Encrypted query method, device, storage medium and apparatus
By selecting an adaptive encryption algorithm based on a preset query engine for data querying on the blockchain, the problems of low security and low query efficiency in blockchain data protection schemes are solved, achieving efficient protection of data privacy and flexible querying.
Patent Information
- Application Number
- CN202311049380.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-08-18
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2043-08-18
AI Technical Summary
Existing blockchain technologies suffer from poor security and low query efficiency in data protection solutions, particularly in terms of data privacy protection and complex query processing.
By obtaining query requests based on a preset query engine, selecting an appropriate encryption algorithm for encryption according to the data type, and querying on the blockchain, it supports the iterative use of multiple encryption algorithms to achieve adaptive encryption, ensuring data privacy and security as well as efficient querying.
It enhances the privacy and security of data on the blockchain, supports complex query processing operations, and improves query efficiency and data protection flexibility.
Smart Images

Figure CN117033466B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data processing, and particularly relates to an encrypted query method, device, storage medium and apparatus. BACKGROUND
[0002] At present, the blockchain technology has been widely applied, such as supply chain management, digital content right confirmation, large-scale data consensus between enterprises, etc. Although the blockchain technology is supported by modern cryptography algorithms, the data on the chain is stored in the form of plaintext, which sacrifices the privacy right of each participant although it gives the blockchain transparency. The existing on-chain data privacy protection scheme either directly uses a trusted hardware execution environment or directly uses a cryptography algorithm for encryption, the former is limited by the memory capacity of the trusted execution environment, which cannot be accessed on a large scale, and the latter is limited by the content of the ciphertext data, which cannot perform query operations, not to mention complex query processing.
[0003] The above content is only used to assist in understanding the technical solutions of the present application and does not represent the acknowledgement of the above content as prior art. SUMMARY
[0004] The main purpose of the present application is to provide an encrypted query method, device, storage medium and apparatus, which aims to solve the technical problems of poor security and low query efficiency caused by the defects of the existing data protection scheme on the blockchain.
[0005] To achieve the above purpose, the present application provides an encrypted query method, which comprises the following steps:
[0006] Obtaining a query request based on a preset query engine;
[0007] Selecting a target encryption algorithm from a preset comprehensive encryption algorithm according to the data type corresponding to the query request;
[0008] Encrypting the query request according to the target encryption algorithm, and querying the target data according to the encryption result.
[0009] Optionally, the step of selecting a target encryption algorithm from a preset comprehensive encryption algorithm according to the data type corresponding to the query request comprises:
[0010] If the data type corresponding to the plaintext data in the query request is a string type, a searchable encryption algorithm is selected as the target encryption algorithm from the preset comprehensive encryption algorithm;
[0011] If the data type corresponding to the plaintext data in the query request is an integer type or a floating-point number type, a deterministic encryption algorithm, a order-preserving encryption algorithm or an additive homomorphic encryption algorithm is selected as the target encryption algorithm from the preset comprehensive encryption algorithm.
[0012] Optionally, when the data type corresponding to the plaintext data in the query request is an integer type or a floating-point number type, the step of selecting a deterministic encryption algorithm, an order-preserving encryption algorithm or an additive homomorphic encryption algorithm as the target encryption algorithm from the preset comprehensive encryption algorithm, comprises:
[0013] When the data type corresponding to the plaintext data in the query request is an integer type or a floating-point number type, the query state type corresponding to the query request is obtained;
[0014] According to the query state type, a deterministic encryption algorithm, an order-preserving encryption algorithm or an additive homomorphic encryption algorithm is selected as the target encryption algorithm from the preset comprehensive encryption algorithm.
[0015] Optionally, the step of selecting a deterministic encryption algorithm, an order-preserving encryption algorithm or an additive homomorphic encryption algorithm as the target encryption algorithm from the preset comprehensive encryption algorithm according to the query state type, comprises:
[0016] If the query state type is an equality query, a deterministic encryption algorithm is selected as the target encryption algorithm from the preset comprehensive encryption algorithm;
[0017] If the query state type is an interval query or a sorting request, an order-preserving encryption algorithm is selected as the target encryption algorithm from the preset comprehensive encryption algorithm;
[0018] If the query state is an additive update or a multiplicative update, an additive homomorphic encryption algorithm is selected as the target encryption algorithm from the preset comprehensive encryption algorithm.
