Data processing method and device, equipment and storage medium

By applying homomorphic encryption and pseudo-random function processing to the query data from the data querying party, combined with ciphertext computation, the problem of low data security during data interaction is solved, achieving secure protection and data flow for both the data provider and the querying party.

CN119150313BActive Publication Date: 2025-11-04CHINA UNIONPAY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411148819.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-20
Publication Date
2025-11-04
Estimated Expiration
2044-08-20

AI Technical Summary

Technical Problem

During data interaction, both data providers and data queryers face low data security and a high risk of data leakage. Queryed information can be maliciously used by dishonest data providers, leading to damage to information security.

Method used

Homomorphic encryption and pseudo-random functions are used to perform multi-level encryption on the query data of the data query party, and ciphertext calculation is performed between the data provider and the query party to ensure data security during the data exchange process.

Benefits of technology

It achieves data security protection for both data providers and queryers, avoids data leakage, ensures the privacy of data queryers is not compromised, realizes data usability without visibility, and promotes data flow and secure interaction.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119150313B_ABST
    Figure CN119150313B_ABST
Patent Text Reader

Abstract

The application discloses a data processing method and device, equipment and a storage medium. The application belongs to the technical field of data processing. The method comprises the following steps: receiving first mapping encrypted data sent by a data querying party, wherein the first mapping encrypted data is data obtained by processing first encrypted querying data of the data querying party by using a hash mapping algorithm, and the first encrypted querying data is data obtained by processing non-plain querying data by using homomorphic encryption and a pseudo-random function; matching the first mapping encrypted data with second mapping encrypted data in each data storage space of N data storage spaces to obtain N matching results; and constructing N querying feedback results for determining querying label data and sending to the data querying party according to the matching results, corresponding encrypted querying data and encrypted label data. In this way, ciphertext processing is adopted throughout the interaction process, the data availability and invisibility of the data querying party and the data providing party are ensured, and the data security of the interaction of the two parties is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application belongs to the technical field of data processing, and particularly relates to a data processing method and device, equipment and a storage medium. BACKGROUND

[0002] With the continuous development of digital economy, data has become a key production factor, and data usage requires data to flow among each other to avoid data silos. Therefore, how to ensure data security while realizing effective data flow has become a topic of concern.

[0003] In related technologies, the data provider usually stores data in plaintext, and when the data query party requests data from the data provider, the data query party also provides data in plaintext. However, these data may include sensitive data, and if the data provider operates improperly, there is a risk of data leakage. For the data query party, when requesting data, the query information of the data query party is leaked to the data provider, which is easily maliciously used by dishonest data providers, causing damage to the information security of the query party. SUMMARY

[0004] The embodiments of the present application provide a data processing method, device, equipment and storage medium, which can solve the problem of low data security of the data provider and the data query party in the data interaction process in related technologies.

[0005] In a first aspect, the embodiments of the present application provide a data processing method applied to a data provider, which can include:

[0006] receiving a query request sent by a data query party, the query request carrying first mapping encrypted data, the first mapping encrypted data being data obtained by processing first encrypted query data of the data query party by a first hash mapping algorithm, the first encrypted query data being data obtained by processing non-plaintext query data of the data query party by a homomorphic encryption and a pseudo-random function, the query request being used to request the data provider to query query label data of the non-plaintext query data;

[0007] matching the first mapping encrypted data with second mapping encrypted data in each data storage space of N data storage spaces to obtain N matching results; wherein the second mapping encrypted data in an i-th data storage space of the N data storage spaces is data obtained by processing second encrypted query data of the data query party by a j-th hash mapping algorithm of N hash mapping algorithms, the second encrypted query data being data obtained by processing preset non-plaintext query data of the data provider by the homomorphic encryption and the pseudo-random function, the N hash mapping algorithms including the first hash mapping algorithm;

[0008] According to each of the N matching results, third encrypted query data corresponding to each of the N matching results, and encrypted tag data of the third encrypted query data, N query feedback results are constructed.

[0009] The N query feedback results are sent to the data query party, and the N query feedback results are used to determine the query tag data.

[0010] In a second aspect, an embodiment of the present application provides a data processing method, applied to a data query party, which can include:

[0011] A query request is sent to a data provider, the query request carrying first mapping encrypted data, the first mapping encrypted data being data obtained by processing first encrypted query data of the data query party by using a first hash mapping algorithm, the first encrypted query data being data obtained by processing non-plaintext query data of the data query party by using homomorphic encryption and a pseudo-random function, and the query request being used to request the data provider to query query tag data of the non-plaintext query data;

[0012] N query feedback results sent by the data query party are received, the N query feedback results being determined according to N matching results, third encrypted query data corresponding to each of the N matching results, and encrypted tag data of the third encrypted query data, the N matching results being obtained by matching the first mapping encrypted data with second mapping encrypted data in each of N data storage spaces, the second mapping encrypted data in an i th data storage space of the N data storage spaces being data obtained by processing second encrypted query data of the data query party by using a j th hash mapping algorithm of N hash mapping algorithms, the second encrypted query data being data obtained by processing preset non-plaintext query data of the data provider by using homomorphic encryption and a pseudo-random function, and the N hash mapping algorithms including the first hash mapping algorithm;

[0013] The query tag data is determined according to a decryption result of the N query feedback results.

[0014] In a third aspect, an embodiment of the present application provides a data processing apparatus, applied to a data provider, which can include:

[0015] A receiving module is configured to receive a query request sent by a data query party, the query request carrying first mapping encrypted data, the first mapping encrypted data being data obtained by processing first encrypted query data of the data query party by using a first hash mapping algorithm, the first encrypted query data being data obtained by processing non-plaintext query data of the data query party by using homomorphic encryption and a pseudo-random function, and the query request being used to request the data provider to query query tag data of the non-plaintext query data;

[0016] The matching module is configured to match the first mapping encrypted data with second mapping encrypted data in each data storage space of the N data storage spaces to obtain N matching results; wherein the second mapping encrypted data in the i th data storage space of the N data storage spaces is data obtained by processing second encrypted query data of the data querying party by a j th hash mapping algorithm in the N hash mapping algorithms, the second encrypted query data is data obtained by processing preset non-plaintext query data of the data providing party by homomorphic encryption and a pseudo-random function, and the N hash mapping algorithms include the first hash mapping algorithm;

[0017] The constructing module is configured to construct N query feedback results according to each of the N matching results, third encrypted query data corresponding to each of the N matching results, and an encrypted label of the third encrypted query data.

[0018] The sending module is configured to send the N query feedback results to the data querying party, and the N query feedback results are used to determine the query label data.

[0019] In a fourth aspect, an embodiment of the present application provides a data processing apparatus applied to a data querying party, which can include:

[0020] The sending module is configured to send a query request to the data providing party, the query request carrying first mapping encrypted data, the first mapping encrypted data being data obtained by processing first encrypted query data of the data querying party by a first hash mapping algorithm, the first encrypted query data being data obtained by processing non-plaintext query data of the data querying party by homomorphic encryption and a pseudo-random function, and the query request being used to request the data providing party to query query label data of the non-plaintext query data.

[0021] The receiving module is configured to receive N query feedback results sent by the data querying party, the N query feedback results being determined by N matching results, third encrypted query data corresponding to each of the N matching results, and an encrypted label of the third encrypted query data, the N matching results being obtained by matching the first mapping encrypted data with second mapping encrypted data in each data storage space of the N data storage spaces, the second mapping encrypted data in the i th data storage space of the N data storage spaces being data obtained by processing second encrypted query data of the data querying party by a j th hash mapping algorithm in the N hash mapping algorithms, the second encrypted query data being data obtained by processing preset non-plaintext query data of the data providing party by homomorphic encryption and a pseudo-random function, and the N hash mapping algorithms including the first hash mapping algorithm.

[0022] The determining module is configured to determine the query label data according to a decryption result of the N query feedback results.

