Data encryption transmission method based on elliptic curve

By agreeing to generate random numbers between the data sender and the receiver, the second ciphertext data of the elliptic curve encryption algorithm is transmitted only in scenarios such as federated learning, which solves the problem of low encryption transmission efficiency in the prior art, and achieves significant bandwidth and time cost reduction.

CN120074794APending Publication Date: 2025-05-30ANT BLOCKCHAIN TECHNOLOGY (SHANGHAI) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510225220.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-26
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

In scenarios such as federated learning that require a large number of encrypted transmissions, existing elliptic curve encryption algorithms lead to the large transmission of ciphertext data requiring high bandwidth resources and time costs. How to improve the communication efficiency of encrypted transmissions is an urgent problem.

Method used

By a method that is agreed in advance between the data sender and the receiver, the data sender only sends the second ciphertext data, and the data receiver generates the random number by itself to obtain the first ciphertext data, so that the first ciphertext data is not required.

Benefits of technology

It effectively reduces the bandwidth resources and time costs required for large batches of ciphertext data, and improves the communication efficiency of encrypted transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074794A_ABST
    Figure CN120074794A_ABST
Patent Text Reader

Abstract

According to the elliptic curve-based data encryption transmission method provided by the invention, in the target ciphertext data obtained by encrypting the plaintext data, the first ciphertext data can be directly obtained through the random number, so that when the ciphertext data is sent to the data receiver, the second ciphertext data can be directly sent to the data receiver; the data receiver can automatically obtain the first ciphertext data by generating the same random number, so that the first ciphertext data does not need to be sent, bandwidth resources and time cost required for large-batch transmission of the ciphertext data can be effectively reduced in a scene such as federated learning in which a private key is required to perform large-data-volume encryption transmission, and the transmission efficiency of the large-data-volume encryption transmission is improved. And the communication efficiency of encryption transmission is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to the field of blockchain technology, and in particular, to a data encryption and transmission method based on elliptic curves. Background Art

[0002] Currently, in asymmetric encryption algorithms, the elliptic curve encryption algorithm has become one of the hot research objects in the field of cryptography due to its advantage of being able to achieve equivalent or higher security performance with a shorter key compared to RSA.

[0003] In the prior art, before encrypting plaintext data using the elliptic curve encryption algorithm, it is necessary to first generate a finite field F_p based on a prime number p, then define an elliptic curve E(F_p) over this finite field F_p, and determine the n-order base point G of this elliptic curve E(F_p).

[0004] When generating keys, a private key d ∈ Z_(n - 1)^* is randomly selected from the set Z_(n - 1)^*, where the set Z_(n - 1)^* is the set of numbers that are relatively prime to n - 1 among 0, 1, 2,..., n - 2. Then, a public key PK = [d]G is generated, where [d]G represents performing scalar multiplication with d on the base point G on the elliptic curve E(F_p), that is, performing d addition operations on the base point G on the elliptic curve E(F_p). The public key PK can be made public, and the private key d needs to be secretly stored and not made public.

[0005] When encrypting, the plaintext data m is obtained, and the public key PK is used to encrypt the plaintext data m to obtain the ciphertext data C, and the ciphertext data C is transmitted to the data recipient. Correspondingly, when decrypting, the obtained ciphertext data C is decrypted using the private key d to obtain the corresponding plaintext data m.

[0006] However, in scenarios such as federated learning that require a large amount of encrypted transmission, batch transmission of a large number of ciphertext data C encrypted using the above method requires high bandwidth resources and time costs. Therefore, how to improve the communication efficiency of encrypted transmission is an urgent problem to be solved. Summary of the Invention

[0007] In view of this, this specification provides a data encryption and transmission method based on elliptic curves to solve the deficiencies in the related art.

[0008] Specifically, this specification is implemented through the following technical solutions:

[0009] According to the first aspect of the embodiments of this specification, a data encryption and transmission method based on elliptic curves is provided.

