A stealth query method, device and medium

By generating private key signature and encryption algorithms by the data owner, an anonymous query method that does not rely on third parties is implemented, the problem of high data leakage risk in traditional methods is solved, and secure data interaction is achieved.

CN114139204BActive Publication Date: 2025-07-22HANGZHOU DBAPPSECURITY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111470144.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-03
Publication Date
2025-07-22
Estimated Expiration
2041-12-03

AI Technical Summary

Technical Problem

Existing anonymous query methods rely on trusted third parties to generate keys or interact with each other. There is a risk that data security depends on third parties, resulting in high possibility of data leakage.

Method used

The data owner generates the private key signature query characteristics by itself and generates the public key through the encryption algorithm. The query party obtains the target data through the private key signature and deblind process to avoid third parties' participation.

Benefits of technology

Reduce the risk of data leakage, realize secure data interaction without relying on third parties, and protect the privacy of queryers and data owners.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114139204B_ABST
    Figure CN114139204B_ABST
Patent Text Reader

Abstract

The present application discloses a stealth query method, which relates to the field of data interaction. In the case where the attribute data does not leave the database of the data owner, the target query feature signature received by the query party is obtained by encrypting the query feature with the private key generated by the data owner himself. The data query party signs the target blinded query feature sent by the query party. The query party can decrypt the target attribute data through the target query feature signature to obtain the target attribute data. Therefore, the stealth query method provided by the present application does not rely on a third party to generate keys or conduct interactions, reducing the risk of data leakage. The present application also provides a stealth query device and a computer-readable storage medium, which correspond to the above method and have the same effect.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data interaction, and particularly to a method, apparatus, and medium for anonymous query. Background Art

[0002] With the rapid development of big data and artificial intelligence in recent years, the increasingly strict protection of user data privacy and security management will become a global trend. When enterprises conduct data query and interaction, the data owner provides data to the query party for query. How to protect privacy during the entire query process, so that the data owner cannot know the query target of the query party, but can successfully return the query result to the query party, and the query party cannot obtain data content other than the data it queries, is a key pain point and problem in the industry that needs to be solved.

[0003] Traditional anonymous query mainly uses oblivious transfer technology to achieve. The data owner sends multiple pieces of information each time, and the query party inputs a selection each time. When the protocol ends, the data owner cannot obtain any valuable information about the query party, and the query party can only obtain the data of B and knows nothing about other data. Thus, the privacy of the query party is protected, and at the same time, the correctness of the data transmission process is ensured. Traditional anonymous query often relies on a trusted third party to generate keys or conduct interactions. The data security of this method largely depends on the security of the third party, and there is a certain risk of data leakage.

[0004] Therefore, providing an anonymous query method that does not rely on a third party is a technical problem that needs to be solved urgently by those skilled in the art. Summary of the Invention

[0005] The purpose of this application is to provide a method, apparatus, and medium for anonymous query that do not rely on a third party.

[0006] To solve the above technical problems, this application provides an anonymous query method applied to a data owner, including:

[0007] Sign the query feature with a private key to obtain a query feature signature, hash the query feature signature to obtain a hashed query feature and disclose it to the query party, generate a public key based on an encryption algorithm and the private key, and disclose the public key to the query party;

[0008] Receive the target blinded query feature sent by the query party;

[0009] Sign the target blinded query feature with the private key to obtain a target blinded query feature signature;

[0010] Send the target blinded query feature signature to the querying party, so that the querying party can obtain the target query feature signature by deblinding the target blinded query feature signature;

[0011] Receive the hash query feature set sent by the querying party and send the encrypted attribute data set corresponding to the hash query feature set to the querying party, so that the querying party can decrypt the target encrypted attribute data corresponding to the target query feature in the encrypted attribute data set through the target query feature signature to obtain the target attribute data.

[0012] Preferably, in the above-mentioned traceable query method, the steps of generating the encrypted attribute data set are as follows:

[0013] Encrypt the attribute data in the database through the corresponding query feature signature in combination with the encryption rule to obtain the encrypted attribute data, and store it in the database;

[0014] Obtain the encrypted attribute data corresponding to the hash query feature set to generate the encrypted attribute data set.

[0015] Preferably, in the above-mentioned traceable query method, the encryption algorithm is the ECC encryption algorithm.

