Data query method, electronic device, storage medium and program product
By introducing edge nodes in the cloud computing system, using these nodes to extract and encrypt the data, the problem of downloading and decryption when users query encrypted data is solved, which improves query efficiency and saves resources.
Patent Information
- Application Number
- CN202510159919.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-13
- Publication Date
- 2025-05-16
AI Technical Summary
In the prior art, data is encrypted and uploaded to a cloud server. When a user wants to query the data stored in the cloud server, he must download all the encrypted data, first decrypt the data, and then query it in the decrypted data, which makes the query efficiency low and leads to a large amount of communication bandwidth and computing resources waste.
By introducing edge nodes between the trusted center server and the data source server, these nodes are used to extract and encrypt the data to generate keyword sequences. After the user equipment sends the query keyword, the target edge node is determined based on the keyword sequence and the query results of the edge node, and the file identifier it returns is obtained and sent to the cloud server. The cloud server sends the encrypted target query file to the user equipment for decryption.
It avoids the process of downloading and decrypting the entire data set when users query data, improves query efficiency, saves communication bandwidth and computing resources, and maintains the security of file transfer.
Smart Images

Figure CN120011315A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of cloud computing technology, and in particular to a data query method, electronic device, storage medium and program product. Background Art
[0002] With the rapid development of cloud computing services, more and more financial industries choose to store massive databases in the cloud. However, in the banking industry, there is often a large amount of sensitive data that needs to be protected, such as account passwords in operation and maintenance data. When such data is simply stored in the cloud server, the privacy of the data cannot be guaranteed, which in turn causes security threats to the customer's data privacy.
[0003] Currently, data is often encrypted in the financial industry and then uploaded to the cloud server to ensure the privacy of the data.
[0004] However, after the data is encrypted and uploaded to the cloud server, when the user wants to query the data stored in the cloud server, all the encrypted data must be downloaded, the data must be decrypted first, and then the query must be performed in the decrypted data, which makes the query efficiency low and leads to a large waste of communication bandwidth and computing resources. Summary of the invention
[0005] The present application provides a data query method, an electronic device, a storage medium and a program product to solve the problem in the prior art that data is encrypted and then uploaded to a cloud server. When a user wants to query the data stored in the cloud server, all the encrypted data must be downloaded, the data must be decrypted first, and then the query must be performed in the decrypted data, which results in low query efficiency and a large amount of waste of communication bandwidth and computing resources.
[0006] In a first aspect, the present application provides a data query method, applied to a trusted central server, the method comprising:
[0007] Acquire target query information sent by a target user device; wherein the target query information includes a query keyword set, and the query keyword set includes multiple query keywords;
[0008] Determine the query result corresponding to each edge node according to the keyword sequences corresponding to the multiple query keywords and the multiple edge nodes; wherein the keyword sequence is a sequence obtained after the data source server extracts keywords from the data file and encrypts them;
[0009] Determine the target edge node corresponding to the target query information according to the query result corresponding to each edge node and the preset minimum query threshold, and send a file identification acquisition request to the server corresponding to the target edge node;
[0010] Receive a target query file identifier returned by the server corresponding to the target edge node, and send the target query file identifier to a cloud server, so that the cloud server sends the target query file corresponding to the target query file identifier to the target user device; wherein, the files in the cloud server are all encrypted files, and the target user device is used to receive the target query file and decrypt the target query file to obtain the target file.
[0011] In a second aspect, the present application provides a data query method, applied to a data source server, the method comprising:
[0012] Extracting keywords from multiple data files to obtain multiple keywords corresponding to each of the data files;
[0013] Encrypt multiple keywords corresponding to each of the data files, and send the encrypted multiple keywords as the keyword sequence to the trusted central server, so that the trusted central server determines the target query file identifier according to the keyword sequence and multiple query keywords, and the trusted central server sends the target query file identifier to the cloud server, so that the cloud server sends the target query file corresponding to the target query file identifier to the target user device; wherein the files in the cloud server are all encrypted files, and the target user device is used to receive the target query file and decrypt the target query file to obtain the target file.
[0014] In a third aspect, the present application provides a data query device, which is configured on a trusted central server, and the device includes:
[0015] A query information acquisition module, used to acquire target query information sent by a target user device; wherein the target query information includes a query keyword set, and the query keyword set includes multiple query keywords;
[0016] A query result determination module, configured to determine the query result corresponding to each edge node according to the multiple query keywords and the keyword sequences corresponding to the multiple edge nodes; wherein the keyword sequence is a sequence obtained after the data source server extracts keywords from the data file and encrypts them;
[0017] A request sending module, used to determine the target edge node corresponding to the target query information according to the query result corresponding to each edge node and a preset minimum query threshold, and send a file identification acquisition request to the server corresponding to the target edge node;
[0018] An identification sending module is used to receive a target query file identification returned by a server corresponding to the target edge node, and send the target query file identification to a cloud server, so that the cloud server sends the target query file corresponding to the target query file identification to the target user device; wherein, the files in the cloud server are all encrypted files, and the target user device is used to receive the target query file and decrypt the target query file to obtain the target file.
