Strength-self-defined multi-feature hidden trace query method and system based on national cryptographic algorithm

By using the combination of the domestic cryptographic algorithm SM9 and the Chinese residual theorem in the anonymous trace query, a multi-feature closure with customized strength is realized, solving the problem that multiple sample closure query and custom feature combination cannot be completed in the existing technology, and improving query efficiency and security.

CN120034333APending Publication Date: 2025-05-23AISINO CORPORATION
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202411980134.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

The prior art cannot complete multi-sample anonymous query without exposing the intersection of both data sets, and cannot meet the anonymous query of multiple feature combinations customized by users based on multiple factors.

Method used

The key generation and decryption mechanism based on the domestic cryptographic algorithm SM9 is adopted, and the public key encryption mechanism between the queryer and the queried party is used to encrypt and decrypt data in combination with the Chinese residual theorem to realize multi-feature anonymization query with custom strength.

Benefits of technology

It realizes multi-sample anonymized query without exposing the intersection of data sets, and supports user-defined anonymized strength, improving query efficiency and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034333A_ABST
    Figure CN120034333A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-feature hidden trace query method and system based on custom strength of a national cryptographic algorithm. A query party generates task configuration parameters of a query task; the queried party audits the task configuration parameters, after the task configuration parameters pass the auditing, a secret key pair of a domestic cryptographic algorithm SM9 is generated, and a public key in the secret key pair is sent to the query party; the query party generates a random number, encrypts the random number based on the public key, and sends the encrypted random number and query conditions in the task configuration parameters to the queried party; generating an original query result based on the query condition, and decrypting the encrypted random number through a private key to obtain a decrypted random number; the queried party encrypts the original query result based on the decrypted random number through the Chinese remainder theorem to generate an encrypted query result, and sends the encrypted query result to the query party; and decrypting the encrypted query result based on the random number by a Chinese remainder theorem query party to obtain a query result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information technology application technology, and more specifically, to a multi-feature anonymous query method and system with customized strength based on a national encryption algorithm. Background Art

[0002] With the introduction of the "Data Security Law" and the "Personal Information Protection Law", the privacy compliance issues of cross-domain data retrieval have been greatly affected. The privacy information anonymous query technology can correctly return the query results under the premise that the queried party cannot obtain the query requirements or conditions of the query party. In the query process and query results, the query party will not obtain any data information of the queried party except the query results. Through the secret state calculation of the whole process, the anonymous query technology is widely used in the scenarios of cross-domain secure sharing of data in different fields such as finance, education, and public security.

[0003] Prior art 1, CN116010678B, discloses a method, device and equipment for anonymous query, wherein the client uses the OPRF protocol to interact with the server for the client keyword, obtains the encrypted value of the client keyword and the stream cipher key, and the client obtains the encrypted value of the server keyword from the server. The intersection keyword is obtained by taking the intersection of the encrypted value of the client keyword and the encrypted value of the server keyword, and the client only selects the keyword to be queried from the intersection keyword, and then uses the homomorphic encryption algorithm to initiate a query to the server to obtain the query result.

[0004] However, the existing technology 1 is based on the search mechanism of cloud opfr secure intersection. It can meet the anonymous query of multiple feature combinations, but cannot customize the anonymous strength according to the security requirements of both parties and the query party. The existing technology 1 cannot complete the anonymous query of multiple samples without exposing the intersection of the two data sets.

[0005] Prior art 2, CN103873236B, discloses a searchable encryption method and device. Prior art 3 provides a searchable encryption method and device, wherein the sender obtains the identity of the searcher or the identity of the group to which the searcher belongs, and the system parameters of the key management center; the sender encrypts the keyword according to the identity of the searcher or the identity of the group to which the searcher belongs, and the system parameters, and uploads the encrypted keyword ciphertext to the storage server. At the same time, the searcher obtains the query key from the key management center according to the identity of the searcher or the identity of the group to which the searcher belongs, generates a query token according to the keyword and the obtained query key, queries the encrypted keyword ciphertext from the storage server through the query token, and receives the data returned by the storage server. Thereby, the searchable encryption technology is realized without the support of expensive public key infrastructure and the sender does not need to download the public key.

