A method, device, equipment and storage medium for string comparison
By converting strings into binary vectors and applying Godel encoding and Paillier encryption algorithms, the problems of low string comparison efficiency and privacy leakage in the prior art are solved, and a high security and low complexity string comparison method is realized.
Patent Information
- Application Number
- CN202111514894.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-13
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2041-12-13
AI Technical Summary
Existing string equality confidentiality decision protocols are inefficient and may disclose privacy information when repeated calls and multiple string comparisons.
By converting the string into a binary vector, applying Godel encoding to generate the ciphertext, and decrypting it using the Paillier encryption algorithm. If the decryption is successful, the string comparison results will be equal.
Improves the security of string alignment, reduces the computational complexity and communication complexity, and only requires one decryption operation and n-1 communication.
Smart Images

Figure CN114186105B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and in particular, to a method, device, equipment and storage medium for string comparison. Background Art
[0002] With the rise and popularization of big data, cloud computing and the Internet of Things, people's social production and life have undergone earth-shaking changes. The development of technology has increased the ways of data collection, storage, calculation and transmission, and promoted the in-depth development of digitization and intelligence. In order to obtain valuable data resources, data owners hope to perform joint calculations while protecting their private data. At the same time, with the increasing importance of privacy data such as web browsing traces, location trajectory records, fingerprint audio information, etc., private information leakage incidents often occur, and the difficulty of maintaining information security has increased. These hidden dangers have hindered the development and progress of computing technology, and restricted the use and promotion of big data and artificial intelligence. Therefore, seeking privacy data processing methods in a multi-party environment has become an urgent task and attracted great attention.
[0003] Secure multi-party computation ensures that participants can make the most of their private data for confidential cooperative computation without revealing the private information of the participants, so that private data can play its positive role in the fields of society, economy and science and technology, and has important theoretical and practical significance in finance and information security. The problem of secure determination of string equality is an important secure multi-party computation problem, which has certain practical significance in information security practice and can be applied to fields such as secure database query, information retrieval, similarity detection, etc.
[0004] Existing secure determination protocols for string equality can be divided into two parts: (1) converting each character of the string into binary form; (2) using the method of XOR operation between two parties to compare the strings pairwise. Existing secure determination protocols for string equality all use the method of XOR operation between two parties. If these protocols are repeatedly called to compare multiple strings pairwise, not only is the efficiency very low, but also a lot of information that should not be leaked will be leaked. Summary of the Invention
[0005] Embodiments of the present invention provide a method, device, equipment and storage medium for string comparison, which solves the problem of character comparison in the ciphertext state.
[0006] In a first aspect, embodiments of the present invention provide a method for string comparison, including:
[0007] Determine at least two strings to be compared;
[0008] Generate ciphertext to be decrypted according to the at least two strings;
[0009] Decrypt the to-be-decrypted ciphertext. If the decryption is successful, the comparison results of the at least two strings are equal.
[0010] Furthermore, the at least two strings correspond to at least two participants one by one, and each participant stores their respective corresponding string.
[0011] Furthermore, generating the to-be-decrypted ciphertext according to the at least two strings includes:
[0012] Generating ciphertexts corresponding to the respective strings according to the at least two strings;
[0013] Determining the last ciphertext as the to-be-decrypted ciphertext in the order of ciphertext generation.
[0014] Furthermore, generating ciphertexts corresponding to the respective strings includes:
[0015] For each string, generating a corresponding binary vector respectively;
[0016] Performing Gödel encoding on each binary vector respectively and determining the corresponding intermediate value;
[0017] Generating corresponding ciphertexts in sequence according to the respective intermediate values.
[0018] Furthermore, for each string, generating a corresponding binary vector respectively includes:
[0019] For each string, converting the single characters in the string into binary form and representing the string in matrix form;
[0020] Connecting the elements of each row in the matrix to obtain the corresponding binary vector.
[0021] Furthermore, performing Gödel encoding on each binary vector respectively and determining the corresponding intermediate value includes:
[0022] Performing Gödel encoding on each binary vector to determine the Gödel numbers corresponding to the respective binary vectors;
[0023] Determining the random numbers corresponding to the respective binary vectors respectively, and determining the corresponding intermediate values according to the random numbers and Gödel numbers corresponding to the respective binary vectors.
