Data summation and query methods, devices, storage media, and program products
By setting multiple query bits in the query bit set to correspond one-to-one with users, and then re-randomizing their sum into a challenge ciphertext for verification, the problem of user privacy leakage caused by malicious queries by data query parties is solved, and the security of the data summation query method is improved.
Patent Information
- Application Number
- CN202411262005.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-09
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2044-09-09
AI Technical Summary
In existing technologies, the problem of data querying parties maliciously sending query requests targeting individual users, leading to the leakage of user privacy, has not been effectively resolved.
By setting multiple query bits in the query bit set to correspond one-to-one with multiple users, and rerandomizing the sum of the query bits into challenge ciphertext, a set of commitment values is generated for verification. This ensures that the sum of each query bit in the query bit set is different from the plaintext corresponding to the preset limit ciphertext, thus avoiding query requests from a single user.
This approach prevents malicious requests from the data query client targeting a single user under reasonable pre-defined plaintext conditions, thereby improving the security of the data summation query method and protecting user privacy.
Smart Images

Figure CN119203224B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data security technology, and in particular to a data summation query method, device, storage medium, and program product. Background Technology
[0002] In related technologies, to ensure the privacy of both parties involved in data queries, the data querying party can send an encrypted summation query request to the data storage party to obtain the encrypted query result and complete the task analysis. However, if the data querying party maliciously sends an encrypted query request targeting a single user, it can still lead to the leakage of that user's privacy on the data storage party. Therefore, how to avoid query requests targeting a single user that result in the exposure of user privacy urgently needs to be addressed. Summary of the Invention
[0003] The main purpose of this application is to provide a data summation query method, device, storage medium, and program product, which aims to solve the technical problem of how to avoid user privacy exposure caused by query requests targeting a single user.
[0004] To achieve the above objectives, this application proposes a data summation query method, applied to a data query terminal. The data summation query method includes:
[0005] Send a query bit set to the data storage terminal; multiple query bits in the query bit set correspond one-to-one with multiple users. When the query request includes the corresponding user, the value of the query bit is the ciphertext of the first preset value.
[0006] The data storage terminal receives a set of challenge ciphertexts. The set of challenge ciphertexts is obtained by the data storage terminal re-randomizing the initial challenge ciphertexts for each initial challenge ciphertext in the initial challenge ciphertext set using the corresponding first random number in the first random number set. The initial challenge ciphertexts include the sum of all query bits in the query bit set.
[0007] Based on the comparison results between the challenge plaintext corresponding to each challenge ciphertext in the challenge ciphertext set and the preset plaintext corresponding to the preset restriction ciphertext, a set of commitment values is generated;
[0008] Send the set of commitment values to the data storage terminal;
[0009] Receive the query results returned by the data storage terminal; the query results are obtained by querying the database based on the query bit set after the data storage terminal verifies the commitment value set.
[0010] In one embodiment, before the step of sending the set of commitment values to the data storage terminal, the data summation query method further includes:
[0011] Receive the first set of random numbers and the initial challenge ciphertext set sent by the data storage terminal;
[0012] For each initial challenge ciphertext, the corresponding first random number in the first random number set is used to rerandomize the initial challenge ciphertext to obtain an intermediate ciphertext set;
[0013] For each intermediate ciphertext in the intermediate ciphertext set, compare the intermediate ciphertext with the corresponding challenge ciphertext in the challenge ciphertext set to obtain the first verification result;
[0014] If the first verification result is successful, then the step of sending the set of commitment values to the data storage terminal will be executed.
[0015] In one embodiment, the step of generating a set of commitment values based on the comparison results between each challenge ciphertext in the challenge ciphertext set and a preset restriction ciphertext includes:
[0016] For each comparison result, calculate the first hash value of the comparison result and the corresponding second random number in the second random number set;
[0017] Based on all the first hash values, obtain the set of commitment values;
[0018] The steps of sending the set of commitment values to the data storage end include:
[0019] The commitment value set, the second random number set, and each comparison result are sent to the data storage terminal so that the data storage terminal can calculate the third hash value of the comparison result and the corresponding second random number in the second random number set for each comparison result, and compare the commitment value with the corresponding third hash value for each commitment value in the commitment value set to verify the commitment value set.
[0020] In one embodiment, before the step of sending the query bit set to the data storage terminal, the method further includes:
[0021] The first ciphertext is obtained by encrypting the preset plaintext corresponding to the preset restricted ciphertext using a third random number.
[0022] The preset plaintext is encrypted using the fourth random number to obtain the second ciphertext;
[0023] An auxiliary random number is obtained based on the third random number, the fourth random number, and the second hash value of the first and second ciphertexts;
[0024] Send the first ciphertext, the second ciphertext, and the auxiliary random number to the data storage terminal;
[0025] The data storage terminal receives a second verification result, which is obtained by the data storage terminal verifying the first ciphertext or the second ciphertext based on the second hash value and the auxiliary random number.
[0026] If the second verification result is successful, then the first or second ciphertext is used as the preset restricted ciphertext, and the step of sending the query bit set to the data storage terminal is executed.
[0027] Furthermore, to achieve the above objectives, this application also proposes a data summation query method, applied to the data storage end. The data summation query method includes:
[0028] Receive the query bit set sent by the data query terminal; multiple query bits in the query bit set correspond one-to-one with multiple users. When the query request includes the corresponding user, the value of the query bit is the ciphertext of the first preset value.
[0029] For each initial challenge ciphertext in the initial challenge ciphertext set, the corresponding first random number in the first random number set is used to rerandomize the initial challenge ciphertext to obtain a challenge ciphertext set; the initial challenge ciphertext includes the sum of all query bits in the query bit set;
[0030] Send the set of challenge ciphertexts to the data query client;
[0031] Receive and verify the set of commitment values returned by the data query terminal; the set of commitment values is generated by the data query terminal based on the comparison results between the challenge plaintext corresponding to each challenge ciphertext in the challenge ciphertext set and the preset plaintext corresponding to the preset restriction ciphertext.
[0032] If the set of committed values passes verification, the database is queried based on the set of query bits to obtain the query results.
[0033] In one embodiment, before the step of receiving the query bit set sent by the data query terminal, the data summation query method further includes:
[0034] The system receives a first ciphertext, a second ciphertext, and an auxiliary random number sent by the data query terminal. The first ciphertext is obtained by the data query terminal using a third random number to encrypt a preset plaintext corresponding to a preset restricted ciphertext. The second ciphertext is obtained by the data query terminal using a fourth random number to encrypt a preset plaintext. The auxiliary random number is obtained by the data query terminal based on the third random number, the fourth random number, and the second hash value of the first and second ciphertexts.
[0035] Encrypt the preset plaintext using an auxiliary random number to obtain the third ciphertext;
[0036] Based on the first ciphertext, the second ciphertext, and the second hash value, the verification ciphertext is obtained;
[0037] Compare the third ciphertext with the verification ciphertext to obtain the second verification result;
[0038] If the second verification result is successful, then the first or second ciphertext is used as the preset restricted ciphertext, and the step of receiving the query bit set sent by the data query terminal is executed.
