Data processing method and related equipment
By splitting and storing encrypted data on multiple devices, using threshold cipher technology, the problem of data being unable to be decrypted after user equipment is damaged or lost is solved, and the secure hosting and efficient recovery of data is achieved.
Patent Information
- Application Number
- CN202410035794.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-08
- Publication Date
- 2025-07-08
AI Technical Summary
After the user equipment is damaged or lost, the encrypted data stored in the cloud cannot be decrypted and restored, and the risk of user data leakage is caused by hosting the key to a third party.
Split the encrypted data into multiple copies and stored on different devices. Using threshold cryptography technology, only some devices need to participate in decryption to achieve secure hosting and recovery of data.
It realizes data security recovery when the device is damaged or lost, avoids key leakage, and improves the success rate and efficiency of data recovery.
Smart Images

Figure CN120281499A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data security technology, and in particular, to a data processing method and related devices. Background Art
[0002] When a user uploads user data on a terminal device to the cloud for backup, it can reduce the storage space of the terminal device occupied by the user data, enable the user data to be synchronized across devices, and when the user data on the terminal device is lost, the lost user data can be restored from the cloud. To protect user privacy, the user data is stored in the cloud in an end-to-end encrypted manner. The so-called end-to-end encryption means that the user data is encrypted and decrypted on the user's terminal device, and the key is only held by the user's device. The user data is transmitted between the terminal device and the cloud in ciphertext form and stored in the cloud in ciphertext form. Therefore, it can ensure that no data leakage occurs when the user data is synchronized and backed up through the cloud.
[0003] The key used to encrypt and decrypt user data can be stored on the user's terminal device. As long as the key is not stolen by anyone or any device outside the terminal device, the security of the user data ciphertext in the cloud can be ensured. However, once events such as terminal device damage or loss occur, the data in the cloud cannot be decrypted and restored. If the key is completely entrusted to a third party, there is a risk of user data leakage. Summary of the Invention
[0004] This application provides a data processing method and related devices to solve the security problems existing in the process of trusteeship and restoration of user's private data.
[0005] The first aspect provides a data processing method. This method can be implemented by a target device corresponding to a target user. The target device can be... The method includes: The target device obtains encrypted data stored in a first device, where the encrypted data includes first encrypted data and second encrypted data. Then, the target device respectively sends the first encrypted data to M of the N second devices, so that each of the M second devices processes the first encrypted data using the first private key stored therein to obtain intermediate data, and returns the intermediate data to the target device. After the target device obtains the intermediate data from the M second devices, it obtains target data based on the M intermediate data and the second encrypted data. Among them, the second encrypted data is the encrypted data corresponding to the target data, and the decryption key of the encrypted data includes N first private keys. The N first private keys are different, and the N first private keys are respectively stored in the N second devices. One of the N second devices stores one of the N first private keys. The first device and the N second devices are different devices. The intermediate data of each second device is obtained based on the first encrypted data and the first private key stored in the second device. N is an integer greater than or equal to 1. M is an integer greater than or equal to 1. M is an integer greater than or equal to 1, and M is less than or equal to N.
[0006] By storing the encrypted data corresponding to the target data in the first device and storing the first private keys of the encrypted data used to decrypt the encrypted data in the N second devices, and the second device and the N second devices belong to different security domains, it is possible to achieve the separation of powers between the first device and the N second devices, that is, the first device does not contact the decryption key, and the second device does not contact the ciphertext corresponding to the target data, which can ensure that neither the first device nor the N second devices can obtain the target data, and can ensure the security of the target data during the trusteeship and decryption processes. Among them, the encrypted data can be split into first encrypted data and second encrypted data. The first encrypted data can be processed by the first private key to obtain intermediate data, and then the intermediate data is used to decrypt the second encrypted data. Thus, when it is necessary to obtain the target data in the plaintext state, the second encrypted data can be decrypted to obtain the target data without sending the second encrypted data to the second device, which can ensure both the recoverability of the target data and the security of the target data.
[0007] In a possible implementation, N is an integer greater than or equal to 3; M is greater than T and less than or equal to N. T is an integer less than or equal to M and greater than 2, and T indicates the threshold number of first private keys required to decrypt the encrypted data. Thus, when it is necessary to recover the encrypted data into the target data, it is not necessary for all N second devices to participate in the recovery of the target data, which can ensure the resilience and efficiency of the target data recovery.
