Information query method, device, system, equipment and storage medium for protecting privacy
By extending the query object collection and encrypted data processing, and using the privacy protection set intersection algorithm, the problem of user privacy leakage in the bank risk control system is solved, and information query under privacy protection is realized.
Patent Information
- Application Number
- CN202011277954.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-11-16
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2040-11-16
AI Technical Summary
When the existing technology directly querys user information from the operator in the bank risk control system, it leads to user privacy leakage, and it is impossible to complete the query of user location and real-name authentication and other information while protecting privacy.
Through the collaborative work of the data requester gateway and the data service gateway, the query object collection is expanded and the encrypted query result data set is generated. The privacy protection set intersection algorithm is used to determine the target query results to avoid directly leaking user privacy.
It realizes the query of user location and real-name authentication without revealing user privacy, and protects the privacy data of data requesters and data service providers.
Smart Images

Figure CN114091045B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of data processing, and in particular, to a method, apparatus, and system for protecting privacy in information query, an electronic device, and a computer-readable storage medium. Background Art
[0002] A bank transaction risk control system can evaluate the risk level of a withdrawal account by using the location information of the withdrawer when withdrawing money. For example, when a withdrawer withdraws money from an ATM with a card, the bank can query the operator for the location of the mobile phone associated with the card at the time of withdrawal through the mobile phone number associated with the card; if the location is close to the location of the ATM, it indicates that the cardholder and the holder of the mobile phone associated with the mobile phone number are very likely to be the same person, then the withdrawer is very likely to be the owner of the bank card, and the risk of this withdrawal is relatively low; otherwise, the withdrawer may not be the owner of the bank card, and the risk of the bank card being stolen or misused is relatively high.
[0003] In the current risk control system, when the bank directly queries the operator for user information, it will disclose a lot of user privacy information to the operator, such as the owner of the queried mobile phone number is a customer of this bank, the location of the bank's ATM, the withdrawal frequency at this location, and so on.
[0004] In addition, when a customer opens an account with a bank, the bank needs to verify whether the mobile phone number retained by the customer is real-name registered and is consistent with the certificate information registered by the customer with the bank. The current practice is that the bank can directly ask the operator for the real-name information of the number, and at the same time disclose the situation that the owner of the number is a potential customer of this bank. In the situation where personal privacy protection is increasingly concerned, it is necessary for the bank to complete the above functions without disclosing customer privacy. Summary of the Invention
[0005] The purpose of the embodiments of the present application is to provide a method, apparatus, and system for protecting privacy in information query, an electronic device, and a computer-readable storage medium, so as to query information such as user location and real-name authentication without disclosing user privacy.
[0006] To solve the above technical problems, the embodiments of the present application provide the following technical solutions:
[0007] The first aspect of the present application provides a method for protecting privacy in information query, which is used for a data requestor gateway and includes:
[0008] Receiving a first query request sent by a data requestor for a target query object;
[0009] According to the first query request, sending a second query request for an extended query object set to a data service provider gateway, where the extended query object set includes the target query object;
[0010] Receive a query result data set containing encrypted data returned by the data service provider gateway, where the query result data set is determined based on the query results corresponding to each object in the extended query object set;
[0011] Based on the query result data set, use the privacy-preserving set intersection algorithm to determine the target query result for the target query object;
[0012] Return the target query result to the data requester.
[0013] The second aspect of this application provides a privacy-preserving information query method for a data service provider gateway, including:
[0014] Receive a second query request for an extended query object set sent by the data requester gateway, where the extended query object set includes a target query object;
[0015] Send the second query request to the data service provider to query each object in the extended query object set through the data service provider;
[0016] Generate a query result data set containing encrypted data according to the query results corresponding to each queried object;
[0017] Return the query result data set to the data requester gateway, so that the data requester gateway uses the privacy-preserving set intersection algorithm to determine the target query result for the target query object according to the query result data set.
[0018] The third aspect of this application provides a privacy-preserving information query device for a data requester gateway, including:
[0019] A first query request receiving module, configured to receive a first query request for a target query object sent by a data requester;
[0020] A second query request sending module, configured to send a second query request for an extended query object set to the data service provider gateway according to the first query request, where the extended query object set includes the target query object;
[0021] A query result data set receiving module, configured to receive the query result data set containing encrypted data returned by the data service provider gateway, where the query result data set is determined based on the query results corresponding to each object in the extended query object set;
[0022] A target query result determination module, configured to determine a target query result for the target query object according to the query result data set by using a privacy-preserving set intersection algorithm;
[0023] A target query result sending module, configured to return the target query result to the data requester.
[0024] A fourth aspect of the present application provides a privacy-protected information query device for a data service provider gateway, including:
[0025] A second query request receiving module, configured to receive a second query request sent by a data requester gateway for an extended query object set, where the extended query object set includes a target query object;
[0026] A second query request forwarding module, configured to send the second query request to a data service provider to query each object in the extended query object set by the data service provider;
[0027] A query result data set generation module, configured to generate a query result data set including encrypted data according to the query results corresponding to each of the queried objects;
[0028] A query result data set sending module, configured to return the query result data set to the data requester gateway, so that the data requester gateway determines a target query result for the target query object according to the query result data set by using a privacy-preserving set intersection algorithm.
[0029] A fifth aspect of the present application provides an information query system, including: a data requester gateway and a data service provider gateway connected to each other; where
[0030] The data requester gateway is configured to execute the method provided in the first aspect of the present application;
[0031] The data service provider gateway is configured to execute the method provided in the second aspect of the present application.
[0032] A sixth aspect of the present application provides an electronic device, including: a memory, a processor, and a computer program stored on the memory and executable on the processor, where the processor executes the computer program to implement the method provided in the first aspect or the second aspect of the present application.
[0033] A seventh aspect of the present application provides a computer-readable medium, on which computer-readable instructions are stored, and the computer-readable instructions can be executed by a processor to implement the method provided in the first aspect or the second aspect of the present application.
[0034] Compared with the prior art, the privacy-protected information query method provided in the first aspect of the present application is used for the data requester gateway. After receiving the first query request for the target query object, the data requester gateway does not directly forward the first query request to the data service provider, but expands the target query object to obtain an extended query object set. After generating the second query request for the extended query object set, the second query request is sent to the data service provider gateway. After receiving the query result data set containing the encrypted data returned by the data service provider gateway, the privacy-protected set intersection algorithm is used to determine the target query result for the target query object and return it to the data requester. Among them, since the data service provider gateway receives the second query request for the extended query object set, the data service provider will not know that the object actually requested by the data requester for query is the target query object, thus effectively avoiding the leakage of the privacy information of the data requester and the target query object to the data service provider. Moreover, since the data service provider gateway returns a query result data set containing encrypted data, and the data requester gateway then uses the privacy-protected set intersection algorithm to determine the target query result for the target query object, it can further avoid the leakage of the information of other objects queried by the data service provider to the data requester.
[0035] The privacy-protected information query method provided in the second aspect of the present application is implemented in cooperation with the privacy-protected information query method provided in the first aspect of the present application. Due to the same inventive concept as the privacy-protected information query method provided in the first aspect of the present application, it can at least achieve the following beneficial effects corresponding to the privacy-protected information query method provided in the first aspect of the present application: After receiving the second query request sent by the data requester gateway, the data service provider gateway first sends the second query request to the data service provider to query each object in the extended query object set through the data service provider. Then, according to the query results corresponding to each of the queried objects, a query result data set containing encrypted data is generated. Next, the query result data set is returned to the data requester gateway so that the data requester gateway can use the privacy-protected set intersection algorithm to determine the target query result for the target query object based on the query result data set. By implementing in cooperation with the privacy-protected information query method provided in the first aspect of the present application, on the one hand, it can effectively avoid the leakage of the privacy information of the data requester and the target query object to the data service provider. On the other hand, by generating a query result data set containing encrypted data and returning it to the data requester gateway, it can further avoid the leakage of the information of other objects queried by the data service provider to the data requester.
[0036] The privacy - protecting information query device provided in the third aspect of the present application and the privacy - protecting information query method provided in the first aspect of the present application are based on the same inventive concept and have the same beneficial effects as the privacy - protecting information query method provided in the first aspect of the present application.
[0037] The privacy - protecting information query device provided in the fourth aspect of the present application and the privacy - protecting information query method provided in the second aspect of the present application are based on the same inventive concept and have the same beneficial effects as the privacy - protecting information query method provided in the second aspect of the present application.
