Ciphertext Data Sharing Method, Apparatus, Device, and Medium
By processing component ciphertext data at multiple data encryption ends in the component channel module, generating component aggregate ciphertext data and sending it to the receiving end, the problem of data security risks during key distribution and ciphertext data transmission is solved, and high security in the data transmission process is achieved.
Patent Information
- Application Number
- CN202210291968.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-03-23
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2042-03-23
AI Technical Summary
During the process of key distribution and ciphertext data transmission, there are data security risks, which are prone to brute-force cracking and data leakage.
By obtaining component ciphertext data from multiple data encryption terminals in the component channel module, processing these data according to preset rules, generating component aggregate ciphertext data, and sending it to the data receiving terminal. This method uses homomorphic encryption algorithms and exclusive OR algorithms to ensure the security of data during transmission.
By dispersed ciphertext data storage and processing, the risk of attack on a single component channel is reduced, security during data transmission is improved, and data leakage is avoided.
Smart Images

Figure CN114598448B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of information security technology, and particularly to a method, apparatus, device, medium and program product for sharing ciphertext data. Background Art
[0002] Data encryption technology can encrypt plaintext data using a key to obtain ciphertext data, and then send the ciphertext data to the relevant data receiving end. The data receiving end decrypts the received ciphertext data using the corresponding key, thereby realizing data security during data transmission and avoiding leakage of important data information.
[0003] In the process of implementing the inventive concept of the present disclosure, the inventors found that there are data security risks during the distribution of keys and the transmission of ciphertext data, and it is easy to be violently cracked resulting in data leakage. Summary of the Invention
[0004] In view of the above problems, the present disclosure provides a method, apparatus, device, medium and program product for sharing ciphertext data.
[0005] According to a first aspect of the present disclosure, there is provided a method for sharing ciphertext data, which is applied to a component channel module. The component channel module includes L component channel ends. The method includes:
[0006] Obtain respective component ciphertext data from N data encryption ends. The component ciphertext data is obtained by encrypting component plaintext data based on a homomorphic encryption algorithm. The component ciphertext data is stored in the L component channel ends. Each data encryption end sends component ciphertext data to K component channel ends, where L > K ≥ 2. The component channel ends store respective component ciphertext data of M data encryption ends, and N > M ≥ 1;
[0007] At the component channel ends, process the M component ciphertext data according to a preset rule to obtain component aggregated ciphertext data;
[0008] Send respective component aggregated ciphertext data of the L component channel ends to a data receiving end. The data receiving end generates target plaintext data based on the respective component aggregated ciphertext data of the L component channel ends.
[0009] According to an embodiment of the present disclosure, the component plaintext data includes key component plaintext data, and the key component plaintext data is generated based on a key generator;
[0010] Wherein, the key generator includes a quantum random number generator.
[0011] According to an embodiment of the present disclosure, at the above-mentioned component channel end, processing M component ciphertext data according to a preset rule to obtain component aggregated ciphertext data includes:
[0012] At the above-mentioned component channel end, calculating M component ciphertext data according to the XOR algorithm to obtain the above-mentioned component aggregated ciphertext data.
[0013] According to an embodiment of the present disclosure, at the above-mentioned component channel end, processing M component ciphertext data according to a preset rule to obtain component aggregated ciphertext data includes:
[0014] At the above-mentioned component channel end, splicing M component ciphertext data according to a preset splicing rule to obtain the above-mentioned component aggregated ciphertext data.
[0015] A second aspect of the present disclosure provides a ciphertext data sharing method, which is applied to a data encryption module. The above-mentioned data encryption module includes N data encryption ends. The above-mentioned method includes:
[0016] Each of the N above-mentioned data encryption ends encrypts the component plaintext data based on the homomorphic encryption algorithm to obtain the component ciphertext data of each of the N above-mentioned data encryption ends;
[0017] Each of the above-mentioned data encryption ends sends the component ciphertext data to K component channel ends in the component channel module according to a preset sending rule. Among them, the above-mentioned component channel module includes L above-mentioned component channel ends, L>K≥2, and the above-mentioned component channel ends store the component ciphertext data of each of the M data encryption ends, N>M≥1.
[0018] According to an embodiment of the present disclosure, the above-mentioned component plaintext data includes key component plaintext data, and the above-mentioned key component plaintext data is generated based on a key generator;
[0019] Among them, the above-mentioned key generator includes a quantum random number generator.
[0020] According to an embodiment of the present disclosure, each of the N above-mentioned data encryption ends encrypts the component plaintext data based on the homomorphic encryption algorithm to obtain the component ciphertext data of each of the N above-mentioned data encryption ends includes:
[0021] Each of the N above-mentioned data encryption ends performs b XOR calculations on the above-mentioned component plaintext data to obtain the first calculated value of each of the N above-mentioned data encryption ends;
[0022] Taking the modulo of the first calculated value of each of the N above-mentioned data encryption ends by the natural number n to obtain the component ciphertext data of each of the N above-mentioned data encryption ends.
[0023] The third aspect of the present disclosure provides a method for sharing ciphertext data, which is applied to a data encryption module and a component channel module. The data encryption module includes N data encryption terminals, and the component channel module includes L component channel terminals, including:
[0024] Each of the N data encryption terminals of the data encryption module encrypts the component plaintext data based on the homomorphic encryption algorithm to obtain the component ciphertext data of each of the N data encryption terminals;
[0025] Each data encryption terminal sends the component ciphertext data to K component channel terminals in the component channel module according to a preset sending rule, where L > K ≥ 2;
[0026] The component channel module obtains the component ciphertext data from each of the N data encryption terminals. The component ciphertext data is stored in the L component channel terminals, and each component channel terminal stores the component ciphertext data of M data encryption terminals, where N > M ≥ 1;
[0027] At the component channel terminal, M component ciphertext data is processed according to a preset rule to obtain component aggregated ciphertext data;
[0028] Send the component aggregated ciphertext data of each of the L component channel terminals to the data receiving end, where the data receiving end generates target plaintext data based on the component aggregated ciphertext data of each of the L component channel terminals.
