Homomorphic encryption-based plaintext data outsourcing encryption system and method

By using homomorphic encryption technology and leveraging the collaborative efforts of data providers, encryption/decryption platforms, and key managers, the security of outsourced data encryption is achieved, solving the problem that traditional encryption cannot be outsourced and improving the security of data transmission and processing.

CN115102687BActive Publication Date: 2025-11-07SHANGHAI HOMO STATE INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210882176.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-26
Publication Date
2025-11-07
Estimated Expiration
2042-07-26

AI Technical Summary

Technical Problem

Traditional data encryption technologies cannot achieve data outsourcing encryption, resulting in data leakage during transmission and third-party trust issues. Furthermore, the processing capacity of existing servers is insufficient to meet the encryption requirements of large data volumes.

Method used

A plaintext data outsourcing encryption system based on homomorphic encryption is adopted. Through the collaborative work of the data provider, encryption/decryption platform and key manager, random numbers are used to obfuscate the plaintext data, and the obfuscated data is encrypted by the homomorphic encryption unit. Finally, the deobfuscation unit performs deobfuscation to ensure that third parties cannot know the original content of the data.

Benefits of technology

This improves the security of outsourced data encryption, making it impossible for encryption/decryption platforms to perceive the original content of the data, thus enhancing the security of data transmission and processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115102687B_ABST
    Figure CN115102687B_ABST
Patent Text Reader

Abstract

The application provides a homomorphic encryption-based plaintext data outsourcing encryption system and method. The outsourcing encryption system comprises a data provider and an encryption and decryption platform. The data provider comprises a data storage unit, a random number generation unit, a confusion unit, a data provider side communication unit and a de-confusion unit. The encryption and decryption platform comprises a platform side communication unit and a homomorphic encryption unit. The data storage unit stores plaintext data to be encrypted. The random number generation unit generates random numbers. The confusion unit uses the random numbers to perform confusion processing on the plaintext data to obtain plaintext confusion data. The data provider side communication unit sends the plaintext confusion data to the encryption and decryption platform. The homomorphic encryption unit uses an encryption key to perform homomorphic encryption on the plaintext confusion data to obtain ciphertext confusion data. The platform side communication unit sends the ciphertext confusion data to the data provider. The de-confusion unit uses the random numbers to perform de-confusion processing on the ciphertext confusion data to obtain ciphertext data.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of data encryption, and particularly relates to a plaintext data outsourcing encryption system and method based on homomorphic encryption. BACKGROUND

[0002] With the increasing importance of information security, more and more people do not want an improper third party to know the real content of data, and therefore data encryption has emerged.

[0003] The encryption process of a traditional password must be completed locally, and if data is outsourced to a third party for encryption, there are problems of data leakage in the transmission process and the trustworthiness of the third party, and there is a great security risk, which is contrary to the original intention of data encryption, and therefore the traditional password cannot realize data outsourcing encryption.

[0004] However, with the advent of the data era, the amount of data is becoming larger and larger, and the processing capacity of the server required for data encryption is becoming stronger and stronger, and therefore it is necessary to develop a new technology to realize data security while allowing a third party with a powerful server to perform data encryption, rather than upgrading the local server. SUMMARY

[0005] The application is made to solve the above problems, and aims to provide a plaintext data outsourcing encryption system and method based on homomorphic encryption with high security.

[0006] In order to achieve the above-mentioned purpose, the application adopts the following scheme:

[0007] <Scheme 1>

[0008] The application provides a plaintext data outsourcing encryption system based on homomorphic encryption, which has the following characteristics: a data provider; and an encryption and decryption platform connected with the data provider through a communication network, wherein the data provider comprises a data storage unit, a random number generation unit, a confusion unit, a data provider side communication unit and a de-confusion unit, the encryption and decryption platform comprises a platform side communication unit and a homomorphic encryption unit, the data storage unit stores plaintext data to be encrypted, the random number generation unit generates random numbers, the confusion unit performs confusion processing on the plaintext data using the random numbers to obtain plaintext confusion data, the data provider side communication unit sends the plaintext confusion data to the encryption and decryption platform, once the platform side communication unit receives the plaintext confusion data, the homomorphic encryption unit performs homomorphic encryption on the plaintext confusion data using an encryption key to obtain ciphertext confusion data, the platform side communication unit sends the ciphertext confusion data to the data provider, and once the data provider side communication unit receives the ciphertext confusion data, the de-confusion unit performs de-confusion processing on the ciphertext confusion data using the random numbers based on the characteristic that homomorphic encryption can perform plaintext and ciphertext operations to obtain ciphertext data.

