Ot communication method and apparatus, electronic device, and storage medium

By introducing a proxy on the server side and using a high-speed communication interface for OT communication, the inefficiency and availability issues when the client and server are deployed across networks are resolved, thereby improving the efficiency and availability of OT communication.

CN115834113BActive Publication Date: 2026-05-15BEIJING PASSWORD CLOUD CORE TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-11
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

When deployed across networks on both the client and server sides, OT communication is extremely inefficient, leading to a loss of communication availability.

Method used

By introducing a proxy on the server side, and physically deploying the proxy and server on the same side, communication can be achieved using a high-speed communication interface, avoiding multiple cross-network transmissions and improving the efficiency and availability of OT communication.

Benefits of technology

By reducing the number of cross-network transmissions, the efficiency and availability of OT communication are improved, and the inefficiency caused by cross-network deployment is resolved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115834113B_ABST
    Figure CN115834113B_ABST
Patent Text Reader

Abstract

Embodiments of the present application disclose an OT communication method and device, electronic equipment and storage medium. An OT access request sent by a client is acquired, the OT access request comprising an OT index; a target access request is generated according to the OT index and the OT access request; the target access request is sent to a server, so that the server determines and feeds back at least two candidate access results in response to the target access request; a target access result is selected from the at least two candidate access results, and the target access result is fed back to the client. Embodiments of the present application improve the efficiency and availability of OT communication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to communication technology, and more particularly to an OT communication method, apparatus, electronic device, and storage medium. Background Technology

[0002] Oblivious transfer (OT) is a privacy-preserving two-way communication protocol. The sender does not know the receiver's privacy, allowing both parties to transmit messages in a selectively obfuscated manner. Oblivious transfer can be broadly categorized into 2-to-1, n-to-1, and n-to-k transfer protocols.

[0003] In practical applications, inadvertent transmission protocols such as n-choose-1 and n-choose-k are often used. During the execution of these protocols, the client and server exchange messages multiple times. When the client and server are deployed across networks, the multiple cross-network transmissions can lead to extremely low OT communication efficiency, ultimately resulting in a loss of availability. Summary of the Invention

[0004] This application provides an OT communication method, apparatus, electronic device, and storage medium to improve the efficiency and availability of OT communication.

[0005] In a first aspect, embodiments of this application provide an OT communication method applied to a proxy terminal physically deployed on the server side. This OT communication method includes:

[0006] Retrieve the OT access request sent by the client. The OT access request includes the OT index.

[0007] Generate the target access request based on the OT index and the OT access request;

[0008] Send a target access request to the server so that the server responds to the target access request, determines and returns at least two candidate access results;

[0009] Select the target access result from at least two candidate access results and return the target access result to the client.

[0010] Secondly, embodiments of this application provide an OT communication method applied to a server physically deployed on the same side as the agent. This OT communication method includes:

[0011] Obtain the target access request sent by the proxy; wherein, the target access request is generated by the OT index and OT access request in the OT access request sent by the client obtained by the proxy;

[0012] In response to the target access request, determine at least two candidate access results;

[0013] The proxy sends feedback on each candidate access result so that the proxy can select the target access result from each candidate access result and send it back to the client.

[0014] Thirdly, embodiments of this application also provide an OT communication device configured on a proxy terminal physically deployed on the server side, wherein the OT communication device includes:

[0015] The access request acquisition module is used to acquire unintentional Transport Protocol (OT) access requests sent by the client. The OT access requests include the OT index.

[0016] The target access request generation module is used to generate target access requests based on the OT index and OT access requests;

[0017] The target access request sending module is used to send a target access request to the server so that the server responds to the target access request, determines and returns at least two candidate access results;

[0018] The result feedback module is used to select the target access result from at least two candidate access results and feed the target access result back to the client.

[0019] Fourthly, embodiments of this application also provide an OT communication device configured on a server physically deployed on the same side as the agent, the OT communication device comprising:

[0020] The target access request acquisition module is used to acquire the target access request sent by the proxy; wherein, the target access request is generated by the OT index and OT access request in the unintentional transport protocol OT access request sent by the client obtained by the proxy.

[0021] The candidate access result determination module is used to determine at least two candidate access results in response to a target access request;

[0022] The candidate access result feedback module is used to feed back each candidate access result to the agent so that the agent can feed back the target access result selected from each candidate access result to the client.

[0023] Fifthly, embodiments of this application also provide an electronic device, which includes:

[0024] One or more processors;

[0025] Storage device for storing one or more programs;

[0026] When one or more programs are executed by one or more processors, the one or more processors implement any of the OT communication methods provided in the embodiments of this application.

[0027] Sixthly, embodiments of this application also provide a storage medium including computer-executable instructions, which, when executed by a computer processor, are used to perform any of the OT communication methods provided in embodiments of this application.

