Data monitoring method, electronic device, and computer-readable storage medium
By encrypting data on local terminals and performing encryption processing on multiple clouds, the problems of high storage costs and poor security during data monitoring are solved, and safe and efficient data monitoring is achieved.
Patent Information
- Application Number
- CN202411320265.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-20
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2044-09-20
AI Technical Summary
Existing data monitoring methods have problems of high storage costs and poor security during storage in smart terminals and transmission in the cloud.
After encrypting the monitoring data and reference data using a local terminal, multiple rounds of encryption are performed on multiple clouds using the target key and perturbation parameters to ensure that specific information cannot be directly obtained on the cloud, and only the monitoring results can be obtained.
While saving local terminal storage and processing costs, it improves the security of data monitoring and reduces the risk of data leakage.
Smart Images

Figure CN119420496B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data processing technology, and in particular to a data monitoring method, electronic equipment, and computer-readable storage medium. Background Art
[0002] With the continuous development of intelligent technology, data monitoring is being applied in more and more fields. Currently, one way to monitor data is to use smart terminals to store and analyze the collected data to be monitored. This method requires storage space on the smart terminals and consumes a large amount of computing power. Alternatively, another method is to send the collected data to be monitored to a cloud server, where a monitoring model deployed on the cloud server stores and monitors the data. However, this method is prone to data leakage during the upload process, resulting in poor security.
[0003] In view of this, how to propose a data monitoring method with high monitoring efficiency and high security has become an urgent problem to be solved. Summary of the Invention
[0004] The main technical problem solved by this application is to provide a data monitoring method, electronic device and computer-readable storage medium, which can improve the security of data monitoring.
[0005] To solve the above technical problems, a technical solution adopted in the present application is: to provide a data monitoring method, which is applied to a data monitoring system, and the data monitoring system includes a local terminal, a first cloud and a second cloud, and the data monitoring method includes: in response to the local terminal obtaining the data to be monitored and its matching reference data, obtaining a target key, using the target key to encrypt the data to be monitored to obtain a first ciphertext, using the target key to encrypt the reference data to obtain a second ciphertext, and transmitting the first ciphertext and the second ciphertext to the first cloud; using the target key and the disturbance parameter, encrypting the first ciphertext and the second ciphertext to obtain the target ciphertext and transmitting it to the second cloud; using the decryption key to decrypt the target ciphertext, obtaining decrypted data and transmitting it to the first cloud; wherein the decryption key corresponds to the target key; based on the decrypted data and the disturbance parameter, obtaining the monitoring result corresponding to the data to be monitored.
[0006] To solve the above technical problems, another technical solution adopted in this application is: to provide an electronic device, comprising: a memory and a processor coupled to each other, wherein the memory stores program instructions, and the processor is used to execute the program instructions to implement the data monitoring method mentioned in the above technical solution.
[0007] In order to solve the above technical problems, another technical solution adopted in this application is: providing a computer-readable storage medium on which program instructions are stored, and when the program instructions are executed by a processor, the data monitoring method mentioned in the above technical solution is implemented.