[0009] In the homomorphic encryption-based plaintext data outsourcing encryption system provided by the application, the system can further comprise a key management party in communication with the encryption and decryption platform via a communication network, wherein the key management party comprises a key generation unit and a key management side communication unit, the key generation unit is configured to generate an encryption key, and the key management side communication unit is configured to send the encryption key to the encryption and decryption platform.

[0010] In the homomorphic encryption-based plaintext data outsourcing encryption system provided by the application, the system can further comprise a key management party in communication with the encryption and decryption platform via a communication network, wherein the key management party comprises a key generation unit and a key management side communication unit, the key generation unit is configured to generate an encryption key, and the key management side communication unit is configured to send the encryption key to the encryption and decryption platform.

[0011] In the homomorphic encryption-based plaintext data outsourcing encryption system provided by the application, the system can further comprise a key management party in communication with the encryption and decryption platform via a communication network, wherein the key management party comprises a key generation unit and a key management side communication unit, the key generation unit is configured to generate an encryption key, and the key management side communication unit is configured to send the encryption key to the encryption and decryption platform.

[0012] In the homomorphic encryption-based plaintext data outsourcing encryption system provided by the application, the system can further comprise a key management party in communication with the encryption and decryption platform via a communication network, wherein the key management party comprises a key generation unit and a key management side communication unit, the key generation unit is configured to generate an encryption key, and the key management side communication unit is configured to send the encryption key to the encryption and decryption platform.

[0013] In the homomorphic encryption-based plaintext data outsourcing encryption system provided by the application, the system can further comprise a key management party in communication with the encryption and decryption platform via a communication network, wherein the key management party comprises a key generation unit and a key management side communication unit, the key generation unit is configured to generate an encryption key, and the key management side communication unit is configured to send the encryption key to the encryption and decryption platform.

[0014] In the homomorphic encryption-based plaintext data outsourcing encryption system provided by the application, the system can further comprise a key management party in communication with the encryption and decryption platform via a communication network, wherein the key management party comprises a key generation unit and a key management side communication unit, the key generation unit is configured to generate an encryption key, and the key management side communication unit is configured to send the encryption key to the encryption and decryption platform.

[0015] <Scheme two>

[0016] The application further provides a homomorphic encryption-based plaintext data outsourcing encryption method, which comprises the following steps:

[0017] The generation unit generates a random number;

[0018] The plaintext data is subjected to confusion processing using the random number to obtain plaintext confusion data;

[0019] The plaintext confusion data is sent to the encryption and decryption platform;

[0020] Once the plaintext confusion data is received, the plaintext confusion data is subjected to homomorphic encryption using the encryption key to obtain ciphertext confusion data;

[0021] The ciphertext confusion data is sent to the data provider;

[0022] Once the ciphertext confusion data is received, the ciphertext confusion data is deconfused using a random number to obtain ciphertext data.

[0023] Effects of the Invention

[0024] According to the homomorphic encryption-based plaintext data outsourcing encryption system and method, the plaintext data is confused using a random number by the confusion unit to obtain plaintext confusion data. Once the plaintext confusion data is received by the platform-side communication unit, the homomorphic encryption unit uses an encryption key to homomorphic encrypt the plaintext confusion data to obtain ciphertext confusion data. Once the ciphertext confusion data is received by the data provider-side communication unit, the deconfusion unit uses a random number to deconfuse the ciphertext confusion data to obtain ciphertext data. Thus, the encryption and decryption platform as a third party cannot perceive the original content of the data in the process of encrypting the data of the data provider, greatly improving the security of data outsourcing encryption. BRIEF DESCRIPTION OF DRAWINGS

[0025] Figure 1 is a structural block diagram of the homomorphic encryption-based plaintext data outsourcing encryption system in the embodiment of the present application.

[0026] Figure 2 is a structural block diagram of the data provider in the embodiment of the present application.

[0027] Figure 3 is a structural block diagram of the key management party in the embodiment of the present application.

[0028] Figure 4 is a structural block diagram of the encryption and decryption platform in the embodiment of the present application; and

[0029] Figure 5 is an action flowchart of the homomorphic encryption-based plaintext data outsourcing encryption system for encrypting plaintext data in the embodiment of the present application. DETAILED DESCRIPTION

[0030] In order to make the technical means, creative features, purposes and effects of the present application easy to understand, the present application is specifically described below in combination with embodiments and drawings.