[0019] In a fourth aspect, the present application provides a data query device, which is configured on a data source server, and the device includes:
[0020] An extraction module, used to extract keywords from a plurality of data files to obtain a plurality of keywords corresponding to each of the data files;
[0021] A keyword encryption module is used to encrypt multiple keywords corresponding to each of the data files, and send the encrypted multiple keywords as the keyword sequence to the trusted central server, so that the trusted central server determines the target query file identifier based on the keyword sequence and multiple query keywords, and the trusted central server sends the target query file identifier to the cloud server, so that the cloud server sends the target query file corresponding to the target query file identifier to the target user device; wherein the files in the cloud server are all encrypted files, and the target user device is used to receive the target query file and decrypt the target query file to obtain the target file.
[0022] In a fifth aspect, the present application provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the data query method as described in any embodiment of the present application is implemented.
[0023] In a sixth aspect, the present application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the data query method as described in any embodiment of the present application.
[0024] In a seventh aspect, the present application provides a computer program product, including a computer program, which, when executed by a processor, implements the data query method as described in any embodiment of the present application.
[0025] In the scheme of the present application, a trusted central server obtains target query information sent by a target user device; wherein the target query information includes a query keyword set, and the query keyword set includes multiple query keywords; according to the keyword sequences corresponding to the multiple query keywords and the multiple edge nodes, a query result corresponding to each edge node is determined; wherein the keyword sequence is a sequence obtained after the data source server extracts keywords from the data file and encrypts it; according to the query result corresponding to each edge node and a preset minimum query threshold, a target edge node corresponding to the target query information is determined, and a file identifier acquisition request is sent to the server corresponding to the target edge node; a target query file identifier returned by the server corresponding to the target edge node is received, and the target query file identifier is sent to the cloud server, so that the cloud server sends the target query file corresponding to the target query file identifier to the target user device; wherein the files in the cloud server are all encrypted files, and the target user device is used to receive the target query file and decrypt the target query file to obtain the target file. That is, the solution of the present application determines the target edge node by comparing the query keyword with the keyword corresponding to each edge node, obtains the file identifier returned by the target edge node, and then sends the file identifier to the cloud server. The cloud server sends the file corresponding to the file identifier to the user device that initiated the query, thereby avoiding the situation where when the user wants to query the data stored in the cloud server, all the data must be downloaded, the data must be decrypted first, and then the query is performed in the decrypted data, thereby improving the query efficiency, saving communication bandwidth and computing resources, and maintaining the security of file transmission. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] In order to more clearly illustrate the technical solution of the present application, the drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.
[0027] Figure 1 It is a flow chart of the data query method provided by this application;
[0028] Figure 2 is another flow chart of the data query method provided by the present application;
[0029] Figure 3 is another flow chart of the data query method provided by the present application;
[0030] Figure 4 It is a structural schematic diagram of the data query device provided by the present application;
[0031] Figure 5is another structural schematic diagram of the data query device provided by the present application;
[0032] Figure 6 It is a structural schematic diagram of the electronic device provided by this application. DETAILED DESCRIPTION
[0033] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present application.
[0034] The acquisition, storage, use, and processing of data in the technical solution of this application comply with the relevant provisions of national laws and regulations.
[0035] Figure 1 This is a flow chart of the data query method provided by the present application. The method can be executed by a data query device, which can be implemented in software and / or hardware. In a specific embodiment, the device can be applied in a trusted center server. The trusted center server, the target user device, the cloud server, the servers corresponding to the multiple edge nodes, and the data source server are all servers in the data query system applied in cloud computing. The following embodiments will be described by taking the application of the device in a trusted center server or a data source server as an example. Figure 1 , the method may specifically include the following steps:
[0036] Step 101: Acquire target query information sent by a target user equipment.
[0037] The target query information includes a query keyword set, and the query keyword set includes multiple query keywords.
[0038] Specifically, the Trusted Authority (TA) server is a trusted server that encrypts data. The target user device is a device of a user who has the authority to query data. The target user device sends the target query information to the trusted center server, and the trusted center server receives the target query information. The target query information may include a query keyword set, and the query keyword set includes information of multiple query keywords, wherein the target query information may be the target query information obtained after the target user device encrypts all query keywords in the query keyword set using a hash algorithm.