[0023] In a fifth aspect, an embodiment of the present application provides a computer device, comprising a processor and a memory having stored computer program instructions;

[0024] The processor executes the computer program instructions to implement the data processing method as shown in the first aspect or the data processing method as shown in the second aspect.

[0025] In a sixth aspect, an embodiment of the present application provides a computer storage medium having stored computer program instructions, which, when executed by a processor, implement the data processing method as shown in the first aspect or the data processing method as shown in the second aspect.

[0026] In a seventh aspect, an embodiment of the present application provides a chip, comprising a processor and a communication interface, the communication interface being coupled to the processor, the processor being configured to run programs or instructions to implement the data processing method as shown in the first aspect or the data processing method as shown in the second aspect.

[0027] In an eighth aspect, an embodiment of the present application provides a computer program product stored in a storage medium, which is executed by at least one processor to implement the data processing method as shown in the first aspect or the data processing method as shown in the second aspect.

[0028] The data processing method, device, equipment and storage medium of the embodiments of the present application receive a query request sent by a data querying party, the query request carrying first mapping encrypted data, the first mapping encrypted data being data obtained by processing first encrypted query data of the data querying party by a first hash mapping algorithm, the first encrypted query data being data obtained by processing non-plain query data of the data querying party by homomorphic encryption and a pseudo-random function, the query request being used to request a data providing party to query query label data of the non-plain query data; the first mapping encrypted data is matched with second mapping encrypted data in each data storage space of N data storage spaces to obtain N matching results; the second mapping encrypted data in the i th data storage space of the N data storage spaces is data obtained by processing second encrypted query data of the data querying party by a j th hash mapping algorithm of N hash mapping algorithms, the second encrypted query data being data obtained by processing preset non-plain query data of the data providing party by homomorphic encryption and a pseudo-random function, the N hash mapping algorithms including the first hash mapping algorithm; N query feedback results are constructed according to each matching result of the N matching results, third encrypted query data corresponding to each matching result and encrypted label data of the third encrypted query data; the N query feedback results are sent to the data querying party, and the N query feedback results are used to determine the query label data. In this way, the homomorphic encryption in the privacy computing technology is used to provide a calculation function on the ciphertext, the query data of the data querying party and the query label data provided by the data providing party are multi-level encrypted, and the ciphertext is processed throughout the interaction process, on the one hand, the first mapping encrypted data received by the data providing party is data after encryption by the data querying party, and the query data of the data querying party is not disclosed, on the other hand, when the data providing party obtains the query label data corresponding to the first mapping encrypted data thereof, ciphertext query and sharing are also used, so that the original data is not disclosed, and the data providing party sends N query feedback data corresponding to the query request to the data querying party, so that the data querying party can decrypt and obtain the data actually queried by the data querying party only by taking the intersection of the first mapping encrypted data sent by itself and the N query feedback data, thus, the data security and privacy of the data providing party can be ensured, and the data of the data querying party is not additionally disclosed, the data stored in the data providing party is available but invisible, the data circulation is effectively realized, the data security of the interaction of the two parties is ensured, and the data property is prevented from being threatened. BRIEF DESCRIPTION OF DRAWINGS

[0029] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed to be used in the embodiments of the present application will be briefly introduced, and other drawings can be obtained by those of ordinary skill in the art without creative labor on the premise that the drawings are not attached.

[0030] Figure 1A flowchart of a data processing method provided by an embodiment of the present application is shown in FIG. 1.

[0031] Figure 2 A flowchart of a data processing method based on a data query party provided by an embodiment of the present application is shown in FIG. 2.

[0032] Figure 3 A comparison diagram of data processing time of a data processing method provided by an embodiment of the present application is shown in FIG. 3.

[0033] Figure 4 A structural diagram of a data processing device provided by an embodiment of the present application is shown in FIG. 4.

[0034] Figure 5 A structural diagram of a data processing device based on a data query party provided by an embodiment of the present application is shown in FIG. 5.

[0035] Figure 6 A structural diagram of a computer device provided by an embodiment of the present application is shown in FIG. 6. DETAILED DESCRIPTION

[0036] The features and exemplary embodiments of various aspects of the present application will be described in detail below with reference to the accompanying drawings and specific embodiments. To make the purpose, technical solutions and advantages of the present application more clear, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain the present application, but not to limit the present application. The present application can be implemented without some of the specific details by those skilled in the art. The following description of the embodiments is only to provide a better understanding of the present application by showing examples of the present application.

[0037] It should be noted that, in this document, relational terms such as first and second and the like can only be used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply that there is any such actual relationship or order between these entities or operations. Moreover, the terms "comprising", "including", or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or apparatus that includes a list of elements does not only include those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or apparatus. Without more limitations, the elements defined by the statement "comprising" do not exclude the presence of additional identical elements in the process, method, article or apparatus that includes the elements.

[0038] The acquisition, storage, use, processing and the like of data (including but not limited to features, information and the like in this document) in the technical solutions of the present application comply with the relevant provisions of national laws and regulations.

[0039] With the continuous development of digital society, data has become a very key production factor, with important resource status and core scientific decision-making role. Data use level requires data to flow among each other, avoiding data silos, but at the same time a series of laws and regulations are issued at the data use level to clearly define the use standards of various data, especially sensitive data, to protect the security and privacy of data. Privacy computing technology can not only protect data security, but also realize effective data circulation, and has become a hot technology under the current environmental requirements. However, data usually contains sensitive information, and if not handled properly, there is a risk of data leakage, which threatens information security and property. For data query, directly using plaintext data query will also leak the query information of the query party to the data provider, and the dishonest data provider may maliciously use the query information of the query party according to the query information, causing damage to the information security of the query party.

[0040] In related technologies, the data query and sharing scheme can include the following two kinds. First, the data provider will construct an information query or sharing system according to its own data source, a party that needs to query or obtain shared data logs in the system to query the data using certain conditions of the data, and exports the results by itself. Second, the data query party knows the specific location of the value to be queried in the database of the data provider, encrypts the location vector to be queried by using homomorphic encryption, and then uses the encrypted information to query the information.

[0041] However, in the former, the querying party uses the plaintext information of the data to query and download the queried data, and in this process, the plaintext data may be leaked due to improper operation; in addition, a data provider with ulterior motives can learn the query result of the querying party, so as to learn the intention elements and additional information of the querying party, and leak the data privacy of the data querying party. In the latter, the location-based query needs the querying party to know the element index to be queried in advance, which usually means that the data of the data provider is ordered, and a large amount of communication is required, which is difficult to achieve in most cases. In order to solve the above technical problems, the privacy computing technology can be used to protect the queried or shared data, prevent data leakage, and protect the data security and privacy of the two parties. Based on this, the embodiments of the present application provide a data processing method and device, computer equipment and storage medium, which can introduce the privacy computing technology into the traditional information query and sharing field, and protect the queried and shared data, realize data protection under the condition of ensuring the query and sharing effect, and more safely circulate and exchange data. In this way, by using the homomorphic encryption method in the privacy computing technology, the query data of the querying party and the data of the data provider are encrypted, the calculation function on the ciphertext is provided, the data privacy and security of the two parties are protected, and the data provider obtains the encrypted data, without leaking the information of the querying party. The data obtained by the querying party is only the shared data corresponding to the query result, without leaking the data information of the data provider, realizing data usability and invisibility, and effectively realizing data circulation.

[0042] The data processing system, method and device, computer equipment and storage medium provided in the embodiments of the present application will be described in detail below with reference to the accompanying drawings. Figures 1 to 6 It should be noted that these embodiments are not intended to limit the scope of the present application.

[0043] In order to better illustrate the content in the embodiments of the present application, the data processing system, method and device, computer equipment and storage medium provided in the embodiments of the present application will be described in detail below with reference to the accompanying drawings. Figure 1 The data processing method provided in the embodiments of the present application will be described in detail.

