Data Encryption Method, Device, Computer Readable Storage Medium and Product

By generating a pseudo-public key in iterative affine encryption technology and sending it to the data receiving device, the problem of low security in iterative affine encryption technology is solved, and high-security data transmission and ciphertext-level data calculation are realized.

CN114969770BActive Publication Date: 2025-06-17JD DIGITS HAIYI INFORMATION TECHNOLOGY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111284063.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-01
Publication Date
2025-06-17
Estimated Expiration
2041-11-01

AI Technical Summary

Technical Problem

The existing iterative affine encryption technology is relatively low in security and low in applicability, especially due to its symmetric encryption characteristics. Once the encryption key is leaked, the decryption key will inevitably be leaked, resulting in lower security.

Method used

By generating the iterative affine key, a random number plaintext is generated and the iterative affine key is used to encrypt the random number plaintext, and a pseudo-public key is obtained. The pseudo-public key is sent to the data receiving device so that the data receiving device can use the pseudo-public key to encrypt data on the calculation plaintext.

Benefits of technology

It realizes that without exposing the iterative affine key, the data receiving device can still realize the conversion from plain text to cipher text, so as to realize cipher text-level data calculation on the basis of ensuring data security. Improves the security of data transmission and is highly adaptable.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114969770B_ABST
    Figure CN114969770B_ABST
Patent Text Reader

Abstract

An embodiment of the present disclosure provides a data encryption method, device, computer-readable storage medium, and product. The method includes: obtaining a random number plaintext, where the random number plaintext is a random number generated together with an affine secret key; performing an encryption operation on the random number according to the iterative affine secret key to obtain a random number ciphertext, and determining the random number ciphertext as a pseudo public key; sending the pseudo public key to a data receiving device, so that the data receiving device performs a data encryption operation on the plaintext to be calculated by using the pseudo public key. Since the data receiving device can still implement the conversion from plaintext to ciphertext without the data sending device exposing the iterative affine secret key, it is possible to implement data calculation at the ciphertext level on the basis of ensuring data security. The security of the data transmission process is relatively high, so it can be adapted to more application scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present disclosure relate to the field of big data, and in particular, to a data encryption method, device, computer-readable storage medium, and product. Background Art

[0002] Through the use of homomorphic encryption technology, federated learning can achieve joint modeling of encrypted data among multiple parties, and can mine the value of data while ensuring the data security of each participating party. The homomorphic encryption technology currently applied in federated learning is mainly the Paillier semi-homomorphic encryption technology, which can support ciphertext addition and scalar multiplication homomorphisms. However, the Paillier encryption algorithm has a large number of modular exponentiation operations in the processes of encryption, decryption, and ciphertext calculation, and the calculation efficiency is relatively low.

[0003] In order to improve the efficiency of encrypted calculation, the existing technology generally adopts the iterative affine encryption technology to perform encryption operations on plaintext.

[0004] In the process of implementing the present disclosure, the inventors found that there are at least the following problems in the existing technology: Since the iterative affine encryption technology is a symmetric encryption technology, once the encryption key is leaked, the decryption key will surely be leaked. Therefore, the security is relatively low and the application scope is relatively small. Summary of the Invention

[0005] Embodiments of the present disclosure provide a data encryption method, device, computer-readable storage medium, and product, which are used to solve the technical problems that the existing iterative affine encryption technology has relatively low security and low applicability.

[0006] In a first aspect, embodiments of the present disclosure provide a data encryption method, including:

[0007] Obtain a random number plaintext, where the random number plaintext is a random number generated together with an iterative affine key;

[0008] Perform an encryption operation on the random number according to the iterative affine key to obtain a random number ciphertext, and determine the random number ciphertext as a pseudo-public key;

[0009] Send the pseudo-public key to a data receiving device, so that the data receiving device uses the pseudo-public key to perform a data encryption operation on the plaintext to be calculated.

[0010] The data encryption method provided in this embodiment generates a random number plaintext while generating an iterative affine key, encrypts the random number plaintext using the iterative affine key to obtain a pseudo-public key, and sends the pseudo-public key to a data receiving device, so that the data receiving device can use the pseudo-public key to encrypt the plaintext to be calculated. Since the data receiving device can still perform the conversion from plaintext to ciphertext without the data sending device exposing the iterative affine key, it can perform data calculations at the ciphertext level on the basis of ensuring data security. The security of the data transmission process is relatively high, so the adaptability is relatively strong.

[0011] In a second aspect, an embodiment of the present disclosure provides a data encryption method, including:

[0012] Obtaining a pseudo-public key sent by a data sending device, where the pseudo-public key is obtained after the data sending device encrypts a random number plaintext generated together with an iterative affine key by using an iterative affine encryption method;

[0013] Performing an encryption operation on the plaintext to be calculated according to the pseudo-public key to obtain a second target ciphertext;

[0014] Sending the second target ciphertext to the data sending device, so that the data sending device performs a ciphertext calculation operation according to the first target ciphertext and the second target ciphertext, where the ciphertext calculation includes one or more of addition calculation and scalar multiplication calculation, and the first target ciphertext is obtained after the data sending device encrypts the data to be calculated by using the random number plaintext.

