A database SQL string operation privacy protection method and system
By homomorphic encryption and auxiliary information calculation of the string data in the database privacy field, combined with number multiplication, addition, or subtraction, the problem of the existing technology being unable to support SQL string operations in character databases is solved, and strong privacy protection and efficient query of character data is achieved.
Patent Information
- Application Number
- CN202211443166.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-17
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2042-11-17
AI Technical Summary
Existing database homomorphic encryption privacy protection solutions cannot effectively support most standard SQL string operations on character-type data, resulting in the inability to achieve strong privacy protection in character-type databases.
By homomorphically encrypting the string data in the database privacy field, calculating auxiliary information, and building a ciphertext data table, identifying the string operation type, and using number multiplication, addition, or subtraction, to calculate, SQL string operation on character data.
It effectively improves the privacy protection of character-type data in the database, supports most standard SQL string operations, and enhances the confidentiality and scenario adaptability of database queries.
Smart Images

Figure CN115712910B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of information security technology, and in particular relates to a database SQL string operation privacy protection method and system. Background Art
[0002] With the development of cloud servers, more and more enterprises and individuals outsource their data to public cloud database systems for management. However, cloud server data leaks occur from time to time, and data security has become a major concern for users to adopt cloud computing and cloud databases.
[0003] In the field of database encryption privacy protection, the early technical means were to use symmetric encryption algorithms such as DES and AES. However, since symmetric encryption itself requires that the ciphertext distribution be sufficiently random, it is impossible to perform certain homomorphic operations on the ciphertext. Therefore, when the database server executes a query, it still needs to decrypt and then perform a plaintext query, which to a certain extent reduces the strength of privacy protection. In recent years, the technical means of applying homomorphic encryption have been used to increase the ability of database servers to directly operate on ciphertext, effectively improving the strength of privacy protection. However, due to the characteristics of the cryptographic algorithm itself, the existing database homomorphic encryption privacy protection schemes almost all have relatively complete solutions for numerical data, such as numerical addition, subtraction, multiplication, etc. It is not applicable to character databases with a higher proportion of character data and operation types.
[0004] In order to support most standard SQL string operations on the privacy field string data of the database, a database SQL string operation privacy protection method and system are proposed. Summary of the invention
[0005] The embodiment of the present invention proposes a database SQL string operation privacy protection method and system to at least solve the problem that the related art cannot support most standard SQL string operations on the privacy field string data of the database.
[0006] According to an embodiment of the present invention, a database SQL string operation privacy protection method is proposed, comprising:
[0007] Perform homomorphic encryption on string data in database privacy fields;
[0008] Calculate auxiliary information based on private field string information and homomorphic encryption information;
[0009] Construct a ciphertext data table based on the encrypted data and auxiliary information;
[0010] Identify the types of string operations involving privacy fields;
[0011] Calculate the ciphertext result after the privacy field string operation using multiplication homomorphism and / or addition homomorphism and / or subtraction homomorphism according to the string operation type;
[0012] The user's final query result is obtained based on the ciphertext result after the privacy field string operation and the query result of the non-privacy field.
[0013] In an exemplary embodiment, performing homomorphic encryption on string data of a database privacy field comprises the steps of:
[0014] Generate the plaintext two-dimensional table Table_P required in the database; assume that Table_P has m data and n fields;
[0015] The user specifies t fields as privacy fields, namely PF1,…,PFt;
[0016] Select random 1024-bit prime numbers p and q, and calculate the modulus N = p·q.
[0017] Let g = N + 1, λ = (p-1)·(q-1), calculate μ = λ -1 mod N;
[0018] The user's Paillier public key is pk = (N, g), and the private key is sk = (λ, μ);
[0019] Let i = 1, 2, ..., t, j = 1, 2, ..., m, the user uses the Paillier public key pk to homomorphically encrypt the string data PF of all private fields i _Data j , that is, select a random number r from (0, N) such that r and N are relatively prime, and calculate the ciphertext PF i _Data j _C=(g^Int(PF i _Data j ))·(r^N)mod N 2 , where Int(PF i _Data j ) represents string data PF i _Data j The corresponding large integer converted in ASCII encoding.
[0020] In an exemplary embodiment, the method of calculating auxiliary information based on the private field string information and the homomorphic encryption information comprises the steps of:
[0021] Encrypt PF using Paillier public key pk i _Data j Each single character of
[0022] Calculate string data PF i _Data j The length of the string is recorded as l;
[0023] Select l different random numbers r in (0,N) 1 ,r 2 ,…,r l , satisfying r 1 ,r 2 ,…,r l are all coprime to N. For k = 1, 2, ..., l, calculate PF i _Data j The ciphertext of each single character PF i _Data j _s k _C=(g^Int(PF i _Data j_ s k ))*(r k ^N)mod N 2 ;
[0024] Each single character ciphertext PF i _Data j _s k _C and string length l are combined into a list PF i _Data j_ Aux is auxiliary information.
[0025] In an exemplary embodiment, constructing a ciphertext data table according to the encrypted data and the auxiliary information comprises the steps of:
[0026] In the plaintext data table Table_P, use the ciphertext data PF i _Data j _C replaces the plaintext data PF i _Data j ;
[0027] Add t fields, where the jth row of the i-th field stores the string PF i _Data j Auxiliary information PF i _Data j_ Aux, forming the ciphertext data table Table_C;
[0028] Upload the encrypted data table Table_C to the database server for storage.
