Data processing method and device, electronic equipment and storage medium

By using a unified encryption key array at the central node to encrypt and compare the data of the participants, the problems of low data security and low processing efficiency in cross-industry alliances are solved, and efficient and secure determination of shared business data is achieved.

CN119382907BActive Publication Date: 2025-12-16MASHANG CONSUMER FINANCE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310924706.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-07-25
Publication Date
2025-12-16
Estimated Expiration
2043-07-25

AI Technical Summary

Technical Problem

In cross-industry alliances, existing technologies cannot effectively ensure the security of business data among participants, and existing intersection processing methods suffer from low data processing efficiency and poor flexibility.

Method used

A unified encryption key array at the central node is used to encrypt the plaintext business data of participating member nodes. Shared business data is identified through data comparison processing to prevent plaintext data from being exchanged between participants. Data comparison is performed in encrypted form to ensure data security.

Benefits of technology

It achieves data security without revealing the data decryption key, while improving data processing efficiency and flexibility, and meeting the personalized needs of different combinations of participants.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119382907B_ABST
    Figure CN119382907B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a data processing method and device, electronic equipment and storage medium. A center node first acquires a ciphertext data set sent by a participating member node. The ciphertext data set of different participating member nodes is obtained by using the same encryption key array for data encryption. The participating member node includes a first participating member node. Then, the center node performs data comparison processing on the ciphertext business data in the ciphertext data set to obtain a data comparison result of the first participating member node. Next, the first participating member node can acquire the data comparison result from the center node, and then determine common business data of a participating member node combination based on the acquired data comparison result. In this way, since the data comparison process is uniformly performed by the center node, the business data cannot be communicated between the participating member nodes, and the center node directly performs data comparison processing based on the ciphertext business data, thereby ensuring the security of the business data of the participating member nodes.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of Internet, and particularly relates to a data processing method and device, electronic equipment and storage medium. BACKGROUND

[0002] At present, for an inter-industry alliance including two or more participating parties (such as enterprises, merchants, etc.), it is usually necessary to calculate common business data (such as common user name list, common commodity information, etc.) between the two or more participating parties based on respective business data of the participating parties, or to calculate the number of common business data between the participating parties, wherein the business data usually includes privacy data (such as user privacy data) with relatively high security requirements, that is, an application scenario involving intersection of privacy data.

[0003] For example, it is necessary to calculate a common member name list of the two or more participating parties based on respective member name lists of the participating parties, so as to realize joint marketing based on the common member name list; for another example, it is necessary to calculate a common black name list of the two or more participating parties based on respective black name lists of the participating parties, so as to realize risk control based on the common black name list; however, in the existing determination process of the common business data, all business data between the two or more participating parties needs to be interchanged, so that non-common business data between the participating parties may be leaked (for example, participating party A obtains business data that participating party A does not have but participating party B has, and participating party B obtains business data that participating party B does not have but participating party A has), and therefore, the business data security of the participating parties cannot be ensured. SUMMARY

[0004] The purpose of the embodiments of the present application is to provide a data processing method, device, electronic equipment and storage medium, which can ensure the business data security of participating member nodes.

[0005] In order to achieve the above technical solutions, the embodiments of the present application are implemented as follows:

[0006] In a first aspect, the embodiments of the present application provide a data processing method applied to a center node, and the method comprises the following steps:

[0007] obtaining a ciphertext data set sent by a participating member node, wherein the ciphertext data set comprises ciphertext business data, the ciphertext business data is obtained by encrypting plaintext business data based on an encryption key array, the encryption key array used by different participating member nodes is the same, and the participating member nodes comprise a first participating member node;

[0008] performing data comparison processing on the ciphertext business data in the ciphertext data set to obtain a data comparison result of the first participating member node.

[0009] In a second aspect, the embodiments of the present application provide a data processing method, applied to a first participant node, and the method comprises the following steps:

[0010] encrypting plaintext business data based on an encryption key array to obtain a ciphertext data set; the ciphertext data set comprises ciphertext business data, and the encryption key array used by different participant nodes is the same;

[0011] sending the ciphertext data set to a center node;

[0012] obtaining a data comparison result generated by the center node; the data comparison result is obtained by comparing data based on the ciphertext business data in the ciphertext data set.

[0013] In a third aspect, the embodiments of the present application provide a data processing device, arranged in a center node, and the device comprises:

[0014] a data acquisition module, configured to acquire a ciphertext data set sent by a participant node, wherein the ciphertext data set comprises ciphertext business data, the ciphertext business data is obtained by encrypting plaintext business data based on an encryption key array, the encryption key array used by different participant nodes is the same, and the participant node comprises a first participant node;

[0015] a data comparison module, configured to compare data of the ciphertext business data in the ciphertext data set to obtain a data comparison result of the first participant node.

[0016] In a fourth aspect, the embodiments of the present application provide a data processing device, arranged in a first participant node, and the device comprises:

[0017] a data encryption module, configured to encrypt plaintext business data based on an encryption key array to obtain a ciphertext data set; the ciphertext data set comprises ciphertext business data, and the encryption key array used by different participant nodes is the same;

[0018] a data sending module, configured to send the ciphertext data set to a center node;

[0019] a result acquisition module, configured to obtain a data comparison result generated by the center node; the data comparison result is obtained by comparing data based on the ciphertext business data in the ciphertext data set.

[0020] In a fifth aspect, the embodiments of the present application provide an electronic device, and the device comprises:

[0021] a processor; and a memory arranged to store computer executable instructions configured to be executed by the processor, the executable instructions comprising instructions for performing the steps in the method as described in the first aspect or the second aspect.

[0022] In a sixth aspect, the embodiments of the present application provide a computer readable storage medium, wherein the storage medium is configured to store computer executable instructions, and the executable instructions cause a computer to perform the steps in the method as described in the first aspect or the second aspect.

[0023] In the embodiments of the present application, the center node first acquires the ciphertext data set sent by the participating member nodes, the ciphertext data set of different participating member nodes being obtained by using the same encryption key array to encrypt the plaintext business data generated by each participating member node, and the participating member nodes including the first participating member node; then, the center node performs data comparison processing on the ciphertext business data in the ciphertext data set to obtain the data comparison result of the first participating member node; next, the first participating member node can acquire the data comparison result from the center node, and then determine the common business data of the participating member node combination based on the acquired data comparison result. As can be seen, since the ciphertext business data is obtained by using the same encryption key array for encryption, if two ciphertext business data are the same, the corresponding two plaintext business data are also the same, therefore, the center node can directly compare the ciphertext business data of different participating member nodes to obtain the data comparison result of the first participating member node, and then determine which same plaintext business data (i.e. common business data) are contained between the participating member nodes based on the data comparison result, so that since the data comparison process is uniformly performed by the center node, the business data is not communicated between the participating member nodes, and the center node directly performs data comparison processing based on the ciphertext business data, without the need to perform decryption processing on the ciphertext business data, and thus without the need to acquire the corresponding data decryption key, that is, the data comparison process is performed on the business data in the form of ciphertext, thereby ensuring the security of the business data in the entire data processing process. BRIEF DESCRIPTION OF DRAWINGS

[0024] In order to more clearly illustrate the technical solutions of the embodiments of the present application or the prior art, the drawings needed in the embodiments or the prior art description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments described in one or more of the present application, and those skilled in the art can also obtain other drawings according to these drawings without creative labor.

[0025] Figure 1 The first flowchart of the data processing method applied to the center node provided by the embodiments of the present application is shown in the figure.

[0026] Figure 2 The first specific implementation principle diagram of the data processing method provided by the embodiment of the application is shown in the following figure.

[0027] Figure 3 The second flow diagram of the data processing method applied to the center node provided by the embodiment of the application is shown in the following figure.

[0028] Figure 4 The second specific implementation principle diagram of the data processing method provided by the embodiment of the application is shown in the following figure.

[0029] Figure 5 The third specific implementation principle diagram of the data processing method provided by the embodiment of the application is shown in the following figure.

[0030] Figure 6 The flow diagram of the data processing method applied to the participating member node provided by the embodiment of the application is shown in the following figure.

[0031] Figure 7 The module composition diagram of the data processing device provided by the embodiment of the application and arranged in the center node is shown in the following figure.

[0032] Figure 8 The module composition diagram of the data processing device provided by the embodiment of the application and arranged in the participating member node is shown in the following figure.

[0033] Figure 9 The structure diagram of the electronic device provided by the embodiment of the application is shown in the following figure. DETAILED DESCRIPTION

[0034] In order to make the person skilled in the art better understand the technical solutions in one or more of the present application, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all embodiments. Based on the embodiments in one or more of the present application, all other embodiments obtained by those skilled in the art without creative labor should belong to the protection scope of the present application.

[0035] It should be noted that, in the case of no conflict, one or more embodiments and features in the embodiments of the present application can be combined with each other. The embodiments of the present application will be described in detail below with reference to the drawings and in combination with the embodiments.

[0036] One or more embodiments of the present application provide a data processing method and device, electronic equipment and storage medium. If the determination process of shared business data between two or more participants is performed by the participants, the business data intercommunication between the two or more participants is required, so that each participant can determine the shared business data between the participant itself and other participants through business data comparison processing. Since a participant can also obtain non-shared business data between the participant itself and other participants, there may be a security problem of business data. In addition, if the intersection processing of the business data of multiple participants is performed based on the existing inadvertent transmission technology to obtain the shared business data between the multiple participants, in order to improve the security of the business data, it is necessary to increase the fake business data to achieve the purpose of confusion, so that not only the real business data is intersected, but also the fake business data is intersected, which will inevitably increase the data processing amount of the intersection process, resulting in low data processing efficiency. In addition, if the multiple participants in a preset participant combination perform intersection set processing based on their own ciphertext data set and the ciphertext data set transmitted by other participants in the preset participant combination to obtain the shared business data of the preset participant combination, since the multiple participants in the preset participant combination are fixed, there is a problem that the determination flexibility of the shared business data is poor and cannot meet the individual needs of different participant member nodes to determine the shared business data of any participant combination. Based on the above problems, on the one hand, since the ciphertext business data is encrypted using the same encryption key array, if two ciphertext business data are the same, the corresponding two plaintext business data are also the same. Therefore, the center node can directly compare the ciphertext business data of different participant member nodes to obtain the data comparison result of the first participant member node, and then determine which same plaintext business data (i.e. shared business data) is contained between the participant member nodes based on the data comparison result. Since the data comparison process is uniformly performed by the center node, the business data will not be intercommunicated between the participant member nodes, and the center node directly performs data comparison processing based on the ciphertext business data, without the need for decryption processing of the ciphertext business data, so there is no need to obtain the corresponding data decryption key. That is, the data comparison process is in the form of ciphertext, thereby ensuring the security of the business data in the entire data processing process.On the other hand, the data comparison result obtained by each participant node from the center node can only include a data comparison sub-result related to the respective ciphertext business data of the participant node. For the case where the data comparison sub-result includes business data, the business data is also generated by the participant node itself and exists in the form of ciphertext. In the entire data processing process, only the center node can obtain all the ciphertext business data. Since the center node cannot obtain the data decryption key, it is not necessary to add fake business data to achieve the purpose of confusion. Therefore, the number of ciphertext business data used in the data comparison process is not increased, thereby improving the data processing efficiency of the entire process. On the other hand, since the data comparison result generated by the center node can include a data comparison sub-result, and each data comparison result can include the correspondence between any ciphertext business data of the first participant node and the plurality of second participant nodes holding the ciphertext business data, rather than specific to which preset participant node combination holds which common business data, the first participant node can determine the common business data of any specified participant node combination based on the data comparison sub-result of the ciphertext business data (i.e., the data comparison result obtained by performing a data comparison task once). The specified participant node combination can include all combinations of the first participant node and other participant nodes. In this way, the first participant node can determine which common business data is included in any participant node combination that it desires to know according to actual needs, thereby improving the flexibility of determining common business data and meeting the individual needs of different participant nodes to determine the common business data of any node combination.

