Data preprocessing method, data encryption method, device and equipment

By pre-generating and storing the first component of ciphertext data before encryption, the problem of long-term encryption process in the prior art is solved, and the ciphertext data is quickly obtained and the service processing efficiency is improved.

CN115396150BActive Publication Date: 2025-06-13ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202210875433.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-25
Publication Date
2025-06-13
Estimated Expiration
2042-07-25

AI Technical Summary

Technical Problem

The existing data encryption technology takes a long time during the encryption process, affecting the efficiency of business processing.

Method used

By pre-creating the first component of the ciphertext data before encryption and storing it into the data set, a second component is generated based on the plaintext data when encryption is required, the first component is selected from the data set, and the ciphertext data is calculated, thereby reducing the calculation amount of the online process.

Benefits of technology

It realizes the rapid acquisition of ciphertext data when encryption is required, and improves business processing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115396150B_ABST
    Figure CN115396150B_ABST
Patent Text Reader

Abstract

The embodiments of this specification disclose a data preprocessing method, a data encryption method, a device, and a device. The data preprocessing method includes: generating a first component of ciphertext data; storing the first component in a dataset; so that when it is necessary to encrypt plaintext data, generating a second component of ciphertext data according to the plaintext data, selecting the first component from the dataset, and calculating the ciphertext data according to the first component and the second component. The embodiments of this specification can quickly obtain ciphertext data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of this specification relate to the field of computer technology, and particularly to a data preprocessing method, a data encryption method, an apparatus, and a device. Background Art

[0002] With the increasing variety and quantity of data, in order to avoid losses caused by the leakage of sensitive data such as company data and customer data, data encryption technology has been widely applied.

[0003] Currently, in the data encryption technology, the encryption process takes a long time, thus affecting the processing efficiency of the service. Summary of the Invention

[0004] The embodiments of this specification provide a data preprocessing method, a data encryption method, an apparatus, and a device.

[0005] In a first aspect of the embodiments of this specification, a data preprocessing method is provided, including:

[0006] Generating a first component of ciphertext data;

[0007] Storing the first component in a data set; so that when it is necessary to encrypt plaintext data, a second component of ciphertext data is generated according to the plaintext data, the first component is selected from the data set, and the ciphertext data is calculated according to the first component and the second component.

[0008] In a second aspect of the embodiments of this specification, a data preprocessing method is provided, including:

[0009] Receiving a data acquisition request;

[0010] Generating a first component of ciphertext data;

[0011] Feeding back the first component; the first component is used to be stored in a data set, and when it is necessary to encrypt plaintext data, a second component of ciphertext data is generated according to the plaintext data, the first component is selected from the data set, and the ciphertext data is calculated according to the first component and the second component.

[0012] In a third aspect of the embodiments of this specification, a data encryption method is provided, including:

[0013] Generating a second component of ciphertext data according to the plaintext data;

[0014] Selecting a first component of ciphertext data from the data set;

[0015] Calculating the ciphertext data of the plaintext data according to the first component and the second component.

[0016] In a fourth aspect of the embodiments of this specification, a data preprocessing apparatus is provided, including:

[0017] A generating unit, configured to generate a first component of ciphertext data;

[0018] A storage unit, configured to store the first component in a dataset; so that when encrypting plaintext data, a second component of ciphertext data is generated according to the plaintext data, the first component is selected from the dataset, and the ciphertext data is calculated according to the first component and the second component.

[0019] In a fifth aspect of the embodiments of the present specification, a data preprocessing device is provided, including:

[0020] A receiving unit, configured to receive a data acquisition request;

[0021] A generating unit, configured to generate a first component of ciphertext data;

[0022] A feedback unit, configured to feedback the first component; the first component is used to be stored in a dataset, when encrypting plaintext data, a second component of ciphertext data is generated according to the plaintext data, the first component is selected from the dataset, and the ciphertext data is calculated according to the first component and the second component.

[0023] In a sixth aspect of the embodiments of the present specification, a data encryption device is provided, including:

[0024] A generating unit, configured to generate a second component of ciphertext data according to plaintext data;

[0025] A selecting unit, configured to select a first component of ciphertext data from a dataset;

[0026] A calculating unit, configured to calculate the ciphertext data of the plaintext data according to the first component and the second component.

[0027] In a seventh aspect of the embodiments of the present specification, a computer device is provided, including:

[0028] At least one processor;

[0029] A memory storing program instructions, wherein the program instructions are configured to be executed by the at least one processor, and the program instructions include instructions for executing the method described in the first aspect or the second aspect.