[0016] The present application also provides a traceable query method, which is applied to the querying party and includes:

[0017] Send the target blinded query feature to the data owner;

[0018] Receive the target blinded query feature signature sent by the data owner, where the target blinded query feature signature is obtained by the data owner signing the target blinded query feature with the private key;

[0019] Obtain the public key generated by the data owner based on the encryption algorithm and the private key, and deblind the blinded query feature signature to obtain the target query feature signature;

[0020] Send the hash query feature set to the data owner, where the hash query feature set includes: a preset number of hash query features publicly signed and hashed by the data owner with the private key and the target hash query feature corresponding to the target query feature signature;

[0021] Receive the encrypted attribute data set corresponding to the hash query feature set sent by the data owner;

[0022] Decrypt the target encrypted attribute data corresponding to the target query feature in the encrypted attribute data set through the target query feature signature to obtain the target attribute data.

[0023] Preferably, in the above-mentioned stealth query method, generating the target blinded query feature includes the following steps:

[0024] Blind the target query feature according to a random factor in combination with the encryption algorithm to obtain the target blinded query feature.

[0025] Preferably, in the above-mentioned stealth query method, the de-blinding of the blinded query feature signature to obtain the target query feature signature includes:

[0026] De-blind the blinded query feature signature according to the random factor and the public key to obtain the target query feature signature.

[0027] The present application also provides a stealth query device, which is applied to the data owner and includes:

[0028] A disclosure module, configured to sign the query feature with a private key to obtain a query feature signature, hash the query feature signature to obtain a hashed query feature and disclose it to the query party, generate a public key based on the encryption algorithm and the private key, and disclose the public key to the query party;

[0029] A receiving feature module, configured to receive the target blinded query feature sent by the query party;

[0030] A signature module, configured to sign the target blinded query feature with the private key to obtain a target blinded query feature signature;

[0031] A sending signature module, configured to send the target blinded query feature signature to the query party, so that the query party can de-blind the target blinded query feature signature to obtain the target query feature signature;

[0032] A receiving and sending module, configured to receive the hashed query feature set sent by the query party and send the encrypted attribute data set corresponding to the hashed query feature set to the query party, so that the query party can decrypt the target encrypted attribute data corresponding to the target query feature in the encrypted attribute data set through the target query feature signature to obtain the target attribute data.

[0033] The present application also provides a stealth query device, which is applied to the query party and includes:

[0034] A sending feature module, configured to send a target blinded query feature to the data owner;

[0035] A receiving signature module, configured to receive the target blinded query feature signature sent by the data owner, where the target blinded query feature signature is obtained by the data owner signing the target blinded query feature with a private key;

[0036] The de - blinding module is used to obtain the public key generated by the data owner based on the encryption algorithm and the private key, de - blind the blinded query feature signature, and obtain the target query feature signature;

[0037] The sending set module is used to send a hash query feature set to the data owner, where the hash query feature set includes: a preset number of hash query features publicly disclosed after being signed and hashed by the private key of the data owner and the target hash query feature corresponding to the target query feature signature;

[0038] The receiving set module is used to receive the encrypted attribute data set corresponding to the hash query feature set sent by the data owner;

[0039] The decryption module is used to decrypt the target encrypted attribute data corresponding to the target query feature in the encrypted attribute data set through the target query feature signature to obtain the target attribute data.

[0040] This application also provides a trace - hiding query device, including:

[0041] A memory for storing a computer program;

[0042] A processor for implementing the steps of the above - mentioned trace - hiding query method when executing the computer program.

[0043] This application also provides a computer - readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the above - mentioned trace - hiding query method are implemented.

[0044] A trace - hiding query method provided by this application is applied to a data owner. The data owner signs and hashes the query feature through the private key to obtain a hash query feature and discloses it to the query party, and generates a public key based on the encryption algorithm and the private key and discloses the public key to the query party; the data owner signs the target blinded query feature sent by the query party through the private key to obtain the target blinded query feature signature. The query party can de - blind the target blinded query feature signature to obtain the target query feature signature. The data owner sends the encrypted attribute data set corresponding to the hash query feature set to the query party. The query party can decrypt the target attribute data through the target query feature signature to obtain the target attribute data. Because the trace - hiding query method provided by this application encrypts the query feature through the private key generated by the data owner itself without the attribute data leaving the local database, the trace - hiding query method provided by this application does not rely on a third party to generate keys or conduct interactions, reducing the risk of data leakage.