[0024] Furthermore, decrypting the to-be-decrypted ciphertext includes:
[0025] Obtaining a private key / public key pair composed of a private key and a public key, and determining the first participant who generated the private key and the public key;
[0026] According to the private key / public key pair, enable the first participant to decrypt the ciphertext to be decrypted and obtain the decryption result.
[0027] In a second aspect, an embodiment of the present invention further provides a string comparison device, including:
[0028] A string determination module, configured to determine at least two strings to be compared;
[0029] A ciphertext to be decrypted generation module, configured to generate a ciphertext to be decrypted according to the at least two strings;
[0030] A decryption module, configured to decrypt the ciphertext to be decrypted. If the decryption is successful, the comparison result of the at least two strings is equal.
[0031] Optionally, the ciphertext to be decrypted generation module is further configured to:
[0032] Generate ciphertexts corresponding to each string according to the at least two strings;
[0033] Determine the last ciphertext as the ciphertext to be decrypted according to the ciphertext generation order.
[0034] Optionally, the ciphertext to be decrypted generation module is further configured to:
[0035] Generate corresponding binary vectors for each string respectively;
[0036] Perform Gödel encoding on each binary vector respectively and determine the corresponding intermediate values;
[0037] Generate corresponding ciphertexts in sequence according to each intermediate value.
[0038] Optionally, the ciphertext to be decrypted generation module is further configured to:
[0039] For each string, convert the single characters in the string into binary form and represent the string in matrix form;
[0040] Connect the elements of each row in the matrix to obtain the corresponding binary vector.
[0041] Optionally, the ciphertext to be decrypted generation module is further configured to:
[0042] Perform Gödel encoding on each binary vector to determine the Gödel numbers corresponding to each binary vector;
[0043] Determine the random numbers corresponding to each binary vector respectively, and determine the corresponding intermediate values according to the random numbers and Gödel numbers corresponding to each binary vector.
[0044] Optionally, the decryption module is further configured to:
[0045] Obtain a private key / public key pair composed of a private key and a public key, and determine a first participant who generates the private key and the public key;
[0046] According to the private key / public key pair, cause the first participant to decrypt the ciphertext to be decrypted, and obtain a decryption result.
[0047] Thirdly, an embodiment of the present invention further provides a computer device for string comparison, including:
[0048] A memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the program, it implements the string comparison method according to any one of the embodiments of the present invention.
[0049] Fourthly, an embodiment of the present invention further provides a storage medium for string comparison, on which a computer program is stored, and when the program is executed by a processing device, it implements the string comparison method according to any one of the embodiments of the present invention.
[0050] In the embodiment of the present invention, at least two strings to be compared are first determined, then a ciphertext to be decrypted is generated according to the at least two strings, and finally the ciphertext to be decrypted is decrypted. If the decryption is successful, the comparison result of the at least two strings is equal. The string comparison method provided by the embodiment of the present invention realizes string comparison under encryption conditions, improves the security of string comparison, and only requires one decryption operation and n - 1 communications, reducing the computational complexity and communication complexity. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] Figure 1 is a flowchart of a string comparison method in Embodiment 1 of the present invention;
[0052] Figure 2 is a flowchart of a string comparison method in Embodiment 2 of the present invention;
[0053] Figure 3 is a schematic structural diagram of a string comparison device in Embodiment 3 of the present invention;
[0054] Figure 4 is a schematic structural diagram of a computer device in Embodiment 4 of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0055] When data is loaded into the big data platform, it is necessary to export the data table to be stored into a data file, and it is necessary to compare the strings in the data file during the test. For example, in the big data platform warehousing project, compare the strings in the data files before and after warehousing; during data migration, compare the strings in the data files of the source database and the new database.
[0056] The comparison process of the strings conforms to the semi - honest model. In the semi - honest model, it is assumed that all participants are semi - honest participants. During the execution of the protocol, semi - honest participants will strictly execute every step of the protocol, but they may retain the information obtained during the execution of the protocol and deduce the private information of other participants from this information.
[0057] The problem to be solved by the present invention is to resist the collusive attack of any participant and ensure the security of information in the case of semi - honest participants participating.
[0058] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the present invention, rather than limiting the present invention. In addition, it should be noted that for the convenience of description, only parts related to the present invention rather than all structures are shown in the drawings.