[0008] The beneficial effects of the present application are as follows: Different from the prior art, the data monitoring method proposed in the present application is that the local terminal sends the target key and the encrypted first ciphertext and the second ciphertext to the first cloud, so that the first cloud performs a further round of encryption on the first ciphertext and the second ciphertext using the disturbance parameter to obtain the target ciphertext containing the comparison relationship between the data to be monitored and the reference data. The target ciphertext is sent by the first cloud to the second cloud, so that the second cloud decrypts the target ciphertext to obtain decrypted data containing the disturbance parameter. The decrypted data is processed using the first cloud to obtain the monitoring results. This method makes it impossible for the first cloud and the second cloud to obtain the specific information of the data to be monitored and the reference data during the data monitoring process, thereby saving the local terminal data storage and data processing costs while improving the security of data monitoring. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without inventive efforts. Among them:
[0010] Figure 1 It is a structural diagram of an implementation scheme of the data monitoring system of the present application;
[0011] Figure 2 This is a flow chart of an implementation method of the data monitoring method of the present application;
[0012] Figure 3 yes Figure 1 Step S101 corresponds to a flow chart of another embodiment;
[0013] Figure 4 yes Figure 1 Step S101 corresponds to a flowchart of another embodiment;
[0014] Figure 5 yes Figure 1 Step S102 corresponds to a flow chart of another embodiment;
[0015] Figure 6 This is a schematic structural diagram of an embodiment of the electronic device of the present application;
[0016] Figure 7It is a structural diagram of an embodiment of a computer-readable storage medium of the present application. DETAILED DESCRIPTION
[0017] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of them, and different embodiments can be adaptively combined. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0018] See also Figure 1 , Figure 1 1 is a schematic diagram of a data monitoring system according to an embodiment of the present invention. The data monitoring system includes a local terminal, a first cloud and a second cloud coupled to each other.
[0019] In one implementation scenario, the local terminal includes a collection device and a processing device coupled to each other, wherein the collection device is configured to collect data to be monitored and send the collected data to be monitored to the processing device, and the processing device is configured to determine matching reference data based on the received data to be monitored.
[0020] The processing device may be a mobile phone, tablet or tablet computer, etc. The acquisition device may be a sensor or smart bracelet, etc.
[0021] In one specific application scenario, the reference data is automatically determined by the processing device based on the data type of the monitored data. For example, if the monitored data is the actual temperature, the reference data is the threshold temperature. Alternatively, the reference data can be set by the relevant object on the processing device.
[0022] See also Figure 2 , Figure 2 This is a flow chart of an embodiment of the data monitoring method of the present application. The method is applied to a data monitoring system. The specific implementation process includes:
[0023] S101: In response to the local terminal obtaining the data to be monitored and the reference data matched thereto, a target key is obtained, the data to be monitored is encrypted using the target key to obtain a first ciphertext, the reference data is encrypted using the target key to obtain a second ciphertext, and the first ciphertext and the second ciphertext are transmitted to the first cloud.
[0024] In one embodiment, after the local terminal obtains the data to be monitored and its matching reference data, the processing device obtains a target key used to encrypt the data to be monitored and the reference data. The target key is used to encrypt the data to be monitored, resulting in a corresponding first ciphertext. Furthermore, the target key is used to encrypt the reference data, resulting in a corresponding second ciphertext. The target key is obtained by encrypting multiple target parameters.
[0025] In one implementation scenario, an encryption key is pre-generated on the local terminal, and the encryption key is used to encrypt multiple target parameters to generate the above-mentioned target key.
[0026] Furthermore, the process of obtaining the first ciphertext and the second ciphertext in response to encryption is implemented in the local terminal. After obtaining the first ciphertext and the second ciphertext, the local terminal transmits the first ciphertext, the second ciphertext and the target key to the first cloud.
[0027] In another embodiment, after obtaining the data to be detected and its matching reference data, the local terminal preprocesses the data to be detected and its matching reference data, and encrypts the preprocessed data to be detected and the reference data using the target key to obtain corresponding first ciphertext and second ciphertext. The preprocessing process includes converting the data to be detected and the matching reference data into integers.
[0028] In a specific application scenario, in response to the data to be monitored being 37.5 and its matching reference data being 37.0, in order to facilitate subsequent calculations and improve the accuracy of subsequent data monitoring, the data to be monitored and the reference data are multiplied by 10 respectively, that is, the preprocessed data to be monitored is 375 and the preprocessed reference data is 370.
[0029] S102: Encrypt the first ciphertext and the second ciphertext using the target key and the perturbation parameter to obtain the target ciphertext and transmit it to the second cloud.
[0030] In one embodiment, a perturbation parameter is determined on the first cloud based on the first ciphertext and the second ciphertext, and the first ciphertext and the second ciphertext are jointly encrypted using the target key and the perturbation parameter to obtain a corresponding target ciphertext.
