Data encryption and search method and device, equipment and medium
The target ciphertext is generated by encoding functions and hash functions, and the existing encryption algorithm cannot support mixed comparison of positive and negative numbers and high-precision encryption in the database, and efficient data encryption and search are achieved, improving system security and retrieval efficiency.
Patent Information
- Application Number
- CN202510474015.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-16
- Publication Date
- 2025-07-04
AI Technical Summary
The existing unsequence and order-preserved encryption algorithms have limitations in database encryption and efficient cryptographic retrieval scenarios, and cannot support mixed comparison of positive and negative numbers, which may leak data characteristics, and the data accuracy or security is lost during the encryption process.
The encoding function is used to encode the transaction amount plaintext data, and the hash function and polynomial operation are used to generate the target ciphertext, which supports mixed comparison of positive and negative numbers and high-precision encryption, and realizes data encryption and search through database agents.
It realizes direct comparison and scope query on ciphertext, improves system security and retrieval efficiency, and reduces computing overhead.
Smart Images

Figure CN120256455A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security, and particularly relates to a data encryption and search method, device, equipment and medium. Background Art
[0002] With the rapid development and application of big data and cloud computing technologies, more and more users choose to store encrypted data in a ciphertext database. Traditional database encryption schemes, such as transparent encryption and decryption, only encrypt data during storage. When data needs to be retrieved, it needs to be decrypted first and then retrieved on the plaintext. In this way, the data is used in plaintext state in memory. On the one hand, there are certain security risks and the full-process security of the data cannot be guaranteed. On the other hand, the performance of the database is greatly reduced. General encryption algorithms, such as AES (Advanced Encryption Standard), SM4, etc., will destroy the size relationship of the plaintext itself and do not support operations such as size comparison and range query directly on the ciphertext. The order-revealing encryption algorithm is an encryption algorithm that makes the ciphertext maintain the corresponding plaintext order. Although the ciphertext itself does not have an order relationship, the size relationship of the original plaintext can be reflected by executing the compare() function on the ciphertext. The order-preserving encryption algorithm can directly reflect the size of the plaintext through the size relationship of the ciphertext. Each of the two algorithms has its own advantages, disadvantages and applicable scenarios. For example, order-revealing encryption is suitable for scenarios with relatively high security requirements, and order-preserving encryption can reuse the range retrieval ability of SQL (Structured Query Language) without modifying the database.
[0003] However, the current order-revealing and order-preserving algorithms have certain limitations in the application process. For example, they only support the comparison of ciphertexts of positive numbers, do not support the mixed comparison of positive and negative numbers, or may leak sign features during mixed comparison; there are requirements for the encryption data precision. When the plaintext precision is very high and the number of decimal places is very large, data precision may be lost during encryption, or the ciphertext comparison fails; the security is relatively low, and the bit information of the data itself will be leaked. Therefore, how to encrypt data in the application scenarios of database encryption and efficient ciphertext retrieval is an urgent problem to be solved at present. Summary of the Invention
[0004] In view of this, the purpose of the present invention is to provide a data encryption and search method, device, equipment and medium, which can encrypt data in the application scenarios of database encryption and efficient ciphertext retrieval, protect the positive and negative characteristics of the data, adaptively encrypt high-precision floating-point numbers at the same time, expand the application scenarios of the algorithm, and improve the security of the system. The specific scheme is as follows:
[0005] In a first aspect, the present application discloses a data encryption and search method applied to a database proxy, including:
[0006] Encoding the plaintext data of the transaction amount sent by the client using an encoding function to obtain target encoded data;
[0007] Encrypting the target encoded data to obtain corresponding target ciphertext, and sending the target ciphertext to the database server so that the database server stores the target ciphertext in the ciphertext database;
[0008] Encrypting the search interval corresponding to the plaintext data of the transaction amount into the search interval of the target ciphertext;
[0009] Determining the encryption method of the target ciphertext, and determining the identification serial number of the ciphertext that meets the preset search interval condition through the database server, the search interval of the target ciphertext, and the ciphertext database according to the encryption method, and returning the search result determined based on the identification serial number.
[0010] Optionally, before encoding the plaintext data of the transaction amount sent by the client using the encoding function, it further includes:
[0011] Generating a key, the encoding function, and a hash function determined based on the key according to security parameters;
[0012] Setting the ciphertext database to an idle state, and setting the identification serial number of the data stored in the ciphertext database to 0.