[0037] wherein, Figure 1 a first flowchart of a data processing method provided by one or more embodiments of the present application, Figure 1 The method in the above embodiment can be executed by a center node, which can be a terminal device or a designated server. As shown in Figure 1 The method includes the following steps:

[0038] S102, obtaining a set of ciphertext data sent by a participant node; the set of ciphertext data includes ciphertext business data; the ciphertext business data is obtained by encrypting plaintext business data based on an encryption key array, and different participant nodes use the same encryption key array; the participant nodes include a first participant node;

[0039] Specifically, the n participating member nodes can belong to an inter-industry alliance, and the n participating member nodes can be n merchants or n enterprises having a preset association relationship. For example, when n is equal to 5, the n participating member nodes include participating member node 1 to participating member node 5. The center node receives the ciphertext data set 1 sent by the participating member node 1, the ciphertext data set 2 sent by the participating member node 2, the ciphertext data set 3 sent by the participating member node 3, the ciphertext data set 4 sent by the participating member node 4, and the ciphertext data set 5 sent by the participating member node 5. That is, the center node obtains n ciphertext data sets sent by the n participating member nodes, for example, the center node obtains 5 ciphertext data sets.

[0040] Specifically, the encryption key array can include a plurality of data encryption keys, which can be generated by the center node or the participating member nodes. For the ciphertext data set 1 sent by the participating member node 1, the ciphertext data set 1 is obtained by the participating member node 1 based on the encryption key array to encrypt the plaintext data set 1 (i.e., including K plaintext business data 1) generated by the participating member node 1. For the ciphertext data set 2 sent by the participating member node 2, the ciphertext data set 2 is obtained by the participating member node 2 based on the encryption key array to encrypt the plaintext data set 2 (i.e., including K plaintext business data 2) generated by the participating member node 2. The same applies to the other participating member nodes, which will not be described here.

[0041] For example, the plaintext data set can be a user list plaintext data, which includes K plaintext user information (i.e., plaintext business data, such as encrypted identity card or mobile phone number, etc.). The ciphertext data set can be a user list ciphertext data, which includes K ciphertext user information (i.e., ciphertext business data, such as encrypted identity card or mobile phone number, etc.). For another example, the plaintext data set can be a commodity list plaintext data, which includes K plaintext commodity information (i.e., plaintext business data, such as at least one of encrypted commodity code, commodity price, and commodity model). The ciphertext data set can be a commodity list ciphertext data, which includes K ciphertext commodity information (i.e., ciphertext business data, such as at least one of encrypted commodity code, commodity price, and commodity model).

[0042] It should be noted that the number of plaintext business data in the plaintext data set of different participating member nodes can be the same or different, that is, the value of K for different participating member nodes can be the same or different, which is not limited in the present application.

[0043] S104, data comparison processing is performed on the ciphertext business data in the ciphertext data set to obtain a data comparison result of the first participant node;

[0044] In some example embodiments, the data comparison result can include common business data of a preset participant node combination, i.e., the center node directly determines which common business data the preset participant node combination holds, and the first participant node obtains the common business data determined by the center node from the center node. Thus, since the multiple participants in the preset participant node combination are fixed, there is a problem of poor flexibility in determining the common business data, which cannot meet the individualized needs of different participant nodes to determine the common business data of any participant node combination. In other example embodiments, the data comparison result can include K data comparison sub-results, which represent a second participant node set holding the ciphertext business data of the first participant node. That is, the data comparison result obtained by the first participant node from the center node is not specific to which common business data a certain preset participant node combination holds. Therefore, the first participant node can determine the common business data of any designated participant node combination based on the data comparison sub-results corresponding to the K ciphertext business data (i.e., the data comparison result obtained by performing one data comparison task), thereby improving the flexibility of determining the common business data and meeting the individualized needs of different participant nodes to determine the common business data of any node combination.

[0045] Specifically, since the ciphertext business data is all encrypted using the same encryption key array, if two ciphertext business data are the same, the corresponding two plaintext business data are also the same. Therefore, the center node can directly compare the ciphertext business data of different participant nodes to find the participant nodes to which the same ciphertext business data belongs, so as to determine the second participant node set corresponding to each ciphertext business data. For the ciphertext business data a, the second participant node set corresponding to the ciphertext business data a includes multiple second participant nodes holding the ciphertext business data a among the n participant nodes. Based on this, for the first participant node, the second participant node set corresponding to the K ciphertext business data of the first participant node is determined.

[0046] Specifically, the first participant node can be any of the n participant nodes. In some example embodiments, all participant nodes are the first participant node, and the data comparison results of the n participant nodes are determined. In other example embodiments, part of the participant nodes are the first participant node, and the data comparison results of part of the n participant nodes are determined. For example, if the n participant nodes include participant node 1 to participant node 5, and all participant nodes are the first participant node, then the data comparison result 1 of participant node 1, the data comparison result 2 of participant node 2, the data comparison result 3 of participant node 3, the data comparison result 4 of participant node 4, and the data comparison result 5 of participant node 5 are determined.

[0047] Specifically, for the case where the data comparison result includes K data comparison sub-results, the S104 performs data comparison processing on the ciphertext business data in the ciphertext data set to obtain the data comparison result of the first participant node, specifically including:

[0048] Step one, performing data comparison processing on the ciphertext business data in the ciphertext data set to determine the data comparison sub-result of the ciphertext business data of the first participant node. The data comparison sub-result is used to represent the second participant node set, and all participant nodes in the second participant node set have the ciphertext business data of the first participant node.

[0049] Step two, based on the data comparison sub-result, the data comparison result of the first participant node is obtained.

[0050] For the participating member node 1, if the ciphertext data set 1 includes the ciphertext business data 11, the ciphertext business data 12 and the ciphertext business data 13, the data comparison result 1 includes the data comparison sub-result 11, the data comparison sub-result 12 and the data comparison sub-result 13; wherein the data comparison sub-result 11 is used to represent a second participating member node set 11 in the n participating member nodes that holds the ciphertext business data 11, that is, the data comparison sub-result 11 includes the corresponding relationship between the ciphertext business data 11 and the second participating member node set 11, and the second participating member node set 11 includes the node identifiers of the participating member nodes that hold the ciphertext business data 11; the data comparison sub-result 12 is used to represent a second participating member node set 12 in the n participating member nodes that holds the ciphertext business data 12, and the data comparison sub-result 13 is used to represent a second participating member node set 13 in the n participating member nodes that holds the ciphertext business data 13; based on this, the data comparison results 2 to 5 corresponding to the participating member nodes 2 to 5 are determined respectively.

[0051] In a specific implementation, the ciphertext data set includes a user list ciphertext data, and the user list ciphertext data includes K ciphertext user information, and the determination process of the data comparison result of the first participating member node can be: performing user information comparison processing based on the user list ciphertext data respectively sent by the n participating member nodes to obtain the user information comparison result of the first participating member node in the n participating member nodes.

[0052] Specifically, the user information comparison result includes K user information comparison sub-results, and the user information comparison sub-result is used to represent a second participating member node set that holds the ciphertext user information of the first participating member node; for example, for the participating member node 1, if the user list ciphertext data 1 includes the ciphertext user information 11, the ciphertext user information 12 and the ciphertext user information 13, the user information comparison result 1 includes the user information comparison sub-result 11, the user information comparison sub-result 12 and the user information comparison sub-result 13; wherein the user information comparison sub-result 11 is used to represent a second participating member node set 11 in the n participating member nodes that holds the ciphertext user information 11; the user information comparison sub-result 12 is used to represent a second participating member node set 12 in the n participating member nodes that holds the ciphertext user information 12, and the user information comparison sub-result 13 is used to represent a second participating member node set 13 in the n participating member nodes that holds the ciphertext user information 13.

[0053] Next, after the central node generates the data comparison result of the first participating member node based on the ciphertext data set sent by the participating member nodes, the central node can determine the common business data of the participating member node combination based on the data comparison result; or the first participating member node can first obtain the data comparison result from the central node, and then determine the common business data of the participating member node combination based on the data comparison result; specifically, for the process of the first participating member node obtaining the data comparison result from the central node, the central node can actively send the data comparison result to the first participating member node after generating the data comparison result, that is, the central node sends the above data comparison result to the first participating member node; or the first participating member node can obtain the data comparison result from the central node, for example, the first participating member node first sends a comparison result obtaining request to the central node, and the central node sends the data comparison result of the first participating member node to the first participating member node only after receiving the comparison result obtaining request, which is not limited in the present application and is within the protection scope of the present application.

[0054] Wherein, for the case that the first participating member node determines the common business data of the specified participating member node combination based on the above data comparison result, the above data comparison result can include K data comparison sub-results, each data comparison sub-result representing a second participating member node set with the first participating member node's ciphertext business data, and the first participating member node determines a target comparison sub-result containing the node identifiers of each participating member node in the specified participating member node combination based on the K data comparison sub-results in the data comparison result after obtaining the data comparison result, and determines the business data targeted by the target comparison sub-result as the common business data of the specified participating member node combination.