[0010] Initialize an elliptic curve based on a finite field in advance, and generate a private key required for an elliptic curve encryption algorithm according to the elliptic curve. The method includes:

[0011] The data sender obtains the plaintext data to be encrypted;

[0012] Generate a random number using a predefined method, where the random number is used to obtain a first ciphertext data corresponding to the plaintext data; and encrypt the plaintext data using the first ciphertext data and the private key to obtain a second ciphertext data corresponding to the plaintext data;

[0013] Transmit the second ciphertext data to the data receiver, so that the data receiver generates the random number using the predefined method, obtains the first ciphertext data according to the random number, and obtains a target ciphertext data corresponding to the plaintext data according to the first ciphertext data and the second ciphertext data.

[0014] According to a second aspect of the embodiments of the present specification, there is provided a data encryption and transmission device based on an elliptic curve. The device includes:

[0015] An initialization module for initializing an elliptic curve based on a finite field in advance and generating a private key required for an elliptic curve encryption algorithm according to the elliptic curve;

[0016] An acquisition module for acquiring the plaintext data to be encrypted;

[0017] An encryption module for generating a random number using a predefined method, where the random number is used to obtain a first ciphertext data corresponding to the plaintext data; and encrypting the plaintext data using the first ciphertext data and the private key to obtain a second ciphertext data corresponding to the plaintext data;

[0018] A transmission module for transmitting the second ciphertext data to a data receiver, so that the data receiver generates the random number using the predefined method, obtains the first ciphertext data according to the random number, and obtains a target ciphertext data corresponding to the plaintext data according to the first ciphertext data and the second ciphertext data.

[0019] According to a third aspect of the embodiments of the present specification, there is provided an electronic device including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the steps of the method described in the first aspect are implemented.

[0020] According to a fourth aspect of the embodiments of the present specification, there is provided a computer-readable storage medium having a computer program stored thereon. When the program is executed by a processor, the steps of the method described in the first aspect are implemented.

[0021] According to a fifth aspect of the embodiments of the present specification, a computer program product is provided, including a computer program / instructions, which when executed by a processor, implement the steps of the method described in the first aspect.

[0022] In the technical solution provided in the present specification, in the target ciphertext data obtained by encrypting the plaintext data, the first ciphertext data can be directly obtained through a random number. Therefore, when sending the ciphertext data to the data recipient, the second ciphertext data can be directly sent to the data recipient, and the data recipient can generate the same random number to obtain the first ciphertext data by itself, thus eliminating the need to send the first ciphertext data. In scenarios such as federated learning that require the use of private keys for encrypting and transmitting large amounts of data, the bandwidth resources and time costs required for transmitting a large number of ciphertext data can be effectively reduced, and the communication efficiency of encrypted transmission is improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Figure 1 is a schematic flow chart of data encryption and transmission based on an elliptic curve shown in an exemplary embodiment of the present specification;

[0024] Figure 2 is a schematic structural diagram of a data encryption and transmission device based on an elliptic curve shown in an exemplary embodiment of the present specification;

[0025] Figure 3 is a schematic structural diagram of an electronic device shown in an exemplary embodiment of the present specification. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0026] In order to enable those skilled in the art to better understand the technical solutions in the present specification, the technical solutions in the embodiments of the present specification will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present specification. Obviously, the described embodiments are only a part of the embodiments of the present specification, rather than all the embodiments. Based on the embodiments in the present specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present specification.

[0027] Figure 1 is a schematic flow chart of data encryption and transmission based on an elliptic curve shown in an exemplary embodiment of the present specification. As Figure 1 shown, the method may include the following steps:

[0028] Step 102, the data sender obtains the plaintext data to be encrypted.

[0029] In the embodiments of this specification, before encrypting the plaintext data using elliptic curve encryption, the data sender needs to first perform the initialization of elliptic curve encryption. Specifically, first generate a finite field \(F_p\) based on a prime number \(p\), and then define an elliptic curve \(E(F_p)\) over this finite field \(F_p\). The functional expression of the elliptic curve \(E(F_p)\) is \(y\) 2 = \(x\) 3 ^3 + \(ax + b\), and determine the \(n\)-th order base point of the elliptic curve \(E(F_p)\). When generating the private key required for this elliptic curve encryption algorithm, a private key \(d\in Z_{(n - 1)}^*\) can be randomly selected from the set \(Z_{(n - 1)}^*\), where the set \(Z_{(n - 1)}^*\) is the set of numbers that are relatively prime to \(n - 1\) among 0, 1, 2, ……, \(n - 2\).