[0031] Furthermore, the generated target ciphertext is sent to the second cloud using the first cloud.
[0032] It should be noted that the target key only encrypts the data, but does not support decryption of the encrypted data; therefore, even if the first cloud obtains the target key, the first ciphertext and the second ciphertext sent by the processing device, it cannot use the target key to decrypt the first ciphertext or the second ciphertext to obtain the corresponding data to be monitored or reference data.
[0033] S103: Decrypt the target ciphertext using the decryption key to obtain decrypted data and transmit it to the first cloud; wherein the decryption key corresponds to the target key.
[0034] In one embodiment, the second cloud decrypts the target ciphertext sent from the first cloud using the decryption key to obtain corresponding decrypted data, wherein the decryption key is determined based on the encryption key used to generate the target key, and the decrypted data includes amplitude information between the monitored data and the reference data.
[0035] Furthermore, the decrypted data is transmitted to the first cloud using the second cloud.
[0036] S104: Based on the decrypted data and the disturbance parameters, a monitoring result corresponding to the data to be monitored is obtained.
[0037] In one embodiment, the first cloud receives the decrypted data sent by the second cloud, and uses the first cloud to analyze the decrypted data according to the disturbance parameters to determine the corresponding monitoring results.
[0038] In one implementation scenario, in response to the decrypted data including amplitude information between the data to be monitored and the reference data, the first cloud is used to analyze the decrypted data according to the disturbance parameters to determine whether the amplitude information corresponds to each other, thereby obtaining a monitoring result based on the amplitude information.
[0039] Furthermore, after obtaining the monitoring result, the first cloud is used to determine whether the monitoring result meets the preset alarm condition.
[0040] Specifically, in response to the monitoring result meeting the preset alarm condition, the first cloud sends the monitoring result to the processing device; and after receiving the monitoring result, the processing device issues an alarm based on the monitoring result. Alternatively, in response to the monitoring result not meeting the preset alarm condition, the processing device continues to obtain the data to be monitored collected by the collection device, and the subsequent steps are sequentially executed to determine whether the subsequently collected data to be monitored meets the preset alarm condition.
[0041] The data monitoring method proposed in this application is that the local terminal sends the target key and the encrypted first and second ciphertexts to the first cloud, so that the first cloud performs a further round of encryption on the first and second ciphertexts using the disturbance parameters to obtain the target ciphertext containing the comparison relationship between the data to be monitored and the reference data. The first cloud sends the target ciphertext to the second cloud, so that the second cloud decrypts the target ciphertext to obtain decrypted data containing the disturbance parameters. The decrypted data is processed using the first cloud to obtain the monitoring results. This method ensures that during the data monitoring process, the first and second clouds are unable to obtain the specific information of the data to be monitored and the reference data, while saving the local terminal's data storage and data processing costs and improving the security of data monitoring.
[0042] See also Figure 3 , Figure 3 yes Figure 1 Step S101 corresponds to a flowchart of another embodiment. Specifically, in response to the local terminal including a collection device and a processing device, the process of obtaining the target key in step S101 includes:
[0043] S201: Acquire a first target parameter and a second target parameter.
[0044] In one embodiment, a first target parameter and a second target parameter are obtained on a processing device, wherein the second target parameter is used to determine a comparison relationship between the data to be monitored and the reference data.
[0045] In a specific application scenario, the first target parameter is 0 and the second target parameter is -1.
[0046] S202: encrypting the first target parameter multiple times using a processing device to obtain multiple first weights; and encrypting the second target parameter using the processing device to obtain a second weight.
[0047] In one embodiment, on a processing device, a first target parameter is encrypted multiple times using a symmetric homomorphic encryption (SHE) algorithm, and a corresponding first weight is obtained after each encryption; and a second target parameter is encrypted using the symmetric homomorphic encryption algorithm to obtain a corresponding second weight.