[0008] In a possible implementation, the encrypted data can be threshold recovered by splitting the target data. The target data corresponds to N target data shards, and the N target data shards are obtained by splitting the target data through the secret sharing method. The encrypted data includes N encrypted data shards corresponding to the N target data shards. An encrypted data shard is obtained by encrypting a target data shard with the first public key corresponding to the first private key stored in a second device. Each encrypted data shard includes 1 corresponding first encrypted data and 1 second encrypted data. Sending the first encrypted data to M second devices includes: sending the corresponding first encrypted data to each of the M second devices respectively. Thus, when recovering the target data, the first encrypted data in the encrypted data shards can be processed by the M second devices, so that the target device can recover the M encrypted data shards into M target data shards based on the intermediate data obtained by the M second devices, and further merge the M target data shards to obtain the target data. During the process of decrypting the encrypted data, the second device does not come into contact with the second encrypted data, which can ensure that the target data will not be leaked to the second device, and all N second devices do not need to participate in the decryption process, which can improve the efficiency of the decryption process and the success rate of recovering the target data.
[0009] In a possible implementation, obtaining the target data according to the M intermediate data and the second encrypted data includes: obtaining M target data shards according to the M intermediate data and the corresponding M second encrypted data. The M target data shards are data shards among the N target data shards. Then, the target data is obtained according to the M target data shards. Since the N target data shards are split based on the secret sharing method, when M is greater than or equal to T, the target data can be reconstructed based on the M target data shards. Thus, all N second devices do not need to participate in the process of recovering the target data, which can improve the success rate and efficiency of recovering the target data.
[0010] In a possible implementation, before obtaining the encrypted data stored in the first device, it further includes: receiving the first public keys corresponding to N second devices, and the first public keys corresponding to the N second devices are different. Encrypting the N target data shards with the first public keys corresponding to the N second devices respectively to obtain N encrypted data shards, and the first public key corresponding to a second device is used to encrypt a target data shard. Sending the N encrypted data shards to the first device so that the first device stores the N encrypted data shards. Encrypting the target data with the key provided by the second device and storing the encrypted data in the first device can isolate the encrypted data and the key on the device other than the target device, can avoid the leakage of the target data to non-target users, and ensure the security of the target data.
[0011] In a possible implementation, the threshold recovery of target data can be achieved by splitting the private key. The N first private keys are N private key shards corresponding to the target private key. The N private key shards are obtained by splitting the target private key through the method of secret sharing. The encrypted data is obtained by encrypting the target data with the public key corresponding to the target private key. Obtaining the target data based on the M intermediate data and the second encrypted data includes: obtaining the target intermediate data based on the M intermediate data; obtaining the target data based on the target intermediate data and the second encrypted data. The target private key is split through the method of secret sharing, and the N first private keys are respectively stored on N second devices. During the process of recovering the target data, when the number of second devices participating in the recovery of the target data is greater than or equal to T, the recovery of the target data can be achieved, thereby improving the resilience of the target data recovery.
[0012] In a possible implementation, before sending the first encrypted data to M second devices among the N second devices, it includes: performing identity authentication with the M second devices; after the identity authentication is passed, performing the step of sending the first encrypted data to M second devices among the N second devices. Sending the first encrypted data to the second device after the identity authentication is passed can ensure that the target data will not be obtained by non-target users, thereby ensuring the security of the target data.
[0013] In a possible implementation, performing identity authentication with the M second devices includes: performing identity authentication with the M second devices through video respectively. Performing identity authentication through video can simplify the recovery process of the target data and improve the decryption efficiency without the need to perform identity authentication through a third-party authentication agency while ensuring the security of the target data.
[0014] In a possible implementation, obtaining the intermediate data from the M second devices includes: receiving the encrypted intermediate data from the M second devices. The encrypted intermediate data is obtained based on the second public key and the intermediate data, and the intermediate data is in plaintext state; obtaining the intermediate data based on the second private key and the encrypted intermediate data. The second public key and the second private key are a pair of public and private key pairs. Since the intermediate data can be used to recover the target data, if the intermediate data and the encrypted data are leaked at the same time, there will be a risk of target data leakage. Therefore, after encrypting the intermediate data to obtain the encrypted intermediate data and then transmitting the encrypted intermediate data, the leakage of the intermediate data can be avoided, further ensuring the security of the target data.