[0055] Specifically, the above specified participating member node combination includes the first participating member node and at least one fifth participating member node, and the fifth participating member node does not include the first participating member node, that is, the fifth participating member node is any participating member node different from the first participating member node in the n participating member nodes; still taking the example that the n participating member nodes include participating member node 1 to participating member node 5, if any of participating member node 1 to participating member node 5 is the first participating member node, then participating member node 1 obtains data comparison result 1 from the central node, participating member node 2 obtains data comparison result 2 from the central node, participating member node 3 obtains data comparison result 3 from the central node, participating member node 4 obtains data comparison result 4 from the central node, and participating member node 5 obtains data comparison result 5 from the central node.

[0056] Specifically, for the data comparison result including K data comparison sub-results, the data comparison sub-result represents the case of the second participant node set of the ciphertext business data of the first participant node, for the participant node 1, the participant node 1 obtains the data comparison result 1 from the center node; still taking the data comparison result 1 including the data comparison sub-result 11, the data comparison sub-result 12 and the data comparison sub-result 13 as an example, the participant node 1 can determine the common business data of any specified participant node combination based on the data comparison sub-result 11, the data comparison sub-result 12 and the data comparison sub-result 13;

[0057] For example, the data comparison sub-result 11 can be represented as {ciphertext business data 11, second participant node set 11}, the second participant node set 11 can be represented as [10001, 10002, 10003], wherein 10001 represents the node identifier of the participant node 1, 10002 represents the node identifier of the participant node 2, and 10003 represents the node identifier of the participant node 3, that is, the participant node 1, the participant node 2 and the participant node 3 all have the ciphertext business data 11, and the participant node 4 and the participant node 5 do not have the ciphertext business data 11; the data comparison sub-result 12 can be represented as {ciphertext business data 12, second participant node set 12}, the second participant node set 12 can be represented as [10001, 10004, 10005], wherein 10004 represents the node identifier of the participant node 4, and 10005 represents the node identifier of the participant node 5, that is, the participant node 1, the participant node 3 and the participant node 5 all have the ciphertext business data 12, and the participant node 2 and the participant node 4 do not have the ciphertext business data 12; the data comparison sub-result 13 can be represented as {ciphertext business data 13, second participant node set 13}, the second participant node set 13 can be represented as [10001, 10003, 10004], that is, the participant node 1, the participant node 3 and the participant node 4 all have the ciphertext business data 13, and the participant node 2 and the participant node 5 do not have the ciphertext business data 13;

[0058] Therefore, if the specified participating member node combination includes participating member node 1 and participating member node 3, the common business data of the specified participating member node combination includes: ciphertext business data 11, ciphertext business data 13, i.e., the ciphertext business data corresponding to the second participating member node set 11 [10001, 10002, 10003] and the ciphertext business data corresponding to the second participating member node set 13 [10001, 10003, 10004] in the second participating member node set 11, 12, 13 containing the node identifiers of participating member node 1 and participating member node 3 at the same time; if the specified participating member node combination includes participating member node 1 and participating member node 4, the common business data of the specified participating member node combination includes: ciphertext business data 12, ciphertext business data 13, i.e., the ciphertext business data corresponding to the second participating member node set 12 [10001, 10004, 10005] and the ciphertext business data corresponding to the second participating member node set 13 [10001, 10003, 10004] in the second participating member node set 11, 12, 13 containing the node identifiers of participating member node 1 and participating member node 4 at the same time; based on this, the first participating member node can quickly determine the common business data of any specified participating member node combination based on the above K data comparison sub-results.

[0059] That is, in the process of determining the common business data of any specified participating member node combination based on the above K data comparison sub-results, the first participating member node searches the second participating member node sets corresponding to the K data comparison sub-results for a second participating member node set containing the node identifiers of all participating member nodes in the specified participating member node combination, and determines the set of ciphertext business data corresponding to the searched second participating member node set as the common business data of the specified participating member node combination; correspondingly, if the ciphertext data set includes username list ciphertext data, the common business data is the common username list of all participating member nodes in the specified participating member node combination; for example, if the username list ciphertext data is suspected blacklist ciphertext data, the common business data is the common blacklist; if the username list ciphertext data is member username list ciphertext data, the common business data is the common member username list; in addition, the number of common business data of the specified participating member node combination can also be calculated based on the K data comparison sub-results.

[0060] In the embodiments of the present application, since all the ciphertext business data are obtained by using the same encryption key array for encryption, if two ciphertext business data are the same, then the corresponding two plaintext business data are also the same. Therefore, the center node can directly compare the ciphertext business data of different participant member nodes, and determine which plaintext business data (i.e., common business data) are contained in the different participant member nodes. In this way, the center node does not need to perform decryption processing on the ciphertext business data, and thus does not need to obtain the corresponding data decryption key. That is, the data comparison process is performed on the business data in the form of ciphertext, thereby ensuring the data security of the entire data processing process.

[0061] In addition, if the data comparison result includes K pieces of ciphertext business data of the first participant node respectively corresponding to a data comparison sub-result, i.e., the ciphertext business data and the data comparison sub-result are one-to-one corresponding, and each data comparison sub-result is used to represent a second participant node set holding a certain ciphertext business data of the first participant node, the second participant node set includes a plurality of second participant nodes having the same ciphertext business data, i.e., the data comparison sub-result includes a corresponding relationship between the ciphertext business data and the plurality of second participant nodes having the ciphertext business data, then the first participant node can determine the common business data of any specified participant node combination based on the K data comparison sub-results. It can be known that, in the embodiment of the application, the business data in the data comparison result obtained by the first participant node from the center node is also in the form of ciphertext, and the data comparison result only includes data comparison sub-results related to the respective ciphertext business data of the participant nodes. In the entire data processing process, only the center node can obtain all the ciphertext business data. Since the center node cannot obtain the data decryption key, it is not necessary to add fake business data to achieve the purpose of confusion, so the number of ciphertext business data used in the data comparison process is not increased, thereby the data processing efficiency of the entire process can be improved. In addition, since the data comparison sub-result generated by the center node includes a corresponding relationship between the ciphertext business data of the first participant node and the plurality of second participant nodes holding the ciphertext business data, but not specifically to which preset participant node combination holds which common business data, the first participant node can determine the common business data of any specified participant node combination based on the K data comparison sub-results (i.e., the data comparison result obtained by executing one data comparison task), wherein the specified participant node combination can include all combinations of the first participant node and other participant nodes. In this way, the first participant node can determine which common business data is included in any participant node combination according to actual needs, thereby improving the determination flexibility of the common business data and meeting the individual needs of different participant nodes to determine the common business data of any node combination.

[0062] In one specific embodiment, the above ciphertext data set includes a user list ciphertext data, the user list ciphertext data includes K pieces of ciphertext user information, and the data comparison result is sent to the first participant node by the center node. As shown in Figure 2 , a specific implementation process of a data processing method is given, mainly including:

[0063] (1) The participating member nodes respectively encrypt the K pieces of plaintext user information based on the encryption key array to obtain user name list ciphertext data, and different participating member nodes use the same encryption key array; for example, the n participating member nodes include participating member node 1 to participating member node 4, participating member node 1 encrypts to obtain user name list ciphertext data 1, participating member node 2 encrypts to obtain user name list ciphertext data 2, participating member node 3 encrypts to obtain user name list ciphertext data 3, and participating member node 4 encrypts to obtain user name list ciphertext data 4;

[0064] (2) The participating member nodes send the user name list ciphertext data generated by themselves to the center node;

[0065] (3) After receiving the user name list ciphertext data sent by the n participating member nodes respectively, the center node performs user information comparison processing based on the n user name list ciphertext data to obtain the user information comparison results corresponding to each participating member node; specifically, user information comparison processing is performed based on user name list ciphertext data 1 to 4 to obtain user information comparison result 1 corresponding to participating member node 1; user information comparison processing is performed based on user name list ciphertext data 1 to 4 to obtain user information comparison result 2 corresponding to participating member node 2; user information comparison processing is performed based on user name list ciphertext data 1 to 4 to obtain user information comparison result 3 corresponding to participating member node 3; user information comparison processing is performed based on user name list ciphertext data 1 to 4 to obtain user information comparison result 4 corresponding to participating member node 4;

[0066] (4) The center node sends the above user information comparison results to the corresponding participating member nodes; specifically, user information comparison result 1 is sent to participating member node 1, user information comparison result 2 is sent to participating member node 2, user information comparison result 3 is sent to participating member node 3, user information comparison result 4 is sent to participating member node 4, and user information comparison result 5 is sent to participating member node 5;

[0067] (5) The participating member nodes determine the common user name list of any specified participating member node combination based on the received user information comparison results; for example, participating member node 1 determines the common user name list a of the specified participating member node combination a, participating member node 2 determines the common user name list b of the specified participating member node combination b, participating member node 3 determines the common user name list c of the specified participating member node combination c, and participating member node 4 determines the common user name list d of the specified participating member node combination d. In addition, the number of common users of any specified participating member node combination can also be determined.

[0068] The participating member nodes are n. In the encryption process of the plaintext business data of the participating member nodes, since the center node can obtain the ciphertext business data of all the participating member nodes, in order to improve the data security, the center node cannot obtain the data encryption key, and thus cannot decrypt the ciphertext business data. Based on this, the m data encryption keys in the encryption key array are generated by m participating member nodes in the n participating member nodes, as shown in Figure 3 As shown in S102, the ciphertext data set sent by the participating member nodes is obtained, and specifically includes:

[0069] S1022, m participating member nodes in the n participating member nodes are determined as key generation nodes;

[0070] The m is an integer greater than 1 and less than or equal to n, the m key generation nodes include the first participating member node and / or the third participating member node, the third participating member node does not include the first participating member node, that is, the third participating member node is any participating member node different from the first participating member node in the n participating member nodes; Specifically, the n participating member nodes can be directly used as the key generation nodes, that is, m is equal to n, or the value of m can be set according to experience, and then m participating member nodes are randomly selected from the n participating member nodes as the key generation nodes, that is, m is less than n; However, considering that the greater the value of m, the more complex the business data encryption process, in order to improve the determination accuracy of the value of m, and at the same time, considering the data security and data encryption efficiency, the value of m can be determined based on the data security level, that is, the value of m is related to the data security level of the current data processing task, and based on this, the determination process of the key generation node includes: determining the number of participating member nodes participating in key generation based on the data security level of the data processing task; Based on the number of participating member nodes, m participating member nodes are selected from the n participating member nodes as key generation nodes.