[0039] In one embodiment, the step of querying a database based on a query bit set to obtain query results includes:
[0040] For each query bit in the query bit set, retrieve the corresponding query data from the database;
[0041] The query results are obtained based on all the query data and the corresponding query bits.
[0042] In addition, to achieve the above objectives, this application also proposes a data summation query device, the device comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the data summation query method as described above.
[0043] In addition, to achieve the above objectives, this application also proposes a storage medium, which is a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the steps of the data summation and query method described above.
[0044] In addition, to achieve the above objectives, this application also provides a computer program product, which includes a computer program that, when executed by a processor, implements the steps of the data summation and query method described above.
[0045] One or more technical solutions proposed in this application have at least the following technical effects:
[0046] This application provides a data summation query method, device, storage medium, and program product. First, multiple query bits in a query bit set are assigned one-to-one correspondence with multiple users. During the data query process, the values of the query bits corresponding to the users in the query request are set to ciphertexts with a first preset value, so that the sum of all query bits in the query bit set can represent the number of users in the query request. Then, the sum of all query bits is rerandomized and used as the challenge ciphertext. Based on the comparison result between the challenge plaintext corresponding to the challenge ciphertext and the preset plaintext corresponding to the preset restriction ciphertext, a commitment value set is generated and verified. When the commitment value set passes verification, it indicates that the sum of all query bits in the query bit set matches the preset restriction ciphertext. When the verification of the commitment value set fails, it can be indicated that the sum of all query bits in the query bit set corresponds to the same plaintext as the preset restriction ciphertext. Therefore, by comparing the challenge plaintext corresponding to each challenge ciphertext in the commitment and verification challenge ciphertext set with the preset plaintext corresponding to the preset restriction ciphertext, it is possible to verify whether the sum of all query bits in the query bit set corresponds to a different plaintext as the preset restriction ciphertext. This verifies whether the number of users in the query request is different from the preset plaintext corresponding to the preset restriction ciphertext. With a reasonable preset plaintext, it can prevent the data query terminal from maliciously sending query requests targeting a single user, thereby exposing the user privacy of that single user and improving the security of the data summation query method. Attached Figure Description
[0047] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0048] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0049] Figure 1 This is a flowchart illustrating the first embodiment of the data summation query method of this application;
[0050] Figure 2 This is a flowchart illustrating the second embodiment of the data summation query method of this application;
[0051] Figure 3 for Figure 2 A flowchart illustrating the specific implementation method of the first phase in the middle;
[0052] Figure 4 for Figure 2 A flowchart illustrating the specific implementation method of the second phase in the middle;
[0053] Figure 5 This is a schematic diagram of the device structure of the hardware operating environment involved in the data summation and query method in the embodiments of this application.
[0054] The realization of the purpose, functional features and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0055] It should be understood that the specific embodiments described herein are merely illustrative of the technical solutions of this application and are not intended to limit this application.
[0056] To better understand the technical solution of this application, a detailed description will be provided below in conjunction with the accompanying drawings and specific implementation methods.
[0057] The main solution of this application embodiment is as follows: A query bit set is sent to the data storage terminal; multiple query bits in the query bit set correspond one-to-one with multiple users; when the query request includes the corresponding user, the value of the query bit is the ciphertext of a first preset value; a challenge ciphertext set is received from the data storage terminal; the challenge ciphertext set is obtained by the data storage terminal re-randomizing the initial challenge ciphertexts in the initial challenge ciphertext set using the corresponding first random number from the first random number set; the initial challenge ciphertext includes the sum of all query bits in the query bit set; a commitment value set is generated based on the comparison results between the challenge plaintext corresponding to each challenge ciphertext in the challenge ciphertext set and the preset plaintext corresponding to the preset restriction ciphertext; the commitment value set is sent to the data storage terminal; a query result is received from the data storage terminal; the query result is obtained by the data storage terminal after verifying the commitment value set; and then querying the database based on the query bit set.
[0058] With the rapid development of information technology, the volume of user data has increased dramatically. A large amount of user data is collected and stored. While this data may be compliant for the data storage provider, it is not permitted to be disclosed externally, such as patient information databases in medical departments and advertising company databases. Simultaneously, data query providers need to utilize this data for computational analysis tasks to improve efficiency and service quality, such as analyzing average disease incidence rates and compiling advertising revenue statistics. Both data query providers and individual users providing data desire the protection and confidentiality of certain private data, such as salary and age. However, under privacy requirements, there is a separation of rights between data analysts and data storage providers. Data analysts have access to but not visibility of the stored data, while data storage providers have access to but not visibility of the data analysts' query requests. Data analysts want to conceal their analytical targets, such as the groups they are surveying; individual users providing data want their data to remain confidential during the data analysis process. Therefore, directly using summation query services can lead to serious privacy issues. On the one hand, transmitting query requests in plaintext reveals the object of analysis; on the other hand, queries targeting a single objective expose the privacy of individual users.
[0059] In related technologies, for a database containing sensitive information of multiple users, many analytical tasks require summing specific data from a subset of users. Therefore, summation queries can be used to perform data retrieval. The data analyst can initiate a query request to the data storage provider containing the set of target users. The data storage provider retrieves the privacy-sensitive values of the target users, sums them, and returns the sums to the data analyst. Among these, summation query methods for privacy protection mainly include three types: cryptographic-based summation query methods, differential privacy-based summation query methods, and audit-based summation query methods.
[0060] Specifically, cryptographic-based summation query methods protect the privacy of the query process through cryptographic methods. Anonymization is achieved by encrypting or compressing the identities of users in the target user set to protect the privacy of the query target. In privacy intersection finding and techniques, in 2017, Ion et al. determined the intersection position under the premise of hiding the intersection through mechanisms such as exchange and achieved privacy summation through additive homomorphic encryption; in 2023, Tu et al. achieved secret sharing based on multi-point unintentional pseudo-random functions, and achieved privacy summation through permutation matrix privacy equality testing, additive homomorphic encryption, and unintentional transmission. In privacy batch summation retrieval techniques, in 2018, Patel et al. implemented summation retrieval of multiple subsets of a statistical database based on additive homomorphic encryption, multiplying the ciphertext bit vectors corresponding to different subsets with the database retrieval value and summing to obtain the query result; in 2021, Mughees et al. implemented privacy batch summation retrieval based on the principle of batch privacy information retrieval. It is evident that cryptographic summation query methods completely blind the target user set. While ensuring query privacy, this compromises the availability of the query request to the data storage provider, granting the queryer significant freedom. However, this can lead to abuse of query rights by the data queryer, sending query requests to a single user, resulting in malicious queries. Therefore, cryptographic summation query methods do not protect the query results; they only guarantee the privacy of the single query execution for the data queryer, failing to consider potential data leakage during the query process. This allows the data queryer to intrusively target a single user within the target user set to precisely query that individual user's sensitive data, leading to the leakage of that individual user's privacy.