[0059] Embodiment 1
[0060] Figure 1 As shown in the flowchart of a method for comparing strings provided in Embodiment 1 of the present invention, this embodiment is applicable to the case of comparing strings in the ciphertext state. This method can be executed by a string comparison device, which can be composed of hardware and / or software and is generally integrated in a device with the function of string comparison. This device can be an electronic device such as a server or a server cluster. As Figure 1 shown, it specifically includes the following steps:
[0061] Step 110: Determine at least two strings to be compared.
[0062] Among them, at least two strings correspond one - to - one with at least two participants, and each participant stores its corresponding string respectively.
[0063] Specifically, in the semi - honest model, each participant holds a string and executes a protocol for securely determining the equality of strings, that is, determining whether the strings are equal while keeping the strings secret.
[0064] In this embodiment, the participants can be set as P i (i = 1, … n), where n is the number of participants, and P i respectively have strings S i = s i1 … s im , and P i needs to securely determine whether the strings S i (i = 1, … n) are equal without revealing any other information about the strings S i .
[0065] Step 120: Generate the ciphertext to be decrypted based on at least two strings.
[0066] In this embodiment, a new homomorphic encryption scheme constructed by means of Gödel coding can be used to create ciphertexts for solving the string comparison problem in a confidential state. Among them, Gödel coding is a coding method that establishes a one-to-one correspondence between a sequence of non-negative integers and a natural number. A finite sequence (a 1 , a 2 , …, a l ) uses l consecutive prime numbers starting from 2 (p 1 , p 2 , …, p l ) to establish the following correspondence:
[0067]
[0068] Specifically, each string can be converted into a binary vector, and then each participant can use Gödel coding to establish a correspondence between their respective binary vectors and a natural number. Starting from the first participant P 1 , each participant can successively calculate the corresponding ciphertext c i using their respective natural numbers until the ciphertext c n is calculated, and c n is determined as the ciphertext to be decrypted.
[0069] Optionally, the Paillier encryption algorithm can be used for encryption. The Paillier encryption algorithm is a semantically secure probabilistic encryption algorithm. In this algorithm, the key generation method is as follows:
[0070] Select two large prime numbers p and q, let N = pq, and λ(N) = lcm(p - 1, q - 1). Randomly select a such that gcd(L(g λ mod N 2 ), N) = 1, where (g, N) is the public key and λ is the private key.
[0071] The encryption method of the Paillier algorithm is as follows:
[0072] Select a random number r (r < N), encrypt the plaintext k, then
[0073] E(k) = g k r N mod N 2 , and E(*) represents the encryption operation.
[0074] Step 130: Decrypt the ciphertext to be decrypted. If the decryption is successful, the comparison result of at least two strings is equal.
[0075] Among them, for the ciphertext encrypted by the Paillier encryption algorithm, the decryption method is as follows:
[0076] Among them, c represents the ciphertext.
[0077] In this embodiment, after determining the ciphertext c to be decrypted n , the Paillier algorithm can be used for decryption. If the decryption result D(c n ) = 0, the decryption is successful, and the strings S i are equal; otherwise, the decryption fails, and the strings S i are not equal. Among them, D(*) represents the decryption operation.
[0078] In the embodiment of the present invention, at least two strings to be compared are first determined, then the ciphertext to be decrypted is generated according to the at least two strings, and finally the ciphertext to be decrypted is decrypted. If the decryption is successful, the comparison result of the at least two strings is equal. The string comparison method provided by the embodiment of the present invention has higher security than the existing method. The existing technology needs to compare strings pairwise, which not only has high computational complexity but also leaks privacy information that should not be leaked. However, this method can determine whether the strings are equal through one round of calculation, improving security. Further, the complexity of the calculation process of this method is lower than that of the existing method. This method only needs to perform one decryption operation, while the number of decryption times in the existing method is related to the length of the binary string. Therefore, the efficiency of this method is higher than that of the existing method. Finally, the communication complexity of this method is lower than that of the existing technology. This method only needs n - 1 times of communication, while the existing protocol needs 2(n - 1) times of communication. Therefore, the communication complexity of this method is lower than that of the existing method.
[0079] Embodiment 2
[0080] Figure 2 The following is a flowchart of a string comparison method provided by the second embodiment of the present invention. This embodiment is applicable to the case of comparing strings in the ciphertext state. As Figure 2 shown, it specifically includes the following steps:
[0081] Step 210: Determine at least two strings to be compared.
[0082] In this embodiment, the way to determine at least two strings to be compared can be to determine each participant P i (i = 1,..., n), and determine each string S to be compared according to the strings corresponding to each participant i (i = 1,..., n).