[0030] The technical solution provided by the embodiments of the present specification can pre-generate a first component of ciphertext data before encrypting plaintext data, and the first component can be stored in a dataset. In this way, when encrypting plaintext data, a second component of ciphertext data can be generated according to the plaintext data, the first component can be selected from the dataset, and the ciphertext data can be calculated according to the first component and the second component. So that when encrypting plaintext data, ciphertext data can be quickly obtained. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] In order to more clearly illustrate the technical solutions in the embodiments of this specification or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. The drawings in the following description are only some embodiments recorded in this specification. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0032] Figure 1 It is a schematic diagram of the encryption process in the embodiments of this specification;

[0033] Figure 2 It is a schematic flowchart of the data preprocessing method in the embodiments of this specification;

[0034] Figure 3 It is a schematic flowchart of the data preprocessing method in the embodiments of this specification;

[0035] Figure 4 It is a schematic flowchart of the data encryption method in the embodiments of this specification;

[0036] Figure 5 It is a schematic diagram of the encryption process in the embodiments of this specification;

[0037] Figure 6 It is a schematic diagram of the structure of the data preprocessing device in the embodiments of this specification;

[0038] Figure 7 It is a schematic diagram of the structure of the data preprocessing device in the embodiments of this specification;

[0039] Figure 8 It is a schematic diagram of the structure of the data encryption device in the embodiments of this specification;

[0040] Figure 9 It is a schematic diagram of the structure of the computer device in the embodiments of this specification. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0041] The following will clearly and completely describe the technical solutions in the embodiments of this specification in conjunction with the drawings in the embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all of the embodiments. Based on the embodiments in this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of this specification.

[0042] In the field of multi-party secure computing, multi-party secure computing based on homomorphic encryption can be applied to various business scenarios, such as medical scenarios, model training scenarios, risk prediction scenarios, etc. For example, a business scenario can include: a group of people want to calculate the average salary, but each person does not want others to know their own salary. Another example, another business scenario can include: two competitive millionaires meet, and they want to compare who is richer, but they don't want to disclose their wealth information.

[0043] The homomorphic encryption is a data encryption technology. It allows direct operations on ciphertext data to obtain an encrypted result, and the result obtained by decrypting it is the same as the result of performing the same operation on plaintext data. Homomorphic encryption algorithms can include partially homomorphic encryption (PHE) algorithms and fully homomorphic encryption (FHE) algorithms. The partially homomorphic encryption algorithm can support homomorphic addition operations or homomorphic multiplication operations. The partially homomorphic encryption algorithm that supports homomorphic addition operations is also called an additive homomorphic encryption algorithm. The partially homomorphic encryption algorithm that supports homomorphic multiplication operations is also called a multiplicative homomorphic encryption algorithm. The additive homomorphic encryption algorithm can support the following operations: adding homomorphic ciphertext data to homomorphic ciphertext data, adding homomorphic ciphertext data to plaintext data, multiplying homomorphic ciphertext data by plaintext data. But it does not support the following operation: multiplying homomorphic ciphertext data by homomorphic ciphertext data. The multiplicative homomorphic encryption algorithm can support the following operations: multiplying homomorphic ciphertext data by homomorphic ciphertext data, multiplying homomorphic ciphertext data by plaintext data, adding homomorphic ciphertext data to plaintext data. But it does not support the following operation: adding homomorphic ciphertext data to homomorphic ciphertext data. The fully homomorphic encryption algorithm can support both homomorphic addition operations and homomorphic multiplication operations.

[0044] Homomorphic encryption has good cryptographic properties. However, the encryption process takes a long time, thus affecting the processing efficiency of the business.

[0045] The inventors found that the encryption process of the encryption algorithm can be split into an offline process and an online process. The offline process is independent of the plaintext data to be encrypted and thus can be pre-executed. The online process is related to the plaintext data to be encrypted. When the plaintext data needs to be encrypted, the execution result of the offline process can be directly obtained; the execution result of the online process can be obtained according to the plaintext data; the ciphertext data of the plaintext data can be calculated according to the execution result of the offline process and the execution result of the online process. In this way, by pre-executing the offline process, when the plaintext data needs to be encrypted, only the online process needs to be executed, thereby reducing the amount of calculation, facilitating the quick acquisition of ciphertext data, and improving the processing efficiency of the business.

[0046] Taking the additive homomorphic encryption algorithm as an example, the additive homomorphic encryption algorithm may include the Paillier algorithm, the OU (Okamoto-Uchiyama) algorithm, etc. The keys involved in the homomorphic encryption algorithm include a public key and a private key. The public key is used to encrypt the plaintext data to obtain homomorphic ciphertext data. By performing operations on the homomorphic ciphertext data, an encrypted result can still be obtained. The private key is used to decrypt the result. The plaintext data can be encrypted according to the formula c = g m h r mod n. c is the homomorphic ciphertext data, r is a random number, m is the plaintext data, (n, g, h) is the public key, and mod represents the remainder operation. The calculation process of h r has nothing to do with the plaintext data m and can be an offline process. The calculation process of g m is related to the plaintext data m and can be an online process. Before encrypting the plaintext data m, h r can be pre-computed. In this way, when it is necessary to encrypt the plaintext data m, the calculation result of h r can be directly obtained; the homomorphic ciphertext data c can be calculated according to the calculation result of h r and g, m, n. In this way, when encrypting the plaintext data m, there is no need to calculate h r again, reducing the amount of calculation and enabling the ciphertext data c to be obtained quickly.