[0039] Optionally, before executing step 101, steps 11 and 12 may also be executed.
[0040] Step 11: Generate a target symmetric key based on security parameters and a key generation algorithm.
[0041] The target symmetric key includes a target public key and a target private key.
[0042] Specifically, the trusted central server generates a target symmetric key according to security parameters and any key generation algorithm, such as a mean value clustering algorithm, and the target symmetric key includes a target public key and a target private key.
[0043] Step 12, sending the target private key to the data source server, and sending the target public key to the target user device, so that the data source server encrypts multiple data files according to the target private key, and the target user device decrypts the target query file according to the target public key to obtain the target file.
[0044] The target user equipment is a user equipment with query authority.
[0045] Specifically, the trusted central server sends the target public key to the target user device, so that the target user device can decrypt the target query file according to the target public key to obtain the target file after receiving the target query file in the future. The sending method can be to broadcast the public key to multiple authorized user devices, including the target user device. The trusted central server sends the target private key to the data source server, so that the data source server encrypts multiple data files according to the target private key, thereby improving the security of data transmission.
[0046] Step 102: extract keywords from multiple data files to obtain multiple keywords corresponding to each data file.
[0047] Specifically, the data source server uses a keyword recognition method to find some words that can represent the characteristics of each data file as keywords, that is, completes keyword extraction for multiple data files, thereby obtaining multiple keywords corresponding to each data file.
[0048] Step 103: encrypt multiple keywords corresponding to each data file, and send the encrypted keywords as a keyword sequence to the trusted central server.
[0049] Among them, the files in the cloud server are all encrypted files, and the target user device is used to receive the target query file and decrypt the target query file to obtain the target file.
[0050] Specifically, the data source server encrypts multiple keywords corresponding to each data file according to a hash algorithm to obtain multiple encrypted keywords. The data source server sends the encrypted multiple keywords as a keyword sequence to the trusted central server, so that the trusted central server determines the target query file identifier according to the keyword sequence and multiple query keywords, and the trusted central server sends the target query file identifier to the cloud server, so that the cloud server sends the target query file corresponding to the target query file identifier to the target user device, and the target user device receives the target query file and decrypts the target query file to obtain the target file.
[0051] Optionally, before executing step 104, the trusted central server may also execute steps 41 to 44.
[0052] Step 41: Receive a file identification set and an association relationship between the file identification set and a keyword sequence sent by a data source server.
[0053] Specifically, the trusted center server receives the file identification set and the association relationship between the file identification set and the keyword sequence sent by the data source server, where the association relationship can be an index matrix generated by the file identification set and the keyword sequence, thereby facilitating the acquisition of the association relationship between the file identification set and the keyword sequence and providing an index basis for subsequent data queries.
[0054] Step 42, split the association relationship into multiple target matrices.
[0055] Among them, the number of target matrices is the same as the number of edge servers.
[0056] Specifically, after receiving the association relationship, that is, the index matrix, the trusted central server splits the index matrix according to the number of edge servers. For example, assuming there are k edge servers, the matrix obtained by each edge server is 1 / k of the index matrix.
[0057] Step 43, obtaining the target total value corresponding to each target matrix according to the multiple target matrices, and determining the file identifier corresponding to each target matrix.
[0058] Specifically, by performing OR operation on each row of the submatrix obtained by each edge server, a target total value including all keyword information of the submatrix can be obtained, and the file identifier corresponding to each target matrix can be determined according to the submatrix, that is, the file identifier corresponding to the association relationship.
[0059] Step 44: for each target matrix, store the file identifier and the target total value corresponding to the target matrix to the server corresponding to the edge node corresponding to the target matrix.
[0060] Specifically, for each target matrix, the file identifier and the target total value corresponding to the target matrix are sent to the server corresponding to the edge node, so that they are stored in the server corresponding to the edge node corresponding to the target matrix.
[0061] Step 104: Determine the query result corresponding to each edge node according to the multiple query keywords and the keyword sequences corresponding to the multiple edge nodes.
[0062] The keyword sequence is a sequence obtained after the data source server extracts and encrypts keywords from the data file.
[0063] Specifically, the trusted central server compares multiple query keywords with the keyword sequence corresponding to each edge node, generates a binary string, and randomly selects a value j∈[0.1], and sets the value of the rth bit of the string to j. Then the binary string is converted into a binary token label T d .
[0064] Step 105: determine the target edge node corresponding to the target query information according to the query result corresponding to each edge node and the preset minimum query threshold, and send a file identification acquisition request to the server corresponding to the target edge node.