[0029] In an exemplary embodiment, the identifying the type of string operation involving the privacy field comprises the steps of:
[0030] The user submits a string operation SQL statement involving privacy fields, which is recorded as SQL_State;
[0031] The database server DBS analyzes the statement SQL_State to determine the string operation type of the privacy field; the string operation type includes CONCAT (PF1, PF2) connection operation, SUBSTR (PF, start, len) substring operation, POSITION (str in PF) position return operation, TRIM (char from PF) character deletion operation, UPPER (PF) uppercase conversion operation, LOWER (PF) lowercase conversion operation, and INITCAP (PF) first letter uppercase conversion operation.
[0032] In an exemplary embodiment, the method of calculating the ciphertext result after the privacy field string operation using multiplication homomorphism and / or addition homomorphism and / or subtraction homomorphism according to the string operation type comprises the steps of:
[0033] Identify integer operations corresponding to string operation types;
[0034] Auxiliary information is used to convert integer operations into homomorphic operations and use them to calculate the ciphertext result after the privacy field string operation.
[0035] In an exemplary embodiment, the identifying the integer operation corresponding to the string operation type includes:
[0036] The CONCAT (PF1, PF2) connection operation is to connect the corresponding strings of the privacy fields PF1 and PF2, and its integer operation is: Comp = Int (PF1) * 256^Len (PF2) + Int (PF2);
[0037] The substring operation of SUBSTR (PF, start, len) is to intercept the corresponding string of the substring of the privacy field PF string starting from start and with a length of len. Its integer operation: Comp = Int (s start+len-1 )*256^0+…+Int(s start )*256^(len-1), where s i Refers to the i-th character in the privacy field PF string;
[0038] The POSITION(str in PF) return position operation is to return the corresponding string of the starting position of the substring str in the privacy field PF string. Its integer operation is: for a certain k, there are Len(str) consecutive 0 characters in the string form of Int(PF)-Int(str)*256^k, then the position is Len(PF)-Len(str)+1-k;
[0039] The TRIM (char from PF) character deletion operation is to delete the corresponding character string of the leading repeated character char in the privacy field PF string, and its integer operation is: Comp = Int (PF) - Int (k char's) * 256^ (Len (PF) - k + 1);
[0040] The UPPER (PF) uppercase conversion operation converts all characters of the privacy field PF string into uppercase corresponding strings, and its integer operation is: Comp = Int (PF) + 32 * (1 + 256 + ... + 256^ (Len (PF) - 1));
[0041] The LOWER (PF) conversion operation is to convert all characters of the privacy field PF string into the corresponding lowercase string, and its integer operation is: Comp = Int (PF) - 32 * (1 + 256 + ... + 256^ (Len (PF) - 1));
[0042] The INITCAP (PF) first letter uppercase conversion operation is to convert the first character of the privacy field PF string into the corresponding uppercase string, and its integer operation is: Comp = Int (PF) + 32*256^ (Len (PF) - 1).
[0043] In an exemplary embodiment, the method of using homomorphic operations to calculate the ciphertext result after the privacy field string operation includes:
[0044] CONCAT(PF1,PF2) connection operation: using the string length in the auxiliary information, using the Paillier number multiplication homomorphism combined with the Paillier addition homomorphism, that is, for j = 1, 2, ..., m, calculate the ciphertext result Comp j _C=PF 1 _Data j ^(256^Len(PF2))*PF 2 _Data j mod N 2 ;
[0045] SUBSTR(PF, start, len) substring operation: using the single character encryption result in the auxiliary information, use Paillier number multiplication homomorphism combined with Paillier addition homomorphism, that is, for j = 1, 2, ..., m, calculate the ciphertext result Comp j _C=PF_Data j _s start+len–1 _C^(256^0)*…*PF_Data j _s start_C^(256^(len–1))mod N 2 ;
[0046] POSITION(str in PF) returns the position operation: using the string length in the auxiliary information, use the Paillier number multiplication homomorphism combined with the Paillier subtraction homomorphism, that is, for j = 1, 2, ..., m, k = 1, 2, ..., Len(PF)-Len(str), calculate the ciphertext result Comp j _C k =PF_Data j *(E(str)^(256^k)) -1 mod N 2 ;
[0047] TRIM (char from PF) deletes characters: Using the string length in the auxiliary information, use the Paillier number multiplication homomorphism combined with the Paillier subtraction homomorphism, that is, for j = 1, 2, ..., m, calculate the ciphertext result Comp j _C=PF_Data j *(E(k char's)^(256^(Len(PF)–k+1))) -1 mod N 2 , where E(kchar's) represents the Paillier encryption result of a string consisting of k consecutive repeated characters char;
[0048] UPPER (PF) conversion to uppercase: Using the string length in the auxiliary information, use the Paillier addition homomorphism, that is, for j = 1, 2, ..., m, calculate the ciphertext result Comp j _C=PF_Data j *E(32*(1+256+…+256^(Len(PF)-1)))mod N 2 , where E(Const) represents the Paillier encryption result of the constant Const;
[0049] LOWER (PF) conversion to lowercase: Using the string length in the auxiliary information, use the Paillier subtraction homomorphism, that is, for j = 1, 2, ..., m, calculate the ciphertext result Comp j _C=PF_Data j *E(32*(1+256+…+256^(Len(PF)-1))) -1 mod N 2 ;
[0050] INITCAP (PF) first character conversion operation: using the string length in the auxiliary information, use the Paillier addition homomorphism, that is, for j = 1, 2, ..., m, calculate the ciphertext result Comp j _C=PF_Data j *E(32*256^(Len(PF)-1))modN 2 .