[0029] The fourth aspect of the present disclosure provides a ciphertext data sharing device, including:
[0030] An acquisition module, configured to acquire the component ciphertext data from each of the N data encryption terminals, where the component ciphertext data is obtained by encrypting the component plaintext data based on the homomorphic encryption algorithm. The component ciphertext data is stored in the L component channel terminals, and each data encryption terminal sends the component ciphertext data to K component channel terminals, L > K ≥ 2, and each component channel terminal stores the component ciphertext data of M data encryption terminals, where N > M ≥ 1;
[0031] A processing module, configured to process M component ciphertext data at the component channel terminal according to a preset rule to obtain component aggregated ciphertext data;
[0032] A first sending module, configured to send the component aggregated ciphertext data of each of the L component channel terminals to the data receiving end, where the data receiving end generates target plaintext data based on the component aggregated ciphertext data of each of the L component channel terminals.
[0033] The fifth aspect of the present disclosure provides a ciphertext data sharing device, including:
[0034] An encryption module, configured to encrypt the component plaintext data by each of the N data encryption ends based on a homomorphic encryption algorithm, so as to obtain the component ciphertext data of each of the N data encryption ends;
[0035] A second sending module, configured to send the component ciphertext data to K component channel ends in a component channel module by each of the data encryption ends according to a preset sending rule, where the component channel module includes L component channel ends, L > K ≥ 2, and each of the component channel ends stores the component ciphertext data of M data encryption ends, N > M ≥ 1.
[0036] A sixth aspect of the present disclosure provides an electronic device, including: one or more processors; a memory, configured to store one or more programs, where when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the above-mentioned ciphertext data sharing method.
[0037] A seventh aspect of the present disclosure further provides a computer-readable storage medium, on which executable instructions are stored, and when the instructions are executed by a processor, the processor is caused to execute the above-mentioned ciphertext data sharing method.
[0038] An eighth aspect of the present disclosure further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the above-mentioned ciphertext data sharing method is implemented. Description of the Drawings
[0039] Through the following description of the embodiments of the present disclosure with reference to the drawings, the above-mentioned content and other objects, features, and advantages of the present disclosure will become clearer. In the drawings:
[0040] Figure 1 Schematically shows an application scenario diagram of a ciphertext data sharing method and apparatus according to an embodiment of the present disclosure;
[0041] Figure 2 Schematically shows a flowchart of a ciphertext data sharing method according to an embodiment of the present disclosure;
[0042] Figure 3 Schematically shows a flowchart of a ciphertext data sharing method according to another embodiment of the present disclosure;
[0043] Figure 4 Schematically shows a flowchart of encrypting component plaintext data by each of the N data encryption ends based on a homomorphic encryption algorithm according to an embodiment of the present disclosure to obtain the component ciphertext data of each of the N data encryption ends;
[0044] Figure 5 Schematically shows a flowchart of a ciphertext data sharing method according to still another embodiment of the present disclosure;
[0045] Figure 6Schematically shows an application scenario diagram of a ciphertext data sharing method according to an embodiment of the present disclosure;
[0046] Figure 7 Schematically shows a structural block diagram of a ciphertext data sharing device according to an embodiment of the present disclosure;
[0047] Figure 8 Schematically shows a structural block diagram of a ciphertext data sharing device according to another embodiment of the present disclosure; and
[0048] Figure 9 Schematically shows a block diagram of an electronic device suitable for implementing the ciphertext data sharing method according to an embodiment of the present disclosure Detailed implementation manners
[0049] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the following detailed description, for the sake of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure. However, obviously, one or more embodiments can also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessarily confusing the concepts of the present disclosure.
[0050] The terms used herein are merely for describing specific embodiments and are not intended to limit the present disclosure. The terms "including", "comprising", etc. used herein indicate the presence of the described features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0051] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.
[0052] In the case of using expressions such as "at least one of A, B, and C", generally, it should be interpreted according to the meaning commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include, but is not limited to, a system having only A, only B, only C, having A and B, having A and C, having B and C, and / or having A, B, and C, etc.).
[0053] Embodiments of the present disclosure provide a method for sharing ciphertext data, which is applied to a component channel module. The component channel module includes L component channel ends. The method for sharing ciphertext data includes: obtaining respective component ciphertext data from N data encryption ends. The component ciphertext data is obtained by encrypting component plaintext data based on a homomorphic encryption algorithm. The component ciphertext data is stored in the L component channel ends. Each data encryption end sends the component ciphertext data to K component channel ends. L > K ≥ 2. The component channel ends store respective component ciphertext data of M data encryption ends among the N data encryption ends. N > M ≥ 1; at the component channel ends, processing the M component ciphertext data according to a preset rule to obtain component aggregated ciphertext data; sending the respective component aggregated ciphertext data of the L component channel ends to a data receiving end. The data receiving end generates target plaintext data based on the respective component aggregated ciphertext data of the L component channel ends.
[0054] According to the embodiments of the present disclosure, since each data encryption end sends the component ciphertext data to K component channel ends, and the component channel ends store respective component ciphertext data of M data encryption ends among the N data encryption ends, N > M ≥ 1, L > K ≥ 2, each component channel can only contain M of the N component ciphertext data, that is, each component channel cannot obtain all M component ciphertext data for generating the target plaintext data. Therefore, it is impossible to obtain the target plaintext data by attacking one component channel, so that the ciphertext data is prevented from being stolen during the process of being shared to the data receiving end, ensuring the data security of the component ciphertext data during data transmission.
[0055] Embodiments of the present disclosure also provide a method for sharing ciphertext data, which is applied to a data encryption module. The data encryption module includes N data encryption ends. The method for sharing ciphertext data includes:
[0056] Each of the N data encryption ends encrypts the component plaintext data based on a homomorphic encryption algorithm to obtain respective component ciphertext data of the N data encryption ends; each data encryption end sends the component ciphertext data to K component channel ends in the component channel module according to a preset sending rule. The component channel module includes L component channel ends. L > K ≥ 2. The component channel ends store respective component ciphertext data of M data encryption ends among the N data encryption ends. N > M ≥ 1.