[0045] In addition, the present application also provides a stealth query method, which is applied to a querying party. The querying party receives a target blinded query feature signature signed by a private key of a data owner, and after de-blinding, obtains the target query feature signature. Through this target query feature signature, the target encrypted attribute data can be decrypted. Without the attribute data leaving the database of the data owner, the querying party receives the target blinded query feature encrypted by the private key generated by the data owner itself. Therefore, the stealth query method provided by the present application does not rely on a third party to generate keys or perform interactions, reducing the risk of data leakage.

[0046] In addition, the present application also provides a stealth query device and a computer-readable storage medium, which correspond to the above method and have the same effect. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] To more clearly illustrate the embodiments of the present application, the following will briefly introduce the drawings required for the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0048] Figure 1 It is a flowchart of a stealth query method provided by an embodiment of the present application;

[0049] Figure 2 It is a flowchart of another stealth query method provided by an embodiment of the present application;

[0050] Figure 3 It is a schematic diagram of a stealth query device provided by an embodiment of the present application;

[0051] Figure 4 It is a schematic diagram of another stealth query device provided by an embodiment of the present application;

[0052] Figure 5 It is a structural diagram of a stealth query device provided by another embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0053] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all embodiments. Based on the embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the protection scope of the present application.

[0054] The core of the present application is to provide a stealth query method, device and medium that do not rely on a third party, reducing the risk of data leakage.

[0055] To enable those skilled in the art to better understand the solution of this application, the following provides a further detailed description of this application in conjunction with the accompanying drawings and specific embodiments.

[0056] With the rapid development of the big data Internet, in some specific situations, the data owner needs to provide the attribute data required by the query party, and the data owner does not need to verify the identity information of the query party. For example, law enforcement departments need to query the credit information of a certain user from the bank, but do not want the bank to monitor this query record to avoid unnecessary impacts on the user. In this case, anonymous query is required. Without the data owner knowing the identity information of the query party and the specific content of the information queried by the query party, the data information required by the query party is provided to the query party. In addition, the query party can only obtain the data information it needs and cannot obtain additional data information to avoid data leakage of the data owner. Traditional anonymous queries often rely on a trusted third party to generate keys or conduct interactions through the trusted third party. The data security of this method largely depends on the security of the third party, and there is a certain risk of data leakage. Therefore, this application provides an anonymous query solution to achieve data interaction between the data owner and the query party without relying on a third party.

[0057] Figure 1 It is a flowchart of an anonymous query method provided by an embodiment of this application. As Figure 1 shown, an embodiment of this application provides an anonymous query method, which is applied to a data owner and includes:

[0058] S11: Sign the query feature with the private key to obtain a query feature signature, hash the query feature signature to obtain a hashed query feature and disclose it to the query party, generate a public key based on the encryption algorithm and the private key, and disclose the public key to the query party;

[0059] S12: Receive the target blinded query feature sent by the query party;

[0060] S13: Sign the target blinded query feature with the private key to obtain a target blinded query feature signature;

[0061] S14: Send the target blinded query feature signature to the query party so that the query party can de-blind the target blinded query feature signature to obtain a target query feature signature;

[0062] S15: Receive the hashed query feature set sent by the query party and send the encrypted attribute data set corresponding to the hashed query feature set to the query party so that the query party can decrypt the target encrypted attribute data corresponding to the target query feature in the encrypted attribute data set through the target query feature signature to obtain the target attribute data.

[0063] In this embodiment, the data owner refers to the party that provides data information, and the querying party is the one that sends a query request to the data owner to obtain the corresponding data information. In this application, the data information is divided into query features and attribute data. The query features are equivalent to features, which are public to both the data owner and the querying party. The attribute data is the data information not made public by the data owner. The querying party can send a query request to the data owner through the query features, and the data querying party can find the corresponding attribute data through the query features. The traceable query method provided by this application provides the target attribute data to the querying party when the data owner does not know the target query features of the querying party, and the querying party cannot obtain additional attribute data to cause information leakage.

[0064] The private key mentioned in this embodiment refers to the one generated by the data owner itself. The private key is not made public. Based on the encryption algorithm and the private key, a public key is generated, and the public key is made public to the querying party. This embodiment does not specifically limit the encryption algorithm. For example, Elliptic Curves Cryptography (ECC) encryption algorithm, Data Encryption Standard (DES), Digital Signature Algorithm (DSA) encryption algorithm, RSA encryption algorithm, etc. The public key is generated according to the specifically selected encryption algorithm in combination with the private key.