[0038] The information query system provided in the fifth aspect of the present application, the electronic device provided in the sixth aspect, and the computer - readable storage medium provided in the seventh aspect are based on the same inventive concept as the privacy - protecting information query methods provided in the first aspect and the second aspect of the present application, and have the same beneficial effects as the methods they adopt, run, or implement. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] By reading the following detailed description with reference to the accompanying drawings, the above - mentioned and other objects, features, and advantages of the exemplary embodiments of the present application will become readily understandable. In the drawings, several embodiments of the present application are shown in an exemplary rather than restrictive manner, and the same or corresponding reference numerals represent the same or corresponding parts, where:
[0040] Figure 1 Schematically shows a schematic diagram of the system architecture corresponding to a privacy - protecting information query method provided by some embodiments of the present application;
[0041] Figure 2 Schematically shows the first flowchart of a privacy - protecting information query method provided by some embodiments of the present application;
[0042] Figure 3 Schematically shows the second flowchart of a privacy - protecting information query method provided by some embodiments of the present application;
[0043] Figure 4 Schematically shows the timing diagram of a privacy - protecting information query method provided by some embodiments of the present application;
[0044] Figure 5 Schematically shows the first schematic diagram of a privacy - protecting information query device provided by some embodiments of the present application;
[0045] Figure 6 Schematically shows the second schematic diagram of a privacy - protecting information query device provided by some embodiments of the present application;
[0046] Figure 7 FIG. 1 schematically shows a schematic diagram of an electronic device provided by some embodiments of the present application;
[0047] Figure 8 FIG. 2 schematically shows a schematic diagram of a computer-readable storage medium provided by some embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0048] Exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be completely conveyed to those skilled in the art.
[0049] It should be noted that, unless otherwise specified, the technical terms or scientific terms used in the present application should have the ordinary meaning understood by those skilled in the art to which the present application belongs.
[0050] In addition, the terms "first", "second", etc. are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally further includes steps or units not listed, or optionally further includes other steps or units inherent to these processes, methods, products or devices.
[0051] Embodiments of the present application provide a method, apparatus and system for querying privacy-protected information, an electronic device, and a computer-readable storage medium, which will be described below with reference to the accompanying drawings.
[0052] For the convenience of understanding the embodiments of the present application, first, some system architectures and inventive concepts of the embodiments of the present application are briefly described as follows: Figure 1 Briefly, some system architectures and inventive concepts of the embodiments of the present application are described as follows:
[0053] Please refer to Figure 1 , which schematically shows a schematic diagram of a system architecture corresponding to a method for querying privacy-protected information provided by some embodiments of the present application. As Figure 1 shown, the system architecture may include a data requester, a data requester gateway, a data service provider gateway, and a data service provider, and the above data requester, data requester gateway, data service provider gateway, and data service provider are connected in sequence.
[0054] Among them, the data requester is the entity that requests a query. It can be implemented as a server or a server cluster. For example, it can be a server in a banking system or any server with information query requirements. In addition, the data requester can also be implemented as other hardware or software devices. For example, it can be a terminal installed in a bank (such as an ATM) or a client installed on a terminal, etc. This application does not make any limitations.
[0055] The data service provider is the entity that provides data query services for the data requester. It is generally implemented as a server or a server cluster. For example, it can be a server of a telecommunications operator, a server that can provide real-name authentication services, or any other server with data query service functions. This application does not make any limitations.
[0056] The data requester gateway is a gateway configured on the side of the data requester. It can be implemented as independent hardware or software. When implemented as software, the data requester gateway can be integrated into the data requester.
[0057] The data service provider gateway is a gateway configured on the side of the data service provider. It can be implemented as independent hardware or software. When implemented as software, the data service provider gateway can be integrated into the data service provider.
[0058] The above data requester gateway and data service provider gateway are new software and / or hardware systems added between the data requester and the data service provider, both of which play the role of an agent. They can not only ensure that the original business functions of the business system (the business system composed of the data requester and the data service provider) remain unchanged, but also add a privacy protection function to the system. The following is a more specific description.
[0059] To solve the problem of possible leakage of user privacy during information query in the prior art, based on the above system architecture, the embodiments of this application at least adopt the following technical concepts:
[0060] By expanding the query request sent by the data requester, the query request for the target query object is expanded into a query request for multiple objects, making it impossible for the data service provider to clearly know which object the data requester actually requests to query, thereby avoiding the leakage of the information of the target query object requested by the data requester to the data service provider; further, in order to avoid the leakage of user privacy caused by the feedback of the information of other objects queried by the data service provider to the data requester, the data service provider gateway generates an encrypted query result data set based on all query results and then returns it to the data requester gateway. The data requester gateway can then use the privacy-preserving set intersection algorithm to obtain the target query result for the target query object without knowing the specific content of the query result data set, thereby avoiding the leakage of user privacy caused by the feedback of the information of other objects queried by the data service provider to the data requester. Based on the above technical concept, it is possible to achieve all-round protection of the privacy data of both the data requester and the data service provider.
[0061] Based on the above technical concept, in order to at least achieve the purpose of all-round protection of the privacy data of both parties in the embodiments of the present application, based on Figure 1 the system architecture shown, an information query can go through the following exemplary steps:
[0062] S1. The data requester sends a first query request for the target query object to the data requester gateway.
[0063] S2. The data requester gateway expands the target query object, generates a second query request for the extended query object set and sends it to the data service provider gateway.
[0064] S3. The data service provider gateway sends the second query request to the data service provider to query the information of each object in the extended query object set.
[0065] S4. The data service provider returns all query results for all objects in the extended query object set.
[0066] S5. The data service provider gateway generates an encrypted query result data set based on the above all query results, the data requester gateway generates a requested query data set based on the first query request, and the data requester gateway and the data service provider gateway interact based on the privacy-preserving set intersection algorithm, and take the above query result data set and the above requested query data set as two privacy-preserving sets to find the intersection, and then the target query result for the target query object can be obtained.
[0067] S6. After the data requester gateway obtains the target query result, it returns the target query result to the data requester, and the data requester obtains the target query result, thus completing the current query process.
[0068] The following will, in conjunction with the accompanying drawings, exemplarily illustrate the privacy - protected information query method and its device provided by the present application from the perspective of the data requester gateway side and the data service provider gateway side respectively. The following exemplary description can refer to the above - mentioned Figure 1 and its corresponding above - mentioned description for understanding.
[0069] Please refer to Figure 2 , which schematically shows the first flowchart of a privacy - protected information query method provided by some embodiments of the present application. This privacy - protected information query method can be used in the data requester gateway and may include the following steps:
[0070] Step S101: Receive a first query request sent by the data requester for a target query object.
[0071] Among them, the first query request may refer to a request for querying whether the information of the target query object is correct or whether it is stored in the data service provider. The expected target query result may be "yes" or "no", or "right" or "wrong", or other yes / no results. For example, the above - mentioned first query request may be a location verification query request, which is used to query whether the target query object appears at a specified location, or to verify the legality or validity of the specified location information corresponding to the target query object; another example is that the above - mentioned first query request may be a real - name authentication query request, which is used to query whether the target query object has passed real - name authentication; and so on. The embodiments of the present application will not list them one by one. As long as it is a situation where the privacy - protected information query method provided by the embodiments of the present application can be used for querying, it should be within the protection scope of the present application.
[0072] Step S102: According to the first query request, send a second query request for an extended query object set to the data service provider gateway, where the extended query object set contains the target query object.
[0073] Considering that if the first query request is directly sent to the data service provider, the information of the target query object queried by the first query request will inevitably be leaked to the data service provider. Therefore, the purpose of this step S102 is at least to perform a fuzzification or generalization process on the first query request, generalizing the query of the target query object to a query for the extended query object set, so that the data service provider cannot accurately determine which object the data requester is actually querying, thereby realizing the protection of the privacy information of the target query object.
[0074] Specifically, in some modified embodiments, this step S102 may include:
[0075] Determine an extended query object set according to the target query object;
[0076] Generate a second query request for the extended query object set;
[0077] Send the second query request to the data service provider gateway.
[0078] In this embodiment, first, the target query object is extended to obtain an extended query object set, and then a second query request is generated for the extended query object set, so that the fuzzification processing of the first query request can be simply and quickly implemented.
[0079] Among them, the determination of the extended query object set according to the target query object may include:
[0080] Extend the identification information of the target query object to obtain an identification information set;
[0081] Determine the extended query object set according to all the objects corresponding to all the identification information in the identification information set.
[0082] It is easy to understand that, in order to identify the target query object, the first query request should carry the identification information of the target query object. In practical applications, the above identification information may include, but is not limited to, mobile phone numbers, ID card numbers, account numbers, or any other identifier that can uniquely identify the identity of the target query object. Further, when performing fuzzification processing on the target query object, it can be directly, quickly, and conveniently extended according to the identification information. For example, if the identification information of the target query object is a mobile phone number, the set of all mobile phone numbers within a range of a number segment where the mobile phone number is located can be used as the identification information set. It should be noted that all the identification information in the extended identification information set can be continuous or discrete, and both can achieve the purpose of the embodiments of the present application. The embodiments of the present application do not limit its specific content.
[0083] In addition, for the sensitive information of the target query object included in the first query request, it can be excluded when generating the second query request to prevent the data service provider from determining the identity of the target query object based on this sensitive information. Taking the first query request as a location verification query request as an example, the query parameter information included in the first query request may include the following fields {data type, time information, subject information of the target query object, specified location information}, where the data type refers to the type of data for which the query is requested, the time information is the time when the target query object to be queried appears at the specified location, the subject information is the information of the query subject object (i.e., the target query object), such as the identification information of the target query object, and the specified location information refers to the information of the location where the target query object to be queried appears corresponding to the above time information. For the sake of understanding, for example, the query parameter information included in this first query request may be {location information, 5:10 on the Xth day of the Xth month of the X year, mobile phone number 12345678900, whether at ATM-A}.