[0057] In the technical solution of the present disclosure, the processing of collection, storage, use, processing, transmission, provision, disclosure, and application of the user's personal information involved all comply with the provisions of relevant laws and regulations, take necessary confidentiality measures, and do not violate public order and good customs.
[0058] In the technical solution of the present disclosure, before obtaining or collecting the user's personal information, the authorization or consent of the user is obtained.
[0059] Figure 1Schematically shows an application scenario diagram of the ciphertext data sharing method according to an embodiment of the present disclosure.
[0060] As Figure 1 shown, the application scenario 100 according to this embodiment may include terminal devices 101, 102, 103, a network 104, a component channel module 110, and a data encryption module 120. The component channel module 110 includes component channel ends 111, 112, 113, 114, and the data encryption module 120 includes data encryption ends 121, 122, 123, 124. The network 104 is used to provide a medium for communication links between the terminal devices 101, 102, 103 and the component channel module 110. The network 104 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.
[0061] Users can use the terminal devices 101, 102, 103 to interact with the server 105 through the network 104 to receive or send messages, etc. Various communication client applications may be installed on the terminal devices 101, 102, 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (only as examples).
[0062] The terminal devices 101, 102, 103 may be various electronic devices with a display screen and supporting web browsing, including but not limited to smart phones, tablet computers, laptop portable computers, and desktop computers, etc.
[0063] The data encryption ends 121, 122, 123, 124, and the component channel ends 111, 112, 113, 114 may be servers providing various services. For example, for the component aggregation ciphertext data that users can receive using the terminal devices 101, 102, 103, the data encryption ends 121, 122, 123, 124 may send the component ciphertext data to the component channel ends 111, 112, 113, 114. The background management server may analyze and process data such as received user requests, etc., and feedback the processing results (such as web pages, information, or data, etc. obtained or generated according to user requests) to the terminal devices.
[0064] It should be noted that the ciphertext data sharing method provided by the embodiments of the present disclosure can generally be executed by the component channel module 110 and the data encryption module 120. Correspondingly, the ciphertext data sharing device provided by the embodiments of the present disclosure can generally be arranged in the component channel module 110 and the data encryption module 120. The component channel ends 111, 112, 113, 114 in the component channel module 110 can be arranged in different servers / server clusters, or can be arranged in different functional modules in the same server / server cluster. The data encryption ends 121, 122, 123, 124 of the data encryption module 120 can be a key management center with relevant permissions, or can be a server / server cluster with data encryption functions.
[0065] It should be understood that Figure 1 the numbers of the terminal devices, networks, and servers in
[0066] are merely illustrative. According to the implementation requirements, there can be any number of terminal devices, networks, and servers. Figure 1 The following will be based on Figures 2 to 6 the described scenario, and will describe in detail the ciphertext data sharing method of the public embodiments through
[0067] Figure 2 FIG. schematically shows a flowchart of the ciphertext data sharing method according to an embodiment of the present disclosure.
[0068] As Figure 2 shown, the ciphertext data sharing method is applied to the component channel module. The component channel module includes L component channel ends, and the method includes operations S210 to S230.
[0069] In operation S210, obtain the component ciphertext data from each of the N data encryption ends. Among them, the component ciphertext data is obtained by encrypting the component plaintext data based on the homomorphic encryption algorithm. The component ciphertext data is stored in the L component channel ends. Each data encryption end sends the component ciphertext data to K component channel ends, L > K ≥ 2. The component channel ends store the component ciphertext data of each of the M data encryption ends, N > M ≥ 1.
[0070] In operation S220, at the component channel ends, process the M component ciphertext data according to a preset rule to obtain the component aggregated ciphertext data.
[0071] In operation S230, send the component aggregated ciphertext data of each of the L component channel ends to the data receiving end. Among them, the data receiving end generates the target plaintext data based on the component aggregated ciphertext data of each of the L component channel ends.
[0072] According to an embodiment of the present disclosure, the target plaintext data may be the plaintext data obtained by synthesizing the component plaintext data of N data encryption ends, that is, the component plaintext data may be sub-shares of the target plaintext data. Since each of the N data encryption ends encrypts its respective component plaintext data based on the homomorphic encryption algorithm, that is, each of the N data encryption ends encrypts its respective component plaintext data based on the same encryption function to obtain component ciphertext data, the data receiving end can, after obtaining the N component ciphertext data, fuse the N component ciphertext data according to the same method and decrypt them according to the decryption function corresponding to the encryption function to obtain the target plaintext data.
[0073] According to an embodiment of the present disclosure, the component ciphertext data may include any type of data obtained after the component plaintext data passes through the homomorphic encryption algorithm. The component plaintext data may be, for example, text data, picture data, etc.
[0074] According to an embodiment of the present disclosure, the data encryption end may encrypt the component plaintext data after obtaining it, or may also generate the component plaintext data at the data encryption end based on relevant rules, as long as it can be ensured that the N component plaintext data generated by each of the N data encryption ends can determine the target plaintext data.
[0075] According to an embodiment of the present disclosure, processing M component ciphertext data according to a preset rule to obtain component aggregated ciphertext data may be to calculate the M component ciphertext data based on a relevant algorithm to obtain the component aggregated ciphertext data, or may also be to encrypt the M component ciphertext data to obtain the component aggregated ciphertext data. However, it is not limited to this. It may also be to splice the M component ciphertext data according to a preset splicing order to obtain the component aggregated ciphertext data. The embodiment of the present disclosure does not limit the specific manner of obtaining the component aggregated ciphertext data, and those skilled in the art can select according to the actual situation.
[0076] In this embodiment, the component plaintext data may include key component plaintext data, that is, sub-shares of the key, and the target plaintext data may include the target key. After the data receiving end obtains the component aggregated ciphertext data of each of the L component channel ends, it can, after filtering out duplicate component ciphertext data, obtain the key component plaintext data of each of the N data encryption ends, and determine the target key based on the key component plaintext data of each of the N data encryption segments, thereby realizing sharing the key with the data receiving end and ensuring data security during the key sharing process.