[0015] In a third aspect, an embodiment of the present disclosure provides a data sending device, including:

[0016] An acquisition module, configured to acquire a random number plaintext, where the random number plaintext is a random number generated together with an iterative affine key;

[0017] An encryption module, configured to encrypt the random number according to the iterative affine key to obtain a random number ciphertext, and determine the random number ciphertext as a pseudo-public key;

[0018] A sending module, configured to send the pseudo-public key to a data receiving device, so that the data receiving device uses the pseudo-public key to perform a data encryption operation on the plaintext to be calculated.

[0019] In a fourth aspect, an embodiment of the present disclosure provides a data receiving device, including:

[0020] A pseudo-public key acquisition module, configured to acquire a pseudo-public key sent by a data sending device, where the pseudo-public key is obtained after the data sending device encrypts a random number plaintext generated together with an iterative affine key by using an iterative affine encryption method;

[0021] A processing module, configured to encrypt the plaintext to be calculated according to the pseudo-public key to obtain a second target ciphertext;

[0022] A transmission module, configured to send the second target ciphertext to the data sending device, so that the data sending device performs a ciphertext calculation operation according to the first target ciphertext and the second target ciphertext, where the ciphertext calculation includes one or more of addition calculation and scalar multiplication calculation, and the first target ciphertext is obtained by the data sending device encrypting the data to be calculated with the random number plaintext.

[0023] In a fifth aspect, an embodiment of the present disclosure provides an electronic device including: a memory and a processor;

[0024] A memory; a memory for storing executable instructions of the processor;

[0025] Wherein, the processor is configured to call program instructions in the memory to execute the data encryption method as described in the first aspect or the second aspect.

[0026] In a sixth aspect, an embodiment of the present disclosure provides a computer-readable storage medium, in which computer-executable instructions are stored, and when the computer-executable instructions are executed by a processor, they are used to implement the data encryption method as described in the first aspect or the second aspect.

[0027] In a seventh aspect, an embodiment of the present disclosure provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the data encryption method according to the first aspect or the second aspect.

[0028] The data encryption method, device, computer-readable storage medium and product provided by the embodiments of the present disclosure generate a random number plaintext while generating an iterative affine key, encrypt the random number plaintext with the iterative affine key to obtain a pseudo-public key, and send the pseudo-public key to the data receiving device, so that the data receiving device can use the pseudo-public key to encrypt the plaintext to be calculated. Since the data receiving device can still implement the conversion from plaintext to ciphertext without the data sending device exposing the iterative affine key, it is possible to implement ciphertext-level data calculation on the basis of ensuring data security. The security of the data transmission process is relatively high, so the adaptability is relatively strong. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] The drawings here are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present disclosure, and are used together with the specification to explain the principles of the present disclosure.

[0030] Figure 1Schematic diagram of the system architecture on which this disclosure is based;

[0031] Figure 2 Schematic flowchart of the data encryption method provided in the first embodiment of this disclosure;

[0032] Figure 3 Schematic flowchart of the generation of the pseudo-public key provided in the embodiments of this disclosure;

[0033] Figure 4 Schematic flowchart of the data encryption method provided in the second embodiment of this disclosure;

[0034] Figure 5 Schematic flowchart of the data encryption method provided in the third embodiment of this disclosure;

[0035] Figure 6 Schematic diagram of the structure of the data sending device provided in the fourth embodiment of this disclosure;

[0036] Figure 7 Schematic diagram of the structure of the data receiving device provided in the fifth embodiment of this disclosure;

[0037] Figure 8 Schematic diagram of the structure of the electronic device provided in the sixth embodiment of this disclosure.

[0038] Through the above-mentioned drawings, the specific embodiments of this disclosure have been shown, and there will be more detailed descriptions hereinafter. These drawings and textual descriptions are not intended to limit the scope of the concept of this disclosure in any way, but to illustrate the concept of this disclosure to those skilled in the art by referring to specific embodiments. Detailed implementation manners

[0039] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all the implementation manners consistent with this disclosure. On the contrary, they are merely examples of the devices and methods consistent with some aspects of this disclosure as detailed in the appended claims.

[0040] First, the terms involved in the embodiments of this disclosure are explained:

[0041] Homomorphic encryption: An encryption technology in which the result of performing operations on the data ciphertext is equivalent to the addition or multiplication operation on the plaintext.

[0042] Somewhat homomorphic encryption: The basic meaning is equivalent to homomorphic encryption, but it only supports one of the addition homomorphic or multiplication homomorphic operations.

[0043] Scalar multiplication homomorphism: A multiplicative homomorphism means that both the multiplier and the multiplicand are ciphertexts. A scalar multiplication homomorphism means that one of the multiplier and the multiplicand is a ciphertext and the other is a plaintext.

[0044] Regarding the technical problems of the existing iterative affine encryption technology mentioned above, which has low security and poor applicability, the present disclosure provides a data encryption method, device, computer-readable storage medium, and product.

