Zero-knowledge protection method of data, server and storage medium

By dividing client data into deterministic and non-deterministic data and converting it into zero-knowledge data, the problem of data privacy infringement in traditional data storage methods is solved, and the secure storage and efficient operation of data are achieved.

CN120034400AActive Publication Date: 2025-05-23DARKCHAIN TECH INC
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510517941.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-24
Publication Date
2025-05-23
Estimated Expiration
2045-04-24

AI Technical Summary

Technical Problem

Traditional data storage methods are prone to infringement and disclosure of client data by storage service platforms, especially in cloud services. Cloud service providers have full permissions and capabilities to obtain and use user data, resulting in the risks of privacy infringement and data protection.

Method used

A zero-knowledge protection method for data is adopted, and the client data is divided into deterministic data and non-deterministic data, and converted into zero-knowledge data, and stored on the second server. Deterministic data is matched through pre-configured optional data sets, while non-deterministic data is processed and stored through mapping tables, ensuring that data is not directly exposed to cloud service providers when stored and accessed.

Benefits of technology

It effectively protects user data from malicious acquisition and disclosure, ensures the security of data privacy, and improves the read and write and comprehensive operation efficiency of the database.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034400A_ABST
    Figure CN120034400A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a zero-knowledge protection method of data, a server and a storage medium. The method comprises the steps that client data sent by a second server are obtained, if the client data comprise target deterministic data, the target deterministic data are converted into first-form data, the first-form data are sent to the second server to be stored, and the first-form data are zero knowledge data. And if the client data comprises the target non-deterministic data, mapping the target non-deterministic data into second-form data, and sending the second-form data to a second server for storage, the second-form data being zero knowledge data. According to the embodiment of the invention, direct acquisition of the user data on the second server is isolated by using the established form data, so that the user data can be reliably protected from being maliciously acquired and leaked.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of data processing technology, and in particular to a zero-knowledge protection method, server, and storage medium for data. Background Art

[0002] As time goes by and technology continues to develop, various application systems serving all aspects of our social life are becoming more and more powerful and complex. The development and operation of these systems have gradually evolved from the original centralized team closed integrated implementation to the multi-party division of labor and collaboration of functional decoupling, subsystem and microservice separation, Internet and communication protocol connection, API access and expansion. This trend continues to liberate the upward scale of information systems, thereby continuously improving the macro-productivity of society.

[0003] Among them, cloud services support the hardware infrastructure of storage, algorithms and computing power for most of the current information technology applications, and are the main pillar for the significant advancement of macro productivity in recent years.

[0004] Storage is a core service in cloud services. In the current traditional and most commonly used storage architecture, relational databases, as software management tool libraries, are responsible for the main function of persistent storage, and non-relational databases play an auxiliary role. When cloud service providers provide servers to application developers, they have virtually full authority and ability to obtain and use all user data that needs to be stored when providing services to their users, as well as the commercial secrets (including code innovations and key configuration parameters) when they design these applications, which not only poses a direct risk to privacy infringement and data protection, but also constitutes an indirect challenge to technological progress and application promotion. At the same time, with the exponential growth of data volume, the traditional reading, writing and parallelization bottlenecks of relational database software on cloud service hardware systems based on centralized services (the contradiction between atomic security requirements and parallel efficiency requirements) have become a constraint and challenge to further scale-up in the future.

[0005] In the current use of cloud services, the database is deployed by the application developer as software on the server hardware provided by the cloud service provider. Although its operation and processing of requests from the upper layer are managed by the application developer, the underlying storage and access of the data stored in the database on the hardware are managed by the resource management operating system of the cloud service provider. Therefore, any data stored by the application developer in the database, including its own system data and user data, is completely transparent from the perspective of the cloud service provider without any authority to conceal it, and its data form is the original form of data storage.

[0006] Take user data as an example. In reality, these data are usually directly stored as actual data (including symmetrically encrypted content, which also contains all actual information from the perspective of information entropy) in traditional relational database storage architectures, allowing cloud service providers to have a clear view of the privacy information of users of application developers using their services, and to copy and transfer them without technical barriers, and to do so without the knowledge of the application developers. Since legal protection requires clear evidence, these protections are in name only and almost unattainable in the absence of knowledge.

[0007] On the other hand, these user data are in various forms (such as integers, floating points, dates, texts, files, binary, etc.), which leads to the non-uniformity of the data format, encoding, length, required storage resources and type. It also leads to additional complexity and resource consumption in the technical requirements and implementation of data operations, reversible conversions, integrity verification, encryption and decryption.

[0008] To sum up, storing actual data directly on the hardware storage service provided by a third party cannot prevent the third party from infringing data privacy. Even with the protection of agreements and legal terms, it lacks practical effect. At the same time, due to the diversity of data, it brings many challenges to the effectiveness of storage and access. Summary of the invention

[0009] One purpose of the embodiments of the present application is to provide a zero-knowledge protection method, server and storage medium for data, so as to solve the technical problem that traditional data storage and use methods easily cause the storage-side service platform to infringe upon and leak the client data served by it.

[0010] In a first aspect, an embodiment of the present application provides a method for zero-knowledge protection of data, which is applied to a first server and includes: obtaining client data sent by a second server, the client data including target deterministic data and / or target non-deterministic data, the target deterministic data being optional data pre-configured for one or more fixed entries, the target non-deterministic data being data other than the target deterministic data, and the target non-deterministic data including data freely input by a user on a fixed entry of an electronic device; if the client data includes target deterministic data, converting the target deterministic data into first form data, and sending the first form data to the second server for storage, the first form data being zero-knowledge data; if the client data includes target non-deterministic data, mapping the target non-deterministic data into second form data, and sending the second form data to the second server for storage, the second form data being zero-knowledge data.

[0011] Optionally, mapping the target non-deterministic data to second-format data includes: acquiring a mapping table, the mapping table being used to record format data corresponding to each non-deterministic data; and adding second-format data corresponding to the target non-deterministic data to the mapping table.

[0012] Optionally, adding second form data corresponding to the target non-deterministic data to the mapping table includes: determining whether the mapping table has pre-stored target associated data corresponding to the target non-deterministic data; if so, determining that the form data corresponding to the target non-deterministic data is the second form data; if not pre-stored, generating second form data corresponding to the target non-deterministic data and target associated data corresponding to the target non-deterministic data, associating the target associated data with the second form data and saving them in the mapping table.

[0013] Optionally, the target associated data is the target non-deterministic data; or, the target associated data is a target hash digest obtained by performing a hash operation on the target non-deterministic data, and the target hash digest is used to point to the target non-deterministic data, and the target non-deterministic data is stored on the first server or the second server.

[0014] Optionally, the generating of target associated data corresponding to the target non-deterministic data includes: determining whether the target non-deterministic data meets a preset lightweight storage condition; if not, directly using the target non-deterministic data as target associated data; if compliant, performing a data lightweight processing operation on the target non-deterministic data to obtain target associated data, wherein the target associated data is used to point to the target non-deterministic data, and the target non-deterministic data is stored on the first server or the second server.

[0015] Optionally, performing a data lightweight processing operation on the target non-deterministic data to obtain target associated data includes: performing a hash operation on the target non-deterministic data to obtain a target hash summary; and using the target hash summary as the target associated data.

[0016] Optionally, the constituent elements of the preset lightweight storage conditions include: the non-deterministic data is binary file data, or the data volume of the non-deterministic data is greater than a predetermined data volume threshold, or the non-deterministic data is designated sensitive data; the determination of whether the target non-deterministic data meets the preset lightweight storage conditions includes: determining whether the target non-deterministic data is binary file data; or, determining whether the data volume of the target non-deterministic data is greater than a predetermined data volume threshold; or, determining whether the target non-deterministic data is designated sensitive data.