[0077] According to an embodiment of the present disclosure, the component plaintext data may include key component plaintext data, and the key component plaintext data is generated based on a key generator; wherein, the key generator includes a quantum random number generator.
[0078] According to an embodiment of the present disclosure, the key generator may include a random number generator for generating a random number sequence. The random number sequence generated by the random number generator has characteristics such as unpredictability and non-repeatability. Therefore, it is difficult to crack the plaintext data of the key component based on the random number generator, thereby strengthening the security attribute during the data transmission process at the source of the plaintext data of the key component.
[0079] According to an embodiment of the present disclosure, the random number generator may include a software random number generator constructed based on a software algorithm, a hardware random number generator constructed based on hardware, and a quantum random number generator. The quantum random number generator is a system that generates true random numbers based on quantum physical principles or quantum effects. Since the quantum random number generator generates random numbers based on quantum random effects and does not have the regularity of related software algorithms, it is difficult to crack the plaintext data of the key component based on the quantum random number generator, which is suitable for further enhancing the data security attribute during the data transmission process of the key sharing process.
[0080] According to an embodiment of the present disclosure, in the case where the component plaintext data is the plaintext data of the key component, the component plaintext data may include a hexadecimal number sequence. In the case where the random number sequence generated by the quantum random number generator is a binary number sequence, the binary number sequence can be converted into a hexadecimal number sequence based on a related conversion method, thereby obtaining the plaintext data of the component key.
[0081] It should be noted that each of the N data encryption terminals can convert the random number sequence into a hexadecimal number sequence based on the same method, and then obtain the plaintext data of its respective component key.
[0082] According to an embodiment of the present disclosure, for operation S220, at the component channel end, processing the M component ciphertext data according to a preset rule to obtain the component aggregated ciphertext data may include the following operations.
[0083] At the component channel end, calculate the M component ciphertext data according to the XOR algorithm to obtain the component aggregated ciphertext data.
[0084] According to an embodiment of the present disclosure, the component plaintext data may be a hexadecimal number sequence, and the component ciphertext data obtained by encrypting the component plaintext data using an encryption function may also be a hexadecimal number sequence. Encrypting the M component ciphertext data using the XOR algorithm may be to perform bitwise XOR on the M hexadecimal number sequences to obtain the component aggregated ciphertext data.
[0085] It should be noted that the number of K can be odd. Therefore, after the data receiving end receives the component aggregated ciphertext data sent by each of the L component channel ends, based on the characteristics of the XOR algorithm, the duplicate component ciphertext data in the L component aggregated ciphertext data sent by the L component channel ends can be filtered out, and the component ciphertext data of each of the N data encryption ends can be obtained.
[0086] According to an embodiment of the present disclosure, for operation S220, at the component channel end, processing M component ciphertext data according to a preset rule to obtain component aggregated ciphertext data may include the following operations.
[0087] At the component channel end, splice the M component ciphertext data according to a preset splicing rule to obtain component aggregated ciphertext data.
[0088] According to an embodiment of the present disclosure, the preset splicing rule may include splicing the M component ciphertext data in a preset order. The data receiving end can split the component aggregated ciphertext data obtained after splicing according to the same preset order, so as to obtain M component ciphertext data. After the data receiving end receives the L component aggregated ciphertext data sent by each of the L component channel ends, it can first split the L component aggregated ciphertext data in a preset order, then determine the duplicate component ciphertext data based on a relevant matching method, and after filtering out the duplicate component ciphertext data, it can obtain the N component ciphertext data sent by each of the N data encryption ends.
[0089] According to an embodiment of the present disclosure, processing M component ciphertext data according to a preset rule to obtain component aggregated ciphertext data can reduce the calculation steps for the data receiving end to process the component aggregated ciphertext data and improve the timeliness of obtaining the target plaintext data.
[0090] Figure 3 Schematically shows a flowchart of a ciphertext data sharing method according to another embodiment of the present disclosure.
[0091] As Figure 3 shown, the ciphertext data sharing method is applied to a data encryption module. The data encryption module includes N data encryption ends. The ciphertext data sharing method includes operation S310 to operation S320.
[0092] In operation S310, each of the N data encryption ends encrypts the component plaintext data based on a homomorphic encryption algorithm to obtain the component ciphertext data of each of the N data encryption ends.
[0093] In operation S320, each data encryption end sends the component ciphertext data to K component channel ends in the component channel module according to a preset sending rule. Among them, the component channel module includes L component channel ends, L > K ≥ 2, and the component channel ends store the component ciphertext data of each of the M data encryption ends, N > M ≥ 1.
[0094] According to an embodiment of the present disclosure, N data encryption terminals may encrypt component plaintext data based on the same encryption function, and the encryption function f(x) needs to satisfy formula (1).
[0095] f(x1) ⊙ f(x2) ⊙ f(x3) ⊙ f(x4) = f(x1 ⊙ x2 ⊙ x3 ⊙ x4) (1)
[0096] In formula (1), x1, x2, x3, and x4 represent component plaintext data, and ⊙ represents a homomorphic operation symbol, which may include, for example, additive homomorphism, multiplicative homomorphism, exclusive-or homomorphism, etc.
[0097] According to an embodiment of the present disclosure, the component plaintext data may include key component plaintext data, and the key component plaintext data is generated based on a key generator; wherein, the key generator includes a quantum random number generator.
[0098] Figure 4 Schematically shows a flowchart of N data encryption terminals respectively encrypting component plaintext data based on a homomorphic encryption algorithm to obtain respective component ciphertext data of the N data encryption terminals according to an embodiment of the present disclosure.
[0099] As Figure 4 shown, in operation S310, N data encryption terminals respectively encrypt component plaintext data based on a homomorphic encryption algorithm to obtain respective component ciphertext data of the N data encryption terminals, which may include operations S410 to S420.
[0100] In operation S410, N data encryption terminals respectively perform b exclusive-or calculations on the component plaintext data to obtain respective first calculated values of the N data encryption terminals;
[0101] In operation S420, the respective first calculated values of the N data encryption terminals are modulo-divided by the natural number n to obtain respective component ciphertext data of the N data encryption terminals.