[0084] Considering that if all fields of the first query request are included in the second query request, then when the data service provider queries all objects in the extended query object set, there is a high probability of accurately determining the actual target query object of this query based on the content in the above "specified location information" field (such as the above ATM-A). Therefore, this "specified location information" belongs to sensitive information. For the sake of understanding, the definition of sensitive information in the embodiments of this application may refer to information that can be utilized by the data service provider to identify the identity of the actual requested target query object.
[0085] Correspondingly, in some alternative embodiments, the generation of the second query request for the extended query object set may include:
[0086] Perform desensitization processing on the query parameter information in the first query request;
[0087] Generate a second query request for the extended query object set according to the remaining query parameter information after desensitization processing.
[0088] Based on the above embodiments, when generating the second query request, the content in the first query request can be desensitized. This desensitization process refers to removing sensitive information and / or the sensitive information fields corresponding to the sensitive information, and generating the second query request using the remaining query parameter information after desensitization. For example, for the query parameter information {data type, time information, subject information of the target query object, specified location information} corresponding to the above first query request, after desensitization, the sensitive information field "specified location information" is removed, and the query parameter information of the generated second query request can include {data type, time information, subject set range information}, where the subject set range information is the identification information set corresponding to the extended query object set. Through the above desensitization process, the problem of privacy information leakage caused by sending sensitive information to the data service provider can be effectively avoided.
[0089] Corresponding to the foregoing first query request, the second query request can be understood to a certain extent as a request for querying sensitive information, so as to facilitate subsequent comparison of the query results containing sensitive information with the query parameter information containing sensitive information in the first query request. For example, if the first query request is a location verification query request, the second query request can be a location information query request for requesting to query the location information of each object in the extended query object set; if the first query request is a real-name authentication query request, the second query request can be a real-name authentication information query request for requesting to query the real-name authentication information of each object in the extended query object set.
[0090] Step S103: Receive the query result data set containing the encrypted data returned by the data service provider gateway, where the query result data set is determined based on the query results corresponding to each object in the extended query object set.
[0091] After receiving the above second query request, the data service provider gateway can forward the second query request to the data service provider to query the information of each object in the extended query object set through the data service provider, and obtain the query results corresponding to each object in the extended query object set. For the sake of understanding, still taking the above first query request as a location verification query request as an example, the query results corresponding to each object in the extended query object set can be {data type, time information, subject information 1, location 1}, {data type, time information, subject information 2, location 2}, {data type, time information, subject information 3, location 3}...
[0092] It should be noted that, in order to successfully determine the target query result corresponding to the target query object based on the privacy-preserving set intersection algorithm later, the query result corresponding to each of the above objects has the same field structure as the query parameter information of the target query object in the first query request, that is, the above query result has the same field structure as the query parameter information of the target query object in the first query request.
[0093] To avoid disclosing information such as the query results of other objects except the target query object to the data requester, the data service provider gateway can encrypt and process the query results corresponding to each object queried to generate a query result data set containing encrypted data, and then return it to the data requester gateway. Among them, since the query result data set is encrypted, it is possible to effectively avoid disclosing information such as the query results of other objects except the target query object to the data requester.
[0094] Step S104: Determine the target query result for the target query object according to the query result data set by using the privacy-preserving set intersection algorithm.
[0095] Since the data service provider gateway encrypts the returned query result data set and the data requester gateway cannot know the specific content in the query result data set, the embodiment of the present application uses the privacy-preserving set intersection algorithm to determine the target query result for the target query object, so that the target query result for the target query object can be obtained without knowing the specific content of the query result data set.
[0096] The privacy-preserving set intersection (PSI) algorithm is an operation that allows two parties holding their respective sets to jointly calculate the intersection of the two sets. At the end of the interactive operation, one or both parties should obtain the correct intersection and will not obtain any information in the other party's set outside the intersection. For example, two participants PA and PB respectively hold two sets SA: {1, 2, 3, 4, 5} and SB: {4, 5, 6, 7, 8}. The purpose of the PSI algorithm interactive operation is to find the intersection of the two parties' sets SA ∩ SB = {4, 5} (possibly only one party gets the result in one protocol), and ensure the privacy of the elements outside the intersection, that is, PA does not know the information of the elements in the set SB - SA ∩ SB; PB does not know the information of the elements in the set SA - SA ∩ SB.
[0097] The PSI algorithm is already a relatively mature algorithm in the current field of privacy data protection. Commonly used PSI algorithms include PSI based on Diffie-Hellman, PSI based on oblivious transfer, etc. The specific algorithm in the embodiments of the present application is not limited, and those skilled in the art can directly implement or implement after modification according to any PSI algorithm provided by the prior art.
[0098] It should be noted that for the application of some PSI algorithms, how to encode the data of the original business system (such as a business system composed of a data requestor and a data service provider), and how to control the interaction process in the PSI algorithm to dock with the original business system are also problems that need to be solved. In this regard, the embodiments of the present application exemplarily give solutions in the following description.
[0099] Specifically, in some embodiments, the determining of the target query result for the target query object by using the privacy-preserving set intersection algorithm according to the query result data set may include:
[0100] Determine a request query data set according to the first query request, wherein the elements in the request query data set are determined according to the query parameter information of the target query object;
[0101] Determine the target query result for the target query object by calculating the intersection of the request query data set and the query result data set.
[0102] The above request query data set and query result data set can be used as privacy-preserving sets, and by taking the intersection of the two sets, the target query result for the target query object can be determined.
[0103] Considering that the query result data set contains encrypted data, it can be understood by referring to the embodiments of the privacy-preserving information query method applied to the data service provider gateway. For example, each element in the query result data set is encrypted data obtained by performing data conversion and encryption processing on the query result corresponding to an object in the extended query object set.
[0104] To ensure that the intersection operation between the request query dataset and the query result dataset can be carried out smoothly and accurately, the elements in the request query dataset and the elements in the query result dataset should have correspondence. To ensure that when the data service party can query the query result corresponding to the target query object, the intersection of the request query dataset and the query result dataset is not an empty set, ensuring the accuracy of information query and avoiding misjudgment. For example, the data structure of the query parameter information of the target query object in the first query request should be consistent with the data structure of the query result, and the query parameter information should also be processed using the same data conversion algorithm, encryption algorithm, encryption key, etc. as the query result, so as to ensure that for the same information, the elements in the request query dataset obtained after being processed by the data requester gateway and the elements in the query result dataset obtained after being processed by the data service party gateway are consistent or can match each other.
[0105] For example, each element in the query result dataset is the fourth encrypted data obtained by the data service party gateway converting the query result corresponding to each of the queried objects from multi-valued data to single-valued data according to a preset data conversion algorithm and encrypting the single-valued data using a second encryption key. Correspondingly, in some embodiments, determining the request query dataset according to the first query request may include:
[0106] Determining the query parameter information corresponding to the target query object according to the first query request;
[0107] Converting the query parameter information from multi-valued data to single-valued data according to a preset data conversion algorithm;
[0108] Encrypting the single-valued data using a first encryption key to obtain first encrypted data;
[0109] Sending the first encrypted data to the data service party gateway;
[0110] Receiving the second encrypted data returned by the data service party gateway, where the second encrypted data is obtained by encrypting the first encrypted data twice using a second encryption key;
[0111] Decrypting the second encrypted data using a first decryption key to obtain third encrypted data; where the first decryption key corresponds to the first encryption key;
[0112] Generating a request query dataset with the third encrypted data as elements.
[0113] Among them, the above first decryption key corresponds to the first encryption key, which means that the encrypted information of the first encryption key can be decrypted by the first decryption key. For example, the above first decryption key and the first encryption key can be inverse to each other. In specific implementation, they can be a pair of inverse elements in a key group.
[0114] Still taking the above first query request as a location verification query request as an example, the query parameter information corresponding to the target query object is {data type, time information, main body information of the target query object, specified location information}, which belongs to multi-valued data. For the convenience of comparison, it is first converted into single-valued data. For the specific conversion algorithm, please refer to the following description. Then, it is encrypted with the first encryption key to obtain the first encrypted data. Then, the first encrypted data is sent to the data service provider gateway. The data service provider gateway performs secondary encryption on the first encrypted data with the second encryption key to obtain the second encrypted data and returns it to the data requestor gateway. The data requestor gateway then decrypts the second encrypted data with the first decryption key to obtain the third encrypted data, so that the third encrypted data becomes the data encrypted only with the second encryption key, ensuring that the third encrypted data and the fourth encrypted data are encrypted with the same encryption key, and further ensuring the accuracy of subsequent intersection calculation.
[0115] Among them, the purpose of encrypting with the first encryption key is to prevent the above query parameter information from being leaked to the data service provider gateway. The process of the data requestor gateway sending the first encrypted data, receiving the second encrypted data, and decrypting to obtain the third encrypted data is actually a process of interacting with the data service provider gateway to change the encryption key. Its purpose is to ensure that the elements in the request query dataset and the elements in the query result dataset are encrypted by the same encryption key through key exchange, and further ensure that the request query dataset and the query result dataset can perform the intersection operation smoothly and accurately.