[0006] However, the prior art 2 cannot satisfy the anonymous query of multiple feature combinations, and the querying party customizes the anonymous strength according to the security requirements of both parties. The prior art 2 cannot complete the anonymous query of multiple samples without exposing the query conditions to a third party.

[0007] Prior art 3, CN115982424B, provides a privacy keyword query method, device and electronic device. Prior art 3 invents a privacy keyword query method, device and electronic device, which relates to the field of privacy computing technology. The client device groups multiple keywords to be queried, and uses the Chinese remainder theorem to package and encode them, and adopts a semi-homomorphic encryption algorithm to perform privacy keyword query through message interaction with the server device, and obtains the query ciphertext data returned by the server device. After decryption and decoding, the query results of the multiple keywords are obtained from the decoded data, realizing one-time privacy query for multiple keywords in batches, improving query efficiency, and realizing privacy query based on the semi-homomorphic encryption method, reducing computing and communication overhead.

[0008] However, the existing technology 3 cannot satisfy the anonymous query of multiple feature combinations customized by users based on multiple factors, and cannot satisfy the security of the queried party's retrieval information without confidential logic calculation. Summary of the invention

[0009] The technical solution of the present invention provides a multi-feature anonymous query method and system with customized strength based on the national encryption algorithm to solve the problem of how to perform multi-feature anonymous query based on customized strength of the national encryption algorithm.

[0010] In order to solve the above problems, the present invention provides a multi-feature anonymous query method with customized strength based on a national secret algorithm, the method comprising:

[0011] The querying party generates task configuration parameters for the query task and sends the task configuration parameters to the queried party;

[0012] The queried party reviews the task configuration parameters. When the task configuration parameters pass the review, the queried party generates a key pair of the domestic cryptographic algorithm SM9 based on the task configuration parameters, and sends the public key in the key pair to the querying party;

[0013] The querying party generates a random number, encrypts the random number based on the public key, and sends the encrypted random number and the query condition in the task configuration parameter to the queried party;

[0014] The queried party generates an original query result based on the query condition, decrypts the encrypted random number using the private key in the key pair, and obtains the decrypted random number;

[0015] The queried party encrypts the original query result by using the Chinese remainder theorem based on the decrypted random number to generate an encrypted query result, and sends the encrypted query result to the querying party;

[0016] The querying party decrypts the encrypted query result based on the random number obtained through the Chinese Remainder Theorem to obtain the query result.

[0017] Preferably, the task configuration parameters include: task number, timestamp, name of the data set to be queried, feature field set to be queried, query logic and query strength.

[0018] Preferably, the queried party generates a key pair of the domestic cryptographic algorithm SM9 based on the task configuration parameters, and sends the public key in the key pair to the querying party, including:

[0019] Based on the q value of the query strength, generate q public key sets [M i ,i∈q], i is the serial number of the i-th public key among q.

[0020] Preferably, the querying party generates a random number, encrypts the random number based on the public key, and sends the encrypted random number and the query condition to the queried party, including:

[0021] The query party generates a multi-feature query condition Q based on the query logic L t , and generate other query conditions Q of the query logic L i ;

[0022] The querying party generates a random number R, uses the domestic cryptographic algorithm SM9 to generate a random number ciphertext R', and combines the random number ciphertext R', the query condition Q t Sent to the queried party.

[0023] Preferably, the queried party generates an original query result based on the query condition, decrypts the encrypted random number using a private key in the key pair, and obtains the decrypted random number, including:

[0024] The queried party according to the query condition Q t Search in the specified target file and generate q query result sets {f 1 ,…,f n};

[0025] Use private key [W i]Decrypt the random number ciphertext R' and get q random numbers [Ri]:

[0026] R i =SM9(R',W i ).