[0028] This application obtains an Unintentional Transport Protocol (OT) access request sent by a client, the OT access request including an OT index; generates a target access request based on the OT index and the OT access request; sends the target access request to the server, causing the server to respond to the target access request, determine and return at least two candidate access results; selects the target access result from the at least two candidate access results, and returns the target access result to the client. The client only needs to send the OT access request including the OT index to the proxy and receive the target access result from the proxy. Other interactions in OT communication are completed by the proxy and server, which are physically deployed on the same side, eliminating the need for multiple cross-network transmissions. Therefore, the technical solution of this application solves the problem that when the client and server are deployed across networks, multiple cross-network transmissions may lead to extremely low OT communication efficiency and even loss of availability, thus improving the efficiency and availability of OT communication. Attached Figure Description

[0029] Figure 1 This is a flowchart of an OT communication method according to Embodiment 1 of this application;

[0030] Figure 2 This is a flowchart of an OT communication method according to Embodiment 2 of this application;

[0031] Figure 3 This is a flowchart of an OT communication method according to Embodiment 3 of this application;

[0032] Figure 4 This is a schematic diagram of the structure of an OT communication device according to Embodiment 4 of this application;

[0033] Figure 5 This is a schematic diagram of the structure of an OT communication device according to Embodiment 5 of this application;

[0034] Figure 6 This is a schematic diagram of the structure of an electronic device according to Embodiment Six of this application. Detailed Implementation

[0035] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.

[0036] It should be noted that the terms "first" and "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0037] Example 1

[0038] Figure 1 This is a flowchart of an OT communication method provided in Embodiment 1 of this application. This embodiment is applicable to communication based on OT. The method can be executed by an OT communication device, which can be implemented in software and / or hardware and is specifically configured in an agent terminal physically deployed on the server side.

[0039] See Figure 1 The OT communication method shown is applied to a proxy physically deployed on the server side, and specifically includes the following steps:

[0040] S110. Obtain the OT access request sent by the client. The OT access request includes the OT index.

[0041] OT (Optical Transmission) is a privacy-preserving two-way communication protocol. In OT communication, the receiver's privacy is unknown to the sender, allowing both parties to transmit messages in a selectively ambiguous manner. Abstractly speaking, A sends a message to B, but A doesn't know what B received. Specifically, the general approach is for A to send multiple messages and let B choose the ones they need, while ensuring that B doesn't learn unwanted information. OT can be broadly categorized into 2-to-1, n-to-1, and n-to-k transmission protocols.

[0042] An OT (Oblivion-to-Operation) access request is a request sent by a client to a proxy based on an unobservable transport protocol. For example, an OT access request may include the server address to be accessed and the content to be accessed. Specifically, the access content includes an OT index. An OT index is identification information used to identify the target access object of the client's OT access request, i.e., used to subsequently determine the target access request. There must be at least one OT index. For example, when OT is an n-choose-k transport protocol, the number of OT indices is k. For example, OT indices can be numbers, letters, or a combination of letters and numbers, etc., and this application does not specifically limit this.

[0043] The client has a pre-installed public key of the proxy, and the proxy also has a pre-installed public key of the client. The client and the proxy establish a secure channel through a key agreement algorithm for information exchange between them. For example, information exchange between the client and the proxy can be a client sending an OT access request. Exemplary key agreement algorithms can be DHE (a technical term, a key agreement algorithm) or ECDHE (a technical term, a key agreement algorithm), etc., and this application does not specifically limit them.

[0044] S120. Generate the target access request based on the OT index and the OT access request.

[0045] To protect client privacy, the proxy needs to encrypt OT access requests so that the server is unaware of the index number corresponding to the information accessed by the proxy. The proxy stores the public key corresponding to all indices sent by the server. Based on the obtained OT index, the proxy determines the public key corresponding to that index. The determined public key is then used to encrypt the proxy's symmetric key to obtain ciphertext. For example, the proxy's symmetric key can be content specified in the OT access request or generated by the proxy; this application does not specifically limit its use. For instance, the symmetric key could be a random number instructing the proxy to generate it.

[0046] The target access request is the access request sent from the proxy to the server. The target access request is generated based on the OT access request and the ciphertext obtained from the OT index.

[0047] S130. Send a target access request to the server so that the server responds to the target access request, determines and returns at least two candidate access results.

[0048] The proxy sends the target access request to the server. Upon receiving the target access request, the server responds. Specifically, the server decrypts the target access request using its stored private key, performs symmetric encryption on the information corresponding to the private key based on the decryption result, and generates candidate access results corresponding to the index number of the private key. The server returns at least two selected candidate access results to the proxy. There are at least two candidate access results.

[0049] S140. Select the target access result from at least two candidate access results and send the target access result back to the client.