[0044] Figure 1 The flowchart of the data processing method provided in the embodiments of the present application is shown in the figure.

[0045] As shown in the figure, the data processing method can be applied to a data provider, and the data processing method can specifically include the following steps: Figure 1

[0046] ​Step 110, receiving a query request sent by the data query party, the query request carrying first mapping encrypted data, the first mapping encrypted data being data obtained by processing first encrypted query data of the data query party by a first hash mapping algorithm, the first encrypted query data being data obtained by processing non-plaintext query data of the data query party by homomorphic encryption and a pseudo-random function, the query request being used to request the data provider to query query label data of the non-plaintext query data; step 120, matching the first mapping encrypted data with second mapping encrypted data in each data storage space of the N data storage spaces to obtain N matching results; wherein the second mapping encrypted data in the i th data storage space of the N data storage spaces is data obtained by processing second encrypted query data of the data query party by a j th hash mapping algorithm of the N hash mapping algorithms, the second encrypted query data being data obtained by processing preset non-plaintext query data of the data provider by homomorphic encryption and a pseudo-random function, the N hash mapping algorithms including the first hash mapping algorithm; step 130, constructing N query feedback results according to each matching result of the N matching results, third encrypted query data corresponding to each matching result, and encrypted label data of the third encrypted query data; and step 140, sending the N query feedback results to the data query party, the N query feedback results being used to determine the query label data.

[0047] In this way, by using homomorphic encryption in the privacy computing technology, a computing function on ciphertext is provided, the query data of the data query party and the query label data provided by the data provider are multi-level encrypted, and ciphertext processing is adopted throughout the interaction process. On the one hand, the first mapping encrypted data received by the data provider is data after encryption by the data query party, and the query data of the data query party is not disclosed. On the other hand, when the data provider obtains the query label data corresponding to the first mapping encrypted data, ciphertext query and sharing are adopted, so that the original data is not disclosed. Moreover, the data provider sends N query feedback data corresponding to the query request to the data query party, so that the data query party can decrypt and obtain the data actually queried by the data query party only by taking the intersection of the first mapping encrypted data sent by the data query party and the N query feedback data. In this way, the data security and privacy of the data provider can be ensured, and the data of the data query party is not additionally disclosed. The data stored in the data provider is available but invisible, and the data flow is effectively realized while the data security of the interaction of the two parties is ensured, and the data property is prevented from being threatened.

[0048] The above steps are described in detail as follows.

[0049] Firstly, step 110 is involved. In the embodiment of the application, the non-plaintext query data of the data query party is the plaintext query data of the data query party encrypted by a non-symmetric encryption algorithm (SM3).

[0050] Then, in some embodiments of the present application, the data storage space is a hash table storage space, the hash table storage space includes M hash buckets, the hash buckets are used to store the second mapping encrypted data, and the N matching results include matching results of the first mapping encrypted data and the second mapping encrypted data in each hash table storage space, where N is an integer greater than 1, and M is an integer greater than 1. Based on this, the step 120 can specifically include:

[0051] Matching the first mapping encrypted data with the second mapping encrypted data stored in each of the M hash buckets in each hash table storage space respectively, to obtain the matching results of the first mapping encrypted data and the second mapping encrypted data in each hash table storage space.

[0052] It should be noted that the data processing method provided by the embodiments of the present application can also include the step of mapping the second encrypted query data to the data storage space. Based on this, before the step 120, the data processing method can also include steps 1501 to 1503.

[0053] Step 1501, obtaining preset non-plaintext query data, the preset non-plaintext query data being data obtained by encrypting preset plaintext query data by using a symmetric encryption algorithm.

[0054] Step 1502, mapping the preset non-plaintext query data to a homomorphic encrypted plaintext domain by using a pseudo-random function to obtain second encrypted query data; wherein the pseudo-random function and the homomorphic encrypted plaintext domain are pre-set by the data querying party and the data providing party.

[0055] Step 1503, mapping the second encrypted query data to a data storage space corresponding to each of the N hash mapping algorithms according to each of the N hash mapping algorithms.

[0056] Exemplarily, the data providing party and the data querying party pre-set a limited homomorphic encrypted plaintext domain If N is 3, three hash mapping algorithms such as h1, h2, and h3 ∈ H can be selected, so that each second encrypted query data can be sampled into a data storage space with a size of M, such as a hash table storage space T, corresponding to its hash mapping algorithm. In addition, the data providing party and the data querying party also need to negotiate an oblivious pseudo-random function (Oblivious Pseudo Random Function, OPRF) so that the union of the data of the two parties can be mapped to the previously agreed plaintext domain so that the two parties can respectively map their own data to the plaintext domain through the OPRF function to obtain the second mapping encrypted data X' stored in the data storage space of the data providing partyS The first mapped encrypted data X′ provided by the data query party R .

[0057] Based on this, the data provider will X′ S Each piece of data in the hash table is inserted sequentially into the hash table storage space T using three hash mapping algorithms. S In this context, the depth of a hash table entry in the hash table storage space is greater than 1.

[0058] Here, this application embodiment provides the following steps for obtaining a pseudo-random function. First, a private key s is generated. k and public key p k The data querying party generates a random number r that is known only to itself. Then, the data querying party uses the random number r to process its input x, and uses the data provider's public key p. k The processed x is encrypted and sent to the data provider. Then, the data provider uses the private key s. k The random function is used to calculate F based on x passed from the data query party. k (x), and return it to the data query party. Then, the data query party processes the received F. k (x) Decrypt using the previously randomly generated r to obtain the output of the final pseudo-random function, which is the x provided by the data query party and the private key s provided by the data provider. k The output F of the OPRF data query is obtained through the OPRF function. k (x).

[0059] Furthermore, regarding step 130, the N query feedback results include query feedback results corresponding to each of the N data storage spaces. Based on this, the data provider determines the data based on each data storage space T among the N data storage spaces. S Each hash bucket T S,B The second mapping encrypted data and the encrypted tag data corresponding to each second mapping encrypted data, B is the maximum capacity of each hash bucket, and the query feedback result is constructed as G(X) = H(x) + rF(x), where H(x) is the encrypted tag data polynomial, r is a random number, and F(x) is the first mapping encrypted data. Thus, when x is the hash bucket T S,B When the element is in the middle, the corresponding F(x) value is 0, while the value of G(x) is the SM4 value of the encrypted tag data.

[0060] In some embodiments of the present application, the N matching results include first type matching results, the first type matching results are used to represent that the target mapping encrypted data corresponding to the first mapping encrypted data is matched from the second mapping encrypted data of the i-th data storage space, the third encrypted query data includes first target encrypted query data, the encryption tag data of the third encrypted query data includes first encryption tag data, and based on this, before step 130, the data processing method can further include steps 1601 and 1602.

[0061] Step 1601, according to the first type matching result, the target mapping encrypted data in the i-th data storage space is mapped by the j-th hash mapping algorithm to obtain the first target encrypted query data.

[0062] Step 1602, according to the association information of the preset encrypted query data and the preset encryption tag data, the first preset encryption tag data associated with the first target encrypted query data is determined as the first encryption tag data.

[0063] Exemplarily, for the elements in each bucket after the cuckoo hash is performed, the OPRF operation is performed to process the real data, and then the corresponding <key, valve> form is constructed, and then the Lagrange interpolation method is used to construct the polynomials F(x) and G(x) belonging to each bucket.

[0064] In some embodiments of the present application, the N matching results include second type matching results, the second type matching results are used to represent that the target mapping encrypted data corresponding to the first mapping encrypted data is not matched from the second mapping encrypted data of the i-th data storage space, the third encrypted query data includes second target encrypted query data, the encryption tag data of the third encrypted query data includes second encryption tag data, and based on this, before step 130, the data processing method can further include steps 1701 to 1703.