[0017] In a second aspect, an embodiment of the present application provides a method for zero-knowledge protection of data, which is applied to a second server, comprising: obtaining a storage request sent by an electronic device, the storage request being used to request the second server to store client data, the client data comprising target deterministic data and target non-deterministic data, the target deterministic data being optional data pre-configured for one or more fixed entries, the target non-deterministic data being data other than the target deterministic data, the target non-deterministic data comprising data freely input by a user on a fixed entry of the electronic device; obtaining first form data corresponding to the target deterministic data, the first form data being zero-knowledge data; storing the first form data on the second server, the second server being used to communicate with the first server; sending the target non-deterministic data to the first server for storage, so that the first server maps the target non-deterministic data to second form data, the second form data being zero-knowledge data; and storing the second form data returned by the first server on the second server.

[0018] Optionally, the target deterministic data includes a target field corresponding to the fixed entry and first actual data under the target field, and obtaining the first form data corresponding to the target deterministic data includes: sending the target deterministic data to the first server, so that the first server converts the target deterministic data into first form data and returns the first form data corresponding to the target field; or, obtaining configuration information sent by the first server, and converting the first actual data of the target field into first form data based on the configuration information.

[0019] In a third aspect, an embodiment of the present application provides a method for zero-knowledge protection of data, which is applied to a second server, including: obtaining a query request sent by an electronic device, the query request carrying a data request identifier, the data request identifier including a deterministic type identifier and / or a non-deterministic type identifier, the deterministic type identifier is used to represent target deterministic data, the non-deterministic type identifier is used to represent target non-deterministic data, the target deterministic data is optional data pre-configured for one or more fixed entries, the target non-deterministic data is data other than the target deterministic data, the target non-deterministic data includes data freely entered by a user on a fixed entry of the electronic device, and the second server stores the target data related to the fixed entry. A first form data corresponding to the deterministic data and a second form data corresponding to the target non-deterministic data, wherein the first form data and the second form data are both zero-knowledge data, the second server is used to communicate with the first server, and the first server stores the target non-deterministic data and the target deterministic data; responding to the query request, determining the target form data corresponding to the data request identifier; sending a data access request to the first server so that the first server returns the target actual data corresponding to the target form data, wherein the target actual data is one or both of the target non-deterministic data and the target deterministic data; and sending the target actual data to the electronic device.

[0020] In a fourth aspect, an embodiment of the present application provides a server, comprising a memory and a processor, wherein the memory is connected to the processor, and the processor is used to execute one or more computer programs stored in the memory, and when the processor executes the one or more computer programs, the server implements the above-mentioned zero-knowledge protection method for data.

[0021] In a fifth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a processor, the processor executes the above-mentioned zero-knowledge protection method for data.

[0022] The embodiments of the present application can achieve the following technical effects: the embodiments of the present application use data in a predetermined form to isolate the direct acquisition of user data on the second server, thereby reliably protecting user data from malicious acquisition and leakage. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the description of the embodiments of the present application will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0024] Figure 1 A schematic diagram of the system architecture of a zero-knowledge protection system for data provided in an embodiment of the present application; Figure 2 A schematic diagram of an application APP provided in an embodiment of the present application providing a registration page for a user on an electronic device; Figure 3 The user A provided in the embodiment of the present application is Figure 2 The schematic diagram of the page after filling in the information on the registration page is shown; Figure 4 A schematic diagram of a registration page after form processing provided in an embodiment of the present application; Figure 5 A schematic diagram of storing target non-deterministic data provided in an embodiment of the present application; Figure 6 A flowchart of a method for zero-knowledge protection of data provided in an embodiment of the present application; Figure 7 A flowchart of a method for zero-knowledge protection of data provided by another embodiment of the present application; Figure 8 A flowchart of a method for zero-knowledge protection of data provided by yet another embodiment of the present application; Fig. 9 A schematic diagram of the structure of a server provided in an embodiment of the present application. DETAILED DESCRIPTION

[0025] In order to make the purpose, technical solutions and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not intended to limit the present application. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in the field without making creative work are within the scope of protection of the present application.

[0026] It should be noted that, if there is no conflict, the various features in the embodiments of the present application can be combined with each other, all within the scope of protection of the present application. In addition, although the functional module division is performed in the device schematic diagram and the logical order is shown in the flow chart, in some cases, the steps shown or described can be performed in a sequence different from the module division in the device or the flow chart. Furthermore, the words "first", "second", "third", etc. used in this application do not limit the data and execution order, but only distinguish the same items or similar items with basically the same functions and effects.

[0027] The following is an embodiment of the present application that provides a zero-knowledge protection system for data. Figure 1 The zero-knowledge protection system 100 for data includes an electronic device 11, a first server 12 and a second server 13. The electronic device 11 is communicatively connected to the second server 13, and the second server 13 is communicatively connected to the first server 12.

[0028] The electronic device 11 is installed with an application APP. After the user starts the application APP on the electronic device 11 and completes relevant operations on the interactive interface provided by the application APP, the application APP submits a storage request to the second server 13 through the electronic device 11. The storage request is used to request the second server 13 to store the client data. For example, the user needs to register the application APP, and the application APP provides the user with a registration page. After the user completes the filling of relevant information on the registration page, he clicks Submit, so that the application APP encapsulates the client data filled in by the user into a storage request and sends the storage request to the second server 13.

[0029] Client data is data generated by the application APP of the electronic device based on user operations. Client data includes target deterministic data and / or target non-deterministic data. Target deterministic data is optional data pre-configured with one or more fixed items. Target non-deterministic data is data other than target deterministic data. Target non-deterministic data includes data freely input by the user on the fixed items of the electronic device.

[0030] See also Figure 2 The application APP provides a registration page 20 for the user on the electronic device 11. The embodiment of the present application sets the following fixed items (ie, fields) on the registration page 20: user name 21, user nickname 22, user avatar 23, user password 24, nationality 25, mobile phone number 26, ethnicity 27, and gender 28.

[0031] Different users enter different names in the area corresponding to User Name 21. For example, User A enters "A" in the area corresponding to User Name 21, User B enters "B" in the area corresponding to User Name 21, and so on. Since data such as "A" and "B" are not pre-configured optional data, the data entered in the area corresponding to User Name 21 is non-deterministic data.

[0032] Different users enter different nicknames in the area corresponding to User Nickname 22. For example, User A enters "Super Soldier" in the area corresponding to User Nickname 22, User B enters "Laughing at Life" in the area corresponding to User Nickname 22, and so on. Thus, the data entered in the area corresponding to User Nickname 22 is non-deterministic data.

[0033] Different users enter different avatars in the area corresponding to User Avatar 23. For example, User A enters "Avatar of A" in the area corresponding to User Avatar 23, User B enters "Avatar of B" in the area corresponding to User Avatar 23, and so on. Thus, the data entered in the area corresponding to User Avatar 23 is non-deterministic data.

[0034] Different users enter different passwords in the area corresponding to User Password 24. For example, User A enters "123456" in the area corresponding to User Password 24, User B enters "987654" in the area corresponding to User Password 24, and so on. Thus, the data entered in the area corresponding to User Password 24 is non-deterministic data.