[0083] Step 220: Generate the ciphertext corresponding to each string according to the at least two strings.
[0084] In this embodiment, the ciphertexts corresponding to the respective strings can be generated using an encryption algorithm, and each participant can sequentially generate the ciphertext corresponding to themselves.
[0085] Optionally, the method for generating the ciphertexts corresponding to the respective strings may be: for each string, respectively generate the corresponding binary vector; respectively perform Gödel encoding on the binary vectors and determine the corresponding intermediate values; according to the intermediate values, sequentially generate the corresponding ciphertexts in order.
[0086] Specifically, for the string S i , it can be converted into the corresponding binary vector V i , and the corresponding participant P i can perform Gödel encoding on the binary vector V i and determine the corresponding intermediate value h i . The participant P 1 can calculate the ciphertext c 1 = h 1 n-1 , and then publish it. The participant P i sequentially calculates c i = c i-1 h i -1 , and then sends c i to P i+1 (P n sends c n to P 1 ).
[0087] Furthermore, the method for respectively generating the corresponding binary vectors for each string may be: for each string, convert the individual characters in the string into binary form and represent the string in matrix form; concatenate the elements of each row in the matrix to obtain the corresponding binary vector.
[0088] Specifically, the participant P i converts the individual characters s i (S i = s i1 …s im ) in their respective strings S ij (1 ≤ j ≤ m) into the binary form corresponding to the ASCII code value, such that s ij = s ij1 , …, s iju (if a number is less than u bits, it is supplemented to u bits by padding zeros at the high position), and represents the string S i as the following m × n - order matrix M i :
[0089]
[0090] Then P i Connect the elements of each row of the matrix M i to obtain the binary vector V i :
[0091] V i =(s i11 s i12 …s i1u s i21 …s i2u …s imu ).
[0092] Furthermore, the method of performing Gödel encoding on each binary vector and determining the corresponding intermediate value can be: performing Gödel encoding on each binary vector to determine the Gödel number corresponding to each binary vector; respectively determining the random number corresponding to each binary vector, and determining the corresponding intermediate value according to the random number and the Gödel number corresponding to each binary vector.
[0093] Specifically, the participant P i can use Gödel encoding to establish a one-to-one correspondence between the binary vector V i and the corresponding Gödel number x i * where the Gödel number x i * is a natural number and satisfies:
[0094]
[0095] where p 1 …p t are t consecutive prime numbers.
[0096] Then select the corresponding random number r i , and determine the corresponding intermediate value h i according to r i * and x i :
[0097] h i =x i * ·r i N mod N 2 ,
[0098] where N = pq, and p and q are two large prime numbers.
[0099] Step 230: According to the ciphertext generation order, determine the last ciphertext as the ciphertext to be decrypted.
[0100] In this embodiment, starting from participant P 1 , corresponding ciphertexts can be generated in sequence from P 1 to P n , and then the last generated ciphertext is determined as the ciphertext to be decrypted.
[0101] Optionally, after generating the ciphertexts c 1 …c n for each string, the ciphertext c n can be determined as the ciphertext to be decrypted.
[0102] Step 240: Obtain a private key / public key pair composed of a private key and a public key, and determine the first participant who generates the private key and the public key.
[0103] Among them, the private key / public key pair is generated by the first participant using the Paillier public key system. After the first participant generates the private key and the public key, the public key is published.
[0104] In this embodiment, to decrypt the ciphertext to be decrypted, it is necessary to determine the private key / public key pair and the first participant who generates the private key and the public key.
[0105] Optionally, the first participant can be P 1 , the private key generated by P 1 is λ, the public key is (g, N), and the generation methods of the public key and the private key are as follows:
[0106] Select two large prime numbers p and q, let N = pq, and λ(N) = lcm(p - 1, q - 1). Randomly select one such that gcd(L(g λ mod N 2 ), N) = 1, where
[0107] Step 250: According to the private key / public key pair, let the first participant decrypt the ciphertext to be decrypted to obtain a decryption result. If the decryption is successful, the comparison results of at least two strings are equal.
[0108] In this embodiment, after determining the private key / public key pair and the corresponding first participant, the first participant can be made to decrypt the ciphertext to be decrypted. If the decryption result is 0, the decryption is successful and the strings are equal.
[0109] Optionally, the first participant can be P 1 , the ciphertext to be decrypted is c n , if the decryption result D(c n ) = 0, then the decryption is successful, where D(*) represents the decryption operation.