[0065] Step 1701, according to the second type matching result, the third mapping encrypted data is randomly selected from the i-th data storage space.

[0066] Step 1702, the third mapping encrypted data in the i-th data storage space is mapped by the j-th hash mapping algorithm to obtain the second target encrypted query data.

[0067] Exemplarily, the j-th hash mapping algorithm can be a cuckoo hash operation.

[0068] Step 1703, the second preset query tag data randomly selected from the association information of the preset encrypted query data and the preset encryption tag data is determined as the second encryption tag data.

[0069] It should be noted that the embodiment of the present application also provides a step of determining the association information, i.e., before step 130 (specifically, before step 1601 or step 1701), the data processing method can further include steps 1801 to 1804.

[0070] In step 1801, preset plaintext query data and preset encrypted tag data corresponding to the preset plaintext query data are obtained.

[0071] In step 1802, the preset plaintext query data is encrypted by using an asymmetric encryption algorithm to obtain preset non-plaintext query data.

[0072] In step 1803, the preset encrypted tag data is encrypted by using a symmetric encryption algorithm to obtain preset encrypted tag data.

[0073] In step 1804, the association information of the preset encrypted query data and the preset encrypted tag data is generated based on the preset non-plaintext query data and the preset encrypted tag data.

[0074] Exemplarily, the preset plaintext query data can be a communication number, and the preset encrypted tag data can be a province-city tag corresponding to the communication number. The data provider will encrypt the preset plaintext query data such as X S SM3 encryption, and a secret key of symmetric encryption algorithm (SM4) encryption is randomly generated to perform SM4 encryption on the preset encrypted tag data corresponding to the preset plaintext query data. In this way, the association information of the preset encrypted query data and the preset encrypted tag data (X i , L i ), i ∈ [X], where X i is the preset non-plaintext query data, and L i is the preset encrypted tag data corresponding to the preset non-plaintext query data. It should be noted that the principle of homomorphic encryption in the embodiment of the present application can be that after data is encrypted by using homomorphic encryption, addition, subtraction, multiplication, and division operations are performed, and the result obtained after decryption is consistent with the result obtained by directly performing addition, subtraction, multiplication, and division operations on the original data. Taking the BFV algorithm as an example, a plaintext domain and a ciphertext domain are first selected, where n is a multiple of 2, q is a prime number, and t is much smaller than q. Secret key generation: a polynomial e, a polynomial a1, and a polynomial s are randomly selected, and a public key p k is calculated: {p k0 =-a1s+e, p k1 =a1}; a polynomial u, a polynomial e1, and a polynomial e2 are randomly selected, and a polynomial m to be encrypted is encrypted, and a ciphertext c is calculated: {c0=p k0 u+e1+δ*m, c1=p k1Then the ciphertext is homomorphically decrypted, c0+c1s=δ*m+(e2s+e1+eu) is calculated, and then divided by δ, rounded to obtain the decrypted result. Here, the communication number is grouped every 8 bits, and then the plaintext polynomial is constructed, so that the data query party uses the BFV homomorphic encryption to encrypt the query plaintext polynomial, sends it to the data provider, and the data provider calculates the encrypted data in each polynomial, and then returns the result of each polynomial to the data query party.

[0075] Therefore, the data processing method provided by the embodiments of the present application can homomorphically encrypt the query data to protect the privacy of the query party; at the same time, the returned data is only the intersection data, which does not leak additional data information of the data provider, protecting the privacy of the data provider. In the entire data processing process, it is all ciphertext, avoiding data leakage, improving the security of data query and sharing operation, thereby avoiding the threat to data property security, realizing data usability and invisibility, and improving the data security of data interaction between the two parties.

[0076] Based on this, the following will be combined Figure 2 The data processing method provided by the embodiments of the present application is described as follows.

[0077] Figure 2 The flowchart of the data processing method provided by the embodiments of the present application is shown.

[0078] As Figure 2 shown, the data processing method can be applied to the data query party, and the data processing method can specifically include the following steps:

[0079] Step 210, a query request is sent to the data provider, the query request carrying first mapping encrypted data, the first mapping encrypted data being data processed by a first hash mapping algorithm from first encrypted query data of the data query party, the first encrypted query data being data processed by homomorphic encryption and a pseudo-random function from non-plain query data of the data query party, the query request being used to request the data provider to query query label data of the non-plain query data; Step 220, N query feedback results sent by the data query party are received, the N query feedback results being determined by N matching results, third encrypted query data corresponding to each matching result in the N matching results, and encrypted label data of the third encrypted query data, the N matching results being obtained by matching the first mapping encrypted data with second mapping encrypted data in each data storage space of N data storage spaces, the second mapping encrypted data in the i-th data storage space of the N data storage spaces being data processed by a j-th hash mapping algorithm from a second encrypted query data of the data query party, the second encrypted query data being data processed by homomorphic encryption and a pseudo-random function from preset non-plain query data of the data provider, the N hash mapping algorithms including the first hash mapping algorithm; Step 230, the query label data is determined according to a decryption result of the N query feedback results.

[0080] In this way, by using homomorphic encryption in privacy computing technology, a computing function on ciphertext is provided, the query data of the data query party and the query label data provided by the data provider are multi-level encrypted, and ciphertext processing is used throughout the interaction process, on the one hand, the first mapping encrypted data received by the data provider is data encrypted by the data query party, and the query data of the data query party is not disclosed, on the other hand, when the data provider obtains the query label data corresponding to the first mapping encrypted data thereof, ciphertext query and sharing are also used, so that the original data is not disclosed, and the data provider sends N query feedback data corresponding to the query request to the data query party, so that the data query party can decrypt and obtain the data actually queried by the data query party only by taking the intersection of the first mapping encrypted data sent by the data query party and the N query feedback data, thus, the data security and privacy of the data provider can be ensured, and the data of the data query party is not additionally disclosed, the data stored in the data provider is available but invisible, and the data circulation is effectively realized while the data security of the interaction of the two parties is ensured, and the data property is prevented from being threatened.

[0081] The above steps are described in detail as follows.

[0082] Firstly, the step 210 can specifically include that the data querying party encodes the non-plaintext query data in a single instruction multiple data (SIMD) package mode, and generates a public key and a private key of homomorphic encryption, encrypts the non-plaintext query data using the public key and a pseudo-random function to obtain first encrypted query data, and unifies the data length of the first encrypted query data through a first hash mapping algorithm, so as to facilitate the data providing party to match the first encrypted query data with second encrypted query data in each of the N data storage spaces respectively, so that the data providing party calculates the output (F(x), G(x)) according to F(x) and G(x).

[0083] In some embodiments of the present application, before the step 210, the data processing method provided in the embodiments of the present application can further include a step of generating first mapping encrypted data, based on which the data processing method can further include the steps 2401 to 2405.

[0084] The step 2401 is to obtain plaintext query data.

[0085] The step 2402 is to encrypt the plaintext query data through an asymmetric encryption algorithm to obtain non-plaintext query data.

[0086] The step 2403 is to map the non-plaintext query data to a homomorphic encryption plaintext domain through a pseudo-random function to obtain first encrypted query data.

[0087] The step 2404 is to extract a first hash mapping algorithm from N hash mapping algorithms, wherein the N hash mapping algorithms, the pseudo-random function and the homomorphic encryption plaintext domain are pre-set by the data querying party and the data providing party.

[0088] The step 2405 is to map the first encrypted query data to a data storage space corresponding to the first hash mapping algorithm according to the first hash mapping algorithm to obtain first mapping encrypted data.

[0089] Exemplarily, if N is 3, the data querying party can select one of the three hash mapping algorithms pre-set by the data providing party to map the processed data X' R to a hash table data storage space T R of the data querying party, wherein the depth of each hash table item is at most 1.

[0090] Then, the step 230 can specifically include the steps 2301 and 2302.