[0045] It should be noted that the data encryption method, device, computer-readable storage medium, and product provided by the present disclosure can be applied to various scenarios of multi-party data secure transmission.

[0046] The existing iterative affine encryption method is generally symmetric encryption. If one wants to achieve encryption at the ciphertext level, the iterative affine cipher needs to be synchronized to the data receiving party so that the data receiving party can use the iterative affine cipher for data encryption. However, at this time, the data transmission is equivalent to plaintext transmission.

[0047] In the process of solving the above technical problems, the inventors found through research that in order to achieve data calculation at the ciphertext level while ensuring data security, a pseudo-public key can be designed so that the data receiving end can use the pseudo-public key for data encryption operations. Specifically, while generating the iterative affine key, a random number plaintext is generated, and the random number plaintext is encrypted using the iterative affine key to obtain the pseudo-public key. The pseudo-public key is sent to the data receiving device, so that the data receiving device can use the pseudo-public key to encrypt the plaintext to be calculated. Thus, without exposing the iterative affine key, the data receiving device can still achieve the conversion from plaintext to ciphertext.

[0048] The following uses specific embodiments to detail the technical solutions of the present disclosure and how the technical solutions of the present disclosure solve the above technical problems. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present disclosure will be described below with reference to the accompanying drawings.

[0049] Figure 1 The system architecture diagram based on the present disclosure is as Figure 1 shown. The system architecture based on the present disclosure at least includes: a data sending device 1 and a data receiving device 2. Among them, both the data sending device 1 and the data receiving device 2 are provided with data encryption devices, and the data encryption devices can be written in languages such as C / C++, Java, Shell, or Python.

[0050] Figure 2 The flowchart of the data encryption method provided in the first embodiment of the present disclosure is as Figure 2 shown. The method includes:

[0051] Step 201: Obtain a random number plaintext, where the random number plaintext is a random number generated together with an iterative affine key.

[0052] The execution subject of this embodiment is a data encryption device, which can be coupled to a data sending device. The data sending device can be communicatively connected to a data receiving device so as to enable data interaction.

[0053] In this embodiment, in order to be able to perform data calculations at the ciphertext level on the basis of ensuring data security, a pseudo-public key can be designed so that the data receiving end can use the pseudo-public key to perform data encryption operations.

[0054] Compared with an ordinary iterative affine encryption method, in the key data structure of the pseudo-public key encryption method, a random number is generated during key generation, and then this random number is encrypted using the encryption method as the encryption pseudo-public key. The pseudo-public key can be obtained through the get_public_key() method of the key. In order to implement the generation of the pseudo-public key, the random number plaintext can be obtained.

[0055] Step 202: Encrypt the random number according to the iterative affine key to obtain a random number ciphertext, and determine the random number ciphertext as the pseudo-public key.

[0056] In this embodiment, after obtaining the random number plaintext, the random number plaintext can be encrypted to generate a random number ciphertext corresponding to the random number plaintext, and the random number ciphertext is determined as the pseudo-public key.

[0057] Specifically, the iterative affine key can be used to perform an affine encryption operation on the random number plaintext to obtain a random number ciphertext. Optionally, an affine encryption operation can be performed on the random number plaintext once, or an iterative affine encryption operation can be performed. The present disclosure does not limit this.

[0058] Step 203: Send the pseudo-public key to the data receiving device so that the data receiving device uses the pseudo-public key to perform data encryption operations on the plaintext to be calculated.

[0059] In this embodiment, after generating the corresponding pseudo-public key according to the random number plaintext, the pseudo-public key can be sent to the data receiving device. Correspondingly, after obtaining the pseudo-public key, the data receiving device can use the pseudo-public key to perform data encryption operations on the plaintext to be calculated. Thus, the plaintext to be calculated can be converted into a ciphertext, and further, a ciphertext homomorphic encryption operation can be performed according to this ciphertext and the ciphertext after iterative affine encryption by the data sender, without sending the iterative affine key in the iterative affine process to the data receiving party, which can improve the security of data transmission.

[0060] Further, on the basis of Embodiment 1, step 202 specifically includes:

[0061] According to the iterative affine key, encrypt the random number plaintext by means of iterative affine encryption to obtain the random number ciphertext.

[0062] In this embodiment, specifically, the iterative affine key can be used to perform iterative affine encryption on the random number plaintext generated simultaneously by the iterative affine key to obtain the random number plaintext. Iterative affine encryption operations can be performed on it for a preset number N of times.

[0063] Optionally, any encryption technology with homomorphic encryption can implement the generation and use of a pseudo-public key through an upload method, where the encryption technology with homomorphic encryption includes semi-homomorphic encryption and fully homomorphic encryption.

[0064] Further, on the basis of Embodiment 1, the step of encrypting the random number plaintext by means of iterative affine encryption according to the iterative affine key to obtain the random number ciphertext includes:

[0065] Perform a decimal point shift operation on the floating point numbers in the random number plaintext to obtain an integer plaintext corresponding to the random number plaintext;

[0066] Use the iterative affine key to perform iterative affine encryption operations on the integer plaintext for a preset number of times to obtain the random number ciphertext.