[0047] In some embodiments, referring to Figure 1 , the offline process and the online process can be deployed on the same device. The embodiments of this specification can provide an encryption device. The encryption device may include any device, equipment, platform, device cluster, etc. with computing and processing capabilities. The encryption device can generate the first component of the ciphertext data; the first component can be stored in a dataset. When it is necessary to encrypt the plaintext data, the encryption device can generate the second component of the ciphertext data according to the plaintext data; the first component can be selected from the dataset; the ciphertext data can be calculated according to the first component and the second component.

[0048] In some embodiments, referring to Figure 1, the offline process and the online process can be deployed on different devices respectively. An embodiment of this specification can provide an encryption system. The encryption system can include a first device and a second device. The first device and the second device can include any device, equipment, platform, device cluster, etc. with computing and processing capabilities. The first device is used to implement the online process, and the second device is used to implement the offline process. Specifically, the first device can send a data acquisition request to the second device. The second device can receive the data acquisition request; can generate the first component of the ciphertext data; and can feedback the first component to the first device. The first device can receive the first component; and can store the first component in the dataset. When encrypting plaintext data is required, the first device can generate the second component of the ciphertext data according to the plaintext data; can select the first component from the dataset; and can calculate the ciphertext data according to the first component and the second component.

[0049] In the above embodiment, the offline process and the online process can be used to implement an encryption algorithm. The encryption algorithm can include a homomorphic encryption algorithm. The homomorphic encryption algorithm can include a semi-homomorphic encryption algorithm and a fully homomorphic encryption algorithm. The semi-homomorphic encryption algorithm can include an additive homomorphic encryption algorithm and a multiplicative homomorphic encryption algorithm. Of course, the encryption algorithm can also include other encryption algorithms, such as non-homomorphic encryption algorithms like the DES algorithm, AES algorithm, IDEA algorithm, RSA algorithm, etc.

[0050] An embodiment of this specification provides a data preprocessing method. The data preprocessing method can be applied to the encryption device. The encryption device can include any device, equipment, platform, device cluster, etc. with computing and processing capabilities.

[0051] Please refer to Figure 2 . The data preprocessing method is used to implement the offline process, and specifically can include the following steps.

[0052] Step S11: Generate the first component of the ciphertext data.

[0053] In some embodiments, the component can refer to the quantity obtained when divided into several parts. For example, when a vector is decomposed into the sum of vectors in multiple directions, each vector in each direction can be called a component. The ciphertext data can include homomorphic ciphertext data. The generation of the first component has nothing to do with the plaintext data. Therefore, before encrypting the plaintext data, the first component of the ciphertext data can be pre-generated, which is beneficial to quickly obtaining the ciphertext data.

[0054] In some embodiments, a first component of ciphertext data can be generated according to an encryption key (hereinafter referred to as the first encryption key). The first encryption key can include a public key. The first key can be calculated according to a key generation algorithm. The key generation algorithm can include an elliptic curve algorithm, etc. For example, a large prime number p and a large prime number q can be generated; n = p 2 q can be calculated; a random number g can be generated; h = g n mod n can be calculated. The random number g satisfies the conditions: g < n and g p-1 ≠ 1 mod p 2 . Then the public key can include (n, g, h), and the private key can include (p, q). The first encryption key can include the public key h. The public key g and the public key n can be the second encryption key and the third encryption key in the following text, respectively.

[0055] The first component of the ciphertext data can be directly generated according to the first encryption key. Alternatively, a random number can also be generated; the first component of the ciphertext data can be generated according to the random number and the first encryption key. The random number can include a random positive integer, etc. In practical applications, a predetermined algorithm can be used to generate the first component of the ciphertext data. For example, the first component of the ciphertext data can be calculated according to the formula h r . h represents the first encryption key, and r represents the random number.

[0056] Step S13: Store the first component in the dataset.

[0057] In some embodiments, the first component can be stored in the dataset. In this way, when it is necessary to encrypt the plaintext data, the second component of the ciphertext data can be generated according to the plaintext data; the first component of the ciphertext data can be selected from the dataset; the ciphertext data of the plaintext data can be calculated according to the first component and the second component. The dataset can be implemented in ways such as a data pool, a data table, a linear list, a queue, a stack, or a graph. The dataset can include one or more first components of the ciphertext data. The dataset can be located in a memory. The memory can include an internal memory and an external memory, etc. The external memory can include a disk storage device, a solid-state storage device, a flash device, and a network-attached memory, etc.