[0065] Specifically, the trusted central server performs a range search to determine the edge nodes containing the keyword, that is, the trusted central server will use the target total value of each edge node stored by itself to perform the AND operation. If the query result is equal to T d , and the obtained T d If the value of is greater than the preset minimum query threshold, it indicates that the matrix stored in the corresponding edge node contains the required query file identifier. At this time, the edge node is determined to be the target edge node, and a file identifier acquisition request is sent to the server corresponding to the target edge node.
[0066] Step 106: Receive the target query file identifier returned by the server corresponding to the target edge node, and send the target query file identifier to the cloud server, so that the cloud server sends the target query file corresponding to the target query file identifier to the target user device.
[0067] Among them, the files in the cloud server are all encrypted files, and the target user device is used to receive the target query file and decrypt the target query file to obtain the target file.
[0068] Specifically, after receiving the file identification acquisition request, the server corresponding to the target edge node returns the file identification to the trusted center server. The trusted center server receives the target query file identification returned by the server corresponding to the target edge node, and then sends the target query file identification to the cloud server, so that the cloud server sends the target query file corresponding to the target query file identification to the target user device. After receiving the target query file, the target user device decrypts the target query file to obtain the target file. The decryption method can be decrypted according to the target public key after receiving the target public key in the aforementioned step, or it can be decrypted according to a pre-set key pair. This application does not limit this.
[0069] In the scheme of the present application, a trusted central server obtains target query information sent by a target user device; wherein the target query information includes a query keyword set, and the query keyword set includes multiple query keywords; according to the keyword sequences corresponding to the multiple query keywords and the multiple edge nodes, a query result corresponding to each edge node is determined; wherein the keyword sequence is a sequence obtained after the data source server extracts keywords from the data file and encrypts it; according to the query result corresponding to each edge node and a preset minimum query threshold, a target edge node corresponding to the target query information is determined, and a file identifier acquisition request is sent to the server corresponding to the target edge node; a target query file identifier returned by the server corresponding to the target edge node is received, and the target query file identifier is sent to the cloud server, so that the cloud server sends the target query file corresponding to the target query file identifier to the target user device; wherein the files in the cloud server are all encrypted files, and the target user device is used to receive the target query file and decrypt the target query file to obtain the target file. That is, the solution of the present application determines the target edge node by comparing the query keyword with the keyword corresponding to each edge node, obtains the file identifier returned by the target edge node, and then sends the file identifier to the cloud server. The cloud server sends the file corresponding to the file identifier to the user device that initiated the query, thereby avoiding the situation where when the user wants to query the data stored in the cloud server, all the data must be downloaded, the data must be decrypted first, and then the query is performed in the decrypted data, thereby improving the query efficiency, saving communication bandwidth and computing resources, and maintaining the security of file transmission.
[0070] Figure 2 It is another flow chart of the data query method provided by the present application, which is applied to the trusted central server. When the file identification acquisition request includes the query result corresponding to the target edge node and the preset minimum query threshold, the process of sending the file identification acquisition request and obtaining the preset minimum query threshold by the trusted central server is described in detail, so as to further illustrate the data query method provided by the present application, such as Figure 2 As shown, the method may include the following steps:
[0071] Step 201: Acquire target query information sent by a target user equipment.
[0072] Step 202: Determine the query result corresponding to each edge node according to the multiple query keywords and the keyword sequences corresponding to the multiple edge nodes.
[0073] Optionally, before executing step 202, the trusted central server further receives a preset minimum query threshold sent by the target user equipment.
[0074] Specifically, presetting the minimum query threshold as the query threshold sent by the target user equipment can make the obtained query result more in line with user needs, thereby improving the accuracy of the query result.
[0075] Step 203: Determine the target edge server identifier corresponding to the target query information according to the query result corresponding to each edge node and the preset minimum query threshold.
[0076] Step 204, determine the target edge node according to the target edge server identifier, and send a file identifier acquisition request to the server corresponding to the target edge node, so that the server corresponding to the target edge node determines the target query file identifier according to the query result corresponding to the target edge node and the preset minimum query threshold.
[0077] Specifically, the server corresponding to the target edge node further searches the file identifier corresponding to itself according to the query result corresponding to the target edge node and the preset minimum query threshold, thereby determining the target query file identifier. d Convert the binary representation vector and multiply it with the transpose of each row of the matrix corresponding to the target edge node. If the result is greater than or equal to the minimum query threshold, it means that the file represented by the row contains the query keyword, and the row number is added to the set R. After the matching is completed, the set R is returned to the trusted central server, and the trusted central server obtains the file identifier.