[0028] Preferably, the queried party encrypts the original query result based on the decrypted random number by using the Chinese remainder theorem to generate an encrypted query result, and sends the encrypted query result to the querying party, including:

[0029] The queried party uses the random number R i , the original query result {f 1 ,…,f n} to encrypt and obtain the encrypted query result [f i ']

[0030] f i '=CRT(f i ,R i ):

[0031] And send the encrypted query result [fi'] to the querying party.

[0032] Preferably, the querying party decrypts the encrypted query result based on the random number by using the Chinese remainder theorem to obtain the query result, including:

[0033] The querying party decrypts the ciphertext data set based on the random number R and the Chinese Remainder Theorem CRT:

[0034] f=CRT(f i ',R)

[0035] The querying party obtains query results that meet the query conditions.

[0036] Based on another aspect of the present invention, the present invention provides a multi-feature anonymous tracking query system with customized strength based on a national secret algorithm, the system comprising: a user end and a server end;

[0037] The user end is used to generate task configuration parameters for the query task and send the task configuration parameters to the server end; to generate a random number, encrypt the random number based on the public key, and send the encrypted random number and the query conditions in the task configuration parameters to the server end; and to decrypt the encrypted query result based on the random number by the query party through the Chinese remainder theorem to obtain the query result;

[0038] The server is used to review the task configuration parameters. When the task configuration parameters pass the review, the server generates a key pair of the domestic cryptographic algorithm SM9 based on the task configuration parameters, and sends the public key in the key pair to the query party; it is used to generate an original query result based on the query condition, decrypt the encrypted random number through the private key in the key pair, and obtain the decrypted random number; it is used to encrypt the original query result based on the decrypted random number through the Chinese remainder theorem, generate an encrypted query result, and send the encrypted query result to the query party.

[0039] Preferably, the task configuration parameters include: task number, timestamp, name of the data set to be queried, feature field set to be queried, query logic and query strength.

[0040] Preferably, the server is used to generate a key pair of the domestic cryptographic algorithm SM9 based on the task configuration parameters, and send the public key in the key pair to the user end, and is also used to:

[0041] Based on the q value of the query strength, generate q public key sets [M i ,i∈q], i is the serial number of the i-th public key among q.

[0042] Preferably, the query is used to generate a random number, encrypt the random number based on the public key, send the encrypted random number and the query condition to the server, and is also used to:

[0043] The user terminal generates a multi-feature query condition Q based on the query logic L t , and generate other query conditions Q of the query logic L i ;

[0044] The user terminal generates a random number R, uses the domestic cryptographic algorithm SM9 to generate a random number ciphertext R', and combines the random number ciphertext R', the query condition Q t Send to the server.

[0045] Preferably, the server is used to generate an original query result based on the query condition, decrypt the encrypted random number using the private key in the key pair to obtain the decrypted random number, and is also used to:

[0046] The server side uses the query condition Q t Search in the specified target file and generate q query result sets {f 1 ,…,f n};

[0047] Use private key [W i]Decrypt the random number ciphertext R' and get q random numbers [Ri]:

[0048] R i =SM9(R',W i ).

[0050] Preferably, the server is used to encrypt the original query result based on the decrypted random number by using the Chinese remainder theorem to generate an encrypted query result, and send the encrypted query result to the user end, and is also used to:

[0051] The server is based on the random number R i , the original query result {f 1 ,…,f n} to encrypt and obtain the encrypted query result [f i ']

[0052] f i '=CRT(f i ,R i ):

[0053] And send the encrypted query result [fi'] to the user end.

[0054] Preferably, the user terminal is used to decrypt the encrypted query result based on the random number by using the Chinese remainder theorem to obtain the query result, and is also used to:

[0055] The user end decrypts the ciphertext data set based on the random number R and the Chinese remainder theorem CRT:

[0056] f=CRT(f i ',R)

[0057] The user terminal obtains query results that meet the query conditions.

