Data query equipment, device, computer equipment and storage medium

By using privacy intersection calculation and public random number splicing technology in private information retrieval, the problems of large amount of calculation and low efficiency in the existing technology are solved, and efficient privacy information retrieval and data security protection are achieved.

CN115412356BActive Publication Date: 2025-05-06HANGZHOU QULIAN TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211071644.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-02
Publication Date
2025-05-06
Estimated Expiration
2042-09-02

AI Technical Summary

Technical Problem

The existing private information retrieval methods are based on fully homomorphic encryption, resulting in large data calculations and low information retrieval efficiency.

Method used

By obtaining candidate key values ​​and data items, the common random numbers are spliced ​​to form plain text data, and the holding party key data is obtained using privacy intersection calculations for encryption, and the cipher text data is sent to the data query device. The data query device obtains the query party's key data through the key reference data and the query key value, decrypts the ciphertext data, and determines the data item to be queried based on the common random number.

Benefits of technology

It reduces the amount of data calculation, improves the efficiency of information retrieval, and ensures the privacy and security of data queryers and data holders.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115412356B_ABST
    Figure CN115412356B_ABST
Patent Text Reader

Abstract

The present application provides a data query device method, apparatus, computer equipment and storage medium. In the method, a data holder concatenates data items corresponding to candidate key values ​​with public random numbers, encrypts the concatenated plaintext data using a key, and sends the encrypted data to a data query party. The data query party decrypts the encrypted data using the query party key data, and determines the data items to be queried from the decrypted data using the public random number. The data transmitted between the data holder and the data query device is only encrypted data, and does not involve specific plaintext data, thereby protecting the data security of both parties. The key transmission is transmitted through private intersection calculation. The data query party can only obtain the correct key of the candidate key value that is the same as the query key value to decrypt the data item corresponding to the candidate key value, and cannot obtain the correct keys and data items of other candidate key values, and the data holder cannot know the data items obtained by the data query party.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a data query device method, apparatus, computer equipment and storage medium. Background Art

[0002] Private Information Retrieval (PIR) is a strategy adopted to protect the privacy of personal privacy on public network platforms. When the data query party submits a data query request to the data holder, the data holder is guaranteed not to know the relevant information of the data query party's specific query statement. Currently, in fields such as medical care and patents that have high requirements for retrieval privacy, private information retrieval has a large application space.

[0003] Existing privacy information retrieval is based on fully homomorphic encryption and performs privacy query by constructing polynomial interpolation. This method reduces the amount of communication between the data holder and the data query party, but the amount of data calculation is extremely large and the information retrieval efficiency is low. Summary of the invention

[0004] Based on this, it is necessary to provide a data query device method, apparatus, computer equipment and storage medium to improve the retrieval efficiency of privacy information retrieval in response to the above technical problems.

[0005] In a first aspect, the present application provides a data query method, applied to a data holding device, the method comprising:

[0006] Obtain candidate key values ​​and data items corresponding to the candidate key values;

[0007] Concatenate the public random number and the data item corresponding to the candidate key value to obtain the plaintext data corresponding to the candidate key value;

[0008] The holder's key data is obtained by performing privacy intersection calculation with the data query device, and the plaintext data corresponding to the candidate key value is encrypting using the first key data in the holder's key data to obtain the ciphertext data corresponding to the candidate key value;

[0009] The ciphertext data corresponding to the candidate key value is sent as encrypted data to the data query device, and the encrypted data is used to instruct the data query device to use the query party key data to decrypt the ciphertext data of the candidate key value to obtain decrypted data, and determine the data item to be queried from the decrypted data based on a public random number; wherein the query party key data is obtained based on the key reference data and the query key value, and the key reference data is obtained by the data query device from the first key data and the second key data in the holder's key data by performing a privacy intersection calculation with the data holding device.

[0010] In some embodiments of the present application, the step of obtaining the holder's key data by performing privacy intersection calculation with the data query device includes:

[0011] Obtaining a public mapping function agreed upon with the data query device;

[0012] Mapping the candidate key value to first mapping data corresponding to the candidate key value through a common mapping function;

[0013] Constructing a first random vector corresponding to the candidate key value, and determining the first random vector as first key data;

[0014] Performing a logical operation on the first mapping data corresponding to the candidate key value and the first key data to obtain second key data corresponding to the candidate key value;

[0015] The first key data and the second key data corresponding to the candidate key value are determined as the holder key data.

[0016] In a second aspect, the present application provides a data query method, which is applied to a data query device, and the method includes:

[0017] Receive encrypted data sent by a data holding device; the encrypted data includes ciphertext data corresponding to each candidate key value; wherein the ciphertext data corresponding to the candidate key value is obtained by encrypting the plaintext data corresponding to the candidate key value using the first key data in the key data of the holding party, and the plaintext data corresponding to the candidate key value is obtained by concatenating the public random number and the data item corresponding to the candidate key value;

[0018] Obtain key reference data from the first key data and the second key data in the key data of the holder by performing privacy intersection calculation with the data holding device, and obtain the querying party key data according to the key reference data and the query key value;

[0019] Decrypting the ciphertext data of the candidate key value using the querying party's key data to obtain decrypted data;

[0020] The data item to be queried is determined from the decrypted data based on the public random number.

[0021] In some embodiments of the present application, it is characterized in that the step of determining the data item to be queried from the decrypted data based on the public random number includes:

[0022] Acquire a first data sequence at a target position in the decrypted data;

[0023] If the data sequence matches the public random number, the second data sequence in the decrypted data is determined as the data item to be queried.

[0024] In some embodiments of the present application, the step of obtaining key reference data from the first key data and the second key data in the key data of the holder by performing privacy intersection calculation with the data holding device includes:

[0025] constructing a second random vector;

[0026] An oblivious transmission is initiated to the data holding device based on the second random vector, and key reference data is obtained from the first key data and the second key data in the key data of the holder.

[0027] In some embodiments of the present application, the step of obtaining the querying party key data according to the key reference data and the query key value includes:

[0028] Performing an XOR operation on the second random vector and the query key value to obtain a first operation result;

[0029] Acquire a common mapping function agreed upon with the data query device, and map the first operation result into second mapping data through the common mapping function;

[0030] An XOR operation is performed on the key reference data and the second mapping data to obtain the querying party key data.

[0031] In a third aspect, the present application provides a data query method, which is applied to a data query system, wherein the data query system includes a data holding device and a data query device that are communicatively connected, and the method includes:

[0032] The data holding device and the data query device perform privacy intersection calculation. Through the privacy intersection calculation, the data holding device obtains the holder's key data, and the data query device obtains the key reference data from the first key data and the second key data in the holder's key data.

[0033] The data holding device obtains the candidate key value and the data item corresponding to the candidate key value;

[0034] The data holding device concatenates the public random number and the data item corresponding to the candidate key value to obtain the plaintext data corresponding to the candidate key value;

[0035] The data holding device uses the first key data in the holding party key data to encrypt the plaintext data corresponding to the candidate key value to obtain the ciphertext data corresponding to the candidate key value;

[0036] The data holding device sends the ciphertext data corresponding to the candidate key value as encrypted data to the data query device;

[0037] The data query device receives the encrypted data sent by the data holding device; the encrypted data includes the ciphertext data corresponding to each candidate key value;

[0038] The data query device obtains the query party's key data according to the key reference data and the query key value;

[0039] The data query device uses the query party key data to decrypt the ciphertext data of the candidate key value to obtain decrypted data;

[0040] The data query device determines the data item to be queried from the decrypted data based on the public random number.