[0048] In one implementation scenario, a processing device is used to predetermine an encryption key corresponding to a symmetric homomorphic encryption algorithm, and the encryption key is used to encrypt a first target parameter to obtain a corresponding first weight; and the encryption key is used to encrypt a second target parameter to obtain a corresponding second weight.
[0049] Specifically, a plurality of initial parameters matching the above-mentioned symmetric homomorphic encryption algorithm are predetermined, and the initial parameters include security parameters (k0, k1, k2), and the security parameters satisfy k0<<k1<k2. In addition, the above-mentioned initial parameters also include two reference prime numbers and a random coefficient. According to the reference prime numbers and the random coefficient, the encryption key corresponding to the symmetric homomorphic encryption algorithm is determined. Among them, p and q are two reference prime numbers, and the bit lengths of p and q are both k0. is a random number with a bit length of k2.
[0050] In a specific implementation scenario, the specific calculation formula for the first target parameter or the second target parameter using the encryption key is as follows:
[0051]
[0052] Wherein, x represents the first target parameter or the second target parameter, and when x represents the first target parameter, E(x) represents the first weight obtained after encryption; r and r′ represent random coefficients, and represents the product of the reference prime number p and the reference prime number q; mo d represents the remainder function.
[0053] It should be noted that due to the differences in random coefficients in different encryption rounds, even if the same data is encrypted, the weights obtained are different. For example, when the first target parameter is 0, the first weights obtained by encrypting the first target parameter multiple times using the above encryption key are different.
[0054] In addition, after the encryption key is determined on the processing device, the encryption key is sent to the second cloud as a decryption key by the processing device to help the second cloud decrypt related data according to the decryption key.
[0055] S203: Determine a target key based on the first weight and the second weight.
[0056] In one embodiment, the first weight and the second weight obtained after encryption are used as the target key.
[0057] In a specific application scenario, in step S202, the first target parameter is 0, the second target parameter is -1, and the first target parameter is encrypted twice using the encryption key to obtain a first weight E(0)1 and a first weight E(0)2; and the second target parameter is encrypted once using the encryption key to obtain a second weight E(-1). Based on the obtained first and second weights, the target key is determined to be pk = [E(0)1, E(0)2, E(-1)].
[0058] The above scheme determines different first weights according to the first target parameter 0 and determines the second weight according to the second target parameter -1, so that the relevant data is subsequently encrypted according to the first weight, and the comparison relationship between the data to be monitored and the reference data is determined using the second weight, thereby avoiding the leakage of the data to be monitored during the data monitoring process and improving the security of data monitoring.
[0059] See also Figure 4 , Figure 4 yes Figure 1 Step S101 in FIG. 1 corresponds to a flow chart of another embodiment. Specifically, the implementation process of encrypting the monitored data on the processing device to obtain the first ciphertext in step S101 includes:
[0060] S301: Obtain a first encryption parameter and a second encryption parameter, and use a processing device to obtain a first reference sub-ciphertext based on the first encryption parameter and a current first weight; and use a processing device to obtain a second reference sub-ciphertext based on the second encryption parameter and other first weights.
[0061] In one embodiment, after determining the target key, the first encryption parameter and the second encryption parameter are determined, and the first weight, the first encryption parameter and the second encryption parameter in the target key are used to obtain the first reference sub-ciphertext and the second reference sub-ciphertext.
[0062] Specifically, in response to encrypting the first target parameter twice through the steps mentioned in the corresponding implementation method above and obtaining the corresponding first weights respectively, the product of the first encryption parameter and one of the first weights is obtained and used as the first reference sub-ciphertext; and the product of the second encryption parameter and the other first weight is obtained, and the second reference sub-ciphertext is determined based on the product.
[0063] S302: Enable the processing device to obtain a first ciphertext according to the data to be monitored, the first reference sub-ciphertext, and the second reference sub-ciphertext.
[0064] In one embodiment, the processing device uses the sum of the data to be monitored, the first reference sub-ciphertext, and the second reference sub-ciphertext as the first ciphertext.