[0031] <EMBODIMENT>

[0032] Figure 1 is a structural block diagram of the homomorphic encryption-based plaintext data encryption system in the embodiment of the present application.

[0033] As shown in Figure 1 In the present embodiment, the homomorphic encryption-based plaintext data outsourcing encryption system 1000 is used for encrypting plaintext data, and includes a data provider 100, a key management party 200 and an encryption and decryption platform 300.

[0034] The data provider 100 is in communication connection with the encryption and decryption platform 300 through a communication network 400, and the key management party 200 is in communication connection with the encryption and decryption platform 300 through a communication network 500.

[0035] Figure 2 is a structural block diagram of the data provider in the embodiment of the present application.

[0036] As shown in Figure 2 , the data provider 100 comprises a data storage unit 101, a random number generating unit 102, a confusion unit 103, a de-confusion unit 104, a data provider side communication unit 105, a data provider side temporary storage unit 106, and a data provider side control unit 107.

[0037] The data storage unit 101 stores original plaintext data data to be encrypted.

[0038] The random number generating unit 102 is used to generate a random number r.

[0039] The confusion unit 103 is used to perform additive confusion processing on the plaintext data data using the random number r to obtain plaintext confusion data data+r.

[0040] The de-confusion unit 104 is used to perform subtractive de-confusion (i.e., HE(data+r)k1-r) processing on the ciphertext confusion data HE(data+r)k1 using the random number r to obtain ciphertext data HE(data)k1, which is the final ciphertext data required by the data provider 100.

[0041] The data provider side communication unit 105 is used to exchange data between the various constituent parts in the data provider 100 and between the data provider 100 and the encryption and decryption platform 300. For example, the plaintext confusion data obtained by the confusion unit 103 is sent to the encryption and decryption platform 300, and the ciphertext confusion data sent by the encryption and decryption platform 300 is received. In this embodiment, the data provider side communication unit 105 uses an SSL (Secure Sockets Layer) secure channel to send the plaintext confusion data to the encryption and decryption platform 300.

[0042] The data provider side temporary storage unit 106 is used to temporarily store the data exchanged between the various constituent parts in the data provider 100 and between the data provider 100 and the encryption and decryption platform 300, including the plaintext confusion data obtained by the confusion unit 103 and the ciphertext confusion data received from the encryption and decryption platform 300.

[0043] The data provider side control unit 107 is used to control the operation of the various constituent parts in the data provider 100.

[0044] Figure 3is a structure block diagram of the key management party in the embodiment of the present application.

[0045] As shown in Figure 3 , the key management party 200 comprises a key generation part 201, a key management side communication part 202, a key management side temporary storage part 203 and a key management side control part 204.

[0046] The key generation part 201 is used to generate an encryption key k1 used for homomorphic encryption processing of plaintext obfuscated data. In actual application, in order to meet the needs of decryption after encryption, the key generation part 201 usually generates a homomorphic key pair consisting of the encryption key k1 and the decryption key k2. If the key pair adopts a symmetric key system, the encryption key k1 is completely consistent with the decryption key k2, that is, k1=k2; if the key pair adopts an asymmetric key system, the encryption key k1 is a private key and the decryption key k2 is a public key.

[0047] The key management side communication part 202 is used for data exchange between each constituent part in the key management party 200 and between the key management party 200 and the encryption and decryption platform 300. For example, the encryption key generated by the key generation part 201 is sent to the encryption and decryption platform 300. In this embodiment, the key management side communication part 202 sends the encryption key to the encryption and decryption platform 300 in the form of a key envelope

[0048] The key management side temporary storage part 203 is used to temporarily store the data exchanged between each constituent part in the key management party 200 and between the key management party 200 and the encryption and decryption platform 300, including the encryption key k1 generated by the key generation part 201.

[0049] The key management side control part 204 is used to control the work between each constituent part in the key management party 200.

[0050] Figure 4 is a structure block diagram of the encryption and decryption platform in the embodiment of the present application.

[0051] As shown in Figure 4 , the encryption and decryption platform 300 comprises a homomorphic encryption part 301, a platform side communication part 302, a platform side temporary storage part 303 and a platform side control part 304.

[0052] The homomorphic encryption part 301 is used to homomorphically encrypt the plaintext obfuscated data data+r using the encryption key k1 to obtain the ciphertext obfuscated data HE(data+r)k1. All homomorphic encryption algorithms supporting plaintext-ciphertext calculation can be applied in this embodiment, such as full homomorphism, semi-homomorphism, other algorithms with homomorphic properties, etc.