[0013] Optionally, encoding the plaintext data of the transaction amount sent by the client using the encoding function to obtain target encoded data includes:
[0014] Determining an expression of the plaintext data of the transaction amount sent by the client based on the sign bit, mantissa, exponent, and base;
[0015] Obtaining target encoded data according to the expression of the plaintext data of the transaction amount and the encoding function.
[0016] Optionally, obtaining target encoded data according to the expression of the plaintext data of the transaction amount and the encoding function includes:
[0017] Shifting the exponent in the expression to obtain a shifted exponent;
[0018] If the sign bit in the expression is a non - negative number, determining a first exponent based on the sum of the shifted exponent and a preset shift threshold;
[0019] If the sign bit in the expression is negative, determine a second exponent based on the difference between the preset offset threshold and the offset exponent;
[0020] Determine a target mantissa according to the sign bit, the base, and the mantissa;
[0021] Use an encoding function to encode the plaintext data of the transaction amount based on the target mantissa and the first exponent or the second exponent to obtain target encoded data.
[0022] Optionally, encrypting the target encoded data to obtain a corresponding target ciphertext includes:
[0023] Use a hash function determined based on the key to perform hash operations on the integer part and the decimal part of the target mantissa in sequence to obtain a corresponding integer part hash value and decimal part hash value;
[0024] Use the hash function to perform a hash operation on the first exponent or the second exponent to determine an exponent hash value;
[0025] Determine an initial ciphertext based on the integer part hash value, the decimal part hash value, and the exponent hash value;
[0026] Determine the initial ciphertext as the target ciphertext;
[0027] Or, perform a polynomial operation on the initial ciphertext to obtain a corresponding operation result, and determine the operation result as the target ciphertext.
[0028] Optionally, according to the encryption method, determining an identification serial number corresponding to the ciphertext that meets the preset search interval condition through the database server, the search interval of the target ciphertext, and the ciphertext database includes:
[0029] If the initial ciphertext is determined as the target ciphertext, send the search interval of the target ciphertext as a search token of the target ciphertext to the database server, so that the database server compares the ciphertext data in the ciphertext database with the endpoint values of the search token based on a comparison function, obtains a corresponding comparison result, and determines an identification serial number corresponding to the ciphertext that meets the preset search interval condition according to the comparison result;
[0030] If the operation result is determined as the target ciphertext, convert the plaintext structured query statement of the search interval corresponding to the plaintext data of the transaction amount into a ciphertext structured query statement, and send the ciphertext structured query statement to the database server, so that the database server executes the ciphertext structured query statement to obtain an identification serial number corresponding to the ciphertext that meets the preset search interval condition.
[0031] Optionally, sending the target ciphertext to a database server so that the database server stores the target ciphertext in a ciphertext database includes:
[0032] Sending the target ciphertext to a database server so that the database server stores the target ciphertext in the ciphertext database in sequence and updates the ciphertext database to determine the identification serial number of the data storage corresponding to the target ciphertext.
[0033] In a second aspect, the present application discloses a data encryption and search device applied to a database proxy, including:
[0034] An encoded data acquisition module, configured to encode the plaintext data of the transaction amount sent by a client by using an encoding function to obtain target encoded data;
[0035] A target ciphertext sending module, configured to encrypt the target encoded data to obtain a corresponding target ciphertext, and send the target ciphertext to a database server so that the database server stores the target ciphertext in a ciphertext database;
[0036] A search range encryption module, configured to encrypt the search range corresponding to the plaintext data of the transaction amount into a search range of the target ciphertext;
[0037] A search result return module, configured to determine the encryption method of the target ciphertext, and determine, according to the encryption method, the identification serial number corresponding to the ciphertext that meets the preset search range condition through the database server, the search range of the target ciphertext, and the ciphertext database, and return a search result determined based on the identification serial number.
[0038] In a third aspect, the present application discloses an electronic device, including:
[0039] A memory, configured to store a computer program;
[0040] A processor, configured to execute the computer program to implement the data encryption and search method as described above.
[0041] In a fourth aspect, the present application discloses a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the data encryption and search method as described above is implemented.
[0042] In this application, the database proxy first encodes the plaintext data of the transaction amount sent by the client using an encoding function to obtain the target encoded data; then encrypts the target encoded data to obtain the corresponding target ciphertext, and sends the target ciphertext to the database server so that the database server stores the target ciphertext in the ciphertext database; then encrypts the search interval corresponding to the plaintext data of the transaction amount into the search interval of the target ciphertext; finally, determines the encryption method of the target ciphertext, and determines the identification serial number corresponding to the ciphertext that meets the preset search interval condition through the database server, the search interval of the target ciphertext, and the ciphertext database according to the encryption method, and returns the search result determined based on the identification serial number. It can be seen that this application realizes the encryption of the plaintext data of the transaction amount through the data interaction between the client, the database proxy, and the database server end, thereby ensuring the security of this information during the data transmission process and preventing it from being intercepted and tampered with by a third party. At the same time, there is no need to decrypt all the ciphertexts before performing relevant searches, which greatly improves the retrieval efficiency and reduces the computational overhead of the system. Brief Description of the Drawings
[0043] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on the provided drawings.