[0065] In a specific application scenario, the specific calculation formula for the first ciphertext is as follows:
[0066]
[0067] Where m1 represents the data to be monitored, E(m1) represents the first ciphertext, r1 represents the first encryption parameter, and r2 represents the second encryption parameter, and k2 and The value of can refer to the values of the relevant parameters in the above step S202. Among them, since the symmetric homomorphic encryption algorithm satisfies multiple operational properties, such as: E(m1)+E(m2)=E(m1+m2); E(m1)*E(m2)=E(m1*m2); E(m1)+m2=E(m1+m2); E(m1)*m2=E(m1*m2), therefore, the first ciphertext obtained by the above process will not affect the monitoring data itself.
[0068] In addition, the process of encrypting the reference data on the processing device in step S101 to obtain the second ciphertext is similar to the process of obtaining the first ciphertext. The detailed process can refer to the above steps S301 to S302 and will not be explained in detail here.
[0069] See also Figure 5 , Figure 5 yes Figure 1 Step S102 corresponds to a flow chart of another embodiment. The disturbance parameter includes a first random parameter and at least one second random parameter, and the first random parameter is selected from the first candidate parameter and the second candidate parameter. The specific implementation process of step S102 includes:
[0070] S401: Obtain a variation range ciphertext based on a target key, a first ciphertext, and a second ciphertext.
[0071] In one embodiment, on the first cloud, a first product of the second weight and the second ciphertext is obtained.
[0072] Furthermore, the sum of the first ciphertext and the first product is used as the variation range ciphertext by the first cloud, wherein the variation range ciphertext is used to represent the difference between the encrypted data to be monitored and the reference data.
[0073] In a specific application scenario, in order to monitor the data to be monitored, it is necessary to determine the comparison relationship between the data to be monitored and the reference data. Since the second weight is obtained by encrypting the second target parameter -1, the specific calculation formula of the change amplitude ciphertext is as follows:
[0074] f=E(T)+E(H)·E(-1)
[0075] Wherein, f represents the variation ciphertext, E(T) represents the first ciphertext, E(H) represents the second weight, and E(-1) represents the second ciphertext.
[0076] S402: For any second random parameter, obtain a target encryption weight based on the first random parameter, the second random parameter and the target key.
[0077] In one embodiment, the perturbation parameters include a first random parameter and at least one second random parameter, wherein the first random parameter is selected from a first candidate parameter and a second candidate parameter that are mutually inverse. For each second random parameter, the first cloud obtains a second product of the first random parameter and the second random parameter, and the first cloud encrypts the second product using a first weight to obtain a target encryption weight.
[0078] In one implementation scenario, the perturbation parameters include a first random parameter and two predetermined second random parameters. The first random parameter is randomly determined from a first candidate parameter of -1 and a second candidate parameter of 1, that is, the first random parameter is -1 or 1. For each second random parameter, the specific calculation formula for the target encryption weight is as follows:
[0079]
[0080] Wherein, s represents the first random parameter, t1 represents one of the second random parameters, and t2 represents another second random parameter. And t1>t2>0; E(s·t1) and E(s·t2) respectively represent the target encryption weights obtained according to the corresponding second random parameters.
[0081] S403: Based on the change range ciphertext and the target encryption weight, obtain the target ciphertext, and transmit the target ciphertext to the second cloud.
[0082] In one embodiment, in response to obtaining target encryption weights corresponding to two different second random parameters through step S402, a third product of one of the target encryption weights and the variation amplitude ciphertext is obtained, the sum of the third product and the other target encryption weight is used as the target ciphertext, and the target ciphertext is transmitted to the second cloud.
[0083] Specifically, the specific calculation formula for the target ciphertext is as follows:
[0084] E(λ)=E(s·t1)·(E(T)+E(H)·E(-1))+E(s·t2)
[0085] Where E(λ) represents the target ciphertext.
[0086] In another embodiment, the number of the second random parameters may be other, such as three or four.