[0051] In an exemplary embodiment, obtaining the final query result of the user based on the ciphertext result of the privacy field string operation and the query result of the non-privacy field includes the steps of:
[0052] The server returns the ciphertext result Comp_C of the privacy field string operation and the query result Res of the non-privacy field to the user;
[0053] The user uses the Paillier private key sk to decrypt the ciphertext result of the privacy field string operation; the user combines the decryption result of the privacy field string with the query result of the non-privacy field to obtain the final query result.
[0054] According to another embodiment of the present invention, a database SQL string operation privacy protection system is provided, comprising:
[0055] processor;
[0056] Memory;
[0057] as well as
[0058] One or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the processor, the programs causing the computer to perform the above method.
[0059] The database SQL string operation privacy protection method and system of the present invention have the following advantages:
[0060] (1) Auxiliary information is calculated based on the private field string information and homomorphic encryption information, and a ciphertext data table is constructed based on the encrypted data and auxiliary information. Compared with traditional database encryption technology solutions, this method can effectively reduce the complexity of database encryption and improve the efficiency of database ciphertext queries.
[0061] (2) Paillier multiplication homomorphism and / or Paillier addition homomorphism and / or Paillier subtraction homomorphism are used to calculate the ciphertext result after the privacy field string operation according to the string operation type. Compared with the traditional technical solution that can only perform encryption operations on numerical data, this can effectively implement encryption operations on character databases and improve the confidentiality of database queries.
[0062] (3) The user's final query result is obtained based on the ciphertext result after the privacy field string operation and the query result of the non-privacy field. Compared with the traditional database technology solutions that only support plaintext operations or only support ciphertext operations, it can effectively realize the mixed operation of database plaintext and ciphertext, and improve the scenario adaptability of the encrypted database.
[0063] (4) The string of the privacy field is divided into multiple segments and the association values between the string segments are calculated based on the length similarity of each string segment and / or the Hamming weight similarity of the string and / or the proportion of repeated characters. The string is combined and reconstructed based on the association values. Compared with the traditional technical solution for operating on the complete string, it can effectively increase redundancy, reduce the probability of large-scale errors, and improve the efficiency of encrypted database queries. BRIEF DESCRIPTION OF THE DRAWINGS
[0064] Figure 1 It is a flow chart of a database SQL string operation privacy protection method according to an embodiment of the present invention;
[0065] Figure 2 is a flowchart of sub-step S01 of an embodiment of the present invention;
[0066] Figure 3 is a flowchart of sub-step S02 of an embodiment of the present invention;
[0067] Figure 4 is a flowchart of sub-step S03 of an embodiment of the present invention;
[0068] Figure 5 is a flowchart of sub-step S04 of an embodiment of the present invention;
[0069] Figure 6 is a flowchart of sub-step S05 of an embodiment of the present invention;
[0070] Figure 7 is a flowchart of sub-step S06 of an embodiment of the present invention;
[0071] Figure 8 It is a schematic diagram of the structure of a database SQL string operation privacy protection system according to an embodiment of the present invention. DETAILED DESCRIPTION
[0072] The present invention is described in detail below in conjunction with specific embodiments. The following embodiments will help those skilled in the art to further understand the invention, but are not intended to limit the present invention in any form. It should be noted that, for those of ordinary skill in the art, several changes and improvements can be made without departing from the concept of the present invention. These all belong to the protection scope of the present invention.
[0073] A database SQL string operation privacy protection method according to an embodiment of the present invention is shown in the flowchart as follows: Figure 1 As shown, the steps include:
[0074] Step S01, performing homomorphic encryption on the string data of the database privacy field;
[0075] Step S02: Calculate auxiliary information based on the private field string information and homomorphic encryption information;
[0076] Step S03: construct a ciphertext data table according to the encrypted data and auxiliary information;
[0077] Step S04: Identify the string operation type involving the privacy field;
[0078] Step S05: Calculate the ciphertext result after the privacy field string operation using multiplication homomorphism and / or addition homomorphism and / or subtraction homomorphism according to the string operation type;
[0079] Step S06, obtaining the final query result of the user according to the ciphertext result after the privacy field character string operation and the query result of the non-privacy field;
[0080] In an exemplary embodiment, the step S01, the flow chart is as follows Figure 2 As shown, including:
[0081] Step S011, generate the plaintext two-dimensional table Table_P required in the database; assume that Table_P has m data and n fields;
[0082] Step S012: The user specifies t fields as privacy fields, namely PF1, ..., PFt;
[0083] Step S013, select random 1024-bit prime numbers p and q, calculate the modulus N = p·q; let g = N+1, λ = (p-1)·(q-1), calculate μ = λ -1 mod N;
[0084] Step S014: the user's Paillier public key is pk = (N, g), and the private key is sk = (λ, μ);
[0085] Step S015: Let i = 1, 2, ..., t, j = 1, 2, ..., m, and the user uses the Paillier public key pk to homomorphically encrypt the string data PF of all private fields. i _Data j , that is, select a random number r from (0, N) such that r and N are relatively prime, and calculate the ciphertext PF i _Data j _C=(g^Int(PF i _Data j))·(r^N)mod N 2 , where Int(PF i _Data j ) represents string data PF i _Data j The corresponding large integer converted in ASCII encoding.