[0061] Furthermore, differential privacy-based summation query methods introduce random noise into each query response, subjecting the final query result to sufficiently varianced random noise. This prevents the retrieved dataset from being distinguished from adjacent datasets to maintain privacy. For example, the Laplace mechanism proposed by Dwork et al. in 2006 can provide a summation query response mechanism that satisfies differential privacy. In 2021, Xiao et al. considered answering summation queries under differential privacy constraints in each query, adding privacy-preserving Gaussian noise to the query response and optimizing the covariance structure of the noise to meet fine-grained accuracy requirements while reducing privacy costs. However, differential privacy-based summation query methods introduce random noise into the query results, reducing their usability and hindering the data queryer's use and understanding of the results. Moreover, this method requires knowledge of the query request, raising privacy concerns for the data queryer.
[0062] Finally, the audit-based summation query method logs past query requests and their responses. Upon receiving a new query request, it first checks the log to see if the new request will leak individual user data from the statistical database. If the new query request is deemed safe (meaning the data queryer cannot deduce sensitive user data from the combination of the new request and previous query results), a response is provided. If the new query request is deemed to jeopardize user data, it is ignored. However, this audit-based summation query method requires the data storage provider to explicitly understand the data queryer's query request set, exposing the privacy of the data queryer's query instructions. This allows the data storage provider to infer their analytical tasks by analyzing the data queryer's query request set, which is the data queryer's privacy, and possibly even a trade secret, and should be kept hidden. Therefore, this method also carries the risk of privacy leakage for the data queryer.
[0063] In summary, data summation query methods in related technologies face challenges in avoiding query requests targeting a single user, which could lead to the exposure of user privacy, and in ensuring the privacy of the data querying party.
[0064] Therefore, this application provides a solution. First, multiple query bits in the query bit set are assigned one-to-one correspondence with multiple users. During the data query process, the values of the query bits corresponding to the users in the query request are set to ciphertexts with a first preset value, so that the sum of all query bits in the query bit set can represent the number of users in the query request. Then, the sum of all query bits is rerandomized and used as the challenge ciphertext. Based on the comparison result between the challenge plaintext corresponding to the challenge ciphertext and the preset plaintext corresponding to the preset restriction ciphertext, a commitment value set is generated and verified. When the commitment value set passes verification, it indicates that the sum of all query bits in the query bit set corresponds to plaintexts that are different from the preset restriction ciphertext. When the verification of the commitment value set fails, it can indicate that the sum of all query bits in the query bit set corresponds to the same plaintext as the preset restriction ciphertext. Therefore, by comparing the challenge plaintext corresponding to each challenge ciphertext in the commitment and verification challenge ciphertext set with the preset plaintext corresponding to the preset restriction ciphertext, it is possible to verify whether the sum of all query bits in the query bit set corresponds to a different plaintext as the preset restriction ciphertext. This verifies whether the number of users in the query request is different from the preset plaintext corresponding to the preset restriction ciphertext. With a reasonable preset plaintext, it can prevent the data query terminal from maliciously sending query requests targeting a single user, thereby exposing the user's privacy and improving the security of the data summation query method.
[0065] In addition, the query requests from the data query terminal in this application are sent to the data storage terminal in encrypted form, which hides the set of query users of the data query terminal. The data storage terminal can only know the encrypted location of the target user set corresponding to the query request, and cannot correspond to the actual users. Therefore, it cannot further infer and analyze the query task of the data query terminal, thus avoiding the leakage of query request privacy.
[0066] It should be noted that the executing entity in this embodiment can be a computing service device with data processing, network communication, and program execution functions, such as a tablet computer, personal computer, or mobile phone, or an electronic device or data summation and query device capable of performing the above functions. The following description uses a data summation and query device as an example to illustrate this embodiment and the subsequent embodiments. The data summation and query device may include a data query terminal and a data storage terminal.
[0067] Based on this, embodiments of this application provide a data summation query method, referring to... Figure 1 , Figure 1 This is a flowchart illustrating the first embodiment of the data summation query method of this application.
[0068] In this embodiment, the data summation query method is applied to the data query terminal, and the data summation query method may include steps S100 to S500:
[0069] Step S100: Send a query bit set to the data storage terminal.
[0070] In this set of query bits, multiple query bits correspond one-to-one with multiple users. When the query request includes the corresponding user, the value of the query bit is the ciphertext of the first preset value.
[0071] It should be noted that when a query request is received, the data query terminal generates a query bit set based on the request. The number of query bits in the query bit set is the same as the total number of users in the database of the data storage terminal, ensuring a one-to-one correspondence between multiple query bits and multiple users. The value of the query bit is either ciphertext of a first preset value or ciphertext of a second preset value, where the first preset value is 1 and the second preset value is 0. If the query request includes the corresponding user, the query bit value is the ciphertext of the first preset value; if the query request does not include the corresponding user, the query bit value is the ciphertext of the second preset value.
[0072] It is understandable that if the database on the data storage side contains user data for m users, and each user i corresponds to a protected privacy-sensitive value d... i Let i = 1, 2, ..., m; the data query process involves the data query terminal R, the data storage terminal S, the database D, the row numbers 1, 2, ..., m, and the target values d1, d2, ..., d1 corresponding to each row.m The data query method provided in this embodiment uses a query request Q and a query result q to determine a user set based on a single query request. The goal of this user set is to calculate the sum q of the privacy-sensitive values of all users in the set; thereafter, if the query request corresponding to the user set is answerable, the data storage end will return the sum value; otherwise, the query request corresponding to the user set will be rejected.
[0073] In practice, the data query client can generate an m-dimensional query bit vector b∈{0,1} based on the user set L in the query request. m Wherein, the i-th bit component b i The value of is as follows: Formula 1:
[0074]
[0075] Then, by encrypting each bit component in the m-dimensional query bit vector, the query bit set can be obtained.
[0076] In this embodiment, the bit components can be encrypted using a homomorphic encryption algorithm, and the value of the query bit is obtained as shown in Formula 2:
[0077] b i ′=Enc pk,r (b i )
[0078] b i ' is the i-th query bit in the query bit set b', Enc pk,r (x) represents the ciphertext obtained by encrypting plaintext x using the public key pk and the random number r. The homomorphic encryption algorithm scheme can include a key generation function Gen, an encryption function Enc, a decryption function Dec, and a rerandomization function Rand. Therefore, the public key pk and the random number r are determined by the functions in the homomorphic encryption algorithm.