[0091] Step 2301, the third encrypted query data in each query feedback result of the N query feedback results is respectively decrypted by the homomorphic encryption key, and the decryption result corresponding to each query feedback result is obtained.

[0092] Specifically, in the case that the decryption result includes the first type of decryption result, the first type of decryption result is used to indicate that the i-th query feedback result of the N query feedback results includes the first encrypted tag data corresponding to the first mapping encrypted data, the step 2301 can specifically include:

[0093] In the case that the decryption result is the first type of decryption result, the first encrypted tag data in the i-th query feedback result is decrypted by the asymmetric encryption key of the encrypted preset query tag data provided by the data query party to obtain the query tag data of the non-plaintext query data.

[0094] It should be noted that the decryption result in the embodiment of the application includes the second type of decryption result, and the first type of decryption result is used to indicate that the i-th query feedback result of the N query feedback results does not include the first encrypted tag data corresponding to the first mapping encrypted data, and the query tag data is random encrypted tag data that does not match the non-plaintext query data.

[0095] Step 2302, the encrypted tag data in each query feedback result is decrypted by the asymmetric encryption key of the encrypted preset query tag data provided by the data query party to obtain the query tag data.

[0096] Exemplarily, the data query party obtains the N query feedback results sent by the data provider, can use the previous homomorphic encryption private key to decrypt F(x) in each feedback result of the N query feedback results, if the decrypted result is 0, then G(x) is the SM4 value of the corresponding tag, then the data query party uses the previous SM4 secret key to decrypt G(x) again, and obtains the query tag data that the data query party really wants, if F(x) is not 0, the group of return values is discarded, or if F(x) is not 0, G(x) can also be decrypted by the SM4 secret key, and the obtained will be random encrypted tag data that does not match the non-plaintext query data, such as random code, random value, etc., to ensure the safety of the data in the data provider.

[0097] Thus, the data processing method provided in the embodiments of the present application protects the privacy of the querying party by homomorphic encryption of the non-plaintext query data, returns only the intersection of the query or shared data, and returns data that is only decrypted in the case of a matching intersection to be real information and does not leak the data information of the data provider, thereby protecting the data security and privacy of the data provider. In addition, homomorphic encryption calculation is used in the interaction between the two parties, and ciphertext processing is used throughout the process to avoid data leakage, improve the security of the operation, ensure the accuracy of the data operation, and achieve data usability and invisibility.

[0098] To better illustrate the effect of the data processing method provided in the embodiments of the present application, the following describes the effect of the data processing method with reference to the accompanying drawings. Figure 3 The effect of the data processing method is compared and described as follows.

[0099] The data processing method provided in the embodiments of the present application can be executed based on a computer device of a data provider and a computer device of a data querying party. The computer device can be an entity physical machine, the operating system is windows 10, a model is built based on SEAL, and the entire process includes data set reading and processing, interpolation polynomial construction, homomorphic encryption, calculation and decryption, query result viewing, and label result decryption.

[0100] Based on this, as shown in Figure 3 , the running results of the proposed method under different data set sizes are shown. As shown in Figure 3 , the time consumption becomes longer and longer as the data set increases. Compared with traditional database query and sharing, although the method proposed in the embodiments of the present application increases the time consumption, the processing of data security and the corresponding encryption and decryption operations well protect the security and privacy of the data, making the data more secure in circulation.

[0101] Thus, the data processing method for information query and sharing based on the privacy computing technology is proposed in the embodiments of the present application. The preset plaintext query data is subjected to SM3 processing, and the preset encryption tag data corresponding to the preset plaintext query data is subjected to SM4 processing, so as to meet the data security requirements. Then, the data is subjected to OPRF and cuckoo hash operations, so as to further protect the data privacy and reduce the calculation complexity. Then, the encrypted query data is subjected to homomorphic calculation, the partition, the stamp algorithm and the numerical approximation algorithm (Paterson-Stockmeyer) of the matrix hyperbolic cosine function are used to further reduce the multiplication depth, the limited homomorphic encryption technology is better used, the complexity is reduced, and the operation speed of the method is improved. Finally, the calculation result is decrypted. Since the random number is introduced during the calculation, when the query result does not exist, the value obtained by the data querying party will be the random number, and the privacy of the data providing party is also well protected. In addition, the privacy computing technology is combined with the information query and sharing, the characteristics of the privacy computing technology can be fully utilized, the data is strongly protected, the data is not easily leaked, the data security of each party in the data query and sharing process is protected, the data is available and invisible, the circulation of the data is effectively promoted, the data silos are broken, and the data is better empowered.

[0102] The present application provides a data processing device, in particular in combination with Figure 4 will be described in detail.

[0103] Figure 4 A structural schematic diagram of a data processing device provided by the embodiments of the present application.

[0104] In some embodiments of the present application, Figure 4 The data processing device shown can be arranged in the computer device of the data providing party.

[0105] As Figure 4 shown, the data processing device 40 specifically can include:

[0106] The receiving module 401 is configured to receive a query request sent by a data querying party, the query request carrying first mapping encryption data, the first mapping encryption data being data obtained by processing first encryption query data of the data querying party by a first hash mapping algorithm, the first encryption query data being data obtained by processing non-plaintext query data of the data querying party by a homomorphic encryption and a pseudo-random function, and the query request being used to request the data providing party to query query tag data of the non-plaintext query data.

[0107] The matching module 402 is configured to match the first mapping encrypted data with second mapping encrypted data in each data storage space of the N data storage spaces to obtain N matching results; the second mapping encrypted data in the i th data storage space of the N data storage spaces is data obtained by processing second encrypted query data of the data querying party by a j th hash mapping algorithm of N hash mapping algorithms, the second encrypted query data is data obtained by processing preset non-plain query data of the data providing party by homomorphic encryption and a pseudo-random function, and the N hash mapping algorithms include the first hash mapping algorithm;

[0108] The constructing module 403 is configured to construct N query feedback results according to each matching result in the N matching results, third encrypted query data corresponding to each matching result, and an encryption label of the third encrypted query data.

[0109] The sending module 404 is configured to send the N query feedback results to the data querying party, and the N query feedback results are used to determine the query label data.

[0110] Thus, the homomorphic encryption in the privacy computing technology can be used to provide a calculation function on the ciphertext, and the query data of the data querying party and the query label data provided by the data providing party are multi-level encrypted, and the ciphertext is processed throughout the interaction process. On the one hand, the first mapping encrypted data received by the data providing party is data after encryption by the data querying party, and the query data of the data querying party is not disclosed. On the other hand, when the data providing party obtains the query label data corresponding to the first mapping encrypted data, the ciphertext is queried and shared, so as to avoid disclosure of the original data. The data providing party sends N query feedback data corresponding to the query request to the data querying party, so that the data querying party can decrypt and obtain the data actually queried by the data querying party only by taking the intersection of the first mapping encrypted data sent by the data querying party and the N query feedback data. In this way, the data security and privacy of the data providing party can be ensured, and the data of the data querying party is not additionally disclosed. The data stored in the data providing party is available but invisible, and the data flow is effectively realized while the data security of the interaction between the two parties is ensured, and the data property is prevented from being threatened.

[0111] The data processing apparatus 40 in the embodiments of the present application will be described in detail below.

[0112] In some embodiments of the present application, the matching module 402 can be specifically configured to, in the case that the data storage space is a hash table storage space, the hash table storage space includes M hash buckets, the hash buckets are used to store the second mapping encrypted data, and the N matching results include matching results of the first mapping encrypted data and the second mapping encrypted data in each hash table storage space, match the first mapping encrypted data with the second mapping encrypted data stored in each of the M hash buckets in each hash table storage space respectively to obtain the matching results of the first mapping encrypted data and the second mapping encrypted data in each hash table storage space.

