, the data providing node contains two queryable data D1 and D1, whose corresponding identification information is ID1 and ID2, whose corresponding public keys are n1, e and n2, e respectively, and whose corresponding private keys are d1 and d2 respectively. The data providing node uses a symmetric key to decrypt e, n1, n2, ID1 and ID2 Encrypt to get the second ciphertext E, symmetric key The SM4 algorithm is used to obtain the second ciphertext E and send it to the data query node. The data query node receives the second ciphertext E and uses the SM4 decryption algorithm Decrypt and determine the public key e,n1 corresponding to the data D1 to be queried.

[0092] The present application provides an embodiment of a hidden query method based on the RSA algorithm, see Figure 3 , the data providing node includes all queryable data, each queryable data corresponds to a public-private key pair, each public-private key pair includes a public key and a private key, each queryable data corresponds to an identification information, and the hidden query method specifically includes the following contents:

[0093] Step S001: The data providing node sends all identification information and corresponding public keys to the data query node;

[0094] It can be understood that each identification information corresponds to a public-private key pair, which is generated using the RSA asymmetric encryption algorithm, and the identification information of all queryable data and its corresponding public key are sent to the data query node. For example, the data providing node contains two queryable data D1 and D1, whose corresponding identification information is ID1 and ID2, whose corresponding public keys are n1, e and n2, e respectively, and whose corresponding private keys are d1 and d2 respectively. The data providing node sends e, n1, n2, ID1 and ID2 to the data query node.

[0095] Step S002: The data query node generates a random code, and uses the public key corresponding to the data to be queried to encrypt the random code to obtain a first ciphertext.

[0096] It can be understood that the data query node extracts the public key corresponding to the data to be queried from the identification information of all the received queryable data and their corresponding public keys, and uses the public key to encrypt a randomly generated random code to obtain the first ciphertext. For example, the data query node arbitrarily selects a random code r, and uses the public key e,n1 corresponding to the data to be queried to encrypt the random code r to obtain the first ciphertext r e mod n1, the first ciphertext r e mod n1 is sent to the data providing node.

[0097] Step S003: the data providing node uses each public key to decrypt the first ciphertext sent by the data query node to obtain the corresponding decrypted plaintext, and performs an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain a corresponding first XOR code.

[0098] It is understandable that, since the data providing node does not know which set of public keys the data query node uses to encrypt the random code, the data providing node needs to use the private keys of all queryable data to decrypt the first ciphertext to obtain the corresponding decrypted plaintext, and perform an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain the corresponding first XOR code. For example, the data providing node uses all private keys d1 and d2 to decrypt the first ciphertext r e Mod n1 is used for decryption, and the corresponding decryption result k1=r is obtained. d1 mod n1=r,k2=r d2 mod n2, and then decrypt the result k1 = r d1 mod n1, k2 = r d2 mod n2 and the corresponding number can be queried data D1 and D2 for XOR operation Send E1 and E2 to the data query node.

[0099] Step S004: the data query node performs an XOR operation on the random code and each first XOR code sent by the data providing node to generate a one-to-one corresponding second XOR code, wherein the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried.

[0100] It can be understood that the data query node uses the previously generated random code and each first XOR code to perform an XOR operation to obtain the corresponding second XOR code, and the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried. For example, the data query node uses the random code r to perform an XOR operation with E1 and E2 respectively to obtain The second XOR code R1 corresponds to the public key of the data to be queried D1, and the data query node extracts the query data D1=R1.

[0101] From the above description, it can be seen that the hidden query method provided by the embodiment of the present application is that the data query node receives all the queryable information and the corresponding public key sent by the data providing node, and generates a random code, and uses the public key corresponding to the data to be queried to encrypt the random code to obtain the ciphertext, and the data providing node uses each public key to decrypt the ciphertext to obtain the corresponding decrypted plaintext, and performs an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain the corresponding first XOR code, and the data query node performs an XOR operation on the random code and each first XOR code to generate multiple second XOR codes, and the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried. An asymmetric key is used to encrypt an arbitrary random code, and all private keys are used to decrypt the encrypted random code to obtain the corresponding decrypted plaintext, and then all decrypted plaintexts are XORed with the corresponding data and random numbers, thereby improving the privacy of the hidden query process.