[0044] Figure 1 It is a flowchart of a data encryption and search method disclosed in this application;
[0045] Figure 2 It is a schematic diagram of the comparison between data plaintext and ciphertext disclosed in this application;
[0046] Figure 3 It is a schematic structural diagram of a data encryption and search device disclosed in this application;
[0047] Figure 4 It is a structural diagram of an electronic device disclosed in this application. Detailed Embodiments
[0048] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0049] Conventional encryption algorithms do not support direct comparison operations on encrypted data. Instead, they need to be decrypted first and then compared, which is very inefficient for large-scale data. Existing order-revealing and order-preserving encryption algorithms have certain usage scenario limitations. For example, they do not support the mixed comparison of positive and negative numbers, or have poor security and will expose the positive and negative characteristics of the data. Existing order-revealing and order-preserving encryption algorithms may have data precision limitations, that is, they do not support encrypting plaintext data with arbitrary precision. During the encryption process, data precision will be lost, or range queries cannot be correctly performed on the ciphertext after encrypting high-precision plaintext. To solve the above technical problems, this application discloses a data encryption and search method, device, equipment, and medium, which can encrypt data in application scenarios facing database encryption and efficient encrypted retrieval, protect the positive and negative characteristics of the data, adaptively encrypt high-precision floating-point numbers, expand the usage scenarios of the algorithm, and improve the security of the system.
[0050] See Figure 1 As shown, an embodiment of the present invention discloses a data encryption and search method, which is applied to a database proxy and includes:
[0051] Step S11: Use an encoding function to encode the plaintext data of the transaction amount sent by the client to obtain the target encoded data.
[0052] In this embodiment, the current digital banking system has become the main channel for users to perform financial services such as transferring money, making payments, and querying account balances. These operations involve a large amount of sensitive information, such as user accounts, passwords, transaction amounts, payee information, etc. How to ensure the security of this information during data transmission and prevent it from being intercepted and tampered with by a third party is the key to protecting the security and privacy of users' funds. To ensure data security, this application designs a data encryption and search method for the financial bank database system, which can be applied to fields that require range comparison such as transaction amounts. In a specific embodiment, taking the amount field in the credit card data table as an example, the method of this application is described in detail. The system consists of three parts: the client, the database intermediate trusted proxy, and the database server side, and is mainly divided into three algorithms: the initialization algorithm (used to determine the initial state and encryption parameters of the algorithm), the encryption algorithm (used to encrypt data), and the search algorithm (used to perform range retrieval on the ciphertext).
[0053] First, the database proxy generates a key, the encoding function, and a hash function determined based on the key according to the security parameters; sets the encrypted database to the idle state, and sets the identification serial number of the data stored in the encrypted database to 0. Specifically, according to the security parameters Generate a key , encoding function , hash function with a key Meanwhile, the server sets the database for storing ciphertext information to an idle state: , sets the identification serial number of data storage to 0: .
[0054] Then, when encoding the plaintext data of the transaction amount sent by the client, the present application determines the expression of the plaintext data of the transaction amount sent by the client based on the sign bit, mantissa, exponent, and base; and obtains the target encoded data according to the expression of the plaintext data of the transaction amount and the encoding function. Specifically, the client sends the plaintext amount m to the trusted proxy, and the proxy encodes m using the encoding function. The present application represents m in scientific notation of sign bit C, mantissa M, exponent e, and base B: , where the value range of the exponent e [-r, r] is determined according to the actual data range. For example, the account amount data is generally a floating-point number, that is, r = 38 and B = 10 are taken. In this way, since the mantissa part can support an arbitrary precision length range, the encryption algorithm of the present application can encrypt plaintext data with arbitrary precision without loss of precision, dynamically select the precision that meets any requirement according to the actual scenario, and the higher the precision only affects the length of the output ciphertext vector.