[0041] In a fourth aspect, the present application provides a data query device, which is applied to a data holding device, and the device includes:

[0042] A data item acquisition module is used to acquire candidate key values ​​and data items corresponding to the candidate key values;

[0043] A plaintext data acquisition module is used to concatenate the public random number and the data items corresponding to the candidate key value to obtain the plaintext data corresponding to the candidate key value;

[0044] A data encryption module, used to obtain the holder's key data by performing privacy intersection calculation with the data query device, and use the first key data in the holder's key data to encrypt the plaintext data corresponding to the candidate key value to obtain the ciphertext data corresponding to the candidate key value;

[0045] A data sending module is used to send the ciphertext data corresponding to the candidate key value as encrypted data to the data query device, the encrypted data is used to instruct the data query device to use the query party key data to decrypt the ciphertext data of the candidate key value to obtain decrypted data, and determine the data item to be queried from the decrypted data based on a public random number; wherein the query party key data is obtained based on the key reference data and the query key value, and the key reference data is obtained by the data query device from the first key data and the second key data in the holder's key data by performing a privacy intersection calculation with the data holding device.

[0046] In a fifth aspect, the present application provides a data query device, which is applied to a data query device, and the device includes:

[0047] A data receiving module, used to receive encrypted data sent by a data holding device; the encrypted data includes ciphertext data corresponding to each candidate key value; wherein the ciphertext data corresponding to the candidate key value is obtained by encrypting the plaintext data corresponding to the candidate key value using the first key data in the key data of the holding party, and the plaintext data corresponding to the candidate key value is obtained by concatenating the public random number and the data item corresponding to the candidate key value;

[0048] A key acquisition module, used to obtain key reference data from the first key data and the second key data in the key data of the holder by performing privacy intersection calculation with the data holding device, and obtain the querying party key data according to the key reference data and the query key value;

[0049] A data decryption module, used to decrypt the ciphertext data of the candidate key value using the querying party's key data to obtain decrypted data;

[0050] The data determination module is used to determine the data item to be queried from the decrypted data based on the public random number.

[0051] In a sixth aspect, the present application further provides a server, the server comprising:

[0052] one or more processors;

[0053] Memory; and

[0054] One or more application programs, wherein the one or more application programs are stored in the memory and configured to be executed by the processor to implement the data query device method.

[0055] In a seventh aspect, the present application also provides a computer-readable storage medium on which a computer program is stored, and the computer program is loaded by a processor to execute the steps in the data query device method.

[0056] The above-mentioned data query device method, apparatus, computer equipment and storage medium obtain candidate key values ​​and data items corresponding to the candidate key values; concatenate public random numbers and data items corresponding to the candidate key values ​​to obtain plaintext data corresponding to the candidate key values; use the first key data in the holder's key data to encrypt the plaintext data corresponding to the candidate key value to obtain the ciphertext data corresponding to the candidate key value; send the ciphertext data corresponding to the candidate key value as encrypted data to the data query device, the encrypted data is used to instruct the data query device to obtain the query party key data according to the key reference data and the query key value, use the query party key data to decrypt the ciphertext data of the candidate key value to obtain decrypted data, and determine the data item to be queried from the decrypted data based on the public random number; wherein, the holder's key data is obtained by the data holder through a privacy intersection calculation with the data query device, and the key reference data is obtained by the data query device from the first key data and the second key data in the holder's key data through a privacy intersection calculation with the data holder. The data holder concatenates the data item corresponding to the candidate key value with the public random number agreed in advance, encrypts the concatenated plaintext data using the first key data obtained after performing privacy intersection calculation with the data query party, and sends the encrypted data to the data query party. The data query party calculates the query party key data using the key reference data obtained after performing privacy intersection calculation with the data query party and the query key value, and uses the query party key data to decrypt the encrypted data, and then determines the data item to be queried from the decrypted data based on the public random number. The data transmitted between the data holder device and the data query device is only encrypted data, and does not involve specific plaintext data, thereby protecting the data security of both parties. The key transmission is transmitted through privacy intersection calculation, and the data query party can only obtain the correct key of the candidate key value that is the same as the query key value to decrypt the data item corresponding to the candidate key value. The data query party cannot obtain the correct keys and data items of other candidate key values, and the data holder cannot know the data items obtained by the data query party. Both parties realize privacy information retrieval, and the amount of data calculation in the data interaction process is small, and the information retrieval efficiency is high. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.

[0058] Figure 1 It is a scene schematic diagram of the data query device method in the embodiment of the present application;

[0059] Figure 2It is a flow chart of a data query device method in an embodiment of the present application;

[0060] Figure 3 is another flow chart of the data query device method in the embodiment of the present application;

[0061] Figure 4 is another flow chart of the data query device method in the embodiment of the present application;

[0062] Figure 5 It is a structural diagram of a data query device in an embodiment of the present application;

[0063] Figure 6 is another structural schematic diagram of the data query device in the embodiment of the present application;

[0064] Figure 7 It is a schematic diagram of the structure of a computer device in an embodiment of the present application. DETAILED DESCRIPTION

[0065] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of this application.

[0066] In the description of this application, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features. In the description of this application, "plurality" means two or more, unless otherwise clearly and specifically defined.

[0067] In the description of the present application, the word "for example" is used to mean "used as an example, illustration or explanation". Any embodiment described as "for example" in the present application is not necessarily to be construed as being more preferred or advantageous than other embodiments. The following description is given to enable any technician in the field to implement and use the present invention. In the following description, details are listed for the purpose of explanation. It should be understood that a person of ordinary skill in the art can recognize that the present invention can be implemented without using these specific details. In other examples, well-known structures and processes will not be elaborated in detail to avoid obscuring the description of the present invention with unnecessary details. Therefore, the present invention is not intended to be limited to the embodiments shown, but is consistent with the widest scope consistent with the principles and features disclosed in the present application.

[0068] The data query device method provided in the embodiment of the present application can be applied to Figure 1 In the data query system shown. The data query system includes a data storage device 100 and a data query device 200 corresponding to the data holder, and the data storage device 100 and the data query device 200 can be a terminal or a server; wherein the terminal can be a mobile phone, a tablet computer, a laptop computer, etc., and the server can be an independent server or a server network or server cluster composed of servers, which includes but is not limited to a computer, a network host, a single network server, a plurality of network server sets or a cloud server composed of multiple servers. The cloud server is composed of a large number of computers or network servers based on cloud computing (Cloud Computing).

[0069] Those skilled in the art will understand that Figure 1 The application environment shown in the figure is only one application scenario of the present application solution and does not constitute a limitation on the application scenario of the present application solution. Other application environments may also include Figure 1 More or less computer equipment as shown in Figure 1 Only one data query device 200 is shown. It can be understood that the data query system may also include one or more other servers, which are not specifically limited here.