[0058] The technical solution of the present invention provides a multi-feature stealth query method and system with customized strength based on a national secret algorithm, wherein the method comprises: generating task configuration parameters of a query task by a querying party, and sending the task configuration parameters to a queried party; reviewing the task configuration parameters by the queried party, and when the task configuration parameters pass the review, generating a key pair of a domestic cryptographic algorithm SM9 based on the task configuration parameters by the queried party, and sending the public key in the key pair to the querying party; generating a random number by the querying party, encrypting the random number based on the public key, and sending the encrypted random number and the query conditions in the task configuration parameters to the queried party; generating an original query result by the queried party based on the query conditions, decrypting the encrypted random number by the private key in the key pair, and obtaining the decrypted random number; encrypting the original query result by the queried party based on the decrypted random number by the Chinese remainder theorem, generating an encrypted query result, and sending the encrypted query result to the querying party; decrypting the encrypted query result by the querying party based on the random number by the Chinese remainder theorem, and obtaining the query result. The technical solution of the present invention adopts user-defined anonymity strength and the Chinese remainder theorem according to the security attributes of both querying parties to complete the anonymity query of complex logical relationships under multiple features, reduce network and computational workload, and improve query efficiency. The technical solution of the present invention adopts an identity-based public key encryption mechanism and the domestic SM9 cryptographic algorithm to improve the security and computational efficiency of the anonymity query by pre-calculating the public and private key pairs of the unique task identifier. BRIEF DESCRIPTION OF THE DRAWINGS

[0059] A more complete understanding of exemplary embodiments of the present invention may be obtained by referring to the following drawings:

[0060] Figure 1 It is a flow chart of a multi-feature anonymous query method with customized strength based on a national encryption algorithm according to a preferred embodiment of the present invention;

[0061] Figure 2 A flowchart of a multi-feature anonymous query method with customized strength based on a national encryption algorithm according to a preferred embodiment of the present invention; and

[0062] Figure 3 This is a structural diagram of a multi-feature anonymous query system with customized strength based on a national encryption algorithm according to a preferred embodiment of the present invention. DETAILED DESCRIPTION

[0063] Now, exemplary embodiments of the present invention are described with reference to the accompanying drawings. However, the present invention can be implemented in many different forms and is not limited to the embodiments described herein. These embodiments are provided to disclose the present invention in detail and completely and to fully convey the scope of the present invention to those skilled in the art. The terms used in the exemplary embodiments shown in the accompanying drawings are not intended to limit the present invention. In the accompanying drawings, the same units / elements are marked with the same reference numerals.

[0064] Unless otherwise specified, the terms (including technical terms) used herein have the commonly understood meanings to those skilled in the art. In addition, it is understood that the terms defined in commonly used dictionaries should be understood to have the same meanings as those in the context of the relevant fields, and should not be understood as idealized or overly formal meanings.

[0065] Figure 1 The present invention is a flowchart of a multi-feature anonymous query method with customized strength based on a national encryption algorithm according to a preferred embodiment of the present invention.

[0066] The anonymous query method of the present invention supports domestic cryptographic algorithms. The present invention can satisfy anonymous queries of multiple feature combinations customized by users based on multiple factors. The present invention improves the security of the queried party's retrieval information without secret logic calculation by applying the Chinese remainder theorem.

[0067] like Figure 1 As shown, the present invention provides a multi-feature anonymous query method with customized strength based on a national secret algorithm, the method comprising:

[0068] Step 101: The querying party generates task configuration parameters of the query task and sends the task configuration parameters to the queried party;

[0069] Preferably, the task configuration parameters include: task number, timestamp, name of the data set to be queried, feature field set to be queried, query logic and query strength.