[0065] This embodiment provides a preferred solution, where the encryption algorithm is the ECC encryption algorithm. The ECC encryption algorithm has strong anti-attack ability. With the same key length, its anti-attack ability is many times stronger; the calculation amount is small, the processing speed is fast, and the overall speed of the ECC encryption algorithm is much faster than that of the RSA encryption algorithm and the DSA encryption algorithm; the storage space occupied is small. The key size and system parameters of the ECC encryption algorithm are much smaller than those of the RSA encryption algorithm and the DSA encryption algorithm, which means that the storage space it occupies is much smaller; the bandwidth requirement is low. When encrypting and decrypting long messages, the bandwidth requirement of the ECC encryption algorithm is much lower when applied to short messages.

[0066] The hash mentioned in this embodiment refers to the hash algorithm. The hash algorithm transforms an input of any length (also called the pre-image) into an output of a fixed length through the hashing algorithm. This output is the hash value. This transformation is a compression mapping. That is, the space of the hash value is usually much smaller than the space of the input. Different inputs may be hashed into the same output, so it is impossible to determine the unique input value from the hash value, and it is very difficult to find the reverse rule.

[0067] The hash query feature set mentioned in this embodiment refers to the target hash query feature corresponding to the target query feature signature generated by the querying party and the hash query features publicly disclosed by the data owner after signing and hashing other data used for obfuscation. This embodiment does not limit the number of hash query features used for obfuscation, which can be designed according to actual needs. In addition, the hash query features used for obfuscation can be manually selected by the querying party or randomly selected automatically. This embodiment does not make specific restrictions.

[0068] The target blinded query feature mentioned in this embodiment refers to the one obtained by the querying party after blinding the target query feature to be queried, and the data owner cannot know the attribute data that the querying party wants to query through this blinded target query feature.

[0069] The encrypted attribute data set mentioned in this embodiment refers to the encrypted attribute data corresponding to the hash query features in the hash query feature set by the data owner. This encrypted attribute data can be decrypted through the corresponding query feature signature combined with the corresponding encryption rules. This embodiment does not limit when to encrypt the attribute data. The attribute data in the database can be encrypted and stored in advance, and the corresponding encrypted attribute data can be directly retrieved when generating the encrypted attribute data set; or the corresponding attribute data can be encrypted after receiving the command to generate the encrypted attribute data set to generate the encrypted attribute data set. This embodiment does not make specific restrictions.

[0070] Specifically, the data owner receives the target blinded query feature sent by the querying party, signs the target blinded query feature to obtain the target blinded query feature signature, and sends the target blinded query feature signature to the querying party. The querying party can obtain the target query feature signature by deblinding the target blinded query feature signature. The data owner receives the target hash query feature and other hash query features used for obfuscation obtained by the querying party after hashing the target query feature signature, and generates an encrypted attribute data set according to this hash query feature set, so that the querying party can decrypt the target encrypted attribute data corresponding to the target query feature in the encrypted attribute data set through the target query feature signature to obtain the target attribute data.

[0071] Because the traceable query method provided in this application encrypts the query features through the private key generated by the data owner without the attribute data leaving the local database, the traceable query method provided in this application does not rely on a third party to generate keys or perform interactions, reducing the risk of data leakage.

[0072] According to the above embodiment, in order to improve the efficiency of data interaction, this embodiment provides a preferred solution. The steps for generating the encrypted attribute data set are as follows:

[0073] Encrypt the attribute data in the database by combining the corresponding query feature signature with the encryption rule to obtain encrypted attribute data, and store it in the database;

[0074] Obtain the encrypted attribute data corresponding to the hash query feature set to generate an encrypted attribute data set.

[0075] The encryption rule mentioned in this embodiment refers to encrypting the attribute data by combining this encryption rule with the query feature signature. This embodiment does not specifically limit this encryption rule. For example, the Advanced Encryption Standard (AES), DES encryption algorithm, 3DES encryption algorithm, etc.

[0076] This embodiment provides a preferred solution. The encryption rule is the AES encryption algorithm. The AES encryption algorithm is a symmetric encryption algorithm, which has better security, efficiency, and flexibility than DES. It can encrypt and decrypt quickly both in software and hardware, is relatively easy to implement, and only requires very little memory.

[0077] The data owner encrypts the attribute data in the database by combining the corresponding query feature signature with the encryption rule to obtain encrypted attribute data, and stores it in the database; when the data owner needs to generate an encrypted attribute data set, directly retrieve the corresponding encrypted attribute data from the database to generate the encrypted attribute data set.