[0102] From the software level, in order to solve the problem of hidden query privacy, an embodiment of the data providing node provided in this application is shown in FIG. Figure 4 , the data providing node includes all queryable data, each queryable data corresponds to a public-private key pair, each public-private key pair includes a public key and a private key, each queryable data corresponds to an identification information, and the data providing node specifically includes the following content:

[0103] The first data transmission module 10: sends all identification information and corresponding public keys to a data query node, wherein the data query node generates a random code and encrypts the random code with a public key corresponding to the data to be queried to obtain a first ciphertext.

[0104] It can be understood that each identification information corresponds to a public-private key pair, which is generated using the RSA asymmetric encryption algorithm. The first data transmission module 10 sends the identification information of all queryable data and its corresponding public key to the data query node. The data query node extracts the public key corresponding to the data to be queried, and uses the public key to encrypt a randomly generated random code to obtain the first ciphertext. For example, the data providing node contains two queryable data D1 and D1, whose corresponding identification information is ID1 and ID2, whose corresponding public keys are n1, e and n2, e respectively, and whose corresponding private keys are d1 and d2 respectively. The first data transmission module 10 sends e, n1, n2, ID1 and ID2 to the data query node; the data query node arbitrarily selects a random code r, and uses the public key e, n1 corresponding to the data to be queried to encrypt the random code r to obtain the first ciphertext r. e modn1, the first ciphertext r e mod n1 is sent to the data providing node. In some specific implementations, the data providing node uses a symmetric key to encrypt all identification information and its corresponding public key to obtain a second ciphertext, and sends the second ciphertext to the data query node. The data query node uses a symmetric key to decrypt the second ciphertext to obtain all identification information and its corresponding public key. For example, the data providing node uses a symmetric key to decrypt e, n1, n2, ID1 and ID2 Encrypt to get the second ciphertext E, symmetric key The SM4 algorithm is used to obtain the second ciphertext E and send it to the data query node.

[0105] The RSA algorithm is a commonly used asymmetric encryption algorithm. The algorithm is based on a number theory fact: it is very easy to multiply two large prime numbers, but it is extremely difficult to factorize the product at that time. Therefore, the product can be made public as an encryption key, that is, a public key, and the two large prime numbers are combined into a private key. The public key can be published for anyone to use, while the private key is owned by oneself for decryption. The decryptor has the private key and publishes the public key generated by the private key calculation to the encryptor. Encryption uses the public key for encryption and sends the ciphertext to the decryptor, who uses the private key to decrypt and decode the ciphertext into plaintext.

[0106] Decryption module 20: Decrypt the first ciphertext using each public key to obtain a corresponding decrypted plaintext, and perform an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain a corresponding first XOR code.

[0107] It is understandable that, since the data providing node does not know which set of public keys the data query node uses to encrypt the random code, the decryption module 20 needs to use the private keys of all queryable data to decrypt the first ciphertext to obtain the corresponding decrypted plaintext, and perform an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain the corresponding first XOR code. For example, the decryption module 20 uses all private keys d1 and d2 to decrypt the first ciphertext r e Mod n1 is used for decryption, and the corresponding decryption result k1=r is obtained. d1 mod n1=r,k2=r d2 mod n2, and then decrypt the result k1 = r d1 mod n1, k2 = r d2 modn2 and the corresponding number can be queried for data D1 and D2 to perform an XOR operation Send E1 and E2 to the data query node.

[0108] The second data transmission module 30: sends all the first XOR codes to the data query node, so that the data query node performs an XOR operation on the random code and each first XOR code to generate a one-to-one corresponding second XOR code, wherein the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried.