[0070] It should also be noted that Figure 1 The scenario diagram of the data query system shown is only an example. The data query system and scenario described in the embodiment of the present invention are intended to more clearly illustrate the technical solution of the embodiment of the present invention, and do not constitute a limitation on the technical solution provided by the embodiment of the present invention. Ordinary technicians in this field can know that with the evolution of the data query system and the emergence of new business scenarios, the technical solution provided by the embodiment of the present invention is also applicable to similar technical problems.

[0071] See also Figure 2 The present application embodiment provides a data query device method, which is mainly applied to the above Figure 1 Taking the data storage device 100 in FIG. 1 as an example, the method includes steps S210 to S230, which are specifically as follows:

[0072] S210, obtaining candidate key values ​​and data items corresponding to the candidate key values.

[0073] The candidate key value and the data item corresponding to the candidate key value are key-value pairs stored on the data storage device, wherein the key value is used to retrieve and query the corresponding data item.

[0074] Among them, the number of candidate key values ​​and the data items corresponding to the candidate key values ​​is two or more. Specifically, the full amount of key-value pairs can be divided in advance through bucket processing (such as hash modulus bucket processing), and after receiving the data query request sent by the data query device, the key-value pairs stored in a bucket are determined as candidate key values ​​and the data items corresponding to the candidate key values ​​based on the data query request, so as to improve the data query efficiency through offline preprocessing operations when the data volume is large.

[0075] S220, concatenate the public random number and the data items corresponding to the candidate key value to obtain the plaintext data corresponding to the candidate key value.

[0076] Among them, the public random number is a random number agreed upon in advance by the data holder and the data query device, and its data length can be a security length agreed upon in advance by the data holder and the data query device. The public random data can be used to locate the correct data item during the decryption process of the data query device.

[0077] After obtaining the public random number, the data holder concatenates the public random number with the data items corresponding to each candidate key value to obtain the plaintext data corresponding to each candidate key value; specifically, the concatenation of the public random number and the data items corresponding to the candidate key values ​​can be done by placing the public random number in front and the data items in the back, or by placing the public random number in the back and the data items in the front, which is not limited here.

[0078] For example, taking the example of placing the public random number in front and the data item in the back for concatenation, the plaintext data corresponding to the candidate key value can be expressed as the following formula (1):

[0079] v′ i =nonce||v i (1)

[0080] Among them, v′ i represents the plaintext data corresponding to the i-th candidate key value, nonce represents a public random number, and v i Represents the data item corresponding to the i-th candidate key value.

[0081] S230, obtain the holder's key data by performing privacy intersection calculation with the data query device, use the first key data in the holder's key data to encrypt the plaintext data corresponding to the candidate key value, and obtain the ciphertext data corresponding to the candidate key value.

[0082] The holder key data includes the first key data and the second key data, which are obtained by the data holder and the data query device through the private set intersection (PSI). Specifically, in one embodiment, the step of obtaining the holder key data by performing the private set intersection calculation with the data query device may specifically include: obtaining the public mapping function agreed with the data query device; mapping the candidate key value to the first mapping data corresponding to the candidate key value through the public mapping function; constructing the first random vector corresponding to the candidate key value, and determining the first random vector as the first key data; performing a logical operation on the first mapping data and the first key data corresponding to the candidate key value to obtain the second key data corresponding to the candidate key value; and determining the first key data and the second key data corresponding to the candidate key value as the holder key data.

[0083] Among them, the public mapping function is a function agreed in advance by the data holder and the data query device, which is used to map the candidate key value to other values ​​to protect the privacy of the data. Specifically, in one embodiment, the public mapping function can be a pseudo-random number generation function, which can map the input data to a random number sequence with a security length; wherein the security length is agreed in advance by the data holder and the data query device, which can be expressed as λ. The longer the security length, the higher the security and anti-collision of the data during the interaction between the data holder and the data query device; the pseudo-random number is a random number sequence that is calculated by a deterministic algorithm and obeys the {0, 1} distribution. When calculating the pseudo-random number, if the initial value used by the pseudo-random number generation function and the input value remain unchanged, then the number sequence of the pseudo-random number will also remain unchanged. For example, the pseudo-random number generation function is represented by the following formula (2):

[0084]

[0085] In the formula, f k (·) identifies the pseudo-random number generation function; is the set of all candidate key values, called the message space; k is the initial value of the pseudo-random number generation function. For the same k and input values, the results are consistent. For example, the data holder holds data y and the data query device holds data x, then the following formula (3) holds:

[0086]

[0087] The first key data and the second key data may include a vector having a length of security length λ and consisting of 0s and 1s.

[0088] In one embodiment, the first key data is a first key matrix, which includes n random vectors with a security length λ and composed of 0 and 1. Similarly, the second key data is a second key matrix, which includes n random vectors with a security length λ and composed of 0 and 1, where n is the number of candidate key values.

[0089] After mapping each candidate key value into first mapping data having a length of security length λ through a common mapping function, for any candidate key value, an XOR operation can be performed between the first key data corresponding to the candidate key value and the first mapping data corresponding to the candidate key value to obtain the second key data.

[0090] For example, suppose the data holder holds the data: (y1, v1), (y2, v2), ..., (y n , v n ), where y i Represents the candidate key value, v i Represents the data item corresponding to the candidate key value, i∈[1,n]; the data holder first randomly constructs a {0,1} n×λ The matrix R0 (i.e., the first key data) is a matrix R1 (i.e., the second key data). It should be noted that the random vector in the i-th row of the matrix R0 is the first key data corresponding to the i-th candidate key value, i∈[1, n]. At the same time, the matrix R1 (i.e., the second key data) can be calculated by the following formula: Similarly, the vector in the i-th row in the matrix R1 is the second key data corresponding to the i-th candidate key value.

[0091] After obtaining the holder's key data, for any plaintext data corresponding to a candidate key value, the first key data corresponding to the candidate key value in the holder's key data is used to encrypt the plaintext data corresponding to the candidate key value to obtain the ciphertext data corresponding to the candidate key value. Further, the plaintext data corresponding to the candidate key value may be encrypted in a symmetric encryption manner using the first key data.

[0092] For example, the plaintext data corresponding to the candidate key value may be encrypted using the AES encryption algorithm with the first key data.

[0093] S240, sending the ciphertext data corresponding to the candidate key value as encrypted data to the data query device, the encrypted data is used to instruct the data query device to use the query party key data to decrypt the ciphertext data of the candidate key value to obtain decrypted data, and determine the data item to be queried from the decrypted data based on the public random number; wherein, the query party key data is obtained based on the key reference data and the query key value, and the key reference data is obtained by the data query device from the first key data and the second key data in the holder's key data by performing a privacy intersection calculation with the data holding device.

[0094] Specifically, after obtaining the ciphertext data corresponding to all candidate key values, the data holder sends the ciphertext data corresponding to all candidate key values ​​as encrypted data to the data query device.

[0095] The query key value is the key value held by the data query party and is the key value of the data item to be queried. The key reference data is obtained by the data query device from the first key data and the second key data in the key data of the holder through the privacy intersection calculation with the data holding device. The data query device can calculate the query party key data corresponding to each ciphertext data based on the query key value and the key reference data.

