Data transmission method, device, equipment and storage medium based on homomorphic encryption

By using homomorphic encryption technology in data transmission, query requests are encrypted, which solves the problem of poor confidentiality of data transmission in the prior art, and achieves high efficiency and security of data transmission.

CN119382863BActive Publication Date: 2025-05-20INST OF APPLIED MATHEMATICS HEBEI ACADEMY OF SCI
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411974683.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-05-20
Estimated Expiration
2044-12-31

AI Technical Summary

Technical Problem

During the data sharing process, existing data transmission methods are poorly confidential, which increases the risk of data leakage.

Method used

Using a data transmission method based on homomorphic encryption, the query request is encrypted through the homomorphic encryption parameters of the target mechanism, the first data is generated, and transmitted to the target mechanism without decryption, and the second data containing the corresponding data of the query request is generated, and finally decrypted the second data using a private key to obtain the target data.

Benefits of technology

It effectively guarantees the security of data during transmission, protects the privacy of data, improves the efficiency and flexibility of data processing, and simplifies the data processing process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119382863B_ABST
    Figure CN119382863B_ABST
Patent Text Reader

Abstract

The present disclosure provides a data transmission method, device, equipment and storage medium based on homomorphic encryption, which belongs to the field of data transmission technology. The method includes: encrypting a query request based on a homomorphic encryption parameter of a target organization to obtain first data, and sending the first data to the target organization; the first data is used to instruct the target organization to generate second data containing data corresponding to the query request; the homomorphic encryption parameter includes a first public key; receiving the second data sent by the target organization, the second data is data obtained by the target organization by fusing the original data based on the first data based on a homomorphic encryption algorithm; decrypting the second data based on a private key to obtain the target data. The data transmission method, device, equipment and storage medium based on homomorphic encryption provided by the present disclosure can improve the security of data transmission and improve computing efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure belongs to the technical field of data transmission, and more specifically, relates to a data transmission method, device, equipment, and storage medium based on homomorphic encryption. Background Art

[0002] With the advent of the big data era, data sharing is required between different institutions. During the data sharing process, how to protect the privacy and data security of each participating party has become an urgent problem to be solved. The existing data transmission methods have poor confidentiality. In some cases, the original data may be directly transmitted to other institutions, increasing the risk of data leakage. Summary of the Invention

[0003] The purpose of the present disclosure is to provide a data transmission method, device, equipment, and storage medium based on homomorphic encryption to improve the security of data transmission and computing efficiency.

[0004] In the first aspect of the embodiments of the present disclosure, a data transmission method based on homomorphic encryption is provided, including:

[0005] Encrypting a query request based on the homomorphic encryption parameters of the target institution to obtain first data, and sending the first data to the target institution; the first data is used to instruct the target institution to generate second data including the data corresponding to the query request; the homomorphic encryption parameters include a first public key;

[0006] Receiving the second data sent by the target institution, where the second data is data obtained by the target institution based on the homomorphic encryption algorithm by fusing the original data on the basis of the first data;

[0007] Decrypting the second data based on the private key to obtain the target data.

[0008] In the second aspect of the embodiments of the present disclosure, a data transmission device based on homomorphic encryption is provided, including:

[0009] A first encryption module, configured to encrypt a query request based on the homomorphic encryption algorithm of the target institution to obtain first data, and send the first data to the target institution; the first data is used to instruct the target institution to generate second data including the data corresponding to the query request; the homomorphic encryption parameters include a first public key;

[0010] A receiving module, configured to receive the second data sent by the target institution, where the second data is data obtained by the target institution based on the homomorphic encryption algorithm by fusing the original data on the basis of the first data;

[0011] A decryption module, configured to decrypt the second data based on the private key to obtain the target data.

[0012] In a third aspect of the embodiments of the present disclosure, an electronic device is provided, including a memory, a processor, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, the steps of the above-mentioned data transmission method based on homomorphic encryption are implemented.

[0013] In a fourth aspect of the embodiments of the present disclosure, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the above-mentioned data transmission method based on homomorphic encryption are implemented.

[0014] The beneficial effects of the data transmission method, device, equipment, and storage medium based on homomorphic encryption provided by the embodiments of the present disclosure are as follows:

[0015] On the one hand, the embodiments of the present disclosure effectively ensure the security of data during transmission. By encrypting the query request into the first data through the homomorphic encryption algorithm, even if the data is intercepted during transmission, it is difficult for attackers to decrypt and obtain the original information, thereby protecting the privacy of the data.

[0016] On the other hand, the embodiments of the present disclosure improve the efficiency and flexibility of data processing. The homomorphic encryption algorithm allows mathematical operations to be performed on ciphertext without decryption. After receiving the first data, the target institution can directly generate the second data containing the data corresponding to the query request based on the homomorphic encryption algorithm, without additional decryption and encryption steps. This not only simplifies the data processing process but also improves the efficiency and flexibility of data processing, making data interaction more convenient and efficient. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the following drawings are only some embodiments of the present disclosure. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0018] Figure 1 It is a schematic flowchart of the data transmission method based on homomorphic encryption provided by an embodiment of the present disclosure;

[0019] Figure 2 It is a structural block diagram of the data transmission device based on homomorphic encryption provided by an embodiment of the present disclosure;

[0020] Figure 3 It is a schematic block diagram of the electronic device provided by an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0021] In the following description, specific details such as specific system architectures and technologies are presented for the purpose of illustration rather than limitation, so as to thoroughly understand the embodiments of the present disclosure. However, those skilled in the art should clearly understand that the present disclosure can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid unnecessary details from interfering with the description of the present disclosure.