[0086] In an exemplary embodiment, the step S02, the flow chart is as follows Figure 3 As shown, including:
[0087] Step S021: Encrypt PF using Paillier public key pk i _Data j Each single character of
[0088] Step S022: Calculate the string data PF i _Data j The length of the string is denoted as l;
[0089] Step S023: Select l different random numbers r in (0,N) 1 ,r 2 ,…,r l , satisfying r 1 ,r 2 ,…,r l are all coprime to N. For k = 1, 2, ..., l, calculate PF i _Data j The ciphertext of each single character PF i _Data j _s k _C=(g^Int(PF i _Data j_ s k ))*(r k ^N)mod N 2 ;
[0090] Step S024: encrypt each single character i _Data j _s k _C and string length l are combined into a list PF i _Data j_ Aux is auxiliary information.
[0091] In an exemplary embodiment, the step S03, the flow chart is as follows Figure 4 As shown, including:
[0092] Step S031: In the plaintext data table Table_P, use the ciphertext data PF i_Data j _C replaces the plaintext data PF i _Data j ;
[0093] Step S032: add t fields, where the jth row of the i-th field stores the string PF i _Data j Auxiliary information PF i _Data j_ Aux, forming the ciphertext data table Table_C;
[0094] Step S033, uploading the encrypted data table Table_C to the database server for storage.
[0095] In an exemplary embodiment, the step S04, the flow chart is as follows Figure 5 As shown, including:
[0096] Step S041: The user submits a string operation SQL statement involving a privacy field, which is recorded as SQL_State;
[0097] Step S042, the database server DBS analyzes the statement SQL_State to determine the string operation type of the privacy field; the string operation type includes CONCAT (PF1, PF2) connection operation, SUBSTR (PF, start, len) substring operation, POSITION (str in PF) return position operation, TRIM (char from PF) character deletion operation, UPPER (PF) uppercase conversion operation, LOWER (PF) lowercase conversion operation, INITCAP (PF) first letter uppercase conversion operation.
[0098] In an exemplary embodiment, the step S05, the flow chart is as follows Figure 6 As shown, including:
[0099] Step S051, identifying the integer operation corresponding to the string operation type;
[0100] Step S052: Use auxiliary information to convert integer operations into homomorphic operations and use them to calculate the ciphertext result after the privacy field string operation.
[0101] In this embodiment, the cloud server CS will comp all the results i,j Sent to a trusted third party TTP; the trusted third party TTP executes all results comp based on all Paillier private keys i,j Decryption of , that is, calculating dec i,j =(comp i,j ^λ f(i) modnf(i) 2 -1) / n f(i) ·μ f(i) mod n f(i) 2 ;
[0102] The trusted third party TTP is responsible for the decryption result large integer dec i,j Decode it into a string (English keywords use ASCII encoding, Chinese and English keywords use UTF-8 encoding), and find out the string length len i,j , whose Hamming weight in character form is hw i,j (i.e. the number of characters that are not 0), and the proportion of repeated characters re i,j (i.e. the ratio of the number of character categories to the total number of characters).
[0103] In an exemplary embodiment, the certificate operations corresponding to the string operation types in step S051 include: the CONCAT (PF1, PF2) connection operation is to connect the corresponding strings of the privacy fields PF1 and PF2, and its integer operation is: Comp = Int (PF1) * 256^Len (PF2) + Int (PF2);
[0104] The substring operation of SUBSTR (PF, start, len) is to intercept the corresponding string of the substring of the privacy field PF string starting from start and with a length of len. Its integer operation: Comp = Int (s start+len-1 )*256^0+…+Int(s start )*256^(len-1), where s i Refers to the i-th character in the privacy field PF string;
[0105] The POSITION(str in PF) return position operation is to return the corresponding string of the starting position of the substring str in the privacy field PF string. Its integer operation is: for a certain k, there are Len(str) consecutive 0 characters in the string form of Int(PF)-Int(str)*256^k, then the position is Len(PF)-Len(str)+1-k;
[0106] The TRIM (char from PF) character deletion operation is to delete the corresponding character string of the leading repeated character char in the privacy field PF string, and its integer operation is: Comp = Int (PF) - Int (k char's) * 256^ (Len (PF) - k + 1);
[0107] The UPPER (PF) uppercase conversion operation converts all characters of the privacy field PF string into uppercase corresponding strings, and its integer operation is: Comp = Int (PF) + 32 * (1 + 256 + ... + 256^ (Len (PF) - 1));
[0108] The LOWER (PF) conversion operation is to convert all characters of the privacy field PF string into the corresponding lowercase string, and its integer operation is: Comp = Int (PF) - 32 * (1 + 256 + ... + 256^ (Len (PF) - 1));
[0109] The INITCAP (PF) first letter uppercase conversion operation is to convert the first character of the privacy field PF string into the corresponding uppercase string, and its integer operation is: Comp = Int (PF) + 32*256^ (Len (PF) - 1).