[0035] The area corresponding to Nationality 25 is pre-configured with multiple optional data. For example, when a user clicks the first drop-down button 251 in the area corresponding to Nationality 25, the first drop-down button 251 expands the following nationality options: China, South Korea, Japan, North Korea, etc. It can be understood that the present application embodiment pre-configures corresponding form data for each nationality option. For example, the form data for China is 1, the form data for South Korea is 2, the form data for Japan is 3, and so on.

[0036] Different users enter different avatars in the area corresponding to Mobile Phone Number 26. For example, User A enters "123......5142" in the area corresponding to User Avatar 23, User B enters "136......8945" in the area corresponding to Mobile Phone Number 26, and so on. Thus, the data entered in the area corresponding to Mobile Phone Number 26 is non-deterministic data.

[0037] The area corresponding to ethnic group 27 is pre-configured with multiple optional data. For example, when the user clicks the second drop-down button 271 in the area corresponding to ethnic group 27, the second drop-down button 271 expands the following ethnic group options: Han, Miao, Zhuang, Korean, etc. It can be understood that the embodiment of the present application configures corresponding form data for each ethnic group option in advance. For example, the form data of the Han is 1, the form data of the Miao is 2, the form data of the Zhuang is 3, and so on.

[0038] The area corresponding to gender 28 is pre-configured with multiple optional data. For example, when the user clicks the third drop-down button 281 in the area corresponding to gender 28, the third drop-down button 281 expands the following ethnic options: male and female. It can be understood that the embodiment of the present application configures corresponding form data for each gender option in advance. For example, the form data of male is 1, the form data of female is 2, and so on.

[0039] It can be seen that although the nationality selected by the user in the area corresponding to nationality 25 is uncertain, or the nationality selected in the area corresponding to ethnicity 27 is uncertain, or the gender selected in the area corresponding to gender 28 is uncertain, there are infinite choices for the data corresponding to user name 21, user nickname 22, user avatar 23 and mobile phone number 26 (because different users can give any name or any avatar or any mobile phone number), the data sets corresponding to nationality 25, ethnicity 27 and gender 28 are all certain. For example, the number of countries in the world is limited and certain, and the formal data of nationality contained in the data set corresponding to nationality 25 is also limited and certain. Therefore, the data input in the area corresponding to nationality 25 is deterministic data. Similarly, the number of ethnic groups in China is limited and certain, and the formal data of ethnic groups contained in the data set corresponding to ethnicity 27 is also limited and certain. Therefore, the area corresponding to ethnicity 27 can be designed as a selection component for deterministic data, and the data input is deterministic data. The number of genders is limited and definite, and the formal data of gender contained in the data set corresponding to gender 28 is also limited and definite. Therefore, the area corresponding to gender 28 can be designed as a selection component for deterministic data, and its input data is deterministic data.

[0040] The embodiment of the present application accurately classifies the data to be stored, dividing it into deterministic data and non-deterministic data. Deterministic data comes from one or more pre-configured optional data sets, and the value range of deterministic data is clear and limited. Non-deterministic data covers all data other than deterministic data, including data freely entered by users and other data whose possible values ​​are not pre-defined. This data classification method is the basis for the subsequent implementation of privacy protection and performance improvement.

[0041] The first server 12 is a server provided for application developers, and the second server 13 is a server provided for cloud service providers. It can be understood that the first server 12 can be regarded as a private server, and the second server 13 can be regarded as a public server.

[0042] The first server 12 obtains the client data sent by the second server. If the client data includes target deterministic data, it converts the target deterministic data into first-form data and sends the first-form data to the second server for storage. The first-form data is zero-knowledge data. If the client data includes target non-deterministic data, the first server 12 maps the target non-deterministic data to second-form data and sends the second-form data to the second server 13 for storage. The second-form data is zero-knowledge data. Zero-knowledge data refers to data that does not provide any useful information to others to discover or dig out the actual data corresponding to the form data.

[0043] The embodiments of the present application creatively use form data and related usage methods, which not only decouple the management scenario of the storage resources provided by cloud service providers and the independent operation scenario required by application developers, enabling them to get what they need from the mechanism without infringing on each other, but also open up the collaboration channel between privacy (the user data being served) and openness (seeking professional services from third-party service providers), making them no longer restrict each other and neglect one another. At the same time, it also provides a peer-to-peer mode interface and a standardized solution for the further integration of emerging technologies such as blockchain and artificial intelligence.

[0044] The second server 13 obtains the first-form data corresponding to the target deterministic data and / or the second-form data corresponding to the non-target deterministic data, and stores the first-form data and / or the second-form data on the second server. The second server 13 is configured with a relational database and stores the first-form data and / or the second-form data on the relational database.

[0045] The target deterministic data includes a target field corresponding to a fixed entry and first actual data under the target field. Please refer to Figure 3 , user A inputs the information as shown Figure 3 on the registration page of the application APP on the electronic device 11. Among them, for the target field of "user name" in the fixed entry, the first actual data under "user name" is "A". Similarly, for the target field of "user nickname" in the fixed entry, the first actual data under "user nickname" is "Super Soldier", and so on.

[0046] There are at least two ways to obtain the first-form data corresponding to the target deterministic data: ① Acquiring first form data corresponding to target deterministic data includes the following steps: sending the target deterministic data to a first server, so that the first server converts the target deterministic data into first form data and returns the first form data corresponding to the target field.

[0047] The first server 12 pre-stores configuration information, which is used to indicate the mapping relationship between the optional data of the target field and the form data. Please refer to Table 1: Table 1

[0048] As can be seen from Table 1, each target field has a mapping relationship between corresponding optional data and formal data. The embodiment of the present application can find out the formal data corresponding to the optional data based on the optional data of the target field. Specifically, the first server finds out the optional data corresponding to the target deterministic data under the target field of the configuration information as the target optional data, selects the formal data corresponding to the target optional data as the first formal data, and returns the first formal data to the second server for storage.

[0049] For example, the target deterministic data includes "nationality - Chinese", "ethnicity - Han", and "gender - male". The first server calls the configuration information, determines that the first form data of the target field corresponding to "nationality" is 0, the first form data of the target field corresponding to "ethnicity" is 0, and the first form data of the target field corresponding to "gender" is 0. The first server returns the first form data corresponding to the target field to the second server, that is, the first server returns "nationality - 0", "ethnicity - 0", and "gender - 0" to the second server.

[0050] The second server does not save configuration information locally, and the data of user A on the second server is formal data. Even if the administrator of the second server obtains the first form data of the user on the second server, he cannot discover or mine the actual data about the user through the first form data. Therefore, the embodiment of the present application can effectively prevent the administrator of the cloud service provider from obtaining any actual data about the user by reading the information stored on the second server.

[0051] ② Obtaining first form data corresponding to the target deterministic data includes the following steps: obtaining configuration information sent by the first server, and converting the first actual data of the target field into the first form data based on the configuration information.

[0052] The second server sends a configuration acquisition request to the first server, so that the first server responds to the configuration acquisition request and returns configuration information to the second server. The second server searches for optional data corresponding to the target deterministic data under the target field of the configuration information as target optional data, selects the form data corresponding to the target optional data as the first form data, and stores the first form data.

[0053] It is understandable that in this scenario, the process by which the second server converts the first actual data of the target field into the first form of data based on the configuration information is developed by the application developer, and the configuration information is not persisted to the hardware. Therefore, the administrator of the cloud service provider will not obtain the configuration information through the second server, and will not obtain any useful data about the user based on the configuration information.