[0116] Through the above implementation method, the interaction process in the PSI algorithm can be successfully docked with the original business system.
[0117] In addition, for different PSI algorithms, the methods of encoding the data of the original business system are also different. Those skilled in the art can flexibly change according to the principles of each PSI algorithm to implement the encoding of the above query parameter information and query results. Taking the PSI algorithm based on elliptic curves as an example, the following describes how to encode the query parameter information. In some alternative implementation methods, the above-mentioned conversion of the query parameter information from multi-valued data to single-valued data according to the preset data conversion algorithm may include:
[0118] Concatenate multiple data items in the query parameter information to obtain a first data string;
[0119] Calculate the first hash value corresponding to the first data string;
[0120] Convert the first hash value into the first point data on the elliptic curve.
[0121] Still taking the above first query request as a location verification query request as an example, the query parameter information corresponding to the target query object is {data type, time information, main body information of the target query object, specified location information}, which belongs to multi-value data. First, concatenate each data item in the above query parameter information to obtain the first data string, then use a hash function to calculate the first hash value corresponding to the first data string, and then convert this first hash value into the first point data on the elliptic curve, so as to convert the query parameter information from multi-value data to single-value data (such as the first point data).
[0122] Through the above implementation manner, the query parameter information can be encoded into single-value data. Since single-value data is more convenient for comparison, therefore, through this implementation manner, converting the query parameter information into the first point data helps to calculate the intersection of the request query data set and the query result data set more conveniently and accurately in the follow-up.
[0123] According to the intersection of the request query data set and the query result data set, the target query result can be determined. Specifically, in some alternative implementation manners, the above first query request is used to request to query whether the query parameter information of the target query object exists in the data provider;
[0124] Determining the target query result for the target query object by calculating the intersection of the request query data set and the query result data set includes:
[0125] Calculate the intersection of the request query data set and the query result data set;
[0126] If the intersection is an empty set, it is determined that the target query result for the target query object is that the query parameter information of the target query object does not exist in the data service provider;
[0127] If the intersection is a non-empty set, it is determined that the target query result for the target query object is that the query parameter information of the target query object exists in the data service provider.
[0128] Taking the above first query request as a location verification query request as an example, if the intersection is a non-empty set, it indicates that the information of the target query object appearing at the specified location at the specified time is consistent with the information recorded by the data service provider. Therefore, it can be determined that the target query result for the target query object is that there is query parameter information of the target query object in the data service provider, and the location verification result is true, indicating that the risk level of the target query object is relatively low; otherwise, if the intersection is an empty set, it indicates that the information of the target query object appearing at the specified location at the specified time is inconsistent with the information recorded by the data service provider or there is no record in the data service provider, and the location verification result is false, indicating that the risk level of the target query object is relatively high.
[0129] Another example, taking the above first query request as an identity verification query request as an example, if the intersection is a non-empty set, it indicates that the identity verification information of the target query object is consistent with the information recorded by the data service provider, indicating that the identity verification information of the target query object is true and reliable; otherwise, if the intersection is an empty set, it indicates that the identity verification information of the target query object is inconsistent with the information recorded by the data service provider or there is no record in the data service provider. Therefore, it indicates that the identity verification information of the target query object is false and unreliable.
[0130] Through the above implementation manner, the target query result for the target query object can be accurately and quickly determined according to the intersection calculation result.
[0131] Step S105: Return the target query result to the data requestor.
[0132] The above-described privacy-protecting information query method provided by the embodiments of the present application is applied to the data requester gateway. After receiving the first query request for the target query object, the data requester gateway does not directly forward the first query request to the data service provider. Instead, it expands the target query object to obtain an extended query object set, generates a second query request for the extended query object set, and then sends the second query request to the data service provider gateway. After receiving the query result data set containing the encrypted data returned by the data service provider gateway, it uses the privacy-protecting set intersection algorithm to determine the target query result for the target query object and returns it to the data requester. Among them, since the data service provider gateway receives the second query request for the extended query object set, the data service provider does not know that the object actually requested by the data requester is the target query object, thus effectively avoiding the leakage of the privacy information of the data requester and the target query object to the data service provider. Moreover, since the query result data set returned by the data service provider gateway contains encrypted data, and the data requester gateway then uses the privacy-protecting set intersection algorithm to determine the target query result for the target query object, it can further avoid the leakage of the information of other objects queried by the data service provider to the data requester.
[0133] In the above embodiment, a privacy-protecting information query method for the data requester gateway is provided, which exemplarily illustrates the privacy-protecting information query method provided by the embodiments of the present application from the perspective of the data requester gateway. Next, the privacy-protecting information query method provided by the embodiments of the present application will be further exemplarily illustrated from the perspective of the data service provider gateway. The following privacy-protecting information query method for the data service provider gateway can be implemented in cooperation with the foregoing privacy-protecting information query method for the data requester gateway. The following embodiments can be understood with reference to the embodiments of the foregoing privacy-protecting information query method for the data requester gateway, and some contents will not be repeated. Correspondingly, the embodiments of the foregoing privacy-protecting information query method for the data requester gateway can also be understood with reference to the embodiments of the following privacy-protecting information query method implemented by the cooperation of the server and the target terminal.
[0134] Please refer to Figure 3 , which schematically shows a second flowchart of a privacy-protecting information query method provided by some embodiments of the present application. The privacy-protecting information query method is used for the data service provider gateway and may include the following steps:
[0135] Step S201: Receive a second query request for an extended query object set sent by the data requester gateway, where the extended query object set includes a target query object.
[0136] This step S201 can be understood in combination with the exemplary description of step S102 in the foregoing embodiments, and will not be elaborated here.
[0137] Step S202: Send the second query request to the data service provider to query each object in the extended query object set through the data service provider.
[0138] After receiving the second query request, the data service provider gateway can forward the second query request to the data service provider to query each object in the extended query object set. After the query is completed by the data service provider, the query results for each object are returned to the data service provider gateway.
[0139] It should be noted that in order to smoothly use the private set intersection algorithm to find the intersection later, the above query results should use the same data structure as the query parameter information in the first query request. Or rather, the data service provider or the data service provider gateway generates the query results for each object in the extended query object set according to the data structure of the query parameter information in the first query request.
[0140] For example, if the data structure of the query parameter information is {data type, time information, main body information of the target query object, specified location information}, then the data structure of the query result for object A is {data type, time information, main body information of object A, location information of object A}.
[0141] Step S203: Generate a query result data set containing encrypted data based on the query results corresponding to each of the queried objects.
[0142] To avoid leaking the query results of other objects except the target query object to the data requester or the data requester gateway, the query results need to be encrypted. In some embodiments, this step S203 may include:
[0143] For the query result corresponding to each of the queried objects, convert the query result from multi-valued data to single-valued data according to a preset data conversion algorithm, and encrypt the single-valued data with a second encryption key to obtain fourth encrypted data;
[0144] Generate a query result data set based on the fourth encrypted data corresponding to each of the objects.
[0145] Please refer to the exemplary description of step S104 in the foregoing embodiments. Still taking the above first query request as a location verification query request as an example, the query parameter information corresponding to the target query object is {data type, time information, main body information of the target query object, specified location information}. The data structure of the query result for any object A in the extended query object set is {data type, time information, main body information of object A, location information of object A}, which belongs to multi-valued data. For the convenience of comparison, it is first converted into single-valued data. For the specific conversion algorithm, please refer to the following description. Then, the second encryption key is used to encrypt the single-valued data to obtain the fourth encrypted data, and this fourth encrypted data is used as an element of the query result data set to generate the query result data set.
[0146] In order to use the PSI algorithm, it is also necessary to encode the above query result. Refer to the way of encoding the query parameter information in step S104 above. In the embodiments of the present application, for the query result, the same encoding method as that of the query parameter information should be used for encoding. Taking the PSI algorithm based on elliptic curves as an example, the above conversion of the query result from multi-valued data to single-valued data according to the preset data conversion algorithm may include:
[0147] Concatenate multiple data items in the query result to obtain a second data string;
[0148] Calculate the second hash value corresponding to the second data string;
[0149] Convert the second hash value into the second point data on the elliptic curve.
[0150] Still taking the above first query request as a location verification query request as an example, the query parameter information corresponding to the target query object is {data type, time information, main body information of the target query object, specified location information}. The data structure of the query result for any object A in the extended query object set is {data type, time information, main body information of object A, location information of object A}, which belongs to multi-valued data. First, concatenate each data item in the above query result to obtain a second data string, then use a hash function to calculate the second hash value corresponding to the second data string, and then convert the second hash value into the second point data on the elliptic curve, so as to convert the query result from multi-valued data to single-valued data (such as the second point data).
[0151] Through the above implementation manner, the query result can be encoded into single-valued data. Since single-valued data is more convenient for comparison, therefore, through this implementation manner, converting the query result into the second point data helps to calculate the intersection of the requested query data set and the query result data set more conveniently and accurately in the subsequent process.
[0152] Step S204: Return the query result data set to the data requester gateway, so that the data requester gateway can use the private set intersection algorithm to determine the target query result for the target query object according to the query result data set.