[0110] In an exemplary embodiment, each string operation type in step S051 uses homomorphic operations to calculate the ciphertext result after the privacy field string operation, including: CONCAT(PF1, PF2) connection operation: using the string length in the auxiliary information, using Paillier number multiplication homomorphism combined with Paillier addition homomorphism, that is, for j = 1, 2, ..., m, calculate the ciphertext result Comp j _C=PF 1 _Data j ^(256^Len(PF2))*PF 2 _Data j mod N 2 ;
[0111] SUBSTR(PF, start, len) substring operation: using the single character encryption result in the auxiliary information, use Paillier number multiplication homomorphism combined with Paillier addition homomorphism, that is, for j = 1, 2, ..., m, calculate the ciphertext result Comp j _C=PF_Data j _s start+len–1 _C^(256^0)*…*PF_Data j _s start _C^(256^(len–1))mod N 2 ;
[0112] POSITION(str in PF) returns the position operation: using the string length in the auxiliary information, use the Paillier number multiplication homomorphism combined with the Paillier subtraction homomorphism, that is, for j = 1, 2, ..., m, k = 1, 2, ..., Len(PF)-Len(str), calculate the ciphertext result Compj _C k =PF_Data j *(E(str)^(256^k)) -1 mod N 2 ;
[0113] TRIM (char from PF) deletes characters: Using the string length in the auxiliary information, use the Paillier number multiplication homomorphism combined with the Paillier subtraction homomorphism, that is, for j = 1, 2, ..., m, calculate the ciphertext result Comp j _C=PF_Data j *(E(k char's)^(256^(Len(PF)–k+1))) -1 mod N 2 , where E(kchar's) represents the Paillier encryption result of a string consisting of k consecutive repeated characters char;
[0114] UPPER (PF) conversion to uppercase: Using the string length in the auxiliary information, use the Paillier addition homomorphism, that is, for j = 1, 2, ..., m, calculate the ciphertext result Comp j _C=PF_Data j *E(32*(1+256+…+256^(Len(PF)-1)))mod N 2 , where E(Const) represents the Paillier encryption result of the constant Const;
[0115] LOWER (PF) conversion to lowercase: Using the string length in the auxiliary information, use the Paillier subtraction homomorphism, that is, for j = 1, 2, ..., m, calculate the ciphertext result Comp j _C=PF_Data j *E(32*(1+256+…+256^(Len(PF)-1))) -1 mod N 2 ;
[0116] INITCAP (PF) first character conversion operation: using the string length in the auxiliary information, use the Paillier addition homomorphism, that is, for j = 1, 2, ..., m, calculate the ciphertext result Comp j _C=PF_Data j *E(32*256^(Len(PF)-1))modN 2 .
[0117] In this embodiment, the TRIM (char from PF) character deletion operation requires that the number k of leading repeated characters char be known in advance; the UPPER (PF) uppercase conversion operation requires that all letters of the original string are lowercase; the LOWER (PF) lowercase conversion operation requires that all letters of the original string are uppercase; and the INITCAP (PF) first character uppercase conversion operation requires that all letters of the original string are lowercase.
[0118] Take POSITION(str in PF) as an example to calculate dec j,k =(Comp j _C k ^λmod N 2 -1) / N*μmod N 2 , if a dec j,k There are k consecutive 0s in the ASCII decoded string form of j It is the smallest value among all Len(PF)-Len(str)+1–k that meet the conditions, that is, the result of the POSITION operation.
[0119] In an exemplary embodiment, before step S052, the method further includes the following steps:
[0120] Split the string of the privacy field into multiple segments evenly or randomly;
[0121] Calculate the association value between the string segments according to the length similarity of each string segment and / or the Hamming weight similarity of the string and / or the proportion of repeated characters;
[0122] Combine and connect the character strings whose correlation values are greater than or equal to the set threshold, and calculate the corresponding ciphertext result according to the operation corresponding to the character string operation type described in the above implementation mode;
[0123] Perform the operation corresponding to the string operation type described in the above implementation mode on the string whose correlation value is less than the set threshold separately to calculate the corresponding ciphertext result;
[0124] The ciphertext result is reassembled according to the original string connection method to form a complete ciphertext result.
[0125] In this embodiment, the calculation of the association value between the string segments according to the length similarity of each string segment and / or the Hamming weight similarity of the string and / or the ratio of repeated characters is: calculating the association value between the string segments according to the positive correlation between the length similarity of the string and the association value between the string segments, calculating the association value between the string segments according to the positive correlation between the Hamming weight similarity of the string and the homomorphic indication value, calculating the association value between the string segments according to the positive correlation between the ratio of repeated characters and the association value between the string segments, calculating the association value between the string segments according to the positive correlation between the length similarity of the string and the Hamming weight similarity of the string and the association value between the string segments, calculating the association value between the string segments according to the positive correlation between the length similarity of the string and the ratio of repeated characters and the association value between the string segments, calculating the association value between the string segments according to the positive correlation between the Hamming weight similarity of the string and the ratio of repeated characters and the association value between the string segments, and calculating the association value between the string segments according to any one of the following: the length similarity of the string and the Hamming weight similarity of the string and the ratio of repeated characters and the association value between the string segments, and the association value between the string segments is represented by a variable x.
[0126] A1 to A7 in Table A represent different implementation methods for calculating the association value between string segments. Any method in Table A is used to calculate the association value between two string segments. For ease of expression, the length similarity of the string is represented by e, the Hamming weight similarity of the string is represented by w, and the proportion of repeated characters is represented by y.
[0127] Table A Different implementations of calculating the association value between string segments
[0128]
[0129]
[0130]
[0131]
[0132]
[0133]
[0134] In this embodiment, the pre-set association threshold value X=2, and if the association value x (for example, A7) between two strings is calculated according to any item in Table A>X, it is determined that the two strings are highly associated (the probability of being treated equally is high), and the two strings are combined and connected, and the corresponding ciphertext results are calculated according to the operation corresponding to the string operation type described in the above implementation. The above steps are performed on two strings, and all the ciphertext results obtained are split and combined according to the order of the original strings to form a complete ciphertext result.
[0135] In an exemplary embodiment, the step S06, the flow chart is as follows Figure 7 As shown, the steps include:
[0136] Step S061: The server returns the ciphertext result Comp_C of the privacy field string operation and the query result Res of the non-privacy field to the user;
[0137] Step S062: The user uses the Paillier private key sk to decrypt the ciphertext result of the privacy field string operation;
[0138] Step S063: The user combines the decryption result of the private field character string with the query result of the non-private field to obtain the final query result.