[0079] In practical implementation, the homomorphic encryption algorithm is selected based on actual usage requirements. In one example, for the Paillier homomorphic encryption algorithm, during the key generation phase, λ-bit prime numbers p and q are randomly selected based on the security parameter λ, n = pq is calculated, and the public key pk = n and the private key sk = φ(n) are output, where φ is the Euler totient function, and φ(n) represents the number of numbers less than n and coprime to n. The data query end can obtain the public key pk = n and the private key sk = φ(n) from the key generation phase, encrypt the query bit vector, and send the public key to the data storage end. Specifically, in the encryption phase, Enc receives the input plaintext m ∈ Z. n Compete against the public key and randomly select a random number. Calculate and output the ciphertext c = Encpk,r (m)=(1+n) m ·r n mod n 2 During the decryption phase, Dec receives the input ciphertext c∈Z. n2 Given the public key pk and the private key sk, calculate and output the plaintext. During the rerandomization phase, Rand receives the input plaintext m∈Z. n Compete against the public key and randomly select a random number. The ciphertext is rerandomized, and the result takes the value c′=c·r. n modn 2 .
[0080] Step S200: Receive the challenge ciphertext set returned by the data storage terminal.
[0081] The challenge ciphertext set is obtained by the data storage end by rerandomizing the initial challenge ciphertexts in the initial challenge ciphertext set using the corresponding first random number from the first random number set. The initial challenge ciphertext includes the sum of all query bits in the query bit set.
[0082] It should be noted that this embodiment uses zero-knowledge proof to verify the query bit set in order to determine whether the corresponding query request can be answered.
[0083] First, during the verification process, after receiving the query bit set, the data storage terminal determines the challenge ciphertext set based on the query bit set and returns the challenge ciphertext set to the data query terminal so that the data query terminal can make a commitment.
[0084] In the specific implementation, the data storage terminal S receives the query bit set b′ and calculates each query bit b in the query bit set. i The sum of ′ and c1 is shown in Formula 3:
[0085]
[0086] Based on the properties of homomorphic encryption, c1 can be obtained as the ciphertext of the number of users corresponding to the user set in the query request.
[0087] Then, the data storage terminal S randomly selects k challenge numbers from the set {0,1}, denoted as o1,…,o k Randomly select k first random numbers r1,…,r k The first set of random numbers is obtained, and the first random number r is used to obtain the first set of random numbers. j Initial challenge ciphertext Rerandomization yields the challenge ciphertext The k newly obtained challenge ciphertexts are then sent as a challenge ciphertext set to the data query client R. When the challenge count is 0, the initial challenge ciphertext is... The initial challenge ciphertext is a pre-set restricted ciphertext, and the challenge count is 1. c1 corresponds to the challenge ciphertext. It can be generated using the following formula four:
[0088]
[0089] Rand is a rerandomization algorithm in homomorphic encryption. Rand(c,r) means rerandomizing the ciphertext c using a random number r.
[0090] Step S300: Generate a set of commitment values based on the comparison results between the challenge plaintext corresponding to each challenge ciphertext in the challenge ciphertext set and the preset plaintext corresponding to the preset restriction ciphertext.
[0091] Step S400: Send the set of commitment values to the data storage terminal.
[0092] Step S500: Receive the query results returned by the data storage terminal.
[0093] The query result is obtained by querying the database based on the query bit set after the data storage terminal verifies the commitment value set.
[0094] It should be noted that after receiving the challenge ciphertext set, the data query end needs to commit to the challenge ciphertext. During the commitment phase, the data query end commits to the comparison result between the challenge plaintext corresponding to the challenge ciphertext and the preset plaintext corresponding to the preset limit ciphertext, and returns the commitment value set to the data storage end. This allows the data storage end to verify and trust whether the sum of each query bit in the query bit set corresponds to a different plaintext than the preset limit ciphertext, and returns the query result based on the verification result.
[0095] In one feasible implementation, step S300 may include steps A310 to A320:
[0096] Step A310: For each comparison result, calculate the first hash value of the comparison result and the corresponding second random number in the second random number set.
[0097] Step A320: Obtain the set of commitment values based on all first hash values;
[0098] Correspondingly, step S400 may include step A410:
[0099] Step A410: Send the commitment value set, the second random number set, and each comparison result to the data storage terminal so that the data storage terminal can calculate the third hash value of the comparison result and the corresponding second random number in the second random number set for each comparison result, and compare the commitment value with the corresponding third hash value for each commitment value in the commitment value set to verify the commitment value set.
[0100] It should be noted that, firstly, the data query end can use the private key sk obtained by the homomorphic encryption algorithm to decrypt the challenge ciphertext c′. oj Given a preset restricted ciphertext, obtain the challenge plaintext and the preset plaintext. Compare the challenge plaintext and the preset plaintext to obtain k comparison results (cmp). j j = 1, ..., k. The alignment result is cmp. j The value of is as follows in Formula 5:
[0101]
[0102] c0 is the preset restricted ciphertext, and Dec is the decryption function of the homomorphic encryption algorithm. sk (c) represents the plaintext obtained by decrypting ciphertext c using the private key sk. j This indicates that the comparison result of the j-th challenge should be compared with the number of challenges selected in the j-th challenge. j Equally, specifically, when the challenge ciphertext and the preset restriction ciphertext correspond to different plaintexts, if o j =1, then If o j =0, then For each j, cmp j ==o j It is valid; however, when the challenge ciphertext corresponds to the same plaintext as the preset restriction ciphertext, It is impossible to achieve cmp for every j. j ==o j Established. Therefore, the subsequent data storage end can verify the cmp. j ==o j This is to verify whether the challenge ciphertext and the preset restriction ciphertext correspond to different plaintexts.
[0103] Then, the data query end can use the second random number set to make commitments to the comparison results, obtain a set of commitment values, and send the set of commitment values to the data storage end. The set of commitment values includes k commitment values, comm. j The commitment value is the first hash value of the comparison result and the corresponding second random number in the second random number set. The commitment value can be calculated using the following formula:
[0104] comm j =hash(op) j ||cmpj )
[0105] hash represents a collision-resistant hash function, op j It is the j-th random number in the second set of random numbers.
[0106] Subsequently, the data storage end can verify the set of committed values based on the second set of random numbers. The specific verification process is as follows: for each comparison result, the data storage end calculates the third hash value of the comparison result and the corresponding second random number in the second set of random numbers; for each committed value in the set of committed values, the committed value is compared with the corresponding third hash value.
[0107] In the specific implementation, the comparison result z′ between the commitment value and the corresponding third hash value i This can be expressed as Formula Seven below:
[0108] z′ j =(Open(o j ,op j ,comm j )==accept)
[0109] `open` is the reveal function of the commitment scheme used by the data query end. Typically, the reveal function corresponds to the commitment scheme of the data query end. In this embodiment, since the data query end chooses a commitment scheme based on a collision-resistant hash function, the data storage end can also choose a reveal scheme based on a collision-resistant hash function to calculate the comparison result `cmp`. j After obtaining the third hash value, the third hash value is compared with the corresponding commitment value comm. j A comparison is performed to verify whether the challenge ciphertext and the preset restriction ciphertext correspond to different plaintexts. The revelation function can be expressed as:
[0110]
[0111] That is, the calculation method of the third hash value is the same as that of the first hash value. The difference is that the third hash value is calculated by the data storage end based on the comparison result and the corresponding second random number, while the first hash value is calculated by the data query end based on the comparison result and the corresponding second random number.