[0053] The platform-side communication section 302 is used to perform data exchange between the respective components in the encryption / decryption platform 300, between the encryption / decryption platform 300 and the data provider 100, and between the encryption / decryption platform 300 and the key management party 200. For example, it receives the plaintext obfuscated data sent by the data provider 100, receives the encryption key sent by the key management party 200, and sends the ciphertext obfuscated data obtained by the homomorphic encryption section 301 to the data provider 100.

[0054] The platform-side temporary storage section 303 is used to temporarily store the data exchanged between the respective components in the encryption / decryption platform 300, between the encryption / decryption platform 300 and the data provider 100, and between the encryption / decryption platform 300 and the key management party 200, including the plaintext obfuscated data received from the data provider 100, the encryption key received from the key management party 200, and the ciphertext obfuscated data obtained by the homomorphic encryption section 301.

[0055] The platform-side control section 304 is used to control the operation of the respective components in the encryption / decryption platform 300.

[0056] The operation process of the plaintext data outsourcing encryption system 1000 based on homomorphic encryption for encrypting plaintext data will be described in detail below in connection with a flowchart.

[0057] Figure 5 is the operation flowchart of the plaintext data outsourcing encryption system based on homomorphic encryption in the embodiment of the present application for encrypting plaintext data.

[0058] As shown in Figure 5 , the operation flowchart of the plaintext data outsourcing encryption system 1000 based on homomorphic encryption for encrypting plaintext data in the present embodiment includes the following steps:

[0059] Step S1, the random number generation section 102 generates a random number r, and then proceeds to step S2.

[0060] Step S2, the obfuscation section 103 uses the random number r to perform additive obfuscation on the plaintext data data to obtain plaintext obfuscated data data+r, and then proceeds to step S3.

[0061] Step S3, the data provider-side communication section 105 sends the plaintext obfuscated data data+r to the encryption / decryption platform 300, and then proceeds to step S4.

[0062] Step S4, once the platform-side communication section 302 receives the plaintext obfuscated data data+r, the homomorphic encryption section 301 uses the encryption key k1 to perform homomorphic encryption on the plaintext obfuscated data data+r to obtain ciphertext obfuscated data HE(data+r)k1, and then proceeds to S5.

[0063] Step S5, the platform-side communication section 302 transmits the ciphertext obfuscated data HE(data+r)k1 to the data provider 100, and then proceeds to step S6.

[0064] Step S6, once the data provider-side communication section 105 receives the ciphertext obfuscated data HE(data+r)k1, the de-obfuscating section 104 performs subtraction de-obfuscating processing on the ciphertext obfuscated data HE(data+r)k1 using the random number r to obtain the ciphertext data HE(data)k1, and then proceeds to an end state.

[0065] Effects of Embodiments

[0066] According to the homomorphic encryption-based plaintext data outsourcing encryption system and method of the present embodiment, since the obfuscating section performs obfuscating processing on the plaintext data using a random number to obtain plaintext obfuscated data, once the platform-side communication section receives the plaintext obfuscated data, the homomorphic encryption section performs homomorphic encryption on the plaintext obfuscated data using an encryption key to obtain ciphertext obfuscated data, and once the data provider-side communication section receives the ciphertext obfuscated data, the de-obfuscating section performs de-obfuscating processing on the ciphertext obfuscated data using the random number to obtain ciphertext data, so that the encryption and decryption platform as a third party cannot perceive the original content of the data in the process of encrypting the data of the data provider, greatly improving the security of data outsourcing encryption.

[0067] The above-described embodiments are preferred cases of the present application and are not intended to limit the scope of protection of the present application.

[0068] For example, in the above-described embodiments, the outsourcing encryption system has a key management party that generates an encryption key used for homomorphic encryption processing on plaintext obfuscated data and transmits the encryption key to the encryption and decryption platform. However, in the present application, the outsourcing encryption system can also not have a key management party, in which case the encryption and decryption platform has a key generation section for generating an encryption key used for encryption processing on plaintext obfuscated data.