[0078] It provides encryption of attribute data in advance. When the corresponding encrypted attribute data is needed, it can be directly retrieved, reducing communication overhead and improving the efficiency of data interaction.

[0079] Figure 2 It is a flowchart of another privacy-preserving query method provided by an embodiment of the present application. As Figure 2 shown, an embodiment of the present application provides a privacy-preserving query method, which is applied to a query party and includes:

[0080] S21: Send a target blinded query feature to the data owner;

[0081] S22: Receive the target blinded query feature signature sent by the data owner, where the target blinded query feature signature is obtained by the data owner signing the target blinded query feature with a private key;

[0082] S23: Obtain the public key generated by the data owner based on the encryption algorithm and the private key, and de-blind the blinded query feature signature to obtain the target query feature signature;

[0083] S24: Send the hash query feature set to the data owner, where the hash query feature set includes: hash query features publicly released after being signed and hashed by a private key of a preset number of data owners and target hash query features corresponding to the target query feature signature;

[0084] S25: Receive the encrypted attribute data set corresponding to the hash query feature set sent by the data owner;

[0085] S26: Decrypt the target encrypted attribute data corresponding to the target query feature in the encrypted attribute data set through the target query feature signature to obtain the target attribute data.

[0086] The traceable query method provided in this embodiment is applied to the querying party.

[0087] The target blinded query feature mentioned in this embodiment refers to the one obtained after the querying party blinds the target query feature to be queried. The data owner cannot know the attribute data that the querying party wants to query through this blinded target query feature. The target blinded query feature is generated by the target query feature in combination with other encryption factors according to the encryption algorithm. The other encryption factors can be random factors, random algorithms, etc. In addition, the data owner generates a public key through this encryption algorithm in combination with the private key and makes it public to the querying party.

[0088] Specifically, the querying party sends the target blinded query feature to the data owner, receives the target blinded query feature signature obtained by signing the target blinded query feature with the private key sent by the data owner, de - blinds the blinded query feature signature according to the public key generated by the data owner based on the encryption algorithm and the private key to obtain the target query feature signature. The querying party generates a hash query feature set, which includes: hash query features publicly released after being signed and hashed by a private key of a preset number of data owners and target hash query features corresponding to the target query feature signature; after receiving the hash query feature set, the data owner will generate a corresponding encrypted attribute data set, and the querying party can decrypt the target encrypted attribute data in the encrypted attribute data set through the target query feature signature to obtain the target attribute data.

[0089] Because in the traceable query method provided in this application, when the attribute data does not leave the database of the data owner, the target query feature signature received by the querying party is encrypted by the private key generated by the data owner itself for the query feature. Therefore, the traceable query method provided in this application does not rely on a third party to generate keys or perform interactions, reducing the risk of data leakage.

[0090] According to the above - mentioned embodiment, this embodiment provides a preferred solution for generating the target blinded query feature. Generating the target blinded query feature includes the following steps:

[0091] Blind the target query feature according to a random factor in combination with an encryption algorithm to obtain a target blinded query feature.

[0092] The querying party blinds the target query feature according to the random factor it selects in combination with an encryption algorithm. The encryption algorithm is public to both the querying party and the data owner. However, the target blinded query feature obtained by combining the random factor cannot be known by the data owner about the attribute information queried by the querying party. The data owner performs a blind signature on the target query feature, protecting the query privacy of the querying party.

[0093] Correspondingly, the querying party blinds the target query feature according to a random factor in combination with an encryption algorithm to obtain a target blinded query feature, and performs de - blinding on the signature of the blinded query feature to obtain a target query feature signature, including:

[0094] Perform de - blinding on the signature of the blinded query feature according to the random factor and the public key to obtain a target query feature signature.

[0095] The public key is generated by the data owner based on the encryption algorithm and the private key, and the public key is made public to the querying party. The querying party can obtain the public key made public by the data owner, and perform de - blinding on the signature of the blinded query feature according to the random factor and the public key to obtain a target query feature signature. The data owner does not know the attribute data queried by the querying party. This target query feature signature can only decrypt the target encrypted attribute data and cannot decrypt other encrypted attribute data, protecting the non - disclosure of the attribute data of the data owner.

[0096] In the above - mentioned embodiments, the method of stealth query applied to the data owner is described in detail. The present application also provides an embodiment of a stealth query device from the perspective of functional modules.