[0070] The querying party of the present invention is the initiator C of the anonymous query privacy computing task, and the queried party is the responder S of the task. The querying party generates the task parameters of this anonymous query, including:

[0071] Task No. Tid

[0072] TimestampTS

[0073] The name of the dataset to be queried.

[0074] Feature field set to be queried [W]

[0075] Query Logic

[0076] Query strength q

[0077] And other task configuration information.

[0078] The present invention sends the query to the query party through the https protocol. The query party reviews the N, [W] and q information and returns confirmation / rejection information. If confirmed, the query party generates task information with the same task number and saves the task configuration information.

[0079] Step 102: The queried party reviews the task configuration parameters. When the task configuration parameters pass the review, the queried party generates a key pair of the domestic cryptographic algorithm SM9 based on the task configuration parameters, and sends the public key in the key pair to the querying party;

[0080] Preferably, the queried party generates a key pair of the domestic cryptographic algorithm SM9 based on the task configuration parameters, and sends the public key in the key pair to the querying party, including:

[0081] Based on the q value of the query strength, generate q public key sets [M i ,i∈q], i is the serial number of the i-th public key among q.

[0082] If the queried party S of the present invention confirms the anonymous query application, then based on the public key encryption mechanism based on the domestic cryptographic algorithm SM9 and the above-mentioned integer anonymous strength q value, q random numbers [M i ,i∈q], precomputed identifier [W i ]’s corresponding private key. i ]The encoding format is:

[0083] M i @TS.Tid

[0084] In the confirmation message, it is returned to the inquiring party.

[0085] Step 103: The querying party generates a random number, encrypts the random number based on the public key, and sends the encrypted random number and the query condition in the task configuration parameter to the queried party;

[0086] Preferably, the querying party generates a random number, encrypts the random number based on a public key, and sends the encrypted random number and the query condition to the queried party, including:

[0087] The query party generates multi-feature query conditions Q based on the query logic L t , and generate other query conditions Q of query logic L i ;

[0088] The querying party generates a random number R, uses the domestic cryptographic algorithm SM9 to generate a random number ciphertext R', and then uses the random number ciphertext R' and the query condition Q t Sent to the queried party.

[0089] After receiving the confirmation response from the queried party, the query party C of the present invention generates a multi-feature query condition Q according to the query logic L. t , and generate other query condition masks {Q i ,i∈q-1,i≠t}, used for anonymous obfuscation Q w .

[0090] The querying party of the present invention generates a random number R, and uses the domestic cryptographic algorithm SM9 to generate a ciphertext R':

[0091] R'=SM9(R,W t )

[0092] And R', [Q t ] is sent to the party being queried.

[0093] Step 104: The queried party generates an original query result based on the query condition, decrypts the encrypted random number using the private key in the key pair, and obtains the decrypted random number;

[0094] Preferably, the queried party generates an original query result based on the query condition, and decrypts the encrypted random number using the private key in the key pair to obtain the decrypted random number, including:

[0095] The queried party uses the query condition Q t Search in the specified target file and generate q query result sets {f 1 ,…,f n};

[0096] Use private key [W i ]Decrypt the random number ciphertext R' and get q random numbers [Ri]:

[0097] R i =SM9(R',W i ).

[0099] The present invention is based on the query condition [Q t ] Perform a local query on the specified file DataID and generate q query result sets {f 1 ,…,f n}. And use [W i ] decrypt R' and get q [Ri]:

[0100] R i =SM9(R',W i )

[0101] Step 105: The queried party encrypts the original query result based on the decrypted random number using the Chinese remainder theorem to generate an encrypted query result, and sends the encrypted query result to the query party;

[0102] Preferably, the queried party encrypts the original query result based on the decrypted random number using the Chinese remainder theorem to generate an encrypted query result, and sends the encrypted query result to the query party, including:

[0103] The queried party uses the random number R i , through the Chinese remainder theorem CRT, the original query result {f 1 ,…,f n} to encrypt and obtain the encrypted query result [f i ']

[0104] f i '=CRT(f i ,R i ):

[0105] And send the encrypted query result [fi'] to the querying party.