[0109] In one embodiment of the data query node provided in this application, see Figure 5 , the data query node specifically includes the following contents:

[0110] The first data receiving module 40 is used for receiving all identification information and corresponding public keys sent by the data providing node.

[0111] It can be understood that after the first data receiving module 40 receives all the identification information and the corresponding public key sent by the first data transmission module 10, it determines the public key corresponding to the data to be queried. For example, the first data receiving module 40 receives all the identification information ID1 and ID2 and the corresponding public keys e, n1 and e, n2 sent by the first data transmission module 10, and selects the public key e, n1 corresponding to the data D1 to be queried.

[0112] Random code encryption module 50: generates a random code, and uses the public key corresponding to the data to be queried to encrypt the random code to obtain a first ciphertext.

[0113] It can be understood that the random code encryption module 50 arbitrarily selects a random code, encrypts the random code using the public key corresponding to the data to be queried to obtain a first ciphertext, and sends the first ciphertext to the data providing node. For example, the random code encryption module 50 arbitrarily selects a random code r, encrypts the random code r using the public key e,n1 corresponding to the data to be queried to obtain a first ciphertext r e mod n1, the first ciphertext r e mod n1 is sent to the data providing node.

[0114] The second data receiving module 60 receives all first XOR codes sent by the data query node, wherein the data providing node uses each public key to decrypt the first ciphertext respectively to obtain the corresponding decrypted plaintext, and performs an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain the corresponding first XOR code.

[0115] It can be understood that, since the data providing node does not know which set of public keys the data query node uses to encrypt the random code, the data providing node needs to use the private keys of all queryable data to decrypt the first ciphertext to obtain the corresponding decrypted plaintext, and perform an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain the corresponding first XOR code. The second data receiving module 60 receives all the first XOR codes sent by the second data transmission module 30 of the data providing node. For example, the decryption module 20 of the data providing node uses all the private keys d1 and d2 to decrypt the first ciphertext r e Mod n1 is used to decrypt, and the corresponding decryption result k1=r is obtained. d1 mod n1=r,k2=r d2 mod n2, and then decrypt the result k1 = r d1 modn1=r,k2=r d2 mod n2 and the corresponding number can be queried data D1 and D2 for XOR operation The second data receiving module 60 receives all first XOR codes E1 and E2 sent by the second data transmission module 30 of the data providing node.

[0116] Data query module 70: Perform an XOR operation on the random code and each first XOR code to generate a one-to-one corresponding second XOR code, wherein the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried.

[0117] It can be understood that the data query module 70 uses the previously generated random code and each first XOR code to perform an XOR operation to obtain the corresponding second XOR code, and the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried. For example, the data query module 70 uses the random code r to perform an XOR operation with E1 and E2 to obtain The second XOR code R1 corresponds to the public key of the data to be queried D1, and the data query module 70 extracts the query data D1=R1.

[0118] In one embodiment of the hidden query system provided by the present application, see Figure 6 , the hidden query system includes: a data providing node and a data query node;

[0119] The data providing node sends all identification information and corresponding public keys to the data query node;

[0120] It can be understood that each identification information corresponds to a public-private key pair, which is generated using the RSA asymmetric encryption algorithm, and the identification information of all queryable data and its corresponding public key are sent to the data query node. For example, the data providing node contains two queryable data D1 and D1, whose corresponding identification information is ID1 and ID2, whose corresponding public keys are n1, e and n2, e respectively, and whose corresponding private keys are d1 and d2 respectively. The data providing node sends e, n1, n2, ID1 and ID2 to the data query node.

[0121] The data query node generates a random code, and uses the public key corresponding to the data to be queried to encrypt the random code to obtain a first ciphertext;

[0122] It can be understood that the data query node extracts the public key corresponding to the data to be queried from the identification information of all the received queryable data and their corresponding public keys, and uses the public key to encrypt a randomly generated random code to obtain the first ciphertext. For example, the data query node arbitrarily selects a random code r, and uses the public key e,n1 corresponding to the data to be queried to encrypt the random code r to obtain the first ciphertext r e mod n1, the first ciphertext r e mod n1 is sent to the data providing node.