[0071] S1024, the key generation instruction is sent to the m key generation nodes determined; the key generation instruction is used to trigger the key generation node to generate the data encryption key and send the data encryption key to the fourth participating member node;

[0072] Specifically, the fourth participating member node does not include the key generation node sending the data encryption key, that is, for each key generation node, the data encryption key generated by each key generation node is sent to other participating member nodes, and the fourth participating member node is any participating member node different from the key generation node sending the data encryption key in the n participating member nodes; The fourth participating member node and the third participating member node can be the same or different;

[0073] Specifically, the set of data encryption keys generated by the m key generation nodes respectively constitutes the encryption key array; for example, taking the value of m equal to 3 and the n participating member nodes including participating member node 1 to participating member node 5 as an example, if the 3 key generation nodes determined from the participating member nodes 1 to 5 include the participating member node 1, the participating member node 2, and the participating member node 3, then the center node sends a key generation instruction to the participating member node 1, the participating member node 2, and the participating member node 3; the participating member node 1 generates a data encryption key A1 according to the key generation mode after receiving the key generation instruction, and sends the data encryption key A1 to the participating member nodes 2 to 5; the participating member node 2 generates a data encryption key A2 according to the key generation mode after receiving the key generation instruction, and sends the data encryption key A2 to the participating member nodes 1, 3 to 5; the participating member node 3 generates a data encryption key A3 according to the key generation mode after receiving the key generation instruction, and sends the data encryption key A3 to the participating member nodes 1 to 2, 4 to 5; in this way, the participating member nodes 1 to 5 will all obtain the encryption key array (A1, A2, A3).

[0074] Specifically, considering that the arrangement order of each data encryption key in the encryption key array used by the participating member nodes 1 to 5 in the data encryption process should be consistent, so as to ensure that the ciphertext business data obtained by encrypting the same plaintext business data is the same, therefore, in the process of the center node sending the key generation instruction to the determined m key generation nodes, one key generation node can be selected from the m key generation nodes as the current sending object in turn, the key generation instruction is sent to the current sending object, after receiving the key generation success feedback information returned by the current sending object, the next current sending object is selected from the m key generation nodes, until the m key generation nodes are all selected; wherein, the key generation node sends the key generation success feedback information to the center node after sending the data encryption key generated by itself to the fourth participating member node and the fourth participating member node returns the key reception success notification; in this way, it can be ensured that the receiving order of the m data encryption keys obtained by each participating member node is consistent, so that the encryption key array constructed by each participating member node is the same.

[0075] In addition, only the data encryption keys generated by the n participating member nodes are sent between the n participating member nodes, and the n participating member nodes do not exchange business data, so there is no problem of business data leakage between the n participating member nodes, thereby further improving the data security.

[0076] S1026, obtain a ciphertext data set obtained by the n participant member nodes according to the encryption key array; the ciphertext data set includes K ciphertext service data; the ciphertext service data is obtained by encrypting the plaintext service data based on the encryption key array, and the encryption key array used by different participant member nodes is the same.

[0077] Specifically, for the process of obtaining the ciphertext data set by the center node from the participant member nodes, the participant member nodes can actively send the ciphertext data set to the center node after generating the ciphertext data set, or the center node can obtain the ciphertext data set from the participant member nodes, for example, the center node first sends a ciphertext data obtaining request to the participant member nodes, and the participant member nodes send their respective ciphertext data sets to the center node after receiving the ciphertext data obtaining request, which is not limited in the present application and is within the protection scope of the present application.

[0078] Specifically, for the process of encrypting the service data, the participant member nodes can directly use the encryption key array as a whole to encrypt the plaintext service data generated by the participant member nodes to obtain the ciphertext service data; for example, for plaintext service data a, if the encryption key array (A1, A2, A3), then the encryption key array (A1, A2, A3) is used as an encryption key sequence to encrypt the plaintext service data a to obtain the ciphertext service data a; or the participant member nodes can use m data encryption keys in the encryption key array as an encryption unit to encrypt the plaintext service data generated by the participant member nodes multiple times to obtain the ciphertext service data; for example, for plaintext service data a, if the encryption key array (A1, A2, A3), then the data encryption key A1 is used to encrypt the plaintext service data a to obtain intermediate ciphertext service data 1, the data encryption key A2 is used to encrypt the intermediate ciphertext service data 1 to obtain intermediate ciphertext service data 2, and the data encryption key A3 is used to encrypt the intermediate ciphertext service data 2 to obtain the final ciphertext service data a; then, any participant member node encrypts the K plaintext service data respectively based on the encryption key array to obtain a ciphertext data set containing K ciphertext service data, and then sends the ciphertext data set to the center node.

[0079] In order to ensure that each participant member node obtains m data encryption keys and forms an encryption key array, and then triggers the participant member nodes to perform data encryption, based on this, S1026, obtaining the ciphertext data set obtained by the n participant member nodes according to the encryption key array, specifically includes:

[0080] Step one, in the case of m data encryption key generation ends, send data encryption instructions to n participating member nodes; the above-mentioned data encryption instruction is used to trigger the participating member node to encrypt the plaintext business data generated by the participating member node based on the encryption key array to obtain the ciphertext business data;

[0081] Specifically, since the key generation node successfully sends the data encryption key generated by itself to the fourth participating member node (i.e. the key generation node receives the key reception success notification returned by the fourth participating member node), the key generation node will send the key generation success feedback information to the center node; therefore, after the center node receives the key generation success feedback information sent by the m key generation nodes respectively, the center node determines that the m data encryption keys are generated, and then the center node sends the data encryption instruction to the n participating member nodes.

[0082] Step two, obtain the ciphertext data set containing K ciphertext business data sent by each participating member node respectively.

[0083] In one embodiment, still taking the above-mentioned ciphertext data set including username list ciphertext data, the username list ciphertext data including K ciphertext user information, and the data comparison result sent by the center node to the first participating member node as an example; on the basis of the above Figure 2 , a specific implementation process of a data processing method is given as shown in Figure 4 , mainly including:

[0084] (1) the center node selects m participating member nodes as key generation nodes from n participating member nodes based on the data security level; for example, n is equal to m, that is, the above-mentioned participating member node 1 to participating member node 4 are all key generation nodes;

[0085] (2) the center node sends the key generation instruction to each participating member node in turn;

[0086] (3) after the participating member node receives the key generation instruction, it generates its own data encryption key according to the key generation mode, and sends its own data encryption key to the fourth participating member node;

[0087] (4) after the participating member node receives the key reception success notification returned by the fourth participating member node, it sends the key generation success feedback information to the center node;

[0088] (5) the center node sends the data encryption instruction to each participating member node after receiving the key generation success feedback information of each participating member node;

[0089] (6) After receiving the data encryption instruction, the participating member node respectively encrypts the K pieces of plaintext user information based on the encryption key array to obtain user name list ciphertext data; wherein the encryption key array is constructed based on the respective data encryption key and the received data encryption key according to the order of obtaining the data encryption key;

[0090] (7) The participating member node sends the user name list ciphertext data generated by itself to the center node;

[0091] (8) The center node performs user information comparison processing based on the n pieces of user name list ciphertext data to obtain the user information comparison result corresponding to each participating member node;

[0092] (9) The center node sends the above-mentioned user information comparison result to the corresponding participating member node;

[0093] (10) The participating member node determines the common user name list of any specified participating member node combination based on the received user information comparison result.

[0094] Among them, for the determination process of the data comparison result of the first participating member node, the above step one, the ciphertext business data in the ciphertext data set is subjected to data comparison processing to determine the data comparison sub-result of the ciphertext business data of the first participating member node, which specifically includes:

[0095] Selecting the ciphertext business data to be compared from the K pieces of ciphertext business data of the first participating member node;

[0096] According to the current selected ciphertext business data to be compared and the ciphertext business data in the n ciphertext data sets, the node identifier of the second participating member node is determined, and the second participating member node has the ciphertext business data to be compared;

[0097] According to the node identifier of the second participating member node and the ciphertext business data to be compared, the data comparison sub-result corresponding to the ciphertext business data to be compared is generated.

[0098] In one specific embodiment, still taking n participating member nodes including participating member node 1 to participating member node 4 as an example, as shown in Figure 5 The specific process of the center node determining the data comparison result 1 of the participating member node 1 based on the n key data sets mainly includes:

[0099] For the first participant node being participant node 1, if the K plaintext business data of participant node 1 (i.e., plaintext data set 1) includes plaintext business data 11, plaintext business data 12 and plaintext business data 13, correspondingly, after the encryption key array is used to encrypt the plaintext business data, the K ciphertext business data of participant node 1 (i.e., ciphertext data set 1) includes ciphertext business data 11, ciphertext business data 12 and ciphertext business data 13; similarly, participant node 2 encrypts each plaintext business data in plaintext data set 2 to generate ciphertext data set 2 (including ciphertext business data 21 to ciphertext business data 2i), participant node 3 encrypts each plaintext business data in plaintext data set 3 to generate ciphertext data set 3 (including ciphertext business data 31 to ciphertext business data 3j), and participant node 4 encrypts each plaintext business data in plaintext data set 4 to generate ciphertext data set 4 (including ciphertext business data 41 to ciphertext business data 4h), where i, j and h are all integers greater than 1;

[0100] In the process of determining the data comparison result 1 of participant node 1 based on the n key data sets, first, the ciphertext business data 11 is taken as the first to-be-compared ciphertext business data, and the ciphertext business data 11 is compared with each ciphertext business data in the ciphertext data set corresponding to participant node 2 to participant node 4, according to the comparison result, the participant node holding the ciphertext business data 11 is taken as the second participant node of the ciphertext business data 11, the second participant node set 11 is obtained, and then the data comparison sub-result 11 is obtained; for example, the data comparison sub-result 11 corresponding to the ciphertext business data 11 can be expressed as {ciphertext business data 11, second participant node set 11}, if participant nodes 1 to 3 all contain the same ciphertext business data as the ciphertext business data 11, then the second participant node set 11 can be expressed as [10001, 10002, 10003];

[0101] Then, the ciphertext business data 12 is taken as the next to-be-compared ciphertext business data, and the ciphertext business data 12 is compared with each ciphertext business data in the ciphertext data set corresponding to participant node 2 to participant node 4, according to the comparison result, the participant node holding the ciphertext business data 12 is taken as the second participant node of the ciphertext business data 12, the second participant node set 12 is obtained, and then the data comparison sub-result 12 is obtained; for example, the data comparison sub-result 12 corresponding to the ciphertext business data 12 can be expressed as {ciphertext business data 12, second participant node set 12}, if participant nodes 1 and 4 all contain the same ciphertext business data as the ciphertext business data 12, then the second participant node set 12 can be expressed as [10001, 10004];

[0102] Next, the ciphertext business data 13 is taken as the next ciphertext business data to be compared, and the ciphertext business data 13 is compared with each ciphertext business data in the ciphertext data set corresponding to the participating member node 2 to the participating member node 4 respectively, according to the comparison result, the participating member node holding the ciphertext business data 13 is taken as the second participating member node of the ciphertext business data 13, the second participating member node set 13 is obtained, and then the data comparison sub-result 13 is obtained; for example, the data comparison sub-result 13 corresponding to the ciphertext business data 13 can be expressed as {ciphertext business data 13, second participating member node set 13}, if the participating member node 1, 3, 4 all contain the same ciphertext business data as the ciphertext business data 13, then the second participating member node set 13 can be expressed as [10001, 10003, 10004];

[0103] Up to now, the data comparison sub-results 11, 12, 13 corresponding to the ciphertext business data 11, the ciphertext business data 12 and the ciphertext business data 13 of the participating member node 1 have been determined, thereby obtaining the data comparison result 1 of the participating member node 1; similarly, the data comparison result 2 of the participating member node 2, the data comparison result 3 of the participating member node 3 and the data comparison result 4 of the participating member node 4 are determined in turn, and the specific process is not described here.