[0102] According to an embodiment of the present disclosure, formula (2) may represent the specific process of a data encryption terminal encrypting component plaintext data.
[0103] f(x) = x b mod n (2)
[0104] In formula (2), x b represents performing b exclusive-or calculations on the component plaintext data x, and n represents a natural number.
[0105] After encrypting four component plaintext data x1, x2, x3, and x4 according to formula (2), formula (1) can be satisfied.
[0106] It should be noted that the ciphertext data sharing method according to the embodiments of the present disclosure can refer to the specific explanations of the above embodiments, and will not be elaborated herein.
[0107] Figure 5 FIG. schematically shows a flowchart of a ciphertext data sharing method according to another embodiment of the present disclosure.
[0108] As Figure 5 shown, the ciphertext data sharing method is applied to a data encryption module and a component channel module. The data encryption module includes N data encryption terminals, and the component channel module includes L component channel terminals. The ciphertext data sharing method includes operations S510 to S550.
[0109] In operation S510, the N data encryption terminals of the data encryption module each encrypt the component plaintext data based on a homomorphic encryption algorithm to obtain the component ciphertext data of each of the N data encryption terminals.
[0110] In operation S520, each data encryption terminal sends the component ciphertext data to K component channel terminals in the component channel module according to a preset sending rule, where L > K ≥ 2.
[0111] In operation S530, the component channel module obtains the component ciphertext data from each of the N data encryption terminals. Among them, the component ciphertext data is stored in the L component channel terminals, and each component channel terminal stores the component ciphertext data of M data encryption terminals, where N > M ≥ 1.
[0112] In operation S540, at the component channel terminal, M component ciphertext data is processed according to a preset rule to obtain component aggregated ciphertext data.
[0113] In operation S550, the component aggregated ciphertext data of each of the L component channel terminals is sent to a data receiving end, where the data receiving end generates target plaintext data based on the component aggregated ciphertext data of each of the L component channel terminals.
[0114] It should be noted that the ciphertext data sharing method according to the embodiments of the present disclosure can refer to the specific explanations of the above embodiments, and will not be elaborated herein.
[0115] Figure 6 FIG. schematically shows an application scenario diagram of the ciphertext data sharing method according to the embodiments of the present disclosure.
[0116] As Figure 6As shown, the data encryption module 610 includes data encryption ends 611, 612, 613, 614. In each data encryption end, a key generator 6111, 6121, 6131, 6141 can be included. Among them, the key generators 6111, 6141 can be quantum random number generators, the key generator 6121 can be a software random number generator, and the key generator 6131 can be a hardware random number generator. The component channel module 620 includes component channel ends 621, 622, 623, 624.
[0117] The key generators 6111, 6121, 6131, 6141 can each generate key component plaintext data A1, B1, C1, D1. It should be noted that the key component plaintext data A1, B1, C1, D1 can be a hexadecimal random number sequence.
[0118] The data encryption ends 611, 612, 613, 614 can each further include encryption units 6112, 6122, 6132, 6142. Each encryption unit can homomorphically encrypt the key component plaintext data A1, B1, C1, D1 according to the encryption function of formula (2) to obtain key component ciphertext data A2, B2, C2, D2. That is, f(A1) = A1 b mod n = A2, f(B1) = B1 b mod n = B2, f(C1) = C1 b mod n = C2, f(D1) = D1 b mod n = D2.
[0119] The data encryption end 611 can send the key component ciphertext data A2 to the component channel ends 621, 622, 623, the data encryption end 612 can send the key component ciphertext data B2 to the component channel ends 622, 623, 624, the data encryption end 613 can send the key component ciphertext data C2 to the component channel ends 621, 623, 624, and the data encryption end 614 can send the key component ciphertext data D2 to the component channel ends 621, 622, 624.
[0120] It should be noted that each data encryption end can send key component ciphertext data to K component channel ends, where K can be an odd number, that is, K can be 3 in this embodiment, or other odd numbers, so that after the data receiving end receives the key component ciphertext data sent by all component channel ends in the component channel module respectively, it can filter out the duplicate key component ciphertext data based on the characteristics of the XOR algorithm to obtain the component ciphertext data of each data encryption end.
[0121] The component channel ends 621, 622, 623, and 624 in the component channel module 620 can obtain the key component ciphertext data A2, C2, D2; the component channel end 622 can obtain the key component ciphertext data A2, B2, D2; the component channel end 623 can obtain the key component ciphertext data A2, B2, C2; and the component channel end 624 can obtain the key component ciphertext data B2, C2, D2. Thus, each component channel end in the component channel module 620 can intelligently obtain three of the four key component ciphertext data, thereby avoiding the loss of all key component ciphertext data after an attack on the same component channel end.
[0122] In this embodiment, there is no communication link connection between the component channel ends 621, 622, 623, and 624 in the component channel module 620, and different component channel ends are isolated from each other, so as to physically avoid malicious attacks on two different component channel ends simultaneously.
[0123] In each component channel end, three key component ciphertext data are calculated according to the XOR algorithm to obtain the component aggregation ciphertext data. That is, in the component channel end 621, the component aggregation ciphertext data E1 = A2^C2^D2; in the component channel end 622, the component aggregation ciphertext data E2 = A2^B2^D2; in the component channel end 623, the component aggregation ciphertext data E3 = A2^B2^C2; and in the component channel end 624, the component aggregation ciphertext data E4 = B2^C2^D2. Here, the symbol ^ represents the XOR algorithm.
[0124] The four component channel ends 621, 622, 623, and 624 of the component channel module 620 send their respective component aggregation ciphertext data E1, E2, E3, and E4 to the data receiving end 630. The data receiving end 630 can generate the target plaintext data according to the component aggregation ciphertext data E1, E2, E3, and E4 of the four component channel ends.
[0125] The data receiving end 630 may include a component synthesis unit 631 and a data decryption unit 632. The component synthesis unit 631 performs an XOR calculation on the component aggregation ciphertext data E1, E2, E3, and E4. That is, in the component synthesis unit 631, the component aggregation ciphertext data E1, E2, E3, and E4 can be synthesized into the key ciphertext data F1. The key ciphertext data F1 can be obtained based on the following reasoning process.