[0087] In the above solution, by selecting any one of two candidate parameters that are opposite to each other as the first random parameter, after the subsequent second cloud decrypts the target ciphertext, without knowing the specific value of the first random parameter, it is impossible to determine the magnitude relationship between the data to be monitored and the reference data, thus ensuring the security during the data monitoring process. Additionally, by setting multiple second random parameters, the difficulty of encrypting the first ciphertext and the second ciphertext is increased, which helps to improve the security of data monitoring.
[0088] In one embodiment, in response to obtaining the target ciphertext through steps S401 to S403 and transmitting it to the second cloud, then Figure 1 The specific implementation process of step S103 includes: on the second cloud, according to the decryption key received by the second cloud and various operation properties satisfied by the symmetric homomorphic encryption algorithm mentioned in the above corresponding embodiment, decrypt the target ciphertext obtained in step S403 to obtain the corresponding decrypted data, and transmit the decrypted data to the first cloud. Among them, the specific expression formula of the decrypted data obtained after decryption is as follows:
[0089] λ = s·t1·(T - H) + s·t2
[0090] Where λ represents the decrypted data. Since the first cloud does not transmit the perturbation parameter to the second cloud when transmitting the target ciphertext to the second cloud, even if the second cloud decrypts the target ciphertext to obtain the decrypted data, it cannot determine the specific value of the data to be monitored or the reference data through the decrypted data, nor can it determine the specific value of the difference between the data to be monitored and the reference data, which improves the security of data transmission in the cloud.
[0091] Furthermore, after transmitting the decrypted data to the first cloud, Figure 1 The specific implementation process of step S104 includes: enabling the first cloud to determine the monitoring result according to the amplitude information in the first random parameter and the decrypted data. The amplitude information is used to represent the difference between the data to be monitored and the reference data.
[0092] Specifically, since t1 > t2 > 0, the first cloud determines the comparison relationship between the data to be monitored and the reference data according to the specific value of the first random parameter, that is, determines the magnitude relationship between the data to be monitored and the reference value. For example, when the first random parameter is -1, if λ is greater than 0, it indicates that T < H; if λ is less than 0, then T ≥ H. Or, when the first random parameter is 1, if λ is greater than 0, it indicates that T ≥ H; if λ is less than 0, then T < H. This method enables the first cloud to determine whether (T - H) is 0, a positive number, or a negative number according to the first random parameter and the decrypted data, so as to judge the magnitude relationship between the two without determining the specific values of the data to be monitored and the reference data, reducing the risk of leakage during data transmission.
[0093] In one implementation scenario, T ≥ H in the monitoring result is used as a preset alarm condition. In response to the monitoring result satisfying the preset alarm condition, it indicates that the value of the monitored data is high, causing the first cloud to send the monitoring result to the processing device, and the processing device to issue an alarm.
[0094] In a specific application scenario, the monitored data T is temperature, and the reference data H is a threshold temperature. When the monitoring result indicates that the monitored data T is greater than the reference data H, the monitoring result is determined to meet the preset alarm condition, causing the first cloud to send the monitoring result to the processing device, which then issues an alarm signal. The processing device can transmit the alarm signal by emitting a corresponding alarm audio signal; or the processing device can display relevant information on a display interface to transmit the alarm signal.
[0095] In another embodiment, the first target parameter may be encrypted multiple times using the encryption key to obtain a corresponding number of first weights, and the second target parameter may be encrypted once using the encryption key to obtain a second weight. For example, if the first target parameter is encrypted three times, the target key obtained is pk = [E(0)1, E(0)2, E(0)3, E(-1)]. Based on this, the specific calculation formula for the first ciphertext in step S302 can be as follows:
[0096]
[0097] The above solution obtains multiple first weights by encrypting the first target parameter multiple times, so as to increase the encryption difficulty and thus improve the security of data monitoring.