[0015] The second aspect provides a data processing method. This aspect can be executed by a target device. The method includes: obtaining first public keys corresponding to N second devices; encrypting target data using the first public keys corresponding to the N second devices to obtain encrypted data, where the encrypted data includes first encrypted data and second encrypted data, the second encrypted data is the encrypted data corresponding to the target data, the decryption key of the encrypted data includes N first private keys, the N first private keys are different, the N first private keys are respectively stored in the N second devices, one of the N second devices stores one of the N first private keys, the N first private keys are used to process the first encrypted data to obtain intermediate data, and the intermediate data is used to process the second encrypted data to obtain the target data; N is an integer greater than or equal to 1; sending the encrypted data to a first device, where the first device and the N second devices are different devices.
[0016] In a possible implementation, N is an integer greater than or equal to 3; M is greater than T and less than or equal to N; T is less than or equal to M and greater than 2, and T indicates the threshold number of first private keys required to decrypt the encrypted data.
[0017] In a possible implementation, the first public keys corresponding to the N second devices are different, the target data corresponds to N target data shards, the N target data shards are obtained by splitting the target data through a secret sharing method, the encrypted data includes N encrypted data shards corresponding to the N target data shards, one encrypted data shard is obtained by encrypting one target data shard using the first public key corresponding to the first private key stored in one second device, and each encrypted data shard includes 1 corresponding first encrypted data and 1 second encrypted data.
[0018] In a possible implementation, the first public keys corresponding to the N second devices are the same, the N first private keys are N private key shards corresponding to a target private key, the N private key shards are obtained by splitting the target private key through a secret sharing method, and the target private key and the first public key are a pair of public-private key pairs.
[0019] A third aspect provides a data processing method. The method includes: a target second device receives first encrypted data, where the first encrypted data is part of the encrypted data, the encrypted data includes the first encrypted data and second encrypted data, the second encrypted data is the encrypted data corresponding to the target data, the decryption key of the encrypted data includes N first private keys, the N first private keys are different, the N first private keys are respectively stored in N second devices, one of the N second devices stores one of the N first private keys, the first device and the N second devices are different devices, and the target second device is one of the N second devices; N is an integer greater than or equal to 1. The target second device sends intermediate data, where the intermediate data is obtained according to the first encrypted data and the first private key stored in the target second device, and the intermediate data is used to recover the second encrypted data to the target data.
[0020] In a possible implementation, the method further includes: the target second device encrypts the intermediate data in plaintext state to obtain encrypted intermediate data. The target second device sending the intermediate data includes: the target second device sending the encrypted intermediate data.
[0021] A fourth aspect provides a device. The device has the functions of implementing the behaviors in the method examples of the first aspect or the second aspect, and the beneficial effects can be referred to the descriptions of the first aspect or the second aspect, which will not be elaborated here. The device may be the target device in the first aspect or the second aspect, or the device may be a device capable of supporting the target device in the first aspect or the second aspect to implement the functions required by the method provided in the first aspect, such as a chip or a chip system.
[0022] In a possible design, the device includes corresponding means or modules for executing the methods of the first aspect or the second aspect. For example, the device includes a processing unit (sometimes also called a processing module) and a transceiver unit (sometimes also called a transceiver module). These units (modules) can execute the corresponding functions in the method examples of the first aspect or the second aspect. For specific details, refer to the detailed descriptions in the method examples, which will not be elaborated here.
[0023] A fifth aspect provides a device. The device has the functions of implementing the behaviors in the method examples of the third aspect. The device may be the target second device in the third aspect, or the device may be a device capable of supporting the target device in the third aspect to implement the functions required by the method provided in the third aspect, such as a chip or a chip system.
[0024] In a possible design, the apparatus includes corresponding means or modules for performing the method of the third aspect. For example, the apparatus includes a processing unit (sometimes also referred to as a processing module) and a transceiver unit (sometimes also referred to as a transceiver module). These units (modules) can perform the corresponding functions in the method examples of the above-mentioned third aspect. For specific details, refer to the detailed description in the method examples and will not be elaborated here.
[0025] The sixth aspect provides a device. The device includes a processor and a memory. The processor is coupled to the memory and is configured to execute a data processing method as in the first aspect or any possible implementation manner of the first aspect, or a data processing method as in the second aspect or any possible implementation manner of the second aspect, or a data processing method as in the third aspect or any possible implementation manner of the third aspect, based on instructions stored in the memory.
[0026] In the seventh aspect, an embodiment of the present application provides a chip system. The chip system includes a processor and may further include a memory and / or a communication interface for implementing the methods described in the first aspect, the second aspect, or the third aspect. In a possible implementation manner, the chip system further includes a memory for storing program instructions and / or data. The chip system may be composed of chips or may include chips and other discrete devices.