[0126] F1 = E1^E2^E3^E4
[0127] =(A2^C2^D2)^(A2^B2^D2)^(A2^B2^C2)^(B2^C2^D2)
[0128] = A2^A2^A2^B2^B2^B2^C2^C2^C2^D2^D2^D2
[0129] = A2^B2^C2^D2。
[0130] Since f(A1) = A1 b mod n = A2: f(B1) = B1 b mod n = B2; f(C1) = C1 b mod n = C2; f(D1) = D1 b mod n = D2。
[0131] Therefore, the key ciphertext data F1F1 = (A1 b mod n)^(B1 b mod n)^(C1 b mod n)^(D1 b mod n) = (A1 b ^B1 b ^C1 b ^D1 b ) mod n。
[0132] The data decryption unit 632 decrypts the key ciphertext data F1 = (A1 b ^B1 b ^C1 b ^D1 b ) mod n based on the homomorphic decryption algorithm, and can obtain the key plaintext data G1 = A1^B1^C1^D1。
[0133] According to the embodiments of the present disclosure, since the data encryption module generates key component plaintext data based on different key generators, it is difficult for other illegal users to steal the key component plaintext data according to the random number generation rules of the same key generator. That is, the illegal users need to crack all data encryption ends at the same time to obtain all the key component plaintext data, thereby strengthening data security at the key generation end.
[0134] According to the embodiments of the present disclosure, each component channel end in the component channel module only obtains a part of all the key component plaintext data, so that illegal users cannot obtain all the key component plaintext data by attacking a single component channel end, and the component channel end only performs calculations on the key component ciphertext data and does not decrypt the key component ciphertext data, thereby further ensuring the data security of the key component ciphertext data during the output process.
[0135] Based on the above ciphertext data sharing method, the present disclosure also provides a ciphertext data sharing device. The following will be combined with Figure 7 and Figure 8Describe the device in detail.
[0136] Figure 7 The structural block diagram of the ciphertext data sharing device according to an embodiment of the present disclosure is schematically shown.
[0137] As Figure 7 shown, the ciphertext data sharing device 700 of this embodiment includes an acquisition module 710, a processing module 720, and a first sending module 730.
[0138] The acquisition module 710 is configured to acquire the respective partial ciphertext data from N data encryption ends. Among them, the partial ciphertext data is obtained by encrypting the partial plaintext data based on the homomorphic encryption algorithm. The partial ciphertext data is stored in L partial channel ends. Each data encryption end sends the partial ciphertext data to K partial channel ends. L > K ≥ 2. The partial channel ends store the partial ciphertext data of M data encryption ends respectively. N > M ≥ 1;
[0139] The processing module 720 is configured to process the M partial ciphertext data at the partial channel ends according to a preset rule to obtain partial aggregated ciphertext data;
[0140] The first sending module 730 is configured to send the respective partial aggregated ciphertext data of the L partial channel ends to a data receiving end. Among them, the data receiving end generates target plaintext data based on the respective partial aggregated ciphertext data of the L partial channel ends.
[0141] According to an embodiment of the present disclosure, the partial plaintext data includes key partial plaintext data, and the key partial plaintext data is generated based on a key generator;
[0142] Among them, the key generator includes a quantum random number generator.
[0143] According to an embodiment of the present disclosure, the processing module may include a first processing unit.
[0144] The first processing unit is configured to calculate the M partial ciphertext data at the partial channel ends according to the exclusive-or algorithm to obtain partial aggregated ciphertext data.
[0145] According to an embodiment of the present disclosure, the processing module may include a second processing module.
[0146] The second processing module is configured to splice the M partial ciphertext data according to a preset splicing rule at the partial channel ends to obtain partial aggregated ciphertext data.
[0147] Figure 8 The structural block diagram of the ciphertext data sharing device according to another embodiment of the present disclosure is schematically shown.
[0148] As Figure 8As shown, the ciphertext data sharing device 800 of this embodiment includes an encryption module 810 and a second sending module 820.
[0149] The encryption module 810 is used for each of the N data encryption ends to encrypt the component plaintext data based on the homomorphic encryption algorithm, so as to obtain the component ciphertext data of each of the N data encryption ends.
[0150] The second sending module 820 is used for each data encryption end to send the component ciphertext data to K component channel ends in the component channel module according to a preset sending rule, where the component channel module includes L component channel ends, L > K ≥ 2, and the component channel ends store the component ciphertext data of each of the M data encryption ends, N > M ≥ 1.
[0151] According to an embodiment of the present disclosure, the component plaintext data includes key component plaintext data, and the key component plaintext data is generated based on a key generator; wherein, the key generator includes a quantum random number generator.
[0152] According to an embodiment of the present disclosure, the encryption module may include: a first calculation unit and a second calculation unit.
[0153] The first calculation unit is used for each of the N data encryption ends to perform b XOR calculations on the component plaintext data to obtain the first calculation values of each of the N data encryption ends.
[0154] The second calculation unit is used for taking the modulo of the first calculation values of each of the N data encryption ends with respect to the natural number n to obtain the component ciphertext data of each of the N data encryption ends.
[0155] According to embodiments of the present disclosure, any plurality of modules among the acquisition module 710, the processing module 720, the first sending module 730, the encryption module 810, and the second sending module 820 may be combined and implemented in one module, or any one of them may be split into multiple modules. Alternatively, at least part of the functions of one or more of these modules may be combined with at least part of the functions of other modules and implemented in one module. According to embodiments of the present disclosure, at least one of the acquisition module 710, the processing module 720, the first sending module 730, the encryption module 810, and the second sending module 820 may be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on substrate, a system on package, an application specific integrated circuit (ASIC), or may be implemented by any other reasonable means such as hardware or firmware for integrating or packaging circuits, or may be implemented in any one of the three implementation manners of software, hardware, and firmware, or in a suitable combination of any several of them. Alternatively, at least one of the acquisition module 710, the processing module 720, the first sending module 730, the encryption module 810, and the second sending module 820 may be at least partially implemented as a computer program module, and when the computer program module is run, corresponding functions may be executed.