[0104] Among them, considering that for the same ciphertext business data, no matter which participating member node the ciphertext business data belongs to, the second participating member node set determined for the ciphertext business data is the same, based on this, if the ciphertext business data has been selected as the ciphertext business data to be compared in the process of determining the data comparison sub-result of other participating member nodes, the second participating member node set corresponding to the ciphertext business data is known, therefore, in order to improve the determination efficiency of the data comparison result, the data comparison sub-result corresponding to the selected ciphertext business data to be compared can be added to the historical comparison sub-result set, so that for the currently selected ciphertext business data to be compared, it is first judged whether the first comparison sub-result corresponding to the currently selected ciphertext business data to be compared exists in the historical comparison sub-result set; if it exists, the first comparison sub-result can be directly determined as the data comparison sub-result of the currently selected ciphertext business data to be compared, only in the case of non-existence, the currently selected ciphertext business data to be compared is compared with each ciphertext business data in the ciphertext data set corresponding to other participating member nodes one by one, specifically, the above-mentioned data comparison processing of the currently selected ciphertext business data to be compared with the ciphertext business data in the n ciphertext data sets to determine the node identifier of the second participating member node, specifically including:

[0105] Step C1, determining whether there is a first comparison sub-result of the to-be-compared ciphertext business data in the historical comparison sub-result set; wherein the historical comparison sub-result set includes data comparison sub-results of the completed comparison of the ciphertext business data;

[0106] For example, in the process of determining the data comparison result 1 for the participating member node 1, for any to-be-compared ciphertext business data in the ciphertext data set 1, based on the data comparison processing of the to-be-compared ciphertext business data and the n ciphertext data sets, the data comparison sub-result of the to-be-compared ciphertext business data is determined, and the data comparison sub-result of the to-be-compared ciphertext business data is added to the historical comparison sub-result set; specifically, the data comparison sub-result 11 corresponding to the ciphertext business data 11, the data comparison sub-result 12 corresponding to the ciphertext business data 12, and the data comparison sub-result 13 corresponding to the ciphertext business data 13 are determined, and the data comparison sub-result 11, the data comparison sub-result 12, and the data comparison sub-result 13 are added to the historical comparison sub-result set; based on this, after the data comparison result 1 for the participating member node 1 is determined, the historical comparison sub-result set includes the data comparison sub-result 11 corresponding to the ciphertext business data 11, the data comparison sub-result 12 corresponding to the ciphertext business data 12, and the data comparison sub-result 13 corresponding to the ciphertext business data 13; therefore, in the process of determining the data comparison result 2 for the participating member node 2, for any ciphertext business data in the ciphertext data set 2, it is first determined whether there is a data comparison sub-result of the ciphertext business data in the historical comparison sub-result set.

[0107] Step C2, if there is, determining the node identifier of the second participating member node with the to-be-compared ciphertext business data based on the first comparison sub-result;

[0108] Specifically, if there is a first comparison sub-result corresponding to the to-be-compared ciphertext business data in the historical comparison sub-result set, it means that in the process of determining the data comparison sub-result of the other participating member node, the ciphertext business data has been selected as the to-be-compared ciphertext business data, and the second participating member node set corresponding to the ciphertext business data is known, therefore, the first comparison sub-result in the historical comparison sub-result set can be directly determined as the data comparison sub-result of the to-be-compared ciphertext business data, and there is no need to perform the step of performing data comparison of the to-be-compared ciphertext business data and the n ciphertext data sets.

[0109] Step C3, if not present, based on the above to be compared with the ciphertext business data and n ciphertext data set of the ciphertext business data data comparison processing, determine the second participant node with the ciphertext business data to be compared; Specifically, the ciphertext business data to be compared is compared with part of the ciphertext business data in the ciphertext data set sent by the n participant nodes respectively.

[0110] In addition, in the process of determining the data comparison result 1 for the participant node 1, not only the data comparison sub result of the ciphertext business data to be compared is added to the historical comparison sub result set, but also the data comparison sub result of the ciphertext business data to be compared is stored in the reserved comparison sub result set. After determining the data comparison sub result 11, the data comparison sub result 12 and the data comparison sub result 13, the reserved comparison sub result set includes the data comparison sub result 11, the data comparison sub result 12 and the data comparison sub result 13, that is, each data comparison sub result in the reserved comparison sub result set is taken out, and the combination of each data comparison sub result taken out is determined as the data comparison result 1. Next, the data comparison sub result determined for the participant node 2 can be stored in the reserved comparison sub result set, so as to obtain the data comparison result 2.

[0111] It should be noted that in the data comparison process, the ciphertext business data to be compared does not need to be compared with the ciphertext data set of the first participant node currently targeted, but only needs to be compared with the ciphertext data set of other participant nodes except the first participant node currently targeted; Considering that for the first participant node for which the data comparison result has been determined, the ciphertext business data to be compared has been compared with the ciphertext data set of the first participant node, therefore, in order to further improve the data comparison efficiency, the ciphertext business data to be compared can only need to be compared with the ciphertext data set of other participant nodes except the first participant node currently targeted and the first participant node for which the data comparison result has been determined.

[0112] The data processing method in the embodiments of the present application, on the one hand, since the ciphertext business data are all encrypted using the same encryption key array, if two ciphertext business data are the same, the corresponding two plaintext business data are also the same, therefore, the center node can directly compare the ciphertext business data of different participating member nodes to obtain the data comparison result of the first participating member node, and then determine which plaintext business data (i.e., common business data) are included in the participating member nodes based on the data comparison result, so that since the data comparison process is uniformly performed by the center node, the business data cannot be exchanged between the participating member nodes, and the center node directly performs data comparison processing based on the ciphertext business data, without the need to decrypt the ciphertext business data, and thus without the need to obtain the corresponding data decryption key, that is, the business data in the data comparison process exists in the form of ciphertext, thereby ensuring the security of the business data in the entire data processing process; on the other hand, the data comparison result obtained by each participating member node from the center node can only include a data comparison sub-result related to the ciphertext business data of the participating member node itself, and for the case where the data comparison sub-result includes business data, the business data is also generated by the participating member node itself and exists in the form of ciphertext, and in the entire data processing process, only the center node can obtain all the ciphertext business data, since the center node cannot obtain the data decryption key, there is no need to increase the number of ciphertext business data used in the data comparison process by adding fake business data, thereby improving the data processing efficiency of the entire process; on the other hand, since the data comparison result generated by the center node can include the data comparison sub-result, and each data comparison result can include the correspondence between any ciphertext business data of the first participating member node and the plurality of second participating member nodes holding the ciphertext business data, rather than which common business data is held by a certain preset participating member node combination, therefore, the first participating member node can determine the common business data of any specified participating member node combination based on the data comparison sub-result of the ciphertext business data (i.e., the data comparison result obtained by performing a data comparison task once), wherein the specified participating member node combination can include all combinations of the first participating member node and other participating member nodes, so that the first participating member node can determine which common business data is included in any participating member node combination according to actual needs, thereby improving the determination flexibility of the common business data and meeting the individual needs of different participating member nodes to determine the common business data of any node combination.

[0113] Corresponding to the above Figures 1 to 5 The data processing method described above is based on the same technical concept, and the embodiments of the present application also provide a data processing method, Figure 6 The flowchart of the data processing method provided by the embodiments of the present application is shown inFigure 6 The method in the code can be executed by the first participating member node, such as... Figure 6 As shown, the method includes at least the following steps:

[0114] S602, the plaintext business data is encrypted based on the encryption key array to obtain a ciphertext data set; the ciphertext data set includes the ciphertext business data, and different participating member nodes use the same encryption key array.

[0115] S604, the above-mentioned encrypted data set is sent to the central node; specifically, the central node performs data comparison processing based on the encrypted data set sent by the participating member nodes to obtain the data comparison result of the first participating member node;

[0116] In some example embodiments, the data comparison results may include shared business data of a preset combination of participating member nodes. That is, the central node directly determines which shared business data the preset combination of participating member nodes holds, and the first participating member node obtains the shared business data determined by the central node. Since the multiple participants in the preset combination of participating member nodes are fixed, this inevitably results in poor flexibility in determining the shared business data, failing to meet the personalized needs of different participating member nodes in determining the shared business data of any combination of participating member nodes. In other example embodiments, the data comparison results may include K data comparison sub-results, each data comparison sub-result being used to characterize the encrypted business data held by the first participating member node. The second set of participating member nodes for business data, i.e., the data comparison results obtained by the first participating member node from the central node, are not specific to which shared business data is held by a certain preset combination of participating member nodes. Therefore, the first participating member node can determine the shared business data of any specified combination of participating member nodes based on the data comparison sub-results corresponding to K encrypted business data (i.e., the data comparison results obtained by performing a data comparison task). In this way, the first participating member node can determine which shared business data is specifically included in any combination of participating member nodes according to actual needs, thereby improving the flexibility of determining shared business data and meeting the personalized needs of different participating member nodes to determine the shared business data of any combination of nodes.

[0117] S606, Obtain the data comparison results generated by the central node; the above data comparison results are obtained by comparing the ciphertext business data in the above ciphertext data set.