[0110] According to the Paillier encryption algorithm, D(cn ) = 0 is equivalent to x 1 *n-1 = ∏ i∈(2,n) x i * , where x i * is the natural number corresponding to the binary vector V i obtained by using the Gödel coding method, and the proposition "if and only if x 1 *n-1 = ∏ i∈(2,n) x i * then the string S 1 …S n is equal" can be proven, and when the decryption result D(c n ) = 0, the string S 1 …S n is equal.
[0111] The following is the proof of the above proposition:
[0112] Sufficiency: Since then if x 1 *n-1 = ∏ i∈(2,n) x i * , it means that for each bit x i of the binary characters representing S ij (j = 1,…t), the following holds. Also, because x ij ∈ {0,1} k , so each bit x 2 of the string S…S n is equal to each bit x 2j ,…x nj of S 1 , and thus the string S 1j …S 1 …S n is equal.
[0113] Necessity: If S 1 …S n is equal, then each bit x 2 …x n of the binary string S 2j ,…x nj is equal to each bit x 1 of the binary string S 1j . Thus, we get Also Therefore, x 1 *n-1= ∏ i∈(2,n) x i * 。
[0114] In the embodiment of the present invention, at least two strings to be compared are first determined, then ciphertexts corresponding to each string are generated according to the at least two strings, and then, in the order of ciphertext generation, the last ciphertext is determined as the ciphertext to be decrypted. Then, a private key / public key pair composed of a private key and a public key is obtained, and the first participant who generates the private key and the public key is determined. Finally, according to the private key / public key pair, the first participant decrypts the ciphertext to be decrypted to obtain a decryption result. If the decryption is successful, the comparison result of the at least two strings is equal. The string comparison method provided by the embodiment of the present invention combines Gödel coding with the Paillier encryption algorithm to construct a new type of homomorphic encryption scheme, solves the problem of string comparison in the ciphertext state, can correctly decrypt the ciphertext only when the calculation result is 0, can resist the collusion attack of any participant, improves the security of string comparison, and only requires one decryption operation and n - 1 communications, reducing the computational complexity and communication complexity.
[0115] Embodiment III
[0116] Figure 3 is a schematic structural diagram of a string comparison device provided by Embodiment III of the present invention. As Figure 3 shown, the device includes: a string determination module 310, a ciphertext to be decrypted generation module 320, and a decryption module 330.
[0117] The string determination module 310 is used to determine at least two strings to be compared.
[0118] The ciphertext to be decrypted generation module 320 is used to generate the ciphertext to be decrypted according to at least two strings.
[0119] The decryption module 330 is used to decrypt the ciphertext to be decrypted. If the decryption is successful, the comparison result of at least two strings is equal.
[0120] Optionally, the ciphertext to be decrypted generation module 320 is further used for:
[0121] generating ciphertexts corresponding to each string according to at least two strings; and determining the last ciphertext as the ciphertext to be decrypted in the order of ciphertext generation.
[0122] Optionally, the ciphertext to be decrypted generation module 320 is further used for:
[0123] generating corresponding binary vectors for each string respectively; performing Gödel coding on each binary vector respectively and determining corresponding intermediate values; and generating corresponding ciphertexts in sequence according to each intermediate value.
[0124] Optionally, the ciphertext to be decrypted generation module 320 is further configured to:
[0125] For each string, convert the individual characters in the string into binary form and represent the string in matrix form; concatenate the elements in each row of the matrix to obtain the corresponding binary vector.
[0126] Optionally, the ciphertext to be decrypted generation module 320 is further configured to:
[0127] Perform Gödel encoding on each binary vector to determine the Gödel number corresponding to each binary vector; respectively determine the random number corresponding to each binary vector, and determine the corresponding intermediate value according to the random number and the Gödel number corresponding to each binary vector.
[0128] Optionally, the decryption module 330 is further configured to:
[0129] Obtain a private key / public key pair composed of a private key and a public key, and determine the first participant who generated the private key and the public key; according to the private key / public key pair, instruct the first participant to decrypt the ciphertext to be decrypted and obtain the decryption result.
[0130] The above device can execute the methods provided in all the foregoing embodiments of the present disclosure, and has the corresponding functional modules and beneficial effects for executing the above methods. For technical details not described in detail in this embodiment, reference can be made to the methods provided in all the foregoing embodiments of the present disclosure.