[0027] In the eighth aspect, an embodiment of the present application provides a data processing system. The data processing system includes a target device for executing the method described in the first aspect and / or the second aspect and a target second device for executing the method described in the third aspect. The communication system may further include a first device.
[0028] In the ninth aspect, the present application provides a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is run, it implements the method in any one of the first aspect to the third aspect.
[0029] In the tenth aspect, a computer program product is provided. The computer program product includes computer program code, and when the computer program code is run, it causes the method in any one of the first aspect to the third aspect to be executed.
[0030] The beneficial effects of the second aspect to the tenth aspect and their implementation manners can be referred to the description of the beneficial effects of the first aspect or its implementation manners. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] Figure 1 is a schematic diagram of the architecture of a data processing system provided by the present application;
[0032] Figure 2Schematic diagram of the scenario for identity authentication via video provided by this application;
[0033] Figure 3 Schematic flow diagram of a data processing method provided by this application;
[0034] Figure 4 Schematic flow diagram of another data processing method provided by this application;
[0035] Figure 5 Schematic flow diagram of yet another data processing method provided by this application;
[0036] Figure 6 Schematic flow diagram of yet another data processing method provided by this application;
[0037] Figure 7 Schematic diagram of the structure of a device provided by this application;
[0038] Figure 8 Schematic diagram of the structure of a device provided by this application. Detailed implementation manners
[0039] Next, the technical solutions in the embodiments of this application will be described in conjunction with the accompanying drawings in the embodiments of this application. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without making creative efforts fall within the scope of protection of this application.
[0040] In the description of this application, unless otherwise specified, " / " indicates that the objects associated before and after are in an "or" relationship. For example, A / B may represent A or B; "and / or" in this application is merely a description of the association relationship of the associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. These three situations, where A and B may be singular or plural. And, in the description of this application, unless otherwise specified, "a plurality of" means two or more than two. "At least one (item)" or its similar expression below refers to any combination of these items, including any combination of a single item or plural items. For example, at least one (item) of a, b, and c may represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c may be single or multiple.
[0041] In addition, for the convenience of clearly describing the technical solutions of the embodiments of the present application, in the embodiments of the present application, terms such as "first" and "second" are used to distinguish identical or similar items with basically the same functions and roles. Those skilled in the art can understand that terms such as "first" and "second" do not limit the quantity and execution order, and "first", "second", etc. do not necessarily limit being different. At the same time, in the embodiments of the present application, words such as "exemplarily" or "for example" are used to represent examples, illustrations or explanations. Any embodiment or technical solution described as "exemplarily" or "for example" in the embodiments of the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "exemplarily" or "for example" is intended to present relevant probabilities in a specific manner for easy understanding.
[0042] The relevant algorithms involved in the embodiments of the present application are explained below to facilitate understanding by those skilled in the art.
[0043] (1) Ciphertext-splittable encryption
[0044] The ciphertext-splittable encryption scheme belongs to public-key encryption. Its ciphertext includes two parts: a message-associated component and a key-applicable component. The grammar expressions of its encryption algorithm and decryption algorithm are as follows:
[0045] Encryption: (Cm, Ck):=ENC(pk, m), where Cm is the message-associated component and Ck is the key-applicable component.
[0046] Decryption: DEC(sk, (Cm, Ck)):
[0047] InterM:=KeyAppl(sk, Ck)
[0048] m:=Recover(InterM, Cm)
[0049] Specifically, the decryption algorithm can be divided into two steps: First, the private key sk is applied to the Ck part of the ciphertext, represented by KeyAppl(sk, Ck), to generate intermediate data InterM; Second, InterM and the Cm part of the ciphertext are mixed and operated, represented by Recover(InterM, Cm), to obtain the plaintext.
[0050] Current public-key encryption schemes can all be used as ciphertext-splittable encryption schemes. The following are three specific ciphertext-splittable encryption algorithms. It can be understood that the following three ciphertext-splittable encryption algorithms are only examples, and the ciphertext-splittable encryption algorithms described in the present application may also include other ciphertext-splittable encryption algorithms.