[0058] In some embodiments, it is possible to detect whether the data volume of a data set reaches a threshold; if the data volume of the data set does not reach the threshold, a first component of ciphertext data can be generated. The data volume of the data set can include the number of data in the data set. The threshold can include the maximum data volume that the data set can accommodate. Alternatively, the threshold can also include a specific value less than the maximum data volume. The threshold can be an empirical value. Alternatively, the threshold can also be obtained through machine learning. For example, if the maximum data volume that the data set can accommodate is 1.5 million, the threshold can be 1 million. If the data volume of the data set is less than 1 million, a first component of ciphertext data can be generated. Alternatively, considering that the generation of the first component will consume computer resources (such as memory resources), thus affecting the real-time calculation of ciphertext data, it is possible to detect whether there is currently a task for encrypting plaintext data; if there is no task for encrypting plaintext data, a first component of ciphertext data can be generated. This can improve the real-time calculation efficiency of ciphertext data, thus facilitating the quick acquisition of ciphertext data.

[0059] The data preprocessing method according to the embodiments of this specification can, before encrypting plaintext data, pre-generate a first component of ciphertext data and store the first component in the data set. In this way, when it is necessary to encrypt plaintext data, a second component of ciphertext data can be generated according to the plaintext data, the first component can be selected from the data set, and the ciphertext data can be calculated based on the first component and the second component. So that, when it is necessary to encrypt plaintext data, ciphertext data can be quickly obtained.

[0060] The embodiments of this specification provide another data preprocessing method. The data preprocessing method can be applied to the second device. The second device can include any device, equipment, platform, device cluster, etc. with computing and processing capabilities.

[0061] Please refer to Figure 3 for this. The data preprocessing method is used to implement an offline process and specifically can include the following steps.

[0062] Step S21: Receive a data acquisition request.

[0063] Step S23: Generate a first component of ciphertext data.

[0064] Step S25: Feedback the first component so that the first component can be stored in the data set.

[0065] In some embodiments, a first device may send a data acquisition request to a second device. The second device may receive the data acquisition request; may generate a first component of ciphertext data; and may feed back the first component to the first device. The first device may receive the first component; and may store the first component in a data set. Thus, when it is necessary to encrypt plaintext data, the second device may generate a second component of the ciphertext data according to the plaintext data; may select the first component of the ciphertext data from the data set; and may calculate the ciphertext data of the plaintext data based on the first component and the second component.

[0066] The first device may detect whether the data volume of the data set reaches a threshold; if the data volume of the data set does not reach the threshold, it may send a data acquisition request to the second device. The threshold may include the maximum data volume that the data set can accommodate. Alternatively, the threshold may also include a specific value less than the maximum data volume.

[0067] The second device may generate a first component; and may feed back a first component. Correspondingly, the first device may receive a first component; and may store a first component in the data set. Alternatively, to improve efficiency, the second device may also batch-generate multiple first components; and may feed back multiple first components. Correspondingly, the first device may receive multiple first components; and may store multiple first components in the data set. Among them, an agreement may be made between the first device and the second device on the number of first components to be generated for each data acquisition request. The second device may comply with the agreement and batch-generate multiple first components. Alternatively, a specified quantity may also be carried in the data acquisition request. The second device may generate the specified number of first components. For example, the first device may obtain the current data volume of the data set; and may subtract the current data volume from the maximum data volume that the data set can accommodate to obtain the specified quantity.

[0068] The data preprocessing method according to the embodiments of this specification may pre-generate a first component of ciphertext data before encrypting plaintext data, and may store the first component in a data set. Thus, when it is necessary to encrypt plaintext data, a second component of the ciphertext data may be generated according to the plaintext data, the first component may be selected from the data set, and the ciphertext data may be calculated based on the first component and the second component. So that, when it is necessary to encrypt plaintext data, the ciphertext data can be quickly obtained.

[0069] The embodiments of this specification provide a data encryption method. The data encryption method may be applied to an encryption device or a first device. The encryption device and the first device may include any device, equipment, platform, device cluster, etc. with computing and processing capabilities. Please refer to Figure 4。The data encryption method is used to implement an online process, and specifically may include the following steps.

[0070] Step S31: Generate a second component of the ciphertext data according to the plaintext data.

[0071] In some embodiments, the plaintext data may include service data such as user data, commodity data, transaction data, and behavior data. The user data may include age, gender, occupation, etc. The commodity data may include commodity categories, review data, etc. The transaction data may include transaction amount, transaction channel, etc. The behavior data may include transaction behavior data, payment behavior data, etc. The plaintext data may include text data, image data, video data, audio data, etc. In practical applications, the plaintext data may be generated by an encryption device or a first device. Alternatively, the plaintext data may also be sent to the encryption device or the first device by other devices.