[0022] To make the objectives, technical solutions, and advantages of the present disclosure clearer, the following will be described through specific embodiments in conjunction with the accompanying drawings.

[0023] Please refer to Figure 1 , Figure 1 which is a schematic flowchart of a data transmission method based on homomorphic encryption provided for an embodiment of the present disclosure. The method includes:

[0024] S101: Encrypt the query request based on the homomorphic encryption parameters of the target institution to obtain the first data, and send the first data to the target institution; the first data is used to instruct the target institution to generate the second data including the data corresponding to the query request; the homomorphic encryption parameters include the first public key.

[0025] In this embodiment, the homomorphic encryption algorithm is a special encryption algorithm that can map plaintext data into a specific mathematical space, perform operations such as addition or multiplication in this mathematical space, and remap the result back to the plaintext space. The core of homomorphic encryption is that the ciphertext obtained after operating on two ciphertexts is the same as the result of performing the same operation on the corresponding plaintexts after decryption. This means that under the homomorphic encryption algorithm, mathematical operations can be performed on ciphertexts without decryption, thus protecting the privacy of data. The homomorphic encryption parameters include key parameters. The key parameters include public keys, private keys, and key lengths. Each institution participating in data transmission has a pair of keys, namely public keys and private keys, during initialization. Public keys are usually used to encrypt data, and private keys are usually used to decrypt data. Each participating institution can send its public key to other participating institutions so that other participating institutions can encrypt data.

[0026] The target institution refers to the sender, which is the initial provider of data in the entire data interaction process. The target institution can send the required information to the requester based on the query information sent by the requester.

[0027] The query request represents the request content that the initiator sends to the target institution, hoping to obtain relevant information or perform a certain query operation. For example, it can be an expression of specific requirements such as querying certain types of business data, user information, etc. However, to ensure its security and confidentiality during transmission, it needs to be encrypted using the homomorphic encryption parameters of the target institution before being sent to the target institution.

[0028] The first data is the result data obtained after encrypting the query request based on the first public key of the target institution. It is essentially the encrypted form of the query request, and its purpose is to be sent to the target institution in an encrypted form, so that the target institution can further generate the subsequent required second data without decrypting the first data.

[0029] In this embodiment, the data transmission method based on homomorphic encryption requires multiple parties to participate. Assume there are multiple requesters and one sender (the target institution). After receiving the encrypted query request from the requester, the target institution uses the homomorphic encryption algorithm to encrypt the first data and the data related to the first data, and transmits the encrypted second data to the requester through the oblivious transfer protocol to ensure that the data is not leaked during the transmission process.

[0030] S102: Receive the second data sent by the target institution. The second data is the data obtained by the target institution by fusing the original data based on the first data using the homomorphic encryption algorithm.

[0031] In this embodiment, after receiving the first data, the target institution decrypts the first data based on the first private key corresponding to the first public key to obtain a hint message, and obtains the original data related to the hint message based on the hint message. Then, the target institution encrypts the first data and the original data related to the hint message using the homomorphic encryption algorithm to obtain the second data. And the second data is sent to the requester.

[0032] The original data refers to the data resources owned by the target institution itself, which are unencrypted and related to the query request. For example, in the financial scenario, the customer account balances, transaction records, etc. stored inside the bank; in the medical scenario, the patient medical record information, examination and test results, etc. saved by the hospital are all original data. After receiving the first data, the target institution will use the homomorphic encryption algorithm to fuse the original data with it, so as to generate the second data containing the corresponding content of the query request. The original data is an important basic information source in the whole data processing process.

[0033] S103: Decrypt the second data based on the private key to obtain the target data.

[0034] In this embodiment, in the asymmetric encryption system, the private key is the key corresponding to the public key and saved by the requester. There is a specific mathematical relationship between the private key and the public key. Only by using the matching private key can the data encrypted with the corresponding public key be decrypted and restored, so as to ensure the security and confidentiality of information during the transmission and interaction process. The second data is the data obtained by the target institution by encrypting using the public key corresponding to the requester.

[0035] The requester uses its own private key to decrypt the second data to obtain the required information. The requester can only decrypt the results it queries and cannot obtain other unqueried data. If the target institution sends the data to other requesters by mistake, other requesters cannot obtain data other than their own requests either, which also ensures the security of data transmission.

[0036] As can be seen from the above, on the one hand, the embodiments of the present disclosure effectively guarantee the security of data during transmission. By encrypting the query request into the first data through the homomorphic encryption algorithm, even if the data is intercepted during transmission, it is difficult for attackers to decrypt and obtain the original information, thus protecting the privacy of the data.