[0096] Specifically, if the query key value is the same as a candidate key value (i.e., the target candidate key value), the query party key data obtained according to the key reference data and the query key value is the same as the first key data corresponding to the target candidate key value, and the correct plaintext data can be obtained by decrypting the ciphertext data corresponding to the target candidate key value through the query party key data, and the plaintext data includes the public random number and the data item corresponding to the candidate key value. On the contrary, if the query key value is not the same as a candidate key value (i.e., the target candidate key value), the query party key data obtained according to the key reference data and the query key value is different from the first key data corresponding to the target candidate key value, and the ciphertext data corresponding to the target candidate key value is decrypted by the query party key data. What is obtained is garbled data, and the correct plaintext data cannot be obtained. Therefore, after obtaining the query party key data, the data query device uses the query party key data to decrypt the ciphertext data corresponding to each candidate key value to obtain multiple decrypted data, and can use the public random number to find the correctly decrypted decrypted data from the decrypted data to obtain the data item of the candidate key value matching the query key value.

[0097] In the above-mentioned data query device method, candidate key values ​​and data items corresponding to the candidate key values ​​are obtained; public random numbers and data items corresponding to the candidate key values ​​are concatenated to obtain plaintext data corresponding to the candidate key values; the plaintext data corresponding to the candidate key values ​​are encrypted using the first key data in the holder's key data to obtain ciphertext data corresponding to the candidate key values; the ciphertext data corresponding to the candidate key values ​​are sent to the data query device as encrypted data, and the encrypted data is used to instruct the data query device to obtain the query party key data according to the key reference data and the query key value, decrypt the ciphertext data of the candidate key value using the query party key data to obtain decrypted data, and determine the data items to be queried from the decrypted data based on the public random number; wherein the holder's key data is obtained by the data holder through a privacy intersection calculation with the data query device, and the key reference data is obtained by the data query device from the first key data and the second key data in the holder's key data through a privacy intersection calculation with the data holder. The data holder concatenates the data item corresponding to the candidate key value with the public random number agreed in advance, and then encrypts the concatenated plaintext data using the first key data obtained after performing privacy intersection calculation with the data query party, and sends the encrypted data to the data query party. The data query party calculates the query party's key data using the key reference data obtained after performing privacy intersection calculation with the data query party and the query key value, and uses the query party's key data to decrypt the encrypted data, and then determines the data item to be queried from the decrypted data based on the public random number. The data transmitted between the data holder device and the data query device is only encrypted data, and does not involve specific plaintext data, thereby protecting the data security of both parties. The transmission of the key for encrypting and decrypting the plaintext data is performed through the privacy intersection. The data query party can only obtain the key corresponding to the candidate key value that is the same as the query key value, and can only correctly decrypt the encrypted data corresponding to the candidate key value that is the same as the query key value, but cannot correctly decrypt the encrypted data corresponding to other candidate key values. Furthermore, based on the query party's key data, the encrypted data corresponding to the candidate key value that matches the query key value is decrypted to obtain valid plaintext data, while the encrypted data corresponding to other candidate key values ​​is decrypted to obtain garbled data. Therefore, the data query party can only obtain the data items corresponding to the query key value but cannot obtain other data items, and the data holder cannot know the data items obtained by the data query party. The privacy information retrieval of both parties does not need to adopt homomorphic encryption, which greatly reduces the amount of data calculation and has high information retrieval efficiency.

[0098] In addition, the existing privacy information retrieval based on fully homomorphic encryption requires data items with longer data lengths to be split into data items to construct separate interpolation polynomials, and then multiple interpolation polynomials are concatenated to obtain the encrypted data corresponding to the data items. Compared with the privacy information retrieval based on fully homomorphic encryption, the data query method in the embodiment of the present application can encrypt data items of any length without the need to split and then concatenate the data, thereby greatly improving the efficiency of information retrieval.

[0099] See also Figure 3 The present application embodiment provides a data query device method, which is mainly applied to the above Figure 1 Taking the data query device 200 in FIG. 1 as an example, the method includes steps 310 to S330, which are specifically as follows:

[0100] S310, receiving encrypted data sent by a data holding device; the encrypted data includes ciphertext data corresponding to each candidate key value; wherein, the ciphertext data corresponding to the candidate key value is obtained by encrypting the plaintext data corresponding to the candidate key value using the first key data in the holder's key data, and the plaintext data corresponding to the candidate key value is obtained by concatenating a public random number and a data item corresponding to the candidate key value.

[0101] Among them, the data query device can send a data query request to the data holding device to prompt the data holding device to send encrypted data to the data query device. Specifically, the data holding device can obtain the candidate key value and the data item corresponding to the candidate key value, and after splicing the public random number and the data item corresponding to the candidate key value to obtain the plaintext data corresponding to the candidate key value, use the first key data in the holder's key data obtained by performing a privacy intersection calculation with the data query device in advance, encrypt the plaintext data corresponding to the candidate key value, and obtain the ciphertext data corresponding to the candidate key value.

[0102] It can be understood that the data processing process of the data holding device may refer to the contents of various embodiments of the data query method applied to the data holding device.

[0103] S320, obtaining key reference data from the first key data and the second key data in the holder's key data by performing privacy intersection calculation with the data holding device, and obtaining the querying party's key data according to the key reference data and the query key value.

[0104] The query key value is the key value held by the data query party, and is the key value of the data item to be queried.

[0105] In one embodiment, the step of obtaining key reference data from first key data and second key data in the holder's key data by performing privacy intersection calculation with the data holding device includes: constructing a second random vector; initiating an oblivious transmission to the data holding device based on the second random vector, and obtaining key reference data from the first key data and the second key data in the holder's key data.

[0106] In which, when the data holding device and the data holding device perform the intersection calculation of the private data of the two parties, the data holding device and the data holding device jointly agree on a security length and a public mapping function; the data holding device randomly generates a random vector r0 with a security length and composed of 0 and 1 as the first key data, and generates a random vector r1 as the second key data based on the data held, the pre-agreed public mapping function and the random vector r0; the data query device randomly generates a random vector s (i.e., the second random vector) with a security length and composed of 0 and 1; the data query device initiates an oblivious transmission to the data holding device based on the random vector s, and obtains the key reference data from the random vector r0 and the random vector r1, wherein the oblivious transmission means that the data holding device only provides the information it needs to the data query device, instead of sending all the information (such as the first key data or the second key data) to the data query device. It can be understood that the key reference data is related to the first key data or the second key data in the data holding device, but the data query device does not directly obtain the first key data or the second key data in the data holding device.

[0107] Specifically, the key reference data may be a key reference matrix, which includes n key reference vectors of length λ and composed of 0 and 1, where n is the number of candidate key values; wherein the specific value of the kth column (k∈[1,λ]) in the key reference matrix is ​​determined based on the random vector s; if the value of the kth column in the random vector s is 0, then the value of the kth column in the key reference matrix is ​​the value of the kth column of the first key data (i.e., matrix R0) corresponding to all candidate key values; if the value of the kth column in the random vector s is 1, then the value of the kth column in the key reference matrix is ​​the value of the kth column of the second key data (i.e., matrix R1) corresponding to all candidate key values.