[0113] In some embodiments of the present application, the data processing apparatus 40 in the embodiments of the present application can further include a mapping module and a determining module; wherein,

[0114] The mapping module is configured to, in the case that the N matching results include first type matching results, the first type matching results are used to indicate that the target mapping encrypted data corresponding to the first mapping encrypted data is matched from the second mapping encrypted data of the ith data storage space, the third encrypted query data includes first target encrypted query data, and the encryption tag data of the third encrypted query data includes first encryption tag data, perform mapping processing on the target mapping encrypted data in the ith data storage space according to the first type matching results by using the jth hash mapping algorithm to obtain the first target encrypted query data.

[0115] The determining module is configured to determine the first preset encryption tag data associated with the first target encrypted query data as the first encryption tag data according to the association information of the preset encrypted query data and the preset encryption tag data.

[0116] In some embodiments of the present application, the data processing apparatus 40 in the embodiments of the present application can further include a screening module, a mapping module and a determining module; wherein,

[0117] The screening module is configured to, in the case that the N matching results include second type matching results, the second type matching results are used to indicate that the target mapping encrypted data corresponding to the first mapping encrypted data is not matched from the second mapping encrypted data of the ith data storage space, the third encrypted query data includes second target encrypted query data, and the encryption tag data of the third encrypted query data includes second encryption tag data, screen out the third mapping encrypted data from the ith data storage space randomly according to the second type matching results.

[0118] The mapping module is configured to perform mapping processing on the third mapping encrypted data in the ith data storage space by using the jth hash mapping algorithm to obtain the second target encrypted query data.

[0119] The determining module is configured to determine the second preset query label data randomly selected from the association information between the preset encrypted query data and the preset encrypted label data as the second encrypted label data.

[0120] In some embodiments of the present application, the data processing apparatus 40 in the embodiments of the present application can further include an obtaining module, an encryption module and a generating module; wherein,

[0121] The obtaining module is configured to obtain preset plaintext query data and preset encrypted label data corresponding to the preset plaintext query data.

[0122] The encryption module is configured to encrypt the preset plaintext query data by using an asymmetric encryption algorithm to obtain preset non-plaintext query data.

[0123] The encryption module can also be configured to encrypt the preset encrypted label data by using a symmetric encryption algorithm to obtain preset encrypted label data.

[0124] The generating module is configured to generate association information between the preset encrypted query data and the preset encrypted label data based on the preset non-plaintext query data and the preset encrypted label data.

[0125] In some embodiments of the present application, the data processing apparatus 40 in the embodiments of the present application can further include an obtaining module and a mapping module; wherein,

[0126] The obtaining module is configured to obtain preset non-plaintext query data, which is data obtained by encrypting the preset plaintext query data by using a symmetric encryption algorithm.

[0127] The mapping module is configured to map the preset non-plaintext query data to a homomorphic encryption plaintext domain by using a pseudo-random function to obtain second encrypted query data; wherein, the pseudo-random function and the homomorphic encryption plaintext domain are set in advance by the data querying party and the data providing party.

[0128] The mapping module can also be configured to map the second encrypted query data to a data storage space corresponding to each of the N hash mapping algorithms according to each of the N hash mapping algorithms.

[0129] The present application provides a data processing apparatus, which will be described in detail in combination with Figure 5 The present application provides a data processing apparatus, which will be described in detail in combination with

[0130] Figure 5 A structural schematic diagram of a data processing apparatus based on a data querying party provided in the embodiments of the present application.

[0131] In some embodiments of the present application, Figure 5 The data processing apparatus shown in the figure can be arranged in a computer device of the data querying party.

[0132] As Figure 5 shown, the data processing apparatus 50 can specifically include:

[0133] The sending module 501 is configured to send a query request to a data provider, the query request carrying first mapping encrypted data, the first mapping encrypted data being data obtained by processing first encrypted query data of a data querying party by using a first hash mapping algorithm, the first encrypted query data being data obtained by processing non-plain query data of the data querying party by using homomorphic encryption and a pseudo-random function, the query request being used to request the data provider to query query label data of the non-plain query data;

[0134] The receiving module 502 is configured to receive N query feedback results sent by the data querying party, the N query feedback results being determined by N matching results, third encrypted query data corresponding to each of the N matching results, and encrypted label data of the third encrypted query data, the N matching results being obtained by matching the first mapping encrypted data with second mapping encrypted data in each of N data storage spaces, the second mapping encrypted data in an i-th data storage space of the N data storage spaces being data obtained by processing second encrypted query data of the data querying party by using a j-th hash mapping algorithm of N hash mapping algorithms, the second encrypted query data being data obtained by processing preset non-plain query data of the data provider by using homomorphic encryption and a pseudo-random function, the N hash mapping algorithms including the first hash mapping algorithm;

[0135] The determining module 503 is configured to determine the query label data according to a decryption result of the N query feedback results.

[0136] Thus, the homomorphic encryption in the privacy computing technology can be used to provide a computing function on ciphertext, the query data of the data querying party and the query label data provided by the data provider are encrypted in multiple levels, and ciphertext processing is used throughout the interaction process, on the one hand, the first mapping encrypted data received by the data provider is data after encryption by the data querying party, and the query data of the data querying party is not disclosed, on the other hand, when the data provider obtains the query label data corresponding to the first mapping encrypted data thereof, ciphertext query and sharing are also used, so that the original data is not disclosed, and the data provider sends N query feedback data corresponding to the query request to the data querying party, so that the data querying party can decrypt and obtain the data actually queried by the data querying party only by taking an intersection of the first mapping encrypted data sent by the data querying party and the N query feedback data, in this way, the data security and privacy of the data provider can be ensured, and the data of the data querying party is not additionally disclosed, the data stored in the data provider is available but invisible, and the data flow is effectively realized while the data security of the interaction of the two parties is ensured, and the data property is prevented from being threatened.

[0137] The data processing apparatus 50 in the embodiments of the present application will be described in detail as follows.

[0138] In some embodiments of the present application, the data processing apparatus 50 in the embodiments of the present application can further include an obtaining module, an encryption module, a mapping module and an extracting module; wherein,

[0139] The obtaining module is configured to obtain the plaintext query data.

[0140] The encryption module is configured to perform encryption processing on the plaintext query data by using an asymmetric encryption algorithm to obtain non-plaintext query data.

[0141] The mapping module is configured to map the non-plaintext query data into a homomorphic encryption plaintext domain by using a pseudo-random function to obtain first encrypted query data.

[0142] The extracting module is configured to extract a first hash mapping algorithm from N hash mapping algorithms, wherein the N hash mapping algorithms, the pseudo-random function and the homomorphic encryption plaintext domain are pre-set by a data querying party and a data providing party.

[0143] The mapping module can also be configured to map the first encrypted query data into a data storage space corresponding to the first hash mapping algorithm according to the first hash mapping algorithm to obtain first mapped encrypted data.

[0144] In some embodiments of the present application, the determining module in the embodiments of the present application is configured to perform decryption processing on the third encrypted query data in each of the N query feedback results by using a homomorphic encryption key to obtain a decryption result corresponding to each of the query feedback results.

[0145] The encrypted label data in each of the query feedback results is decrypted by using a key for asymmetric encryption of the encrypted preset query label data provided by the data querying party to obtain the query label data.

[0146] In some embodiments of the present application, the determining module can also be configured to, in a case where the decryption result includes a first type of decryption result, the first type of decryption result being used to indicate that the i th query feedback result of the N query feedback results includes the first encrypted label data corresponding to the first mapped encrypted data, and in a case where the decryption result is the first type of decryption result, decrypt the first encrypted label data in the i th query feedback result by using the key for asymmetric encryption of the encrypted preset query label data provided by the data querying party to obtain the query label data of the non-plaintext query data.

[0147] In some embodiments of the present application, the decryption result includes a second type of decryption result, and the first type of decryption result is used to represent that the first encrypted tag data corresponding to the first mapping encrypted data is not included in the i-th query feedback result of the N query feedback results, and the query tag data is random encrypted tag data that does not match the non-plaintext query data.