[0156] Figure 9 Schematically shows a block diagram of an electronic device suitable for implementing the ciphertext data sharing method according to an embodiment of the present disclosure.
[0157] As Figure 9 shown, the electronic device 900 according to an embodiment of the present disclosure includes a processor 901, which may perform various appropriate actions and processes according to a program stored in a read only memory (ROM) 902 or a program loaded from a storage section 908 into a random access memory (RAM) 903. The processor 901 may include, for example, a general microprocessor (such as a CPU), an instruction set processor, and / or a related chipset, and / or a dedicated microprocessor (such as an application specific integrated circuit (ASIC)), etc. The processor 901 may also include on-board memory for caching purposes. The processor 901 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.
[0158] In the RAM 903, various programs and data required for the operation of the electronic device 900 are stored. The processor 901, the ROM 902, and the RAM 903 are connected to each other via a bus 904. The processor 901 performs various operations of the method flow according to the embodiments of the present disclosure by executing the programs in the ROM 902 and / or the RAM 903. It should be noted that the programs may also be stored in one or more memories other than the ROM 902 and the RAM 903. The processor 901 may also perform various operations of the method flow according to the embodiments of the present disclosure by executing the programs stored in the one or more memories.
[0159] According to an embodiment of the present disclosure, the electronic device 900 may further include an input / output (I / O) interface 905, and the input / output (I / O) interface 905 is also connected to the bus 904. The electronic device 900 may further include one or more of the following components connected to the I / O interface 905: an input portion 906 including a keyboard, a mouse, etc.; an output portion 907 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage portion 908 including a hard disk, etc.; and a communication portion 909 including a network interface card such as a LAN card, a modem, etc. The communication portion 909 performs communication processing via a network such as the Internet. A drive 910 is also connected to the I / O interface 905 as needed. A removable medium 911, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is mounted on the drive 910 as needed so that a computer program read therefrom is installed into the storage portion 908 as needed.
[0160] The present disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or may exist separately without being assembled into the device / apparatus / system. The above computer-readable storage medium carries one or more programs, and when the one or more programs are executed, the method according to the embodiments of the present disclosure is implemented.
[0161] According to an embodiment of the present disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, which may include, for example, but is not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In the present disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program, and the program may be used by or in combination with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present disclosure, the computer-readable storage medium may include one or more memories other than the above-described ROM 902 and / or RAM 903 and / or ROM 902 and RAM 903.
[0162] An embodiment of the present disclosure also includes a computer program product, which includes a computer program that contains program code for executing the method shown in the flowchart. When the computer program product runs in a computer system, the program code is used to enable the computer system to implement the method provided by the embodiment of the present disclosure.
[0163] When the computer program is executed by the processor 901, the above functions defined in the system / apparatus of the embodiment of the present disclosure are executed. According to an embodiment of the present disclosure, the above-described systems, apparatuses, modules, units, etc. may be implemented by computer program modules.
[0164] In one embodiment, the computer program may rely on tangible storage media such as optical storage devices and magnetic storage devices. In another embodiment, the computer program may also be transmitted and distributed in the form of a signal on a network medium, and be downloaded and installed through the communication part 909, and / or be installed from the removable medium 911. The program code included in the computer program may be transmitted by any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.
[0165] In such an embodiment, the computer program may be downloaded and installed from the network through the communication part 909, and / or be installed from the removable medium 911. When the computer program is executed by the processor 901, the above functions defined in the system of the embodiment of the present disclosure are executed. According to an embodiment of the present disclosure, the above-described systems, devices, apparatuses, modules, units, etc. may be implemented by computer program modules.
[0166] According to embodiments of the present disclosure, program code for executing the computer programs provided by the embodiments of the present disclosure can be written in any combination of one or more programming languages. Specifically, these computing programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. The programming languages include, but are not limited to, such as Java, C++, Python, the "C" language, or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device can be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (e.g., by using an Internet service provider to connect through the Internet).
[0167] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and combinations of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0168] Those skilled in the art can understand that the features recited in the various embodiments and / or claims of the present disclosure can be combined or combined in various ways, even if such combinations or combinations are not explicitly recited in the present disclosure. In particular, without departing from the spirit and teachings of the present disclosure, the features recited in the various embodiments and / or claims of the present disclosure can be combined and combined in various ways. All such combinations and / or combinations fall within the scope of the present disclosure.
[0169] The embodiments of the present disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present disclosure. Although the embodiments have been described separately above, this does not mean that the measures in each embodiment cannot be used advantageously in combination. The scope of the present disclosure is defined by the appended claims and their equivalents. Without departing from the scope of the present disclosure, those skilled in the art can make various substitutions and modifications, and these substitutions and modifications should fall within the scope of the present disclosure.
Claims
1. A ciphertext data sharing method is applied to a component channel module, and the component channel module includes L component channel ends. The method includes: Obtain the component ciphertext data from each of the N data encryption ends. Among them, the component ciphertext data is obtained by the data encryption end encrypting the component plaintext data based on the homomorphic encryption algorithm. The component plaintext data is generated based on the key generator of the data encryption end. The component ciphertext data is stored in the L component channel ends. Each data encryption end sends the component ciphertext data to K component channel ends. L > K > 2 and K is an odd number. Each component channel end stores the component ciphertext data of M data encryption ends respectively. N > M > 1; At each component channel end, calculate the component ciphertext data of M data encryption ends respectively according to the XOR algorithm to obtain the component aggregated ciphertext data of each component channel end; Send the component aggregated ciphertext data of the L component channel ends respectively to the data receiving end. Among them, the data receiving end performs an XOR calculation on the component aggregated ciphertext data of the L component channel ends respectively to obtain the key ciphertext data; and decrypt the key ciphertext data based on the homomorphic decryption algorithm to obtain the target key.
2. The ciphertext data sharing method according to claim 1, wherein, the key generator includes a quantum random number generator.