[0019] Optionally, the step of encrypting the query request according to the target encryption algorithm and querying the target data according to the encryption result, comprises:
[0020] The plaintext data in the query request is semantically segmented to obtain a segmentation result;
[0021] The redundant keywords in the segmentation result are screened, and the screened keywords are shuffled to obtain target keyword information;
[0022] The target keyword information is encrypted according to the searchable encryption algorithm and the preset random stream cipher encryption method, and the target data is queried according to the encryption result.
[0023] Optionally, the step of querying the target data according to the encryption result, comprises:
[0024] The target ciphertext data is obtained from the blockchain according to the encrypted ciphertext in the encryption result;
[0025] The target ciphertext data is decrypted to obtain the target data.
[0026] Optionally, the step of decrypting the target ciphertext data to obtain target data comprises:
[0027] decrypting the random number stream password and the target encryption algorithm contained in the target ciphertext data to obtain a decryption result;
[0028] determining the target data according to the decryption result.
[0029] In addition, to achieve the above object, the application further provides an encrypted query device, which comprises a memory, a processor, and an encrypted query program stored in the memory and executable on the processor, and the encrypted query program is configured to implement the steps of the encrypted query as described above.
[0030] In addition, to achieve the above object, the application further provides a storage medium, which stores an encrypted query program, and the encrypted query program implements the steps of the encrypted query method as described above when executed by a processor.
[0031] In addition, to achieve the above object, the application further provides an encrypted query device, which comprises:
[0032] a request acquisition module configured to acquire a query request based on a preset query engine;
[0033] an algorithm determination module configured to select a target encryption algorithm from preset comprehensive encryption algorithms according to a data type corresponding to the query request;
[0034] an encrypted query module configured to encrypt the query request according to the target encryption algorithm and query target data according to an encryption result.
[0035] The application acquires a query request based on a preset query engine, selects a target encryption algorithm from preset comprehensive encryption algorithms according to a data type corresponding to the query request, encrypts the query request according to the target encryption algorithm, and queries target data according to an encryption result. Compared with the protection limitation of the data protection scheme on the block chain in the prior art caused by imperfect hardware and algorithm encryption, the application enables the encrypted ciphertext data to support complex query processing operations, improves the security of user data privacy, and supports efficient query of on-chain ciphertext content. BRIEF DESCRIPTION OF DRAWINGS
[0036] Figure 1 is a structural schematic diagram of an encrypted query device of a hardware running environment related to the embodiment scheme of the application;
[0037] Figure 2A flowchart of the first embodiment of the encryption query method of the present application;
[0038] Figure 3 An architecture diagram of the on-chain encrypted data performing complex query processing for the first embodiment of the encryption query method of the present application;
[0039] Figure 4 A multi-layer encrypted data diagram for the first embodiment of the encryption query method of the present application;
[0040] Figure 5 A flowchart of the second embodiment of the encryption query method of the present application;
[0041] Figure 6 An encryption query flowchart for the second embodiment of the encryption query method of the present application;
[0042] Figure 7 A structure block diagram of the first embodiment of the encryption query device of the present application.
[0043] The implementation, functional features and advantages of the present application will be further described with reference to the embodiments and the accompanying drawings. DETAILED DESCRIPTION
[0044] It should be understood that the specific embodiments described herein are merely intended to explain the present application and not to limit the present application.
[0045] Reference Figure 1 , Figure 1 An encryption query device structure diagram of the hardware running environment involved in the embodiment scheme of the present application.
[0046] As Figure 1As shown, the encryption query device can include a processor 1001, such as a central processing unit (CPU), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. The communication bus 1002 is used to realize the connection communication between the components. The user interface 1003 can include a display screen (Display), and the optional user interface 1003 can further include a standard wired interface, a wireless interface. The wired interface of the user interface 1003 can be a USB interface in the present application. The network interface 1004 can optionally include a standard wired interface, a wireless interface (such as a wireless fidelity (Wireless-Fidelity, Wi-Fi) interface). The memory 1005 can be a high-speed random access memory (Random Access Memory, RAM), and can also be a stable memory (Non-volatile Memory, NVM), such as a disk memory. The memory 1005 can also be an independent storage device from the aforementioned processor 1001.
[0047] Those skilled in the art can understand that Figure 1 The structure shown in the figure does not constitute a limitation on the encryption query device, and can include more or fewer components than the figure, or combine certain components, or different component arrangements.
[0048] As Figure 1 As shown, the memory 1005, which is a computer storage medium, can include an operating system, a network communication module, a user interface module, and an encryption query program.
[0049] In Figure 1 As shown in the encryption query device, the network interface 1004 is mainly used to connect the background server and communicate data with the background server; the user interface 1003 is mainly used to connect the user equipment; the encryption query device calls the encryption query program stored in the memory 1005 through the processor 1001, and executes the encryption query method provided by the embodiment of the present application.