[0123] The data providing node uses each public key to decrypt the first ciphertext respectively to obtain a corresponding decrypted plaintext, performs an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain a corresponding first XOR code, and sends the first XOR code to the data query node;

[0124] It is understandable that, since the data providing node does not know which set of public keys the data query node uses to encrypt the random code, the data providing node needs to use the private keys of all queryable data to decrypt the first ciphertext to obtain the corresponding decrypted plaintext, and perform an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain the corresponding first XOR code. For example, the data providing node uses all private keys d1 and d2 to decrypt the first ciphertext r eMod n1 is used to decrypt, and the corresponding decryption result k1=r is obtained. d1 mod n1=r,k2=r d2 mod n2, and then decrypt the result k1 = r d1 mod n1, k2 = r d2 mod n2 and the corresponding number can be queried data D1 and D2 for XOR operation Send E1 and E2 to the data query node.

[0125] The data query node performs an XOR operation on the random code and each first XOR code to generate a one-to-one corresponding second XOR code, wherein the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried;

[0126] The data providing node includes all queryable data, each queryable data corresponds to a public-private key pair, each public-private key pair includes a public key and a private key, and each queryable data corresponds to an identification information.

[0127] It can be understood that the data query node uses the previously generated random code and each first XOR code to perform an XOR operation to obtain the corresponding second XOR code, and the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried. For example, the data query node uses the random code r to perform an XOR operation with E1 and E2 respectively to obtain The second XOR code R1 corresponds to the public key of the data to be queried D1, and the data query node extracts the query data D1=R1.

[0128] From the above description, it can be seen that in the hidden query system provided by the embodiment of the present application, the data query node receives all the queryable information and the corresponding public key sent by the data providing node, and generates a random code, and uses the public key corresponding to the data to be queried to encrypt the random code to obtain the ciphertext, and the data providing node uses each public key to decrypt the ciphertext to obtain the corresponding decrypted plaintext, and performs an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain the corresponding first XOR code, and the data query node performs an XOR operation on the random code and each first XOR code to generate multiple second XOR codes, and the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried. An asymmetric key is used to encrypt an arbitrary random code, and all private keys are used to decrypt the encrypted random code to obtain the corresponding decrypted plaintext, and then all decrypted plaintexts are XORed with the corresponding data and random numbers, thereby improving the privacy of the hidden query process.

[0129] From the hardware level, in order to solve the problem of privacy leakage in existing hidden query, the present application provides an embodiment of an electronic device for implementing all or part of the content in the hidden query method, and the electronic device specifically includes the following content:

[0130] Figure 7 FIG. 9 is a schematic block diagram of the system structure of the electronic device 9600 according to an embodiment of the present application. Figure 7 As shown, the electronic device 9600 may include a central processor 9100 and a memory 9140; the memory 9140 is coupled to the central processor 9100. It is worth noting that Figure 7 is exemplary; other types of structures may also be used to supplement or replace this structure to implement telecommunication functions or other functions.

[0131] In one embodiment, the hidden query function may be integrated into a central processing unit, wherein the central processing unit may be configured to perform the following control:

[0132] Step S001: The data providing node sends all identification information and corresponding public keys to the data query node;

[0133] It can be understood that each identification information corresponds to a public-private key pair, which is generated using the RSA asymmetric encryption algorithm, and the identification information of all queryable data and its corresponding public key are sent to the data query node. For example, the data providing node contains two queryable data D1 and D1, whose corresponding identification information is ID1 and ID2, whose corresponding public keys are n1, e and n2, e respectively, and whose corresponding private keys are d1 and d2 respectively. The data providing node sends e, n1, n2, ID1 and ID2 to the data query node.