[0030] When using this elliptic curve encryption algorithm to encrypt the plaintext data, the data sender first needs to obtain the plaintext data to be encrypted, denoted as \(m\).

[0031] Step 104, generate a random number using a pre-agreed method, where the random number is used to obtain the first ciphertext data corresponding to the plaintext data; and encrypt the plaintext data using the first ciphertext data and the private key to obtain the second ciphertext data corresponding to the plaintext data.

[0032] After the data sender obtains the plaintext data \(m\) to be encrypted, a random number \(r\) can be first generated using a pre-agreed method. This random number \(r\) can be used to obtain the first ciphertext data corresponding to the plaintext data \(m\). Specifically, the coordinate point \(R\) on the elliptic curve \(E(F_p)\) mapped by the random number \(r\) can be determined, and this coordinate point \(R\) is used as the first ciphertext data \(C1\).

[0033] When determining the coordinate point \(R\) on the elliptic curve \(E(F_p)\) mapped by the random number \(r\), the random number \(r\) can be directly used as the abscissa of the coordinate point \(R\), and then according to this abscissa and the functional expression of the elliptic curve \(E(F_p)\) \(y\) 2 = \(x\) 3 ^3 + \(ax + b\), determine the ordinate of the coordinate point \(R\). Alternatively, the hash value \(hash(r)\) of the random number \(r\) can be used as the abscissa of the coordinate point \(R\), and then according to this abscissa and the functional expression of the elliptic curve \(E(F_p)\) \(y\) 2 = \(x\) 3 ^3 + \(ax + b\), determine the ordinate of the coordinate point \(R\). The embodiments of this specification do not limit this.

[0034] After obtaining the first ciphertext data C1, when encrypting the plaintext data m using the first ciphertext data C1 and the private key d, a first sub-ciphertext data can be obtained based on the plaintext data m to be encrypted and the base point of the elliptic curve. Then, a second sub-ciphertext data can be obtained based on the private key d and the first ciphertext data C1. Finally, the second ciphertext data C2 corresponding to the plaintext data m can be obtained based on the first sub-ciphertext data and the second sub-ciphertext data. The specific method for obtaining the second ciphertext data C2 depends on the specific elliptic curve encryption algorithm, which will not be described here for the time being and will be elaborated later according to the specific elliptic curve encryption algorithm.

[0035] After obtaining the first ciphertext data C1 and the second ciphertext data C2, the target ciphertext data C = {C1, C2} corresponding to the plaintext data m can be obtained. That is, in the embodiments of this specification, the target ciphertext data C obtained by encrypting the plaintext data m using the elliptic curve encryption algorithm is actually two coordinate points C1 and C2 on the elliptic curve E(F_p). Later, the coordinate point corresponding to C1 will be called the first coordinate point, and the coordinate point corresponding to C2 will be called the second coordinate point.

[0036] Among them, the said convention method is a method for generating random numbers pre-agreed by the data sender and the data receiver, and the random numbers generated by the data sender and the data receiver using this convention method are the same.

[0037] Step 106: Transmit the random number and the second ciphertext data to the data receiver, so that the data receiver generates the random number using the said convention method, obtains the first ciphertext data according to the random number, and obtains the target ciphertext data corresponding to the plaintext data according to the first ciphertext data and the second ciphertext data.

[0038] Since the target ciphertext data C is composed of two coordinate points C1 and C2, each coordinate point has an abscissa and an ordinate. And the first ciphertext data C1 is the first coordinate point R on the elliptic curve E(F_p) mapped by the random number r. That is to say, as long as the random number r and the elliptic curve E(F_p) are obtained, the first coordinate point R as the first ciphertext data C1 can be obtained. Therefore, in the embodiments of this specification, the abscissa and ordinate of C1 are not sent to the data receiver, but only the second ciphertext data C2 is sent to the data receiver, and the data receiver is made to generate the same random number r as the data sender in step 104 using the above-mentioned convention method, so that the data receiver restores the first ciphertext data C1 according to the random number r and the publicly known elliptic curve E(F_p), and then obtains the target ciphertext data C from the first ciphertext data C1 and the second ciphertext data C2.