3. The ciphertext data sharing method according to claim 1, wherein, N data encryption ends respectively encrypt the component plaintext data based on the homomorphic encryption algorithm to obtain the component ciphertext data of the N data encryption ends respectively, including: Each of the N data encryption ends performs b XOR calculations on the component plaintext data to obtain the first calculated values of the N data encryption ends respectively; Take the first calculated values of the N data encryption ends modulo the natural number n to obtain the component ciphertext data of the N data encryption ends respectively.
4. A ciphertext data sharing method is applied to a data encryption module, and the data encryption module includes N data encryption ends. The method includes: Each of the N data encryption ends encrypts the component plaintext data based on the homomorphic encryption algorithm to obtain the component ciphertext data of the N data encryption ends respectively. The component plaintext data is generated based on the key generator of the data encryption end; Each data encryption end sends the component ciphertext data to K component channel ends in the component channel module according to a preset sending rule. Among them, the component channel module includes L component channel ends. L > K > 2 and K is an odd number. Each component channel end stores the component ciphertext data of M data encryption ends respectively. N > M > 1; Among them, the component channel module enables the data receiving end to obtain the target key by performing the following operations: Obtain the component ciphertext data from each of the N data encryption ends. Among them, the component ciphertext data is stored in the L component channel ends. Each component channel end stores the component ciphertext data of M data encryption ends respectively; At each of the component channel ends, component ciphertext data of each of the M data encryption ends is calculated according to the exclusive OR algorithm to obtain component aggregated ciphertext data of each of the component channel ends; Send the component aggregated ciphertext data of each of the L component channel ends to the data receiving end, where the data receiving end performs an exclusive OR calculation on the component aggregated ciphertext data of each of the L component channel ends to obtain key ciphertext data; and decrypt the key ciphertext data based on the homomorphic decryption algorithm to obtain the target key.
5. The ciphertext data sharing method according to claim 4, wherein, the key generator includes a quantum random number generator.
6. The ciphertext data sharing method according to claim 4, wherein, each of the N data encryption ends encrypts the component plaintext data based on the homomorphic encryption algorithm to obtain the component ciphertext data of each of the N data encryption ends, including: each of the N data encryption ends performs b exclusive OR calculations on the component plaintext data to obtain the first calculated value of each of the N data encryption ends; take the modulo of the first calculated value of each of the N data encryption ends with the natural number n to obtain the component ciphertext data of each of the N data encryption ends.
7. A ciphertext data sharing method, applied to a data encryption module and a component channel module, the data encryption module includes N data encryption ends, and the component channel module includes L component channel ends, including: each of the N data encryption ends in the data encryption module encrypts the component plaintext data based on the homomorphic encryption algorithm to obtain the component ciphertext data of each of the N data encryption ends; each data encryption end sends the component ciphertext data to K component channel ends in the component channel module according to a preset sending rule, where L > K > 2 and K is an odd number; the component channel module obtains the component ciphertext data from each of the N data encryption ends, where the component ciphertext data is stored in the L component channel ends, each component channel end stores the component ciphertext data of each of the M data encryption ends, and N > M > 1; at each of the component channel ends, calculate M component ciphertext data according to the exclusive OR algorithm to obtain component aggregated ciphertext data; send the component aggregated ciphertext data of each of the L component channel ends to the data receiving end, where the data receiving end performs an exclusive OR calculation on the component aggregated ciphertext data of each of the L component channel ends to obtain key ciphertext data; and decrypt the key ciphertext data based on the homomorphic decryption algorithm to obtain the target plaintext data.
8. A ciphertext data sharing device, including: an acquisition module, configured to acquire the component ciphertext data from each of the N data encryption ends, where the component ciphertext data is obtained by the data encryption end encrypting the component plaintext data based on the homomorphic encryption algorithm, the component plaintext data is generated based on the key generator of the data encryption end, the component ciphertext data is stored in the L component channel ends, each data encryption end sends the component ciphertext data to K of the component channel ends, L > K > 2 and K is an odd number, and each component channel end stores the component ciphertext data of each of the M data encryption ends, and N > M > 1; A processing module, configured to calculate respective component ciphertext data of M of the data encryption ends according to an exclusive-or algorithm at each of the component channel ends, so as to obtain component aggregated ciphertext data of each of the component channel ends; A first sending module, configured to send respective component aggregated ciphertext data of L of the component channel ends to a data receiving end, where the data receiving end performs an exclusive-or calculation on the respective component aggregated ciphertext data of L of the component channel ends to obtain key ciphertext data; and decrypts the key ciphertext data based on a homomorphic decryption algorithm to obtain a target key.
9. A ciphertext data sharing device comprising: An encryption module, configured to encrypt respective component plaintext data of N data encryption ends based on a homomorphic encryption algorithm to obtain respective component ciphertext data of N of the data encryption ends, where the component plaintext data is generated based on a key generator of the data encryption ends; A second sending module, configured to send, by each of the data encryption ends according to a preset sending rule, the component ciphertext data to K component channel ends in a component channel module, where the component channel module includes L component channel ends, L>K>2 and K is an odd number, and each of the component channel ends stores respective component ciphertext data of M data encryption ends, N>M>1; wherein the component channel module is configured to: Obtain respective component ciphertext data from N data encryption ends, where the component ciphertext data is stored in L of the component channel ends, and each of the component channel ends stores respective component ciphertext data of M data encryption ends; At each of the component channel ends, calculate respective component ciphertext data of M of the data encryption ends according to an exclusive-or algorithm to obtain component aggregated ciphertext data of each of the component channel ends; Send respective component aggregated ciphertext data of L of the component channel ends to a data receiving end, where the data receiving end performs an exclusive-or calculation on the respective component aggregated ciphertext data of L of the component channel ends to obtain key ciphertext data; and decrypts the key ciphertext data based on a homomorphic decryption algorithm to obtain a target key.
10. An electronic device comprising: One or more processors; A storage device, configured to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the method according to any one of claims 1 to 7.
11. A computer-readable storage medium, on which executable instructions are stored, and when the instructions are executed by a processor, the processor is caused to execute the method according to any one of claims 1 to 7.
12. A computer program product, including a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
SM2 algorithm-based decryption key division and decryption method, device and medium
CN109257176A
File storage method and device and server
CN113032357A