[0139] In this embodiment, the user uses the Paillier private key sk to perform the calculation result Comp on the privacy field j Decryption of _C, that is, calculation of dec j =(Comp j _C^λmod N 2 -1) / N*μmod N 2 , and obtain the plaintext query result of the privacy field. If the string operation is a position operation (POSITION), calculate dec j,k =(Comp j _C k ^λmod N 2 -1) / N*μmod N 2 , if a dec j,k There are k consecutive 0s in the ASCII decoded string form of j It is the smallest value among all Len(PF)-Len(str)+1–k that meet the conditions, that is, the result of the POSITION operation.
[0140] The user combines the query results of the private field and the non-private field, namely, dec and Res, to obtain the final query result and complete the query.
[0141] To help better understand the details of the present invention, a specific implementation example of a SQL string SUBSTR homomorphic operation is given below. Due to the limitation of data size, only the case where the modulus n=p*q in Paillier encryption is 128 bits is used for illustration. In actual processes, a larger security parameter should be used.
[0142] 1) Paillier encryption parameter settings:
[0143] p=12458956711587562123,
[0144] q=14717327422403960303,
[0145] pk:N=p*q=183362545265991497115233232112238403269,
[0146] sk:λ=(p-1)*(q-1)=183362545265991497088056947978246880844,
[0147] μ=λ -1 modN=161629877898154436766220129125868491783.
[0148] 2) Assume that a plaintext data table contains a privacy field "email", and the email field value of a data record is "amanda79@gmail.com", its ASCII encoding sequence is [0x61, 0x6D, 0x61, 0x6E, 0x64, 0x61, 0x37, 0x39, 0x40, 0x67, 0x6D, 0x61, 0x69, 0x6C, 0x2E, 0x63, 0x6F, 0x6D] = [97, 109, 97, 110, 100, 97, 55, 57, 64, 103, 109, 97, 105, 108, 46, 99, 111, 109]. Its corresponding integer is 97*256 17 +109*256 16 +97*256 15 +110*256 14 +100*256 13 +97*256 12 +55*256 11 +57*256 10 +64*256 9 +103*256 8 +109*256 7 +97*256 6+105*256 5 +108*256 4 +46*256 3 +99*256 2 +111*256+109*1=8487112021679314975928238817989101690777453.
[0149] The plaintext integer of the string "amanda79@gmail.com" is encrypted using Paillier homomorphic encryption, and the ciphertext is s_C=16421177971230616094813243732203526778897157164570988834906208124785563949299.
[0150] The auxiliary information is composed of the encryption of each single character of the string "amanda79@gmail.com" and the length of the string "18". The ciphertext vector [s 0 _C,s 1 _C,…,s 17 _C] is as follows:
[0151] [1864489722459001359312327125958837142062865807877209715040460012822396283732,15263343186963627304869080496271834382145558360014068134662778915138566223363,6715269770448632728391703563179078453094980520399663395962437087134567250503,18893740853837748132975971667582067229976106623749238440289811757525469116026,2980953922938028319993702417697035673139395881943227317937883060001563865424,11475882251610573976169113982398288919955165842406294580041752853430500074444,13064814761293642240963133155092137630695556935172293379016921198530535922999,2658233846968359448304435075388864285945241033662408417519729464335496178379,15779358333698166913199594616241838968949372892689754396103627816196600032597,27825391136944981953732818771975339608498232926262033037177831720162541638862,26505800618604023912862812670043831520548887181407206426166364104178644809064,23969404367943273699010230965953984781840693284099007632678936204532325120969,3874152071131510947011054498463468726685155673515181577371034303432544268758,26506071894494143103619603069059918073606482995356414647167708018946942264419,28240719218912120573511318707469946481633069873045299976890962868024472662318,2 5639547039614734088419586561744832422706237547806718986839514816057387455392,23253415027892258386566699319903676051739114008581022132868458021250194602686,6115016326737349251199728856507746440860045399298894819054060909576479607405].,
[0152] 3) Assume that the query user enters the query statement SUBSTR(mailbox,0,6), which extracts a substring consisting of the first 6 characters of all mailbox data and submits the query to the database server.
[0153] 4) The database server parses the query statement and finds that it is a SUBSTR operation on the privacy field "email". It will then perform a homomorphic operation based on the auxiliary information of "email". For the record corresponding to the plaintext mailbox "amanda79@gmail.com", the length of the string in the auxiliary information is l = 18, and the ciphertext vector [s 0 _C,…,s 17 _C], for start = 0, len = 6, perform the homomorphic operation Comp_C = s 5 _C^(256^0)*…*s 0 _C^(256^5)mod N 2 The ciphertext calculation result is 19370969684580705572617849333841157976386556266039400730944135701731308482944, and this result is sent back to the querying user.
[0154] 5) The query user performs homomorphic decryption on the received ciphertext calculation result and obtains the decrypted result of 107122413954145, which is then expressed in 256-base. Assuming that the upper limit of the uniform length of characters is 20, since 107122413954145=97*256 5 +109*256 4 +97*256 3 +110*256 2 +100*256 1 +97*1, the decoded sequence is [0,0,0,0,0,0,0,0,0,0,0,0,0,0,97,109,97,110,100,97]. We further get the string "amanda", which is indeed the result of the query "SUBSTR('amanda79@gmail.com',0,6)", that is, the first 6 characters of "amanda79@gmail.com". The SUBSTR query result is correct, and the query is completed.