[0055] Meanwhile, the present application can also hide the sign bit. Therefore, the present application offsets the exponent in the expression to obtain the offset exponent; if the sign bit in the expression is a non-negative number, the first exponent is determined based on the sum of the offset exponent and the preset offset threshold; if the sign bit in the expression is a negative number, the second exponent is determined based on the difference between the preset offset threshold and the offset exponent; the target mantissa is determined according to the sign bit, the base, and the mantissa; and the encoding function is used to encode the plaintext data of the transaction amount based on the target mantissa and the first exponent or the second exponent to obtain the target encoded data. For example, the exponent e is uniformly offset by R, that is , where it is required that , and here R = 40 can be taken. Then, the exponent is processed again according to the sign bit C. For non-negative numbers ( ), the exponent is set to ; for negative numbers ( ), the exponent is set to , achieving the effect of unifying the sign bit. At the same time, the mantissa is offset, and is calculated, and finally the target encoded data In this way, the present application protects the sign bit of the plaintext data during the data encryption process, without leaking the sign bit characteristics of the data itself. Therefore, it supports the scenario of mixed comparison of positive and negative numbers, improving the security of the system. Moreover, it supports the encryption and comparison of plaintext with mixed positive and negative numbers and different numerical types, and the encryption function can uniformly process signed numerical values, hiding the positive and negative characteristics of the data itself, making it very convenient to support the requirements in the application scenario.
[0056] Step S12: Encrypt the target encoded data to obtain the corresponding target ciphertext, and send the target ciphertext to the database server so that the database server stores the target ciphertext in the ciphertext database.
[0057] In this embodiment, after obtaining the target encoded data, encrypt the target encoded data. When encrypting, use the hash function determined based on the key to perform hash operations on the integer part and the decimal part of the target mantissa in sequence to obtain the corresponding integer part hash value and decimal part hash value; use the hash function to perform a hash operation on the first exponent or the second exponent to determine the exponent hash value; determine the initial ciphertext based on the integer part hash value, the decimal part hash value, and the exponent hash value; determine the initial ciphertext as the target ciphertext; or, perform a polynomial operation on the initial ciphertext to obtain the corresponding operation result, and determine the operation result as the target ciphertext. Specifically, there are two data encryption algorithms in the present application. Data encryption algorithm one: Perform bit-by-bit hash operations on the encoded Specifically, the method is to perform calculations on and in sequence using the above hash function. When performing a hash on , it is required to perform hashes on its integer and decimal parts in sequence. Among them, represent in the form of a bit string , calculate , where k is the key, refers to a binary bit 0, 1 string (for example, e = 18 can be represented as ’b1b2b3b4b5’ = ’10010’), and take the modulus P = 3, and then a series of exponential encryption result sets can be obtained. Similarly, for the integer and decimal parts of the mantissa , , calculate to obtain the encrypted result set of the integer part of the mantissa . For with f decimal places, that is , for each , calculate to obtain the single encrypted result set of the decimal part of the mantissa The encrypted result set z of the fractional part of the sum of mantissas: . Finally, the ciphertext is obtained .
[0058] Data Encryption Algorithm 2: Perform bit-by-bit hashing on the encoded . The specific method is to perform calculations on and successively using the above hash function. It is required to perform hashing on by hashing its integer and fractional parts successively. Among them, represent in the form of a bit string , calculate , take P = 3, and then a series of can be obtained. Similarly, for the integer and fractional parts of the mantissa , , calculate , and obtain . For with f decimal places, that is , for each , calculate , and obtain the single encrypted result set of the fractional part of the mantissa and the encrypted result set z of the fractional part of the mantissa: . Finally, the ciphertext is obtained . For the ciphertext , perform polynomial operations to obtain the final ciphertext . Let have lengths of respectively, then calculate , and A = 5, B = 1 / 5 can be taken.
[0059] After encrypting the target-encoded data through any of the above data encryption algorithms and obtaining the corresponding target ciphertext, the database proxy will send it to the server, and the server will store it in order and update the EDB (Enterprise Database), That is, the target ciphertext is sent to the database server, so that the database server stores the target ciphertext in the ciphertext database in sequence, updates the ciphertext database, and determines the identification serial number of the data storage corresponding to the target ciphertext. In this way, the data encryption algorithm of the present application encrypts the plaintext into two parts, the exponent part and the mantissa part. After offset, randomization, and polynomial encoding processing, compared with the existing encryption methods, it better hides the data characteristics. When the comparison function is executed, 1 bit of information will be leaked, but this bit of information only indicates that the exponent part is different or the mantissa is different when the exponent parts are exactly the same. Compared with the existing methods that will expose the different positions when the two specific plaintexts are expanded in binary, the method of the present application is more secure.
[0060] Step S13: Encrypt the search interval corresponding to the plaintext data of the transaction amount into the search interval of the target ciphertext.