[0072] In some embodiments, a second component of the ciphertext data may be generated according to the plaintext data and an encryption key (hereinafter referred to as the second encryption key). The second encryption key may include a public key. The second encryption key may be calculated according to a key generation algorithm. The key generation algorithm may include an elliptic curve algorithm. The second encryption key and the first encryption key may be the same or different. The generation method of the second encryption key may refer to the generation method of the first encryption key.

[0073] In practical applications, a predetermined algorithm may be used to generate the second component of the ciphertext data. For example, the second component of the ciphertext data may be calculated according to the formula g m where g represents the second encryption key and m represents the plaintext data.

[0074] Step S33: Select a first component of the ciphertext data from the dataset.

[0075] In some embodiments, the dataset may include one or more first components of the ciphertext data. The first component may be randomly selected from the dataset. Alternatively, other methods may also be used to select the first component from the dataset. For example, the first component in the dataset may correspond to a generation time. The first component with the earliest generation time may be selected from the dataset.

[0076] In some embodiments, in order to enhance the security of the ciphertext data and increase the cracking difficulty, for different plaintext data, different first components may be used to calculate the corresponding ciphertext data. To this end, after the first component is selected from the dataset, the selected first component may be deleted to avoid the repeated use of the first component. That is, the first components in the dataset will be continuously consumed. Therefore, it is necessary to continuously generate first components to supplement the first components in the dataset.

[0077] In some embodiments, it is possible to detect whether the data set is empty. If not, the first component of the ciphertext data can be selected from the data set. If so, the first component of the ciphertext data can be generated. The specific generation process will not be elaborated here.

[0078] Step S35: Calculate the ciphertext data of the plaintext data according to the first component and the second component.

[0079] In some embodiments, the ciphertext data may include homomorphic ciphertext data. A predetermined algorithm can be used to calculate the ciphertext data. For example, mathematical operations such as addition, subtraction, multiplication, or division can be performed on the first component and the second component to obtain the ciphertext data. In practical applications, the ciphertext data can be calculated only according to the first component and the second component. Alternatively, the ciphertext data can also be calculated according to the first component, the second component, and an encryption key (hereinafter referred to as the third encryption key). The third encryption key may include a public key. The third encryption key can be calculated according to a key generation algorithm. The key generation algorithm may include an elliptic curve algorithm, etc. The third encryption key, the second encryption key, and the first encryption key may be different. Alternatively, any multiple of the third encryption key, the second encryption key, and the first encryption key may be the same. For example, the ciphertext data can be calculated according to the formula c = g m h r modn. h r represents the first component of the ciphertext data, g m represents the second component of the ciphertext data, and n represents the third encryption key.

[0080] In some embodiments, the data encryption method can be applied to a first device. The first device can send a data acquisition request to a second device. The second device can receive the data acquisition request; can generate the first component of the ciphertext data; and can feedback the first component to the first device. The first device can receive the first component; and can store the first component in the data set.

[0081] The data encryption method of the embodiments of this specification can, when it is necessary to encrypt plaintext data, generate the second component of the ciphertext data according to the plaintext data; select the first component of the ciphertext data from the data set; and calculate the ciphertext data according to the first component and the second component. So that, when it is necessary to encrypt plaintext data, the ciphertext data can be obtained quickly.

[0082] Please refer to Figure 5 . The following introduces a scenario example of the embodiments of this specification. It should be noted that the scenario example is only for better understanding the technical effects of the embodiments of this specification and does not constitute an improper limitation on the embodiments of this specification.

[0083] In this scenario example, a key generation algorithm can be used to generate a first encryption key, a second encryption key, and a third encryption key. Specifically, a large prime number p and a large prime number q can be generated; n = p 2 q can be calculated; a random number g can be generated; h = g n mod n can be calculated. The random number g satisfies the conditions: g < n and g p-1 ≠ 1 mod p 2 . Then the public key can include (n, g, h), and the private key can include (p, q). The first encryption key can include the public key h. The second encryption key can include the public key g. The third encryption key can include the public key n.

[0084] In this scenario example, a random number can be generated; according to the random number and the first encryption key, a first component of the ciphertext data can be generated; and the first component can be stored in a dataset. Specifically, the first component of the ciphertext data can be calculated according to the formula h r . h represents the first encryption key, and r represents the random number.

[0085] In this scenario example, when encrypting plaintext data, according to the plaintext data and the second encryption key, a second component of the ciphertext data can be generated; the first component can be selected from the dataset; and according to the first component, the second component, and the third encryption key, the ciphertext data of the plaintext data can be calculated. Specifically, the second component of the ciphertext data can be calculated according to the formula g m . g represents the second encryption key, and m represents the plaintext data. Specifically, the ciphertext data can be calculated according to the formula c = g m h r mod n. h r represents the first component of the ciphertext data, g m represents the second component of the ciphertext data, and n represents the third encryption key.