[0050] The target access result can be the access result corresponding to the target access request. The proxy determines the target access result from at least two received candidate access results based on the index number. That is, the candidate access result corresponding to the index number among at least two candidate access results is determined as the target access result. Specifically, the target access result can be decrypted using a symmetric encryption key, and the decrypted target access result is sent back to the client.

[0051] In practice, OT clients and servers often need to be deployed across networks, and high network overhead is a major cause of low OT communication efficiency. This application adds a proxy to the OT client; for example, a hardware security module can be added as a proxy. The proxy and server are physically deployed together and can communicate through various high-speed communication interfaces, such as USB 3.0 (Universal Serial Bus 3.0), serial ports, and high-speed LANs, avoiding the low efficiency problems of traditional Internet or WAN communication. Intermediate results of OT communication are temporarily stored in the proxy, and then the proxy returns the communication results to the client. In this way, the OT client and proxy only need to perform a small amount of cross-network communication to complete the entire OT process.

[0052] The technical solution of this embodiment obtains an Unintentional Transport Protocol (OT) access request sent by the client, the OT access request including an OT index; generates a target access request based on the OT index and the OT access request; sends the target access request to the server, so that the server responds to the target access request, determines and returns at least two candidate access results; selects the target access result from the at least two candidate access results, and returns the target access result to the client. The client only needs to send the OT access request including the OT index to the proxy and receive the target access result from the proxy. Other interactions in OT communication are completed by the proxy and server, which are physically deployed on the same side, without the need for multiple cross-network transmissions. Therefore, the technical solution of this application solves the problem that when the client and server are deployed across networks, multiple cross-network transmissions may lead to extremely low OT communication efficiency and even loss of availability, thus improving the efficiency and availability of OT communication.

[0053] Example 2

[0054] Figure 2 This is a flowchart of an OT communication method provided in Embodiment 2 of this application. The technical solution of this embodiment is further refined based on the above technical solution.

[0055] Furthermore, the OT communication method also includes: obtaining at least two candidate public keys sent by the server. Accordingly, "generating a target access request based on the OT index and the OT access request" is refined to: "selecting a target public key from each candidate public key based on the OT index; encrypting a target random number based on the target public key to generate a target access request", so as to encrypt the access request to obtain the target access request.

[0056] See Figure 2 An OT communication method shown includes:

[0057] S210. Obtain the Unintentional Transport Protocol (OT) access request sent by the client. The OT access request includes the OT index.

[0058] S220: Obtain at least two candidate public keys sent by the server.

[0059] A candidate public key is a set of public keys used in OT communication, with the number of public keys corresponding to the OT communication mode. For example, if the OT communication is an n-to-k transport protocol, the server sends n candidate public keys. Specifically, the server generates n pairs of candidate public and private keys based on the OT communication mode. Each candidate public key is labeled with an index number, and the corresponding candidate private key has the same index number. Each pair of candidate public and private keys corresponds to one access result. The server sends the candidate public keys to the proxy. For example, the server can periodically change the candidate public and private key pairs and send the updated candidate public keys to the proxy in real time, further ensuring the security of OT communication.

[0060] S230. Select the target public key from the candidate public keys according to the OT index.

[0061] The candidate public key with the same index number as the OT index is selected as the target public key. The target public key can be used to perform asymmetric encryption on OT requests to ensure that the server cannot obtain the OT index accessed by the proxy, thus protecting the client's privacy.

[0062] S240. Encrypt the target random number based on the target public key to generate a target access request.

[0063] The target random number is a random number generated by the proxy. For example, after receiving an OT access request from the client, the proxy can generate a random number using a random number function and use this random number as the target random number. The target random number is then encrypted using the RSA (an asymmetric encryption algorithm) algorithm based on the target public key to generate the target access request.

[0064] S250. Send a target access request to the server so that the server responds to the target access request, determines and returns at least two candidate access results.

[0065] In an optional embodiment, sending a target access request to the server so that the server responds to the target access request by determining and returning at least two candidate access results includes: sending a target access request to the server so that the server, based on the candidate private keys corresponding to the candidate public keys of at least two candidates, decrypts the target access request to obtain each candidate random number, encrypts the corresponding candidate access result plaintext, and returns at least two candidate access result ciphertexts; wherein the number of candidate public keys is the same as and corresponds to the number of candidate access result plaintexts.

[0066] When the proxy sends a target access request to the server, the server decrypts the request using at least two candidate public keys corresponding to candidate private keys, obtaining candidate random numbers. Specifically, upon receiving the target access request, the server decrypts it using all candidate private keys, obtaining candidate random numbers corresponding to each candidate private key. This correspondence can be marked by an index number. Each candidate random number has the same index number as the candidate private key. The candidate random number decrypted using the candidate private key corresponding to the target public key is the target random number; other candidate private keys, since they do not correspond to the target public key, may result in garbled text, which can be considered random numbers in a computer.