[0153] It should be noted that, in order to cooperate with the data requester gateway to implement the private set intersection algorithm, refer to the description of the part of step S104 above. The data service provider gateway also needs to cooperate with the data requester gateway to complete the replacement of the encryption key of the first encrypted data. In some alternative embodiments, the method of the embodiment of the present application may further include:
[0154] Receive the first encrypted data sent by the data requester gateway;
[0155] Perform secondary encryption on the first encrypted data using the second encryption key to obtain the second encrypted data;
[0156] Send the second encrypted data to the data requester gateway, so that the data requester gateway can decrypt the second encrypted data using the first decryption key to obtain the third encrypted data encrypted only with the second encryption key.
[0157] Through the above implementation, it can cooperate with the data requester gateway to complete the replacement of the encryption key of the first encrypted data, which is convenient for the data requester gateway to smoothly implement the private set intersection algorithm.
[0158] Based on the above description, the privacy protection information query method for the data service provider gateway provided by the embodiment of the present application has the same inventive concept as the privacy protection information query method for the data requester gateway provided by the foregoing embodiment of the present application, and at least has the following corresponding beneficial effects: After receiving the second query request sent by the data requester gateway, the data service provider gateway first sends the second query request to the data service provider to query each object in the extended query object set through the data service provider, and then generates a query result data set containing encrypted data according to the query result corresponding to each queried object. Next, return the query result data set to the data requester gateway, so that the data requester gateway can use the private set intersection algorithm to determine the target query result for the target query object according to the query result data set. By cooperating with the privacy protection information query method provided in the first aspect of the present application, on the one hand, it can effectively prevent the privacy information of the data requester and the target query object from being leaked to the data service provider. On the other hand, by generating a query result data set containing encrypted data and returning it to the data requester gateway, it can further prevent the information of other objects queried by the data service provider from being leaked to the data requester.
[0159] For the convenience of understanding the above embodiments, the embodiments of the present application also provide some specific implementation manners. The following specific embodiments can be understood with reference to any of the foregoing embodiments, and any of the foregoing embodiments can also be understood with reference to the following embodiments. Some content will not be repeated.
[0160] It should be noted that in the following exemplary description, although some terms have changed, this does not affect the expression of their meanings. The following description will make a corresponding explanation of some terms and the terms in the foregoing embodiment description. The corresponding relationship expressed by this corresponding explanation can include both an equivalent relationship and a superordinate-subordinate relationship. Those skilled in the art can understand it in combination with the actual situation.
[0161] First, in some embodiments, for any specific PSI system: define the party that can obtain the intersection result as the PSI result acquirer; define the other party that provides data and participates in the operation of the PSI system protocol but does not have the set intersection information as the PSI service supporter. From the perspective of the upper-layer business system, the inputs of the PSI result acquirer and the PSI service supporter are each a set. In some embodiments of the present application, the data requestor gateway can be regarded as the PSI result acquirer, and the data service provider gateway can be regarded as the PSI service supporter.
[0162] Refer to Figure 1 In the shown system architecture, the data requestor initiates a request to the data requestor gateway regarding whether a subject (i.e., the target query object) is at a specified location at a certain time point or a request for the real-name situation of a subject ({data type, time information, subject information, specified location information or certificate information}, where the first item "data type" indicates the information type of the fourth item "specified location information or certificate information"); and receives an affirmative or negative reply from the data requestor gateway.
[0163] The data requestor gateway, according to the request of the data requestor, takes {data type, time information, subject information, specified location information or certificate information} as the input of the PSI result acquirer, interacts with the data service provider gateway, and calculates the intersection information; if there is an intersection, it replies affirmatively to the data requestor, and if there is no intersection, it replies negatively.
[0164] The data service provider has the location information data of the subject and the certificate information data of the subject, and replies the location information or certificate information of the relevant subject according to the request of the data service provider gateway.
[0165] The data service provider gateway requests and receives the corresponding subject location information or collection of document information from the data service provider according to the data (data type, time information, and subject set range information) sent by the data requester gateway; and uses this information collection as the input of the PSI service supporter to interact with the data requester gateway.
[0166] The overall goal is that the data requester can ask the data service provider whether the location of a subject is the same as the specified location or whether the document information of a subject is consistent, but the data service provider cannot obtain the identity information of the queried subject.
[0167] The steps for information query are as follows:
[0168] 1. The data requester sends query information, i.e., the first query request, to the data requester gateway, including query parameter information {data type, time information, subject information, specified location information or document information} (e.g., location information, query at 5:10, number 13423232, whether at ATM_GPS).
[0169] 2. The data requester gateway processes the query parameter information {data type, time information, subject information, specified location information} of the data requester: (1) determines the set range where the subject is located according to the subject information (e.g., the number 13423232 is within the set of the 134 number segment); (2) sends the data type, time information, and subject set range information to the data service provider gateway; (3) the data requester gateway processes the query information into a set element and uses it as the input of the PSI result acquirer to perform the corresponding interaction of the PSI system with the data service provider gateway.
[0170] 3. The data service provider gateway receives the information sent by the data requester gateway and queries the data service provider for all subject information {data type, time information, subject set range information} that meets the requirements according to the subject set range information, time information, and data type therein.
[0171] 4. The data service provider receives the request from the data service provider gateway and returns all subjects within the required subject set range in the information set that meets the requirements. Such as {{location type, time, subject 1, location 1}, {location type, time, subject 2, location 2}, {location type, time, subject 3, location 3},...}, or {{document type, subject 1, document 1}, {document type, subject 2, document 2}, {document type, subject 3, document 3},...}.
[0172] 5. After the data service provider gateway obtains the required information set, it uses this set as the input of the PSI service supporter and performs the interaction required by the PSI system with the data requester gateway.
[0173] 6. The protocol for the data requester gateway to run the PSI system obtains the result of the PSI intersection (an empty set or an existing intersection).
[0174] 7. If there is an intersection, the data requester gateway replies "yes" to the data requester; if it is an empty set, it replies "no" to the data requester.
[0175] The following uses a specific PSI scheme to illustrate the specific operations of the above-designed PSI system interaction.
[0176] In the description of the following PSI scheme, the PB party is equivalent to the data requester gateway in the above invention scheme. As the PSI result acquirer of the PSI system, it can obtain the intersection result of the PSI system operation; the PA party is equivalent to the PSI data service provider gateway in the above scheme and serves as the PSI service supporter of the PSI system.
[0177] From a business perspective, the input of the PA party is a set, and the input of the PB party is also a set (maybe only one element). The final result is that PB can obtain the intersection of the two sets, but the PA party cannot obtain any information about the elements of the PB party's set. Therefore, the PSI system can be abstracted as an existing subsystem in terms of the business of this invention scheme, and the overall framework of the invention scheme does not depend on the specific PSI implementation technology.
[0178] Taking the PSI system based on the Diffie-Hellman (DH) assumption on an elliptic curve as an example, let E be an elliptic curve system (satisfying the points of y 2 = x 3 + ax + b), given the parameters of the large prime number P, integers a and b, the order n of the elliptic curve group, and the base point G; let the m-fold point operation of a point K be m[×]K.
[0179] PA acts as the server side; PB acts as the client; execute the PSI protocol, and PB obtains the intersection of the two sets.
[0180] The DH-based PSI protocol is as follows:
[0181] For PA, PA has the set of data SA = {sa1, sa2, sa3,...}, performs a hash operation on each set element to obtain the hash values {H(sa1), H(sa2), H(sa3),...}; then converts the hash values into points on the elliptic curve respectively: uses the hash value as one coordinate value of the point, and then calculates the other coordinate; if it is unsuccessful, hash again or transform the original hash value using other rules, and the converted points are denoted as: {EP(sa1), EP(sa2), EP(sa3),...}; then randomly select a random number uniformly (Corresponding to the second encryption key), perform the ra - fold point operation (i.e., encryption) on the points of the elliptic curve formed by each set element, and obtain the privacy - protected set {ra[×]EP(sa1), ra[×]EP(sa2), ra[×]EP(sa3),...}.
[0182] For PB, PB has the set data SB = {sb1, sb2, sb3,...}. Take the hash value of each set element through hash operation to obtain {H(sb1), H(sb2), H(sb3),...}; then convert the hash values into points on the elliptic curve respectively, and the converted points are denoted as: {EP(sb1), EP(sb2), EP(sb3),...}; then randomly and uniformly select a random number (Corresponding to the first encryption key), perform the rb - fold point operation (i.e., encryption) on the points of the elliptic curve formed by each set element, and obtain the privacy - protected set {rb[×]EP(sb1), rb[×]EP(sb2), rb[×]EP(sb3),...}.
[0183] The above process is the data blinding or encryption process. Each party processes the data separately without involving an interaction process. In the actual protocol design, it can be adjusted according to the application as long as it is processed before sending to the other party.
[0184] Next, PB, as the client, initiates a service request and sends the data MSG1: {rb[×]EP(sb1), rb[×]EP(sb2), rb[×]EP(sb3),...} to PA; if the SB data is arranged in a certain order, it is randomly permuted before sending; establish an index between the original data SB = {sb1, sb2, sb3,...} and the randomly - permuted blinded elements {rb[×]EP(sb1), rb[×]EP(sb2), rb[×]EP(sb3),...}.