[0037] On the other hand, the embodiments of the present disclosure improve the efficiency and flexibility of data processing. The homomorphic encryption algorithm allows mathematical operations to be performed on ciphertext without decryption. After receiving the first data, the target institution can directly generate the second data containing the data corresponding to the query request based on the homomorphic encryption algorithm without additional decryption and encryption steps. This not only simplifies the data processing process but also improves the efficiency and flexibility of data processing, making data interaction more convenient and efficient.

[0038] In an embodiment of the present disclosure, encrypting the query request into the first data based on the homomorphic encryption parameters of the target institution includes:

[0039] Encrypting the query request into the first data based on the first formula and the homomorphic encryption parameters of the target institution, where the first formula is:

[0040]

[0041] Among them, the query request is represented as the plaintext message m; the homomorphic encryption parameters of the target institution include the public key , represents the i-th vector element, , b is a scalar value, the random noise vector , represents the i-th random noise vector element, the first data is represented as , q is a positive integer representing the modulus, t is a preset scaling factor, mod represents the modulo operation, represents the floor operation. The b scalar value can be used to perform an initial transformation or confusion on the plaintext data to increase the security of the data.

[0042] In this embodiment, the modulus q limits the value range of the operation result, ensuring that the encryption calculation result is within a suitable numerical range. The scaling factor t is used to perform appropriate numerical scaling on the plaintext message m during the encryption process, facilitating subsequent operations based on the homomorphic property and accurately restoring the plaintext during decryption.

[0043] Generally, it is obtained by performing a specific transformation on a part of the query request and then encrypting it using the first public key of the target institution and specific parameters in the homomorphic encryption algorithm. Usually, it is On the basis of, other parts of the query request are encrypted, and the encryption process is complex.

[0044] In an embodiment of the present disclosure, the target institution generates second data including data corresponding to the query request, including:

[0045] The target institution generates second data including data corresponding to the query request based on a second formula, and the second formula is:

[0046]

[0047] Wherein, the second data is , the original data is , the parameters related to the homomorphic encryption algorithm used by the target institution for this fusion encryption operation, the public key is set as , the private key is , is The corresponding private key; represents the j-th vector element, , represents a scalar value, the random noise vector , represents the j-th random noise vector element, represents the modulus, which is a positive integer, represents a preset scaling factor, and t can be the same value; mod represents the modulo operation, represents the floor operation. l can be the same as n or different.

[0048] In an embodiment of the present disclosure, sending the first data to the target institution includes:

[0049] The first data is segmented into multiple sub-data according to a preset segmentation rule, and each sub-data is sequentially transmitted to the target institution through the network.

[0050] In this embodiment, the preset segmentation rule is determined based on one or more of the length of the data, the sensitivity level of the data, and the network transmission bandwidth.

[0051] The length of the data refers to the amount of information contained in the first data, usually measured in units such as the number of bytes. The data length is one of the important factors in determining the segmentation rules. Longer data needs to be split into multiple sub-data for easy transmission and processing. At the same time, the size of each sub-data can be reasonably allocated according to the data length to avoid the situation of overly large or overly small sub-data and improve the overall transmission efficiency.

[0052] The sensitivity level of the data is used to measure the degree of confidentiality and importance of the data. For data with a high sensitivity level, more stringent measures can be taken during segmentation, such as further subdividing the sub-data, increasing the encryption level, etc., to ensure the security of the data during transmission. Different sensitivity levels of data have different segmentation strategies and transmission requirements to meet the needs of data protection.

[0053] The network transmission bandwidth refers to the amount of data that the network can transmit per unit time, usually measured in units such as Mbps and Gbps. The network transmission bandwidth is one of the key factors affecting the data transmission speed and efficiency. If the size of the first data exceeds the carrying capacity of the network transmission bandwidth, it may lead to slow transmission or even failure. By determining the segmentation rules according to the network transmission bandwidth, the first data can be split into sub-data suitable for the current network conditions, making full use of network resources and improving the transmission efficiency.

[0054] In this embodiment, when the amount of the first data is large, if the first data is directly transmitted as a whole, it may lead to slow transmission or even transmission failure due to network transmission bandwidth limitations. After splitting it into multiple sub-data, the transmission order and time of the sub-data can be flexibly adjusted according to the network conditions to achieve parallel transmission or off-peak transmission, improving the overall transmission efficiency. Various interference or unstable factors may occur during the network transmission process, such as network fluctuations, temporary interruptions, etc. Smaller sub-data is easier to retransmit or correct errors when encountering transmission problems, rather than retransmitting the entire large data, thus enhancing the stability and reliability of the transmission.

[0055] In this embodiment, although the homomorphic encryption algorithm has advantages in protecting data privacy, there are problems such as high computational complexity and ciphertext expansion. After segmenting the first data, each sub-data is encrypted and transmitted separately, and then processed and integrated after being received by the target institution. Relatively speaking, it can disperse the impact brought by ciphertext expansion to a certain extent and avoid the difficulties brought by a single overly large ciphertext during transmission and processing. By segmenting the first data into multiple sub-data, performing encryption operations separately, and then integrating and processing at the target institution, the complex calculations can be decomposed into multiple relatively simple sub-calculations, thereby reducing the overall computational complexity to a certain extent and improving the computational efficiency.