[0061] In this embodiment, the database proxy encrypts the search interval of the plaintext data of the transaction amount into the search interval of the ciphertext , where . Specifically, the above data encryption algorithm one can be used to encrypt the search interval of the plaintext into the search interval of the ciphertext.
[0062] Step S14: Determine the encryption method of the target ciphertext, and according to the encryption method, determine the identification serial number of the ciphertext corresponding to the preset search interval condition through the database server, the search interval of the target ciphertext, and the ciphertext database, and return the search result determined based on the identification serial number.
[0063] In this embodiment, since different data encryption algorithms are used, the forms of the ciphertexts obtained are different. Therefore, the encryption method of the ciphertext is first determined. If the initial ciphertext is determined as the target ciphertext (i.e., encrypted using data encryption algorithm one), the search interval of the target ciphertext is sent as the search token of the target ciphertext to the database server, so that the database server compares the ciphertext data in the ciphertext database with the endpoint values of the search token based on a comparison function, obtains the corresponding comparison result, and determines the identification number corresponding to the ciphertext that meets the preset search interval condition according to the comparison result. If the operation result is determined as the target ciphertext (i.e., encrypted using data encryption algorithm two), the plaintext structured query statement of the search interval corresponding to the plaintext data of the transaction amount is converted into a ciphertext structured query statement, and the ciphertext structured query statement is sent to the database server, so that the database server executes the ciphertext structured query statement to obtain the identification number corresponding to the ciphertext that meets the preset search interval condition. Finally, the search result determined based on the identification number is returned. In this way, this application supports directly reusing the comparison and range search capabilities of SQL on the ciphertext, supports returning correct relevant data such as max, min, order by, >=, between and, etc., without the need to perform relevant searches after decrypting all the ciphertexts, greatly improving the retrieval efficiency and reducing the computational overhead of the system.
[0064] In summary, in this application, the database proxy first encodes the plaintext data of the transaction amount sent by the client using an encoding function to obtain the target encoded data; then encrypts the target encoded data to obtain the corresponding target ciphertext, and sends the target ciphertext to the database server so that the database server stores the target ciphertext in the ciphertext database; then encrypts the search interval corresponding to the plaintext data of the transaction amount into the search interval of the target ciphertext; finally, determines the encryption method of the target ciphertext, and determines the identification number corresponding to the ciphertext that meets the preset search interval condition through the database server, the search interval of the target ciphertext, and the ciphertext database according to the encryption method, and returns the search result determined based on the identification number. It can be seen that this application realizes the encryption of the plaintext data of the transaction amount through the data interaction between the client, the database proxy, and the database server end, thereby ensuring the security of this information during the data transmission process and preventing it from being intercepted and tampered with by a third party. At the same time, there is no need to perform relevant searches after decrypting all the ciphertexts, greatly improving the retrieval efficiency and reducing the computational overhead of the system.
[0065] Based on the previous embodiment, the present application can determine the identification number corresponding to the ciphertext that meets the preset search range condition according to the encryption method through the database server, the search range of the target ciphertext, and the encrypted database, and return the search result determined based on the identification number. Next, a detailed description of the specific search algorithm will be given.
[0066] Data Search Algorithm 1: If the target ciphertext is encrypted using Data Encryption Algorithm 1, the database proxy encrypts the search range of the plaintext data of the transaction amount into the search range of the ciphertext and sends it to the server as a search token, where , , . After receiving the search token of the ciphertext, the server compares the encrypted data in the database with the two encrypted data in the token. The key comparison function compare() is used, which compares the encrypted search endpoints with the ciphertext values in the database. According to the characteristics of the keyed hash function F, if there is a relationship in these corresponding encrypted data vectors, it means , otherwise it means . The specific process is as follows: Initialize the result set . For each in the EDB of the database, the server executes the comparison function , , to obtain . If , output 1, otherwise output 0. According to the above compare() function, compare the encrypted data with the endpoint values of the search token in turn to obtain the corresponding values that meet the size relationship : . If is satisfied, add the serial number d to the result set result, that is . Finally, return the result set result to the client. Specifically, as shown in the data plaintext-ciphertext comparison table in Figure 2 , the data precision of the ciphertext is controllable during calculation and storage, and amount1 is the encryption result using the optional Data Encryption Method 1. When the search condition required by the user is: " ", the database proxy uploads the search range as . Then execute the above search algorithm to obtain the corresponding id serial numbers as [1, 4, 5, 6, 8].