[0067] The obtained candidate random numbers are used to symmetrically encrypt the plaintext of each candidate access result corresponding to each candidate private key, resulting in ciphertext of the candidate access result corresponding to each candidate private key. There are at least two ciphertexts of candidate access results. The server sends each ciphertext of candidate access results back to the proxy. Each candidate public key has a unique corresponding candidate access result plaintext with the same index number. That is, the number of candidate public keys is the same as the number of candidate access result plaintexts and they correspond to each other.

[0068] By sending a target access request to the server, the server decrypts the target access request using at least two candidate public keys corresponding to candidate private keys. The resulting candidate random numbers are then used to encrypt the corresponding candidate access results in plaintext, and the server returns at least two candidate access result ciphertexts, thus ensuring the security of the access results.

[0069] S260. Select the target access result from at least two candidate access results and send the target access result back to the client.

[0070] In an optional embodiment, the selection of a target access result from at least two candidate access results includes: decrypting the ciphertext of the candidate access result corresponding to the OT index according to the target random number to obtain the plaintext of the candidate access result corresponding to the decrypted candidate access result ciphertext, which is then used as the target access result.

[0071] After receiving the ciphertext of the candidate access result, the agent uses the OT index obtained from the client to decrypt the ciphertext of the candidate access result with the same index number as the OT index using the target random number, and obtains the target access result.

[0072] By decrypting the ciphertext of the candidate access result corresponding to the OT index according to the target random number, the plaintext of the candidate access result corresponding to the decrypted candidate access result ciphertext is obtained as the target access result. It is not necessary to decrypt all the candidate access result ciphertexts, saving computing resources, improving decryption efficiency, and thus improving the efficiency of OT communication.

[0073] The technical solution of this embodiment obtains at least two candidate public keys sent by the server, selects the target public key from each candidate public key according to the OT index, encrypts the target random number according to the target public key, generates a target access request, realizes asymmetric encryption of the target random number, and ensures the security of the transmission of the target random number.

[0074] Example 3

[0075] Figure 3 This is a flowchart of an OT communication method provided in Embodiment 3 of this application. This embodiment is applicable to communication based on OT. The method can be executed by an OT communication device, which can be implemented in software and / or hardware and is specifically configured on a server that is physically deployed on the same side as the agent.

[0076] See Figure 3 The OT communication method shown is applied to a server that is physically deployed on the same side as the agent, and specifically includes the following steps:

[0077] S310. Obtain the target access request sent by the agent; wherein, the target access request is generated by the OT index and OT access request in the OT access request sent by the client obtained by the agent.

[0078] The server obtains the target access request sent by the proxy. The target access request is generated by the proxy from the OT index and OT access request in the OT access request sent by the client. For the specific generation method, please refer to the above embodiment.

[0079] S320. In response to the target access request, determine at least two candidate access results.

[0080] Upon receiving a target access request, the server responds. Specifically, the server decrypts the request using its stored private key, performs symmetric encryption on the information corresponding to the private key based on the decryption result, and generates candidate access results corresponding to the index number of the private key. There are at least two candidate access results.

[0081] S330. Feed back each candidate access result to the agent so that the agent can feed back the target access result selected from each candidate access result to the client.

[0082] The server sends back the candidate access results to the proxy, enabling the proxy to select the target access result from these candidates and send it back to the client. Specifically, after obtaining the candidate access results, the proxy selects the target access result based on the OT index obtained from the client and sends the target access result back to the client.

[0083] The technical solution of this embodiment obtains a target access request sent by a proxy. This target access request is generated by the proxy from the OT index and OT access request in the OT access request sent by the client. In response to the target access request, at least two candidate access results are determined. Each candidate access result is fed back to the proxy, so that the proxy can return the target access result selected from the candidate results to the client. The interaction process in OT communication is completed by the proxy and server, which are physically deployed on the same side. Multiple cross-network transmissions are not required; the proxy only needs to return the target access result to the client. Therefore, the technical solution of this application solves the problem that when the client and server are deployed across networks, multiple cross-network transmissions may lead to extremely low OT communication efficiency and even loss of availability, thus improving the efficiency and availability of OT communication.

[0084] In an optional embodiment, the OT communication method further includes: generating at least two public-private key pairs including candidate public keys and corresponding candidate private keys, and sending at least two candidate public keys to the agent. Correspondingly, the target access request is obtained by the agent encrypting the target random number based on the target random number and the target public key selected from each candidate public key based on the OT index.

[0085] The server generates at least two public-private key pairs, including a candidate public key and a corresponding candidate private key. It then sends all candidate public keys from these pairs to the agent. The server can periodically update all public-private key pairs and send the updated candidate public keys to the agent in real time, further ensuring the security of OT communication.