[0086] In this scenario example, considering the need for security, the binary bit lengths of the random number r, the first encryption key h, and the second encryption key g are often 2048 bits. The binary bit length of the plaintext data m is often 64 bits. Therefore, compared with the random number r, the first encryption key h, and the second encryption key g, the plaintext data m is relatively small. The calculation time-consuming of the power operation is related to the size of the base number and the size of the exponent. Since the plaintext data m is relatively small, the calculation time-consuming of g m is much less than the calculation time-consuming of h r . Experience shows that the calculation time-consuming of h r occupies about 98% of the time, while the calculation time-consuming of g m occupies about 2% of the time. By pre-calculating h r。Thus, when it is necessary to encrypt the plaintext data m, the calculation result of h can be directly obtained r without having to calculate h r again, thus saving 98% of the time.

[0087] Please refer to Figure 6 。The embodiment of this specification also provides a data preprocessing device, which may specifically include the following units.

[0088] A generating unit 41 for generating a first component of the ciphertext data;

[0089] A storage unit 43 for storing the first component in a data set; so that when it is necessary to encrypt the plaintext data, a second component of the ciphertext data is generated according to the plaintext data, the first component is selected from the data set, and the ciphertext data is calculated according to the first component and the second component.

[0090] Please refer to Figure 7 。The embodiment of this specification also provides a data preprocessing device, which may specifically include the following units.

[0091] A receiving unit 51 for receiving a data acquisition request;

[0092] A generating unit 53 for generating a first component of the ciphertext data;

[0093] A feedback unit 55 for feeding back the first component; the first component is used to be stored in a data set, and when it is necessary to encrypt the plaintext data, a second component of the ciphertext data is generated according to the plaintext data, the first component is selected from the data set, and the ciphertext data is calculated according to the first component and the second component.

[0094] Please refer to Figure 8 。The embodiment of this specification also provides an encryption device, which may specifically include the following units.

[0095] A generating unit 61 for generating a second component of the ciphertext data according to the plaintext data;

[0096] A selecting unit 63 for selecting a first component of the ciphertext data from a data set;

[0097] A calculating unit 65 for calculating the ciphertext data of the plaintext data according to the first component and the second component.

[0098] Please refer to Figure 9 。The embodiment of this specification also provides a computer device.

[0099] The computer device may include a memory and a processor.

[0100] The memory includes, but is not limited to, Dynamic Random Access Memory (DRAM), Static Random Access Memory (SRAM), etc. The memory can be used to store computer instructions.

[0101] The processor can be implemented in any suitable manner. For example, the processor can take the form of, for example, a microprocessor or a processor and a computer-readable medium storing computer-readable program code (such as software or firmware) executable by the (micro)processor, logic gates, switches, Application Specific Integrated Circuit (ASIC), programmable logic controller, and embedded microcontroller, etc. The processor can be used to execute the computer instructions to implement Figure 3 or Figure 4 the corresponding embodiments.

[0102] This specification also provides an embodiment of a computer storage medium. The computer storage medium includes, but is not limited to, Random Access Memory (RAM), Read-Only Memory (ROM), Cache, Hard Disk Drive (HDD), Memory Card, etc. The computer storage medium stores computer program instructions. When the computer program instructions are executed, it realizes: This specification Figure 3 or Figure 4 the program instructions or modules of the corresponding embodiments.

[0103] It should be noted that the various embodiments in this specification are described in a progressive manner. For the same or similar parts between the various embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the device embodiments and computer device embodiments, since they are basically similar to the method embodiments, the description is relatively simple. For the relevant parts, reference can be made to the partial description of the method embodiments. Additionally, it can be understood that after reading this specification document, those skilled in the art can, without creative effort, think of combining some or all of the embodiments listed in this specification arbitrarily, and these combinations are also within the scope of disclosure and protection of this specification.

[0104] In the 1990s, it was obvious to distinguish whether an improvement in a technology was an improvement in hardware (e.g., improvement in circuit structures such as diodes, transistors, switches, etc.) or an improvement in software (improvement in method processes). However, with the development of technology, many improvements in method processes today can be regarded as direct improvements in hardware circuit structures. Almost all designers obtain the corresponding hardware circuit structure by programming the improved method process into the hardware circuit. Therefore, it cannot be said that an improvement in a method process cannot be implemented with a hardware entity module. For example, a Programmable Logic Device (PLD) (such as a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logical function is determined by the user programming the device. The designer can program by himself to "integrate" a digital system on a piece of PLD, without having to ask a chip manufacturer to design and manufacture a dedicated integrated circuit chip. Moreover, nowadays, instead of manually manufacturing integrated circuit chips, this programming is mostly implemented using "logic compiler" software, which is similar to the software compiler used in program development and writing. The original code before compilation also has to be written in a specific programming language, which is called Hardware Description Language (HDL), and there is not only one kind of HDL, but many kinds, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones currently are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also be aware that by simply making a little logical programming of the method process with the above-mentioned several hardware description languages and programming it into the integrated circuit, it is easy to obtain the hardware circuit that implements the logical method process.