[0131] Embodiment 4
[0132] Figure 4 FIG. is a schematic structural diagram of a computer device provided in Embodiment 4 of the present invention. Figure 4 FIG. shows a block diagram of a computer device 412 suitable for implementing the embodiments of the present invention. Figure 4 The computer device 412 shown is only an example and should not impose any limitation on the functions and usage scope of the embodiments of the present invention. The device 412 is a typical device for string comparison calculation.
[0133] As Figure 4 shown, the computer device 412 is presented in the form of a general-purpose computing device. The components of the computer device 412 may include, but are not limited to: one or more processors 416, a storage device 428, and a bus 418 connecting different system components (including the storage device 428 and the processor 416).
[0134] The bus 418 represents one or more of several types of bus architectures, including a memory bus or memory controller, a peripheral bus, an Accelerated Graphics Port, a processor, or a local bus using any of the multiple bus architectures. By way of example, these architectures include, but are not limited to, Industry Standard Architecture (ISA) bus, Micro Channel Architecture (MCA) bus, Enhanced ISA bus, Video Electronics Standards Association (VESA) local bus, and Peripheral Component Interconnect (PCI) bus.
[0135] The computer device 412 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by the computer device 412, including volatile and nonvolatile media, removable and non-removable media.
[0136] The storage device 428 may include computer system readable media in the form of volatile memory, such as Random Access Memory (RAM) 430 and / or cache memory 432. The computer device 412 may further include other removable / non-removable, volatile / nonvolatile computer system storage media. By way of example only, the storage system 434 may be used for reading and writing on non-removable, nonvolatile magnetic media ( Figure 4 not shown, typically referred to as a "hard disk drive"). Although Figure 4 not shown in the figure, a disk drive for reading and writing on removable nonvolatile disks (such as a "floppy disk"), and an optical disk drive for reading and writing on removable nonvolatile optical disks (such as Compact Disc-Read Only Memory (CD-ROM), Digital Video Disc-Read Only Memory (DVD-ROM), or other optical media) may be provided. In these cases, each drive may be connected to the bus 418 through one or more data media interfaces. The storage device 428 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of the embodiments of the present invention.
[0137] A program 436 having a set (at least one) of program modules 426 can be stored, for example, in a storage device 428. Such program modules 426 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include the implementation of a network environment. The program modules 426 generally execute the functions and / or methods in the embodiments described in the present invention.
[0138] The computer device 412 can also communicate with one or more external devices 414 (such as a keyboard, a pointing device, a camera, a display 424, etc.), and can also communicate with one or more devices that enable a user to interact with the computer device 412, and / or communicate with any device that enables the computer device 412 to communicate with one or more other computing devices (such as a network card, a modem, etc.). Such communication can be carried out through an input / output (I / O) interface 422. In addition, the computer device 412 can also communicate with one or more networks (such as a Local Area Network (LAN), a Wide Area Network (WAN), and / or a public network, such as the Internet) through a network adapter 420. As shown in the figure, the network adapter 420 communicates with other modules of the computer device 412 through a bus 418. It should be understood that although not shown in the figure, other hardware and / or software modules can be used in combination with the computer device 412, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, Redundant Arrays of Independent Disks (RAID) systems, tape drives, and data backup storage systems, etc.
[0139] The processor 416 executes various functional applications and data processing by running the programs stored in the storage device 428, such as implementing the string comparison method provided in the above embodiments of the present invention.
[0140] Embodiment Five
[0141] An embodiment of the present invention provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processing device, it implements the method for comparing strings in the embodiment of the present invention. The computer-readable medium described above in the present invention may be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, a computer-readable storage medium may be any tangible medium that contains or stores a program, and the program can be used by or in combination with an instruction execution system, apparatus, or device. In the present disclosure, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, in which computer-readable program code is carried. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium, and the computer-readable signal medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device. The program code contained on a computer-readable medium can be transmitted by any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.
[0142] In some embodiments, the client and the server can communicate using any currently known or future-developed network protocol such as HTTP (HyperText Transfer Protocol), and can be interconnected with digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include local area networks ("LANs"), wide area networks ("WANs"), the Internet (e.g., the Internet), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed networks.
[0143] The above computer-readable medium may be included in the above electronic device; or it may exist separately without being assembled into the electronic device.
[0144] The above computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to: determine at least two strings to be compared; generate a ciphertext to be decrypted based on the at least two strings; decrypt the ciphertext to be decrypted, and if the decryption is successful, the comparison result of the at least two strings is equal.