[0134] Step S002: The data query node generates a random code, and uses the public key corresponding to the data to be queried to encrypt the random code to obtain a first ciphertext.

[0135] It can be understood that the data query node extracts the public key corresponding to the data to be queried from the identification information of all the received queryable data and their corresponding public keys, and uses the public key to encrypt a randomly generated random code to obtain the first ciphertext. For example, the data query node arbitrarily selects a random code r, and uses the public key e,n1 corresponding to the data to be queried to encrypt the random code r to obtain the first ciphertext r e mod n1, the first ciphertext r e mod n1 is sent to the data providing node.

[0136] Step S003: the data providing node uses each public key to decrypt the first ciphertext sent by the data query node to obtain the corresponding decrypted plaintext, and performs an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain a corresponding first XOR code.

[0137] It is understandable that, since the data providing node does not know which set of public keys the data query node uses to encrypt the random code, the data providing node needs to use the private keys of all queryable data to decrypt the first ciphertext to obtain the corresponding decrypted plaintext, and perform an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain the corresponding first XOR code. For example, the data providing node uses all private keys d1 and d2 to decrypt the first ciphertext r e Mod n1 is used for decryption, and the corresponding decryption result k1=r is obtained. d1 mod n1=r,k2=r d2 mod n2, and then decrypt the result k1 = r d1 mod n1, k2 = r d2 mod n2 and the corresponding number can be queried data D1 and D2 for XOR operation Send E1 and E2 to the data query node.

[0138] Step S004: the data query node performs an XOR operation on the random code and each first XOR code sent by the data providing node to generate a one-to-one corresponding second XOR code, wherein the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried.

[0139] It can be understood that the data query node uses the previously generated random code and each first XOR code to perform an XOR operation to obtain the corresponding second XOR code, and the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried. For example, the data query node uses the random code r to perform an XOR operation with E1 and E2 respectively to obtain The second XOR code R1 corresponds to the public key of the data to be queried D1, and the data query node extracts the query data D1=R1.

[0140] From the above description, it can be known that in the electronic device provided by the embodiment of the present application, the data query node receives all the queryable information and the corresponding public key sent by the data providing node, and generates a random code, and uses the public key corresponding to the data to be queried to encrypt the random code to obtain the ciphertext, and the data providing node uses each public key to decrypt the ciphertext to obtain the corresponding decrypted plaintext, and performs an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain the corresponding first XOR code, and the data query node performs an XOR operation on the random code and each first XOR code to generate multiple second XOR codes, and the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried. An asymmetric key is used to encrypt an arbitrary random code, and all private keys are used to decrypt the encrypted random code to obtain the corresponding decrypted plaintext, and then all decrypted plaintexts are XORed with the corresponding data and random numbers, thereby improving the privacy in the hidden query process.

[0141] In another embodiment, the hidden query system can be configured separately from the central processor 9100. For example, the hidden query system can be configured as a chip connected to the central processor 9100, and the blockchain data interaction function can be realized through the control of the central processor.

[0142] like Figure 7 As shown, the electronic device 9600 may also include: a communication module 9110, an input unit 9120, an audio processor 9130, a display 9160, and a power supply 9170. It is worth noting that the electronic device 9600 does not necessarily have to include Figure 7 In addition, the electronic device 9600 may also include Figure 7 For components not shown, reference may be made to the prior art.

[0143] like Figure 7 As shown, the central processing unit 9100 is sometimes also referred to as a controller or an operation control, and may include a microprocessor or other processor device and / or logic device. The central processing unit 9100 receives input and controls the operation of various components of the electronic device 9600.

[0144] The memory 9140 may be, for example, one or more of a cache, a flash memory, a hard drive, a removable medium, a volatile memory, a non-volatile memory or other suitable devices. The above-mentioned information related to the failure may be stored, and a program for executing the relevant information may also be stored. The CPU 9100 may execute the program stored in the memory 9140 to implement information storage or processing, etc.