[0078] Step 205: Receive the target query file identifier returned by the server corresponding to the target edge node, and send the target query file identifier to the cloud server, so that the cloud server sends the target query file corresponding to the target query file identifier to the target user device.
[0079] In the solution of the present application, after the trusted central server determines the server corresponding to the target edge node, the server corresponding to the target edge node performs further search, thereby further improving the accuracy of data query.
[0080] Figure 3It is another flow chart of the data query method provided by the present application, which is applied to the data source server and describes in detail the process of encrypting the data source server, so as to further illustrate the data query method provided by the present application, such as Figure 3 As shown, the method may include the following steps:
[0081] Step 301: extract keywords from multiple data files to obtain multiple keywords corresponding to each data file.
[0082] Step 302, receiving the target private key sent by the trusted central server, and encrypting multiple data files according to the target private key to obtain multiple encrypted files.
[0083] Specifically, after receiving the target private key sent by the trusted center server, the data source server encrypts multiple data files according to the target private key to obtain multiple encrypted files, so that the encrypted files can be decrypted by the target user device according to the corresponding private key.
[0084] Step 303: Send the multiple encrypted files to the cloud server so that the cloud server stores the multiple encrypted files.
[0085] Step 304: encrypt multiple keywords corresponding to each data file, and send the encrypted keywords as a keyword sequence to the trusted central server.
[0086] Step 305: Generate an association relationship based on the file identification set and the keyword sequence, and send the file identification set and the association relationship to the trusted central server.
[0087] Specifically, the data source server extracts all keywords in the file to form a keyword set. Then, it generates a corresponding file identifier for each file. The data source server encrypts each keyword in the keyword set using a hash function and sends it to the trusted central server. After that, the data source server constructs a binary matrix using the file identifier set and the keyword set, and then assigns values to the matrix to obtain an index matrix, which is used to characterize the association between the file identifier set and the keyword set.
[0088] In the scheme of the present application, the data source server extracts keywords from multiple data files to obtain multiple keywords corresponding to each data file; encrypts multiple keywords corresponding to each data file, and sends the encrypted multiple keywords as a keyword sequence to the trusted central server, so that the trusted central server determines the target query file identifier according to the keyword sequence and multiple query keywords, and makes the trusted central server send the target query file identifier to the cloud server, so that the cloud server sends the target query file corresponding to the target query file identifier to the target user device; wherein, the files in the cloud server are all encrypted files, and the target user device is used to receive the target query file and decrypt the target query file to obtain the target file. That is, in the scheme of the present application, multiple keywords of each data file are encrypted, avoiding the situation where the data file keyword leakage leads to the leakage of data file information, thereby further improving the security of data query.
[0089] Figure 4 Schematic diagram of a data query device provided by the present application. The device is suitable for executing the data query method provided by the present application and is configured in a trusted central server. Figure 4 As shown, the device may specifically include:
[0090] The query information acquisition module 401 is used to acquire target query information sent by a target user equipment; wherein the target query information includes a query keyword set, and the query keyword set includes multiple query keywords.
[0091] The query result determination module 402 is used to determine the query result corresponding to each edge node according to the keyword sequences corresponding to the multiple query keywords and the multiple edge nodes; wherein the keyword sequence is a sequence obtained after the data source server extracts keywords from the data file and encrypts them.
[0092] The request sending module 403 is used to determine the target edge node corresponding to the target query information according to the query result corresponding to each edge node and the preset minimum query threshold, and send a file identification acquisition request to the server corresponding to the target edge node.
[0093] The identification sending module 404 is used to receive the target query file identification returned by the server corresponding to the target edge node, and send the target query file identification to the cloud server, so that the cloud server sends the target query file corresponding to the target query file identification to the target user device; wherein, the files in the cloud server are all encrypted files, and the target user device is used to receive the target query file and decrypt the target query file to obtain the target file.
[0094] In one embodiment, the query information acquisition module 401 is also used to: before acquiring the target query information sent by the target user device, generate a target symmetric key according to security parameters and a key generation algorithm; wherein the target symmetric key includes a target public key and a target private key; send the target private key to the data source server, and send the target public key to the target user device, so that the data source server encrypts multiple data files according to the target private key, and enables the target user device to decrypt the target query file according to the target public key to obtain the target file; wherein the target user device is a user device with query authority.
[0095] In one embodiment, the query result determination module 402 is also used to: receive a file identification set sent by the data source server and an association relationship between the file identification set and the keyword sequence before determining the query result corresponding to each edge node based on the multiple query keywords and the keyword sequences corresponding to the multiple edge nodes; split the association relationship into multiple target matrices; wherein the number of the target matrices is the same as the number of the edge servers; obtain a target total value corresponding to each target matrix based on the multiple target matrices, and determine the file identification corresponding to each target matrix; for each target matrix, store the file identification and the target total value corresponding to the target matrix to the server corresponding to the edge node corresponding to the target matrix.