[0039] Since the above method can directly make the data recipient generate the same random number r as the data sender without sending the first ciphertext data C1 to the data recipient, and enable the data recipient to restore the first ciphertext data C1 according to the random number r, it can effectively reduce the bandwidth resources and time costs required for transmitting a large amount of ciphertext data, and improve the communication efficiency of encrypted transmission.

[0040] The following uses a specific application scenario to illustrate the specific process of data encryption transmission provided in the embodiments of this specification when the elliptic curve encryption algorithm is a homomorphic encryption algorithm.

[0041] In the training scenario of the SecureBoost model in federated learning, the data sender is the party holding the labels and model parameters, and the data recipient is the party holding the features. Since the data recipient does not want to disclose the features it owns, and the data sender needs to use the features of the data recipient to train its own model, the data sender can provide a part of the model parameters to the data recipient, and the data recipient uses the features it holds to assist the data recipient in updating the gradient information. To prevent the data recipient from inferring the label information held by the data sender based on the gradient information, the data sender also needs to homomorphically encrypt the gradient information and send the ciphertext to the data recipient. The data recipient performs a homomorphic operation using the gradient ciphertext information and its own features, and sends the cumulative sum of the gradient ciphertext to the data sender. The data sender decrypts it to update the model parameters.

[0042] However, in the SecureBoost model, the number of samples often reaches hundreds of thousands or even millions, which means that in a single training cycle, the number of ciphertexts generated may be as high as millions. Therefore, the data sender can use the data encryption transmission method provided in this specification to encrypt and transmit the data (i.e., the above gradient information).

[0043] That is, the data recipient inputs the features it holds into the model to be trained, obtains the output result of the model to be trained, and sends the output result to the data sender. The data sender calculates the gradient information based on the output result of the model to be trained and the labels it holds. At this time, Figure 1In step 102 shown above, the data sender can use the calculated gradient information as the plaintext data m to be encrypted. Similarly, before performing elliptic curve encryption on the plaintext data, it is necessary to first initialize the elliptic curve encryption. Specifically, first generate a finite field F_p based on a prime number p, then define an elliptic curve E(F_p) on this finite field F_p, and determine the n-order base point G of the elliptic curve E(F_p). When generating the private key required for this elliptic curve encryption algorithm, a private key d ∈ Z_(n - 1)^* can be randomly selected from the set Z_(n - 1)^*, where the set Z_(n - 1)^* is the set of numbers that are relatively prime to n - 1 among 0, 1, 2,..., n - 2.

[0044] Next, in step 104, after the data sender obtains the plaintext data m to be encrypted, a random number r can be generated using a predefined method, and the random number r is mapped onto the elliptic curve E(F_p) to obtain the first coordinate point R corresponding to the random number r on the elliptic curve, which is used as the first ciphertext data C1.

[0045] Since the elliptic curve encryption algorithm is a homomorphic encryption algorithm, the elliptic curve encryption algorithm used here can include Lifted EC-ElGamal and Twisted EC-ElGamal.

[0046] First, taking Lifted EC-ElGamal as an example for illustration, the method for obtaining the second ciphertext data C2 is as follows: According to the plaintext data m and the n-order base point G of the elliptic curve E(F_p), the first sub-ciphertext data [m]G is obtained, that is, performing m addition operations on the base point G. Then, according to the private key d and the first ciphertext data C1 = R, the second sub-ciphertext data [d]R is obtained, that is, performing d addition operations on the first coordinate point R. Finally, the second ciphertext data C2 = [m]G + [d]R is obtained based on the first sub-ciphertext data and the second sub-ciphertext data. Thus, the target ciphertext data C = {C1, C2} = {R, [m]G + [d]R}. Then, the second ciphertext data C2 = [m]G + [d]R is sent to the data receiver through step 106, without sending the first ciphertext data C1 = R.

[0047] After the subsequent data recipient receives the second ciphertext data C2, it can first generate the same random number r using a pre-agreed method, and then restore the first ciphertext data C1 = R based on the random number r and the elliptic curve E(F_p). Then, the target ciphertext data C = {R, [m]G + [d]R} is obtained from the first ciphertext data C1 and the second ciphertext data C2. At this time, the target ciphertext data is the gradient information encrypted by the homomorphic encryption algorithm. Therefore, the data recipient can perform homomorphic operations based on this encrypted gradient information to obtain the ciphertext operation result and return the ciphertext operation result to the data sender. Since the data sender holds the private key d, the data sender can use the private key d to decrypt the ciphertext operation result to obtain the plaintext operation result. Specifically, the data sender can first calculate [m]G = C2 - [d]C1, and then solve for the plaintext m based on [m]G.