[0086] Accordingly, the target access request is obtained by the proxy by encrypting the target random number based on the target random number and the target public key selected from each candidate public key based on the OT index.

[0087] The proxy selects the target public key from among the candidate public keys based on the OT index. The candidate public key with the same index number as the OT index is then identified as the target public key. The proxy uses the target public key to encrypt a target random number to obtain the target access request.

[0088] By generating at least two public-private key pairs, including candidate public keys and corresponding candidate private keys, and sending at least two candidate public keys to the proxy, the proxy can obtain the candidate public keys in a timely manner. The target access request is obtained by the proxy through encryption of the target random number based on the target random number and the target public key selected from the candidate public keys based on the OT index. This ensures that the server cannot know the target public key selected by the proxy, thus protecting the client's information privacy.

[0089] In an optional embodiment, in response to a target access request, at least two candidate access results are determined, including: decrypting the target access request according to each candidate private key to obtain a corresponding candidate random number; encrypting the plaintext of the corresponding candidate access result according to each candidate random number to obtain at least two candidate access result ciphertexts; wherein the number of candidate public keys is the same as and corresponds to the number of candidate access result plaintexts.

[0090] Upon receiving a target access request, the server decrypts the request using each candidate private key. Specifically, the candidate random number obtained by decrypting the request using the candidate private key corresponding to the target public key becomes the target random number. Since the other candidate private keys do not correspond to the target public key, the decryption results may be garbled, but in a computer, garbled text can be considered as random numbers. The server uses all the decrypted random numbers as candidate random numbers corresponding to each candidate private key, and then uses these candidate random numbers to symmetrically encrypt the plaintext of the candidate access result corresponding to each candidate private key, obtaining the ciphertext of the candidate access result. The number of plaintext candidate access results is the same as the number of candidate private keys, and they all have the same index number. Therefore, the number of ciphertext candidate access results is the same as the number of candidate private keys, and they all have the same index number.

[0091] By decrypting the target access request based on each candidate private key, the corresponding candidate random number is obtained. Since the server does not know the OT index in the OT access request sent by the client, it obtains the candidate random number corresponding to all candidate private keys, encrypts the plaintext of the corresponding candidate access result, and obtains at least two candidate access result ciphertexts, which can ensure the security of the candidate access result in the process of sending it to the proxy.

[0092] Accordingly, the agent sends back each of the candidate access results to the agent so that the agent can send back the target access result selected from each candidate access result to the client. This includes: sending back each candidate access result to the agent so that the agent can decrypt the ciphertext of the candidate access result corresponding to the OT index according to the target random number, and sending back the decrypted candidate access result plaintext as the target access result to the client.

[0093] After receiving the ciphertext of the candidate access results, the server sends the ciphertext as each candidate access result to the proxy. Upon receiving the ciphertext, the proxy uses the OT index obtained from the client and a target random number to decrypt the ciphertext of the candidate access result with the same index number as the OT index, thus obtaining the target access result.

[0094] By feeding back each candidate access result to the proxy, the proxy can decrypt the ciphertext of the candidate access result corresponding to the OT index based on the target random number. This eliminates the need to decrypt all candidate access result ciphertexts, saving computing resources, improving decryption efficiency, and thus improving the efficiency of OT communication. The proxy then feeds back the decrypted candidate access result plaintext as the target access result to the client, allowing the client to directly obtain the target access result through the proxy, reducing cross-network transmission and improving the efficiency of OT communication.

[0095] Example 4

[0096] Figure 4 The diagram shown is a structural schematic of an OT communication device provided in Embodiment 4 of this application. This embodiment is applicable to communication based on OT and is configured on a proxy terminal physically deployed on the server side. The specific structure of the OT communication device is as follows:

[0097] Access request acquisition module 410 is used to acquire unintentional transport protocol (OT) access requests sent by the client. The OT access request includes an OT index.

[0098] The target access request generation module 420 is used to generate a target access request based on the OT index and the OT access request.

[0099] The target access request sending module 430 is used to send a target access request to the server so that the server responds to the target access request, determines and returns at least two candidate access results;

[0100] The result feedback module 440 is used to select the target access result from at least two candidate access results and feed the target access result back to the client.

[0101] The technical solution of this embodiment obtains an Unintentional Transport Protocol (OT) access request sent by the client, the OT access request including an OT index; generates a target access request based on the OT index and the OT access request; sends the target access request to the server, so that the server responds to the target access request, determines and returns at least two candidate access results; selects the target access result from the at least two candidate access results, and returns the target access result to the client. The client only needs to send the OT access request including the OT index to the proxy and receive the target access result from the proxy. Other interactions in OT communication are completed by the proxy and server, which are physically deployed on the same side, without the need for multiple cross-network transmissions. Therefore, the technical solution of this application solves the problem that when the client and server are deployed across networks, multiple cross-network transmissions may lead to extremely low OT communication efficiency and even loss of availability, thus improving the efficiency and availability of OT communication.