[0067] In this embodiment, the floating point numbers in the random number plaintext can be converted into integers through scale transformation to obtain an integer plaintext corresponding to the random number plaintext. At this time, the floating point numbers are expanded by a certain number of data bits, but the precision of the decimals has been encoded into the integer domain. Then, by using the iterative affine key and performing iterative affine encryption operations and modular exponentiation for a preset number of times, the final random number ciphertext can be obtained.

[0068] Figure 3 It is a schematic flowchart of the pseudo-public key generation provided by the embodiments of the present disclosure. As Figure 3 shown, first, it is necessary to obtain the random number plaintext 31, perform a decimal point shift operation on the random number plaintext 31 to obtain the integer plaintext 32, and perform N times of iterative affine encryption operations on the integer plaintext 32 to obtain the random number ciphertext 33.

[0069] The data encryption method provided in this embodiment generates a random number plaintext while generating an iterative affine key, encrypts the random number plaintext using the iterative affine key to obtain a pseudo-public key, and sends the pseudo-public key to a data receiving device. As a result, the data receiving device can use the pseudo-public key to encrypt the plaintext to be calculated. Since the data receiving device can still perform the conversion from plaintext to ciphertext without the data sending device exposing the iterative affine key, it is possible to achieve data calculation at the ciphertext level on the basis of ensuring data security. The security of the data transmission process is relatively high, so the adaptability is relatively strong.

[0070] Figure 4 FIG. 4 is a schematic flowchart of the data encryption method provided in Embodiment 2 of the present disclosure. On the basis of Embodiment 1, as Figure 4 shown, after step 201, the method further includes:

[0071] Step 401: Obtain the data to be calculated.

[0072] Step 402: Multiply the data to be calculated by the random number plaintext to obtain preprocessed data.

[0073] Step 403: According to the iterative affine key, perform an encryption operation on the preprocessed data in an iterative affine encryption manner to obtain a first target ciphertext.

[0074] In this embodiment, when the data sending device performs data transmission, it can perform a data encryption operation according to the random number plaintext and the iterative affine key. Specifically, first, the data to be calculated can be obtained, and the data to be calculated is multiplied by the random number plaintext to obtain preprocessed data. According to the iterative affine key, an iterative affine encryption operation is performed on the preprocessed data to obtain a first target ciphertext.

[0075] Correspondingly, the data sending device can also perform a decryption operation on the first target ciphertext. Specifically, after obtaining the first target ciphertext, an inverse transformation process of iterative affine can be performed (that is, the operation steps are the same as those in the encryption process, but the operation parameters are in reverse order compared with the encryption process, and the decryption parameters are the inverses of the encryption parameters), and finally, multiply by the inverse of the random number to obtain the data to be calculated corresponding to the first target ciphertext.

[0076] Optionally, after obtaining the preprocessed data, the floating-point numbers in the preprocessed data can be converted into integers. Correspondingly, after performing the inverse transformation on the first target ciphertext, the integers in the result of the inverse transformation can be converted into floating-point numbers, and then multiplied by the inverse of the random number to obtain the data to be calculated corresponding to the first target ciphertext.

[0077] Further, on the basis of any of the above embodiments, after step 203, the method further includes:

[0078] Obtain the second target ciphertext sent by the data receiving device, where the first target ciphertext and the second target ciphertext are in the same ciphertext domain. Among them, the second target ciphertext is obtained after the data receiving device encrypts the plaintext to be calculated using the pseudo-public key.

[0079] Perform a ciphertext calculation operation based on the first target ciphertext and the second target ciphertext to obtain a calculation result, where the ciphertext calculation includes one or more of addition calculation and scalar multiplication calculation.

[0080] In this embodiment, after obtaining the pseudo-public key, the data receiving device can encrypt the plaintext to be calculated for data transmission using the pseudo-public key to obtain the second target ciphertext. Correspondingly, the second target ciphertext sent by the data receiving device can also be obtained, where the second target ciphertext and the first target ciphertext are in the same ciphertext domain, so that the two can perform data calculation operations at the ciphertext level. Therefore, a ciphertext calculation operation can be performed based on the first target ciphertext and the second target ciphertext to obtain a calculation result, where the ciphertext calculation includes one or more of addition calculation and multiplication calculation.

[0081] The data encryption method provided in this embodiment can, when the data sending device performs data transmission, encrypt the data according to the random number plaintext and the iterative affine key, so that the first target ciphertext and the second target ciphertext are in the same ciphertext domain, and data calculation at the ciphertext level can be realized on the basis of ensuring data security.

[0082] Figure 5 It is a schematic flowchart of the data encryption method provided in Embodiment 3 of the present disclosure. As Figure 5 shown, the method includes:

[0083] Step 501: Obtain the pseudo-public key sent by the data sending device, where the pseudo-public key is obtained after the data sending device encrypts the random number plaintext generated together with the iterative affine key using the iterative affine encryption method.

[0084] Step 502: Encrypt the plaintext to be calculated according to the pseudo-public key to obtain the second target ciphertext.