[0051] 1. Elgamal Encryption: In the Elgamal encryption scheme, a user's public-private key pair is (y = g sk , sk ∈ Zp), where g is a generator of a multiplicative group of prime order p. The ciphertext generated by encrypting a message m is C1 = g r , C2 = m.y r , r ∈ R Zp. Accordingly, the decryption process is In fact, this scheme itself already satisfies ciphertext splittability: Cm = C2, Ck = C1; InterM = KeyAppl(sk, Ck) = (Ck)sk = (g),
[0052] 2. RSA Encryption: Let n = p.q, where p and q are large prime numbers. The user's public-private key pair is (e, d), where e.d = 1 (mod φ(n)), and φ is Euler's totient function. The ciphertext generated by encrypting a message m is C = encode(m) e (mod n), and the decryption is m = decode(Cd (mod n)). Obviously, the RSA ciphertext has only one element, so it is not ciphertext-splittable encryption itself. However, we can adopt a hybrid encryption mode to transform it into ciphertext-splittable encryption as follows:
[0053] Encryption: Select a random symmetric key k, calculate Cm = E(k, m), and then calculate Ck = encode(k) e (mod n), where E(·) is a symmetric encryption algorithm.
[0054] Decryption: First calculate InterM = k = decode(encode(k) e.d (mod n)) = KeyAppl(d, Ck), and then calculate m = Recover(InterM, Cm) = D(k, Cm), where D(·) is a symmetric decryption algorithm.
[0055] 3. Post-Quantum Encryption: Post-quantum computing encryption schemes are basically lattice-based. We present the basic form of an encryption scheme based on an unstructured lattice. Let A ∈ Zpk×n be a public matrix, where p is a prime number. The user's public-private key is (B = sk t .A + e, sk ∈ Zp k ), where sk ∈ Zp k , is a vector, and e ∈ χ is noise, where χ is a suitable noise distribution.
[0056] For a message m ∈ {0, 1}k The encryption is as follows: Select \(r\in_R\mathbb{Z}_p\) n , \(e_1, e_2\in\chi\), calculate \(C_1 = A\cdot r+e_1\), \(C_2 = B\cdot r+e_2 + m\).
[0057] The decryption is: \(m=\text{Apprx}(C_2 - sk\) t .C_1)\), where \(\text{Apprx}()\) is an approximation function.
[0058] Comparing this scheme with Elgamal encryption, we find that it can be regarded as a noisy version of Elgamal encryption. Therefore, the scheme itself can be easily transformed into ciphertext-splittable encryption: \(C_m = C_2\), \(C_k = C_1\); \(\text{InterM}=\text{KeyAppl}(sk,C_k)=sk\) t .C_k+e_3\), where \(e_3\in\chi\), \(m = \text{Recover}(\text{InterM},C_m)=\text{Apprx}(C_m-\text{InterM})\). The operations in each step are basically similar to Elgamal encryption, and the difference is that \(\text{KeyAppl}()\) needs to add an extra noise \(e_3\).
[0059] (2) Secret sharing
[0060] Let \(t,n\) be positive integers, \(t\leq n\), \(n\) is the total number of participants in the secret sharing scheme (denoted as \(P_1,\cdots,P\) n as \(n\) participants), \(t\) is the threshold. In the \((t,n)\)-Shamir secret sharing scheme, the Dealer splits a secret value into \(n\) secret shares and distributes each secret share (through a secure channel) to one of the \(n\) participants for custody; among them, any \(\geq t + 1\) participants can cooperate to recover the secret value using their secret shares, while any \(\leq t\) participants cannot calculate the secret value. The Shamir secret sharing scheme works using the Lagrange interpolation theorem.
[0061] Specifically, the \((t,n)\)–Shamir secret sharing scheme works as follows:
[0062] Assume \(q\) is a prime power, \(q > n\), let \(\mathbb{F}\) q be a finite field. Assume \(a_0\in\mathbb{F}\) q is the secret value to be shared.
[0063] Secret share generation (Distribute), perform the following operations:
[0064] In \(\mathbb{F}\) q select \(t\) random elements \(a_1,\cdots,a\) t , define the polynomial
[0065] Suppose \(\tau_1,\cdots,\tau\) n \(\in\mathbb{F}\)q n non - zero and distinct elements that are known to all n participants, such as the identification information (ID) of the participants. Calculate s j = f(τ j ) mod q, and send s j to P j , where 1 ≤ j ≤ n.