[0054] For deterministic data, the embodiment of the present application pre-constructs configuration information and uses zero-knowledge first-form data to correspond to source data with practical meaning. In actual storage, the public server only saves the first-form data, while the source data and configuration information are stored on the private server, and the two servers are securely connected through the network. This storage method makes it impossible for the service provider of the public server to know the actual content of the data, and guarantees data privacy from a mechanism perspective. For example, in an e-commerce system, the category of goods (such as clothing, electronic products, etc.) can be used as deterministic data, and the mapping relationship from "clothing" to formal data "1", "electronic products" to formal data "2", etc. is pre-constructed. The public server only stores formal data such as "1" and "2", while the private server saves source data and configuration information such as "clothing" and "electronic products".

[0055] The second server sends the target non-deterministic data to the first server for storage, so that the first server maps the target non-deterministic data into second form data, the second form data being zero-knowledge data. The first server sends the second form data to the second server, and the second server stores the second form data.

[0056] The first server is configured with a NoSQL database, which stores the mapping between the formal data of the target non-deterministic data and the actual data. The NoSQL database provides an efficient mapping service for this scenario.

[0057] For the first server, the first server obtains the client data sent by the second server, and the client data includes target deterministic data and / or target non-deterministic data. The target deterministic data is optional data pre-configured for one or more fixed items, and the target non-deterministic data is data excluding the target deterministic data, including data freely input by the user on the fixed items of the electronic device. If the client data includes target deterministic data, the first server converts the target deterministic data into first form data, and sends the first form data to the second server for storage, and the first form data is zero-knowledge data. If the client data includes target non-deterministic data, the first server maps the target non-deterministic data into second form data, and sends the second form data to the second server for storage, and the second form data is zero-knowledge data.

[0058] The first server maps the target non-deterministic data to the second form data, including the following steps: the first server obtains a mapping table, the mapping table is used to record the form data corresponding to each non-deterministic data, and adds the second form data corresponding to the target non-deterministic data to the mapping table.

[0059] For non-deterministic data, given the unpredictability of its values, a mapping table is first built on a private server before storage, using zero-knowledge second-form data to correspond to the source data, and then only the newly generated second-form data is stored in the public server. To avoid repeated construction of mappings, before building the mapping table, it will be checked whether there is a mapping relationship for the same source data. If it does exist, the existing second-form data will be used directly. For example, in free input scenarios such as user comments, if two users enter the same comment content, the system will reuse the generated second-form data to reduce redundant storage.

[0060] The first server obtains existing form data in the mapping table, generates new form data based on the existing form data, the new form data is different from all the existing form data, and uses the new form data as the second form data.

[0061] Generating new form data based on existing form data includes the following steps: the first server determines the maximum arrangement number corresponding to the last non-deterministic data arranged in sequence in the mapping table, adds the natural number 1 to the maximum arrangement number to obtain a new maximum arrangement number, and uses the new maximum arrangement number as the new form data.

[0062] For example, see Table 2, which is as follows: Table 2

[0063] As can be seen from Table 2, in the current mapping table, the maximum arrangement number corresponding to the non-deterministic data arranged at the end is "3". It can be understood that for the first actual data, its second form data is "0". Similarly, for the second actual data, its second form data is "1". For the third actual data, its second form data is "2". For the fourth actual data, its second form data is "3".

[0064] In order to add the target non-deterministic data of user A to the mapping table, and to allocate the second form data to the target non-deterministic data, the embodiment of the present application adds the natural number 1 to the maximum arrangement sequence number to obtain a new maximum arrangement sequence number "4", and uses the new maximum arrangement sequence number "4" as the second form data, and updates the mapping table, as shown in Table 3: Table 3

[0065] The first server sends the second form data "4" obtained from Table 3 to the second server. So far, the second server has obtained the registration information of user A. Figure 4 , the second form data of user name 21, user nickname 22, user avatar 23, user password 24 and mobile phone number 26 are all "4", the first form data of nationality 25 is 0, the first form data of ethnicity 27 is 0, and the first form data of gender 28 is 0. The second server is the server of the cloud service provider, and the administrator of the cloud service provider or others can Figure 4 The registration information shown does not discover or mine any useful or meaningful information about User A, thus achieving zero-knowledge protection of the data.

[0066] In some embodiments, adding second form data corresponding to the target non-deterministic data to the mapping table includes the following steps: determining whether the mapping table has pre-stored target associated data corresponding to the target non-deterministic data; if so, determining that the form data corresponding to the target non-deterministic data is the second form data; if not, generating the second form data corresponding to the target non-deterministic data and the target associated data corresponding to the target non-deterministic data, associating the target associated data with the second form data and saving them in the mapping table.

[0067] In some embodiments, the target associated data is target non-deterministic data, and determining whether the mapping table has pre-stored target associated data corresponding to the target non-deterministic data includes the following steps: traversing the mapping table to determine whether the target non-deterministic data exists.

[0068] As shown in Table 3, if user A performs a secondary registration, before the target non-deterministic data needs to be assigned the second form of data, the first server can directly traverse Table 3 to see whether there is target non-deterministic data about user A. Since the target associated data is the target non-deterministic data, this process is actually equivalent to traversing the mapping table to see whether there is target associated data corresponding to the target non-deterministic data. Obviously, the non-deterministic data corresponding to the sequence number "4" in Table 3 is the target non-deterministic data about user A. The first server can return the non-deterministic data corresponding to the sequence number "4" as the target non-deterministic data of user A to the second server.

[0069] In other embodiments, the target associated data is a target hash digest obtained by performing a hash operation on the target non-deterministic data, and the target hash digest is used to point to the target non-deterministic data.

[0070] Determining whether the mapping table has pre-stored target associated data corresponding to the target non-deterministic data includes the following steps: performing hash operation processing on the target non-deterministic data to obtain a reference hash summary, and traversing the mapping table to see whether there is a hash summary corresponding to the reference hash summary.

[0071] See Table 4: Table 4

[0072] As can be seen from Table 4, the target non-deterministic data "{(user name: A)" about user A is hashed to obtain a reference hash digest, and the mapping table is traversed to see if there is a hash digest corresponding to the reference hash digest. Obviously, Table 4 shows that there is a hash digest corresponding to the reference hash digest, that is, the mapping table has pre-stored target associated data corresponding to the target non-deterministic data.

[0073] The data form of non-deterministic data can be a string, file data, image data, voice data, video data, etc. Generally, if the file data, image data, voice data, and video data have a large amount of data, if such data is directly written into the mapping table, it is easy to cause the data amount of the mapping table to be too large, which does not conform to the simplified expression form of the mapping table. Therefore, in the case where the data amount of non-deterministic data is large, the embodiment of the present application can maintain the simplified expression of the mapping table, so that the mapping table does not carry too much data, and can also reliably and effectively store the non-deterministic data, so as to facilitate subsequent inquiries, and can completely and reliably return the non-deterministic data to the electronic device or the second server.

[0074] In some embodiments, generating target-associated data corresponding to target non-deterministic data includes the following steps: determining whether the target non-deterministic data meets preset lightweight storage conditions; if not, directly using the target non-deterministic data as target-associated data; if compliant, performing data lightweight processing operations on the target non-deterministic data to obtain target-associated data; the target-associated data is used to point to the target non-deterministic data; and the target non-deterministic data is stored on the first server or the second server.

[0075] The constituent elements of the preset lightweight storage conditions include: the non-deterministic data is binary file data, or the data volume of the non-deterministic data is greater than a predetermined data volume threshold, or the non-deterministic data is designated sensitive data. Correspondingly, judging whether the target non-deterministic data meets the preset lightweight storage conditions includes the following steps: judging whether the target non-deterministic data is binary file data, or judging whether the data volume of the target non-deterministic data is greater than a predetermined data volume threshold, or judging whether the target non-deterministic data is designated sensitive data.