[0067] Data Search Algorithm 2: The plaintext SQL statement submitted by the client is " ", and the ciphertext SQL statement submitted by the database trusted proxy is " ", the database server can directly utilize the search ability of SQL to return the IDs that meet this range. Specifically, Figure 2 the data precision of the ciphertext is controllable during the calculation and storage processes. amount2 is the encryption result using the optional data encryption algorithm II. When a user submits a plaintext SQL statement " ", the proxy will convert it into a ciphertext SQL statement " ". After that, the database executes the above statement on the ciphertext column and returns the corresponding ID numbers as [1, 4, 5, 6, 8]. At the same time, this method has practicality and efficiency in the application of structured databases. Taking order by as an example, when conducting an efficiency test on a dataset of millions of floating-point numbers, the time consumption for plaintext is about 2.59 s, and the time consumption for ciphertext is about 4.25 s. When a search index is established on the ciphertext column, the time consumption is only about 1 s.
[0068] As can be seen from the above, the retrieval algorithm I first compares the exponent parts, and the comparison of positive and negative numbers can also be directly carried out through the exponent parts. For two numerical values with a difference in order of magnitude or a mixed comparison of positive and negative numbers, the result can be quickly returned. When the exponent parts are exactly the same, the comparison of the mantissa part vectors is continued. The fast modulus operation and the discovery of different values will directly return the comparison result. The optional retrieval algorithm II supports directly reusing the comparison ability of SQL and can complete the retrieval without modifying the database. At the same time, since the ciphertext after floating-point number encryption is still a floating-point number, a relatively high retrieval efficiency can still be maintained during range retrieval, and it also supports establishing an index on the ciphertext column to accelerate.
[0069] See Figure 3 shown, an embodiment of the present invention discloses a data encryption and search device, which is applied to a database proxy and includes:
[0070] An encoded data acquisition module 11, configured to encode the plaintext data of the transaction amount sent by the client using an encoding function to obtain target encoded data;
[0071] A target ciphertext sending module 12, configured to encrypt the target encoded data to obtain a corresponding target ciphertext, and send the target ciphertext to the database server so that the database server stores the target ciphertext in the ciphertext database;
[0072] A search interval encryption module 13, configured to encrypt the search interval corresponding to the plaintext data of the transaction amount into a search interval of the target ciphertext;
[0073] A search result return module 14 is configured to determine the encryption method of the target ciphertext, and determine the identification serial number corresponding to the ciphertext that meets the preset search range condition through the database server, the search range of the target ciphertext, and the ciphertext database according to the encryption method, and return the search result determined based on the identification serial number.
[0074] In summary, in this application, the database proxy first encodes the plaintext data of the transaction amount sent by the client using an encoding function to obtain target encoded data; then encrypts the target encoded data to obtain corresponding target ciphertext, and sends the target ciphertext to the database server so that the database server stores the target ciphertext in the ciphertext database; then encrypts the search range corresponding to the plaintext data of the transaction amount into the search range of the target ciphertext; finally, determines the encryption method of the target ciphertext, and determines the identification serial number corresponding to the ciphertext that meets the preset search range condition through the database server, the search range of the target ciphertext, and the ciphertext database, and returns the search result determined based on the identification serial number. It can be seen that through the data interaction between the client, the database proxy, and the database server end, this application realizes the encryption of the plaintext data of the transaction amount, thereby ensuring the security of this information during data transmission and preventing it from being intercepted and tampered with by a third party. At the same time, there is no need to decrypt all the ciphertext before performing relevant searches, which greatly improves the retrieval efficiency and reduces the computational overhead of the system.
[0075] In some specific embodiments, the device may further be configured to generate a key, the encoding function, and a hash function determined based on the key according to security parameters; set the ciphertext database to an idle state, and set the identification serial number of the data stored in the ciphertext database to 0.
[0076] In some specific embodiments, the encoded data acquisition module 11 may specifically be configured to determine the expression of the plaintext data of the transaction amount sent by the client based on the sign bit, mantissa, exponent, and base; and obtain the target encoded data according to the expression of the plaintext data of the transaction amount and the encoding function.
[0077] In some specific embodiments, the encoded data acquisition module 11 may specifically be configured to offset the exponent in the expression to obtain an offset exponent; if the sign bit in the expression is a non - negative number, determine a first exponent based on the sum of the offset exponent and a preset offset threshold; if the sign bit in the expression is a negative number, determine a second exponent based on the difference between the preset offset threshold and the offset exponent; determine a target mantissa according to the sign bit, the base, and the mantissa; and use an encoding function to encode the plaintext data of the transaction amount based on the target mantissa and the first exponent or the second exponent to obtain target encoded data.