[0050] Based on the above hardware structure, an embodiment of the encryption query method of the present application is proposed.
[0051] Referring to Figure 2 , Figure 2 The flowchart of the first embodiment of the encryption query method of the present application is proposed.
[0052] In this embodiment, the encryption query method includes the following steps:
[0053] Step S10: obtaining a query request based on a preset query engine.
[0054] It should be noted that the execution subject in the embodiment can be a device including a data encryption query system composed of a blockchain and a query agent (query engine), such as a computer, a tablet, a mobile phone, or a notebook, and can also be other devices that can achieve the same or similar functions, and the embodiment does not limit this. In the embodiment and the following embodiments, the encryption query method of the application is described by taking a computer as an example.
[0055] It should be understood that the preset query engine can be a program set in advance for querying, wherein the scheme is composed of two parts of the query agent and the blockchain. Each node runs the query agent in addition to participating in the blockchain consensus. The request from the client is processed by the query agent. Under the assumption that any one of the consensus nodes is a malicious adversary, i.e., they may try to obtain private data as much as possible by not complying with the protocol, this security assumption meets the real demand. For example, the nodes are run by participants who do not trust each other and have conflicts of interest. They have a strong incentive to sniff the private data of the other party. Under this adversary assumption, the application can guarantee the security of the data on the chain. Thanks to the consensus mechanism, the blockchain technology can operate normally in the presence of no more than half of the malicious nodes in the network. Therefore, the security of the blockchain part does not need to be paid special attention to, and only the security of the query agent needs to be ensured. The method of the application ensures the confidentiality and integrity of the data by placing the query agent in the hardware trusted execution environment for running. For details, refer to the architecture diagram of the chain encryption data shown in FIG. 1 for performing complex query processing. Figure 3
[0056] It can be understood that the query request can be a query request instruction issued by the user. In the plaintext space, the user sends the content to be queried to the blockchain server. Then, the server searches according to the data, and finally returns the search result to the user. Since the user data and the query are stored in the form of plaintext on the blockchain server, the user data and the query related information will be leaked. In order to protect the privacy of the data, the user selects to encrypt the data before uploading it to the blockchain for storage and calculation.
[0057] Step S20: selecting a target encryption algorithm from the preset comprehensive encryption algorithm according to the data type corresponding to the query request.
[0058] It should be noted that the data type corresponding to the query request can be a constant data type in the content to be queried in the query request. The constant data type can be an integer type, a string type, or a floating-point number type. Compared with the traditional encryption method which destroys the order information of the original plaintext data so that the retrieval in the ciphertext space cannot be realized, the scheme can meet more scene query processing operations of the data in the ciphertext by adaptive encryption.
[0059] It can be understood that the preset comprehensive encryption algorithm can be an encryption algorithm corresponding to various data types, wherein the preset comprehensive encryption algorithm contains the correspondence between the data types and the encryption algorithms, and the preset comprehensive encryption algorithm includes searchable encryption, deterministic encryption, order-preserving encryption, additive homomorphic encryption, etc.
[0060] It should be understood that in the present application, the user as a data holder has a corresponding key, the query agent is run by a consensus node, and the encrypted data is saved in the form of a blockchain. It is assumed that the plaintext data is divided into string type, integer type and floating point type. The string type data is encrypted using a searchable encryption algorithm, and the integer type and floating point type data are encrypted using an order-preserving encryption algorithm and a deterministic encryption algorithm.
[0061] In a specific implementation, the target encryption algorithm is selected from the encryption algorithms such as searchable encryption, deterministic encryption, order-preserving encryption, and additive homomorphic encryption by determining the data type contained in the to-be-queried content in the query request, so as to encrypt the query request.
[0062] Step S30: encrypting the query request according to the target encryption algorithm, and querying the target data according to the encryption result.
[0063] It should be noted that the query request is encrypted by the target encryption algorithm to generate first ciphertext data, and the target ciphertext data is queried on the blockchain through the first ciphertext data, so as to determine the target data through the target ciphertext data.
[0064] It can be understood that the data stored on the blockchain is all encrypted ciphertext data. In the present scheme, the query request is encrypted and matched with the ciphertext data stored on the blockchain to obtain matched ciphertext data, and the matched ciphertext data is fed back to the local for decryption to obtain the decrypted target data.
[0065] Further, the step of querying the target data according to the encryption result comprises: obtaining the target ciphertext data from the blockchain according to the encrypted ciphertext in the encryption result; and decrypting the target ciphertext data to obtain the target data.