[0076] Compared with the non-deterministic data with a smaller data volume recorded in the mapping table, the data volume of binary file data is usually larger. If the target non-deterministic data is binary file data, it means that the data volume of the target non-deterministic data is large and it is inconvenient to store it in the mapping table. If the target non-deterministic data is not binary file data, but the data volume of the target non-deterministic data is greater than the predetermined data volume threshold, the target non-deterministic data is also inconvenient to store in the mapping table. The preset data volume threshold is customized by the designer based on engineering experience. If the target non-deterministic data is designated sensitive data, in order to improve confidentiality, the target non-deterministic data is also inconvenient to store in the mapping table, but it can be stored in other locations.

[0077] If the target non-deterministic data does not meet the preset lightweight storage conditions, it means that there is no need to perform any processing on the target non-deterministic data, and the target non-deterministic data can be directly written into the mapping table as target associated data.

[0078] If the target non-deterministic data meets the preset lightweight storage conditions, it means that it is necessary to perform a data lightweight processing operation on the target non-deterministic data to obtain the target associated data, and the target non-deterministic data will not be written to the mapping table at this time. The embodiment of the present application adopts this approach to reduce the amount of data in the mapping table and reduce the data storage load of the mapping table.

[0079] In some embodiments, performing a data lightweight processing operation on the target non-deterministic data to obtain target associated data includes the following steps: performing a hash operation on the target non-deterministic data to obtain a target hash summary, and using the target hash summary as the target associated data.

[0080] In some embodiments, the target non-deterministic data is recorded in a designated file, and the storage location of the designated file may be on the first server or the second server. It is understandable that when the designated file is stored on the first server, since the first server is a private server, others will not obtain the target non-deterministic data, thereby achieving confidentiality. It is also understandable that when the designated file is stored on the second server, although the second server is a shared server, the designated file lacks effective information constraints on the second server. For example, the second server does not save user information or other useful information of the designated file. The administrator of the second server or others lacks the guidance of user information or other useful information and it is difficult to obtain the designated file from the second server. Therefore, relatively speaking, storing the designated file on the second server will not make the designated file easy to obtain, and when the storage load of the first server is too large, storing the designated file on the second server can effectively alleviate the storage pressure of the first server.

[0081] The target hash digest is used as the file name of the specified file, and the file name of the specified file is the suffix path for storing the specified file.

[0082] See also Figure 5 , the target non-deterministic data is the video clip 51. The first server allocates the second form data "5" to the video clip 51 according to the above method. Since the data volume of the video clip 51 is large, the first server performs a hash operation on the video clip 51 to obtain the target hash digest "61248......6978". The embodiment of the present application configures a prefix path for the specified file. The prefix path is the path of the target folder where the specified file is stored. For example, the path of the target folder is E:\98djUj29s\.

[0083] like Figure 5 As shown, the designated file is a video clip 51, and the video clip 51 is stored in a target folder 52. When the electronic device or the second server needs to obtain the video clip 51, the first server combines the prefix path with the file name "61248......6978" of the video clip 51 to form a file acquisition path: E:\98djUj29s\61248......6978, and obtains the video clip 51 based on the file acquisition path.

[0084] It can be understood that, relative to the data volume of the target non-deterministic data, the data volume of the target hash summary is much smaller than the data volume of the target non-deterministic data. The embodiment of the present application stores the target hash summary as target associated data directly on the mapping table, which can greatly reduce the data storage load of the mapping table.

[0085] In addition, the embodiment of the present application directly performs a hash operation on the target non-deterministic data, and the probability of duplication between the obtained target hash digest and the hash digests obtained from other non-deterministic data is very low, that is, the probability of hash collision is very low, which is beneficial to improving the uniqueness of the hash digest of the target non-deterministic data, and when the non-deterministic data is subsequently queried, since the probability of the existence of two identical hash digests is very low, the first server will not return erroneous non-deterministic data to the electronic device or the second server.

[0086] Finally, if the relevant technology determines the target-associated data corresponding to the target non-deterministic data with different parameters, such as generating the target-associated data corresponding to the target non-deterministic data based on the timestamp or other variables of the target non-deterministic data, then this approach is prone to the following problems: the same target non-deterministic data is easily processed into different target-associated data, and the different target-associated data are stored in the mapping table, which easily increases the storage load of the mapping table but does not produce additional benefits.

[0087] The first server uses a standardized hash algorithm to perform hash operations on the target non-deterministic data. Any target non-deterministic data is processed using a standardized hash algorithm. Since the target non-deterministic data is certain and unique, the target associated data (i.e., the target hash summary) corresponding to the target non-deterministic data is also unique, so multiple hash summaries describing the same target non-deterministic data will not be stored in the mapping table. This approach has the effect of improving the uniformity of the system, which is of great significance, especially in large systems such as blockchain.

[0088] In general, in order to optimize the storage resource utilization of private servers, the embodiments of the present application propose that for some source data (i.e., target non-deterministic data) that meet the preset lightweight storage conditions, lightweight processing is first performed to form target-related data with pointer properties, and the target-related data is stored in the mapping table of the private server. At this time, if the target non-deterministic data or the specified file containing the target non-deterministic data is stored on the public server, it is not stored in the same orderly management area as the database, but is designed to be stored in a specific area separated from the database and stored in a confused mode. In this area, all data of all users are mixed and placed in a "big warehouse" without any identification measures such as labels, classifications or partitions. The only mapping relationship that can identify these data exists only on the private server. In this way, even if the operator of the public server obtains these source data, due to the lack of effective identification information, the actual meaning of the data cannot be known.

[0089] It should be emphasized here that the scope of privacy includes not only the specific content of information, but also the ownership of information and the relevance of information. For example, even if a public server operator sees a certain headshot picture, the value of the picture is extremely limited because it is impossible to know who it belongs to. In addition, the application developer has the ability to encrypt and lock the entire area where the source data is stored, further enhancing the privacy protection of the data. In this way, while making full use of the public server storage resources, data privacy is guaranteed to the greatest extent.

[0090] In some embodiments, the zero-knowledge protection method also includes the following steps: obtaining a non-deterministic data access request sent by the second server, the non-deterministic data access request includes second form data, which is used to request the first server to return specified non-deterministic data corresponding to the second form data to the second server, responding to the non-deterministic data access request, extracting specified associated data corresponding to the second form data from a mapping table, and determining whether the specified associated data has undergone a data lightweight processing operation. If not, directly returning the specified associated data to the second server as specified non-deterministic data; if it has, extracting the specified associated data corresponding to the second form data from the mapping table, using the specified associated data as a suffix path, obtaining a preset prefix path, combining the prefix path and the suffix path to form a file acquisition path, obtaining the specified non-deterministic data based on the file acquisition path, and returning the specified non-deterministic data to the second server.

[0091] In the data query stage, the embodiment of the present application provides an efficient process. First, the second form of data is queried from the public server, and then the corresponding source data is queried from the private server. If the source data is pointer-type source data, the source data is further queried according to the corresponding rules and finally returned to the user. This query process not only ensures data privacy, but also effectively improves the read and write and comprehensive operation efficiency of the database through reasonable data storage and processing methods.

[0092] In general, the embodiments of the present application isolate the direct acquisition of user data on the second server using data in a predetermined format, thereby reliably protecting user data from malicious acquisition and leakage.