[0106] The queried party of the present invention uses the key R i , using the Chinese remainder theorem CRT to 1 ,…,f n} to encrypt and obtain the ciphertext [f i ']:

[0107] f i '=CRT(f i ,R i )

[0108] And send the ciphertext data set [fi'] to the querying party.

[0109] Step 106: The querying party decrypts the encrypted query result based on random numbers using the Chinese Remainder Theorem to obtain the query result.

[0110] Preferably, the querying party decrypts the encrypted query result based on a random number using the Chinese remainder theorem to obtain the query result, including:

[0111] The querying party decrypts the ciphertext data set based on the random number R and the Chinese Remainder Theorem CRT:

[0112] f=CRT(f i ',R)

[0113] The querying party obtains the query results that meet the query conditions.

[0114] The querying party of the present invention uses the key R to decrypt the ciphertext data set using the Chinese remainder theorem CRT.

[0115] f=CRT(f i ',R)

[0116] According to the CRT stream encryption and decryption algorithm, the querying party can and can only correctly recover the query condition to be anonymized as Q w For example, Figure 2 shown.

[0117] Users of the present invention can independently and flexibly configure the intensity of anonymous queries according to the actual conditions of the parties involved, such as security, resources, and time sensitivity; random numbers are combined with the Chinese remainder theorem to complete data set encryption and decryption, thereby ensuring data security while improving computing and transmission efficiency.

[0118] The present invention combines the cross-domain multi-party participation and audit / confirmation mechanism of anonymous query, completes the pre-calculation process in parallel, and optimizes the task execution efficiency. It adopts the SM9 domestic public key encryption algorithm based on identification, uses the timestamp + task identification as the public and private identification, optimizes the execution efficiency of each anonymous query task, and ensures the anti-attack capability of malicious tasks to steal private keys.

[0119] The present invention is based on a domestic cryptographic algorithm and realizes a minimized privacy protection mechanism for data query in the scenario of cross-domain data security sharing. It has fast response speed and relatively low resource requirements. The use of domestic cryptographic algorithms can better meet the current requirements of government affairs, finance and other fields for the security compliance of cryptographic algorithms for cross-domain data sharing.

[0120] Figure 3 This is a structural diagram of a multi-feature anonymous query system with customized strength based on a national encryption algorithm according to a preferred embodiment of the present invention.

[0121] like Figure 3 As shown, the present invention provides a multi-feature anonymous tracking query system with customized strength based on the national secret algorithm, the system includes: a user end and a server end;

[0122] The user end 301 is used to generate task configuration parameters of the query task and send the task configuration parameters to the server end;

[0123] Preferably, the task configuration parameters include: task number, timestamp, name of the data set to be queried, feature field set to be queried, query logic and query strength.

[0124] The server 302 is used to review the task configuration parameters. When the task configuration parameters pass the review, the server generates a key pair of the domestic cryptographic algorithm SM9 based on the task configuration parameters, and sends the public key in the key pair to the user end;

[0125] Preferably, the server 302 is used to generate a key pair of the domestic cryptographic algorithm SM9 based on the task configuration parameters, and send the public key in the key pair to the user end, and is also used to:

[0126] Based on the q value of the query strength, generate q public key sets [M i ,i∈q], i is the serial number of the i-th public key among q.

[0127] The client 301 is used to generate a random number, encrypt the random number based on the public key, and send the encrypted random number and the query condition in the task configuration parameter to the server;

[0128] Preferably, the user end 301 is used to generate a random number, encrypt the random number based on a public key, send the encrypted random number and the query condition to the server, and also to:

[0129] The user generates multi-feature query conditions Q based on the query logic L. t , and generate other query conditions Q of query logic L i ;

[0130] The user end generates a random number R, uses the domestic cryptographic algorithm SM9, generates a random number ciphertext R', and then adds the random number ciphertext R' and the query condition Q t Send to the server.