[0066] It should be noted that the target ciphertext data is obtained from the blockchain according to the key corresponding to the ciphertext data in the encryption result. The main idea in the present scheme is to save one or more ciphertext data on the blockchain. Such ciphertext data is iteratively encrypted by multiple encryption algorithms, and the corresponding encryption layer of the specified ciphertext data is dynamically selected according to the difference of the query request to achieve adaptability.
[0067] It can be understood that by matching the first ciphertext data after encrypting the query request with the multiple types of ciphertext data stored on the blockchain, the target ciphertext data is determined according to the matching result, and the target data is obtained by decrypting the target ciphertext data locally.
[0068] Further, the step of decrypting the target ciphertext data to obtain target data includes: decrypting the random number stream password and the target encryption algorithm contained in the target ciphertext data to obtain a decryption result; and determining the target data according to the decryption result.
[0069] It should be noted that the ciphertext data stored on the blockchain is multi-layer ciphertext data generated by encrypting multiple encryption algorithms and then encrypting with a random number stream password.
[0070] It can be understood that in the decryption process, the random number stream password is decrypted first, and then the encryption algorithm is decrypted to obtain the plaintext data.
[0071] In a specific implementation, reference can be made to the multi-layer ciphertext data diagram generated by iterative use of the multiple encryption algorithms shown in Figure 4 It is shown that the multi-layer ciphertext data used for adaptive encryption is shown, and in the process of processing the query request, since the query is strictly ordered, the performance impact caused by encrypting the data each time is considered, therefore, the present application adopts the method of storing multiple multi-layer ciphertext data on the chain, and only the corresponding ciphertext data needs to be decrypted when processing a specific query. Therefore, when encrypting the query request, the plaintext data is first encrypted by a comprehensive encryption algorithm and then encrypted by a random number stream password, so when decrypting, the random number stream password is decrypted first, and then the comprehensive encryption algorithm is decrypted to obtain the plaintext data.
[0072] The present embodiment obtains a query request based on a preset query engine; selects a target encryption algorithm from a preset comprehensive encryption algorithm according to the data type corresponding to the query request; encrypts the query request according to the target encryption algorithm, and queries target data according to the encryption result. Compared with the protection limitations caused by imperfect hardware and algorithm encryption in the prior art data protection scheme on the blockchain, the present embodiment performs adaptive encryption on the on-chain data, so that the encrypted ciphertext data supports complex query processing operations, improves the security of user data privacy, and supports efficient query of on-chain ciphertext content.
[0073] Referring to Figure 5 , Figure 5 is a flowchart of the encryption query method of the second embodiment of the present application, based on the first embodiment shown in Figure 2 The second embodiment of the encryption query method of the present application is proposed based on the first embodiment shown in
[0074] In the embodiment, the step S20 comprises:
[0075] Step S201: if the data type corresponding to the plaintext data in the query request is a string type, selecting a searchable encryption algorithm as a target encryption algorithm from a preset comprehensive encryption algorithm.
[0076] It should be noted that the searchable encryption algorithm can be an algorithm preset for encrypting data of the string type. The encryption process is to encrypt the plaintext data by a symmetric key cryptographic algorithm and a first key, and generate a random number by a pseudo-random number generation algorithm combined with a second key, wherein the first key is a private key held by the client, and the second key is a public key held by the client and the consensus node.
[0077] It can be understood that when the plaintext data type in the query request to be encrypted is a string type data, the searchable encryption algorithm is selected as the target encryption algorithm, and the plaintext data is encrypted by combining the pseudo-random number generation algorithm, so as to obtain the ciphertext data, so as to facilitate the matching of the ciphertext data (ciphertext) on the blockchain in the later period. The ciphertext can be ciphertext data generated according to the keyword.
[0078] Further, when encrypting the data of the string type, the plaintext data in the query request is subjected to semantic segmentation to obtain a segmentation result; redundant keywords in the segmentation result are screened, and the screened keywords are shuffled to obtain target keyword information; the target keyword information is encrypted according to the searchable encryption algorithm and a preset random number stream cipher encryption method, and the target data is queried according to the encryption result.
[0079] It should be noted that the segmentation result can be that the string contained in the plaintext data is segmented into multiple keywords, the segmentation result contains multiple keywords, the remaining keywords are obtained by screening and removing the redundant keywords in the segmentation result, and the order of the remaining keywords is shuffled. The target keyword information after shuffling is encrypted by the searchable encryption algorithm and the preset random number stream cipher encryption method, and the target data is queried according to the encryption result.