[0096] In one embodiment, the file identification acquisition request includes the query result corresponding to the target edge node and the preset minimum query threshold, and the request sending module 403 is specifically used to: determine the target edge server identifier corresponding to the target query information according to the query result corresponding to each edge node and the preset minimum query threshold; determine the target edge node according to the target edge server identifier, and send a file identification acquisition request to the server corresponding to the target edge node, so that the server corresponding to the target edge node determines the target query file identifier according to the query result corresponding to the target edge node and the preset minimum query threshold.
[0097] In one embodiment, the request sending module 403 is further used to: before determining the query result corresponding to each edge node according to the multiple query keywords and the keyword sequences corresponding to the multiple edge nodes, receive the preset minimum query threshold sent by the target user equipment.
[0098] The device on the trusted center server side of the present application, its optional implementation methods and the beneficial effects that can be achieved are the same as those of the method embodiment on the trusted center server side mentioned above, and will not be repeated here.
[0099] Figure 5is another structural diagram of the data query device provided by the present application, which is suitable for executing the data query method provided by the present application and is configured in the data source server. Figure 5 As shown, the device may specifically include:
[0100] The extraction module 501 is used to extract keywords from multiple data files to obtain multiple keywords corresponding to each of the data files.
[0101] The keyword encryption module 502 is used to encrypt multiple keywords corresponding to each of the data files, and send the encrypted multiple keywords as the keyword sequence to the trusted central server, so that the trusted central server determines the target query file identifier based on the keyword sequence and multiple query keywords, and enables the trusted central server to send the target query file identifier to the cloud server, so that the cloud server sends the target query file corresponding to the target query file identifier to the target user device; wherein, the files in the cloud server are all encrypted files, and the target user device is used to receive the target query file and decrypt the target query file to obtain the target file.
[0102] In one embodiment, the extraction module 501 is also used to extract keywords from multiple data files, and after obtaining multiple keywords corresponding to each of the data files, receive the target private key sent by the trusted center server, and encrypt the multiple data files according to the target private key to obtain multiple encrypted files; send the multiple encrypted files to the cloud server so that the cloud server stores the multiple encrypted files; the keyword encryption module 502 is also used to: encrypt the multiple keywords corresponding to each of the data files, and after sending the encrypted multiple keywords as the keyword sequence to the trusted center server, generate an association relationship based on the file identification set and the keyword sequence, and send the file identification set and the association relationship to the trusted center server.
[0103] The optional implementation methods and the beneficial effects that can be achieved of the device on the data source server side of the present application are the same as those of the method embodiment on the data source server side described above, and will not be described in detail here.
[0104] The present application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the data query method provided in any of the above embodiments when executing the program.
[0105] The present application also provides a computer-readable medium on which a computer program is stored. When the program is executed by a processor, the data query method provided in any of the above embodiments is implemented.
[0106] Reference below Figure 6 , which shows a structural schematic diagram of an electronic device 600 suitable for implementing the present application. Figure 6 The electronic device shown is only an example and should not bring any limitation to the function and scope of use of the present application.
[0107] like Figure 6 As shown, the electronic device 600 includes a central processing unit (CPU) 601, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 602 or a program loaded from a storage part 608 into a random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the electronic device 600 are also stored. The CPU 601, the ROM 602, and the RAM 603 are connected to each other via a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.
[0108] The following components are connected to the I / O interface 605: an input section 606 including a keyboard, a mouse, etc.; an output section 607 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 608 including a hard disk, etc.; and a communication section 609 including a network interface card such as a LAN card, a modem, etc. The communication section 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to the I / O interface 605 as needed. A removable medium 611, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 610 as needed, so that a computer program read therefrom is installed into the storage section 608 as needed.
[0109] In particular, according to the embodiments disclosed in the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 609, and / or installed from the removable medium 611. When the computer program is executed by the central processing unit (CPU) 601, the above-mentioned functions defined in the system of the present application are executed.
[0110] It should be noted that the computer-readable medium shown in the present application may be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in combination with an instruction execution system, device or device. In the present application, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries a computer-readable program code. This propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. Computer-readable signal media may also be any computer-readable medium other than computer-readable storage media, which may send, propagate or transmit a program for use by or in conjunction with an instruction execution system, apparatus or device. The program code contained on the computer-readable medium may be transmitted using any appropriate medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.