[0056] As can be seen from the above, in this embodiment, the first data is segmented into multiple data segments according to a preset segmentation rule. Each sub-data is a part of the first data, and they are sequentially transmitted to the target institution through the network. The sub-data is relatively smaller in scale than the original data, more flexible during transmission, can reduce the pressure on network transmission caused by excessive data volume, and is also convenient for individually monitoring and managing each sub-data, enhancing the controllability and reliability of data transmission, and improving the overall computing efficiency.

[0057] In an embodiment of the present disclosure, decrypting the second data based on a private key to obtain target data includes:

[0058] Dividing the second data into multiple first data blocks according to a preset segmentation rule, and respectively decrypting each first data block using the private key to obtain multiple second data blocks;

[0059] Merging the multiple second data blocks based on the association logic between the second data blocks to obtain the second data; the association logic is determined based on the data segmentation and combination rules of the homomorphic encryption algorithm.

[0060] In this embodiment, dividing the second data into multiple first data blocks according to a preset segmentation rule can break down large and complex data into smaller parts, making it more convenient for subsequent processing operations. Because if the entire second data is directly decrypted, due to reasons such as excessive data scale, the decryption process may have a large computational amount, low efficiency, or even exceed the system resource capacity.

[0061] The segmentation rule also needs to consider the characteristics of the homomorphic encryption algorithm in data processing. The ciphertext data after homomorphic encryption has its particularity in structure and processing method. The segmentation rule needs to fit its encrypted state to ensure that the first data blocks segmented can be reasonably restored according to the logic required by the homomorphic encryption when decrypting with the private key later, avoiding destroying the internal correlation of the data and the security guaranteed by the encryption algorithm. The segmentation rule includes data length, data sensitivity level, network transmission bandwidth, etc. Common segmentation rules include dividing data by a fixed number of bytes; dividing data according to specific fields, marks, or semantics; dividing data according to network transmission bandwidth, etc.

[0062] In this embodiment, the second data is divided into K first data blocks based on a preset segmentation rule. The ciphertext part corresponding to the u-th first data block is and . The private key is . Decryption operations are performed on each first data block to obtain multiple second data blocks, and the second data blocks are marked as .

[0063] For each first data block, decrypt it according to the third formula to obtain a second data block. The third formula is:

[0064]

[0065] Among them, the part calculated first within the inner brackets is the difference and summation operations based on the ciphertext part and as well as the encryption parameters. The purpose is to remove some "interference" factors such as those based on the public key and noise added during the encryption process. Then, the result is limited within the modulus range through the modulo operation mod, and finally multiplied by the ratio of the scaling factor to the modulus to restore the approximation of the second data block corresponding to the first data block.

[0066] In this embodiment, the association logic is the inherent laws and rules followed when splitting and combining data based on the homomorphic encryption algorithm, and is used to guide how to accurately combine multiple second data blocks to restore the complete second data. The association logic includes the order, interdependence relationship, and combination methods such as splicing and operation among the second data blocks, and is the key basis to ensure that the decrypted data can be correctly restored. The target data is the real data information with practical application value that the requester initially expects to obtain when initiating a query request.

[0067] It can be concluded from the above that this embodiment processes the second data based on the preset segmentation rules, reduces the difficulty and computational amount of data decryption, improves the decryption efficiency, and avoids the problem of system resource overload caused by excessive data scale. At the same time, this embodiment also uses the association logic based on the homomorphic encryption algorithm to combine the second data blocks, ensuring the integrity and accuracy of the data, and increasing the security of the data and the reliability of the encryption algorithm.

[0068] In an embodiment of the present disclosure, the first data is also used to instruct the target institution to adjust the second encryption parameter of the original data based on the first data.

[0069] Adjusting the second encryption parameter of the original data based on the first data includes:

[0070] Determining the indication information corresponding to the second encryption parameter based on the first data, and adjusting the second encryption parameter of the original data based on the indication information.

[0071] In this embodiment, the second encryption parameter, that is, the algorithm parameter in homomorphic encryption. The second encryption parameter includes encryption algorithm parameters, homomorphic operation parameters, and performance parameters. Among them, the encryption algorithm parameters include noise parameters, modulus parameters, and encryption times; the homomorphic operation parameters include operation type parameters and operation depth parameters; the performance parameters include time complexity parameters and space complexity parameters.

[0072] Noise parameters are used to hide plaintext information and enhance the security of ciphertext. The modulus is a parameter in the homomorphic encryption algorithm that defines the integer ring or finite field, determining the value range and calculation precision of encrypted data. A larger modulus can provide higher security but also increase the computational and storage overheads. The number of encryption times refers to the number of times the same data is encrypted. Multiple encryptions can improve data security but also increase the computational cost and the degree of ciphertext expansion.

[0073] Homomorphic encryption algorithms support different types of operations, such as additive homomorphic, multiplicative homomorphic, or fully homomorphic. For fully homomorphic encryption algorithms, the operation depth parameter limits the number of consecutive homomorphic operations that can be performed on ciphertext. The time complexity parameter is used to measure the time overhead of the homomorphic encryption algorithm during the processes of encryption, decryption, and homomorphic operations. The space complexity parameter refers to the storage space required by the homomorphic encryption algorithm during the processes of encryption, decryption, and homomorphic operations.