[0131] The server 302 is used to generate an original query result based on the query condition, decrypt the encrypted random number using the private key in the key pair, and obtain the decrypted random number;

[0132] Preferably, the server 302 is used to generate an original query result based on the query condition, decrypt the encrypted random number using the private key in the key pair to obtain the decrypted random number, and is also used to:

[0133] Through the server according to the query condition Q t Search in the specified target file and generate q query result sets {f 1 ,…,f n};

[0134] Use private key [W i ]Decrypt the random number ciphertext R' and get q random numbers [Ri]:

[0135] R i =SM9(R',W i ).

[0137] The server 302 is used to encrypt the original query result based on the decrypted random number using the Chinese remainder theorem, generate an encrypted query result, and send the encrypted query result to the user end;

[0138] Preferably, the server 302 is used to encrypt the original query result based on the decrypted random number by using the Chinese remainder theorem, generate an encrypted query result, and send the encrypted query result to the user end, and is also used to:

[0139] The server is based on the random number R i , through the Chinese remainder theorem CRT, the original query result {f 1 ,…,f n} to encrypt and obtain the encrypted query result [f i ']

[0140] f i '=CRT(f i ,R i ):

[0141] And send the encrypted query result [fi'] to the user end.

[0142] The user terminal 301 is used to decrypt the encrypted query result based on random numbers through the Chinese remainder theorem through the user terminal to obtain the query result.

[0143] Preferably, the user terminal 301 is used to decrypt the encrypted query result based on the random number by using the Chinese remainder theorem to obtain the query result, and is also used to:

[0144] The user end decrypts the ciphertext data set based on the random number R and the Chinese remainder theorem CRT:

[0145] f=CRT(f i ',R)

[0146] The client obtains the query results that meet the query conditions.

[0147] A multi-feature anonymous query system with customized strength based on a national secret algorithm in a preferred embodiment of the present invention corresponds to a multi-feature anonymous query method with customized strength based on a national secret algorithm in another preferred embodiment of the present invention, which will not be repeated here.

[0148] It will be appreciated by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes. The schemes in the embodiments of the present invention may be implemented in various computer languages, for example, object-oriented programming language Java and literal scripting language JavaScript, etc.

[0149] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0150] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0151] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0152] Although the preferred embodiments of the present invention have been described, those skilled in the art may make other changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.

[0153] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalents, the present invention is also intended to include these modifications and variations.

[0154] The invention has been described above with reference to a few embodiments. However, it is readily apparent to a person skilled in the art that other embodiments than the ones disclosed above are equally within the scope of the invention, as defined by the appended patent claims.

[0155] Generally, all terms used in the claims are to be interpreted according to their ordinary meaning in the technical field, unless explicitly defined otherwise herein. All references to "a / / the [means, component, etc.]" are to be openly interpreted as at least one instance of a means, component, etc., unless explicitly stated otherwise. The steps of any method disclosed herein do not necessarily have to be performed in the exact order disclosed, unless explicitly stated otherwise.

Claims

1. A multi-feature anonymous query method with customized strength based on a national secret algorithm, the method comprising: The querying party generates task configuration parameters for the query task and sends the task configuration parameters to the queried party; The queried party reviews the task configuration parameters. When the task configuration parameters pass the review, the queried party generates a key pair of the domestic cryptographic algorithm SM9 based on the task configuration parameters, and sends the public key in the key pair to the querying party; The querying party generates a random number, encrypts the random number based on the public key, and sends the encrypted random number and the query condition in the task configuration parameter to the queried party; The queried party generates an original query result based on the query condition, decrypts the encrypted random number using the private key in the key pair, and obtains the decrypted random number; The queried party encrypts the original query result by using the Chinese remainder theorem based on the decrypted random number to generate an encrypted query result, and sends the encrypted query result to the querying party; The querying party decrypts the encrypted query result based on the random number by using the Chinese remainder theorem to obtain the query result.