[0185] After receiving PB's data MSG1, PA performs the ra - fold point operation on each data to obtain MSG2: {ra[×]rb[×]EP(sb1), ra[×]rb[×]EP(sb2), ra[×]rb[×]EP(sb3),...}; and sends the above data in the original order to PB.
[0186] After receiving MSG2: {ra[×]rb[×]EP(sb1), ra[×]rb[×]EP(sb2), ra[×]rb[×]EP(sb3),...}, PB uses the inverse element rb -1 (that is, rb×rb -1 ≡1 mod n), perform the point - fold operation on each of the above - mentioned data again to obtain RESULT1: {rb -1[×]ra[×]rb[×]EP(sb1),rb -1 [×]ra[×]rb[×]EP(sb2),rb -1 [×]ra[×]rb[×]EP(sb3),…}, that is, {ra[×]EP(sb1), ra[×]EP(sb2), ra[×]EP(sb3),…}; and establish an index between the original data SB = {sb1, sb2, sb3, …} and RESULT1; sort RESULT1.
[0187] PA sends its own data MSG3: {ra[×]EP(sa1), ra[×]EP(sa2), ra[×]EP(sa3),…} to PB; if the SA data is arranged in a certain order, it is randomly permuted before sending.
[0188] After receiving MSG3 sent by PA, PB sorts MSG3.
[0189] PB compares each element in RESULT1 with each element in MSG3; if there is an equal situation, it means that the index value sb corresponding to this element also exists in the set SA of PA; that is, to find the intersection of the two blinded sets, so PB can obtain the original intersection of both parties.
[0190] Please refer to Figure 4 , which schematically shows a timing diagram of a privacy-protected information query method provided by some embodiments of the present application, as Figure 4 shown, the privacy-protected information query method may include the following content:
[0191] Step S301: The data requester sends a first query request to the data requester gateway. For example, if the first query request is a location verification query request, the query parameter information sent for the verification service of location verification includes M1 = {location type, specified time point 1, mobile phone number 1, specified ATM location coordinates 1}; if the first query request is a real-name authentication query request, the query parameter information sent for the verification service of real-name system includes M1 = {document type, mobile phone number 1, document number 1}.
[0192] Step S302: After receiving M1, taking the first query request as a location verification query request as an example, the data requester gateway performs the following operations:
[0193] (1) Determine the set range where the subject is located according to the mobile phone number 1 in the M1 message (i.e., the identification information of the target query object), such as all mobile phone numbers in the 134 number segment.
[0194] (2) Send a second query request to the data service provider gateway, where the second query request includes query parameter information M2 = {location type, specified time point 1, all mobile phone numbers in the 134 number segment}.
[0195] (3) The data requester gateway, as the PSI result acquirer of the PSI system, processes M1 as follows:
[0196] (3.1) Concatenate each item in M1 and calculate the output first hash value H(M1) = H(location type|specified time point 1|mobile phone number 1|specified ATM location coordinates 1) through a hash function.
[0197] (3.2) Convert the first hash value H(M1) into a point EP(M1) on the elliptic curve.
[0198] (3.3) Use the first encryption key rb of the data requester gateway to encrypt or blind EP(M1) to obtain the first encrypted data M3 = rb[×]EP(M1), and send the first encrypted data M3 to the data service provider gateway.
[0199] Similarly, the above operations are the same for the real-name verification service processing, except that the contents of M1 are different.
[0200] Step S303: After receiving the information M2 sent by the data requester gateway, the data service provider gateway queries all subject information that meets the requirements from the data service provider according to the subject's set range information, time information, and data type in it, that is, forwards M2 to the data service provider.
[0201] Step S304: After receiving the request from the data service provider gateway, the data service provider returns the mobile phone number information that meets the requirements according to the contents of each item in M2. This information consists of the subject and the corresponding location information or ID number information, and forms a set M4 = {{location type, specified time point 1, subject 1, location 1}, {location type, specified time point 1, subject 2, location 2}, {location type, specified time point 1, subject 3, location 3},...}, or for the real-name verification service M4 = {{document type, subject 1, document 1}, {document type, subject 2, document 2}, {document type, subject 3, document 3},...}, and sends M4 to the data service provider gateway.
[0202] Step S305: After receiving the required information set M4, the data service provider gateway uses this set as the input of the PSI service supporter:
[0203] (1) Concatenate each item of each element in the set M4 (the query results corresponding to all objects) and calculate the second hash value through a hash function, H(M4_1) = H(location type|specified time point 1|subject 1|location 1), H(M4_2) = H(location type|specified time point 1|subject 2|location 2), H(M4_3) = H(location type|specified time point 1|subject 3|location 3),...
[0204] (2) Convert each second hash value into a point on the elliptic curve, namely the second point data EP(M4_1), EP(M4_2), EP(M4_3),...
[0205] (3) Encrypt each point using the second encryption key ra of the data requester gateway to obtain the fourth encrypted data ra[×]EP(M4_1), ra[×]EP(M4_2), ra[×]EP(M4_3),...;
[0206] (4) Compose all the encrypted elements into a set M5 = {ra[×]EP(M4_1), ra[×]EP(M4_2), ra[×]EP(M4_3),...} and send it to the data requester gateway. This set M5 is the query result data set.
[0207] Step S306: After receiving the first encrypted data M3 = rb[×]EP(M1) sent by the data requester gateway, the data service provider gateway re-encrypts M3 using its second encryption key ra (i.e., double encryption) to obtain the second encrypted data M6 = ra[×]rb[×]EP(M1), and sends M6 to the data requester gateway.
[0208] Step S307: The data requester gateway runs the protocol of the PSI system to obtain the result of the PSI intersection (an empty set or an existing intersection):
[0209] (1) After receiving M6, the data requester gateway uses the inverse of its first encryption key rb, namely the first decryption key rb -1 to decrypt the second encrypted data M6 to obtain the third encrypted data M7 = rb -1 [×]ra[×]rb[×]EP(M1) = ra[×]EP(M1);
[0210] (2) Compare M7 with each element in the set M5. If there is an equal situation, it means there is an intersection in the PSI system operation result. If not, the intersection is an empty set.
[0211] Step S308: If there is an intersection, the data requester gateway replies "yes" to the data requester; if it is an empty set, it replies "no" to the data requester.
[0212] In the above embodiments, a privacy - protected information query method applied to a data requester gateway is provided. Correspondingly, the present application also provides a privacy - protected information query device applied to a data requester gateway. The privacy - protected information query device applied to a data requester gateway provided by the embodiments of the present application can implement the above - mentioned privacy - protected information query method applied to a data requester gateway, and the privacy - protected information query device applied to a data requester gateway can be implemented in a software, hardware, or a combination of software and hardware manner. For example, the privacy - protected information query device applied to a data requester gateway can include integrated or separate functional modules or units to execute the corresponding steps in the above - mentioned various methods. Please refer to Figure 5 , which schematically shows a first schematic diagram of a privacy - protected information query device provided by some embodiments of the present application. Since the device embodiments are basically similar to the method embodiments, the description is relatively simple, and for the relevant parts, refer to the partial description of the method embodiments. The device embodiments described below are only illustrative.
[0213] As Figure 5 shown, a privacy - protected information query device 10 applied to a data requester gateway may include:
[0214] A first query request receiving module 101, configured to receive a first query request for a target query object sent by a data requester;
[0215] A second query request sending module 102, configured to send a second query request for an extended query object set to a data service provider gateway according to the first query request, where the extended query object set includes the target query object;
[0216] A query result data set receiving module 103, configured to receive a query result data set including encrypted data returned by the data service provider gateway, where the query result data set is determined based on query results corresponding to each object in the extended query object set;
[0217] A target query result determining module 104, configured to determine a target query result for the target query object by using a privacy - protected set intersection algorithm according to the query result data set;
[0218] A target query result sending module 105, configured to return the target query result to the data requester.
[0219] In some modified embodiments of the embodiments of the present application, the second query request sending module 102 includes:
[0220] An extended query object set determination unit, configured to determine an extended query object set according to the target query object;
[0221] A second query request generation unit, configured to generate a second query request for the extended query object set;
[0222] A second query request sending unit, configured to send the second query request to the data service provider gateway.
[0223] In some alternative embodiments of the present application, the extended query object set determination unit includes:
[0224] An identification information extension subunit, configured to extend the identification information of the target query object to obtain an identification information set;
[0225] An extended query object set determination subunit, configured to determine an extended query object set according to all objects corresponding to all identification information in the identification information set.
[0226] In some alternative embodiments of the present application, the second query request generation unit includes:
[0227] A desensitization processing subunit, configured to perform desensitization processing on the query parameter information in the first query request;
[0228] A second query request generation subunit, configured to generate a second query request for the extended query object set according to the remaining query parameter information after desensitization processing.