[0080] It should be understood that the present application uses searchable encryption technology to realize keyword search on ciphertext data. First, the string is divided into multiple keywords by semantic segmentation, the redundant keywords are deleted, and then the order of each keyword is shuffled. Then, all the keywords are filled to a fixed length by adding zeros at the end. Finally, the keywords are encrypted by the searchable encryption technology, Figure 6 is a schematic diagram of the searchable encryption technology process, k a held by the data owner, k bHeld by the encryption party and the query party, the user as the data holder encrypts the data, and when the query party queries the keyword W, it is in turn with each ciphertext C i The exclusive or operation is performed to obtain Next, it is determined whether the following condition is established: If yes, it indicates that the keyword exists.
[0081] It can be understood that, to further illustrate the execution process of the searchable encryption algorithm, reference can be made to the searchable encryption algorithm process schematic diagram shown in Figure 6 When the client newly writes a plaintext string data, the string is first segmented into multiple keywords according to semantics, and the segmentation method can also be specified by the user. If the string itself is a keyword, segmentation is not required. The segmented keywords are de-duplicated and shuffled. Since the segmented keywords have different lengths, each keyword needs to be padded to a fixed length. For the convenience of subsequent description, the fixed length is denoted as n, and each padded keyword is denoted as W i . E(·) is a symmetric key cipher algorithm, and E sk (x) represents that the plaintext p is encrypted using the algorithm E(·) and the key sk. F(·) is a secure pseudo-random number generation algorithm, i.e., a pre-set random number stream cipher encryption algorithm, and F pk (x) represents that a random number is generated using the seed x and the key pk, wherein sk is a private key held by the client, and pk is a public key held by the client and the consensus node. The client calculates X i i = E sk (W i ), and then divides X i of length n into two parts, denoted as L i of length n-m and R i of length m. Then, the sub-key k i = F i (L pk ) is obtained by using the random number generation algorithm with L i as the seed. Next, the client generates a string Si of length n-m using another random number generator, and calculates the ciphertext C of length m using the sub-key ki as the key. Finally, the ciphertext C is obtained. Finally, the consensus node stores C i in the blockchain.
[0082] In a specific implementation, when the client queries the keyword W t on the ciphertext data, it sends X t to the consensus node, and the consensus node calculates each ciphertext C i in turn and X t XOR value gets <SL i , SR i > and then determines whether SR i = F pk (SL i ) is true, if true, it means that the keyword matching is successful, otherwise, the matching fails. When the matching is successful, the target ciphertext data is extracted from the chain data, and the target ciphertext data is decrypted to obtain the target data.
[0083] Step S202: If the data type corresponding to the plaintext data in the query request is an integer type or a floating-point number type, select a deterministic encryption algorithm, a order-preserving encryption algorithm or an additive homomorphic encryption algorithm from a preset comprehensive encryption algorithm as a target encryption algorithm.
[0084] It should be noted that the deterministic encryption algorithm can be an encryption algorithm pre-set for integer type data, wherein the deterministic encryption algorithm Dec(K, Enc(K, m)) = m is true for any plaintext m and key K, and the same (m, K) corresponds to the same ciphertext. Such an encryption algorithm is called deterministic algorithm encryption, and the key K is held by the client. Each time the plaintext integer type data is written, the key and the deterministic encryption algorithm are used for encryption. In addition, for the homomorphic encryption algorithm, the Paillier encryption algorithm is used to realize the additive homomorphism, and the RSA encryption algorithm is used to realize the multiplicative homomorphism.
[0085] It can be understood that for the order-preserving encryption algorithm, it has been theoretically proved that if the ciphertext is stateless, the linear length order-preserving encryption scheme cannot achieve the ideal security of IND-OCPA (indistinguishability under ordered chosen plaintext attack), that is, it does not leak any plaintext information except the order of the plaintext. Therefore, the present application adopts a slightly weaker security definition than the ideal security: ROPF (random order preserving function), which is formally described as follows: the order-preserving encryption scheme Π = (Gen, Enc, Query, Dec) has a plaintext space D and a ciphertext space R, and satisfies |D| ≤ |R|, and the scheme Π is considered to be ROPF secure. The following gives an implementation of ROPF, wherein f: A→B is an order-preserving function, that is, for any i, j∈A, f(i) > f(j) and i > j.