[0145] The input unit 9120 provides input to the central processing unit 9100. The input unit 9120 is, for example, a key or a touch input device. The power supply 9170 is used to provide power to the electronic device 9600. The display 9160 is used to display display objects such as images and texts. The display may be, for example, an LCD display, but is not limited thereto.

[0146] The memory 9140 may be a solid-state memory, such as a read-only memory (ROM), a random access memory (RAM), a SIM card, etc. It may also be a memory that saves information even when the power is off, can be selectively erased, and is provided with more data, examples of which are sometimes referred to as EPROMs, etc. The memory 9140 may also be some other type of device. The memory 9140 includes a buffer memory 9141 (sometimes referred to as a buffer). The memory 9140 may include an application / function storage unit 9142, which is used to store application programs and function programs or processes for executing the operation of the electronic device 9600 through the central processor 9100.

[0147] The memory 9140 may also include a data storage unit 9143 for storing data, such as contacts, digital data, pictures, sounds, and / or any other data used by the electronic device. The driver storage unit 9144 of the memory 9140 may include various drivers for communication functions of the electronic device and / or for executing other functions of the electronic device (such as messaging applications, address book applications, etc.).

[0148] The communication module 9110 is a transmitter / receiver 9110 that sends and receives signals via an antenna 9111. The communication module (transmitter / receiver) 9110 is coupled to the central processor 9100 to provide input signals and receive output signals, which may be the same as the case of a conventional mobile communication terminal.

[0149] Based on different communication technologies, multiple communication modules 9110 may be provided in the same electronic device, such as a cellular network module, a Bluetooth module and / or a wireless LAN module, etc. The communication module (transmitter / receiver) 9110 is also coupled to a speaker 9131 and a microphone 9132 via an audio processor 9130 to provide an audio output via the speaker 9131 and receive an audio input from the microphone 9132, thereby realizing a common telecommunication function. The audio processor 9130 may include any suitable buffer, decoder, amplifier, etc. In addition, the audio processor 9130 is also coupled to the central processor 9100, so that recording can be performed on the local machine through the microphone 9132, and the sound stored on the local machine can be played through the speaker 9131.

[0150] The embodiments of the present application also provide a computer-readable storage medium capable of implementing all the steps in the hidden query method in the above embodiments. The computer-readable storage medium stores a computer program. When the computer program is executed by a processor, all the steps of the hidden query method in the above embodiments are implemented by the execution subject being a server or a client. For example, when the processor executes the computer program, the following steps are implemented:

[0151] Step S001: The data providing node sends all identification information and corresponding public keys to the data query node;

[0152] It can be understood that each identification information corresponds to a public-private key pair, which is generated using the RSA asymmetric encryption algorithm, and the identification information of all queryable data and its corresponding public key are sent to the data query node. For example, the data providing node contains two queryable data D1 and D1, whose corresponding identification information is ID1 and ID2, whose corresponding public keys are n1, e and n2, e respectively, and whose corresponding private keys are d1 and d2 respectively. The data providing node sends e, n1, n2, ID1 and ID2 to the data query node.

[0153] Step S002: The data query node generates a random code, and uses the public key corresponding to the data to be queried to encrypt the random code to obtain a first ciphertext.

[0154] It can be understood that the data query node extracts the public key corresponding to the data to be queried from the identification information of all the received queryable data and their corresponding public keys, and uses the public key to encrypt a randomly generated random code to obtain the first ciphertext. For example, the data query node arbitrarily selects a random code r, and uses the public key e,n1 corresponding to the data to be queried to encrypt the random code r to obtain the first ciphertext r e mod n1, the first ciphertext r e mod n1 is sent to the data providing node.

[0155] Step S003: the data providing node uses each public key to decrypt the first ciphertext sent by the data query node to obtain the corresponding decrypted plaintext, and performs an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain a corresponding first XOR code.