[0098] In another embodiment, the perturbation parameter includes a first random parameter and a second random parameter, and the second random parameter is selected from the first candidate parameter and the second candidate parameter. The specific implementation process of step S102 includes: obtaining the variation amplitude ciphertext based on the target key, the first ciphertext, and the second ciphertext. The specific implementation process can refer to the corresponding embodiment described above.
[0099] Furthermore, a target encryption weight is obtained based on the first random parameter, the second random parameter, and the target key. A target ciphertext is obtained based on the variation range ciphertext and the target encryption weight, and the target ciphertext is transmitted to the second cloud.
[0100] Specifically, the product of the target encryption weight and the change amplitude ciphertext is obtained, the product is used as the target ciphertext, and the target ciphertext is transmitted to the second cloud. Among them, the specific calculation formula of the target ciphertext in this embodiment is as follows:
[0101] E(λ)=E(s·t1)·(E(T)+E(H)·E(-1))
[0102] In the above solution, only one determined second random parameter is used to encrypt the first ciphertext and the second ciphertext to obtain the target ciphertext, which helps to improve the acquisition efficiency of the target ciphertext.
[0103] In another embodiment, to improve the data monitoring efficiency and save the consumption of computing resources, the above perturbation parameter may also only include the first random parameter. Based on this, the specific implementation process of step S102 includes: obtaining the change amplitude ciphertext based on the target key, the first ciphertext, and the second ciphertext. The specific implementation process can refer to the corresponding above embodiment.
[0104] Further, based on the first random parameter, obtain the target encryption weight. Where when the target key is pk = [E(0)1, E(0)2, E(-1)|, the specific calculation formula of the target encryption weight is as follows:
[0105]
[0106] Further, based on the change amplitude ciphertext and the target encryption weight, obtain the target ciphertext, and transmit the target ciphertext to the second cloud. The specific calculation formula of the target ciphertext is as follows:
[0107] E(λ) = E(s)·(E(T) + E(H)·E(-1))
[0108] Further, the second cloud decrypts the target ciphertext, and the expression formula of the decrypted data obtained after decryption is λ = s.(T - H). Transmit this decrypted data to the first cloud. The first cloud determines the monitoring result according to the first random parameter and the amplitude information in the decrypted data. For example, when the first random parameter is -1, if λ > 0, it indicates that T < H; if λ ≤ 0, then T ≥ H. Or, when the first random parameter is 1, if λ ≥ 0, it indicates that T ≥ H; if λ < 0, then T < H.
[0109] Please refer to Figure 6 , Figure 6: It is a structural diagram of an embodiment of an electronic device of the present application. The electronic device includes: a memory 10 and a processor 20 coupled to each other. The memory 10 stores program instructions, and the processor 20 is used to execute the program instructions to implement the data monitoring method mentioned in any of the above embodiments. Specifically, the electronic device includes but is not limited to: a desktop computer, a laptop computer, a tablet computer, a server, etc., which are not limited here. In addition, the processor 20 can also be called a CPU (Center Processing Unit). The processor 20 may be an integrated circuit chip with signal processing capabilities. The processor 20 can also be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. In addition, the processor 20 can be implemented by an integrated circuit chip.
[0110] See also Figure 7 , Figure 7 The storage medium 30 stores program instructions 40 that can be executed by a processor, and when the program instructions 40 are executed by the processor, the data monitoring method mentioned in any of the above embodiments is implemented.
[0111] In the several embodiments provided in this application, it should be understood that the disclosed methods and devices can be implemented in other ways. For example, the device implementation methods described above are only schematic. For example, the division of modules or units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, and the indirect coupling or communication connection of devices or units can be electrical, mechanical or other forms.
[0112] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0113] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0114] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) or a processor to execute all or part of the steps of each embodiment method of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0115] The above description is only an implementation method of the present application and does not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made using the contents of the description and drawings of this application, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present application.