[0108] After obtaining the key reference data, the data query device can perform a logical operation based on the key reference data and the query key value to obtain the query party key data. Specifically, in one embodiment, the step of obtaining the query party key data based on the key reference data and the query key value includes: performing an XOR operation on the second random vector and the query key value to obtain a first operation result; obtaining a public mapping function agreed with the data query device, and mapping the first operation result to second mapping data through the public mapping function; performing an XOR operation on the key reference data and the second mapping data to obtain the query party key data.

[0109] Specifically, as mentioned above, the key reference data may be a key reference matrix; after obtaining the second mapping data, the step of performing an XOR operation on the key reference data and the second mapping data to obtain the query party key data is specifically: arbitrarily obtaining a key reference vector from the key reference matrix, determining it as a target key reference vector, and the target key reference vector corresponds to the target candidate key value; then, performing an XOR operation on the target key reference vector and the second mapping data to obtain the query party key data corresponding to the target candidate key value. For example, the query party key data may be calculated by the following formula (4):

[0110]

[0111] Among them, t i,j represents the querying party key data corresponding to the j-th query key value calculated based on the key reference vector of the i-th row in the key reference matrix, Q i refers to the key reference vector of the i-th row in the key reference matrix, x j is the jth query key value, and s is the second random vector.

[0112] It can be understood that if the query key value is the same as the target candidate key value, the query party key data corresponding to the target candidate key value is the same as the first key data corresponding to the target candidate key value, and the data item corresponding to the target candidate key value can be decrypted; if the query key value is not the same as the target candidate key value, the query party key data corresponding to the target candidate key value is garbled data, and the data item corresponding to the target candidate key value cannot be decrypted;.

[0113] S330, using the querying party's key data to decrypt the ciphertext data of the candidate key value to obtain decrypted data.

[0114] Specifically, the data query device uses the query party key data to decrypt the encrypted data corresponding to each candidate key value respectively, and obtains the decrypted data corresponding to each candidate key value. It can be understood that when the query key value is the same as a candidate key value (i.e., the target candidate key value), the query party key data can decrypt the encrypted data corresponding to the target candidate key value to obtain a correct decryption result, while decrypting the encrypted data corresponding to other candidate key values ​​other than the target candidate key value will obtain an invalid decryption result, that is, the decrypted data corresponding to the candidate key value that matches the query key value is decrypted based on the query party key data. The decrypted data is the plaintext data corresponding to the candidate key value, while the decrypted data corresponding to other candidate key values ​​is garbled data.

[0115] S340, determining a data item to be queried from the decrypted data based on the public random number.

[0116] Among them, the public random number is a random number pre-agreed upon by the data holder and the data query party, and its data length can be a safe length.

[0117] As mentioned above, if the encrypted data is correctly decrypted, the corresponding decrypted data is the plaintext data corresponding to the candidate key value matching the query key value, which is the concatenated public random number and data item; if the encrypted data is invalidly decrypted, the corresponding decrypted data is invalid data. Therefore, if the decrypted data includes a public random number, the decrypted data is the data that is correctly decrypted, and the decrypted data is the data hit by the query key value, where the data other than the public random number is the data item corresponding to the query key value (i.e., the data item to be queried); after obtaining the interface data, the data query device determines the correctly decrypted target decrypted data from the decrypted data based on the public random number, and obtains the data item to be queried from the target interface data.

[0118] Specifically, in one embodiment, the step of determining a data item to be queried from decrypted data based on a public random number includes: obtaining a first data sequence at a target position in the decrypted data; if the data sequence matches the public random number, determining a second data sequence in the decrypted data as the data item to be queried.

[0119] The target position refers to the position where the public random number is placed when the data holder splices the public random number and the data item. For example, if the length of the public random number is a security length λ and the data holder places the public random number in front and the data item in the back for splicing, the target position refers to the first λ bits in the decrypted data. The first data sequence refers to the data sequence at the target position in the decrypted data, and the second data sequence refers to the data sequence outside the target position in the decrypted data.

[0120] Specifically, the data query device obtains the first data sequence of the target position and compares the first data sequence with the public random number. If the first data sequence is the same as the public random number, the second data sequence in the decrypted data is determined as the data item to be queried. Continuing with the example that the length of the public random number is the security length λ and the data holder places the public random number in front and the data item in the back for splicing, if the first λ bits of the decrypted data are equal to the public random number, the data after the λth bit in the decrypted data is the data item to be queried.

[0121] In the above data query method, the data holder concatenates the data item corresponding to the candidate key value with the public random number, and then encrypts the concatenated plaintext data using the first key data obtained after performing privacy intersection calculation with the data query party, and sends the encrypted data to the data query party. The data query party calculates the query party's key data using the key reference data obtained after performing privacy intersection calculation with the data query party and the query key value, and decrypts the encrypted data using the query party's key data, and determines the data item to be queried from the decrypted data using the public random number. The data transmitted between the data holder device and the data query device only involves encrypted data, and does not involve specific plaintext data, thereby protecting the data security of both parties. In addition, during the data transmission process, The key for encrypting and decrypting plaintext data (i.e., the first key data) is transmitted through privacy intersection calculation. The data query party can only correctly decrypt the encrypted data corresponding to the candidate key value matching the query key value based on the query party key data calculated by the key reference data and the query key value, while the encrypted data corresponding to other candidate key values ​​are invalidly decrypted. Furthermore, the encrypted data corresponding to the candidate key value matching the query key value is decrypted based on the query party key data to obtain valid plaintext data, while the encrypted data corresponding to other candidate key values ​​is decrypted to obtain garbled data. Therefore, the data query party can only obtain the data items corresponding to the query key value but cannot obtain other data items, and the data holder cannot know the data items obtained by the data query party, thereby ensuring the privacy information retrieval of both parties.

[0122] See also Figure 4 , the present application embodiment provides a data query method, which is applied to Figure 1 The data query system shown includes a data holding device and a data query device that are communicatively connected, and the method includes:

[0123] S410, the data holding device and the data query device perform privacy intersection calculation, through which the data holding device obtains the holder's key data, and the data query device obtains key reference data from the first key data and the second key data in the holder's key data;

[0124] S420, the data holding device obtains a candidate key value and a data item corresponding to the candidate key value;

[0125] S430, the data holding device concatenates the public random number and the data item corresponding to the candidate key value to obtain the plaintext data corresponding to the candidate key value;

[0126] S440, the data holding device encrypts the plaintext data corresponding to the candidate key value using the first key data in the holding party key data to obtain the ciphertext data corresponding to the candidate key value;

[0127] S450, the data holding device sends the ciphertext data corresponding to the candidate key value to the data query device;

[0128] S460, the data query device receives the encrypted data sent by the data holding device; the encrypted data includes the ciphertext data corresponding to each candidate key value;

[0129] S470, the data query device obtains the query party key data according to the key reference data and the query key value;

[0130] S480, the data query device decrypts the ciphertext data of the candidate key value using the query party key data to obtain decrypted data;

[0131] S490, the data query device determines the data item to be queried from the decrypted data based on the public random number.