[0085] Step 503: Perform a ciphertext calculation operation based on the first target ciphertext sent by the data sending device and the second target ciphertext, where the ciphertext calculation includes one or more of addition calculation and scalar multiplication calculation, and the first target ciphertext is obtained after the data sending device encrypts the data to be calculated using the random number plaintext.

[0086] The execution entity of this embodiment is a data encryption device, which can be coupled to a data receiving device that can communicate with a data sending device.

[0087] In this embodiment, the data receiving device can obtain the pseudo-public key sent by the data sending device. Among them, compared with the ordinary iterative affine encryption method, in the key data structure of the pseudo-public key encryption method, a random number plaintext is generated during key generation. The data sending device can perform an iterative affine encryption operation on the random number plaintext to obtain the pseudo-public key, so that the data sending device can send the pseudo-public key to the data receiving device. After obtaining the pseudo-public key, the data receiving device can use the pseudo-public key to perform a data encryption operation on the plaintext to be calculated for data transmission to obtain the second target ciphertext, and can also perform a ciphertext calculation operation based on the first target ciphertext and the second target ciphertext sent by the data sending device. Among them, the second target ciphertext and the first target ciphertext are in the same ciphertext domain, so that the two can perform data calculation operations at the ciphertext level. The ciphertext calculation includes one or more of addition calculation and scalar multiplication calculation.

[0088] Further, on the basis of Embodiment 3, step 502 specifically includes:

[0089] Perform a scalar multiplication operation on the plaintext to be calculated and the pseudo-public key to obtain the second target ciphertext.

[0090] In this embodiment, the pseudo-public key encryption operation can be specifically divided into implicit application and explicit application. Among them, the implicit application of pseudo-public key encryption is the addition operation of plaintext and ciphertext. When performing an addition operation on ciphertext and plaintext, the plaintext to be calculated needs to first perform a scalar multiplication operation with the pseudo-public key cipher_scale, that is, the plaintext to be calculated can be converted into ciphertext, and then the operation between the plaintext to be calculated and the first target ciphertext is converted into the addition of the first target ciphertext and the second target ciphertext.

[0091] Further, on the basis of Embodiment 3, step 502 specifically includes:

[0092] Perform an assignment initialization operation on the pseudo-public key to obtain a target pseudo-public key, where the target pseudo-public key has a preset target attribute after the assignment initialization.

[0093] Use the target pseudo-public key to perform an encryption operation on the plaintext to be calculated to obtain the second target ciphertext.

[0094] In this embodiment, the explicit application of pseudo-public key encryption is to directly encrypt the plaintext to be calculated using the pseudo-public key cipher_scale. Since cipher_scale is a special ciphertext, it also has the cipher_scale attribute. During the initialization process, this parameter can be directly set to a negative number to distinguish it from general ciphertexts. Since the encryption process requires modular exponentiation operations, ciphertexts cannot be negative. Based on this, the use of the encryption function by general ciphertexts can be restricted. In addition, the ciphertext generated by pseudo-public key encryption must also have the same cipher_scale attribute as other ciphertexts encrypted with this key. Therefore, during the pseudo-public key encryption process, the pseudo-public key ciphertext itself needs to be used as the cipher_scale attribute of the ciphertext for assignment initialization to obtain the target pseudo-public key, where the target pseudo-public key has a preset target attribute after assignment initialization. The target pseudo-public key is used to encrypt the plaintext to be calculated to obtain the second target ciphertext. This can make the second target ciphertext of pseudo-public key encryption consistent with the ciphertext of direct encryption.

[0095] Further, based on Embodiment 3, the step of using the target pseudo-public key to encrypt the plaintext to be calculated to obtain the second target ciphertext includes:

[0096] Performing a multiplication operation on the target pseudo-public key and the plaintext to be calculated to obtain the second target ciphertext.

[0097] Specifically, a multiplication operation can be performed on the target pseudo-public key and the plaintext to be calculated to obtain the second target ciphertext.

[0098] The data encryption method provided in this embodiment can, after obtaining the pseudo-public key, use the pseudo-public key to perform a data encryption operation on the plaintext to be calculated for data transmission to obtain the second target ciphertext, and the second target ciphertext can also be sent to the data sending device. Thus, without the data sending device exposing the iterative affine key, the data receiving device can still achieve the conversion from plaintext to ciphertext, and thus, on the basis of ensuring data security, data calculation at the ciphertext level can be realized.

[0099] Figure 6 FIG. is a schematic structural diagram of a data sending device provided in Embodiment 4 of the present disclosure, as Figure 6As shown in the figure, the data sending device includes: an acquisition module 61, an encryption module 62, and a sending module 63. Among them, the acquisition module 61 is used to acquire a random number plaintext, where the random number plaintext is a random number generated together with an iterative affine key; the encryption module 62 is used to perform an encryption operation on the random number according to the iterative affine key to obtain a random number ciphertext, and determine the random number ciphertext as a pseudo public key; the sending module 63 is used to send the pseudo public key to a data receiving device, so that the data receiving device uses the pseudo public key to perform a data encryption operation on the plaintext to be calculated.