[0112] Correspondingly, the methods for obtaining query results at the data storage end may include: querying the database to obtain the corresponding query data for each query bit in the query bit set; and obtaining the query results based on all the query data and the corresponding query bits.
[0113] It should be noted that the data storage terminal S can calculate the total comparison results of k challenges. The verification of the commitment value set is determined based on the overall comparison results. When z′=1, it indicates that the commitment value set has passed verification, and the data storage terminal retrieves the value d of each row i from database D. i Compare it with the corresponding bit b′ in the ciphertext query vector b′ i Multiply and sum to get the query result And send it to the data query terminal R. When z′=0, the query result is returned to the data query terminal R.
[0114] Understandably, after receiving the query result, the data query terminal checks if the query result is ⊥. If the query result is not ⊥, it uses the private key sk to decrypt the query result q′, thus obtaining the decrypted query result q.
[0115]
[0116] In a feasible implementation, before step S400, the data summation query method may further include: receiving a first set of random numbers and an initial challenge ciphertext set sent by the data storage terminal; for each initial challenge ciphertext, re-randomizing the initial challenge ciphertext using the corresponding first random number in the first set of random numbers to obtain an intermediate ciphertext set; for each intermediate ciphertext in the intermediate ciphertext set, comparing the intermediate ciphertext with the corresponding challenge ciphertext in the challenge ciphertext set to obtain a first verification result; if the first verification result is a successful verification, then step S400 is executed.
[0117] It should be noted that before sending the set of commitment values to the data storage terminal, the data query terminal can also perform a validity verification on the challenge ciphertext set to verify whether the challenge ciphertext was obtained by re-randomizing the initial challenge ciphertext using a first random number. The principle of validity verification is that the data query terminal re-randomizes each initial challenge ciphertext using the corresponding first random number to obtain an intermediate ciphertext. The validity of the challenge ciphertext set is verified by comparing the consistency between the intermediate ciphertext generated by the data query terminal and the challenge ciphertext generated by the data storage terminal.
[0118] Among them, the comparison result z between the middle ciphertext and the corresponding challenge ciphertext j The value of is as follows in Formula 8:
[0119]
[0120] The first verification result is shown in Formula Nine:
[0121]
[0122] z represents the first verification result, Λ represents consecutive XOR, j represents the j-th challenge, and k represents the number of challenges. j This represents the comparison result between the j-th intermediate ciphertext and the corresponding challenge ciphertext.
[0123] Understandably, the data query end can determine z i == 1, to verify the legality of the j-th challenge ciphertext. Then, when z ≠ 1, it is determined that the challenge ciphertext set fails the verification and a ⊥ is sent to the data storage terminal S. When z = 1, it is determined that the challenge ciphertext set passes the verification and the commitment value set and the second random number set are sent to the data storage terminal so that the data storage terminal can verify the commitment value set.
[0124] In a feasible implementation, before step S100, the data summation query method may further include: encrypting the preset plaintext corresponding to the preset restricted ciphertext using a third random number to obtain a first ciphertext; encrypting the preset plaintext using a fourth random number to obtain a second ciphertext; obtaining an auxiliary random number based on the third random number, the fourth random number, and the second hash values of the first and second ciphertexts; sending the first ciphertext, the second ciphertext, and the auxiliary random number to the data storage terminal; receiving a second verification result returned by the data storage terminal, wherein the second verification result is obtained by the data storage terminal verifying the first or second ciphertext based on the second hash value and the auxiliary random number; if the second verification result is a successful verification, then the first or second ciphertext is used as the preset restricted ciphertext, and step S100 is executed.
[0125] It should be noted that before data querying, the key and preset restriction ciphertext can be shared and verified at the data query end and data storage end. The preset restriction ciphertext is the ciphertext corresponding to the preset plaintext. To prevent the data query end from maliciously sending query requests targeting a single user, the preset plaintext is the value 1.
[0126] In the specific implementation, during the key sharing phase, the key generation algorithm of the homomorphic encryption algorithm can be run on the data query terminal to generate a public key pk and a private key sk. The public key pk is sent to the data storage terminal, and the private key sk is stored locally, thus completing the key sharing.
[0127] During the sharing and verification phase of the pre-defined restricted ciphertext, the data query terminal can use the third random number E to encrypt the pre-defined plaintext corresponding to the pre-defined restricted ciphertext to obtain the first ciphertext M; use the fourth random number F to encrypt the pre-defined plaintext to obtain the second ciphertext N; and use Formula 10 to calculate the second hash value e; Formula 10 is:
[0128] e = hash(pk||M||N)
[0129] Then, using Formula 11, based on the third random number, the fourth random number, and the second hash value, the auxiliary random number Z is obtained; Formula 11 is:
[0130] Z = E·F e
[0131] Z is the auxiliary random number, E is the third random number, F is the fourth random number, and e is the second hash value.
[0132] The first ciphertext, the second ciphertext, and the auxiliary random number are sent to the data storage terminal so that the data storage terminal can verify the first ciphertext or the second ciphertext based on the second hash value and the auxiliary random number, and determine the preset restricted ciphertext.
[0133] Correspondingly, the method for the data storage terminal to verify the first ciphertext or the second ciphertext may include: receiving the first ciphertext, the second ciphertext, and an auxiliary random number sent by the data query terminal; the first ciphertext is obtained by the data query terminal encrypting the preset plaintext corresponding to the preset restricted ciphertext using a third random number; the second ciphertext is obtained by the data query terminal encrypting the preset plaintext using a fourth random number; the auxiliary random number is obtained by the data query terminal based on the third random number, the fourth random number, and the second hash value of the first ciphertext and the second ciphertext; encrypting the preset plaintext using the auxiliary random number to obtain the third ciphertext; obtaining the verification ciphertext based on the first ciphertext, the second ciphertext, and the second hash value; comparing the third ciphertext and the verification ciphertext to obtain a second verification result; if the second verification result is a successful verification, then the first ciphertext or the second ciphertext is used as the preset restricted ciphertext, and the step of receiving the query bit set sent by the data query terminal is executed.
[0134] It should be noted that the data storage end can verify the generation process of the first or second ciphertext based on the auxiliary random number, and then verify whether the plaintext corresponding to the received first or second ciphertext is the preset plaintext. By comparing the verification ciphertext obtained from the received ciphertext with the third ciphertext obtained from the encryption based on the auxiliary random number, the distribution and verification of the preset restricted ciphertext can be realized, thereby achieving the purpose of sharing the preset restricted ciphertext between the data query end and the data storage end.