[0048] It should be noted that given the elliptic curve E(F_p) and its base point G, solving for m is a mathematical problem. Therefore, when using the Lifted EC-ElGamal elliptic curve encryption algorithm, the length of m does not exceed a preset length. For example, the length of m does not exceed 40 bits.

[0049] Taking Twisted EC-ElGamal as an example for further explanation. When using the Twisted EC-ElGamal elliptic curve encryption algorithm, the initialization in step 102 is similar to that of Lifted EC-ElGamal. The difference is that in addition to determining an n-order base point G of the elliptic curve E(F_p), Twisted EC-ElGamal also needs to determine another n-order base point H of E(F_p), where G is not equal to H. The rest of the initialization is exactly the same. Then, the method for obtaining the second ciphertext data C2 in the Twisted EC-ElGamal elliptic curve encryption algorithm is as follows: based on the plaintext data m and the n-order base point H of the elliptic curve E(F_p), the first sub-ciphertext data [m]H is obtained, that is, performing m addition operations on the base point H. Then, based on the private key d and the first ciphertext data C1 = R, the second sub-ciphertext data [d^(-1)]R is obtained, that is, performing d^(-1) addition operations on the coordinate point R. Finally, the second ciphertext data C2 = [m]H + [d^(-1)]R is obtained from the first sub-ciphertext data and the second sub-ciphertext data. Thus, the target ciphertext data C = {C1, C2} = {R, [m]H + [d^(-1)]R}. Then, the second ciphertext data C2 = [m]H + [d^(-1)]R is sent to the data recipient through step 106, without sending the first ciphertext data C1 = R.

[0050] After the subsequent data recipient receives the second ciphertext data C2, it can first generate the same random number r using a pre-agreed method, and then restore the first ciphertext data C1 = R based on the random number r and the elliptic curve E(F_p). Then, the target ciphertext data C = {R, [m]H + [d^(-1)]R} is obtained from the first ciphertext data C1 and the second ciphertext data C2. At this time, the target ciphertext data is the gradient information encrypted by the homomorphic encryption algorithm. Therefore, the data recipient can perform homomorphic operations based on this encrypted gradient information to obtain the ciphertext operation result and return the ciphertext operation result to the data sender. Since the data sender holds the private key d, the data sender can use the private key d to decrypt the ciphertext operation result to obtain the plaintext operation result. Specifically, the data sender can first calculate [m]H = C2 - [d^(-1)]C1, and then solve for the plaintext m based on [m]H. Similarly, given the elliptic curve E(F_p) and its base point H, solving for m is a mathematical problem. Therefore, when using the Twisted EC-ElGamal elliptic curve encryption algorithm, the length of m does not exceed a preset length. For example, the length of m does not exceed 40 bits.

[0051] In addition, whether using Lifted EC-ElGamal or Twisted EC-ElGamal as described above, each plaintext data requires a random number r for encryption. In the federated learning scenario, the sample size is usually in the hundreds of thousands or even millions. Each gradient information corresponding to a sample is encrypted using a random number r, and the data sender needs to send hundreds of thousands or even millions of random numbers r. Therefore, to further improve the data transmission efficiency, in the embodiments of this specification, the data sender and the data recipient can use the same pseudo-random sequence generator and the same random number seed seed to generate the same random number r. Specifically, the same pseudo-random sequence generator can be deployed in the data sender and the data recipient. When generating a random number, the data sender can first generate the random number seed seed, and then generate the random number r based on the random number seed seed and the pseudo-random sequence generator. Correspondingly, the data sender can pre-transmit the random number seed seed to the data recipient, and the data recipient can generate the same random number r based on this random number seed seed and the pseudo-random sequence generator, and then restore the first ciphertext data C1 = R based on the random number r, and finally obtain the target ciphertext data C, where the random numbers generated by the data sender and the data recipient based on the same random number seed and the same pseudo-random sequence generator are the same. That is to say, when the data sender encrypts a large number of plaintext data and sends them to the data recipient, it only needs to send one random number seed seed and the second ciphertext data in the target ciphertext data corresponding to each plaintext data, without sending the random number corresponding to each plaintext data and the second ciphertext data corresponding to each plaintext data.