[0148] The present application also provides a computer device. Specifically in combination Figure 6 The specific implementation is described in detail.

[0149] Figure 6 FIG. 1 is a structural schematic diagram of a computer device provided by an embodiment of the present application.

[0150] As Figure 6 shown, the computer device can include at least one of the following: an electronic device, a server, involved in the embodiments of the present application. The computer device can include a processor 601 and a memory 602 having computer program instructions stored therein.

[0151] Specifically, the processor 601 can include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or can be configured to implement one or more integrated circuits of the embodiments of the present application.

[0152] The memory 602 can include a mass storage for data or instructions. By way of example and not limitation, the memory 602 can include a hard disk drive (HDD), a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive or a combination of two or more of these. Where appropriate, the memory 602 can include removable or non-removable (or fixed) media. Where appropriate, the memory 602 can be internal or external to the integrated gateway disaster recovery device. In certain embodiments, the memory 602 is a non-volatile solid-state memory. In certain embodiments, the memory 602 includes solid-state storage (ROM). Where appropriate, this ROM can be mask-programmed ROM, programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), electrically alterable ROM (EAROM), or flash memory, or a combination of two or more of these.

[0153] The processor 601 reads and executes the computer program instructions stored in the memory 602 to implement any one of the data processing methods in the above embodiments.

[0154] In one example, the computer device can further include a communication interface 603 and a bus 610. As shown in FIG. 6, the processor 601, the memory 602, and the communication interface 603 are connected through the bus 610 and complete communication with each other. Figure 6

[0155] The communication interface 603 is mainly used to realize the communication between the modules, devices, units and / or equipment in the embodiments of the present application.

[0156] The bus 610 includes hardware, software or both to couple the components of the traffic control device to each other. By way of example, and not limitation, the bus can include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard System (ETSA) bus, a Front Side Bus (FSB), a HyperTransport (HT) interconnect, an Industry Standard System (TSA) bus, an Infiniband interconnect, a Low Pin Count (LPC) bus, a memory bus, a Micro Channel System (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable bus or combination of two or more of these. Where appropriate, the bus 610 can include one or more buses. Although specific buses are described and shown in the embodiments of the present application, the present application contemplates any suitable bus or interconnect.

[0157] The payment device can perform the data processing method in the embodiments of the present application, thereby realizing the data processing method and device described in combination Figures 1 to 6

[0158] In addition, in combination with the data processing method in the above embodiments, the embodiments of the present application can provide a computer readable storage medium to realize. The computer readable storage medium has computer program instructions stored thereon; the computer program instructions are executed by the processor to realize any one of the data processing methods in the above embodiments.

[0159] It should be clear that the present application is not limited to the specific configurations and processes described above and shown in the drawings. For the sake of brevity, detailed descriptions of well-known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of the present application is not limited to the specific steps described and shown, and those skilled in the art can make various changes, modifications and additions, or change the order between steps, after understanding the spirit of the present application.

[0160] ​​The functional blocks shown in the above structural block diagrams can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, ASICs (application specific integrated circuits), appropriate firmware, plug-ins, functional cards, and the like. When implemented in software, the elements of the present application are program or code segments that are used to perform the required tasks. The program or code segments can be stored in a machine-readable medium or transmitted through a data signal carried in a carrier wave over a transmission medium or communication link. The "machine-readable medium" can include any medium that can store or transfer information. Examples of the machine-readable medium include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, optical fiber media, radio frequency (RF) links, and the like. The code segments can be downloaded via a computer network such as the Internet, an intranet, or the like.

[0161] It should also be noted that the exemplary embodiments mentioned in the present application describe some methods or systems based on a series of steps or devices. However, the present application is not limited to the order of the above steps, that is, the steps can be performed in the order mentioned in the embodiments, or in an order different from that in the embodiments, or several steps can be performed simultaneously.

[0162] The above is only a specific implementation of the present application, and those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described systems, modules and units can refer to the corresponding processes in the foregoing method embodiments, which will not be described here. It should be understood that the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of various equivalent modifications or replacements within the technical scope disclosed in the present application, and these modifications or replacements should be covered within the protection scope of the present application.

Claims

1. A data processing method applied to a data provider, comprising: receiving a query request sent by a data query party, the query request carrying first mapping encrypted data, the first mapping encrypted data being data obtained by processing first encrypted query data of the data query party by a first hash mapping algorithm, the first encrypted query data being data obtained by processing non-plaintext query data of the data query party by homomorphic encryption and a pseudo-random function, the query request being used to request the data provider to query query label data of the non-plaintext query data; matching the first mapping encrypted data with second mapping encrypted data in each data storage space of N data storage spaces to obtain N matching results; wherein the second mapping encrypted data in an i-th data storage space of the N data storage spaces is data obtained by processing second encrypted query data by a j-th hash mapping algorithm of N hash mapping algorithms, the second encrypted query data being data obtained by processing preset non-plaintext query data of the data provider by homomorphic encryption and a pseudo-random function, the N hash mapping algorithms including the first hash mapping algorithm; constructing N query feedback results according to each matching result of the N matching results, third encrypted query data corresponding to the each matching result, and encrypted label data of the third encrypted query data; a decryption result of the third encrypted query data in each query feedback result of the N query feedback results includes a first type of decryption result or a second type of decryption result, the first type of decryption result being used to indicate that the i-th query feedback result of the N query feedback results includes first encrypted label data corresponding to the first mapping encrypted data, and the second type of decryption result being used to indicate that target mapping encrypted data corresponding to the first mapping encrypted data is not matched from the second mapping encrypted data of the i-th data storage space; sending the N query feedback results to the data query party, the N query feedback results being used to determine the query label data.

2. The method of claim 1, wherein, The data storage space is a hash table storage space, the hash table storage space includes M hash buckets, the hash bucket being used to store the second mapping encrypted data, and the N matching results include matching results of the first mapping encrypted data and the second mapping encrypted data in each hash table storage space; the matching of the first mapping encrypted data with the second mapping encrypted data in each data storage space of the N data storage spaces to obtain the N matching results comprises: matching the first mapping encrypted data with the second mapping encrypted data stored in each hash bucket of M hash buckets in each hash table storage space respectively to obtain the matching results of the first mapping encrypted data and the second mapping encrypted data in each hash table storage space.

3. The method of claim 1, wherein, The N matching results include first type matching results, the first type matching results are used to represent that target mapping encrypted data corresponding to the first mapping encrypted data is matched from the second mapping encrypted data of the i th data storage space, the third encrypted query data includes first target encrypted query data, and encrypted tag data of the third encrypted query data includes first encrypted tag data; The method further includes: According to the first type matching result, the target mapping encrypted data in the i th data storage space is processed by mapping through the j th hash mapping algorithm, and the first target encrypted query data is obtained; According to the association information of the preset encrypted query data and the preset encrypted tag data, the first preset encrypted tag data associated with the first target encrypted query data is determined as the first encrypted tag data.

4. The method of claim 1 or 3, wherein, The N matching results include second type matching results, the second type matching results are used to represent that target mapping encrypted data corresponding to the first mapping encrypted data is not matched from the second mapping encrypted data of the i th data storage space, the third encrypted query data includes second target encrypted query data, and encrypted tag data of the third encrypted query data includes second encrypted tag data; The method further includes: According to the second type matching result, the third mapping encrypted data is randomly selected from the i th data storage space; The third mapping encrypted data in the i th data storage space is processed by mapping through the j th hash mapping algorithm, and the second target encrypted query data is obtained; The second preset query tag data randomly selected from the association information of the preset encrypted query data and the preset encrypted tag data is determined as the second encrypted tag data.