[0135] In practical implementation, the data storage end can use Formula Twelve to encrypt the preset plaintext using an auxiliary random number to obtain the third ciphertext v1; Formula Twelve is:
[0136] v1 = Enc pk,Z (1)
[0137] Using Formula Thirteen, the verification ciphertext v2 is obtained based on the first ciphertext, the second ciphertext, and the second hash value; Formula Thirteen is:
[0138]
[0139] n is the parameter of the homomorphic encryption algorithm, satisfying public key pk = n, private key sk = φ(n), and φ is Euler's totient function.
[0140] Where, since v1 = Enc pk,Z (1)=(1+n)·Z n = (1+n)·(E·Fe ) n = (1+n)·E n ·F en v2 = M·F en Therefore, if v1 and v2 are equal, it means that c0 = (1 + n)·E n This means that M is indeed ciphertext containing 1s. Therefore, the data storage end can verify whether M or N is ciphertext containing 1s by comparing the values of v1 and v2.
[0141] Understandably, if the data storage terminal verifies ciphertext where M or N is 1, the second verification result is considered successful. The first or second ciphertext can then be used as a preset restricted ciphertext, and a successful reception signal of the preset restricted ciphertext can be sent to the data query terminal, allowing the data query terminal to send a query request to the data storage terminal. If the data storage terminal verifies ciphertext where M or N is not 1, the second verification result is considered unsuccessful, and the data storage terminal can reject the query request from the data query terminal.
[0142] Therefore, this embodiment provides a data summation query method. By comparing the challenge plaintext corresponding to each challenge ciphertext in the commitment and verification challenge ciphertext set with the preset plaintext corresponding to the preset restriction ciphertext, it can verify whether the sum of each query bit in the query bit set corresponds to a different plaintext than the preset restriction ciphertext. This realizes the verification of whether the number of users in the query request is different from the preset plaintext corresponding to the preset restriction ciphertext. With a reasonable preset plaintext, it can prevent the data query terminal from maliciously sending query requests targeting a single user, which would expose the user privacy of that single user, thus improving the security of the data summation query method.
[0143] In addition, in this embodiment, the query request from the data query terminal is sent to the data storage terminal in encrypted form, which hides the set of query users of the data query terminal. The data storage terminal can only know the encrypted location of the target user set corresponding to the query request, and cannot correspond to the actual users. Therefore, it cannot further reason and analyze the query task of the data query terminal, thus avoiding the leakage of query request privacy.
[0144] Based on the first embodiment of this application, in the second embodiment of this application, the same or similar content as in the first embodiment can be referred to the above description, and will not be repeated hereafter. Based on this, a data summation query method is applied to a data storage terminal. The data summation query method may include: receiving a query bit set sent by a data query terminal; multiple query bits in the query bit set correspond one-to-one with multiple users, and when the query request includes the corresponding user, the value of the query bit is a ciphertext of a first preset value; for each initial challenge ciphertext in the initial challenge ciphertext set, using the corresponding first random number in the first random number set, re-randomizing the initial challenge ciphertext to obtain a challenge ciphertext set; the initial challenge ciphertext includes the sum of all query bits in the query bit set; sending the challenge ciphertext set to the data query terminal; receiving and verifying a commitment value set returned by the data query terminal; the commitment value set is generated by the data query terminal based on the comparison result between the challenge plaintext corresponding to each challenge ciphertext in the challenge ciphertext set and the preset plaintext corresponding to the preset restriction ciphertext; if the commitment value set passes verification, querying the database based on the query bit set to obtain the query result.
[0145] In one feasible implementation, before the step of receiving the query bit set sent by the data query terminal, the data summation query method further includes: receiving a first ciphertext, a second ciphertext, and an auxiliary random number sent by the data query terminal; the first ciphertext is obtained by the data query terminal encrypting a preset plaintext corresponding to a preset restriction ciphertext using a third random number; the second ciphertext is obtained by the data query terminal encrypting the preset plaintext using a fourth random number; the auxiliary random number is obtained by the data query terminal based on the third random number, the fourth random number, and the second hash value of the first ciphertext and the second ciphertext; the preset plaintext is encrypted using the auxiliary random number to obtain a third ciphertext; a verification ciphertext is obtained based on the first ciphertext, the second ciphertext, and the second hash value; the third ciphertext and the verification ciphertext are compared to obtain a second verification result; if the second verification result is a successful verification, the first ciphertext or the second ciphertext is used as the preset restriction ciphertext, and the step of receiving the query bit set sent by the data query terminal is executed.
[0146] In one feasible implementation, the step of querying the database based on the query bit set to obtain query results includes: querying the database for each query bit in the query bit set to obtain corresponding query data; and obtaining query results based on all query data and the corresponding query bits.
[0147] It is understood that the data summation query method provided in this embodiment is the data summation query method executed by the data storage terminal corresponding to the data query terminal in Embodiment 1 above. The data summation query method provided in this embodiment adopts the data summation query method in Embodiment 1 above, and can solve the technical problem of how to avoid user privacy exposure caused by query requests targeting a single user. Compared with related technologies, the beneficial effects of the data summation query method provided in this embodiment are the same as those of the data summation query method provided in Embodiment 1 above, and other technical features in the data summation query method executed by the data storage terminal in this embodiment are the same as those disclosed in Embodiment 1 above, and will not be repeated here.
[0148] In summary, referring to Figures 2 to 4 , Figure 2 This is a flowchart illustrating the second embodiment of the data summation query method of this application. Figure 3 for Figure 2 A flowchart illustrating a specific implementation method for the first phase of the project. Figure 4 for Figure 2 A flowchart illustrating the specific implementation method of the second phase.
[0149] like Figure 2 As shown, the data summation query method provided in this embodiment can include two stages. The first stage is a homomorphic ciphertext sharing method, in which the sharing and verification of the key and preset restricted ciphertext can be completed at the data query end and the data storage end.
[0150] In the second phase, a zero-knowledge proof of homomorphic ciphertext inequality is introduced to verify that the data query client did not send a precise query targeting a single user. Specifically, the data query client initiates a query request, and the data storage client uses a zero-knowledge proof to verify that the sum of the query bits in the query bit set included in the query request corresponds to a different plaintext than the preset restricted ciphertext received in the first phase. This verifies that the size of the user set in the query request is not 1. After passing the verification, the correct query result is sent, avoiding data leakage caused by precise queries.