[0100] Further, on the basis of Embodiment 4, the encryption module is used to: perform an encryption operation on the random number plaintext in an iterative affine encryption manner according to the iterative affine key to obtain the random number ciphertext.

[0101] Further, on the basis of Embodiment 4, the encryption module is used to: perform a decimal point shifting operation on the floating point numbers in the random number plaintext to obtain an integer plaintext corresponding to the random number plaintext; perform a preset number of iterative affine encryption operations on the integer plaintext by using the iterative affine key to obtain the random number ciphertext.

[0102] Further, on the basis of any of the above embodiments, the device further includes: a data to be calculated acquisition module, configured to acquire data to be calculated; a calculation module, configured to multiply the data to be calculated by the random number plaintext to obtain preprocessed data; an encryption processing module, configured to perform an encryption operation on the preprocessed data in an iterative affine encryption manner according to the iterative affine key to obtain a first target ciphertext.

[0103] Further, on the basis of any of the above embodiments, the device further includes: an acquisition module, configured to acquire a second target ciphertext sent by a data receiving device, where the first target ciphertext and the second target ciphertext are in the same ciphertext domain, and the second target ciphertext is obtained by the data receiving device performing a data encryption operation on the plaintext to be calculated by using the pseudo public key; the calculation module is further configured to perform a ciphertext calculation operation according to the first target ciphertext and the second target ciphertext to obtain a calculation result, where the ciphertext calculation includes one or more of addition calculation and scalar multiplication calculation.

[0104] Figure 7 This is a schematic structural diagram of the data receiving device provided in Embodiment 5 of the present disclosure, as Figure 7As shown in the figure, the data receiving device includes: a pseudo-public key acquisition module 71, a processing module 72, and a transmission module 73. Among them, the pseudo-public key acquisition module 71 is used to acquire the pseudo-public key sent by the data sending device, where the pseudo-public key is obtained after the data sending device encrypts the random number plaintext generated together with the iterative affine key by means of iterative affine encryption; the processing module 72 is used to encrypt the plaintext to be calculated according to the pseudo-public key to obtain a second target ciphertext; the transmission module 73 is used to perform a ciphertext calculation operation according to the first target ciphertext and the second target ciphertext sent by the data sending device, where the ciphertext calculation includes one or more of addition calculation and scalar multiplication calculation, and the first target ciphertext is obtained after the data sending device encrypts the data to be calculated using the random number plaintext.

[0105] Further, on the basis of Embodiment 5, the processing module is configured to: perform a scalar multiplication operation on the plaintext to be calculated and the pseudo-public key to obtain a second target ciphertext.

[0106] Further, on the basis of Embodiment 5, the processing module is configured to: perform an assignment initialization operation on the pseudo-public key to obtain a target pseudo-public key, where the target pseudo-public key has a preset target attribute after the assignment initialization; use the target pseudo-public key to encrypt the plaintext to be calculated to obtain the second target ciphertext.

[0107] Further, on the basis of Embodiment 5, the processing module is configured to: perform a multiplication operation on the target pseudo-public key and the plaintext to be calculated to obtain a second target ciphertext.

[0108] Another embodiment of the present disclosure further provides an electronic device, including: a memory, a processor;

[0109] The memory; a memory for storing the executable instructions of the processor;

[0110] Among them, the processor is used to call the program instructions in the memory to execute the data encryption method as described in any one of the above embodiments.

[0111] Another embodiment of the present disclosure further provides a computer-readable storage medium, where computer-executable instructions are stored in the computer-readable storage medium, and when the computer-executable instructions are executed by a processor, they are used to implement the data encryption method as described in any one of the above embodiments.

[0112] Another embodiment of the present disclosure further provides a computer program product, including a computer program, where the computer program implements the data encryption method as described in any one of the above embodiments when executed by a processor.

[0113] Figure 8FIG. 0 is a schematic structural diagram of an electronic device provided in Embodiment 6 of the present disclosure. The device may be a mobile phone, a computer, a digital broadcast terminal, a messaging device, a tablet device, a medical device, a personal digital assistant, etc.

[0114] As Figure 8 shown, device 800 may include one or more of the following components: a processing component 802, a memory 804, a power component 806, a multimedia component 808, an audio component 810, an input / output (I / O) interface 812, a sensor component 814, and a communication component 816.

[0115] The processing component 802 generally controls the overall operation of the device 800, such as operations associated with display, telephone calls, data communications, camera operations, and recording operations. The processing component 802 may include one or more processors 820 to execute instructions to complete all or part of the steps of the above methods. In addition, the processing component 802 may include one or more modules to facilitate the interaction between the processing component 802 and other components. For example, the processing component 802 may include a multimedia module to facilitate the interaction between the multimedia component 808 and the processing component 802.

[0116] The memory 804 is configured to store various types of data to support the operation of the device 800. Examples of such data include instructions for any application or method operating on the device 800, contact data, phone book data, messages, pictures, videos, etc. The memory 804 may be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, a magnetic disk, or an optical disk.