[0074] In this embodiment, the indication information includes data feature-related information and security requirement-related information, etc. Data feature-related information such as data sensitivity, data format, and structure, etc., and security requirement-related information includes the adjustment direction of encryption parameters, the adjustment amplitude of encryption parameters, etc. By adjusting the second encryption parameter of the original data through the indication information, the encryption process can be made dynamic, improving data security. For example, if fixed encryption parameters are always used, an attacker can gradually infer the encryption parameters by observing and analyzing communication traffic or ciphertext features over a long period, thereby cracking the encrypted data.

[0075] It can be concluded from the above that dynamically adjusting parameters can disrupt the attacker's analysis rhythm, reduce the risk of encryption parameter leakage, and ensure that even if part of the data is intercepted, it is difficult to obtain complete and valid information. In an embodiment of the present disclosure, the indication information includes the adjustment direction of encryption parameters and the adjustment amplitude of encryption parameters;

[0076] Adjusting the second encryption parameter of the original data based on the indication information includes:

[0077] Determining the encryption strength and encryption value of the second encryption parameter based on the adjustment direction of encryption parameters;

[0078] Determining the encryption step size of the encryption value based on the adjustment amplitude of encryption parameters;

[0079] Adjusting the second encryption parameter based on the encryption strength, encryption value, and encryption step size of the encryption value of the second encryption parameter.

[0080] In this embodiment, the encryption strength reflects the complexity of confusing and transforming data during the encryption process. The higher the encryption strength, the more difficult it is for an attacker to crack the encrypted data. For example, the encryption strength can be divided into three levels: low, medium, and high. The encryption value is a specific parameter value or variable value used in the encryption algorithm to construct the encryption transformation. For example, in some homomorphic encryption algorithms, the encryption value is related to the modulus, noise value, etc.

[0081] The specific value of the encryption value determines the transformation method of the encryption operation on the data. Reasonably selecting and adjusting the encryption value can optimize the performance and function of the encryption algorithm while ensuring data security. For example, in a homomorphic encryption algorithm, by adjusting the encryption value, the feasibility and accuracy of performing homomorphic operations on the ciphertext can be controlled, and at the same time, it will also affect the size and computational complexity of the ciphertext.

[0082] The encryption step size refers to the amplitude or increment of each parameter change when adjusting the encryption parameters. The encryption step size can be a fixed value or determined dynamically according to specific circumstances, such as adjusting according to factors such as the importance of the data, the frequency of queries, or the performance requirements of the system. A smaller encryption step size can make the adjustment of the encryption parameters more refined and can more precisely adapt to different security requirements and performance requirements; a larger encryption step size can improve the adjustment speed and reduce the computational amount.

[0083] Adjust the second encryption parameter based on the encryption strength, encryption value, and encryption step size of the second encryption parameter. For example, adjust the noise parameter and the number of encryption times according to the encryption strength, adjust the modulus according to the encryption value, and adjust the step size of the modulus value changing from one value to another according to the encryption step size. After the target institution adjusts the second encryption parameter, it needs to send the adjusted parameter to the receiving party through a network communication protocol or other means, and the receiving party adjusts the private key accordingly to ensure that the receiving party can decrypt the received second data.

[0084] It can be concluded from the above that in this embodiment, by refining the adjustment direction and amplitude of the encryption parameters, the encryption strength, encryption value, and encryption step size can be flexibly adjusted, optimizing the performance and function of the encryption algorithm, and ensuring data security. At the same time, through the synchronous adjustment of the parameters, the decryption ability of the receiving party is guaranteed, enhancing the security and reliability of data transmission.

[0085] In an embodiment of the present disclosure, before decrypting the second data to obtain the target data based on the private key, it further includes:

[0086] Compare the first check code attached to the second data with the second check code regenerated based on the received second data through a specific check code generation mechanism based on the homomorphic encryption algorithm;

[0087] Determine whether to decrypt the second data based on the matching result of the first verification code and the second verification code.

[0088] In this embodiment, when the homomorphic encryption algorithm encrypts data, in addition to generating the encrypted second data, it also generates a first verification code through a specific verification code generation algorithm based on the specific characteristics of the data and some parameters in the encryption process, and transmits it together with the second data. When the second data is received, the receiving party uses the same specific verification code generation mechanism based on the homomorphic encryption algorithm to generate a verification code again according to the received second data, that is, the second verification code. During the generation process, calculations are performed according to the same rules and parameters as the sender to ensure that the generated verification codes are comparable. The receiving party compares the first verification code attached to the received second data with the regenerated second verification code bit by bit or according to specific comparison rules. If the two verification codes are exactly the same, it means that the data has not been corrupted or tampered with during transmission; if there are differences between the two verification codes, it indicates that there may be problems with the data.

[0089] If the first verification code matches the second verification code, that is, the two are exactly the same, it means that the integrity and authenticity of the second data have been verified, and the data is reliable, and the decryption operation based on the private key can continue to obtain the target data. If the first verification code does not match the second verification code, it indicates that the second data has been interfered with, damaged or maliciously tampered with during transmission. At this time, corresponding measures need to be taken, such as notifying the sender to resend the data, performing data repair or further security checks according to specific situations, etc., until the correct and reliable data is obtained and then the decryption operation is performed.