[0118] Specifically, the data comparison result can be obtained by the center node based on the ciphertext business data in the ciphertext data sets respectively sent by the n participant member nodes; after obtaining the data comparison result, the first participant member node determines the common business data of the participant member node combination based on the data comparison result; in the case that the data comparison result includes the common business data of the preset participant member node combination, the first participant member node can directly obtain the common business data of the preset participant member node combination based on the data comparison result; and in the case that the data comparison result includes K data comparison sub-results obtained by data comparison processing based on the ciphertext data sets sent by the n participant member nodes, each data comparison sub-result represents the case that the second participant member node set holding the ciphertext business data of the first participant member node, the first participant member node determines the common business data of any specified participant member node combination based on the K data comparison sub-results received, and the specified participant member node combination includes the first participant member node and at least one fifth participant member node.

[0119] Specifically, after obtaining the data comparison result, the first participant member node determines the target comparison sub-result containing the node identifiers of all the participant member nodes in the specified participant member node combination based on the K data comparison sub-results in the data comparison result, and determines the business data to which the target comparison sub-result is directed as the common business data of the specified participant member node combination.

[0120] In the embodiments of the present application, since the ciphertext business data is all encrypted using the same encryption key array, if two ciphertext business data are the same, the corresponding two plaintext business data are also the same, therefore, the center node can directly compare the ciphertext business data of different participant member nodes, and determine which plaintext business data are contained in the different participant member nodes (i.e. the common business data), so that the center node does not need to decrypt the ciphertext business data, and thus does not need to obtain the corresponding data decryption key, that is, the data comparison process is in the form of ciphertext, thereby ensuring the data security of the entire data processing process.

[0121] In addition, if the data comparison result includes K pieces of ciphertext business data of the first participant node respectively corresponding to a data comparison sub-result, i.e., the ciphertext business data and the data comparison sub-result are one-to-one corresponding, and each data comparison sub-result is used to represent a second participant node set holding a certain ciphertext business data of the first participant node, the second participant node set includes a plurality of second participant nodes holding the same ciphertext business data, i.e., the data comparison sub-result includes a corresponding relationship between the ciphertext business data and the plurality of second participant nodes holding the ciphertext business data, the first participant node can determine the common business data of any specified participant node combination based on the K data comparison sub-results. It can be known that, in the embodiment of the application, the business data in the data comparison result obtained by the first participant node from the center node is also in the form of ciphertext, and the data comparison result only includes data comparison sub-results related to the respective ciphertext business data of the participant nodes. In the entire data processing process, only the center node can obtain all the ciphertext business data. Since the center node cannot obtain the data decryption key, it is not necessary to add fake business data to achieve the purpose of confusion, so the number of ciphertext business data used in the data comparison process is not increased, thereby improving the data processing efficiency of the entire process. In addition, since the data comparison sub-result generated by the center node includes a corresponding relationship between the ciphertext business data of the first participant node and the plurality of second participant nodes holding the ciphertext business data, and is not specific to which common business data is held by a certain predetermined participant node combination, the first participant node can determine the common business data of any specified participant node combination based on the K data comparison sub-results (i.e., the data comparison result obtained by performing a data comparison task once), wherein the specified participant node combination can include a node combination obtained by all combination modes between the first participant node and other participant nodes. In this way, the first participant node can determine which common business data is included in any participant node combination expected to be known according to actual needs, thereby improving the determination flexibility of the common business data and meeting the individual needs of different participant nodes to determine the common business data of any node combination.

[0122] In the step S602, the plaintext business data is encrypted based on the encryption key array to obtain a ciphertext data set, and the step S602 specifically includes:

[0123] determining an encryption key array including m data encryption keys, wherein the key generation nodes of the m data encryption keys include the first participant node and / or the third participant node, and m is an integer greater than 1 and less than or equal to n;

[0124] In the case of receiving the data encryption instruction sent by the center node, the plaintext service data generated by the first participant node is encrypted based on the encryption key array to obtain a ciphertext data set.

[0125] In the case that the ciphertext data set includes username list ciphertext data, the username list ciphertext data includes K ciphertext user information, and the data comparison result is a user information comparison result including K user information comparison subresults, the user information comparison subresult is used to represent the second participant node set holding the ciphertext user information of the first participant node.

[0126] The data processing method in the embodiment of the application, on the one hand, since the ciphertext business data are all obtained by using the same encryption key array for encryption, if two ciphertext business data are the same, then the corresponding two plaintext business data are also the same, therefore, the center node can directly compare the ciphertext business data of different participating member nodes to obtain the data comparison result of the first participating member node, and then determine which same plaintext business data (i.e., common business data) are contained between the participating member nodes based on the data comparison result, so that since the data comparison process is uniformly performed by the center node, the business data cannot be communicated between the participating member nodes, and the center node directly performs data comparison processing based on the ciphertext business data, without the need to perform decryption processing on the ciphertext business data, and thus without the need to obtain the corresponding data decryption key, that is, the business data in the data comparison process exists in the form of ciphertext, thereby ensuring the business data security of the entire data processing process; on the other hand, the data comparison result obtained by each participating member node from the center node can only include a data comparison sub-result related to the ciphertext business data of the participating member node itself, and for the case that the data comparison sub-result includes business data, the business data is also generated by the participating member node itself and exists in the form of ciphertext, and in the entire data processing process, only the center node can obtain all the ciphertext business data, since the center node cannot obtain the data decryption key, there is no need to increase the number of ciphertext business data used in the data comparison process by adding fake business data, so as to improve the data processing efficiency of the entire process; on the other hand, since the data comparison result generated by the center node can include the data comparison sub-result, and each data comparison result can include the correspondence between any ciphertext business data of the first participating member node and the plurality of second participating member nodes holding the ciphertext business data, rather than which common business data is held by a certain preset participating member node combination, therefore, the first participating member node can determine the common business data of any specified participating member node combination based on the data comparison sub-result of the ciphertext business data (i.e., the data comparison result obtained by performing one data comparison task), wherein the specified participating member node combination can include all combinations of the first participating member node and other participating member nodes, so that the first participating member node can determine which common business data is contained in any participating member node combination according to actual needs, thereby improving the determination flexibility of the common business data and meeting the individual needs of different participating member nodes to determine the common business data of any node combination.

[0127] It should be noted that the embodiment in the present application and the previous embodiment in the present application are based on the same inventive concept, so the specific implementation of the embodiment can be referred to the implementation of the foregoing data processing method, and the repeated parts will not be described again.

[0128] Corresponding to the above Figures 1 to 5 The data processing method described, based on the same technical concept, the embodiments of the present application also provide a data processing device, Figure 7 The module composition diagram of the data processing device provided by the embodiments of the present application is set in the center node, and the device is used for executing Figures 1 to 5 The data processing method described, as shown in Figure 7 The device comprises:

[0129] The data acquisition module 702 is used for acquiring the ciphertext data set sent by the participating member node, the ciphertext data set comprises ciphertext business data, the ciphertext business data is obtained by encrypting the plaintext business data based on the encryption key array, the encryption key array used by different participating member nodes is the same, and the participating member node comprises a first participating member node;

[0130] The data comparison module 704 is used for data comparison processing on the ciphertext business data in the ciphertext data set, so as to obtain the data comparison result of the first participating member node.

[0131] The data processing apparatus in the embodiments of the present application, on the one hand, since the ciphertext business data are all obtained by using the same encryption key array for encryption, if two ciphertext business data are the same, then the corresponding two plaintext business data are also the same, therefore, the center node can directly compare the ciphertext business data of different participating member nodes to obtain the data comparison result of the first participating member node, and then determine which same plaintext business data (i.e., common business data) are contained between the participating member nodes based on the data comparison result, so that since the data comparison process is uniformly performed by the center node, the business data cannot be communicated between the participating member nodes, and the center node directly performs data comparison processing based on the ciphertext business data, without the need to perform decryption processing on the ciphertext business data, and thus without the need to obtain the corresponding data decryption key, that is, the business data in the data comparison process exists in the form of ciphertext, thereby ensuring the business data security of the entire data processing process; on the other hand, the data comparison result obtained by each participating member node from the center node can only include a data comparison sub-result related to the ciphertext business data of the participating member node itself, and for the case that the data comparison sub-result contains business data, the business data is also generated by the participating member node itself and exists in the form of ciphertext, and in the entire data processing process, only the center node can obtain all the ciphertext business data, since the center node cannot obtain the data decryption key, it is not necessary to add fake business data to achieve the purpose of confusion, therefore, the number of ciphertext business data used in the data comparison process is not increased, thereby the data processing efficiency of the entire process can be improved; on the other hand, since the data comparison result generated by the center node can include the data comparison sub-result, and each data comparison result can include the correspondence between any ciphertext business data of the first participating member node and the plurality of second participating member nodes holding the ciphertext business data, rather than specifically to which common business data is held by a certain preset participating member node combination, therefore, the first participating member node can determine the common business data of any specified participating member node combination based on the data comparison sub-result of the ciphertext business data (i.e., the data comparison result obtained by executing one data comparison task), wherein the specified participating member node combination can include all combinations of the first participating member node and other participating member nodes, so that the first participating member node can determine which common business data is contained in any participating member node combination according to actual needs, thereby improving the determination flexibility of the common business data, and meeting the individualized needs of different participating member nodes to determine the common business data of any node combination.

[0132] It should be noted that the embodiments of the data processing apparatus in the present application and the embodiments of the data processing method in the present application are based on the same inventive concept, therefore the specific implementation of the embodiments can be referred to the foregoing implementation of the corresponding data processing method, and the repeated parts will not be described herein again.

[0133] Corresponding to the above Figure 6 The data processing method described, based on the same technical concept, the embodiments of the present application also provide a data processing device, Figure 8 The module composition diagram of the data processing device provided by the embodiments of the present application is set in the first participant node, and the device is used for executing Figure 6 The data processing method described, as shown in Figure 8 The device comprises:

[0134] The data encryption module 802 is used for encrypting the plaintext business data based on the encryption key array to obtain a ciphertext data set; the ciphertext data set comprises ciphertext business data, and the encryption key array used by different participant nodes is the same;

[0135] The data sending module 804 is used for sending the ciphertext data set to the center node;

[0136] The result obtaining module 806 is used for obtaining the data comparison result generated by the center node; the data comparison result is obtained by data comparison based on the ciphertext business data in the ciphertext data set.