[0229] In some alternative embodiments of the present application, the target query result determination module 104 includes:
[0230] A request query data set determination unit, configured to determine a request query data set according to the first query request, where elements in the request query data set are determined according to the query parameter information of the target query object;
[0231] An intersection calculation unit, configured to determine a target query result for the target query object by calculating the intersection of the request query data set and the query result data set.
[0232] In some alternative embodiments of the present application, the request query data set determination unit includes:
[0233] A query parameter information determination subunit, configured to determine the query parameter information corresponding to the target query object according to the first query request;
[0234] A data conversion subunit, configured to convert the query parameter information from multi-valued data to single-valued data according to a preset data conversion algorithm;
[0235] The first encrypted data generation subunit is configured to encrypt the single-valued data with a first encryption key to obtain first encrypted data;
[0236] The first encrypted data sending subunit is configured to send the first encrypted data to the data service provider gateway;
[0237] The second encrypted data receiving subunit is configured to receive second encrypted data returned by the data service provider gateway, where the second encrypted data is obtained by performing secondary encryption on the first encrypted data with a second encryption key;
[0238] The second encrypted data decryption subunit is configured to decrypt the second encrypted data with a first decryption key to obtain third encrypted data; where the first decryption key corresponds to the first encryption key;
[0239] The request query data set generation subunit is configured to generate a request query data set with the third encrypted data as an element.
[0240] In some alternative embodiments of the embodiments of the present application, the data conversion subunit includes:
[0241] The first data concatenation subunit is configured to concatenate multiple data items in the query parameter information to obtain a first data string;
[0242] The first hash calculation subunit is configured to calculate a first hash value corresponding to the first data string;
[0243] The first elliptic data conversion subunit is configured to convert the first hash value into first point data on an elliptic curve.
[0244] In some alternative embodiments of the embodiments of the present application, the first query request is used to request to query whether the query parameter information of the target query object exists in the data provider;
[0245] The intersection calculation unit includes:
[0246] The intersection calculation subunit is configured to calculate the intersection of the request query data set and the query result data set;
[0247] The empty set processing subunit is configured to, if the intersection is an empty set, determine that the target query result for the target query object is that the query parameter information of the target query object does not exist in the data service provider;
[0248] A non-empty set processing subunit, configured to, if the intersection is a non-empty set, determine that the target query result for the target query object is the query parameter information indicating the existence of the target query object at the data service side.
[0249] In some modified embodiments of the embodiments of the present application, the first query request includes: a location verification query request or a real-name authentication query request; where
[0250] The location verification query request is used to request to query whether the target query object appears at a specified location;
[0251] The real-name authentication query request is used to request to query whether the target query object has passed real-name authentication.
[0252] The privacy-protecting information query device 10 for the data requester gateway provided by the embodiments of the present application has the same inventive concept and the same beneficial effects as the privacy-protecting information query method for the data requester gateway provided by the foregoing embodiments of the present application.
[0253] In addition, corresponding to the privacy-protecting information query method for the data service side gateway provided in the above embodiments, the present application further provides a privacy-protecting information query device for the data service side gateway. The privacy-protecting information query device provided by the embodiments of the present application can implement the privacy-protecting information query method for the data service side gateway, and the privacy-protecting information query device for the data service side gateway can be implemented in a software, hardware, or a combination of software and hardware manner. For example, the privacy-protecting information query device for the data service side gateway can include integrated or separate functional modules or units to execute the corresponding steps in the above methods. Please refer to Figure 6 , which shows a second schematic diagram of a privacy-protecting information query device provided by some embodiments of the present application. Since the device embodiments are basically similar to the method embodiments, the description is relatively simple, and for the related parts, please refer to the partial description of the method embodiments. The device embodiments described below are only illustrative.
[0254] As Figure 6 shown, the privacy-protecting information query device 20 for the data requester gateway may include:
[0255] A second query request receiving module 201, configured to receive a second query request sent by the data requester gateway for an extended query object set, where the extended query object set includes a target query object;
[0256] The second query request forwarding module 202 is configured to send the second query request to the data service provider, so as to query each object in the extended query object set through the data service provider;
[0257] The query result data set generation module 203 is configured to generate a query result data set including encrypted data according to the query results corresponding to each of the queried objects;
[0258] The query result data set sending module 204 is configured to return the query result data set to the data requester gateway, so that the data requester gateway determines the target query result for the target query object according to the query result data set by using the privacy-preserving set intersection algorithm.
[0259] In some alternative embodiments of the present application, the query result data set generation module 203 includes:
[0260] The single-value data conversion unit is configured to convert the query result corresponding to each of the queried objects from multi-value data to single-value data according to a preset data conversion algorithm, and encrypt the single-value data with a second encryption key to obtain fourth encrypted data;
[0261] The query result data set generation unit is configured to generate a query result data set according to the fourth encrypted data corresponding to each object.
[0262] In some alternative embodiments of the present application, the single-value data conversion unit includes:
[0263] The second data concatenation subunit is configured to concatenate multiple data items in the query result to obtain a second data string;
[0264] The second hash calculation subunit is configured to calculate a second hash value corresponding to the second data string;
[0265] The second elliptic data conversion subunit is configured to convert the second hash value into second point data on an elliptic curve.
[0266] In some alternative embodiments of the present application, the apparatus 20 further includes:
[0267] The first encrypted data receiving module is configured to receive the first encrypted data sent by the data requester gateway;
[0268] The secondary encryption module is configured to perform secondary encryption on the first encrypted data with a second encryption key to obtain second encrypted data;
[0269] The second encrypted data sending module is configured to send the second encrypted data to the data requester gateway, so that the data requester gateway decrypts the second encrypted data using the first decryption key to obtain the third encrypted data encrypted only by the second encryption key.
[0270] The privacy - protected information query device 20 for the data service provider gateway provided by the embodiments of the present application has the same inventive concept and the same beneficial effects as the privacy - protected information query method for the data service provider gateway provided by the foregoing embodiments of the present application.
[0271] The embodiments of the present application also provide an information query system corresponding to the privacy - protected information query method provided in the foregoing embodiments. This information query system can be understood with reference to Figure 1 the schematic diagram of the system architecture shown, as Figure 1 shown, this information query system may include: a data requester gateway and a data service provider gateway that are interconnected; wherein,
[0272] The above - mentioned data requester gateway is configured to execute the privacy - protected information query method for the data requester gateway provided in any of the foregoing embodiments;
[0273] The above - mentioned data service provider gateway is configured to execute the privacy - protected information query method for the data service provider gateway provided in any of the foregoing embodiments.
[0274] The information query system provided by the embodiments of the present application has the same inventive concept as the privacy - protected information query methods for the data service provider gateway and the data requester gateway provided in the foregoing embodiments. For specific content, please refer to the embodiment descriptions of the privacy - protected information query method for the data requester gateway and the embodiment descriptions of the privacy - protected information query method for the data service provider gateway for understanding, which will not be elaborated here. This information query system has the same beneficial effects as the methods it adopts, runs, or implements.
[0275] The embodiments of the present application also provide an electronic device corresponding to any of the privacy - protected information query methods provided in the foregoing embodiments. The electronic device can be any electronic device with data operation and network transmission functions to execute the above - mentioned privacy - protected information query method for the data service provider gateway or the privacy - protected information query method for the data requester gateway.
[0276] Please refer to Figure 7 which shows a schematic diagram of an electronic device provided by some embodiments of the present application. As Figure 7As shown, the electronic device 30 may include: a processor 300, a memory 301, a bus 302, and a communication interface 303. The processor 300, the communication interface 303, and the memory 301 are connected through the bus 302. A computer program that can run on the processor 300 is stored in the memory 301. When the processor 300 runs the computer program, it executes the privacy-protecting information query method provided in any of the foregoing embodiments of the present application.
[0277] Among them, the memory 301 may include a high-speed random access memory (Random Access Memory, RAM), and may also include a non-volatile memory, such as at least one disk memory. Through at least one communication interface 303 (which can be wired or wireless), a communication connection is established between this system network element and at least one other network element, and the Internet, wide area network, local area network, metropolitan area network, etc. can be used.
[0278] The bus 302 may be an ISA bus, a PCI bus, an EISA bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. Among them, the memory 301 is used to store a program. After receiving an execution instruction, the processor 300 executes the program. The privacy-protecting information query method disclosed in any of the foregoing embodiments of the present application can be applied to the processor 300 or implemented by the processor 300.
[0279] The processor 300 may be an integrated circuit chip with the ability to process signals. In the implementation process, each step of the above method may be completed by the integrated logic circuit of the hardware in the processor 300 or the instructions in the form of software. The above-mentioned processor 300 may be a general-purpose processor, which may include a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application may be directly embodied as being executed and completed by a hardware decoding processor, or executed and completed by a combination of hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory 301, and the processor 300 reads the information in the memory 301 and combines its hardware to complete the steps of the above method.
[0280] The electronic device provided by the embodiments of the present application and the privacy protection information query method provided by the embodiments of the present application are based on the same inventive concept and have the same beneficial effects as the methods adopted, run or implemented by it.