[0097] Figure 3 It is a schematic diagram of a stealth query device provided by an embodiment of the present application. As Figure 3 shown, a stealth query device, applied to the data owner, includes:

[0098] A public disclosure module 31, configured to sign the query feature through a private key to obtain a query feature signature, hash the query feature signature to obtain a hashed query feature, and make it public to the querying party, generate a public key based on the encryption algorithm and the private key, and make the public key public to the querying party;

[0099] A receiving feature module 32, configured to receive the target blinded query feature sent by the querying party;

[0100] A signature module 33, configured to sign the target blinded query feature through a private key to obtain a target blinded query feature signature;

[0101] A sending signature module 34, configured to send a target blinded query feature signature to a querying party, so that the querying party can obtain a target query feature signature by deblinding the target blinded query feature signature;

[0102] A receiving and sending module 35, configured to receive a hash query feature set sent by the querying party and send an encrypted attribute data set corresponding to the hash query feature set to the querying party, so that the querying party can decrypt target encrypted attribute data corresponding to a target query feature in the encrypted attribute data set by using the target query feature signature to obtain target attribute data.

[0103] Specifically, a disclosure module 31 signs a query feature by using a private key to obtain a query feature signature, hashes the query feature signature to obtain a hash query feature and discloses it to the querying party, generates a public key based on an encryption algorithm and the private key, and discloses the public key to the querying party. A receiving feature module 32 receives a target blinded query feature sent by the querying party. A signature module 33 signs the target blinded query feature by using the private key to obtain a target blinded query feature signature. A sending signature module 34 sends the target blinded query feature signature to the querying party, so that the querying party can obtain a target query feature signature by deblinding the target blinded query feature signature. A receiving and sending module 35 receives a hash query feature set sent by the querying party and sends an encrypted attribute data set corresponding to the hash query feature set to the querying party, so that the querying party can decrypt target encrypted attribute data corresponding to a target query feature in the encrypted attribute data set by using the target query feature signature to obtain target attribute data. In the case where the attribute data does not leave the local database, the query feature is encrypted by using a private key generated by the data owner. Therefore, the traceable query method provided in this application does not rely on a third party to generate a key or perform interaction, reducing the risk of data leakage.

[0104] Since the embodiments of the apparatus part correspond to the embodiments of the method part, for the descriptions of the embodiments of the apparatus part, please refer to the descriptions of the embodiments of the method part, which will not be elaborated here.

[0105] In the above embodiments, the traceable query method applied to the querying party is described in detail. This application also provides an embodiment of a traceable query apparatus from the perspective of functional modules.

[0106] Figure 4 It is a schematic diagram of another traceable query apparatus provided in an embodiment of this application. As Figure 4 shown, a traceable query apparatus, applied to a querying party, includes:

[0107] A sending feature module 41, configured to send a target blinded query feature to a data owner;

[0108] A receiving signature module 42, configured to receive a target blinded query feature signature sent by a data owner, where the target blinded query feature signature is obtained by the data owner signing the target blinded query feature with a private key;

[0109] A de - blinding module 43, configured to obtain a public key generated by the data owner based on an encryption algorithm and a private key, and de - blind the blinded query feature signature to obtain a target query feature signature;

[0110] A sending set module 44, configured to send a hash query feature set to the data owner, where the hash query feature set includes: a preset number of hash query features publicly disclosed by the data owner after signing with a private key and hashing, and a target hash query feature corresponding to the target query feature signature;

[0111] A receiving set module 45, configured to receive an encrypted attribute data set corresponding to the hash query feature set sent by the data owner;

[0112] A decryption module 46, configured to decrypt the target encrypted attribute data corresponding to the target query feature in the encrypted attribute data set through the target query feature signature to obtain target attribute data.

[0113] Specifically, after the sending feature module 41 sends a target blinded query feature to the data owner, the receiving signature module 42 receives the target blinded query feature signature sent by the data owner, where the target blinded query feature signature is obtained by the data owner signing the target blinded query feature with a private key. The de - blinding module 43 obtains a public key generated by the data owner based on an encryption algorithm and a private key, and de - blinds the blinded query feature signature to obtain a target query feature signature. The sending set module 44 sends a hash query feature set to the data owner, where the hash query feature set includes: a preset number of hash query features publicly disclosed by the data owner after signing with a private key and hashing, and a target hash query feature corresponding to the target query feature signature. The receiving set module 45 receives an encrypted attribute data set corresponding to the hash query feature set sent by the data owner. The decryption module 46 decrypts the target encrypted attribute data corresponding to the target query feature in the encrypted attribute data set through the target query feature signature to obtain target attribute data. In the case where the attribute data does not leave the database of the data owner, the target query feature signature received by the querying party is encrypted by the private key generated by the data owner itself for the query feature. Therefore, the anonymous query method provided in this application does not rely on a third party to generate keys or perform interactions, reducing the risk of data leakage.