[0111] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present application. In this regard, each box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the above-mentioned module, program segment or a part of a code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flow chart, and the combination of the boxes in the block diagram or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0112] The modules and / or units described in this application may be implemented in software or hardware. The modules and / or units described may also be provided in a processor, for example, may be described as: a processor applied to a trusted central server, including a query information acquisition module, a query result determination module, a request sending module, and an identification sending module. Alternatively, it may be described as: a processor applied to a data source server, including an extraction module and a keyword encryption module. The names of these modules do not, in some cases, constitute limitations on the modules themselves.
[0113] As another aspect, the present invention further provides a computer-readable medium, which may be included in the device described in the above embodiment; or may exist independently without being assembled into the device. The above computer-readable medium carries one or more programs, and when the above one or more programs are executed by a device, the device performs the following operations:
[0114] The trusted central server obtains target query information sent by a target user device; wherein the target query information includes a query keyword set, and the query keyword set includes multiple query keywords; according to the keyword sequences corresponding to the multiple query keywords and the multiple edge nodes, the query result corresponding to each edge node is determined; wherein the keyword sequence is a sequence obtained after the data source server extracts keywords from the data file and encrypts it; according to the query result corresponding to each edge node and a preset minimum query threshold, the target edge node corresponding to the target query information is determined, and a file identifier acquisition request is sent to the server corresponding to the target edge node; the target query file identifier returned by the server corresponding to the target edge node is received, and the target query file identifier is sent to the cloud server, so that the cloud server sends the target query file corresponding to the target query file identifier to the target user device; wherein the files in the cloud server are all encrypted files, and the target user device is used to receive the target query file and decrypt the target query file to obtain the target file.
[0115] Or the computer-readable medium carries one or more programs, and when the one or more programs are executed by a device, the device performs the following operations:
[0116] The data source server extracts keywords from multiple data files to obtain multiple keywords corresponding to each data file; encrypts the multiple keywords corresponding to each data file, and sends the encrypted multiple keywords as a keyword sequence to a trusted central server, so that the trusted central server determines a target query file identifier based on the keyword sequence and multiple query keywords, and enables the trusted central server to send the target query file identifier to a cloud server, so that the cloud server sends the target query file corresponding to the target query file identifier to a target user device; wherein the files in the cloud server are all encrypted files, and the target user device is used to receive the target query file and decrypt the target query file to obtain the target file.
[0117] According to the technical solution of the present invention, the trusted central server obtains the target query information sent by the target user device; wherein the target query information includes a query keyword set, and the query keyword set includes multiple query keywords; according to the keyword sequences corresponding to the multiple query keywords and the multiple edge nodes, the query result corresponding to each edge node is determined; wherein the keyword sequence is a sequence obtained after the data source server extracts keywords from the data file and encrypts it; according to the query result corresponding to each edge node and a preset minimum query threshold, the target edge node corresponding to the target query information is determined, and a file identifier acquisition request is sent to the server corresponding to the target edge node; the target query file identifier returned by the server corresponding to the target edge node is received, and the target query file identifier is sent to the cloud server, so that the cloud server sends the target query file corresponding to the target query file identifier to the target user device; wherein the files in the cloud server are all encrypted files, and the target user device is used to receive the target query file and decrypt the target query file to obtain the target file. That is, the solution of the present application determines the target edge node by comparing the query keyword with the keyword corresponding to each edge node, obtains the file identifier returned by the target edge node, and then sends the file identifier to the cloud server. The cloud server sends the file corresponding to the file identifier to the user device that initiated the query, thereby avoiding the situation where when the user wants to query the data stored in the cloud server, all the data must be downloaded, the data must be decrypted first, and then the query is performed in the decrypted data, thereby improving the query efficiency, saving communication bandwidth and computing resources, and maintaining the security of file transmission.
[0118] An embodiment of the present application also provides a computer program product, including a computer program, which, when executed by a processor, implements a data query method as provided in any embodiment of the present application.
[0119] In the process of implementation, the computer program product can be written in one or more programming languages or a combination thereof to perform the computer program code of the present application, and the programming language includes an object-oriented programming language, such as Java, Smalltalk, C++, and also includes a conventional procedural programming language, such as "C" language or similar programming language. The program code can be executed entirely on the user's computer, partially on the user's computer, as an independent software package, partially on the user's computer and partially on the remote computer, or completely on the remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (for example, using an Internet service provider to connect through the Internet).
[0120] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps recorded in this application can be executed in parallel, sequentially or in different orders, as long as the expected results of the technical solution of this application can be achieved, and this document is not limited here.
[0121] The above specific implementations do not constitute a limitation on the protection scope of this application. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions may occur depending on design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principles of this application should be included in the protection scope of this application.