[0093] The above embodiments are about the method of converting the target deterministic data and the target non-deterministic data into the first form data and the second form data respectively and the method of saving the target deterministic data and the target non-deterministic data. Hereinafter, the embodiment of the present application further introduces the method of the electronic device or the second server querying the target deterministic data and the target non-deterministic data, which is as follows: The second server obtains a query request sent by the electronic device, and the query request carries a data request identifier. The data request identifier includes a deterministic type identifier and / or a non-deterministic type identifier. The deterministic type identifier is used to represent the target deterministic data, and the non-deterministic type identifier is used to represent the target non-deterministic data. The second server saves the first form data corresponding to the target deterministic data and the second form data corresponding to the target non-deterministic data, and the first server saves the target non-deterministic data and the target deterministic data.

[0094] The second server responds to the query request and determines the target form data corresponding to the data request identifier. For example, if the data request identifier is a deterministic type identifier, the target form data is the first form data, if the data request identifier is an indeterminate type identifier, the target form data is the second form data, and if the data request identifier includes a deterministic type identifier and an indeterminate type identifier, the target form data includes the first form data and the second form data.

[0095] The second server sends a data access request to the first server, so that the first server returns target actual data corresponding to the target form data, and the target actual data is one or both of the target non-deterministic data and the target deterministic data. For example, when the target form data is the first form data, the target actual data is the target deterministic data, when the target form data is the second form data, the target actual data is the target non-deterministic data, and when the target form data includes the first form data and the second form data, the target actual data includes the target deterministic data and the target non-deterministic data.

[0096] The second server sends the target actual data to the electronic device.

[0097] In order to elaborate on the zero-knowledge protection method for data provided by the embodiment of the present application, the embodiment of the present application provides the following application scenarios to explain this in detail, as follows: ①Data classification module: When the system starts, the data classification module is initialized. When new client data enters the storage process, the module will first determine the data type of the client data. If the client data includes deterministic data, the system will match it according to the pre-configured optional data set. For example, in a school management system, the gender (male / female) of the student is deterministic data, and the system identifies such deterministic data through the preset gender data set. If the client data includes non-deterministic data, such as free input content such as the student's self-description, the system will classify it as non-deterministic data.

[0098] ②Deterministic data processing module: 2.1 Mapping construction: For deterministic data, the system will build a mapping relationship on a private server. For example, in an e-commerce system, the brand of a product is used as deterministic data. Assuming there are brands "A", "B", and "C", the system will generate first-form data "101", "102", and "103" for them respectively, and record the corresponding relationship between the brand and the first-form data in the configuration file.

[0099] 2.2 Storage process: After the mapping is built, the first form of data will be transmitted and stored in the public database, while the source data and configuration files are stored in the private server. For example, in the above e-commerce system, the public server only records data in the form of "101", "102", "103", etc., while the private server saves the brand information of "A", "B", "C" and the corresponding configuration files.

[0100] ③Non-deterministic data processing module: 3.1 Mapping detection and construction: When non-deterministic data enters the system, the private server will first detect whether there is the same source data. Taking the dynamics posted by users on social platforms as an example, if two users post dynamics with the same content, the system will directly reuse the existing form data. If there is no identical data, a new mapping record will be constructed to generate the corresponding second form data.

[0101] 3.2 Storage operation: After the second form of data is generated, it is also stored in the public server, and the source data is stored in the private server, waiting for possible subsequent lightweight processing.

[0102] 3.3 Lightweight processing module: For some source data that meet the lightweight conditions (such as large-size images, long texts, etc.), the system will perform lightweight processing on a private server. Taking a high-definition image as an example, the system will convert it into low-resolution pointer data with specific identifiers (i.e. target-related data), and store the original high-definition image in a specific obfuscation area separated from the public server and database. On the private server, the corresponding rule information between the pointer data and the original high-definition image will be retained.

[0103] ④Data query module: 4.1 Preliminary query: When receiving a query request, the system first queries the public server for the corresponding form data. For example, when querying the brand information of an e-commerce product, first obtain the form data such as "101" and "102" from the public server.

[0104] 4.2 Deep query: According to the type of form data, the system initiates a request to the private server to obtain the corresponding source data. If the source data is pointer data, such as the above-mentioned image pointer data, the private server will find the original high-definition image from the obfuscation area of ​​the public server according to the corresponding rules, and integrate it with other source data and return it to the user.

[0105] ⑤Encryption and security module: Application developers can use mature encryption algorithms (such as AES encryption algorithm) to encrypt specific obfuscated areas on public servers that store source data. At the same time, strict access control is set up so that only authorized query requests can obtain relevant data, further ensuring data privacy and security.

[0106] To sum up, the embodiments of the present application improve the privacy protection capability of database stored data from a mechanism perspective through data classification processing, innovative storage methods and optimized query processes, while also improving the database's read and write efficiency and overall operational efficiency, effectively solving the pain points of the prior art.

[0107] The database privacy protection and performance improvement method proposed in the embodiment of the present application shows significant beneficial effects in many aspects, as follows: ①Privacy protection level: 1.1 Zero-knowledge storage: By dividing data into deterministic and non-deterministic data and using zero-knowledge formal data storage, the public server only holds formal data without actual meaning and is completely unaware of the real data content. For example, in the medical data storage scenario, the patient's diagnosis results are stored in the public database as formal data. Even if the public server operator obtains the data, it cannot obtain any valuable medical information from it, which greatly protects the patient's privacy.

[0108] 1.2 All-round privacy protection: Not only does it protect the data content, but it also provides strong protection for data ownership and relevance. For example, the original source data is stored in a specific area of ​​the public server in an obfuscated mode, and the unique identification mapping is stored on a private server, so that the public server cannot know the user to whom the data belongs and the relationship between the data. Just like the pictures posted by users on social platforms, even if they are obtained by public servers, these pictures have no actual value because they do not know the user to whom the pictures belong and the relationship with other users' data. At the same time, the application developer encrypts and locks this area, further strengthening privacy protection. Even if the data is accidentally leaked, it cannot be decrypted and viewed without authorization.

[0109] ②Performance improvement level: 2.1 Improved storage efficiency: Formal data uses a unified integer data type with the smallest storage space, which reduces the space required for data storage. Taking the large amount of commodity category data in the e-commerce system as an example, using formal data to store data greatly saves storage space and improves storage efficiency compared to raw text storage. At the same time, this uniformity and simplification reduces the cost of data differentiation and processing. Different data does not need to adapt to complex and diverse storage formats, which reduces the conversion and sorting work during the storage process.

[0110] 2.2 Enhanced operational performance: In terms of read and write operations, the database read and write speed has been improved due to the optimization of data storage methods. For example, in query operations, the formal data is first quickly obtained from the public database, and then the source data is obtained from the private server based on the mapping. The process is clear and concise, which reduces the query time. In addition, the uniformity of formal data improves parallel processing capabilities. Multiple query requests can process different forms of data at the same time without interfering with each other, improving overall operational efficiency. In terms of atomic operations, the performance of atomic operations has been enhanced due to the simplification of data formats, and data processing is more efficient and accurate.

[0111] In summary, the embodiments of the present application, through innovative data processing and storage mechanisms, effectively protect data privacy while significantly improving the read and write performance and overall operation performance of the database, providing strong technical support for various scenarios that rely on database storage and management of data.

[0112] As another aspect of the embodiment of the present application, the embodiment of the present application provides a zero-knowledge protection method for data, which is applied to the first server. Figure 6 ,The zero-knowledge protection method of data includes the following steps: S61, acquiring client data sent by the second server, where the client data includes target deterministic data and / or target non-deterministic data.