[0114] Figure 5 This is a structural diagram of an anonymous query device provided in another embodiment of the present application. As Figure 5 shown, the anonymous query device includes: a memory 50, configured to store a computer program;

[0115] A processor 51, which is configured to implement the steps of the stealth query method in the above embodiments when executing a computer program.

[0116] The stealth query device provided in this embodiment may include, but is not limited to, a smart phone, a tablet computer, a laptop computer, a desktop computer, etc.

[0117] Among them, the processor 51 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 51 may be implemented in at least one hardware form of digital signal processing (DSP), field-programmable gate array (FPGA), and programmable logic array (PLA). The processor 51 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the wake state, also known as the central processing unit (CPU); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 51 may be integrated with a graphics processing unit (GPU), and the GPU is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 51 may further include an artificial intelligence (AI) processor, and the AI processor is used to process computational operations related to machine learning.

[0118] The memory 50 may include one or more computer-readable storage media, and the computer-readable storage media may be non-transitory. The memory 50 may further include high-speed random access memory and non-volatile memory, such as one or more disk storage devices and flash storage devices. In this embodiment, the memory 50 is at least used to store the following computer program 501. After the computer program is loaded and executed by the processor 51, it can implement the relevant steps of the stealth query method disclosed in any of the foregoing embodiments. In addition, the resources stored in the memory 50 may further include an operating system 502 and data 503, etc., and the storage method may be temporary storage or permanent storage. Among them, the operating system 502 may include Windows, Unix, Linux, etc. The data 503 may include, but is not limited to, data involved in implementing the stealth query.

[0119] In some embodiments, the stealth query device may further include a display screen 52, an input / output interface 53, a communication interface 54, a power supply 55, and a communication bus 56.

[0120] Those skilled in the art can understand that Figure 5 the structure shown in does not constitute a limitation on the stealth query device, and may include more or fewer components than those shown in the figure.

[0121] The stealth query device provided by the embodiments of the present application includes a memory and a processor. When the processor executes the program stored in the memory, the following method can be implemented: the stealth query method. In the case where the attribute data does not leave the database of the data owner, the target query feature signature received by the query party is encrypted by the private key generated by the data owner himself for the query feature. Therefore, the stealth query method provided by the present application does not rely on a third party to generate keys or perform interactions, reducing the risk of data leakage.

[0122] Finally, the present application also provides an embodiment corresponding to a computer-readable storage medium. A computer program is stored on the computer-readable storage medium, and when the computer program is executed by the processor, the steps recorded in the above method embodiments (the stealth query method corresponding to the data owner side, the stealth query method corresponding to the query party) are implemented.

[0123] It can be understood that if the methods in the above embodiments are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and executes all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.

[0124] The computer-readable storage medium provided by this embodiment stores a computer program, and when the processor executes this program, the following method can be implemented: the stealth query method. In the case where the attribute data does not leave the database of the data owner, the target query feature signature received by the query party is encrypted by the private key generated by the data owner himself for the query feature. Therefore, the stealth query method provided by the present application does not rely on a third party to generate keys or perform interactions, reducing the risk of data leakage.

[0125] The above has introduced in detail the stealth query method, device and computer-readable storage medium provided by the present application. Each embodiment in the specification is described in a progressive manner, and the key point of each embodiment is the difference from other embodiments. For the same or similar parts among the embodiments, reference can be made to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and for the relevant parts, reference can be made to the description in the method part. It should be noted that for those of ordinary skill in the art in this technical field, without departing from the principle of the present application, several improvements and modifications can be made to the present application, and these improvements and modifications also fall within the protection scope of the claims of the present application.

[0126] It should also be noted that in this specification, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of another identical element in the process, method, article or device including the said element.