[0117] The power component 806 provides power to the various components of the device 800. The power component 806 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power for the device 800.

[0118] The multimedia component 808 includes a screen that provides an output interface between the device 800 and the user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen can be implemented as a touch screen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors can sense not only the boundaries of the touch or swipe actions but also detect the duration and pressure associated with the touch or swipe operation. In some embodiments, the multimedia component 808 includes a front camera and / or a rear camera. When the device 800 is in an operating mode, such as a shooting mode or a video mode, the front camera and / or the rear camera can receive external multimedia data. Each of the front camera and the rear camera can be a fixed optical lens system or have a focal length and optical zoom capabilities.

[0119] The audio component 810 is configured to output and / or input audio signals. For example, the audio component 810 includes a microphone (MIC) that is configured to receive external audio signals when the device 800 is in an operating mode, such as a call mode, a recording mode, and a voice recognition mode. The received audio signals can be further stored in the memory 804 or transmitted via the communication component 816. In some embodiments, the audio component 810 further includes a speaker for outputting audio signals.

[0120] The I / O interface 812 provides an interface between the processing component 802 and a peripheral interface module, which can be a keyboard, a click wheel, buttons, etc. These buttons can include but are not limited to: a home button, a volume button, a power button, and a lock button.

[0121] The sensor component 814 includes one or more sensors for providing status assessments of various aspects of the device 800. For example, the sensor component 814 can detect the on / off state of the device 800, the relative positioning of components, such as the display and the keypad of the device 800. The sensor component 814 can also detect a change in the position of the device 800 or a component of the device 800, the presence or absence of user contact with the device 800, the orientation or acceleration / deceleration of the device 800, and the temperature change of the device 800. The sensor component 814 can include a proximity sensor configured to detect the presence of nearby objects without any physical contact. The sensor component 814 can also include a light sensor, such as a CMOS or a CCD image sensor, for use in imaging applications. In some embodiments, the sensor component 814 can further include an acceleration sensor, a gyroscope sensor, a magnetic sensor, a pressure sensor, or a temperature sensor.

[0122] The communication component 816 is configured to facilitate wired or wireless communication between the device 800 and other devices. The device 800 may access a communication standard-based wireless network, such as WiFi, 2G, or 3G, or a combination thereof. In an exemplary embodiment, the communication component 816 receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component 816 further includes a Near Field Communication (NFC) module to facilitate short-range communication. For example, the NFC module may be implemented based on Radio Frequency Identification (RFID) technology, Infrared Data Association (IrDA) technology, Ultra Wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.

[0123] In an exemplary embodiment, the device 800 may be implemented by one or more Application Specific Integrated Circuits (ASICs), Digital Signal Processors (DSPs), Digital Signal Processing Devices (DSPDs), Programmable Logic Devices (PLDs), Field Programmable Gate Arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components for performing the above method.

[0124] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions, such as the memory 804 including instructions, is also provided. The above instructions may be executed by the processor 820 of the device 800 to complete the above method. For example, the non-transitory computer-readable storage medium may be a ROM, Random Access Memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device, etc.

[0125] A non-transitory computer-readable storage medium, when the instructions in the storage medium are executed by the processor of the terminal device, enables the terminal device to execute the split-screen processing method of the terminal device.

[0126] Those skilled in the art will readily conceive of other embodiments of the present disclosure after considering the specification and practicing the invention disclosed herein. The present disclosure is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common general knowledge or conventional technical means in the technical field not disclosed by the present disclosure. The specification and embodiments are only to be considered as exemplary, and the true scope and spirit of the present disclosure are pointed out by the following claims.

[0127] It should be understood that the present disclosure is not limited to the exact structures described above and shown in the drawings, and various modifications and changes may be made without departing from its scope. The scope of the present disclosure is only limited by the appended claims.

Claims

1. A data encryption method, characterized in that, Including: Obtain a random number plaintext, where the random number plaintext is a random number generated together with an iterative affine key; Perform an encryption operation on the random number according to the iterative affine key to obtain a random number ciphertext, and determine the random number ciphertext as a pseudo-public key; Send the pseudo-public key to a data receiving device, so that the data receiving device uses the pseudo-public key to perform a data encryption operation on the plaintext to be calculated to obtain a second target ciphertext; Send the second target ciphertext to a data sending device, so that the data sending device performs a ciphertext calculation operation according to the first target ciphertext and the second target ciphertext, where the ciphertext calculation includes one or more of addition calculation and scalar multiplication calculation, and the first target ciphertext is obtained by the data sending device encrypting the plaintext to be calculated using the random number plaintext.

2. The method according to claim 1, characterized in that, The performing an encryption operation on the random number according to the iterative affine key to obtain a random number ciphertext includes: According to the iterative affine key, perform an encryption operation on the random number plaintext in an iterative affine encryption manner to obtain the random number ciphertext.

3. The method according to claim 2, characterized in that, The according to the iterative affine key, performing an encryption operation on the random number plaintext in an iterative affine encryption manner to obtain the random number ciphertext includes: Perform a decimal point shifting operation on the floating point numbers in the random number plaintext to obtain an integer plaintext corresponding to the random number plaintext; Use the iterative affine key to perform a preset number of iterative affine encryption operations on the integer plaintext to obtain the random number ciphertext.