[0078] In some specific embodiments, the target ciphertext sending module 12 may specifically be configured to perform hash operations on the integer part and the decimal part of the target mantissa in sequence using a hash function determined based on the key to obtain corresponding integer - part hash values and decimal - part hash values; perform a hash operation on the first exponent or the second exponent using the hash function to determine an exponent hash value; determine an initial ciphertext based on the integer - part hash value, the decimal - part hash value, and the exponent hash value; determine the initial ciphertext as the target ciphertext; or perform polynomial operations on the initial ciphertext to obtain a corresponding operation result and determine the operation result as the target ciphertext.
[0079] In some specific embodiments, the search result return module 14 may specifically be configured to, if the initial ciphertext is determined as the target ciphertext, send the search interval of the target ciphertext as a search token of the target ciphertext to the database server, so that the database server compares the ciphertext data in the ciphertext database with the endpoint values of the search token using a comparison function to obtain a corresponding comparison result, and determine the identification number corresponding to the ciphertext that meets the preset search interval condition according to the comparison result; if the operation result is determined as the target ciphertext, convert the plaintext structured query statement of the search interval corresponding to the plaintext data of the transaction amount into a ciphertext structured query statement, and send the ciphertext structured query statement to the database server, so that the database server executes the ciphertext structured query statement to obtain the identification number corresponding to the ciphertext that meets the preset search interval condition.
[0080] In some specific embodiments, the target ciphertext sending module 12 may specifically be configured to send the target ciphertext to the database server, so that the database server stores the target ciphertext in the ciphertext database in sequence and updates the ciphertext database to determine the identification number corresponding to the data storage of the target ciphertext.
[0081] Furthermore, the embodiments of the present application also disclose an electronic deviceFigure 4 It is a structural diagram of an electronic device 20 shown according to an exemplary embodiment. The content in the figure should not be regarded as any limitation on the scope of use of this application.
[0082] Figure 4 It is a schematic structural diagram of an electronic device 20 provided in an embodiment of this application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. Among them, the memory 22 is used to store a computer program, and the computer program is loaded and executed by the processor 21 to implement the relevant steps in the data encryption and search method disclosed in any of the foregoing embodiments. In addition, the electronic device 20 in this embodiment may specifically be an electronic computer.
[0083] In this embodiment, the power supply 23 is used to provide working voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows is any communication protocol applicable to the technical solution of this application, and no specific limitation is imposed on it here; the input / output interface 25 is used to obtain external input data or output data to the outside, and its specific interface type can be selected according to specific application needs, and no specific limitation is made here.
[0084] In addition, as a carrier for resource storage, the memory 22 may be a read-only memory, a random access memory, a magnetic disk, or an optical disc, etc. The resources stored thereon may include an operating system 221, a computer program 222, etc., and the storage method may be temporary storage or permanent storage.
[0085] Among them, the operating system 221 is used to manage and control each hardware device and the computer program 222 on the electronic device 20, and it may be Windows Server, Netware, Unix, Linux, etc. In addition to the computer program that can be used to complete the data encryption and search method executed by the electronic device 20 disclosed in any of the foregoing embodiments, the computer program 222 may further include computer programs that can be used to complete other specific tasks.
[0086] Furthermore, this application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the data encryption and search method disclosed above. For the specific steps of this method, reference may be made to the corresponding content disclosed in the foregoing embodiments, and details are not repeated here.
[0087] In this specification, the various embodiments are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the embodiments, reference can be made to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple. For the relevant parts, reference can be made to the description in the method section.
[0088] Those skilled in the art can further realize that the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the examples have been generally described according to their functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0089] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be directly implemented by hardware, software modules executed by a processor, or a combination of both. The software modules can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium well-known in the technical field.
[0090] Finally, it should also be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising one..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the element.
[0091] The technical solutions provided in this application have been introduced in detail above. Specific examples are used in this article to elaborate on the principles and implementation manners of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to this application.
Claims
1. A data encryption and search method, characterized in that, Applied to a database proxy, including: Encoding the plaintext data of the transaction amount sent by the client using an encoding function to obtain target encoded data; Encrypting the target encoded data to obtain a corresponding target ciphertext, and sending the target ciphertext to the database server so that the database server stores the target ciphertext in the ciphertext database; Encrypting the search range corresponding to the plaintext data of the transaction amount into the search range of the target ciphertext; Determining the encryption method of the target ciphertext, and determining the identification number corresponding to the ciphertext that meets the preset search range condition through the database server, the search range of the target ciphertext, and the ciphertext database according to the encryption method, and returning the search result determined based on the identification number.