[0132] Specifically, assume that the data holding device holds candidate key-value pairs (y1, v1), (y2, v2), ..., (y n , v n ), the data query device holds query key values ​​x1, x2, ..., x m , if x j =y i , the data query device will obtain v i , but the data holding device does not know what data the data query device has obtained.

[0133] The data holding device and the data query device agree in advance on a security length λ, a pseudo-random number generation function, and a public random number nonce.

[0134] The larger the security length λ is, the higher the algorithm security and anti-collision performance will be. Correspondingly, the efficiency of the algorithm will be lower. The pseudo-random number generation function can be expressed as: in, The set of all messages is called the message space. It can be understood that for the same k and input, the results are consistent, that is, The data length of the public random number nonce is a security length λ.

[0135] The data holding device randomly generates a first random vector of length λ consisting of 0 and 1 for any candidate key-value pair, that is, a {0, 1} n×λ Matrix R0; It can be understood that the random vector in the i-th row of the matrix R0 is the first key data of the i-th candidate key-value pair, i∈[1,n], that is, Represented as the first key data of the i-th candidate key-value pair.

[0136] The data holding device converts the candidate key value y in the candidate key value pair through a public mapping function i Mapped to the first mapping data f corresponding to the candidate key value k (y i ), and then according to the first mapping data f corresponding to the candidate key value k (y i ) and the first key data Perform logical operations to obtain the second key data corresponding to the candidate key value The matrix R1 is obtained. Specifically, the matrix R1 can be obtained by the following formula (5):

[0137]

[0138] For the candidate key-value pairs (y i , v i ), i∈[1,n], the data holding device concatenates the public random number nonce and the candidate key value y i The corresponding data item v i , get the candidate key value y i The corresponding plaintext data is then used As the key, use symmetric encryption (such as AES) to encrypt the candidate key value y i The corresponding plaintext data is encrypted to obtain the encrypted data e i , and the encrypted data e i Sent to the data query device. Specifically, the encrypted data e i It can be obtained by the following formula (6):

[0139]

[0140] The data query device randomly generates a second random vector of length λ consisting of 0 and 1, wherein the second random vector can be represented as s∈{0,1} λ .

[0141] The data query device initiates an oblivious transmission to the data holding device according to the second random vector to construct the key reference data. The key reference data may be a key reference matrix Q, which includes n key reference vectors of length λ and composed of 0 and 1. The specific value of the kth column (k∈[1,λ]) in the key reference matrix Q is determined based on the random vector s; if the value of the kth column in the random vector s is 0, the value of the kth column in the key reference matrix is ​​the value of the kth column of the matrix R0; if the value of the kth column in the random vector s is 1, the value of the kth column in the key reference matrix is ​​the value of the kth column of the matrix R1.

[0142] Obviously, That is, the values ​​of each position on the i-th row vector in the key reference matrix Q are determined by the second random vector and the first key data corresponding to the i-th candidate key value. and the second key data Decide.

[0143] The data query device uses the key reference matrix Q and the query key value x j , calculate the query party key data t i,j Specifically, the querying party key data t i,j It can be calculated by the following formula (7):

[0144]

[0145] Among them, t i,j Represents the query party key data corresponding to the j-th query key value, calculated based on the key reference vector in the i-th row.

[0146] It is understandable that if x j =y i , then t i,j and Equal; the specific reasons are as follows:

[0147]

[0148] Also because So if x j =y i , then no matter what the value of s is, If x j ≠y i , then t i,j The data is garbled, and the data query device cannot obtain any additional information about the data holder.

[0149] The data query device calculates the query party key data t i,j Then, using the querying party key data t i,j Encrypted datai Decrypt and get the decrypted data d i,j Specifically, the decrypted data is d i,j It can be calculated by the following formula (8):

[0150]

[0151] The data query device uses the public random number nonce to decrypt the data d i Specifically, if the decrypted data d i If the first λ bits of are equal to the public random number nonce, it means that the corresponding key-value pair is hit, d i The data after the λ bit is the data item v i .

[0152] Furthermore, the above data query method is described by taking the example that the data holding device holds three candidate key-value pairs (y1, v1), (y2, v2) and (y3, v3), and the data query device holds query key values ​​x1 and x2.

[0153] Specifically, the data holding device randomly generates a first random vector of length λ consisting of 0 and 1 for any candidate key-value pair, that is, obtains the first key data corresponding to y1 The first key data corresponding to y2 And the first key data corresponding to y3 At the same time, the second key data corresponding to y1 can be obtained by the following equations (8) to (10): The second key data corresponding to y2 and the second key data corresponding to y3

[0154]

[0155]

[0156]

[0157] Then, the data holding device concatenates the public random number nonce and the data items corresponding to each candidate key value to obtain the plaintext data corresponding to the candidate key value (including nonce||v1, nonce||v2 and once||v3); then, using the first key data The plaintext data (nonce||v1) corresponding to the candidate key value y1 is encrypted by symmetric encryption (such as AES) to obtain the encrypted data e1; the first key data Encrypt the plaintext data (nonce||v2) corresponding to the candidate key value y2 by symmetric encryption (such as AES) to obtain encrypted data e2; and use the first key data The plaintext data (nonce||v3) corresponding to the candidate key value y3 is encrypted by symmetric encryption (such as AES) to obtain encrypted data e3; and the encrypted data e1 and e2 are sent to the data query device.

[0158] Specifically, the encrypted data e1, e2, and e3 can be obtained by the following formulas (11) to (13):

[0159]

[0160]

[0161]

[0162] The data query device randomly generates a second random vector of length λ consisting of 0 and 1, wherein the second random vector can be represented as s∈{0,1} λ .

[0163] The data query device initiates an oblivious transmission to the data holding device according to the second random vector to construct key reference data, wherein the key reference data may be a key reference matrix Q, and the specific value of the key reference matrix Q can be found above and will not be described here.

[0164] For the query key value x1, the data query device can calculate the three query party key data through the following formulas (14) to (16):

[0165]

[0166]

[0167]

[0168] Among them, Q 1 represents the key reference vector of row 1 in the key reference matrix, which consists of the first key data of the candidate key value y1 and the second key data Decision; similarly, Q 2 , Q 3 They represent the key reference vectors of the 2nd and 3rd rows in the key reference matrix, respectively, which are determined by the first key data and the second key data of the corresponding candidate key value; t 1,1 represents the querying party key data corresponding to the query key value x1 calculated based on the key reference vector of the first row. Similarly, t 2,1represents the querying party key data corresponding to the query key value x1 calculated based on the key reference vector in the second row, t 3,1 Represents the querying party key data corresponding to the query key value x1, calculated based on the key reference vector in the third row.

[0169] Then, the data query device uses the querying party key data t 1,1 For the encrypted data e1, we get the decrypted data d 1,1 ; Using the querying party key data t 2,1 For the encrypted data e2, the decrypted data d is obtained 2,1 ; Using the querying party key data t 3,1 For the encrypted data e3, the decrypted data d is obtained 3,1 .

[0170] Assume x1=y1, then, Using the querying party key data t 1,1 Decrypting the encrypted data e1 can get the correct decryption result, that is, d 1,1 =nonce||v1; and x1≠y2, that is Using the querying party key data t 2,1 Decrypting the encrypted data e2 yields garbled data, i.e., d 2,1 ≠nonce||v2; and x1≠y3, that is Using the querying party key data t 3,1 Decrypting the encrypted data e3 yields garbled data, i.e., d 3,1 ≠nonce||v3.