[0102] Optional, the OT communication device also includes:

[0103] The candidate public key acquisition module is used to acquire at least two candidate public keys sent by the server.

[0104] Accordingly, the target access request generation module 420 includes:

[0105] The target public key selection unit is used to select the target public key from each candidate public key according to the OT index;

[0106] The OT request encryption unit is used to encrypt a target random number based on the target public key and generate a target access request.

[0107] Optionally, the target access request sending module 430 includes:

[0108] The target access request sending unit is used to send a target access request to the server, so that the server decrypts the target access request based on at least two candidate public keys corresponding to candidate private keys, obtains each candidate random number, encrypts the corresponding candidate access result plaintext, and obtains and returns at least two candidate access result ciphertexts; wherein the number of candidate public keys is the same as and corresponds to the number of candidate access result plaintexts.

[0109] Correspondingly, the result feedback module 440 includes:

[0110] The result ciphertext decryption unit is used to decrypt the candidate access result ciphertext corresponding to the OT index according to the target random number, and obtain the candidate access result plaintext corresponding to the decrypted candidate access result ciphertext as the target access result.

[0111] The OT communication device provided in this application embodiment can execute the OT communication method provided in any embodiment of this application, and has the corresponding functional modules and beneficial effects for executing the OT communication method.

[0112] Example 5

[0113] Figure 5 The diagram shown is a structural schematic of an OT communication device provided in Embodiment 5 of this application. This embodiment is applicable to communication based on OT and is configured on a server that is physically deployed on the same side as the agent. The specific structure of the OT communication device is as follows:

[0114] The target access request acquisition module 510 is used to acquire the target access request sent by the proxy; wherein, the target access request is generated by the OT index and OT access request in the unintentional transport protocol OT access request sent by the client obtained by the server;

[0115] The candidate access result determination module 520 is used to determine at least two candidate access results in response to the target access request;

[0116] The candidate access result feedback module 530 is used to feed back each candidate access result to the agent so that the agent can feed back the target access result selected from each candidate access result to the client.

[0117] The technical solution of this embodiment obtains a target access request sent by a proxy. This target access request is generated by the proxy from the OT index and OT access request in the OT access request sent by the client. In response to the target access request, at least two candidate access results are determined. Each candidate access result is fed back to the proxy, so that the proxy can return the target access result selected from the candidate results to the client. The interaction process in OT communication is completed by the proxy and server, which are physically deployed on the same side. Multiple cross-network transmissions are not required; the proxy only needs to return the target access result to the client. Therefore, the technical solution of this application solves the problem that when the client and server are deployed across networks, multiple cross-network transmissions may lead to extremely low OT communication efficiency and even loss of availability, thus improving the efficiency and availability of OT communication.

[0118] Optional, the OT communication device also includes:

[0119] The public-private key pair generation module is used to generate at least two public-private key pairs, including candidate public keys and corresponding candidate private keys, and send at least two candidate public keys to the agent. Correspondingly, the target access request is obtained by the agent encrypting the target random number based on the target random number and the target public key selected from each candidate public key based on the OT index.

[0120] Optionally, the candidate access result determination module 520 includes:

[0121] The access request decryption unit is used to decrypt the target access request based on each candidate private key to obtain the corresponding candidate random number;

[0122] The plaintext encryption unit for access results is used to encrypt the corresponding candidate access result plaintext according to each candidate random number to obtain at least two candidate access result ciphertexts; wherein, the number of candidate public keys is the same as and corresponds to the number of candidate access result plaintexts;

[0123] Correspondingly, the candidate access result feedback module 530 includes:

[0124] The candidate access result sending unit is used to send each candidate access result back to the agent so that the agent can decrypt the ciphertext of the candidate access result corresponding to the OT index according to the target random number, and send the decrypted candidate access result plaintext back to the client as the target access result.

[0125] The OT communication device provided in this application embodiment can execute the OT communication method provided in any embodiment of this application, and has the corresponding functional modules and beneficial effects for executing the OT communication method.

[0126] Example 6

[0127] Figure 6 This is a schematic diagram of the structure of an electronic device provided in Embodiment Six of this application, as shown below. Figure 6 As shown, the electronic device includes a processor 610, a memory 620, an input device 630, and an output device 640; the number of processors 610 in the electronic device can be one or more. Figure 6 Taking a processor 610 as an example; the processor 610, memory 620, input device 630, and output device 640 in the electronic device can be connected via a bus or other means. Figure 6 Taking the example of a connection between China and Israel via a bus.