[0052] Further, before transmitting the second ciphertext data to the data receiver, the data sender may also compress the second ciphertext data and then transmit the compressed second ciphertext data to the data receiver.

[0053] Specifically, from the elliptic curve, it can be known that the elliptic curve is symmetric about the x-axis (i.e., the horizontal axis). Therefore, whether according to the elliptic curve or according to the functional expression of the elliptic curve y 2 = x 3 + ax + b, it can be known that once the abscissa of a point on the elliptic curve is determined, the absolute value of the ordinate of this point can be determined. The only thing that is not determined is the sign of the ordinate.

[0054] Since the first ciphertext data C1 = R and the second ciphertext data C2 are both points on the elliptic curve, in order to compress the data volume of the second ciphertext data C2, the compressed second ciphertext data can be obtained according to the abscissa of the second coordinate point corresponding to the second ciphertext data C2 and the identifier indicating the sign of the ordinate of this second coordinate point. Since the data volume of the identifier indicating the sign of the ordinate of the second coordinate point is necessarily much smaller than the data volume required for the ordinate of the target point itself, the purpose of compression can be achieved.

[0055] Further, the prime number p based on which the finite field F_p is generated during initialization in step 102 can be an odd prime number. Then, when defining the elliptic curve E(F_p) over the finite field F_p, it is equivalent to discretizing the elliptic curve E(F_p) using the finite field F_p. Therefore, all results of operations based on the elliptic curve E(F_p) need to be modulo the odd prime number p. Thus, when the absolute value of the ordinate of the second coordinate point is fixed and the sign is not fixed, the results of taking the modulo of the positive and negative ordinates of this second coordinate point with respect to the odd prime number p must be one odd and one even. That is to say, the last bit of the binary numbers of the positive and negative ordinates of the second coordinate point must be one 1 and one 0. Therefore, the finite field F_p can be generated based on the odd prime number p. Correspondingly, the last bit of the binary number used to identify the ordinate of the second coordinate point is determined as the identifier indicating the sign of the ordinate of the second coordinate point.

[0056] By transmitting the random number (or random number seed) and the compressed second ciphertext data to the data receiver through the above step 106, the required bandwidth resources and time costs can be further reduced, and the communication efficiency of encrypted transmission is improved, as shown in Table 1 below.

[0057]

[0058] Table 1

[0059] In Table 1, assume that the data sender has L samples in a batch, that is, L gradient information needs to be encrypted and transmitted. Then, L random numbers can be generated according to the random number seed to obtain the corresponding L first ciphertext data C1 = R, and the above-mentioned Lifted EC-ElGamal or Twisted EC-ElGamal is used for encrypted transmission.

[0060] During transmission, if the method of "compressed ciphertext + random number seed" is adopted, a random number seed and L compressed second ciphertext data need to be transmitted. A compressed second ciphertext occupies 33 bytes (only the abscissa and 1 bit identifier for indicating the positive or negative of the ordinate), and the length of a random number seed is 128 bytes. Then, this method needs to transmit 128 + 33L bytes.

[0061] If the method in the prior art is adopted, L target ciphertext data C need to be sent, and each target ciphertext occupies 128 bytes, so a total of 128L bytes need to be transmitted.

[0062] If the method of "compressed ciphertext" is adopted, a compressed first ciphertext data and a compressed second ciphertext data need to be sent, which altogether occupy 65 bytes. Then, a total of 65L bytes need to be transmitted.

[0063] It can be seen that when L reaches one million, the encrypted transmission method provided in this specification reduces the transmission volume by 3.88 times compared with the scheme of directly transmitting ciphertext, and reduces the transmission volume by 2 times compared with the scheme of "compressed ciphertext", significantly reducing the transmission volume.