[0137] The data processing apparatus in the embodiments of the present application, on the one hand, since the ciphertext business data are all obtained by using the same encryption key array for encryption, if two ciphertext business data are the same, then the corresponding two plaintext business data are also the same, therefore, the center node can directly compare the ciphertext business data of different participating member nodes to obtain the data comparison result of the first participating member node, and then determine which same plaintext business data (i.e., common business data) are contained between the participating member nodes based on the data comparison result, so that since the data comparison process is uniformly performed by the center node, the business data cannot be communicated between the participating member nodes, and the center node directly performs data comparison processing based on the ciphertext business data, without the need to perform decryption processing on the ciphertext business data, and thus without the need to obtain the corresponding data decryption key, that is, the business data in the data comparison process exists in the form of ciphertext, thereby ensuring the business data security of the entire data processing process; on the other hand, the data comparison result obtained by each participating member node from the center node can only include a data comparison sub-result related to the ciphertext business data of the participating member node itself, and for the case that the data comparison sub-result contains business data, the business data is also generated by the participating member node itself and exists in the form of ciphertext, and in the entire data processing process, only the center node can obtain all the ciphertext business data, since the center node cannot obtain the data decryption key, it is not necessary to add fake business data to achieve the purpose of confusion, therefore, the number of ciphertext business data used in the data comparison process is not increased, thereby the data processing efficiency of the entire process can be improved; on the other hand, since the data comparison result generated by the center node can include the data comparison sub-result, and each data comparison result can include the correspondence between any ciphertext business data of the first participating member node and the plurality of second participating member nodes holding the ciphertext business data, rather than specifically to which common business data is held by a certain preset participating member node combination, therefore, the first participating member node can determine the common business data of any specified participating member node combination based on the data comparison sub-result of the ciphertext business data (i.e., the data comparison result obtained by performing a data comparison task once), wherein the specified participating member node combination can include all combinations of the first participating member node and other participating member nodes, so that the first participating member node can determine which common business data is contained in any participating member node combination according to actual needs, thereby improving the determination flexibility of the common business data, and meeting the individualized needs of different participating member nodes to determine the common business data of any node combination.

[0138] It should be noted that the embodiments of the data processing apparatus in the present application and the embodiments of the data processing method in the present application are based on the same inventive concept, therefore the specific implementation of the embodiments can be referred to the foregoing implementation of the corresponding data processing method, and the repeated parts will not be described herein again.

[0139] Further, corresponding to the above-mentioned Figures 1 to 6 method, based on the same technical concept, the embodiments of the present application further provide an electronic device, which is used to execute the above-mentioned data processing method, as shown in Figure 9 .

[0140] The electronic device can have a large difference due to different configurations or performances, and can include one or more processors 901 and memories 902, and the memories 902 can store one or more stored application programs or data. The memory 902 can be a temporary storage or a persistent storage. The application programs stored in the memory 902 can include one or more modules (not shown in the figure), and each module can include a series of computer executable instructions in the electronic device. Further, the processor 901 can be configured to communicate with the memory 902 and execute a series of computer executable instructions in the memory 902 on the electronic device. The electronic device can further include one or more power supplies 903, one or more wired or wireless network interfaces 904, one or more input and output interfaces 905, one or more keyboards 906, and the like.

[0141] In one specific embodiment, the electronic device includes a memory and one or more programs, wherein one or more programs are stored in the memory, and the one or more programs can include one or more modules, and each module can include a series of computer executable instructions in the electronic device, and the one or more processors are configured to execute the one or more programs include computer executable instructions for:

[0142] obtaining a ciphertext data set sent by a participating member node, the ciphertext data set including ciphertext business data, the ciphertext business data being obtained by encrypting plaintext business data based on an encryption key array, different participating member nodes using the same encryption key array, the participating member node including a first participating member node;

[0143] performing data comparison processing on the ciphertext business data in the ciphertext data set to obtain a data comparison result of the first participating member node.

[0144] In another specific embodiment, the electronic device includes a memory and one or more programs, wherein one or more programs are stored in the memory, and the one or more programs can include one or more modules, and each module can include a series of computer executable instructions in the electronic device, and the one or more processors are configured to execute the one or more programs include computer executable instructions for:

[0145] encrypting the plaintext service data based on the encryption key array to obtain a ciphertext data set; the ciphertext data set includes ciphertext service data, and encryption key arrays used by different participant nodes are the same;

[0146] sending the ciphertext data set to a center node;

[0147] obtaining a data comparison result generated by the center node; the data comparison result is obtained based on data comparison of the ciphertext service data in the ciphertext data set.

[0148] The electronic device in the embodiments of the present application, on the one hand, since the ciphertext business data are all obtained by using the same encryption key array for encryption, if the two ciphertext business data are the same, then the corresponding two plaintext business data are also the same, therefore, the center node can directly compare the ciphertext business data of different participating member nodes to obtain the data comparison result of the first participating member node, and then determine which same plaintext business data (i.e., common business data) are contained between the participating member nodes based on the data comparison result, so that since the data comparison process is uniformly performed by the center node, the business data cannot be communicated between the participating member nodes, and the center node directly performs data comparison processing based on the ciphertext business data, without the need to perform decryption processing on the ciphertext business data, and thus without the need to obtain the corresponding data decryption key, that is, the business data in the data comparison process exists in the form of ciphertext, thereby ensuring the business data security of the entire data processing process; on the other hand, the data comparison result obtained by each participating member node from the center node can only include a data comparison sub-result related to the ciphertext business data of the participating member node itself, and for the case that the data comparison sub-result includes business data, the business data is also generated by the participating member node itself and exists in the form of ciphertext, and in the entire data processing process, only the center node can obtain all the ciphertext business data, since the center node cannot obtain the data decryption key, it is not necessary to increase the number of ciphertext business data used in the data comparison process by adding fake business data, so as to improve the data processing efficiency of the entire process; on the other hand, since the data comparison result generated by the center node can include the data comparison sub-result, and each data comparison result can include the correspondence between any ciphertext business data of the first participating member node and the plurality of second participating member nodes holding the ciphertext business data, rather than which common business data is held by a certain preset participating member node combination, therefore, the first participating member node can determine the common business data of any specified participating member node combination based on the data comparison sub-result of the ciphertext business data (i.e., the data comparison result obtained by performing a data comparison task once), wherein the specified participating member node combination can include all combinations of the first participating member node and other participating member nodes, so that the first participating member node can determine which common business data is contained in any participating member node combination according to actual needs, thereby improving the determination flexibility of the common business data and meeting the individual needs of different participating member nodes to determine the common business data of any node combination.

[0149] It should be noted that the embodiments of the electronic device in the present application and the embodiments of the data processing method in the present application are based on the same inventive concept, and therefore the specific implementation of the embodiments can refer to the corresponding data processing method implementation described above, and the repeated parts will not be described again.

[0150] Further, corresponding to the above Figures 1 to 6 Further, corresponding to the above

[0151] obtain a ciphertext data set sent by a participating member node, the ciphertext data set comprising ciphertext business data, the ciphertext business data being obtained by encrypting plaintext business data based on an encryption key array, the encryption key array used by different participating member nodes being the same, the participating member node comprising a first participating member node; perform data comparison processing on the ciphertext business data in the ciphertext data set to obtain a data comparison result of the first participating member node.

[0152] Further, corresponding to the above

[0153] Further, corresponding to the above

[0154] Further, corresponding to the above

[0155] The computer executable instructions stored in the storage medium in the embodiment of the application, when executed by the processor, on one hand, since the ciphertext business data is all obtained by using the same encryption key array for encryption, if two ciphertext business data are same, then the corresponding two plaintext business data are also same, therefore, the center node can directly compare the ciphertext business data of different participating member nodes to obtain the data comparison result of the first participating member node, and then determine which same plaintext business data (i.e. common business data) is contained between the participating member nodes based on the data comparison result, so that since the data comparison process is uniformly executed by the center node, the business data will not be communicated between the participating member nodes, and the center node directly performs data comparison processing based on the ciphertext business data, without the need for decryption processing of the ciphertext business data, and thus without the need for obtaining the corresponding data decryption key, that is, the business data in the data comparison process exists in the form of ciphertext, thereby ensuring the business data security of the entire data processing process; on the other hand, the data comparison result obtained by each participating member node from the center node can only include the data comparison sub-result related to the ciphertext business data of the participating member node itself, for the case that the data comparison sub-result contains business data, the business data is also generated by the participating member node itself and exists in the form of ciphertext, in the entire data processing process, only the center node can obtain all the ciphertext business data, since the center node cannot obtain the data decryption key, it is not necessary to increase the number of counterfeit business data to achieve the purpose of confusion, therefore, the number of ciphertext business data used in the data comparison process will not be increased, thereby the data processing efficiency of the entire process can be improved; on the other hand, since the data comparison result generated by the center node can include the data comparison sub-result, and each data comparison result can include the corresponding relationship between any ciphertext business data of the first participating member node and the plurality of second participating member nodes holding the ciphertext business data, rather than specifically to which common business data is held by a certain preset participating member node combination, therefore, the first participating member node can determine the common business data of any specified participating member node combination based on the data comparison sub-result of the ciphertext business data (i.e. the data comparison result obtained by executing a data comparison task once), wherein the specified participating member node combination can include the node combination obtained by all combination modes between the first participating member node and other participating member nodes, so that the first participating member node can determine which common business data is contained in any participating member node combination according to actual needs, thereby improving the determination flexibility of the common business data, and meeting the individualized needs of different participating member nodes to determine the common business data of any node combination.

[0156] It should be noted that the embodiments of the storage medium in the present application are based on the same inventive concept as the embodiments of the data processing method in the present application, and therefore the specific implementation of the embodiments can be referred to the foregoing implementation of the corresponding data processing method, and the repeated parts will not be described herein.

[0157] The above describes specific embodiments of the present application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in a different order and still accomplish the desired result. Additionally, the processes depicted in the accompanying figures do not necessarily require the particular order shown, or sequential order, to achieve the desired results. In certain implementations, multitasking and parallel processing can be advantageous. One skilled in the art will appreciate that embodiments of the present application can be comprised of a method, system, or computer program product. Accordingly, embodiments of the present application can be embodied in a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, embodiments of the present application can take the form of a computer program product on one or more computer-readable storage media (including, but not limited to, disk memory, CD-ROMs, optical storage devices, etc.) embodying computer readable program code. Embodiments of the present application are described in reference to the flow diagrams and / or block diagrams of the methods, apparatus (systems), and computer program products according to embodiments of the present application. It will be understood that each flow and / or block in the flow diagrams and / or block diagrams, and combinations of flows and / or blocks in the flow diagrams and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flow diagrams and / or block diagrams block or blocks. Figure 1 one or more flows and / or blocks Figure 1 means for carrying out the function specified by the flow or flows and / or block or blocks.