[0105] The systems, devices, modules or units illustrated in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer can be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or any combination of these devices.

[0106] From the description of the above embodiments, those skilled in the art can clearly understand that this specification can be implemented by means of software plus a necessary general hardware platform. Based on such an understanding, the technical solutions of this specification, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in various embodiments or some parts of the embodiments of this specification.

[0107] This specification can be used in many general-purpose or special-purpose computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet-type devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronic devices, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and so on.

[0108] This specification can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. This specification can also be practiced in a distributed computing environment, where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.

[0109] Although this specification is depicted through embodiments, those of ordinary skill in the art know that this specification has many variations and changes without departing from the spirit of this specification. It is hoped that the appended claims will cover these variations and changes without departing from the spirit of this specification.

Claims

1. A data preprocessing method is applied to the field of multi-party secure computing. The data preprocessing method is used to implement an encryption algorithm, and the encryption algorithm is selected from semi-homomorphic encryption algorithms and fully homomorphic encryption algorithms. The semi-homomorphic encryption algorithm at least includes a semi-homomorphic encryption algorithm that supports homomorphic multiplication operations, and the fully homomorphic encryption algorithm can simultaneously support homomorphic addition operations and homomorphic multiplication operations; the method includes: Generating a first component of ciphertext data according to a first encryption key, where the ciphertext data includes homomorphic ciphertext data; Storing the first component in a data set; So that when it is necessary to perform homomorphic encryption on plaintext data, generating a second component of ciphertext data according to a second encryption key and the plaintext data, selecting the first component from the data set, and calculating the ciphertext data of the plaintext data according to a third encryption key, the first component, and the second component. The ciphertext data is used for multi-party secure computing; The first encryption key, the second encryption key, and the third encryption key are public keys used to implement the encryption algorithm, and the first encryption key, the second encryption key, and the third encryption key are obtained according to a key generation algorithm.

2. The method according to claim 1, wherein generating the first component of the ciphertext data includes: Generating a random number; Generating a first component of ciphertext data according to the random number and the encryption key.

3. The method according to claim 1, wherein generating the first component of the ciphertext data includes: If the data volume of the data set does not reach a threshold, generating a first component of ciphertext data; Or, if there is no task for encrypting plaintext data, generating a first component of ciphertext data.

4. A data preprocessing method is applied to the field of multi-party secure computing. The data preprocessing method is used to implement an encryption algorithm, and the encryption algorithm is selected from semi-homomorphic encryption algorithms and fully homomorphic encryption algorithms. The semi-homomorphic encryption algorithm at least includes a semi-homomorphic encryption algorithm that supports homomorphic multiplication operations, and the fully homomorphic encryption algorithm can simultaneously support homomorphic addition operations and homomorphic multiplication operations; the method includes: Receiving a data acquisition request; Generating a first component of ciphertext data according to a first encryption key, where the ciphertext data includes homomorphic ciphertext data; Feeding back the first component; The first component is used to be stored in a data set. When it is necessary to perform homomorphic encryption on plaintext data, generating a second component of ciphertext data according to a second encryption key and the plaintext data, selecting the first component from the data set, and calculating the ciphertext data of the plaintext data according to a third encryption key, the first component, and the second component. The ciphertext data is used for multi-party secure computing; The first encryption key, the second encryption key, and the third encryption key are public keys used to implement the encryption algorithm, and the first encryption key, the second encryption key, and the third encryption key are obtained according to a key generation algorithm.

5. The method according to claim 4, wherein generating the first component of the ciphertext data includes: Batch generating a plurality of first components; The feeding back the first component includes: Feeding back the plurality of first components.

6. A data encryption method, which is applied to the field of multi-party secure computing. The data encryption method is used to implement an encryption algorithm, and the encryption algorithm is selected from semi-homomorphic encryption algorithms and fully homomorphic encryption algorithms. The semi-homomorphic encryption algorithm at least includes a semi-homomorphic encryption algorithm that supports homomorphic multiplication operations, and the fully homomorphic encryption algorithm can simultaneously support homomorphic addition operations and homomorphic multiplication operations; the method includes: Generating a second component of ciphertext data according to a second encryption key and plaintext data, where the ciphertext data includes homomorphic ciphertext data; Selecting a first component of ciphertext data from a dataset, where the first component of the ciphertext data is generated according to a first encryption key; Calculating the ciphertext data of the plaintext data according to a third encryption key, the first component, and the second component, where the ciphertext data is used for multi-party secure computing; The first encryption key, the second encryption key, and the third encryption key are public keys used to implement the encryption algorithm, and the first encryption key, the second encryption key, and the third encryption key are obtained according to a key generation algorithm.