Claims
1. A data monitoring method, characterized in that: The data monitoring method is applied to a data monitoring system, which includes a local terminal, a first cloud and a second cloud. The data monitoring method includes: In response to the local terminal obtaining the data to be monitored and its matching reference data, obtaining a target key, encrypting the data to be monitored using the target key to obtain a first ciphertext, encrypting the reference data using the target key to obtain a second ciphertext, and transmitting the first ciphertext and the second ciphertext to the first cloud; Encrypting the first ciphertext and the second ciphertext using the target key and the perturbation parameter to obtain a target ciphertext and transmitting it to the second cloud; Decrypting the target ciphertext using a decryption key to obtain decrypted data and transmitting the decrypted data to the first cloud; wherein the decryption key corresponds to the target key; Based on the decrypted data and the disturbance parameter, a monitoring result corresponding to the data to be monitored is obtained.
2. The method according to claim 1, characterized in that The local terminal includes a collection device and a processing device, and obtaining the target key includes: Obtaining a first target parameter and a second target parameter; encrypting the first target parameter multiple times using the processing device to obtain multiple first weights; and encrypting the second target parameter using the processing device to obtain a second weight; The target key is determined based on the first weight and the second weight.
3. The method according to claim 2, characterized in that The step of encrypting the data to be monitored by using the target key to obtain a first ciphertext includes: Obtaining a first encryption parameter and a second encryption parameter, and obtaining, using the processing device, a first reference sub-ciphertext based on the first encryption parameter and a current first weight; and obtaining, using the processing device, a second reference sub-ciphertext based on the second encryption parameter and other first weights; The processing device is enabled to obtain the first ciphertext according to the data to be monitored, the first reference sub-ciphertext, and the second reference sub-ciphertext.
4. The method according to claim 2, characterized in that The perturbation parameters include a first random parameter and at least one second random parameter, the first random parameter being selected from a first candidate parameter and a second candidate parameter, and encrypting the first ciphertext and the second ciphertext using the target key and the perturbation parameters to obtain a target ciphertext and transmitting it to the second cloud, including: Obtaining a variation ciphertext based on the target key, the first ciphertext, and the second ciphertext; and For any of the second random parameters, obtaining a target encryption weight based on the first random parameter, the second random parameter, and the target key; Based on the change amplitude ciphertext and the target encryption weight, the target ciphertext is obtained, and the target ciphertext is transmitted to the second cloud.
5. The method according to claim 4, characterized in that The obtaining, based on the target key, the first ciphertext, and the second ciphertext, a variation range ciphertext includes: Obtaining, using the first cloud, a first product of the second weight and the second ciphertext; The first cloud is used to calculate the sum of the first ciphertext and the first product as the variation amplitude ciphertext.
6. The method according to claim 4, characterized in that The acquiring, for any second random parameter, a target encryption weight based on the first random parameter, the second random parameter, and the target key, includes: Obtaining, using the first cloud, a second product of the first random parameter and the second random parameter; The first cloud is enabled to encrypt the second product using the first weight to obtain the target encryption weight.
7. The method according to claim 4, characterized in that The obtaining, based on the decrypted data and the disturbance parameter, a monitoring result corresponding to the data to be monitored, includes: The first cloud determines the monitoring result according to the first random parameter and the amplitude information in the decrypted data; wherein the amplitude information is used to represent the difference between the data to be monitored and the reference data.
8. The method according to claim 7, characterized in that After obtaining the monitoring result corresponding to the data to be monitored based on the decrypted data and the disturbance parameter, the method further includes: In response to the monitoring result meeting a preset alarm condition, the first cloud sends the monitoring result to the processing device.
9. An electronic device, characterized in that: include: A memory and a processor coupled to each other, wherein the memory stores program instructions, and the processor is used to execute the program instructions to implement the data monitoring method according to any one of claims 1 to 8.
10. A computer-readable storage medium having program instructions stored thereon, characterized in that: When the program instructions are executed by a processor, the data monitoring method according to any one of claims 1 to 8 is implemented.
Citation Information
Patent Citations
Data processing method, related device and storage medium
CN115801308A
Homomorphic decryption method and apparatus, and non-volatile storage medium and computer device
WO2024174107A1