[0155] A database SQL string operation privacy protection system according to an embodiment of the present invention is shown in the structural diagram Figure 8 As shown, including:
[0156] processor;
[0157] Memory;
[0158] as well as
[0159] One or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the processor, the programs causing the computer to perform the above method.
[0160] Of course, those skilled in the art should realize that the above embodiments are only used to illustrate the present invention, and are not intended to limit the present invention. As long as they are within the scope of the present invention, any changes or modifications to the above embodiments will fall within the protection scope of the present invention.
Claims
1. A privacy protection method for database SQL string operations, It is characterized in that include: Perform homomorphic encryption on string data in database privacy fields; Calculate auxiliary information based on private field string information and homomorphic encryption information; The method of calculating auxiliary information according to the private field string information and the homomorphic encryption information includes the steps of: encrypting each single character of the private field string using the Paillier public key; calculating the string length of the string data; Calculate the ciphertext of each single character of the privacy field string; combine the ciphertext of each single character and the string length into a list as auxiliary information; Construct a ciphertext data table based on the encrypted data and auxiliary information; The method of constructing a ciphertext data table according to the encrypted data and the auxiliary information comprises the steps of: replacing the plaintext data with the ciphertext data in the plaintext data table; Add a new field in the plaintext data table to store auxiliary information to form a ciphertext data table; Upload the encrypted data table to the database server for storage; Identify the types of string operations involving privacy fields; Identify the integer operation corresponding to the string operation type, use the auxiliary information to convert the integer operation into a homomorphic operation and use it to calculate the ciphertext result after the privacy field string operation; the homomorphic operation includes addition homomorphism, subtraction homomorphism, multiplication homomorphism combined with addition homomorphism, and multiplication homomorphism combined with subtraction homomorphism; The method of using auxiliary information to convert integer operations into homomorphic operations and using this to calculate the ciphertext result after the privacy field string operation includes the steps of: evenly or randomly dividing the string of the privacy field into multiple segments; Calculate the association value between string segments according to the length similarity of each string segment and / or the Hamming weight similarity of the string and / or the ratio of repeated characters; combine and connect the strings whose association value is greater than or equal to the set threshold, use auxiliary information to convert integer operations into homomorphic operations and use this to calculate the ciphertext result after the string operation; For strings with correlation values less than the set threshold, use auxiliary information to convert integer operations into homomorphic operations and use this to calculate the ciphertext result after the string operation; The ciphertext result after the string operation is reassembled according to the original string connection method to form the ciphertext result after the privacy field string operation; The user's final query result is obtained based on the ciphertext result after the privacy field string operation and the query result of the non-privacy field.
2. The database SQL string operation privacy protection method according to claim 1, It is characterized in that The method of performing homomorphic encryption on the string data of the database privacy field comprises the following steps: Generate the plaintext two-dimensional table Table_P required in the database; assume that Table_P has m data and n fields; The user specifies t fields as privacy fields, namely PF1,…,PFt; Select random 1024-bit prime numbers p and q, calculate the modulus N = p·q; let g = N+1, λ = (p-1)·(q-1), calculate μ = λ -1 modN; The Paillier public key is calculated as pk = (N, g) and the private key is sk = (λ, μ); Let i = 1, 2, ..., t, j = 1, 2, ..., m, and use the Paillier public key pk to homomorphically encrypt the string data PF of all private fields i _Data j , that is, select a random number r from (0, N) such that r and N are relatively prime, and calculate the ciphertext PF i _Data j _C=(g^Int(PF i _Data j ))·(r^N)modN 2 , where Int(PF i _Data j ) represents string data PF i _Data j The corresponding large integer converted in ASCII encoding.
3. The database SQL string operation privacy protection method according to claim 2, It is characterized in that The method of calculating auxiliary information according to the private field string information and the homomorphic encryption information comprises the following steps: Encrypt PF using Paillier public key pk i _Data j Each single character of Calculate string data PF i _Data j The length of the string is recorded as l; Select l different random numbers r in (0,N) 1 ,r 2 ,…,r l , satisfying r 1 ,r 2 ,…,r l are all coprime to N. For k = 1, 2, ..., l, calculate PF i _Data j The ciphertext of each single character PF i _Data j _s k _C=(g^Int(PF i _Data j_ s k ))*(r k ^N)modN 2 ; Each single character ciphertext PF i _Data j _s k _C and string length l are combined into a list PF i _Data j_ Aux is auxiliary information.
4. The database SQL string operation privacy protection method according to claim 3, It is characterized in that The method of constructing a ciphertext data table according to the encrypted data and auxiliary information comprises the following steps: In the plaintext data table Table_P, use the ciphertext data PF i _Data j _C replaces the plaintext data PF i _Data j ; Add t fields, where the jth row of the i-th field stores the string PF i _Data j Auxiliary information PF i _Data j_ Aux, forming the ciphertext data table Table_C; Upload the encrypted data table Table_C to the database server for storage.
5. The database SQL string operation privacy protection method according to claim 4, It is characterized in that The identification of the string operation type involving the privacy field comprises the steps of: The user submits a string operation SQL statement involving privacy fields, which is recorded as SQL_State; The database server DBS analyzes the statement SQL_State to determine the string operation type of the privacy field; the string operation type includes CONCAT (PF1, PF2) connection operation, SUBSTR (PF, start, len) substring operation, POSITION (str in PF) position return operation, TRIM (char from PF) character deletion operation, UPPER (PF) uppercase conversion operation, LOWER (PF) lowercase conversion operation, and INITCAP (PF) first letter uppercase conversion operation.