[0128] The memory 620, as a computer-readable storage medium, can be used to store software programs, computer-executable programs, and modules, such as the program instructions / modules corresponding to the OT communication method in this embodiment (e.g., access request acquisition module 410, target access request generation module 420, target access request sending module 430, and result feedback module 440). The processor 610 executes various functional applications and data processing of the electronic device by running the software programs, instructions, and modules stored in the memory 620, thereby implementing the aforementioned OT communication method.

[0129] The memory 620 may primarily include a program storage area and a data storage area. The program storage area may store the operating system and at least one application program required for a given function; the data storage area may store data created based on terminal usage. Furthermore, the memory 620 may include high-speed random access memory and non-volatile memory, such as at least one disk storage device, flash memory device, or other non-volatile solid-state storage device. In some instances, the memory 620 may further include memory remotely located relative to the processor 610, which can be connected to the electronic device via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.

[0130] Input device 630 can be used to receive input character information and generate key signal inputs related to user settings and function control of the electronic device. Output device 640 may include display devices such as a display screen.

[0131] Example 7

[0132] Embodiment 7 of this application also provides a storage medium containing computer-executable instructions. When executed by a computer processor, the computer-executable instructions are used to execute an OT communication method applied to an agent physically deployed on the server side. The method includes: obtaining an Unintentional Transport Protocol (OT) access request sent by a client, the OT access request including an OT index; generating a target access request based on the OT index and the OT access request; sending the target access request to the server so that the server responds to the target access request, determines and feeds back at least two candidate access results; selecting the target access result from the at least two candidate access results, and feeding back the target access result to the client.

[0133] Embodiment 7 of this application also provides a storage medium containing computer-executable instructions. When executed by a computer processor, the computer-executable instructions are used to execute an OT communication method applied to a server physically deployed on the same side as the agent. The method includes: obtaining a target access request sent by the agent; wherein the target access request is generated by the OT index and OT access request in the unintentional transport protocol OT access request sent by the client obtained by the server; in response to the target access request, determining at least two candidate access results; and feeding back each candidate access result to the agent so that the agent feeds back the target access result selected from each candidate access result to the client.

[0134] Of course, the computer-executable instructions provided in the embodiments of this application are not limited to the method operations described above, but can also perform related operations in the OT communication method provided in any embodiment of this application.

[0135] Based on the above description of the implementation methods, those skilled in the art can clearly understand that this application can be implemented using software and necessary general-purpose hardware, and of course, it can also be implemented using hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as a computer floppy disk, read-only memory (ROM), random access memory (RAM), flash memory, hard disk, or optical disk, etc., including several instructions to cause an electronic device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments of this application.

[0136] It is worth noting that in the embodiments of the search device described above, the various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of each functional unit are only for easy differentiation and are not used to limit the scope of protection of this application.

[0137] Note that the above are merely preferred embodiments and the technical principles employed in this application. Those skilled in the art will understand that this application is not limited to the specific embodiments described herein, and various obvious changes, readjustments, and substitutions can be made without departing from the scope of protection of this application. Therefore, although this application has been described in detail through the above embodiments, this application is not limited to the above embodiments, and may include many other equivalent embodiments without departing from the concept of this application, the scope of which is determined by the scope of the appended claims.

Claims

1. An OT communication method, characterized in that, A proxy terminal physically deployed on the server side, wherein the proxy terminal and the server communicate through various high-speed communication interfaces, the method comprising: Obtain the Unintentional Transport Protocol (OT) access request sent by the client, wherein the OT access request includes an OT index; Generate a target access request based on the OT index and the OT access request; Send the target access request to the server so that the server responds to the target access request, determines and returns at least two candidate access results; Select a target access result from the at least two candidate access results, and return the target access result to the client; The method further includes: Obtain at least two candidate public keys sent by the server; Accordingly, generating a target access request based on the OT index and the OT access request includes: The target public key is selected from each of the candidate public keys according to the OT index; The target random number is encrypted using the target public key to generate a target access request; the target random number is a random number generated by the proxy. The step of sending the target access request to the server causes the server to respond to the target access request and return at least two candidate access results, including: The target access request is sent to the server, so that the server decrypts the target access request according to the candidate private keys corresponding to the at least two candidate public keys, obtains each candidate random number, encrypts the corresponding candidate access result plaintext, and obtains and returns at least two candidate access result ciphertexts; wherein, the number of candidate public keys is the same as and corresponds to the number of candidate access result plaintexts; Accordingly, selecting the target access result from the at least two candidate access results includes: The candidate access result ciphertext corresponding to the OT index is decrypted according to the target random number to obtain the candidate access result plaintext corresponding to the decrypted candidate access result ciphertext, which is used as the target access result.