[0086] In a specific implementation, in order to illustrate the processing process of the order-preserving encryption algorithm and the processing process of the decryption algorithm, refer to Table 1 order-preserving encryption algorithm and Table 2 decryption algorithm;
[0087] Table 1 Order-preserving encryption algorithm
[0088]
[0089]
[0090] Table 2 decryption algorithm
[0091]
[0092] Further, the step S202 further comprises: if the data type corresponding to the plaintext data in the query request is an integer type or a floating-point number type, obtaining a query state type corresponding to the query request; and selecting a deterministic encryption algorithm, an order-preserving encryption algorithm or an additive homomorphic encryption algorithm from the preset comprehensive encryption algorithm as a target encryption algorithm according to the query state type.
[0093] It should be noted that the floating-point number type can refer to a data type in which the position of the decimal point of a number is not fixed but can float, and the floating-point number can be used to represent a real number. Compared with a fixed-point number, the floating-point number can flexibly express a larger range of real numbers by floating the position of the exponential decimal point up and down as needed.
[0094] It can be understood that the query state type can be for a query instruction type contained in the query content, and the query instruction type can include an equal value query, an interval query, data sorting, keyword search and the like. Different encryption algorithms are used for different query instruction types. In the present scheme, by combining the query state type and the data type corresponding to the query request, more accurate data encryption query can be achieved.
[0095] Further, the step of selecting a deterministic encryption algorithm, an order-preserving encryption algorithm or an additive homomorphic encryption algorithm from the preset comprehensive encryption algorithm as a target encryption algorithm according to the query state type comprises: if the query state type is an equal value query, selecting a deterministic encryption algorithm from the preset comprehensive encryption algorithm as the target encryption algorithm; if the query state type is an interval query or a sorting request, selecting an order-preserving encryption algorithm from the preset comprehensive encryption algorithm as the target encryption algorithm; and if the query state is an additive update or a multiplicative update, selecting an additive homomorphic encryption algorithm from the preset comprehensive encryption algorithm as the target encryption algorithm.
[0096] It should be noted that the adaptive encryption scheme integrating multiple encryption algorithms is the core content of the present application, and the highest security of the ciphertext data is sought under the condition of meeting the current query request. In the state without query request, the highest security of the one-time random number stream cipher encryption algorithm is used, in the state of equivalent query request, the deterministic encryption algorithm is used, and in the state of interval query or sorting request, the order-preserving encryption algorithm is used. Since the type of query request cannot be known in advance, the main idea of the adaptive encryption scheme is to save one or more ciphertext data on the blockchain, and such ciphertext data is iteratively encrypted by multiple encryption algorithms, and the corresponding encryption layer of the specified ciphertext data is dynamically selected according to the different query requests to realize adaptability.
[0097] In a specific implementation, once the query agent receives the query request, it encrypts the constant in the query request with the corresponding encryption method. For example, if the query contains WHERE Age=32, the agent uses the deterministic encryption algorithm to encrypt 32; if the query contains WHERE Age>32, the agent uses the order-preserving encryption algorithm to encrypt 32; if the query contains UPDATE Age=Age+10, the agent uses the additive homomorphic encryption algorithm to encrypt 10; and then replaces 32 with the obtained ciphertext.
[0098] The embodiment based on a preset query engine acquires a query request; selects a target encryption algorithm from preset comprehensive encryption algorithms according to a data type corresponding to the query request; encrypts the query request according to the target encryption algorithm, and queries target data according to an encryption result. Compared with the protection limitation of the data protection scheme on the blockchain in the prior art caused by imperfect hardware and algorithm encryption, the embodiment executes adaptive encryption on on-chain data, so that the encrypted ciphertext data supports complex query processing operations, improves user data privacy security, and supports efficient query of on-chain ciphertext content.
[0099] In addition, to achieve the above object, the present application also proposes a storage medium, wherein the storage medium stores an encryption query program, and the encryption query program realizes the steps of the encryption query method when executed by a processor.
[0100] Reference Figure 7 , Figure 7 The structure block diagram of the first embodiment of the encryption query device of the present application is shown in the figure.
[0101] As Figure 7 shown, the encryption query device proposed by the embodiment of the present application comprises:
[0102] The request acquisition module 10 is configured to acquire a query request based on a preset query engine.
[0103] The algorithm determination module 20 is configured to select a target encryption algorithm from preset comprehensive encryption algorithms according to a data type corresponding to the query request.
[0104] The encrypted query module 30 is configured to encrypt the query request according to the target encryption algorithm and query target data according to an encryption result.