6. The database SQL string operation privacy protection method according to claim 5, It is characterized in that The integer operation corresponding to the identification string operation type includes: The CONCAT (PF1, PF2) connection operation is to connect the corresponding strings of the privacy fields PF1 and PF2, and its integer operation is: Comp = Int (PF1) * 256^Len (PF2) + Int (PF2); The substring operation of SUBSTR (PF, start, len) is to intercept the corresponding string of the substring of the privacy field PF string starting from start and with a length of len. Its integer operation: Comp = Int (s start+len-1 )*256^0+…+Int(s start )*256^(len-1), where s i Refers to the i-th character in the privacy field PF string; The POSITION(str in PF) return position operation is to return the corresponding string of the starting position of the substring str in the privacy field PF string. Its integer operation is: for a certain k, there are Len(str) consecutive 0 characters in the string form of Int(PF)-Int(str)*256^k, then the position is Len(PF)-Len(str)+1-k; The TRIM (char from PF) character deletion operation is to delete the corresponding character string of the leading repeated character char in the privacy field PF string, and its integer operation is: Comp = Int (PF) - Int (k char's) * 256^ (Len (PF) - k + 1); The UPPER (PF) uppercase conversion operation converts all characters of the privacy field PF string into uppercase corresponding strings, and its integer operation is: Comp = Int (PF) + 32 * (1 + 256 + ... + 256^ (Len (PF) - 1)); The LOWER (PF) conversion operation is to convert all characters of the privacy field PF string into the corresponding lowercase string, and its integer operation is: Comp = Int (PF) - 32 * (1 + 256 + ... + 256^ (Len (PF) - 1)); The INITCAP (PF) first letter uppercase conversion operation is to convert the first character of the privacy field PF string into the corresponding uppercase string, and its integer operation is: Comp = Int (PF) + 32*256^ (Len (PF) - 1).
7. The database SQL string operation privacy protection method according to claim 5, It is characterized in that The method of using auxiliary information to convert integer operations into homomorphic operations and using the same to calculate the ciphertext result after the string operation includes: CONCAT(PF1,PF2) connection operation: using the string length in the auxiliary information, using the Paillier number multiplication homomorphism combined with the Paillier addition homomorphism, that is, for j = 1, 2, ..., m, calculate the ciphertext result Comp j _C=PF 1 _Data j ^(256^Len(PF2))*PF 2 _Data j modN 2 ; SUBSTR(PF, start, len) substring operation: using the single character encryption result in the auxiliary information, use Paillier number multiplication homomorphism combined with Paillier addition homomorphism, that is, for j = 1, 2, ..., m, calculate the ciphertext result Comp j _C=PF_Data j_ s start+len–1 _C^(256^0)*…*PF_Data j_ s start _C^(256^(len–1))modN 2 ; POSITION(str in PF) returns the position operation: using the string length in the auxiliary information, use the Paillier number multiplication homomorphism combined with the Paillier subtraction homomorphism, that is, for j = 1, 2, ..., m, k = 1, 2, ..., Len(PF)-Len(str), calculate the ciphertext result Comp j _C k =PF_Data j *(E(str)^(256^k)) -1 modN 2 ; TRIM (char from PF) deletes characters: Using the string length in the auxiliary information, use the Paillier number multiplication homomorphism combined with the Paillier subtraction homomorphism, that is, for j = 1, 2, ..., m, calculate the ciphertext result Comp j _C=PF_Data j *(E(kchar's)^(256^(Len(PF)–k+1))) -1 modN 2 , where E(kchar's) represents the Paillier encryption result of a string consisting of k consecutive repeated characters char; UPPER (PF) conversion to uppercase: Using the string length in the auxiliary information, use the Paillier addition homomorphism, that is, for j = 1, 2, ..., m, calculate the ciphertext result Comp j _C=PF_Data j *E(32*(1+256+…+256^(Len(PF)-1)))modN 2 , where E(Const) represents the Paillier encryption result of the constant Const; LOWER(PF) Lowercase operation: Using the string length in the auxiliary information, with Paillier subtraction homomorphism, that is, for j = 1, 2, …, m, calculate the ciphertext result Comp j _C = PF_Data j *E(32*(1 + 256 + … + 256^(Len(PF) - 1))) - 1 mod N 2 ; INITCAP (PF) first character conversion operation: using the string length in the auxiliary information, use the Paillier addition homomorphism, that is, for j = 1, 2, ..., m, calculate the ciphertext result Comp j _C=PF_Data j *E(32*256^(Len(PF)-1))modN 2 .
8. The database SQL string operation privacy protection method according to claim 7, It is characterized in that The method of obtaining the final query result of the user based on the ciphertext result of the privacy field string operation and the query result of the non-privacy field comprises the following steps: The server returns the ciphertext result Comp_C of the privacy field string operation and the query result Res of the non-privacy field to the user; The user uses the Paillier private key sk to decrypt the ciphertext result of the private field string operation; The user combines the decryption result of the private field string and the query result of the non-private field to obtain the final query result.
9. A database SQL string operation privacy protection system, Features include: processor; Memory; as well as One or more programs, wherein the one or more programs are stored in a memory and configured to be executed by the processor, the programs causing the computer to execute the method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Data homomorphic encrypting and unloading method of multi-data source
CN103425933A
Multi-user privacy protection machine learning method and device based on multi-key fully homomorphic encryption
CN114844621A