[0064] Figure 2 It is a schematic structural diagram of a data encryption transmission device based on an elliptic curve shown in an exemplary embodiment of this specification. As Figure 2 shown, the device includes:

[0065] An initialization module 200, configured to initialize an elliptic curve based on a finite field in advance, and generate a private key required for an elliptic curve encryption algorithm according to the elliptic curve;

[0066] An acquisition module 201, configured to acquire plaintext data to be encrypted;

[0067] An encryption module 202, configured to generate a random number by using a predefined method, where the random number is used to obtain first ciphertext data corresponding to the plaintext data; and encrypt the plaintext data by using the first ciphertext data and the private key to obtain second ciphertext data corresponding to the plaintext data;

[0068] A transmission module 203, configured to transmit the second ciphertext data to a data recipient, so that the data recipient generates the random number by using the agreed method, obtains the first ciphertext data according to the random number, and obtains the target ciphertext data corresponding to the plaintext data according to the first ciphertext data and the second ciphertext data.

[0069] Optionally, the encryption module 202 is specifically configured to generate a random number seed; generate a random number according to the random number seed, and transmit the random number seed to a data recipient; wherein, the random numbers generated by the data sender and the data recipient according to the random number seed are the same.

[0070] Optionally, the first ciphertext data is the first coordinate point corresponding to the random number on the elliptic curve;

[0071] The encryption module 202 is specifically configured to obtain a first sub-ciphertext data according to the plaintext data to be encrypted and the base point of the elliptic curve; and obtain a second sub-ciphertext data according to the private key and the first ciphertext data; obtain the second ciphertext data corresponding to the plaintext data according to the first sub-ciphertext data and the second sub-ciphertext data.

[0072] Optionally, the transmission module 203 is specifically configured to compress the second ciphertext data; transmit the random number and the compressed second ciphertext data to a data recipient.

[0073] Optionally, the transmission module 203 is specifically configured to determine a second coordinate point corresponding to the second ciphertext data on the elliptic curve; obtain the compressed second ciphertext data according to the abscissa of the second coordinate point and an identifier for indicating the positive or negative of the ordinate of the second coordinate point, wherein the data volume of the identifier is smaller than the data volume of the ordinate.

[0074] Optionally, the finite field is a finite field generated based on an odd prime number;

[0075] The transmission module 203 is specifically configured to determine the last bit of the binary number for representing the ordinate as the identifier for indicating the positive or negative of the ordinate of the second coordinate point; obtain the compressed second ciphertext data according to the abscissa and the identifier.

[0076] Optionally, the elliptic curve encryption algorithm is a homomorphic encryption algorithm;

[0077] The apparatus further includes:

[0078] The decryption module 204 is configured to, when receiving the ciphertext operation result after the data recipient performs a homomorphic operation on the target ciphertext data, decrypt the ciphertext operation result using the private key to obtain the plaintext operation result.

[0079] Optionally, the data sender holds a tag;

[0080] The data recipient holds a feature; the feature is used to input into the model to be trained to obtain the output result of the model to be trained;

[0081] The plaintext data is the gradient information calculated by the data sender according to the output result of the model to be trained sent by the data recipient and the tag;

[0082] The gradient information is used to update the model parameters of the model to be trained.

[0083] Figure 3 It is a schematic structural diagram of an electronic device in an exemplary embodiment. Please refer to Figure 3 , at the hardware level, the electronic device includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory. Of course, other required hardware may also be included. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it, forming a device for hiding the recipient address or a device for verifying the transaction attribution at the logical level. Of course, in addition to the software implementation, this specification does not exclude other implementation methods, such as logic devices or a combination of software and hardware, etc. That is to say, the execution subject of the following processing flow is not limited to each logical unit, and may also be hardware or a logic device.

[0084] Based on the same concept as the above method, this specification also provides an electronic device, including: a processor; a memory for storing executable instructions of the processor; wherein, the processor runs the executable instructions to implement the steps of the method as described in any of the above embodiments.

[0085] Based on the same concept as the above method, this specification also provides a computer-readable storage medium, on which computer instructions are stored, and when the instructions are executed by a processor, the steps of the method as described in any of the above embodiments are implemented.

[0086] Based on the same concept as the above method, this specification also provides a computer program product, including computer programs / instructions, and when the computer programs / instructions are executed by a processor, the steps of the method as described in any of the above embodiments are implemented.