2. The data encryption and search method according to claim 1, wherein Before encoding the plaintext data of the transaction amount sent by the client using the encoding function, it further includes: Generating a key, the encoding function, and a hash function determined based on the key according to security parameters; Setting the ciphertext database to an idle state and setting the identification number of the data stored in the ciphertext database to 0.
3. The data encryption and search method according to claim 2, characterized in that, Encoding the plaintext data of the transaction amount sent by the client using the encoding function to obtain target encoded data, including: Determining the expression of the plaintext data of the transaction amount sent by the client based on the sign bit, mantissa, exponent, and base; Obtaining target encoded data according to the expression of the plaintext data of the transaction amount and the encoding function.
4. The data encryption and search method according to claim 3, wherein Obtaining target encoded data according to the expression of the plaintext data of the transaction amount and the encoding function, including: Shifting the exponent in the expression to obtain a shifted exponent; If the sign bit in the expression is a non-negative number, determining a first exponent based on the sum between the shifted exponent and a preset shift threshold; If the sign bit in the expression is a negative number, determining a second exponent based on the difference between the preset shift threshold and the shifted exponent; Determining a target mantissa according to the sign bit, the base, and the mantissa; Encoding the plaintext data of the transaction amount using the encoding function based on the target mantissa and the first exponent or the second exponent to obtain target encoded data.
5. The data encryption and search method according to claim 4, wherein Encrypting the target encoded data to obtain a corresponding target ciphertext, including: Performing hash operations on the integer part and the decimal part of the target mantissa in sequence using the hash function determined based on the key to obtain a corresponding integer part hash value and decimal part hash value; Performing a hash operation on the first exponent or the second exponent using the hash function to determine an exponent hash value; Determining an initial ciphertext based on the integer part hash value, the decimal part hash value, and the exponent hash value; Determining the initial ciphertext as the target ciphertext; Or, performing a polynomial operation on the initial ciphertext to obtain a corresponding operation result, and determining the operation result as the target ciphertext.
6. The data encryption and search method according to claim 5, characterized in that, Determining the identification number corresponding to the ciphertext that meets the preset search range condition through the database server, the search range of the target ciphertext, and the ciphertext database according to the encryption method, including: If the initial ciphertext is determined as the target ciphertext, the search range of the target ciphertext is sent as a search token of the target ciphertext to the database server, so that the database server compares the ciphertext data in the ciphertext database with the endpoint values of the search token based on a comparison function, obtains corresponding comparison results, and determines the identification serial number corresponding to the ciphertext that meets the preset search range condition according to the comparison results; If the operation result is determined as the target ciphertext, the plaintext structured query statement of the search range corresponding to the plaintext data of the transaction amount is converted into a ciphertext structured query statement, and the ciphertext structured query statement is sent to the database server, so that the database server executes the ciphertext structured query statement to obtain the identification serial number corresponding to the ciphertext that meets the preset search range condition.
7. The data encryption and search method according to any one of claims 1 to 6, characterized in that, The sending the target ciphertext to the database server so that the database server stores the target ciphertext in the ciphertext database includes: Sending the target ciphertext to the database server so that the database server stores the target ciphertext in sequence in the ciphertext database and updates the ciphertext database to determine the identification serial number of the data storage corresponding to the target ciphertext.
8. A data encryption and search device, characterized in that, Applied to a database proxy, it includes: An encoded data acquisition module, configured to encode the plaintext data of the transaction amount sent by the client by using an encoding function to obtain target encoded data; A target ciphertext sending module, configured to encrypt the target encoded data to obtain a corresponding target ciphertext, and send the target ciphertext to the database server so that the database server stores the target ciphertext in the ciphertext database; A search range encryption module, configured to encrypt the search range corresponding to the plaintext data of the transaction amount into a search range of the target ciphertext; A search result return module, configured to determine the encryption method of the target ciphertext, and determine the identification serial number corresponding to the ciphertext that meets the preset search range condition through the database server, the search range of the target ciphertext, and the ciphertext database according to the encryption method, and return a search result determined based on the identification serial number.
9. An electronic device, characterized in that, It includes: A memory, configured to store a computer program; A processor, configured to execute the computer program to implement the data encryption and search method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, A computer program is stored on a computer-readable storage medium, and when the computer program is executed by a processor, the data encryption and search method according to any one of claims 1 to 7 is implemented.
Citation Information
Cited By
Precision-controllable lattice-based homomorphic encryption inner product data similarity retrieval method and system
CN121501866A