[0156] It is understandable that, since the data providing node does not know which set of public keys the data query node uses to encrypt the random code, the data providing node needs to use the private keys of all queryable data to decrypt the first ciphertext to obtain the corresponding decrypted plaintext, and perform an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain the corresponding first XOR code. For example, the data providing node uses all private keys d1 and d2 to decrypt the first ciphertext r eMod n1 is used to decrypt, and the corresponding decryption result k1=r is obtained. d1 mod n1=r,k2=r d2 mod n2, and then decrypt the result k1 = r d1 mod n1, k2 = r d2 mod n2 and the corresponding number can be queried data D1 and D2 for XOR operation Send E1 and E2 to the data query node.

[0157] Step S004: the data query node performs an XOR operation on the random code and each first XOR code sent by the data providing node to generate a one-to-one corresponding second XOR code, wherein the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried.

[0158] It can be understood that the data query node uses the previously generated random code and each first XOR code to perform an XOR operation to obtain the corresponding second XOR code, and the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried. For example, the data query node uses the random code r to perform an XOR operation with E1 and E2 respectively to obtain The second XOR code R1 corresponds to the public key of the data to be queried D1, and the data query node extracts the query data D1=R1.

[0159] From the above description, it can be seen that the computer-readable medium provided by the embodiment of the present application, the data query node receives all the queryable information and the corresponding public key sent by the data providing node, and generates a random code, and uses the public key corresponding to the data to be queried to encrypt the random code to obtain the ciphertext, and the data providing node uses each public key to decrypt the ciphertext to obtain the corresponding decrypted plaintext, and performs an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain the corresponding first XOR code, and the data query node performs an XOR operation on the random code and each first XOR code to generate multiple second XOR codes, and the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried. An asymmetric key is used to encrypt an arbitrary random code, and all private keys are used to decrypt the encrypted random code to obtain the corresponding decrypted plaintext, and then all decrypted plaintexts are XORed with the corresponding data and random numbers, thereby improving the privacy in the hidden query process.

[0160] It will be appreciated by those skilled in the art that embodiments of the present invention may be provided as methods, devices, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0161] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (apparatus), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0162] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0163] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0164] The present invention uses specific embodiments to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea. At the same time, for those skilled in the art, according to the idea of ​​the present invention, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present invention.

Claims

1. A hidden query method based on RSA algorithm, characterized in that: Executed by a data providing node, the data providing node includes all queryable data, each queryable data corresponds to a public-private key pair, each public-private key pair includes a public key and a private key, each queryable data corresponds to an identification information, the hidden query method includes: Sending all identification information and corresponding public keys to a data query node, wherein the data query node generates a random code and encrypts the random code using the public key corresponding to the data to be queried to obtain a first ciphertext; Decrypting the first ciphertext using each private key to obtain a corresponding decrypted plaintext, and performing an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain a corresponding first XOR code; Sending all the first XOR codes to the data query node, so that the data query node performs an XOR operation on the random code and each first XOR code to generate a one-to-one corresponding second XOR code, wherein the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried; The hidden query method also includes: using a symmetric key to encrypt all the identification information and the corresponding public key to obtain a second ciphertext; sending all the identification information and the corresponding public key to the data query node includes: sending the second ciphertext to the data query node.

2. A hidden query method based on RSA algorithm, characterized in that: Executed by a data query node, the hidden query method includes: Receive all identification information and corresponding public keys sent by the data providing node; Generate a random code, and use the public key corresponding to the data to be queried to encrypt the random code to obtain a first ciphertext; Receive all first XOR codes sent by the data query node, wherein the data providing node uses each private key to decrypt the first ciphertext respectively to obtain the corresponding decrypted plaintext, and performs an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain the corresponding first XOR code; Performing an XOR operation on the random code and each first XOR code to generate a one-to-one corresponding second XOR code, wherein the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried; the data providing node uses a symmetric key to encrypt all the identification information and the corresponding public key to obtain a second ciphertext, and receiving all the identification information and the corresponding public key sent by the data providing node includes: receiving the second ciphertext sent by the data query node.