[0090] It can be concluded from the above that the verification code is a means to verify the data source. Only a legitimate target institution with the correct homomorphic encryption algorithm and related keys can generate the correct verification code that matches the data. When the receiving party receives the data and performs verification, if the verification codes match, to a certain extent, it can prove that the data is sent by a legitimate target institution, rather than from an illegal or untrusted source, thereby increasing the credibility and security of the data.

[0091] In an embodiment of the present disclosure, the query request includes multi-dimensional query conditions;

[0092] Encrypting the query request based on the homomorphic encryption algorithm of the target institution to obtain the first data includes:

[0093] Determine the first encryption parameter corresponding to the homomorphic encryption algorithm;

[0094] Encode the multi-dimensional query conditions to obtain encoded data;

[0095] Encrypt the encoded data based on the first encryption parameter of the target institution to obtain the first data.

[0096] In this embodiment, the multi-dimensional query conditions refer to the restrictive conditions set from multiple different aspects and angles in the query request. For example, when querying medical data, conditions from different dimensions such as the patient's age range, disease type, treatment time range, and medication situation can be covered simultaneously. These multi-dimensional conditions can make the query more accurately locate the specific data content that meets the requirements, so that the finally obtained data best matches the actual needs of the queryer.

[0097] Existing methods generally directly encrypt the multi-dimensional query conditions and then transmit them, but this will increase the storage space and is not conducive to data transmission. In this embodiment, the multi-dimensional query conditions are encoded to obtain encoded data, and then the encoded data is encrypted, which can significantly reduce the space occupied by the data during storage and transmission and improve the storage efficiency. In addition, the compressed data has a smaller volume, a faster transmission speed, reduces network latency, and improves the timeliness of data transmission.

[0098] In an embodiment of the present disclosure, the first data is further used to instruct the target institution to determine the data distribution of the original data based on the first data, and determine the data processing method of the original data based on the data distribution of the original data.

[0099] Among them, determining the data processing method of the original data based on the data distribution of the original data includes:

[0100] If the data distribution of the original data is uniformly distributed data, the data processing method of the original data is the numerical truncation method;

[0101] If the data distribution of the original data is normally distributed data, the data processing method of the original data is the interval approximation method. In this embodiment, the numerical truncation method is a method for approximately processing numerical data. It directly discards a part of the data according to the preset truncation rule to obtain an approximate value. According to the characteristics and precision requirements of the data, select the digits or positions to be truncated. For example, for decimal data, it can be decided to truncate to a certain number of digits after the decimal point; for integer data, it can be truncated to a certain digit.

[0102] Exemplarily, when measuring the length of steel in a construction project, the measuring tool is accurate to millimeters. If the data is 500.356 millimeters, it can be truncated to 500.3 millimeters for approximate calculation in some preliminary calculations, because in this scenario, the precision difference at the millimeter level has little impact on the overall result, and this truncation can significantly reduce the calculation amount.

[0103] The interval approximation method is a method that divides the value range of data into several intervals, and then determines its approximate value according to the interval where the data is located. Each interval corresponds to a preset representative value, and the data is approximated to the representative value of the interval where it is located. According to the distribution of the data and the analysis purpose, determine the appropriate interval division method. The intervals can be equidistant or non-equidistant, depending on the characteristics of the data. For example, according to the characteristics of the normal distribution, the data is divided into several typical intervals (such as intervals corresponding to excellent, good, medium, passing, failing, etc. corresponding to different score ranges), and the representative value of the interval (such as the midpoint of the interval) is used for calculation.

[0104] Exemplarily, when calculating the average score of students in a class, the scores are divided into intervals of 0-59 points, 60-69 points, 70-79 points, 80-89 points, and 90-100 points. When calculating, 29.5 points, 64.5 points, 74.5 points, 84.5 points, and 95 points are used as the representative values of each interval for approximate calculation, which can not only simplify the calculation but also reflect the overall score level to a certain extent.

[0105] It can be concluded from the above that by selecting the appropriate data processing method (numerical truncation method or interval approximation method) according to the data distribution of the original data, this embodiment effectively improves the efficiency and accuracy of data processing, simplifies the calculation process at the same time, and can significantly improve the transmission efficiency of data after encryption.

[0106] Corresponding to the data transmission method based on homomorphic encryption in the above embodiment, Figure 2 This is a structural block diagram of a data transmission device based on homomorphic encryption provided by an embodiment of the present disclosure. For the sake of convenience of description, only the parts related to the embodiments of the present disclosure are shown. Refer to Figure 2 As shown in, the data transmission device 20 based on homomorphic encryption includes: a first encryption module 21, a receiving module 22, and a decryption module 23.

[0107] Among them, the first encryption module 21 is used to encrypt the query request based on the homomorphic encryption algorithm of the target institution to obtain the first data, and send the first data to the target institution; the first data is used to instruct the target institution to generate the second data including the data corresponding to the query request; the homomorphic encryption parameter includes the first public key.

[0108] The receiving module 22 is used to receive the second data sent by the target institution, and the second data is the data obtained by the target institution based on the homomorphic encryption algorithm by fusing the original data on the basis of the first data;

[0109] The decryption module 23 is used to decrypt the second data based on the private key to obtain the target data.