[0281] The embodiments of the present application also provide a computer-readable medium corresponding to the privacy protection information query method provided by the foregoing embodiments. Please refer to Figure 8 , which shows that the computer-readable storage medium is an optical disc 40, on which a computer program (i.e., a program product) is stored. When the computer program is run by a processor, it will execute the privacy protection information query method provided by any of the foregoing embodiments.
[0282] It should be noted that examples of the computer-readable storage medium may also include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other optical and magnetic storage media, which will not be elaborated here one by one.
[0283] The computer-readable storage medium provided by the above embodiments of the present application and the method for querying information while protecting privacy provided by the embodiments of the present application are based on the same inventive concept and have the same beneficial effects as the methods adopted, run, or implemented by the application programs stored therein.
[0284] It should be noted that the flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to multiple embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the part of the module, program segment, or code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combination of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system for performing the specified functions or actions, or may be implemented by a combination of dedicated hardware and computer instructions.
[0285] Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0286] In several embodiments provided by the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For another example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the couplings, direct couplings, or communication connections shown or discussed with each other may be through some communication interfaces. The indirect couplings or communication connections of the devices or units may be electrical, mechanical, or other forms.
[0287] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0288] In addition, in each embodiment of the present application, each functional unit may be integrated into one processing unit, may exist physically alone for each unit, or two or more units may be integrated into one unit.
[0289] If the above functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and may include several instructions to enable a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium may include: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs.
[0290] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some or all of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of each embodiment of the present application, and they should all be covered within the scope of the claims and the description of the present application.
Claims
1. A privacy-protecting information query method, characterized in that, For a data requester gateway, including: Receiving a first query request sent by a data requester for a target query object; According to the first query request, sending a second query request for an extended query object set to a data service provider gateway, where the extended query object set includes the target query object; Receiving a query result data set containing encrypted data returned by the data service provider gateway, the query result data set being determined based on the query results corresponding to each object in the extended query object set; According to the query result data set, using a privacy-preserving set intersection algorithm to determine a target query result for the target query object; Returning the target query result to the data requester; The using a privacy-preserving set intersection algorithm to determine a target query result for the target query object according to the query result data set includes: Determining a request query data set according to the first query request, where the elements in the request query data set are determined according to the query parameter information of the target query object; The determining a request query data set according to the first query request includes: Determining the query parameter information corresponding to the target query object according to the first query request; Converting the query parameter information from multi-valued data to single-valued data according to a preset data conversion algorithm; Encrypting the single-valued data with a first encryption key to obtain first encrypted data; Sending the first encrypted data to the data service provider gateway; Receiving second encrypted data returned by the data service provider gateway, where the second encrypted data is obtained by secondarily encrypting the first encrypted data with a second encryption key; Decrypting the second encrypted data with a first decryption key to obtain third encrypted data; where the first decryption key corresponds to the first encryption key; Generating a request query data set with the third encrypted data as an element.
2. The method according to claim 1, wherein The sending a second query request for an extended query object set to a data service provider gateway according to the first query request includes: Determining an extended query object set according to the target query object; Generating a second query request for the extended query object set; Sending the second query request to the data service provider gateway.
3. The method according to claim 2, wherein The determining an extended query object set according to the target query object includes: Expanding the identification information of the target query object to obtain an identification information set; Determining an extended query object set according to all objects corresponding to all identification information in the identification information set.
4. The method according to claim 2, characterized in that, The generating a second query request for the extended query object set includes: Performing desensitization processing on the query parameter information in the first query request; Generating a second query request for the extended query object set according to the remaining query parameter information after desensitization processing.
5. The method according to claim 1, wherein The using a privacy-preserving set intersection algorithm to determine a target query result for the target query object according to the query result data set includes: determining a target query result for the target query object by calculating the intersection of the request query data set and the query result data set.
6. The method according to claim 1, wherein According to the preset data conversion algorithm, converting the query parameter information from multi-valued data to single-valued data includes: Concatenating multiple data items in the query parameter information to obtain a first data string; Calculating a first hash value corresponding to the first data string; Converting the first hash value into first point data on an elliptic curve.
7. The method according to claim 5, wherein The first query request is used to request to query whether the query parameter information of the target query object exists in the data provider; Determining the target query result for the target query object by calculating the intersection of the requested query data set and the query result data set includes: Calculating the intersection of the requested query data set and the query result data set; If the intersection is an empty set, determining that the target query result for the target query object is that the query parameter information of the target query object does not exist in the data service provider; If the intersection is a non-empty set, determining that the target query result for the target query object is that the query parameter information of the target query object exists in the data service provider.
8. The method according to any one of claims 1 to 7, characterized in that, The first query request includes: a location verification query request or a real-name authentication query request; where The location verification query request is used to request to query whether the target query object appears at a specified location; The real-name authentication query request is used to request to query whether the target query object has passed real-name authentication.
9. A method for querying information while protecting privacy, characterized in that, For the data service provider gateway, it includes: Receiving a second query request sent by the data requestor gateway for an extended query object set, where the extended query object set includes a target query object; Sending the second query request to the data service provider to query each object in the extended query object set through the data service provider; Generating a query result data set containing encrypted data according to the query results corresponding to each of the queried objects; Returning the query result data set to the data requestor gateway so that the data requestor gateway can determine the target query result for the target query object according to the query result data set using the private set intersection algorithm; The method further includes: Receiving the first encrypted data sent by the data requestor gateway; Performing secondary encryption on the first encrypted data using a second encryption key to obtain second encrypted data; Sending the second encrypted data to the data requestor gateway so that the data requestor gateway decrypts the second encrypted data using a first decryption key to obtain third encrypted data encrypted only with the second encryption key.
10. The method according to claim 9, characterized in that, Generating a query result data set containing encrypted data according to the query results corresponding to each of the queried objects includes: For the query result corresponding to each of the queried objects, converting the query result from multi-valued data to single-valued data according to a preset data conversion algorithm, and encrypting the single-valued data using a second encryption key to obtain fourth encrypted data; Generating a query result data set according to the fourth encrypted data corresponding to each object.
11. The method according to claim 10, wherein Converting the query result from multi-valued data to single-valued data according to a preset data conversion algorithm includes: Concatenate multiple data items in the query result to obtain a second data string; Calculate the second hash value corresponding to the second data string; Convert the second hash value into the second point data on the elliptic curve.
12. An information query device for protecting privacy, characterized in that, For the data requester gateway, it includes: The first query request receiving module is used to receive the first query request sent by the data requester for the target query object; The second query request sending module is used to send a second query request for the extended query object set to the data service provider gateway according to the first query request, where the extended query object set contains the target query object; The query result data set receiving module is used to receive the query result data set containing the encrypted data returned by the data service provider gateway, and the query result data set is determined based on the query results corresponding to each object in the extended query object set; The target query result determining module is used to determine the target query result for the target query object by using the privacy-preserving set intersection algorithm according to the query result data set; The target query result sending module is used to return the target query result to the data requester; The target query result determining module includes: Determine the request query data set according to the first query request, where the elements in the request query data set are determined according to the query parameter information of the target query object; The determining the request query data set according to the first query request includes: Determine the query parameter information corresponding to the target query object according to the first query request; Convert the query parameter information from multi-value data to single-value data according to a preset data conversion algorithm; Encrypt the single-value data with the first encryption key to obtain the first encrypted data; Send the first encrypted data to the data service provider gateway; Receive the second encrypted data returned by the data service provider gateway, where the second encrypted data is obtained by encrypting the first encrypted data twice with the second encryption key; Decrypt the second encrypted data with the first decryption key to obtain the third encrypted data; where the first decryption key corresponds to the first encryption key; Generate a request query data set with the third encrypted data as an element.
13. An information query device for protecting privacy, characterized in that, For the data service provider gateway, it includes: The second query request receiving module is used to receive the second query request sent by the data requester gateway for the extended query object set, where the extended query object set includes the target query object; The second query request forwarding module is used to send the second query request to the data service provider to query each object in the extended query object set through the data service provider; The query result data set generating module is used to generate a query result data set containing the encrypted data according to the query results corresponding to each queried object; The query result data set sending module is used to return the query result data set to the data requester gateway, so that the data requester gateway determines the target query result for the target query object by using the privacy-preserving set intersection algorithm according to the query result data set; The device further includes: Receiving first encrypted data sent by the data requester gateway; Performing secondary encryption on the first encrypted data using a second encryption key to obtain second encrypted data; Sending the second encrypted data to the data requester gateway, so that the data requester gateway decrypts the second encrypted data using a first decryption key to obtain third encrypted data encrypted only with the second encryption key.
14. An information query system, characterized in that, It includes: A data requester gateway and a data service provider gateway that are interconnected; wherein, The data requester gateway is used to execute the method according to any one of claims 1 to 8; The data service provider gateway is used to execute the method according to any one of claims 9 to 11.
15. An electronic device, comprising: A memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor runs the computer program, it is executed to implement the method according to any one of claims 1 to 11.
16. A computer-readable medium, characterized in that, Computer-readable instructions are stored thereon, and the computer-readable instructions can be executed by a processor to implement the method according to any one of claims 1 to 11.
Citation Information
Patent Citations
DNS (domain name server) query method and device
CN106357839A
Business data query method, device and system, storage medium and electronic equipment
CN107239536A