[0151] Specifically, such as Figure 3As shown, the homomorphic ciphertext sharing method proposed in the first stage is a process in which the verifier receives the ciphertext c obtained by the prover using Paillier encryption on a public plaintext m, and verifies the ciphertext. Specifically, it includes the following steps: The prover determines a first random number r and a second random number r′ based on the n of the Paillier algorithm. Using the first random number and the Paillier homomorphic encryption public key pk, the prover encrypts m to obtain ciphertext c0. Using the second random number and the Paillier homomorphic encryption public key pk, the prover encrypts m to obtain ciphertext a. Based on the Paillier homomorphic encryption public key, ciphertext c, and a, the prover uses a hash algorithm to obtain a state value e. Based on the first random number, the second random number, and the state value, the prover calculates a random parameter Z. The prover then sends the Paillier homomorphic encryption public key, ciphertext c,a, and random parameter Z to the verifier. The verifier uses the Paillier homomorphic encryption public key and random parameter Z to encrypt m to obtain a first result v1. Based on the ciphertext c,a, the verifier calculates a second result v2 = c·a. e / (1+n) me The validity of the ciphertext c is verified by comparing the first and second results. It can be seen that v1 = Enc pk,Z (m)=(1+n) m ·Z n = (1+n) m ·(r·r′ e ) n = (1+n) m ·r n ·r′ en v2=c·r′ en The legitimacy of the ciphertext generation process can be verified by subtracting random terms. In the first stage, the data querying party uses this method to prove to the data storage party that the transmitted ciphertext is 1, that is, setting m=1.
[0152] like Figure 4 As shown, the homomorphic ciphertext inequality zero-knowledge proof introduced in the second stage is used to prove to the verifier that the plaintexts corresponding to the shared ciphertexts c0 and c1 are not equal. In this embodiment, the prover is the data queryer, and the verifier is the data storage provider. The two ciphertexts they hold are c0, the ciphertext with the value 1 shared in the first stage, and c1, the sum of each component in the bit vector of the query request (i.e., the ciphertext of the number of users in the user set corresponding to the query request). Thus, the detection of user requests can be effectively achieved, rejecting malicious and precise queries from the data queryer. The prover holds the Paillier homomorphic encryption public key pk = n and the private key sk = φ(n), and the verifier holds the homomorphic encryption public key pk = n.
[0153] In addition, during the zero-knowledge proof process of unequal homomorphic ciphertexts, the verifier randomly generates a set of challenge bits, b, and uses the Paillier homomorphic encryption public key to re-randomize the corresponding ciphertext in the challenge bit set to generate a set of challenge ciphertexts. The verifier sends this set of challenge ciphertexts to the prover, requesting the prover to guess the challenge bits by comparing the challenge ciphertexts with c0. In the commitment phase, the prover decrypts the challenge ciphertexts and compares them with c0. After inverting the result to obtain the comparison result cmp, the prover selects a random number op, uses a collision-resistant hash-based commitment scheme to calculate the commitment value hash(op||cmp), and sends the commitment value to the verifier. During this process, the verifier also sends the challenge bits and the random number used for re-randomization to the prover. The prover, based on the challenge bits and this random number, uses the Paillier homomorphic encryption public key to re-randomize the ciphertext corresponding to the challenge bits and compares it with the received challenge ciphertext to verify the legitimacy of the challenge ciphertext. After the validity of the challenge ciphertext is verified, the prover sends a random parameter `op` to the verifier. The verifier then reveals the commitment based on the random number `op` and the comparison result `cmp`, calculates `hash(op||b)`, and compares it with the commitment value sent by the prover. If they are equal, the single challenge verification passes. It can be seen that when the two ciphertexts to be verified correspond to different plaintexts, the prover can always correctly obtain the challenge bits and complete the verification. However, when the two ciphertexts correspond to the same plaintext, the prover's probability of guessing correctly in a single challenge is 1 / 2. After k challenges, the probability of the prover guessing correctly decreases to 1 / 2. k In practice, to reduce the number of communication rounds, the verifier and the proviser each summarize the challenge ciphertexts from k verification interactions into a challenge ciphertext set before sending it.
[0154] This application provides a data summation and query device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, which are executed by the at least one processor to enable the at least one processor to perform the data summation and query method in Embodiment 1 above.
[0155] The following is for reference. Figure 5 The diagram illustrates a structural schematic of a data summation query device suitable for implementing embodiments of this application. The data summation query device in embodiments of this application may include, but is not limited to, mobile terminals such as laptops, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), etc., and fixed terminals such as desktop computers. Figure 5 The data summation and query device shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.
[0156] like Figure 5 As shown, the data summation and query device may include a processing unit 1001 (e.g., a central processing unit, a graphics processing unit, etc.) that can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1002 or a program loaded from a storage device 1003 into a random access memory (RAM) 1004. The RAM 1004 also stores various programs and data required for the operation of the data summation and query device. The processing unit 1001, ROM 1002, and RAM 1004 are interconnected via a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to the I / O interface 1006: input devices 1007 including, for example, a touchscreen, touchpad, keyboard, mouse, image sensor, microphone, etc.; output devices 1008 including, for example, a liquid crystal display (LCD), speaker, etc.; storage devices 1003 including, for example, magnetic tape, hard disk, etc.; and communication devices 1009. Communication device 1009 allows the data summing and querying device to communicate wirelessly or wiredly with other devices to exchange data. Although the figures show data summing and querying devices with various systems, it should be understood that it is not required to implement or possess all of the systems shown. More or fewer systems may be implemented alternatively.
[0157] Specifically, according to the embodiments disclosed in this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from storage device 1003, or installed from ROM 1002. When the computer program is executed by processing device 1001, it performs the functions defined in the methods of the embodiments disclosed in this application.
[0158] The data summation query device provided in this application, employing the data summation query method described in the above embodiments, can solve the technical problem of how to avoid user privacy exposure caused by query requests targeting a single user. Compared with related technologies, the beneficial effects of the data summation query device provided in this application are the same as those of the data summation query method provided in the above embodiments, and other technical features in this data summation query device are the same as those disclosed in the previous embodiment method, and will not be repeated here.
[0159] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any suitable manner in one or more embodiments or examples.
[0160] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0161] This application provides a computer-readable storage medium having computer-readable program instructions (i.e., a computer program) stored thereon, the computer-readable program instructions being used to execute the data summation query method in the above embodiments.
[0162] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.
[0163] The aforementioned computer-readable storage medium may be included in the data summing and querying device; or it may exist independently and not assembled into the data summing and querying device.
[0164] The aforementioned computer-readable storage medium carries one or more programs. When these programs are executed by the data summation and query device, the data summation and query device causes the data summation and query device to: send a query bit set to the data storage terminal; each query bit in the query bit set corresponds one-to-one with a user, and when the query request includes the corresponding user, the value of the query bit is a ciphertext of a first preset value; receive a challenge ciphertext set returned by the data storage terminal; the challenge ciphertext set is obtained by the data storage terminal re-randomizing the initial challenge ciphertexts in the initial challenge ciphertext set using the corresponding first random number from the first random number set, and the initial challenge ciphertext includes the sum of all query bits in the query bit set; generate a commitment value set based on the comparison results between the challenge plaintext corresponding to each challenge ciphertext in the challenge ciphertext set and the preset plaintext corresponding to the preset restriction ciphertext; send the commitment value set to the data storage terminal; receive the query result returned by the data storage terminal; and obtain the query result by querying the database based on the query bit set after the data storage terminal verifies that the commitment value set is valid.