5. The method of claim 4, wherein, The method further includes: Obtaining preset plaintext query data and preset encrypted tag data corresponding to the preset plaintext query data; The preset plaintext query data is encrypted by using an asymmetric encryption algorithm to obtain preset non-plaintext query data; The preset encrypted tag data is encrypted by using a symmetric encryption algorithm to obtain encrypted encrypted tag data; Based on the preset non-plaintext query data and the encrypted encrypted tag data, the association information of the preset encrypted query data and the preset encrypted tag data is generated.

6. The method of claim 1, wherein, The method further includes: Obtaining the preset non-plaintext query data, which is data obtained by encrypting preset plaintext query data by using an asymmetric encryption algorithm; The preset non-plaintext query data is mapped into a homomorphic encryption plaintext domain by using a pseudo-random function to obtain the second encrypted query data; wherein the pseudo-random function and the homomorphic encryption plaintext domain are preset by the data query party and the data provider; According to each hash mapping algorithm in the N hash mapping algorithms, the second encrypted query data is mapped into a data storage space corresponding to each hash mapping algorithm.

7. A data processing method applied to a data query party, comprising: sending a query request to a data provider, the query request carrying first mapping encrypted data, the first mapping encrypted data being data obtained by processing first encrypted query data of the data query party by a first hash mapping algorithm, the first encrypted query data being data obtained by processing non-plain query data of the data query party by homomorphic encryption and a pseudo-random function, the query request being used to request the data provider to query query tag data of the non-plain query data; receiving N query feedback results sent by the data query party, the N query feedback results being determined by N matching results, third encrypted query data corresponding to each matching result in the N matching results, and encrypted tag data of the third encrypted query data, the N matching results being obtained by matching the first mapping encrypted data with second mapping encrypted data in each data storage space of N data storage spaces, second mapping encrypted data in an i-th data storage space of the N data storage spaces being data obtained by processing second encrypted query data by a j-th hash mapping algorithm of N hash mapping algorithms, the second encrypted query data being data obtained by processing preset non-plain query data of the data provider by homomorphic encryption and a pseudo-random function, the N hash mapping algorithms including the first hash mapping algorithm, a decryption result of the third encrypted query data in each query feedback result of the N query feedback results including a first type of decryption result or a second type of decryption result, the first type of decryption result being used to indicate that the i-th query feedback result of the N query feedback results includes first encrypted tag data corresponding to the first mapping encrypted data, the second type of decryption result being used to indicate that target mapping encrypted data corresponding to the first mapping encrypted data is not matched from the second mapping encrypted data of the i-th data storage space, and determining the query tag data according to the decryption results of the N query feedback results.

8. The method of claim 7, wherein, The method further includes: obtaining non-plain query data by encrypting the non-plain query data by using an asymmetric encryption algorithm; mapping the non-plain query data to a homomorphic encryption plaintext domain by using a pseudo-random function to obtain the first encrypted query data; extracting a first hash mapping algorithm from the N hash mapping algorithms, wherein the N hash mapping algorithms, the pseudo-random function, and the homomorphic encryption plaintext domain are preset by the data query party and the data provider; mapping the first encrypted query data to a data storage space corresponding to the first hash mapping algorithm according to the first hash mapping algorithm to obtain the first mapping encrypted data. The determining the query tag data according to the decryption results of the N query feedback results includes:

9. The method of claim 7, wherein, decrypting the third encrypted query data in each query feedback result of the N query feedback results by using a homomorphic encryption key to obtain a decryption result corresponding to each query feedback result. ​ The encrypted label data in each query feedback result is decrypted by using a symmetric encryption key of the encrypted preset query label data provided by the data query party, to obtain query label data.

10. The method of claim 9, wherein, The encrypted label data in each query feedback result is decrypted by using a symmetric encryption key of the encrypted preset query label data provided by the data query party, to obtain query label data. In a case where the decryption result is the first type of decryption result, the first encrypted label data in the i-th query feedback result is decrypted by using an asymmetric encryption key of the encrypted preset query label data provided by the data query party, to obtain the query label data of the non-plaintext query data.

11. The method of claim 10, wherein, The query label data is random encrypted label data that does not match the non-plaintext query data.

12. A data processing apparatus applied to a data provider, comprising: a receiving module configured to receive a query request sent by a data query party, the query request carrying first mapping encrypted data, the first mapping encrypted data being data processed by a first hash mapping algorithm from first encrypted query data of the data query party, the first encrypted query data being data processed by homomorphic encryption and a pseudo-random function from non-plaintext query data of the data query party, the query request being used to request the data provider to query query label data of the non-plaintext query data; a matching module configured to match the first mapping encrypted data with second mapping encrypted data in each data storage space of N data storage spaces, to obtain N matching results; wherein the second mapping encrypted data in an i-th data storage space of the N data storage spaces is data processed by a j-th hash mapping algorithm from a second encrypted query data, the second encrypted query data being data processed by homomorphic encryption and a pseudo-random function from preset non-plaintext query data of the data provider, the N hash mapping algorithms including the first hash mapping algorithm; a constructing module configured to construct N query feedback results according to each matching result of the N matching results, third encrypted query data corresponding to the each matching result, and encrypted label data of the third encrypted query data; a decryption result of the third encrypted query data in each query feedback result of the N query feedback results includes a first type of decryption result or a second type of decryption result, the first type of decryption result being used to indicate that the i-th query feedback result of the N query feedback results includes first encrypted label data corresponding to the first mapping encrypted data, and the second type of decryption result being used to indicate that target mapping encrypted data corresponding to the first mapping encrypted data is not matched from the second mapping encrypted data of the i-th data storage space; a sending module configured to send the N query feedback results to the data query party, the N query feedback results being used to determine query label data.

13. A data processing apparatus applied to a data query party, comprising: The sending module is configured to send a query request to a data provider, wherein the query request carries first mapping encrypted data, the first mapping encrypted data is data obtained by processing first encrypted query data of the data query party by using a first hash mapping algorithm, and the first encrypted query data is data obtained by processing non-plain query data of the data query party by using a homomorphic encryption and a pseudo-random function, and the query request is used to request the data provider to query query label data of the non-plain query data; The receiving module is configured to receive N query feedback results sent by the data query party, wherein the N query feedback results are determined by N matching results, third encrypted query data corresponding to each matching result in the N matching results, and encrypted label data of the third encrypted query data, the N matching results are obtained by matching the first mapping encrypted data with second mapping encrypted data in each data storage space of N data storage spaces, the second mapping encrypted data in an i th data storage space of the N data storage spaces is data obtained by processing second encrypted query data by using a j th hash mapping algorithm of N hash mapping algorithms, the second encrypted query data is data obtained by processing preset non-plain query data of the data provider by using the homomorphic encryption and the pseudo-random function, and the N hash mapping algorithms include the first hash mapping algorithm; a decryption result of the third encrypted query data in each query feedback result of the N query feedback results includes a first type of decryption result or a second type of decryption result, the first type of decryption result is used to indicate that the i th query feedback result of the N query feedback results includes the first encrypted label data corresponding to the first mapping encrypted data, and the second type of decryption result is used to indicate that the target mapping encrypted data corresponding to the first mapping encrypted data is not matched from the second mapping encrypted data of the i th data storage space; The determining module is configured to determine the query label data according to the decryption result of the N query feedback results.

14. A computer device, the device comprising: A processor and a memory storing computer program instructions; The processor executes the computer program instructions to implement the steps of the data processing method in any one of claims 1-11.

15. A storage medium, the storage medium storing computer program instructions, the computer program instructions being executed by a processor to implement the steps of the data processing method in any one of claims 1-11.

16. A computer program product, the program product being stored in a storage medium, the program product being executed by at least one processor to implement the steps of the data processing method in any one of claims 1-11.

Citation Information

Patent Citations

  • Data anonymous trace query method and device, storage medium and electronic equipment

    CN116680324A

  • Private query method, apparatus and system, and storage medium

    WO2024077948A1