[0113] S62: If the client data includes target deterministic data, convert the target deterministic data into first-format data, and send the first-format data to the second server for storage, where the first-format data is zero-knowledge data.

[0114] S63: If the client data includes target non-deterministic data, map the target non-deterministic data into second-format data, and send the second-format data to the second server for storage, where the second-format data is zero-knowledge data.

[0115] The embodiment of the present application isolates the direct acquisition of user data on the second server using data in a predetermined format, thereby reliably protecting the user data from malicious acquisition and leakage.

[0116] In some embodiments, mapping the target non-deterministic data to second form data includes: obtaining a mapping table, the mapping table is used to record the form data corresponding to each non-deterministic data, and adding the second form data corresponding to the target non-deterministic data to the mapping table.

[0117] In some embodiments, adding second form data corresponding to the target non-deterministic data to the mapping table includes: determining whether the mapping table has pre-stored target associated data corresponding to the target non-deterministic data; if so, determining that the form data corresponding to the target non-deterministic data is the second form data; if not pre-stored, generating the second form data corresponding to the target non-deterministic data and the target associated data corresponding to the target non-deterministic data, associating the target associated data with the second form data and saving them in the mapping table.

[0118] In some embodiments, the target associated data is target non-deterministic data; or, the target associated data is a target hash digest obtained by performing a hash operation on the target non-deterministic data, the target hash digest is used to point to the target non-deterministic data, and the target non-deterministic data is stored on the first server or the second server.

[0119] In some embodiments, target-associated data corresponding to target non-deterministic data is generated, including: determining whether the target non-deterministic data meets preset lightweight storage conditions; if not, directly using the target non-deterministic data as target-associated data; if compliant, performing data lightweight processing operations on the target non-deterministic data to obtain target-associated data, the target-associated data is used to point to the target non-deterministic data, and the target non-deterministic data is stored on the first server or the second server.

[0120] In some embodiments, a data lightweight processing operation is performed on the target non-deterministic data to obtain target associated data, including: performing a hash operation on the target non-deterministic data to obtain a target hash summary; and using the target hash summary as the target associated data.

[0121] In some embodiments, constituent elements of the preset lightweight storage conditions include: the non-deterministic data is binary file data, or the data volume of the non-deterministic data is greater than a predetermined data volume threshold, or the non-deterministic data is designated sensitive data; determining whether the target non-deterministic data meets the preset lightweight storage conditions includes: determining whether the target non-deterministic data is binary file data; or, determining whether the data volume of the target non-deterministic data is greater than a predetermined data volume threshold; or, determining whether the target non-deterministic data is designated sensitive data.

[0122] As another aspect of the embodiment of the present application, the embodiment of the present application provides a zero-knowledge protection method for data, which is applied to the second server. Figure 7,The zero-knowledge protection method of data includes the following steps: S71, obtaining a storage request sent by the electronic device, where the storage request is used to request the second server to store client data.

[0123] S72, obtaining first form data corresponding to the target deterministic data, where the first form data is zero-knowledge data; S73, storing the first format data on a second server, where the second server is used to communicate with the first server; S74, sending the target non-deterministic data to the first server for storage, so that the first server maps the target non-deterministic data into second-form data, where the second-form data is zero-knowledge data; S75: Store the second format data returned by the first server on the second server.

[0124] In some embodiments, the target deterministic data includes a target field corresponding to a fixed entry and first actual data under the target field, and obtaining the first form data corresponding to the target deterministic data includes: sending the target deterministic data to a first server so that the first server converts the target deterministic data into first form data and returns the first form data corresponding to the target field; or, obtaining configuration information sent by the first server, and converting the first actual data of the target field into first form data based on the configuration information.

[0125] As another aspect of the embodiment of the present application, the embodiment of the present application provides a zero-knowledge protection method for data, which is applied to the second server. Figure 8 ,The zero-knowledge protection method of data includes the following steps: S81, obtaining a query request sent by an electronic device; S82, responding to the query request, determining target form data corresponding to the data request identifier; S83, sending a data access request to the first server, so that the first server returns target actual data corresponding to the target form data, where the target actual data is one or both of target non-deterministic data and target deterministic data; S84, sending the target actual data to the electronic device.

[0126] The query request carries a data request identifier, which includes a deterministic type identifier and / or a non-deterministic type identifier. The deterministic type identifier is used to represent target deterministic data, and the non-deterministic type identifier is used to represent target non-deterministic data. The target deterministic data is optional data pre-configured for one or more fixed entries. The target non-deterministic data is data other than the target deterministic data. The target non-deterministic data includes data freely input by a user on a fixed entry of an electronic device. The second server stores first form data corresponding to the target deterministic data and second form data corresponding to the target non-deterministic data. Both the first form data and the second form data are zero-knowledge data. The second server is used to communicate with the first server, and the first server stores the target non-deterministic data and the target deterministic data.

[0127] In general, the embodiments of the present application can at least achieve the following technical effects: 1. It is difficult for cloud service providers to obtain meaningful information from the second server they provide. The first form of data and the second form of data in the database of the second server are in a zero-knowledge state (difficult to guess information about the actual data). When the system is running, the data with actual meaning will be directly generated and used by the application, which protects the privacy of application developers and their user data. At the same time, the performance of the second server will be significantly improved.

[0128] 2. Improve efficiency in many aspects: Since the storage format of formal data is extremely simplified and unified, the database space storage efficiency, reading and writing speed, parallel operation and even code integration optimization capabilities are greatly improved.

[0129] 3. Security: Zero knowledge of server hardware storage prevents server providers and their related malicious environments from obtaining and using user information unnecessarily.

[0130] 4. Decoupling: Sensitive information is decoupled to the application end, facilitating cross-Internet information cooperation and further improving system integration and upgrade capabilities.

[0131] 5. It can be used as a basic technical means for data protection and sharing in future data space architecture.

[0132] It should be noted that, in each of the above-mentioned embodiments, there is not necessarily a certain order between the above-mentioned steps. A person skilled in the art can understand, based on the description of the embodiments of the present application, that in different embodiments, the above-mentioned steps may have different execution orders, that is, they may be executed in parallel, may be executed interchangeably, and so on.

[0133] See also Fig. 9 , Fig. 9Schematic diagram of the structure of a server provided in an embodiment of the present application. The server may be a first server or a second server. Fig. 9 As shown, the server 900 includes one or more processors 91 and a memory 92. The memory 92 is connected to the one or more processors 91, for example, via a bus.

[0134] The processor 91 is configured to support the server to execute the corresponding functions of the method in the above method embodiment. The processor can be a central processing unit (CPU), a network processor (NP), a hardware chip or any combination thereof. The above hardware chip can be an application specific integrated circuit (ASIC), a programmable logic device (PLD) or a combination thereof. The above PLD can be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL) or any combination thereof.

[0135] The memory 92 is used to store program codes, etc. The memory may include a volatile memory (VM), such as a random access memory (RAM); the memory may also include a non-volatile memory (NVM), such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD) or a solid-state drive (SSD); the memory may also include a combination of the above types of memory.

[0136] The memory 92 may be used to store non-volatile software programs, non-volatile computer executable programs and modules, such as program instructions / modules corresponding to the zero-knowledge protection method for data in the embodiment of the present application. The processor executes the various functional applications and data processing of the zero-knowledge protection method for data and the zero-knowledge protection device for data by running the non-volatile software programs, instructions and modules stored in the memory, that is, to realize the functions of each module or unit of the zero-knowledge protection method for data and the zero-knowledge protection device for data provided in the above method embodiment.