Claims

1. A stealth query method, characterized in that, Applied to the data owner, including: Sign the query feature with the private key to obtain a query feature signature, hash the query feature signature to obtain a hashed query feature and disclose it to the query party, generate a public key based on the encryption algorithm and the private key, and disclose the public key to the query party; Receive the target blinded query feature sent by the query party; Sign the target blinded query feature with the private key to obtain a target blinded query feature signature; Send the target blinded query feature signature to the query party, so that the query party can de-blind the target blinded query feature signature to obtain a target query feature signature; Receive the hashed query feature set sent by the query party and send the encrypted attribute data set corresponding to the hashed query feature set to the query party, so that the query party can decrypt the target encrypted attribute data corresponding to the target query feature in the encrypted attribute data set with the target query feature signature to obtain the target attribute data.

2. The stealth query method according to claim 1, wherein The steps for generating the encrypted attribute data set are as follows: Encrypt the attribute data in the database with the corresponding query feature signature in combination with the encryption rule to obtain encrypted attribute data, and store it in the database; Obtain the encrypted attribute data corresponding to the hashed query feature set to generate the encrypted attribute data set.

3. The stealth query method according to claim 2, wherein The encryption algorithm is the ECC encryption algorithm.

4. A stealth query method, characterized in that, Applied to the query party, including: Send a target blinded query feature to the data owner; Receive the target blinded query feature signature sent by the data owner, where the target blinded query feature signature is obtained by the data owner signing the target blinded query feature with the private key; Obtain the public key generated by the data owner based on the encryption algorithm and the private key, and de-blind the target blinded query feature signature to obtain a target query feature signature; Send a hashed query feature set to the data owner, where the hashed query feature set includes: a preset number of hashed query features publicly disclosed by the data owner after signing and hashing with the private key and the target hashed query feature corresponding to the target query feature signature; Receive the encrypted attribute data set corresponding to the hashed query feature set sent by the data owner; Decrypt the target encrypted attribute data corresponding to the target query feature in the encrypted attribute data set with the target query feature signature to obtain the target attribute data.

5. The stealth query method according to claim 4, wherein The steps for generating the target blinded query feature include the following: Blind the target query feature according to the random factor in combination with the encryption algorithm to obtain the target blinded query feature.

6. The stealth query method according to claim 5, wherein The de-blinding of the target blinded query feature signature to obtain a target query feature signature includes: De-blind the target blinded query feature signature according to the random factor and the public key to obtain a target query feature signature.

7. A stealth query device, characterized in that, Applied to the data owner, including: A disclosure module for signing the query feature with the private key to obtain a query feature signature, hashing the query feature signature to obtain a hashed query feature and disclosing it to the query party, generating a public key based on the encryption algorithm and the private key, and disclosing the public key to the query party; A receiving feature module, configured to receive a target blinded query feature sent by the querying party; A signature module, configured to sign the target blinded query feature with the private key to obtain a target blinded query feature signature; A sending signature module, configured to send the target blinded query feature signature to the querying party, so that the querying party can de-blind the target blinded query feature signature to obtain a target query feature signature; A receiving and sending module, configured to receive a hash query feature set sent by the querying party and send the encrypted attribute data set corresponding to the hash query feature set to the querying party, so that the querying party can decrypt the target encrypted attribute data corresponding to the target query feature in the encrypted attribute data set through the target query feature signature to obtain target attribute data.

8. A stealth query device, characterized in that, Applied to the querying party, including: A sending feature module, configured to send a target blinded query feature to the data owner; A receiving signature module, configured to receive the target blinded query feature signature sent by the data owner, where the target blinded query feature signature is obtained by the data owner signing the target blinded query feature with the private key; A de-blinding module, configured to obtain the public key generated by the data owner based on the encryption algorithm and the private key, and de-blind the target blinded query feature signature to obtain a target query feature signature; A sending set module, configured to send a hash query feature set to the data owner, where the hash query feature set includes: a preset number of hash query features publicly signed and hashed by the data owner with the private key and the target hash query feature corresponding to the target query feature signature; A receiving set module, configured to receive the encrypted attribute data set corresponding to the hash query feature set sent by the data owner; A decrypting module, configured to decrypt the target encrypted attribute data corresponding to the target query feature in the encrypted attribute data set through the target query feature signature to obtain target attribute data.

9. A stealth query device, characterized in that, Including: A memory, configured to store a computer program; A processor, configured to implement the steps of the traceable query method according to any one of claims 1 to 6 when executing the computer program.

10. A computer-readable storage medium, characterized in that, The computer program is stored on a computer-readable storage medium, and when the computer program is executed by a processor, the steps of the traceable query method according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Blind signature acquisition method and device and server

    CN109818730A

  • Data sending method, data query method, data sending device, data query device, electronic equipment and data query system

    CN110636070A