2. An OT communication method, characterized in that, The method, applied to a server physically deployed on the same side as the proxy, wherein the proxy and the server communicate via various high-speed communication interfaces, includes: Obtain the target access request sent by the proxy; wherein, the target access request is generated by the OT index in the unintentional transport protocol OT access request sent by the client obtained by the proxy and the OT access request; In response to the target access request, at least two candidate access results are determined; The agent sends each of the candidate access results back to the agent so that the agent can send the target access result selected from each of the candidate access results back to the client. The method further includes: Generate at least two public-private key pairs, including candidate public keys and corresponding candidate private keys, and send at least two candidate public keys to the agent. Accordingly, the target access request is obtained by the proxy end by encrypting the target random number based on the target random number and the target public key selected from each of the candidate public keys based on the OT index; the target random number is a random number generated by the proxy end. In response to the target access request, at least two candidate access results are determined, including: Based on each of the candidate private keys, the target access request is decrypted to obtain the corresponding candidate random number; Each candidate access result plaintext is encrypted according to the candidate random number to obtain at least two candidate access result ciphertexts; wherein the number of candidate public keys is the same as and corresponds to the number of candidate access result plaintexts; Accordingly, the step of feeding back each of the candidate access results to the proxy, so that the proxy will feed back the target access result selected from each of the candidate access results to the client, includes: The agent sends each of the candidate access results back to the agent so that the agent can decrypt the ciphertext of the candidate access result corresponding to the OT index according to the target random number, and send the decrypted candidate access result plaintext back to the client as the target access result.

3. An OT communication device, characterized in that, A proxy terminal configured and physically deployed on the server side, the proxy terminal and the server communicating through various high-speed communication interfaces, the device comprising: The access request acquisition module is used to acquire unintentional Transport Protocol (OT) access requests sent by the client, wherein the OT access request includes an OT index; The target access request generation module is used to generate a target access request based on the OT index and the OT access request; The target access request sending module is used to send the target access request to the server so that the server responds to the target access request, determines and returns at least two candidate access results; The result feedback module is used to select a target access result from the at least two candidate access results and feed the target access result back to the client. The device further includes: A candidate public key acquisition module is used to acquire at least two candidate public keys sent by the server; Accordingly, the target access request generation module includes: A target public key selection unit is configured to select a target public key from the candidate public keys according to the OT index; An OT request encryption unit is used to encrypt the target random number according to the target public key to generate a target access request; the target random number is a random number generated by the proxy. The target access request sending module includes: A target access request sending unit is configured to send the target access request to the server, so that the server, based on the candidate private keys corresponding to the at least two candidate public keys, decrypts the target access request to obtain each candidate random number, encrypts the corresponding candidate access result plaintext, and obtains and returns at least two candidate access result ciphertexts; wherein, the number of candidate public keys is the same as and corresponds to the number of candidate access result plaintexts; Correspondingly, the results feedback module includes: The result ciphertext decryption unit is used to decrypt the candidate access result ciphertext corresponding to the OT index according to the target random number, and obtain the candidate access result plaintext corresponding to the decrypted candidate access result ciphertext as the target access result.

4. An OT communication device, characterized in that, The device, configured on a server physically deployed on the same side as the proxy, wherein the proxy and the server communicate via various high-speed communication interfaces, includes: The target access request acquisition module is used to acquire the target access request sent by the proxy; wherein, the target access request is generated by the OT index in the unintentional transport protocol OT access request sent by the client and the OT access request obtained by the server. A candidate access result determination module is used to determine at least two candidate access results in response to the target access request; The candidate access result feedback module is used to feed back each of the candidate access results to the agent, so that the agent can feed back the target access result selected from each of the candidate access results to the client; The device further includes: A public-private key pair generation module is used to generate at least two public-private key pairs, including candidate public keys and corresponding candidate private keys, and send at least two candidate public keys to the agent. Accordingly, the target access request is obtained by the proxy end by encrypting the target random number based on the target random number and the target public key selected from each of the candidate public keys based on the OT index; the target random number is a random number generated by the proxy end. The candidate access result determination module includes: The access request decryption unit is used to decrypt the target access request according to each of the candidate private keys to obtain the corresponding candidate random number; The plaintext encryption unit for access results is used to encrypt the corresponding candidate access result plaintext according to each of the candidate random numbers to obtain at least two candidate access result ciphertexts; wherein the number of candidate public keys is the same as and corresponds to the number of candidate access result plaintexts; Accordingly, the candidate access result feedback module includes: The candidate access result sending unit is used to send each of the candidate access results back to the agent, so that the agent can decrypt the ciphertext of the candidate access result corresponding to the OT index according to the target random number, and send the decrypted candidate access result plaintext back to the client as the target access result.

5. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the OT communication method as described in claim 1; and / or implements the OT communication method as described in claim 2.

6. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements an OT communication method as described in claim 1; and / or implements an OT communication method as described in claim 2.