4. The method according to claim 1, characterized in that, After obtaining the random number plaintext, it further includes: Obtain the plaintext to be calculated; Multiply the plaintext to be calculated by the random number plaintext to obtain preprocessed data; According to the iterative affine key, perform an encryption operation on the preprocessed data in an iterative affine encryption manner to obtain a first target ciphertext.

5. The method according to claim 4, characterized in that, After sending the pseudo-public key to the data receiving device, it further includes: Obtain the second target ciphertext sent by the data receiving device, where the first target ciphertext and the second target ciphertext are in the same ciphertext domain, and the second target ciphertext is obtained by the data receiving device performing a data encryption operation on the plaintext to be calculated using the pseudo-public key; Perform a ciphertext calculation operation according to the first target ciphertext and the second target ciphertext to obtain a calculation result, where the ciphertext calculation includes one or more of addition calculation and scalar multiplication calculation.

6. A data encryption method, characterized in that, Including: Obtain a pseudo-public key sent by a data sending device, where the pseudo-public key is obtained by the data sending device performing an encryption operation on a random number plaintext generated together with an iterative affine key in an iterative affine encryption manner; According to the pseudo-public key, perform an encryption operation on the plaintext to be calculated to obtain a second target ciphertext; Send the second target ciphertext to the data sending device, so that the data sending device performs a ciphertext calculation operation according to the first target ciphertext and the second target ciphertext, where the ciphertext calculation includes one or more of addition calculation and scalar multiplication calculation, and the first target ciphertext is obtained by the data sending device encrypting the plaintext to be calculated using the random number plaintext.

7. The method according to claim 6, characterized in that, Performing an encryption operation on the plaintext to be calculated according to the pseudo-public key to obtain a second target ciphertext, including: Performing a scalar multiplication operation on the plaintext to be calculated and the pseudo-public key to obtain a second target ciphertext.

8. The method according to claim 6, characterized in that, Performing an encryption operation on the plaintext to be calculated according to the pseudo-public key to obtain a second target ciphertext, including: Performing an assignment initialization operation on the pseudo-public key to obtain a target pseudo-public key, where the target pseudo-public key has a preset target attribute after the assignment initialization; Performing an encryption operation on the plaintext to be calculated using the target pseudo-public key to obtain the second target ciphertext.

9. The method according to claim 8, characterized in that, Performing an encryption operation on the plaintext to be calculated using the target pseudo-public key to obtain the second target ciphertext, including: Performing a multiplication operation on the target pseudo-public key and the plaintext to be calculated to obtain a second target ciphertext.

10. A data sending device, characterized in that, Including: An acquisition module, configured to acquire a random plaintext, where the random plaintext is a random number generated together with an iterative affine key; An encryption module, configured to perform an encryption operation on the random number according to the iterative affine key to obtain a random ciphertext, and determine the random ciphertext as the pseudo-public key; A sending module, configured to send the pseudo-public key to a data receiving device, so that the data receiving device performs a data encryption operation on the plaintext to be calculated using the pseudo-public key to obtain a second target ciphertext; A transmission module, configured to send the second target ciphertext to the data sending device, so that the data sending device performs a ciphertext calculation operation according to the first target ciphertext and the second target ciphertext, where the ciphertext calculation includes one or more of addition calculation and scalar multiplication calculation, and the first target ciphertext is obtained by the data sending device encrypting the plaintext to be calculated using the random plaintext.

11. A data receiving device, characterized in that, Including: A pseudo-public key acquisition module, configured to acquire a pseudo-public key sent by a data sending device, where the pseudo-public key is obtained by the data sending device performing an encryption operation on a random plaintext generated together with an iterative affine key in an iterative affine encryption manner; A processing module, configured to perform an encryption operation on the plaintext to be calculated according to the pseudo-public key to obtain a second target ciphertext; A transmission module, configured to send the second target ciphertext to the data sending device, so that the data sending device performs a ciphertext calculation operation according to the first target ciphertext and the second target ciphertext, where the ciphertext calculation includes one or more of addition calculation and scalar multiplication calculation, and the first target ciphertext is obtained by the data sending device encrypting the plaintext to be calculated using the random plaintext.

12. An electronic device, characterized in that, Including: A memory, a processor; A memory; A memory for storing executable instructions of the processor; Wherein, the processor is configured to call program instructions in the memory to execute the data encryption method according to any one of claims 1-5 or 6-9.

13. A computer-readable storage medium, characterized in that, Computer-executable instructions are stored in the computer-readable storage medium, and when the computer-executable instructions are executed by a processor, they are used to implement the data encryption method according to any one of claims 1-5 or 6-9.

14. A computer program product, characterized in that, Comprising a computer program which, when executed by a processor, implements the data encryption method according to any one of claims 1-5 or 6-9.

Citation Information

Patent Citations

  • Encoding / Decoding method using multiple affine key, authentication method and each device using the same

    JP2001308845A