7. According to the method of claim 6, the generating of the second component of the ciphertext data includes: Generating a second component of ciphertext data according to the plaintext data and the encryption key.

8. According to the method of claim 6, the method further includes: Deleting the selected first component from the dataset.

9. According to the method of claim 6, the method further includes: Sending a data acquisition request; Receiving the first component of the feedback ciphertext data; Storing the first component in the dataset.

10. A data preprocessing device, which is applied to the field of multi-party secure computing. The data preprocessing device is used to implement an encryption algorithm, and the encryption algorithm is selected from semi-homomorphic encryption algorithms and fully homomorphic encryption algorithms. The semi-homomorphic encryption algorithm at least includes a semi-homomorphic encryption algorithm that supports homomorphic multiplication operations, and the fully homomorphic encryption algorithm can simultaneously support homomorphic addition operations and homomorphic multiplication operations; the device includes: A generating unit, which is used to generate a first component of ciphertext data according to a first encryption key, where the ciphertext data includes homomorphic ciphertext data; A storage unit, which is used to store the first component in a dataset; So that when homomorphic encryption of plaintext data is required, a second component of ciphertext data is generated according to a second encryption key and the plaintext data, the first component is selected from the dataset, and the ciphertext data of the plaintext data is calculated according to a third encryption key, the first component, and the second component, where the ciphertext data is used for multi-party secure computing; The first encryption key, the second encryption key, and the third encryption key are public keys used to implement the encryption algorithm, and the first encryption key, the second encryption key, and the third encryption key are obtained according to a key generation algorithm.

11. A data preprocessing device, which is applied to the field of multi-party secure computing. The data preprocessing device is used to implement an encryption algorithm, and the encryption algorithm is selected from semi-homomorphic encryption algorithms and fully homomorphic encryption algorithms. The semi-homomorphic encryption algorithm at least includes a semi-homomorphic encryption algorithm that supports homomorphic multiplication operations, and the fully homomorphic encryption algorithm can simultaneously support homomorphic addition operations and homomorphic multiplication operations; the device Comprising: A receiving unit, configured to receive a data acquisition request; A generating unit, configured to generate a first component of ciphertext data according to a first encryption key, where the ciphertext data includes homomorphic ciphertext data; A feedback unit, configured to feedback the first component; The first component is used to be stored in a dataset. When homomorphic encryption needs to be performed on plaintext data, a second component of the ciphertext data is generated according to a second encryption key and the plaintext data, the first component is selected from the dataset, and the ciphertext data of the plaintext data is calculated according to a third encryption key, the first component, and the second component. The ciphertext data is used for multi-party secure computation; The first encryption key, the second encryption key, and the third encryption key are public keys for implementing the encryption algorithm, and the first encryption key, the second encryption key, and the third encryption key are obtained according to a key generation algorithm.

12. A data encryption device, applied to the field of multi-party secure computation. The data encryption device is used to implement an encryption algorithm, and the encryption algorithm is selected from a semi-homomorphic encryption algorithm and a fully homomorphic encryption algorithm. The semi-homomorphic encryption algorithm at least includes a semi-homomorphic encryption algorithm that supports homomorphic multiplication operations, and the fully homomorphic encryption algorithm can support both homomorphic addition operations and homomorphic multiplication operations; the device Comprising: A generating unit, configured to generate a second component of ciphertext data according to a second encryption key and the plaintext data, where the ciphertext data includes homomorphic ciphertext data; A selecting unit, configured to select a first component of the ciphertext data from a dataset, where the first component of the ciphertext data is generated according to a first encryption key; A calculating unit, configured to calculate the ciphertext data of the plaintext data according to a third encryption key, the first component, and the second component. The ciphertext data is used for multi-party secure computation; The first encryption key, the second encryption key, and the third encryption key are public keys for implementing the encryption algorithm, and the first encryption key, the second encryption key, and the third encryption key are obtained according to a key generation algorithm.

13. A computer device, Comprising: At least one processor; A memory storing program instructions, where the program instructions are configured to be executed by the at least one processor, and the program instructions include instructions for executing the method according to any one of claims 1-9.

Citation Information

Patent Citations

  • Cloud storage-oriented online / offline searchable encryption method based on identity

    CN108924103A

  • A certificate-free online / offline searchable ciphertext method

    CN109274659A

  • Homomorphic encryption processing method and related equipment

    CN113965314A

  • Homomorphic encryption processing method and related equipment

    CN114444108A