[0165] Computer program code for performing the operations of this application can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, and C++, and conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a Local Area Network (LAN) or a Wide Area Network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0166] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0167] The modules described in the embodiments of this application can be implemented in software or hardware. The names of the modules do not necessarily limit the functionality of the unit itself.
[0168] The readable storage medium provided in this application is a computer-readable storage medium that stores computer-readable program instructions (i.e., a computer program) for executing the above-described data summation query method. This solves the technical problem of how to avoid exposing user privacy due to query requests targeting a single user. Compared with related technologies, the beneficial effects of the computer-readable storage medium provided in this application are the same as those of the data summation query method provided in the above embodiments, and will not be repeated here.
[0169] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the data summation and query method described above.
[0170] The computer program product provided in this application solves the technical problem of how to avoid exposing user privacy due to query requests targeting a single user. Compared with related technologies, the beneficial effects of the computer program product provided in this application are the same as those of the data summation query method provided in the above embodiments, and will not be repeated here.
[0171] The above description is only a part of the embodiments of this application and does not limit the patent scope of this application. All equivalent structural transformations made under the technical concept of this application and using the contents of the specification and drawings of this application, or direct / indirect applications in other related technical fields, are included in the patent protection scope of this application.
Claims
1. A data summation query method, characterized in that, The data summation query method, applied to the data query terminal, includes: Send a set of query bits to the data storage terminal; in the set of query bits, multiple query bits correspond one-to-one with multiple users, and when the query request includes the corresponding user, the value of the query bit is the ciphertext of the first preset value; The data storage terminal receives a set of challenge ciphertexts returned by the data storage terminal. The set of challenge ciphertexts is obtained by the data storage terminal re-randomizing the initial challenge ciphertexts in the initial challenge ciphertext set using the corresponding first random number from the first random number set. The initial challenge ciphertexts include the sum of all query bits in the query bit set. Based on the comparison results between the challenge plaintext corresponding to each challenge ciphertext in the challenge ciphertext set and the preset plaintext corresponding to the preset restriction ciphertext, a commitment value set is generated; Send the set of commitment values to the data storage terminal; The system receives the query results returned by the data storage terminal; the query results are obtained by the data storage terminal after verifying that the commitment value set is valid, and then querying the database based on the query bit set.
2. The data summation query method as described in claim 1, characterized in that, Before the step of sending the set of commitment values to the data storage terminal, the data summation query method further includes: Receive the first set of random numbers and the initial challenge ciphertext set sent by the data storage terminal; For each of the initial challenge ciphertexts, the initial challenge ciphertexts are rerandomized using the first random number corresponding to the first random number set to obtain an intermediate ciphertext set; For each intermediate ciphertext in the intermediate ciphertext set, the intermediate ciphertext is compared with the corresponding challenge ciphertext in the challenge ciphertext set to obtain the first verification result; If the first verification result is successful, then the step of sending the set of commitment values to the data storage terminal is executed.
3. The data summation query method as described in claim 1, characterized in that, The step of generating a set of commitment values based on the comparison results between each challenge ciphertext in the challenge ciphertext set and the preset restriction ciphertext includes: For each of the comparison results, calculate the first hash value of the comparison result and the corresponding second random number in the second random number set; Based on all the first hash values, obtain the set of commitment values; The step of sending the set of commitment values to the data storage terminal includes: The commitment value set, the second random number set, and each comparison result are sent to the data storage terminal, so that the data storage terminal calculates the third hash value of the comparison result and the corresponding second random number in the second random number set for each comparison result, and compares the commitment value with the corresponding third hash value for each commitment value in the commitment value set to verify the commitment value set.
4. The data summation query method as described in claim 1, characterized in that, Before the step of sending the query bit set to the data storage terminal, the method further includes: The preset plaintext corresponding to the preset restricted ciphertext is encrypted using a third random number to obtain the first ciphertext; The preset plaintext is encrypted using a fourth random number to obtain the second ciphertext; An auxiliary random number is obtained based on the third random number, the fourth random number, and the second hash value of the first ciphertext and the second ciphertext; The first ciphertext, the second ciphertext, and the auxiliary random number are sent to the data storage terminal; The data storage terminal receives a second verification result, which is obtained by the data storage terminal verifying the first ciphertext or the second ciphertext based on the second hash value and the auxiliary random number. If the second verification result is successful, then the first ciphertext or the second ciphertext is used as the preset restricted ciphertext, and the step of sending the query bit set to the data storage terminal is executed.
5. A data summation query method, characterized in that, Applied to the data storage end, the data summation query method includes: The system receives a set of query bits sent by the data query terminal; each query bit in the set corresponds to a user, and when the query request includes the corresponding user, the value of the query bit is the encrypted value of a first preset value. For each initial challenge ciphertext in the initial challenge ciphertext set, the initial challenge ciphertext is rerandomized using the corresponding first random number from the first random number set to obtain a challenge ciphertext set; the initial challenge ciphertext includes the sum of all query bits in the query bit set; Send the set of challenge ciphertexts to the data query terminal; Receive and verify the set of commitment values returned by the data query terminal; the set of commitment values is generated by the data query terminal based on the comparison results between the challenge plaintext corresponding to each challenge ciphertext in the challenge ciphertext set and the preset plaintext corresponding to the preset restriction ciphertext. If the set of commitment values passes verification, the database is queried based on the set of query bits to obtain the query results.
6. The data summation query method as described in claim 5, characterized in that, Before the step of receiving the query bit set sent by the data query terminal, the data summation query method further includes: The system receives a first ciphertext, a second ciphertext, and an auxiliary random number sent by the data query terminal. The first ciphertext is obtained by the data query terminal encrypting the preset plaintext corresponding to the preset restricted ciphertext using a third random number. The second ciphertext is obtained by the data query terminal encrypting the preset plaintext using a fourth random number. The auxiliary random number is obtained by the data query terminal based on the third random number, the fourth random number, and the second hash value of the first ciphertext and the second ciphertext. The preset plaintext is encrypted using the auxiliary random number to obtain the third ciphertext; Based on the first ciphertext, the second ciphertext, and the second hash value, the verification ciphertext is obtained; By comparing the third ciphertext and the verification ciphertext, a second verification result is obtained; If the second verification result is successful, then the first ciphertext or the second ciphertext is used as the preset restricted ciphertext, and the step of receiving the query bit set sent by the data query terminal is executed.
7. The data summation query method as described in claim 5, characterized in that, The step of querying the database based on the query bit set to obtain query results includes: For each query bit in the query bit set, the corresponding query data is retrieved from the database; The query result is obtained based on all the query data and the corresponding query bits.
8. A data summation and query device, characterized in that, The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the data summation query method as described in any one of claims 1 to 7.
9. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, it implements the steps of the data summation query method as described in any one of claims 1 to 7.
10. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the steps of the data summation query method as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Privacy data query method and device based on smart contract
CN110580417A
Threshold multi-keyword search method capable of resisting off-line keyword guess and subversive attack
CN117335971A