[0158] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions means which implement the function specified in the flow diagrams and / or block diagrams flow or flows and / or block or blocks. The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flow diagrams and / or block diagrams flow or flows and / or block or blocks. Figure 1 one or more flows and / or blocks Figure 1 means for carrying out the function specified by the flow or flows and / or block or blocks. These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flow diagrams and / or block diagrams flow or flows and / or block or blocks. Figure 1 one or more flows and / or blocks Figure 1 Figure 1The steps of a method, process, or algorithm described in connection with the present disclosure can be embodied directly in hardware, in a software module executed by a processor, or in a combination of the two. A software module can reside in RAM, flash memory, ROM, EEPROM, or any other form of non- transitory computer-readable media of a computer, such as an external disk drive, hard drive, or other storage device. When the software module is executed by the processor, the processor can be said to "execute" the steps of the method, process, or algorithm, and the method steps can be embodied in this context as operations performed by the computer program using resources provided by and associated with the computer. The software module can be stored on a non-transitory computer-readable medium, such as the memory of the computer, that can direct a computer-based device to function in a particular manner, such that the device operates as directed by the software module.

[0159] It should also be noted that the terms "comprising," "including," or any other variation thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can also include other elements not expressly listed or inherent to such process, method, article, or apparatus. An element preceded by "comprises a... " does not, without more constraints, foreclose the existence of additional identical elements in the process, method, article, or apparatus that comprises the recited element. The embodiments of the present application can be described in the general context of computer-executable instructions, such as program modules, being executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, and the like, that perform particular tasks or implement particular abstract data types. One or more embodiments of the present application can also be practiced in distributed computing environments where tasks are performed by remote processing devices that are linked through a communications network. In a distributed computing environment, program modules can be located in both local and remote computer storage media including memory storage devices. The various embodiments of the present application are described in the general context of method steps, which can be implemented in one or more computer-executable procedures or programs. Such programs can be executed by a computer or other programmable device to perform a task or implement a particular abstract data type. Embodiments of the present application can be described in the general context of computer-executable instructions, such as program modules, being executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, and the like, that perform particular tasks or implement particular abstract data types. One or more embodiments of the present application can also be practiced in distributed computing environments where tasks are performed by remote processing devices that are linked through a communications network. In a distributed computing environment, program modules can be located in both local and remote computer storage media including memory storage devices. The various embodiments of the present application are described in the general context of method steps, which can be implemented in one or more computer-executable procedures or programs. Such programs can be executed by a computer or other programmable device to perform a task or implement a particular abstract data type.

Claims

1. A data processing method, characterized in that, Applied to the central node, the method includes: Obtain the set of ciphertext data sent by participating member nodes. The set of ciphertext data includes ciphertext service data. The ciphertext service data is obtained by encrypting plaintext service data based on an encryption key array. Different participating member nodes use the same encryption key array. The participating member nodes include the first participating member node. The encryption key array consists of a set of m data encryption keys generated by m participating member nodes out of n participating member nodes, where m is an integer greater than 1 and less than or equal to n, and n is an integer greater than 1. The encrypted business data in the encrypted data set is subjected to data comparison processing to obtain the data comparison result of the first participating member node; the data comparison result includes: the correspondence between any encrypted business data of the first participating member node and multiple second participating member nodes holding the encrypted business data.

2. The method according to claim 1, characterized in that, The encrypted business data in the encrypted data set is compared to obtain the data comparison result of the first participating member node, including: The encrypted business data in the encrypted data set is subjected to data comparison processing to determine the data comparison sub-result of the encrypted business data of the first participating member node. The data comparison sub-result is used to characterize the second participating member node set. All participating member nodes in the second participating member node set have the encrypted business data of the first participating member node. Based on the data comparison sub-results, the data comparison results of the first participating member node are obtained.

3. The method according to claim 2, characterized in that, The encrypted business data consists of K items, and the encrypted data set consists of n items, where n and K are both integers greater than 1; the step of performing data comparison processing on the encrypted business data in the encrypted data set to determine the data comparison sub-result of the encrypted business data of the first participating member node includes: Select the encrypted business data to be compared from the K encrypted business data of the first participating member node; The node identifier of the second participating member node is determined by comparing the encrypted business data to be compared with the encrypted business data in the n encrypted data sets. Based on the node identifier of the second participating member node and the encrypted service data to be compared, a data comparison sub-result is generated.

4. The method according to claim 3, characterized in that, The step of performing data comparison processing based on the encrypted service data to be compared with the encrypted service data in the n encrypted data sets to determine the node identifier of the second participating member node includes: Determine whether a first comparison sub-result of the encrypted business data to be compared exists in the historical comparison sub-result set; If it exists, then the node identifier of the second participating member node that has the encrypted business data to be compared is determined based on the first comparison sub-result; If it does not exist, then a data comparison process is performed based on the encrypted business data to be compared with the encrypted business data in the n encrypted data sets to determine the node identifier of the second participating member node.

5. The method according to claim 1, characterized in that, The number of participating member nodes is n, and the process of obtaining the set of ciphertext data sent by the participating member nodes includes: Among the n participating member nodes, m participating member nodes are determined as key generation nodes; the m key generation nodes include the first participating member node and / or the third participating member node; Send key generation instructions to m key generation nodes; the key generation instructions are used to trigger the key generation nodes to generate data encryption keys and send the data encryption keys to the fourth participating member node, and the set of data encryption keys generated by the m key generation nodes respectively constitutes the encryption key array; Obtain the set of ciphertext data obtained by encrypting the n participating member nodes according to the encryption key array.

6. The method according to claim 5, characterized in that, The step of obtaining the set of ciphertext data encrypted by the n participating member nodes according to the encryption key array includes: After the generation of m data encryption keys is completed, a data encryption instruction is sent to n participating member nodes; the data encryption instruction is used to trigger the participating member nodes to encrypt the plaintext service data of the participating member nodes based on the encryption key array to obtain ciphertext service data; Obtain the ciphertext data set containing K ciphertext service data sent by the participating member node.

7. The method according to claim 5, characterized in that, The step of determining m participating member nodes out of the n participating member nodes as key generation nodes includes: Based on the data security level of the data processing task, determine the number of participating member nodes for generating the participation key; Based on the number of participating member nodes, m participating member nodes are selected from the n participating member nodes as key generation nodes.

8. The method according to any one of claims 1 to 7, characterized in that, The encrypted data set includes encrypted user list data, which includes K encrypted user information entries.

9. A data processing method, characterized in that, Applied to the first participating member node, the method includes: The plaintext business data is encrypted using an encryption key array to obtain a ciphertext data set. The ciphertext data set includes the ciphertext business data, and different participating member nodes use the same encryption key array. The encryption key array consists of a set of m data encryption keys generated by m of the n participating member nodes, where m is an integer greater than 1 and less than or equal to n, and n is an integer greater than 1. The encrypted data set is sent to the central node; Obtain the data comparison result generated by the central node; the data comparison result is obtained by comparing the encrypted business data in the encrypted data set; the data comparison result includes: the correspondence between any encrypted business data of the first participating member node and multiple second participating member nodes holding the encrypted business data.

10. The method according to claim 9, characterized in that, The data comparison result includes the data comparison sub-result of the encrypted business data of the first participating member node. The data comparison sub-result is used to characterize the second participating member node set. All participating member nodes in the second participating member node set have the encrypted business data of the first participating member node. After obtaining the data comparison results generated by the central node, the process also includes: Based on the data comparison sub-results, the shared business data of the specified participating member node combination is determined; The designated combination of participating member nodes includes the first participating member node and at least one fifth participating member node.

11. The method according to claim 9, characterized in that, The encryption of plaintext business data based on an encryption key array yields a set of ciphertext data, including: Determine an array of encryption keys containing m data encryption keys; the key generation nodes for the m data encryption keys include the first participating member node and / or the third participating member node, where n represents the number of participating member nodes; Upon receiving a data encryption instruction from the central node, the plaintext business data of the first participating member node is encrypted based on the encryption key array to obtain a set of ciphertext data.

12. The method according to claim 9, characterized in that, The encrypted data set includes encrypted user list data, which includes K encrypted user information entries, where K is an integer greater than 1.

13. A data processing apparatus, characterized in that, Located at the central node, the device includes: The data acquisition module is used to acquire a set of encrypted data sent by participating member nodes. The set of encrypted data includes encrypted business data, which is obtained by encrypting plaintext business data based on an encryption key array. Different participating member nodes use the same encryption key array. The participating member nodes include the first participating member node. The encryption key array consists of a set of m data encryption keys generated by m participating member nodes out of n participating member nodes, where m is an integer greater than 1 and less than or equal to n, and n is an integer greater than 1. The data comparison module is used to perform data comparison processing on the encrypted business data in the encrypted data set to obtain the data comparison result of the first participating member node; the data comparison result includes: the correspondence between any encrypted business data of the first participating member node and multiple second participating member nodes holding the encrypted business data.

14. A data processing apparatus, characterized in that, The device, located at the first participating member node, includes: The data encryption module is used to encrypt plaintext business data based on an encryption key array to obtain a ciphertext data set. The ciphertext data set includes ciphertext business data, and different participating member nodes use the same encryption key array. The encryption key array consists of a set of m data encryption keys generated by m of the n participating member nodes, where m is an integer greater than 1 and less than or equal to n, and n is an integer greater than 1. The data sending module is used to send the encrypted data set to the central node; The result acquisition module is used to acquire the data comparison result generated by the central node; the data comparison result is obtained by comparing the encrypted business data in the encrypted data set; the data comparison result includes: the correspondence between any encrypted business data of the first participating member node and multiple second participating member nodes holding the encrypted business data.

15. An electronic device, characterized in that, The device includes: Processor; and A memory configured to store computer-executable instructions configured to be executed by the processor, the executable instructions including steps for performing the method as described in any one of claims 1 to 8 or any one of claims 9 to 12.

16. A computer-readable storage medium, characterized in that, The storage medium is used to store computer-executable instructions that cause the computer to perform the method as described in any one of claims 1 to 8 or any one of claims 9 to 12.

Citation Information

Patent Citations

  • Method and device for matching data

    CN107196918A

  • Method and device for matching data

    CN107196919A