2. According to the method of claim 1, the task configuration parameters include: Task number, timestamp, name of the dataset to be queried, set of feature fields to be queried, query logic, and query strength.

3. The method according to claim 2, wherein the queried party generates a key pair of the domestic cryptographic algorithm SM9 based on the task configuration parameters, and sends the public key in the key pair to the querying party, comprising: Based on the q value of the query strength, generate q public key sets [M i ,i∈q], i is the serial number of the i-th public key among q.

4. The method according to claim 2, wherein the querying party generates a random number, encrypts the random number based on the public key, and sends the encrypted random number and the query condition to the queried party, comprising: The query party generates a multi-feature query condition Q based on the query logic L t , and generate other query conditions Q of the query logic L i ; The querying party generates a random number R, uses the domestic cryptographic algorithm SM9 to generate a random number ciphertext R', and combines the random number ciphertext R', the query condition Q t Sent to the queried party.

5. The method according to claim 1, wherein the queried party generates an original query result based on the query condition, decrypts the encrypted random number using a private key in the key pair, and obtains the decrypted random number, comprising: The queried party according to the query condition Q t Search in the specified target file and generate q query result sets {f1,…,f n }; Use private key [W i ]Decrypt the random number ciphertext R' and get q random numbers [Ri]: R i =SM9(R’,W i )。 6. The method according to claim 1, wherein the queried party encrypts the original query result based on the decrypted random number by using the Chinese remainder theorem to generate an encrypted query result, and sends the encrypted query result to the query party, comprising: The queried party uses the random number R i , the original query result {f1,…,f n } to encrypt and obtain the encrypted query result [f i '] f i ’=CRT(f i ,R i ): And send the encrypted query result [fi'] to the querying party.

7. According to the method of claim 1, the querying party decrypts the encrypted query result based on the random number by using the Chinese remainder theorem to obtain the query result, comprising: The querying party decrypts the ciphertext data set based on the random number R and the Chinese Remainder Theorem CRT: f=CRT(f i ’,R) The querying party obtains query results that meet the query conditions.

8. A multi-feature anonymous query system with customized strength based on a national secret algorithm, the system comprising: The client and the server; The user end is used to generate task configuration parameters for the query task and send the task configuration parameters to the server end; Used to generate a random number, encrypt the random number based on the public key, and send the encrypted random number and the query condition in the task configuration parameter to the server; Used to decrypt the encrypted query result based on the random number using the Chinese remainder theorem to obtain the query result; The server is used to review the task configuration parameters. When the task configuration parameters pass the review, the server generates a key pair of the domestic cryptographic algorithm SM9 based on the task configuration parameters, and sends the public key in the key pair to the user end; it is used to generate an original query result based on the query condition, decrypt the encrypted random number by the private key in the key pair, and obtain the decrypted random number; It is used to encrypt the original query result based on the decrypted random number through the Chinese remainder theorem, generate an encrypted query result, and send the encrypted query result to the user end.

9. The system according to claim 8, wherein the task configuration parameters include: Task number, timestamp, name of the dataset to be queried, set of feature fields to be queried, query logic, and query strength.

10. The system according to claim 9, wherein the server is used to generate a key pair of the domestic cryptographic algorithm SM9 based on the task configuration parameters, and send the public key in the key pair to the user end, and is also used to: Based on the q value of the query strength, generate q public key sets [M i ,i∈q], i is the serial number of the i-th public key among q.

Citation Information

Patent Citations

  • A searchable encryption method and device

    CN103873236B

  • Hidden query method and system

    CN113987583A

  • National secret and index confusion-based hidden trace query method and device

    CN114547668A

  • Hidden trace query method, device and equipment

    CN116010678A