[0069] For example, in the above embodiment, the obfuscation unit in the data provider uses a random number to perform additive obfuscation on the plaintext data to obtain plaintext obfuscated data, and correspondingly, the de-obfuscation unit uses a random number to perform subtractive de-obfuscation on the ciphertext obfuscated data to obtain ciphertext data. However, in the present application, the obfuscation unit can also use a random number to perform subtractive obfuscation on the plaintext data to obtain plaintext obfuscated data, and correspondingly, the de-obfuscation unit uses a random number to perform additive de-obfuscation on the ciphertext obfuscated data to obtain ciphertext data; or, the obfuscation unit uses a random number to perform multiplicative or divisive obfuscation on the plaintext data to obtain plaintext obfuscated data, and correspondingly, the de-obfuscation unit uses a random number to perform divisive or multiplicative de-obfuscation on the ciphertext obfuscated data to obtain ciphertext data. In summary, in the process of using a random number to perform obfuscation on plaintext data and de-obfuscation on ciphertext obfuscated data, the operation method of obfuscation can be addition, subtraction, multiplication or division, and the operation method of de-obfuscation of ciphertext only needs to correspond to the operation method of obfuscation, that is, addition corresponds to subtraction, and multiplication corresponds to division.

Claims

1. A homomorphic encryption based clear-text data outsourcing encryption system, characterized by, The system comprises: a data provider; and an encryption and decryption platform connected with the data provider through a communication network, wherein the data provider comprises a data storage unit, a random number generation unit, a confusion unit, a data provider side communication unit and a de-confusion unit, the encryption and decryption platform comprises a platform side communication unit and a homomorphic encryption unit, the data storage unit stores plaintext data to be encrypted, the random number generation unit generates a random number, the confusion unit uses the random number to perform confusion processing on the plaintext data to obtain plaintext confusion data, the data provider side communication unit sends the plaintext confusion data to the encryption and decryption platform, once the platform side communication unit receives the plaintext confusion data, the homomorphic encryption unit uses an encryption key to perform homomorphic encryption on the plaintext confusion data to obtain ciphertext confusion data, the platform side communication unit sends the ciphertext confusion data to the data provider, once the data provider side communication unit receives the ciphertext confusion data, the de-confusion unit uses the random number to perform de-confusion processing on the ciphertext confusion data based on the characteristic that homomorphic encryption can be used to perform plaintext and ciphertext operations to obtain ciphertext data.

2. The homomorphic encryption based clear-text data outsourcing encryption system of claim 1, wherein, The system further comprises: a key management party connected with the encryption and decryption platform through a communication network, wherein the key management party comprises a key generation unit and a key management side communication unit, the key generation unit is used to generate the encryption key, and the key management side communication unit sends the encryption key to the encryption and decryption platform.

3. The homomorphic encryption based plaintext data outsourcing encryption system according to claim 2, characterized in that: wherein the key management side communication unit sends the encryption key to the encryption and decryption platform in the form of a key envelope.

4. The homomorphic encryption based plaintext data outsourcing encryption system according to claim 1, characterized in that: wherein, the encryption and decryption platform further comprises a key generation unit, and the key generation unit is used to generate the encryption key.

5. The homomorphic encryption based plaintext data outsourcing encryption system according to any one of claims 1-4, characterized in that: wherein, the homomorphic encryption is full homomorphic encryption or semi-homomorphic encryption.

6. The homomorphic encryption based plaintext data outsourcing encryption system according to any one of claims 1-4, characterized in that: wherein, the operation method of the confusion processing is addition, subtraction, multiplication or division, and correspondingly, the operation method of the de-confusion processing is subtraction, addition, division or multiplication.

7. The homomorphic encryption based plaintext data outsourcing encryption system according to any one of claims 1-4, characterized in that: wherein the data provider side communication unit sends the plaintext confusion data to the encryption and decryption platform through an SSL secure channel.

8. A homomorphic encryption-based method of outsourcing encryption of plaintext data, characterized by, The system comprises the following steps: generating a random number; using the random number to perform confusion processing on plaintext data to obtain plaintext confusion data; sending the plaintext confusion data to an encryption and decryption platform; once the plaintext confusion data is received, using an encryption key to perform homomorphic encryption on the plaintext confusion data to obtain ciphertext confusion data; sending the ciphertext confusion data to a data provider; Once the ciphertext obfuscated data is received, the ciphertext obfuscated data is de-obfuscated using the random number based on the property of homomorphic encryption that allows plaintext-ciphertext operations to obtain ciphertext data.

Citation Information

Patent Citations

  • Homomorphic encryption-based position privacy querying method

    CN107749865A

  • A data encryption method and decryption method based on a confusion encryption block algorithm

    CN109861819A