[0171] Similarly, for the query key value x2, the data query device can calculate the two query party key data through the following formulas (17) to (19):

[0172]

[0173]

[0174]

[0175] Among them, Q 1 represents the key reference vector of row 1 in the key reference matrix, which consists of the first key data of the candidate key value y1 and the second key data Decision; similarly, Q 2 , Q 3 They represent the key reference vectors of the 2nd and 3rd rows in the key reference matrix, respectively, which are determined by the first key data and the second key data of the corresponding candidate key value; t 1,2represents the querying party key data corresponding to the query key value x2 calculated based on the key reference vector of the first row. Similarly, t 2,2 represents the querying party key data corresponding to the query key value x2 calculated based on the key reference vector in the second row, t 3,2 Represents the querying party key data corresponding to the query key value x2, calculated based on the key reference vector in the third row.

[0176] Then, the data query device uses the querying party key data t 1,2 For the encrypted data e1, we get the decrypted data d 1,2 ; Using the querying party key data t 2,2 For the encrypted data e2, the decrypted data d is obtained 2,2 ; Using the querying party key data t 3,2 For the encrypted data e3, the decrypted data d is obtained 3,2 .

[0177] Assume x2=y3, then, Using the querying party key data t 1,2 Decrypting the encrypted data e1 does not yield the correct decryption result, but rather garbled data, i.e., d 1,2 ≠nonce||v1; Using the querying party key data t 2,2 Decrypting the encrypted data e2 cannot obtain the correct decryption result, that is, d 2,2 ≠nonce||v2; and x2=y3, that is Using the querying party key data t 3,2 Decrypting the encrypted data e3 can obtain the correct decryption result, that is, d 3,2 =nonce||v3.

[0178] Finally, the data query device can decrypt the data d based on the public random number nonce 1,1 ,d 2,1 ,d 3,1 ,d 1,2 ,d 2,2 and 3,2 Specifically, if the decrypted data d i,j If the first λ bits of are equal to the public random number nonce, it means that the corresponding key-value pair is hit, d i,j The data after the λ bit is the data item v i , that is, the data query device can be obtained from d 1,1 Query the key value x1 to obtain v1, and get v1 from d 3,2 The data query device obtains v3 corresponding to the query key value x2, but the data query device cannot obtain v2.

[0179] In order to better implement the data query device method provided in the embodiment of the present application, on the basis of the data query device method provided in the embodiment of the present application, the embodiment of the present application also provides a data query device, which is applied to the data holding device, such as Figure 5 As shown, the data query device 500 includes:

[0180] A data item acquisition module 510 is used to acquire candidate key values ​​and data items corresponding to the candidate key values;

[0181] A plaintext data acquisition module 520 is used to concatenate the public random number and the data items corresponding to the candidate key value to obtain the plaintext data corresponding to the candidate key value;

[0182] The data encryption module 530 is used to obtain the holder key data by performing privacy intersection calculation with the data query device, and use the first key data in the holder key data to encrypt the plaintext data corresponding to the candidate key value to obtain the ciphertext data corresponding to the candidate key value;

[0183] The data sending module 540 is used to send the ciphertext data corresponding to the candidate key value as encrypted data to the data query device, and the encrypted data is used to instruct the data query device to use the query party key data to decrypt the ciphertext data of the candidate key value to obtain decrypted data, and determine the data item to be queried from the decrypted data based on the public random number; wherein, the query party key data is obtained based on the key reference data and the query key value, and the key reference data is obtained by the data query device from the first key data and the second key data in the holder's key data by performing privacy intersection calculation with the data holding device.

[0184] In some embodiments of the present application, the data encryption module is specifically used to obtain a public mapping function agreed upon with a data query device; map a candidate key value to first mapping data corresponding to the candidate key value through the public mapping function; construct a first random vector corresponding to the candidate key value, and determine the first random vector as first key data; perform logical operations on the first mapping data and the first key data corresponding to the candidate key value to obtain second key data corresponding to the candidate key value; and determine the first key data and the second key data corresponding to the candidate key value as holder key data.

[0185] In order to better implement the data query device method provided in the embodiment of the present application, on the basis of the data query device method provided in the embodiment of the present application, the embodiment of the present application also provides a data query device, which is applied to the data query device, such as Figure 6 As shown, the data query device 600 includes:

[0186] The data receiving module 610 is used to receive encrypted data sent by the data holding device; the encrypted data includes ciphertext data corresponding to each candidate key value; wherein the ciphertext data corresponding to the candidate key value is obtained by encrypting the plaintext data corresponding to the candidate key value using the first key data in the key data of the holding party, and the plaintext data corresponding to the candidate key value is obtained by concatenating the public random number and the data item corresponding to the candidate key value;

[0187] The key acquisition module 620 is used to acquire the querying party key data according to the key reference data and the query key value; wherein the key reference data is acquired by the data querying device from the first key data and the second key data in the holding party key data by performing privacy intersection calculation with the data holding device;

[0188] A data decryption module 630 is used to decrypt the ciphertext data of the candidate key value using the querying party key data to obtain decrypted data;

[0189] The data determination module 640 is used to determine the data item to be queried from the decrypted data based on the public random number.

[0190] In some embodiments of the present application, the data determination module is specifically used to obtain a first data sequence at a target position in the decrypted data; if the first data sequence matches the public random number, a second data sequence in the decrypted data is determined as a data item to be queried.

[0191] In some embodiments of the present application, the key acquisition module is specifically used to perform an XOR operation on the second random vector and the query key value to obtain a first operation result; obtain a common mapping function agreed upon with the data query device, and map the first operation result to second mapping data through the common mapping function; perform an XOR operation on the key reference data and the second mapping data to obtain the query party key data.

[0192] In some embodiments of the present application, the key acquisition module is specifically used to construct a second random vector; initiate an oblivious transmission to the data holding device based on the second random vector, and obtain key reference data from the first key data and the second key data in the holder's key data.

[0193] For the specific definition of the data query device, please refer to the definition of the data query method above, which will not be repeated here. Each module in the above-mentioned data query device can be implemented in whole or in part by software, hardware and a combination thereof. The above-mentioned modules can be embedded in or independent of the processor in the computer device in the form of hardware, or can be stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above modules.

[0194] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Figure 7 As shown. The computer device includes a processor, a memory and a network interface connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store candidate key-value pairs and other data. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a data query method is implemented.

[0195] Those skilled in the art will understand that Figure 7 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0196] In some embodiments of the present application, a computer device is provided, including one or more processors; a memory; and one or more applications, wherein the one or more applications are stored in the memory and configured to be executed by the processor in the steps of the above-mentioned data query device method. The steps of the data query device method here can be the steps of the data query device method in each of the above-mentioned embodiments.

[0197] In some embodiments of the present application, a computer-readable storage medium is provided, which stores a computer program, and the computer program is loaded by a processor, so that the processor executes the steps of the above-mentioned data query device method. The steps of the data query device method here can be the steps in the data query device method of each of the above-mentioned embodiments.