[0110] In an embodiment of the present disclosure, the first encryption module 21 is specifically used for:

[0111] Encrypt the query request based on the first formula and the homomorphic encryption parameters of the target institution to obtain the first data, where the first formula is:

[0112]

[0113] Among them, the query request is represented as the plaintext message m; the homomorphic encryption parameters of the target institution include the public key , represents the i-th vector element, , b is a scalar value, and the random noise vector , represents the i-th random noise vector element, and the first data is represented as , q is a positive integer representing the modulus, t is a preset scaling factor, and mod represents the modulo operation, represents the floor operation.

[0114] In an embodiment of the present disclosure, the receiving module 22 is specifically configured to:

[0115] The target institution generates the second data including the data corresponding to the query request based on the second formula, and the second formula is:

[0116]

[0117] Among them, the second data is , the original data is , the parameters related to the homomorphic encryption algorithm used by the target institution for this fusion encryption operation, the public key is set as , and the private key is , is corresponding private key; represents the j-th vector element, , represents a scalar value, and the random noise vector , represents the j-th random noise vector element, represents the modulus, which is a positive integer, represents the preset scaling factor, and mod represents the modulo operation, represents the floor operation.

[0118] In an embodiment of the present disclosure, the decryption module 23 is specifically configured to:

[0119] Divide the second data into multiple first data blocks according to the preset segmentation rule, and decrypt each first data block using the private key to obtain multiple second data blocks;

[0120] Multiple second data blocks are merged based on the association logic between the second data blocks to obtain second data; the association logic is determined based on the rules of data segmentation and combination of the homomorphic encryption algorithm.

[0121] In an embodiment of the present disclosure, the first data is further used to instruct the target institution to adjust the second encryption parameter of the original data based on the first data.

[0122] In an embodiment of the present disclosure, adjusting the second encryption parameter of the original data based on the first data includes:

[0123] Determine the indication information corresponding to the second encryption parameter based on the first data, and adjust the second encryption parameter of the original data based on the indication information.

[0124] In an embodiment of the present disclosure, the indication information includes the encryption parameter adjustment direction and the encryption parameter adjustment amplitude;

[0125] Adjusting the second encryption parameter of the original data based on the indication information includes:

[0126] Determine the encryption strength and encryption value of the second encryption parameter based on the encryption parameter adjustment direction;

[0127] Determine the encryption step size of the encryption value based on the encryption parameter adjustment amplitude;

[0128] Adjust the second encryption parameter based on the encryption strength, encryption value of the second encryption parameter, and the encryption step size of the encryption value.

[0129] See Figure 3 , Figure 3 is a schematic block diagram of an electronic device provided by an embodiment of the present disclosure. As Figure 3 shown, the electronic device 300 in this embodiment may include: one or more processors 301, one or more input devices 302, one or more output devices 303, and one or more memories 304. The above-mentioned processors 301, input devices 302, output devices 303, and memories 304 communicate with each other through the communication bus 305. The memory 304 is used to store computer programs, and the computer programs include program instructions. The processor 301 is used to execute the program instructions stored in the memory 304. Among them, the processor 301 is configured to call the program instructions to execute the functions of each module in the above device embodiments, such as Figure 2 the functions of the modules 21 to 23 shown.

[0130] It should be understood that in the embodiments of the present disclosure, the so-called processor 301 may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0131] The input device 302 may include a touchpad, a fingerprint acquisition sensor (for acquiring the fingerprint information and the direction information of the fingerprint of the user), a microphone, etc., and the output device 303 may include a display (such as an LCD), a speaker, etc.

[0132] The memory 304 may include a read-only memory and a random access memory, and provide instructions and data to the processor 301. A part of the memory 304 may also include a non-volatile random access memory. For example, the memory 304 may also store information about the device type.

[0133] In specific implementation, the processor 301, the input device 302, and the output device 303 described in the embodiments of the present disclosure may implement the implementation manners described in the first embodiment and the second embodiment of the data transmission method based on homomorphic encryption provided by the embodiments of the present disclosure, and may also implement the implementation manner of the electronic device described in the embodiments of the present disclosure, which will not be elaborated herein.

[0134] In another embodiment of the present disclosure, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program, and the computer program includes program instructions. When the program instructions are executed by a processor, all or part of the processes in the methods of the above embodiments are implemented. It can also be completed by instructing relevant hardware through the computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by the processor, the steps of the above various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disc, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electrical carrier signal, telecommunication signal, and software distribution medium, etc.

[0135] The computer-readable storage medium can be the internal storage unit of the electronic device in any of the foregoing embodiments, such as the hard disk or memory of the electronic device. The computer-readable storage medium can also be an external storage device of the electronic device, such as a plug-in hard disk equipped on the electronic device, a smart media card (Smart Media Card, SMC), a secure digital (SecureDigital, SD) card, a flash card (Flash Card), etc. Further, the computer-readable storage medium can also include both the internal storage unit and the external storage device of the electronic device. The computer-readable storage medium is used to store the computer program and other programs and data required by the electronic device. The computer-readable storage medium can also be used to temporarily store the data that has been output or will be output.