[0145] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages or combinations thereof. The programming languages include, but are not limited to, object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may execute entirely on the user's computer, partially on the user's computer, execute as a stand-alone software package, execute partially on the user's computer and partially on a remote computer, or execute entirely on the remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network connection, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0146] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system for performing the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.
[0147] The units involved in the embodiments described in the present disclosure may be implemented in software or in hardware. In some cases, the name of the unit does not constitute a limitation on the unit itself.
[0148] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. By way of example, and without limitation, the types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), and the like.
[0149] In the context of this disclosure, a machine-readable medium may be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0150] Note that the above are only the preferred embodiments of the present invention and the technical principles applied. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein, and various obvious changes, re-adjustments, and substitutions can be made by those skilled in the art without departing from the protection scope of the present invention. Therefore, although the present invention has been described in more detail through the above embodiments, the present invention is not limited to the above embodiments. Without departing from the concept of the present invention, it may also include more other equivalent embodiments, and the scope of the present invention is determined by the scope of the appended claims.
Claims
1. A method for string comparison, characterized in that, it includes: Determine at least two strings to be compared; According to the at least two strings, for each string, generate corresponding binary vectors respectively, perform Gödel encoding on each binary vector, and determine the Gödel number corresponding to each binary vector; where the Gödel number is represented as x i * , x i * is a natural number and satisfies where s i11 ,…, s imu are elements in the binary vector, x i1 ,…, x it are t natural numbers, p 1 … p t are t consecutive prime numbers; determine the random number corresponding to each binary vector respectively, and determine the corresponding intermediate value according to the random number and the Gödel number corresponding to each binary vector; where the intermediate value is represented as h i , and satisfies h i =x i * ·r i N mod N 2 , where x i * is the Gödel number, r i is the random number, N = pq, p and q are two large prime numbers; according to each intermediate value, generate corresponding ciphertexts in sequence, and according to the ciphertext generation order, determine the last ciphertext as the ciphertext to be decrypted; Obtain a private key / public key pair composed of a private key and a public key, and determine a first participant who generates the private key and the public key. According to the private key / public key pair, let the first participant decrypt the ciphertext to be decrypted and obtain a decryption result. If the decryption is successful, the comparison result of the at least two strings is equal; wherein, the private key and the public key are generated by the first participant using the Paillier public key system.
2. The method according to claim 1, characterized in that, The at least two strings correspond one-to-one with at least two participants, and each participant stores their respective corresponding string.
3. The method according to claim 1, characterized in that, For each string, generate a corresponding binary vector, including: For each string, convert a single character in the string into a binary form and represent the string in a matrix form; Connect the elements of each row in the matrix to obtain a corresponding binary vector.
4. A string comparison device, characterized in that, it includes: A string determination module for determining at least two strings to be compared; The to-be-decrypted ciphertext generation module is used to, according to the at least two strings, for each string, respectively generate a corresponding binary vector, perform Gödel encoding on each binary vector, and determine the Gödel number corresponding to each binary vector; wherein, the Gödel number is represented as x i * , x i * is a natural number and satisfies where s i11 ,…, s imu are elements in the binary vector, x i1 ,…, x it are t natural numbers, p 1 … p t are t consecutive prime numbers; respectively determine the random number corresponding to each binary vector, and determine the corresponding intermediate value according to the random number and the Gödel number corresponding to each binary vector; wherein, the intermediate value is represented as h i , and satisfies h i = x i * · r i N mod N 2 , where x i * is the Gödel number, r i is the random number, N = pq, and p and q are two large prime numbers; according to each intermediate value, generate corresponding ciphertexts in sequence, and according to the ciphertext generation order, determine the last ciphertext as the to-be-decrypted ciphertext; A decryption module for obtaining a private key / public key pair composed of a private key and a public key, and determining a first participant who generates the private key and the public key. According to the private key / public key pair, let the first participant decrypt the ciphertext to be decrypted and obtain a decryption result. If the decryption is successful, the comparison result of the at least two strings is equal; wherein, the private key and the public key are generated by the first participant using the Paillier public key system.
5. A computer device, characterized in that, it includes: A memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the string comparison method according to any one of claims 1-3.
6. A computer-readable storage medium, on which a computer program is stored, characterized in that, When the program is executed by a processing device, it implements the string comparison method according to any one of claims 1-3.