[0198] Those of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Any reference to memory, storage, database or other media used in the embodiments provided in this application may include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory or optical memory, etc. Volatile memory may include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM).

[0199] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0200] The above is a detailed introduction to a data query device method, apparatus, computer equipment and storage medium provided in the embodiments of the present application. Specific examples are used herein to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea. At the same time, for those skilled in the art, according to the ideas of the present invention, there will be changes in the specific implementation methods and application scopes. In summary, the content of this specification should not be understood as a limitation on the present invention.

Claims

1. A data query method, characterized in that: Applied to a data holding device, the method comprises: Obtain candidate key values ​​and data items corresponding to the candidate key values; Concatenate the public random number and the data item corresponding to the candidate key value to obtain the plaintext data corresponding to the candidate key value; The holder's key data is obtained by performing a privacy intersection calculation with the data query device, and the plaintext data corresponding to the candidate key value is encrypting using the first key data in the holder's key data to obtain the ciphertext data corresponding to the candidate key value; The ciphertext data corresponding to the candidate key value is sent as encrypted data to a data query device, and the encrypted data is used to instruct the data query device to use the query party key data to decrypt the ciphertext data of the candidate key value to obtain decrypted data, and determine the data item to be queried from the decrypted data based on the public random number; wherein the query party key data is obtained based on the key reference data and the query key value, and the key reference data is obtained by the data query device from the first key data and the second key data in the holder key data by performing a privacy intersection calculation with the data holding device.

2. The method according to claim 1, characterized in that The step of obtaining the holder's key data by performing privacy intersection calculation with the data query device includes: Acquire a common mapping function agreed upon with the data query device; Mapping the candidate key value to first mapping data corresponding to the candidate key value through the common mapping function; Constructing a first random vector corresponding to the candidate key value, and determining the first random vector as first key data; Performing a logical operation on the first mapping data corresponding to the candidate key value and the first key data to obtain second key data corresponding to the candidate key value; The first key data and the second key data corresponding to the candidate key value are determined as holder key data.

3. A data query method, characterized in that: Applied to a data query device, the method comprises: Receive encrypted data sent by a data holding device; the encrypted data includes ciphertext data corresponding to each candidate key value; wherein the ciphertext data corresponding to the candidate key value is obtained by encrypting the plaintext data corresponding to the candidate key value using the first key data in the key data of the holding party, and the plaintext data corresponding to the candidate key value is obtained by concatenating a public random number and a data item corresponding to the candidate key value; Obtain key reference data from the first key data and the second key data in the key data of the holder by performing privacy intersection calculation with the data holding device, and obtain the querying party key data according to the key reference data and the query key value; Decrypting the ciphertext data of the candidate key value using the querying party key data to obtain decrypted data; A data item to be queried is determined from the decrypted data based on the public random number.

4. The method according to claim 3, characterized in that The step of determining the data item to be queried from the decrypted data based on the public random number comprises: Acquire a first data sequence at a target position in the decrypted data; If the data sequence matches the public random number, the second data sequence in the decrypted data is determined as the data item to be queried.

5. The method according to claim 3, characterized in that: The step of obtaining key reference data from the first key data and the second key data in the key data of the holder by performing privacy intersection calculation with the data holding device comprises: constructing a second random vector; An oblivious transmission is initiated to the data holding device based on the second random vector, and key reference data is obtained from the first key data and the second key data in the holder key data.

6. The method according to claim 5, characterized in that The step of obtaining the querying party's key data according to the key reference data and the query key value comprises: Performing an XOR operation on the second random vector and the query key value to obtain a first operation result; Acquire a common mapping function agreed upon with the data query device, and map the first operation result into second mapping data through the common mapping function; An XOR operation is performed on the key reference data and the second mapping data to obtain the querying party key data.

7. A data query method, characterized in that: Applied to a data query system, the data query system includes a data holding device and a data query device in communication connection, the method includes: The data holding device performs privacy intersection calculation with the data query device, through which the data holding device obtains the holder's key data, and the data query device obtains key reference data from the first key data and the second key data in the holder's key data; The data holding device obtains a candidate key value and a data item corresponding to the candidate key value; The data holding device concatenates the public random number and the data item corresponding to the candidate key value to obtain the plaintext data corresponding to the candidate key value; The data holding device uses the first key data in the holding party key data to encrypt the plaintext data corresponding to the candidate key value to obtain the ciphertext data corresponding to the candidate key value; The data holding device sends the ciphertext data corresponding to the candidate key value as encrypted data to the data query device; The data query device receives the encrypted data sent by the data holding device; the encrypted data includes ciphertext data corresponding to each candidate key value; The data query device obtains the query party key data according to the key reference data and the query key value; The data query device uses the query party key data to decrypt the ciphertext data of the candidate key value to obtain decrypted data; The data query device determines a data item to be queried from the decrypted data based on a public random number.

8. A data query device, characterized in that: Applied to a data holding device, the device comprises: A data item acquisition module is used to acquire candidate key values ​​and data items corresponding to the candidate key values; A plaintext data acquisition module, used to concatenate the public random number and the data item corresponding to the candidate key value to obtain the plaintext data corresponding to the candidate key value; A data encryption module, used to obtain the holder's key data by performing privacy intersection calculation with the data query device, and encrypt the plaintext data corresponding to the candidate key value using the first key data in the holder's key data to obtain the ciphertext data corresponding to the candidate key value; A data sending module, used for sending the ciphertext data corresponding to the candidate key value as encrypted data to a data query device, wherein the encrypted data is used to instruct the data query device to decrypt the ciphertext data of the candidate key value using the query party key data to obtain decrypted data, and determine the data item to be queried from the decrypted data based on the public random number; wherein the query party key data is obtained based on key reference data and the query key value, and the key reference data is obtained by the data query device from the first key data and the second key data in the holder key data by performing a privacy intersection calculation with the data holding device.

9. A data query device, characterized in that: Applied to data query equipment, the device comprises: A data receiving module, used to receive encrypted data sent by a data holding device; the encrypted data includes ciphertext data corresponding to each candidate key value; wherein the ciphertext data corresponding to the candidate key value is obtained by encrypting the plaintext data corresponding to the candidate key value using the first key data in the key data of the holding party, and the plaintext data corresponding to the candidate key value is obtained by concatenating a public random number and a data item corresponding to the candidate key value; A key acquisition module, configured to acquire key reference data from the first key data and the second key data in the key data of the holder by performing privacy intersection calculation with the data holding device, and acquire the querying party key data according to the key reference data and the query key value; A data decryption module, used to decrypt the ciphertext data of the candidate key value using the querying party key data to obtain decrypted data; The data determination module is used to determine the data item to be queried from the decrypted data based on the public random number.

10. A computer device, characterized in that: include: one or more processors; Memory; as well as One or more application programs, wherein the one or more application programs are stored in the memory and configured to be executed by the processor to implement the data query device method according to any one of claims 1 to 7.

11. A computer-readable storage medium, characterized in that: A computer program is stored thereon, and the computer program is loaded by a processor to execute the steps in the data query device method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Privacy-protected data query method and device

    CN111046047A

  • Data encryption and decryption method, device and system

    CN112016113A