Claims

1. A data encryption transmission method based on an elliptic curve, wherein an elliptic curve is initialized based on a finite field in advance, and a private key required by an elliptic curve encryption algorithm is generated according to the elliptic curve, the method comprising: The data sender obtains the plaintext data to be encrypted; Generate a random number using an agreed method, wherein the random number is used to obtain first ciphertext data corresponding to the plaintext data; and, using the first ciphertext data and the private key to encrypt the plaintext data to obtain second ciphertext data corresponding to the plaintext data; The second ciphertext data is transmitted to the data recipient, so that the data recipient adopts the agreed method to generate the random number, obtains the first ciphertext data according to the random number, and obtains the target ciphertext data corresponding to the plaintext data according to the first ciphertext data and the second ciphertext data.

2. The method according to claim 1, wherein the random number is generated by a predetermined method, specifically comprising: Generate a random number seed; A random number is generated according to the random number seed, and the random number seed is transmitted to a data receiver; wherein the random number generated according to the random number seed by the data sender and the data receiver is the same.

3. The method according to claim 1, wherein the first ciphertext data is a first coordinate point corresponding to the random number on the elliptic curve; Encrypting the plaintext data using the first ciphertext data and the private key to obtain second ciphertext data corresponding to the plaintext data specifically includes: Obtaining first sub-ciphertext data according to the plaintext data to be encrypted and the base point of the elliptic curve; and obtaining second sub-ciphertext data according to the private key and the first ciphertext data; According to the first sub-ciphertext data and the second sub-ciphertext data, second ciphertext data corresponding to the plaintext data is obtained.

4. The method according to claim 1, wherein transmitting the second ciphertext data to a data recipient comprises: compressing the second ciphertext data; The compressed second ciphertext data is transmitted to the data receiver.

5. The method according to claim 4, compressing the second ciphertext data, specifically comprising: Determine a second coordinate point corresponding to the second ciphertext data on the elliptic curve; The compressed second ciphertext data is obtained according to the abscissa of the second coordinate point and an identifier for indicating the positive and negative of the ordinate of the second coordinate point, wherein the data volume of the identifier is smaller than the data volume of the ordinate.

6. The method according to claim 5, wherein the finite field is a finite field generated based on odd prime numbers; Obtaining compressed second ciphertext data according to the abscissa of the second coordinate point and an identifier used to indicate the positive or negative value of the ordinate of the second coordinate point specifically includes: Determine the last bit of the binary number used to represent the ordinate as an identifier used to represent the positive or negative ordinate of the second coordinate point; The compressed second ciphertext data is obtained according to the horizontal coordinate and the identifier.

7. The method according to any one of claims 1 to 6, wherein the elliptic curve encryption algorithm is a homomorphic encryption algorithm; The method further comprises: When the ciphertext operation result after the data recipient performs a homomorphic operation on the target ciphertext data is received, the ciphertext operation result is decrypted using the private key to obtain a plaintext operation result.

8. The method according to claim 7, wherein the data sender holds a tag; The data receiver holds features; the features are used to input the model to be trained to obtain the output result of the model to be trained; The plaintext data is the gradient information calculated by the data sender according to the output result of the model to be trained and the label sent by the data receiver; The gradient information is used to update the model parameters of the model to be trained.

9. A data encryption transmission device based on elliptic curve, the device comprising: An initialization module, used to initialize an elliptic curve based on a finite field in advance, and generate a private key required by an elliptic curve encryption algorithm according to the elliptic curve; An acquisition module, used for acquiring plaintext data to be encrypted; An encryption module, used to generate a random number using an agreed method, wherein the random number is used to obtain first ciphertext data corresponding to the plaintext data; and, using the first ciphertext data and the private key to encrypt the plaintext data to obtain second ciphertext data corresponding to the plaintext data; A transmission module is used to transmit the second ciphertext data to a data recipient, so that the data recipient adopts the agreed method to generate the random number, obtains the first ciphertext data according to the random number, and obtains the target ciphertext data corresponding to the plaintext data according to the first ciphertext data and the second ciphertext data.

10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of any one of the methods of claims 1 to 8 when executing the program.

11. A computer-readable storage medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the steps of the method according to any one of claims 1 to 8.

12. A computer program product, comprising a computer program / instruction, which, when executed by a processor, implements the steps of the method according to any one of claims 1 to 8.