[0105] In the embodiment, a query request is obtained based on a preset query engine, a target encryption algorithm is selected from preset comprehensive encryption algorithms according to a data type corresponding to the query request, the query request is encrypted according to the target encryption algorithm, and target data is queried according to an encryption result. Compared with the protection limitation of a data protection scheme on a block chain in the prior art caused by imperfect hardware and algorithm encryption, the embodiment enables adaptive encryption of on-chain data, enables encrypted ciphertext data to support complex query processing operations, improves user data privacy security, and supports efficient query of on-chain ciphertext content.
[0106] Further, the algorithm determination module 20 is further configured to select a searchable encryption algorithm as the target encryption algorithm from the preset comprehensive encryption algorithms if the data type corresponding to the plaintext data in the query request is a string type, and select a deterministic encryption algorithm, an order-preserving encryption algorithm or an additive homomorphic encryption algorithm as the target encryption algorithm if the data type corresponding to the plaintext data in the query request is an integer type or a floating-point number type.
[0107] Further, the algorithm determination module 20 is further configured to obtain a query state type corresponding to the query request if the data type corresponding to the plaintext data in the query request is an integer type or a floating-point number type, and select a deterministic encryption algorithm, an order-preserving encryption algorithm or an additive homomorphic encryption algorithm as the target encryption algorithm according to the query state type.
[0108] Further, the algorithm determination module 20 is further configured to select a deterministic encryption algorithm as the target encryption algorithm from the preset comprehensive encryption algorithms if the query state type is an equal value query, select an order-preserving encryption algorithm as the target encryption algorithm from the preset comprehensive encryption algorithms if the query state type is an interval query or a sorting request, and select an additive homomorphic encryption algorithm as the target encryption algorithm from the preset comprehensive encryption algorithms if the query state is an additive update or a multiplicative update.
[0109] Further, the encryption query module 30 is further configured to perform semantic segmentation on the plaintext data in the query request to obtain a segmentation result, filter redundant keywords in the segmentation result, and scramble the filtered keywords to obtain target keyword information, encrypt the target keyword information according to a searchable encryption algorithm and a preset random stream cipher encryption method, and query target data according to an encryption result.
[0110] Further, the encryption query module 30 is further configured to obtain target ciphertext data from the blockchain according to the encrypted ciphertext in the encryption result, decrypt the target ciphertext data to obtain target data.
[0111] Further, the encryption query module 30 is further configured to decrypt the random stream cipher and the target encryption algorithm contained in the target ciphertext data to obtain a decryption result, and determine the target data according to the decryption result.
[0112] It should be understood that the above is only an example, and does not constitute any limitation on the technical solutions of the present application. In specific applications, those skilled in the art can set it up according to the needs, and the present application does not limit this.
[0113] It should be noted that the above-described workflow is only illustrative and does not limit the scope of protection of the present application. In actual application, those skilled in the art can select part or all of them to achieve the purpose of the embodiment scheme according to actual needs, which is not limited here.
[0114] In addition, technical details not described in detail in this embodiment can be referred to the encryption query method provided by any embodiment of the present application, which will not be repeated here.
[0115] It should be noted that in this document, the terms "include", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or system including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or system. Without more limitations, the element defined by the statement "including a" does not exclude the presence of another identical element in the process, method, article or system including the element.
[0116] The above embodiment numbers of the present application are only for description, and do not represent the advantages and disadvantages of the embodiments. In the unit claims of several devices, several of these devices can be embodied by the same hardware item. The use of the words first, second, and third does not represent any order, and these words can be interpreted as names.
[0117] Those skilled in the art can clearly understand the above-mentioned embodiment method can be realized by means of software and the necessary general hardware platform, of course, can also be realized by hardware, but in many cases, the former is a better embodiment. Based on such understanding, the technical solutions of the present application essentially or say the part of the prior art contribution can be embodied in the form of a software product, which is stored in a storage medium (such as a read-only memory image (Read Only Memory image, ROM) / random access memory (Random Access Memory, RAM), a magnetic disk, an optical disk), including a plurality of instructions for making a terminal device (which can be a mobile phone, a computer, a server, or a network device, etc.) execute the method described in various embodiments of the present application.
[0118] The above is only the preferred embodiment of the present application, and does not limit the patent scope of the present application, and any equivalent structure or equivalent process transformation using the content of the present application specification and drawings, or directly or indirectly applied to other related technical fields, are also included in the patent protection scope of the present application.