3. A hidden query method based on RSA algorithm, characterized in that: The data providing node includes all queryable data, each queryable data corresponds to a public-private key pair, each public-private key pair includes a public key and a private key, each queryable data corresponds to an identification information, and the hidden query method includes: The data providing node sends all identification information and the corresponding public key to the data query node; The data query node generates a random code, and uses a public key corresponding to the data to be queried to encrypt the random code to obtain a first ciphertext; The data providing node uses each private key to decrypt the first ciphertext sent by the data query node to obtain the corresponding decrypted plaintext, and performs an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain a corresponding first XOR code; The data query node performs an XOR operation on the random code and each first XOR code sent by the data providing node to generate a one-to-one corresponding second XOR code, wherein the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried; The hidden query method also includes: using a symmetric key to encrypt all the identification information and the corresponding public key to obtain a second ciphertext; the data providing node sends all the identification information and the corresponding public key to the data query node, including: the data providing node sends the second ciphertext to the data query node.

4. A data providing node, applied to a hidden query method based on RSA algorithm, characterized in that: The data providing node includes all queryable data, each queryable data corresponds to a public-private key pair, each public-private key pair includes a public key and a private key, each queryable data corresponds to an identification information, and the data providing node includes: The first data transmission module is used to send all identification information and corresponding public keys to a data query node, wherein the data query node generates a random code and encrypts the random code with the public key corresponding to the data to be queried to obtain a first ciphertext; The first data transmission module is further used to encrypt all the identification information and the corresponding public key using a symmetric key to obtain a second ciphertext; and send the second ciphertext to the data query node; Decryption module: using each private key to decrypt the first ciphertext respectively to obtain the corresponding decrypted plaintext, and performing an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain the corresponding first XOR code; The second data transmission module: sends all the first XOR codes to the data query node, so that the data query node performs an XOR operation on the random code and each first XOR code to generate a one-to-one corresponding second XOR code, wherein the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried.

5. A data query node, applied to a hidden query method based on an RSA algorithm, characterized in that: include: The first data receiving module receives all identification information and corresponding public keys sent by the data providing node; The first data receiving module is also used to receive a second ciphertext sent by the data query node; The data providing node encrypts all the identification information and the corresponding public key using a symmetric key to obtain a second ciphertext; Random code encryption module: generates a random code, and uses the public key corresponding to the data to be queried to encrypt the random code to obtain a first ciphertext; The second data receiving module receives all first XOR codes sent by the data query node, wherein the data providing node uses each private key to decrypt the first ciphertext to obtain the corresponding decrypted plaintext, and performs an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain the corresponding first XOR code; Data query module: Perform an XOR operation on the random code and each first XOR code to generate a one-to-one corresponding second XOR code, wherein the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried.

6. A hidden query system based on RSA algorithm, characterized in that: include: Data providing nodes and data query nodes; The data providing node sends all identification information and corresponding public keys to the data query node; The data query node generates a random code, and uses a public key corresponding to the data to be queried to encrypt the random code to obtain a first ciphertext; The data providing node uses each private key to decrypt the first ciphertext respectively to obtain a corresponding decrypted plaintext, performs an XOR operation on each decrypted plaintext and the corresponding queryable data to obtain a corresponding first XOR code, and sends the first XOR code to the data query node; The data query node performs an XOR operation on the random code and each first XOR code to generate a one-to-one corresponding second XOR code, wherein the second XOR code corresponding to the public key corresponding to the data to be queried is the data to be queried; The data providing node includes all queryable data, each queryable data corresponds to a public-private key pair, each public-private key pair includes a public key and a private key, and each queryable data corresponds to an identification information.

7. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the hidden query method according to any one of claims 1 to 3 are implemented.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the hidden query method according to any one of claims 1 to 3 are implemented.

Citation Information

Patent Citations

  • Data storage method, query method and device, storage medium and computer equipment

    CN108009440A

  • Data query method, computing device and system

    CN109299149A