[0136] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the components and steps of the examples have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present disclosure.

[0137] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described electronic devices and units can refer to the corresponding processes in the foregoing method embodiments and will not be described in detail here.

[0138] In several embodiments provided by this application, it should be understood that the disclosed electronic devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Additionally, the displayed or discussed couplings or direct couplings or communication connections to each other can be indirect couplings or communication connections through some interfaces or units, or can be electrical, mechanical, or other forms of connection.

[0139] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of the embodiments of the present disclosure.

[0140] In addition, in each embodiment of the present disclosure, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0141] The above are only the specific implementation manners of the present disclosure, but the protection scope of the present disclosure is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present disclosure can easily think of various equivalent modifications or substitutions, and these modifications or substitutions should all be covered within the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure should be subject to the protection scope of the claims.

Claims

1. A data transmission method based on homomorphic encryption, characterized in that: include: Encrypting the query request based on the homomorphic encryption parameters of the target organization to obtain first data, and sending the first data to the target organization; The first data is used to instruct the target organization to generate second data containing data corresponding to the query request; the homomorphic encryption parameters include a first public key; The first data is also used to instruct the target organization to adjust a second encryption parameter of the original data based on the first data, including: Determine indication information corresponding to the second encryption parameter based on the first data, and adjust the second encryption parameter of the original data based on the indication information; The indication information includes the encryption parameter adjustment direction and the encryption parameter adjustment range; The adjusting the second encryption parameter of the original data based on the indication information comprises: Determining the encryption strength and encryption value of the second encryption parameter based on the encryption parameter adjustment direction; Determining an encryption step size of the encrypted value based on the encryption parameter adjustment amplitude; adjusting the second encryption parameter based on the encryption strength of the second encryption parameter, the encryption value, and the encryption step of the encryption value; Receiving second data sent by the target organization, where the second data is data obtained by the target organization by fusing the original data with the first data based on a homomorphic encryption algorithm; The second data is decrypted based on the private key to obtain target data.

2. The data transmission method based on homomorphic encryption according to claim 1, characterized in that: The step of encrypting the query request based on the homomorphic encryption parameter of the target organization to obtain the first data includes: The query request is encrypted based on the first formula and the homomorphic encryption parameter of the target organization to obtain the first data, wherein the first formula is: The query request is represented as a plaintext message m; the homomorphic encryption parameters of the target organization include the public key , represents the i-th vector element, , b is a scalar value, random noise vector , represents the i-th random noise vector element, and the first data is represented as , q is a positive integer, indicating the modulus, t is the preset scaling factor, mod indicates the modulus operation, Indicates floor operation.

3. The data transmission method based on homomorphic encryption according to claim 1, characterized in that: The target organization generates second data containing data corresponding to the query request, including: The target organization generates second data including data corresponding to the query request based on a second formula, where the second formula is: Among them, the second data is , the original data is , the target organization uses the homomorphic encryption algorithm parameters for this fusion encryption operation, and the public key is set to , the private key is , for The corresponding private key; represents the jth vector element, , Represents a scalar value, a random noise vector , represents the jth random noise vector element, Represents the modulus, which is a positive integer. Indicates the preset scaling factor, mod indicates the modulo operation, Indicates floor operation.

4. The data transmission method based on homomorphic encryption according to claim 1, characterized in that: The decrypting the second data based on the private key to obtain the target data includes: Dividing the second data into a plurality of first data blocks according to a preset segmentation rule, and decrypting each first data block using a private key to obtain a plurality of second data blocks; Based on the association logic between the second data blocks, multiple second data blocks are merged to obtain second data; the association logic is determined based on the data segmentation and combination rules of the homomorphic encryption algorithm.

5. A data transmission device based on homomorphic encryption, characterized in that: include: A first encryption module, used to encrypt the query request based on the homomorphic encryption algorithm of the target organization to obtain first data, and send the first data to the target organization; The first data is used to instruct the target organization to generate second data containing data corresponding to the query request; The homomorphic encryption parameters include a first public key; The first data is also used to instruct the target organization to adjust a second encryption parameter of the original data based on the first data, including: Determine indication information corresponding to the second encryption parameter based on the first data, and adjust the second encryption parameter of the original data based on the indication information; The indication information includes the encryption parameter adjustment direction and the encryption parameter adjustment range; The adjusting the second encryption parameter of the original data based on the indication information comprises: Determining the encryption strength and encryption value of the second encryption parameter based on the encryption parameter adjustment direction; Determining an encryption step size of the encrypted value based on the encryption parameter adjustment amplitude; adjusting the second encryption parameter based on the encryption strength of the second encryption parameter, the encryption value, and the encryption step of the encryption value; A receiving module, used to receive second data sent by a target organization, where the second data is data obtained by the target organization by fusing the original data with the first data based on a homomorphic encryption algorithm; A decryption module is used to decrypt the second data based on a private key to obtain target data.

6. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 4 are implemented.

7. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 4 are implemented.

Citation Information

Patent Citations

  • Encryption protocol conversion method, result acquisition node and privacy computing node

    CN114885038A

  • Data security detection method and device in privacy computing

    CN116938434A

  • Location data protection method and system based on searchable encryption

    CN118643538A