Claims
1. A method of encrypting a query, the method comprising: The encryption query method comprises the following steps: obtaining a query request based on a preset query engine; selecting a target encryption algorithm from preset comprehensive encryption algorithms according to a data type corresponding to the query request; encrypting the query request according to the target encryption algorithm and querying target data according to an encryption result; the step of selecting the target encryption algorithm from the preset comprehensive encryption algorithms according to the data type corresponding to the query request comprises: if the data type corresponding to the plaintext data in the query request is a string type, selecting a searchable encryption algorithm from the preset comprehensive encryption algorithms as the target encryption algorithm; if the data type corresponding to the plaintext data in the query request is an integer type or a floating-point number type, selecting a deterministic encryption algorithm, a sorted encryption algorithm or an additive homomorphic encryption algorithm from the preset comprehensive encryption algorithms as the target encryption algorithm; the step of querying the target data according to the encryption result comprises: obtaining target ciphertext data from a blockchain according to the encryption ciphertext in the encryption result; decrypting the target ciphertext data to obtain target data.
2. The encrypted query method as described in claim 1, characterized in that, the step of selecting the deterministic encryption algorithm, the sorted encryption algorithm or the additive homomorphic encryption algorithm from the preset comprehensive encryption algorithms as the target encryption algorithm if the data type corresponding to the plaintext data in the query request is the integer type or the floating-point number type comprises: if the data type corresponding to the plaintext data in the query request is the integer type or the floating-point number type, obtaining a query state type corresponding to the query request; selecting the deterministic encryption algorithm, the sorted encryption algorithm or the additive homomorphic encryption algorithm from the preset comprehensive encryption algorithms as the target encryption algorithm according to the query state type.
3. The encrypted query method as described in claim 2, characterized in that, the step of selecting the deterministic encryption algorithm, the sorted encryption algorithm or the additive homomorphic encryption algorithm from the preset comprehensive encryption algorithms as the target encryption algorithm according to the query state type comprises: if the query state type is an equal value query, selecting the deterministic encryption algorithm from the preset comprehensive encryption algorithms as the target encryption algorithm; if the query state type is an interval query or a sorting request, selecting the sorted encryption algorithm from the preset comprehensive encryption algorithms as the target encryption algorithm; if the query state is an additive update or a multiplicative update, selecting the additive homomorphic encryption algorithm from the preset comprehensive encryption algorithms as the target encryption algorithm.
4. The method of encrypting a query of claim 1, wherein, the step of encrypting the query request according to the target encryption algorithm and querying the target data according to the encryption result comprises: if the data type corresponding to the plaintext data in the query request is the string type, performing semantic segmentation on the plaintext data in the query request to obtain a segmentation result; screening redundant keywords in the segmentation result and scrambling the screened keywords to obtain target keyword information; encrypting the target keyword information according to the searchable encryption algorithm and a preset random stream password encryption method and querying the target data according to an encryption result.
5. The method of encrypting a query of claim 1, wherein, the step of decrypting the target ciphertext data to obtain the target data comprises: decrypting a random stream password and the target encryption algorithm contained in the target ciphertext data to obtain a decryption result; Determine target data according to the decryption result.
6. An encrypted query device, characterized by The encrypted query device comprises a memory, a processor, and an encrypted query program stored on the memory and executable on the processor, and the encrypted query program, when executed by the processor, implements the encrypted query method according to any one of claims 1 to 5.
7. A storage medium, characterized by The storage medium stores an encrypted query program, and the encrypted query program, when executed by the processor, implements the encrypted query method according to any one of claims 1 to 5.
8. An encrypted query apparatus, characterized by comprising: The encrypted query device comprises: The request acquisition module is configured to acquire a query request based on a preset query engine. The algorithm determination module is configured to select a target encryption algorithm from preset comprehensive encryption algorithms according to a data type corresponding to the query request. The encrypted query module is configured to encrypt the query request according to the target encryption algorithm, and query target data according to an encryption result. The step of selecting the target encryption algorithm from the preset comprehensive encryption algorithms according to the data type corresponding to the query request comprises: If the data type corresponding to the plaintext data in the query request is a string type, a searchable encryption algorithm is selected as the target encryption algorithm from the preset comprehensive encryption algorithms. If the data type corresponding to the plaintext data in the query request is an integer type or a floating-point number type, a deterministic encryption algorithm, an order-preserving encryption algorithm, or an additive homomorphic encryption algorithm is selected as the target encryption algorithm from the preset comprehensive encryption algorithms. The step of querying the target data according to the encryption result comprises: Acquiring target ciphertext data from a blockchain according to the encryption ciphertext in the encryption result. Decrypting the target ciphertext data to obtain target data.
Citation Information
Patent Citations
Encrypted database construction method and device, medium and equipment
CN114253943A
Data management method and system based on block chain and homomorphic encryption
CN116303263A