[0137] The memory may include a program storage area and a data storage area, wherein the program storage area may store an operating system and an application required for at least one function. The data storage area may store data created based on the use of the zero-knowledge protection device for data, etc. In some embodiments, the memory may optionally include a memory remotely arranged relative to the processor, and these remote memories may be connected to the zero-knowledge protection device for data via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0138] The one or more modules are stored in the memory, and when executed by the one or more processors, execute the zero-knowledge protection method for data in any of the above method embodiments, for example, execute the method steps described in the above method embodiments to realize the functions of the modules described in the above device embodiments.

[0139] An embodiment of the present application further provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a server, the server executes the method as described in the above embodiment.

[0140] A person skilled in the art can understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program, and the program can be stored in a computer-readable storage medium, and when the program is executed, it can include the processes of the embodiments of the above-mentioned methods. The storage medium can be a disk, an optical disk, a read-only memory (ROM) or a random access memory (RAM), etc.

[0141] The above disclosure is only the preferred embodiment of the present application, which certainly cannot be used to limit the scope of rights of the present application. Therefore, equivalent changes made according to the claims of the present application are still within the scope covered by the present application.

Claims

1. A zero-knowledge protection method for data, applied to a first server, characterized in that: include: Acquire client data sent by the second server, the client data including target deterministic data and / or target non-deterministic data, the target deterministic data being optional data pre-configured for one or more fixed items, the target non-deterministic data being data other than the target deterministic data, the target non-deterministic data including data freely input by a user on a fixed item of the electronic device; If the client data includes target deterministic data, converting the target deterministic data into first form data, and sending the first form data to the second server for storage, the first form data being zero-knowledge data; If the client data includes target non-deterministic data, the target non-deterministic data is mapped to second-form data, and the second-form data is sent to the second server for storage, where the second-form data is zero-knowledge data.

2. The zero-knowledge protection method according to claim 1, characterized in that: Mapping the target non-deterministic data into second-format data includes: Obtaining a mapping table, wherein the mapping table is used to record the form data corresponding to each non-deterministic data; Second form data corresponding to the target non-deterministic data is added to the mapping table.

3. The zero-knowledge protection method according to claim 2, characterized in that: The adding of the second form data corresponding to the target non-deterministic data in the mapping table includes: Determining whether the mapping table has pre-stored target associated data corresponding to the target non-deterministic data; If it has been pre-stored, determining that the form data corresponding to the target non-deterministic data is the second form data; If not pre-stored, second form data corresponding to the target non-deterministic data and target associated data corresponding to the target non-deterministic data are generated, and the target associated data is associated with the second form data and stored in the mapping table.

4. The zero-knowledge protection method according to claim 3, characterized in that: The target-related data is the target non-deterministic data; or, The target associated data is a target hash digest obtained by performing a hash operation on the target non-deterministic data, and the target hash digest is used to point to the target non-deterministic data. The target non-deterministic data is stored on the first server or the second server.

5. The zero-knowledge protection method according to claim 3, characterized in that: The generating target associated data corresponding to the target non-deterministic data includes: Determining whether the target non-deterministic data meets the preset lightweight storage conditions; If not, the target non-deterministic data is directly used as the target associated data; If it is in compliance, a data lightweight processing operation is performed on the target non-deterministic data to obtain target associated data, where the target associated data is used to point to the target non-deterministic data, and the target non-deterministic data is stored on the first server or the second server.

6. The zero-knowledge protection method according to claim 5, characterized in that: The performing a data lightweight processing operation on the target non-deterministic data to obtain target associated data includes: Performing hash operation processing on the target non-deterministic data to obtain a target hash summary; The target hash digest is used as target associated data.

7. The zero-knowledge protection method according to claim 5, characterized in that: The constituent elements of the preset lightweight storage conditions include: the non-deterministic data is binary file data, or the data volume of the non-deterministic data is greater than a predetermined data volume threshold, or the non-deterministic data is designated sensitive data; The determining whether the target non-deterministic data meets the preset lightweight storage condition includes: Determine whether the target non-deterministic data is binary file data; or, Determine whether the amount of the target non-deterministic data is greater than a predetermined data amount threshold; or, Determine whether the target non-deterministic data is designated sensitive data.

8. A zero-knowledge protection method for data, applied to a second server, characterized in that: include: Acquire a storage request sent by the electronic device, the storage request being used to request the second server to store client data, the client data comprising target deterministic data and target non-deterministic data, the target deterministic data being optional data pre-configured for one or more fixed items, the target non-deterministic data being data other than the target deterministic data, the target non-deterministic data comprising data freely input by a user on a fixed item of the electronic device; Acquire first form data corresponding to the target deterministic data, the first form data being zero-knowledge data; storing the first form of data on the second server, the second server being used for communication connection with the first server; Sending the target non-deterministic data to the first server for storage, so that the first server maps the target non-deterministic data into second-form data, where the second-form data is zero-knowledge data; The second server stores the second-format data returned by the first server.

9. The zero-knowledge protection method according to claim 8, characterized in that: The target deterministic data includes a target field corresponding to the fixed entry and first actual data under the target field, and the acquiring first form data corresponding to the target deterministic data includes: sending the target deterministic data to the first server, so that the first server converts the target deterministic data into first form data and returns the first form data corresponding to the target field; or, The configuration information sent by the first server is acquired, and first actual data of the target field is converted into first form data based on the configuration information.

10. A zero-knowledge protection method for data, applied to a second server, characterized in that: include: Acquire a query request sent by an electronic device, the query request carries a data request identifier, the data request identifier includes a deterministic type identifier and / or a non-deterministic type identifier, the deterministic type identifier is used to indicate target deterministic data, the non-deterministic type identifier is used to indicate target non-deterministic data, the target deterministic data is optional data pre-configured for one or more fixed entries, the target non-deterministic data is data other than the target deterministic data, the target non-deterministic data includes data freely input by a user on a fixed entry of the electronic device, the second server stores first form data corresponding to the target deterministic data and second form data corresponding to the target non-deterministic data, the first form data and the second form data are both zero-knowledge data, the second server is used to communicate with the first server, and the first server stores the target non-deterministic data and the target deterministic data; In response to the query request, determining target form data corresponding to the data request identifier; Sending a data access request to the first server so that the first server returns target actual data corresponding to the target form data, wherein the target actual data is one or both of the target non-deterministic data and the target deterministic data; The target actual data is sent to the electronic device.

11. A server, characterized in that: The method comprises a memory and a processor, wherein the memory is connected to the processor, and the processor is used to execute one or more computer programs stored in the memory. When the processor executes the one or more computer programs, the server implements the zero-knowledge protection method for data as described in any one of claims 1 to 7, the zero-knowledge protection method for data as described in any one of claims 8 to 9, or the zero-knowledge protection method for data as described in claim 10.

12. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, which includes program instructions. When the program instructions are executed by a processor, the processor executes the zero-knowledge protection method for data as described in any one of claims 1 to 7, the zero-knowledge protection method for data as described in any one of claims 8 to 9, or the zero-knowledge protection method for data as described in claim 10.

Citation Information

Patent Citations

  • Account login method, page display method, client, and server

    CN107196898A

  • Zero-knowledge data storage verification method and device based on BLS signature and storage medium

    CN114021158A

  • Data processing method and system based on zero knowledge proof, terminal and storage medium

    CN114065156A

  • Data processing method, device and equipment and computer storage medium

    CN116522404A

  • Private data processing method and device, electronic equipment and readable storage medium

    CN116561789A