Claims
1. A data query method, characterized in that: Applied to a trusted central server, the method comprises: Acquire target query information sent by a target user device; wherein the target query information includes a query keyword set, and the query keyword set includes multiple query keywords; Determine the query result corresponding to each edge node according to the keyword sequences corresponding to the multiple query keywords and the multiple edge nodes; wherein the keyword sequence is a sequence obtained after the data source server extracts keywords from the data file and encrypts them; Determine the target edge node corresponding to the target query information according to the query result corresponding to each edge node and the preset minimum query threshold, and send a file identification acquisition request to the server corresponding to the target edge node; Receive a target query file identifier returned by the server corresponding to the target edge node, and send the target query file identifier to a cloud server, so that the cloud server sends the target query file corresponding to the target query file identifier to the target user device; wherein, the files in the cloud server are all encrypted files, and the target user device is used to receive the target query file and decrypt the target query file to obtain the target file.
2. The method according to claim 1, characterized in that Before acquiring the target query information sent by the target user equipment, the method further includes: Generate a target symmetric key according to the security parameters and the key generation algorithm; wherein the target symmetric key includes a target public key and a target private key; The target private key is sent to the data source server, and the target public key is sent to the target user device, so that the data source server encrypts multiple data files according to the target private key, and the target user device decrypts the target query file according to the target public key to obtain the target file; wherein the target user device is a user device with query authority.
3. The method according to claim 1, characterized in that Before determining the query result corresponding to each edge node according to the multiple query keywords and the keyword sequences corresponding to the multiple edge nodes, the method further includes: Receiving a file identification set sent by the data source server and an association relationship between the file identification set and the keyword sequence; Splitting the association relationship into a plurality of target matrices; wherein the number of the target matrices is the same as the number of the edge servers; Obtaining a target total value corresponding to each target matrix according to the plurality of target matrices, and determining a file identifier corresponding to each target matrix; For each of the target matrices, the file identifier and the target total value corresponding to the target matrix are stored in a server corresponding to an edge node corresponding to the target matrix.
4. The method according to claim 1, characterized in that The file identification acquisition request includes the query result corresponding to the target edge node and the preset minimum query threshold, and the target edge node corresponding to the target query information is determined according to the query result corresponding to each edge node and the preset minimum query threshold, and the file identification acquisition request is sent to the server corresponding to the target edge node, including: Determine the target edge server identifier corresponding to the target query information according to the query result corresponding to each edge node and the preset minimum query threshold; The target edge node is determined according to the target edge server identifier, and a file identifier acquisition request is sent to a server corresponding to the target edge node, so that the server corresponding to the target edge node determines the target query file identifier according to the query result corresponding to the target edge node and the preset minimum query threshold.
5. The method according to claim 1, characterized in that Before determining the query result corresponding to each edge node according to the multiple query keywords and the keyword sequences corresponding to the multiple edge nodes, the method further includes: The preset minimum query threshold sent by the target user equipment is received.
6. A data query method, characterized in that: Applied to a data source server, the method comprises: Extracting keywords from multiple data files to obtain multiple keywords corresponding to each of the data files; Encrypt multiple keywords corresponding to each of the data files, and send the encrypted multiple keywords as the keyword sequence to the trusted central server, so that the trusted central server determines the target query file identifier according to the keyword sequence and multiple query keywords, and the trusted central server sends the target query file identifier to the cloud server, so that the cloud server sends the target query file corresponding to the target query file identifier to the target user device; wherein the files in the cloud server are all encrypted files, and the target user device is used to receive the target query file and decrypt the target query file to obtain the target file.
7. The method according to claim 6, characterized in that After extracting keywords from the multiple data files to obtain multiple keywords corresponding to each of the data files, the method further includes: Receiving the target private key sent by the trusted central server, and encrypting the plurality of data files according to the target private key to obtain a plurality of encrypted files; sending the plurality of encrypted files to a cloud server so that the cloud server stores the plurality of encrypted files; After encrypting the multiple keywords corresponding to each of the data files and sending the encrypted multiple keywords as the keyword sequence to the trusted central server, the method further includes: An association relationship is generated according to the file identification set and the keyword sequence, and the file identification set and the association relationship are sent to the trusted central server.
8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, it implements the data query method as described in any one of claims 1 to 5, or implements the data query method as described in any one of claims 6 to 7.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, it implements the data query method as described in any one of claims 1 to 5, or implements the data query method as described in any one of claims 6 to 7.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, it implements the data query method as described in any one of claims 1 to 5, or implements the data query method as described in any one of claims 6 to 7.