[0066] Secret Reconstruction: Perform the following operations. For any set of t + 1 participants The corresponding marking information is The secret shares held are The secret value a0 can be recovered as follows: Calculate where
[0067] Shamir LSSS is a perfectly secure ideal threshold scheme in the sense of information theory. The correctness and privacy of the scheme are guaranteed by the Lagrange interpolation theorem: For any field F, any t + 1 distinct elements τ1,…,τ t+1 , and t + 1 values s1,…,s t+1 , there exists a unique polynomial f of degree at most t over the field F such that f(τ j ) = s j , where 1 ≤ j ≤ t + 1.
[0068] (3) Threshold Cryptography
[0069] Threshold cryptography is a method to solve the above - mentioned problem: Split the private key into n (n ≥ 2) shares to form n key shares, which are distributed and stored locally and on the server. When the private key is needed for signing / decryption, t parties (2 ≤ t ≤ n) cooperate to complete the corresponding operations without reconstructing the private key at any point. The advantage of the threshold key mechanism is that as long as the adversary does not break t points, the private key cannot be restored.
[0070] Threshold cryptography is a distributed version of the public - key encryption or digital - signature scheme, that is, using (t,n) - secret sharing to split the private key into n private - key shares, and t + 1 private - key - share holders can complete the functions of the original cryptographic scheme without restoring the original private key. Threshold cryptography is a relatively mature technology. A threshold public - key encryption scheme can be divided into the following algorithms:
[0071] (PK,(SK1,…,SKn)) ← DKG(): Distributed Key Generation algorithm, that is, n participants interact to generate the public key PK and n key shares SKi using (t,n) - secret sharing; each participant holds one key share but cannot obtain information about other key shares.
[0072] C ← Enc(PK, m): The public key encryption algorithm, which is the same as the original scheme.
[0073] m ← Dec((SK1, …, SKn), C): The distributed decryption algorithm. ≥ t + 1 private key share holders complete the decryption operation through interaction without restoring the original private key. The interactive decryption process does not disclose any information of each private key share.
[0074] Using existing technologies, the aforementioned ciphertext-splittable Elgamal encryption scheme, ciphertext-splittable RSA encryption scheme, and ciphertext-splittable Lattice encryption scheme can all be easily transformed into corresponding (t, n)-threshold encryption schemes. It is worth noting that in the corresponding (t, n)-threshold encryption scheme, the decryption algorithm can still be divided into the KeyAppl() and Recover() processes. However, each private key share needs to act on the KeyAppl() algorithm separately to generate partial intermediate values InterMi, and the Recover() algorithm combines these intermediate values InterMi and Cm to calculate the plaintext.
[0075] The following gives examples of the scenarios to which the solution provided by this application can be applied. It can be understood that the solution provided by this application can also be applied in other secret trusteeship and recovery scenarios, which are not listed one by one here.
[0076] In the cloud backup scenario, the user's private data such as address books, photos, account passwords, etc. can be uploaded to the cloud server for storage. To avoid the leakage of the user's private data, the user can encrypt the private data with a key and then upload the encrypted private data to the cloud server for storage backup. Generally, this key is stored on the user's device. In the case of the loss or damage of the user's device, the key may be lost, which may lead to the inability to decrypt the encrypted private data stored in the cloud server on other user devices. To ensure that the encrypted private data stored in the cloud server can be decrypted on other user devices, the user can entrust the key to a third party for storage. When the user needs to use the key to obtain private data on other user devices, the key can be restored on other user devices with the assistance of the third party. Based on the solution provided by this application, the secure trusteeship and recovery of the key can be achieved.
[0077] In the blockchain scenario, the user's account consists of an address (public key) and a private key. The user controls the digital assets in the account by using the private key. The private key is the credential to prove the user's identity, and only through the signature of the private key can the transaction be confirmed. To avoid the leakage, theft, or loss of the blockchain private key, based on the solution provided by this application, the secure trusteeship and recovery of the key can be achieved.
[0078] Such asFigure 1 As shown Figure 1 This is a schematic diagram of the architecture of a data processing system provided by this application. The system includes a first device, N second devices, and a target device. Among them, the target device is used to encrypt the target data to obtain the encrypted data corresponding to the target data. The target device is also used to decrypt the encrypted data to obtain the target data. Among them, the target data can be a secret that the target user wants to protect and entrust, such as a password key, a private key, or other keys. The target data can also be other data, such as a file, an image, a video, or an audio, etc. The first device is used to store the encrypted data corresponding to the target data. The N second devices are used to store N first private keys, each second device stores one first private key, and the N first private keys are different. The first device and the N second devices belong to different trust domains, so as to ensure that the first device and the N second devices will not collude, and can ensure the security of the target data, that is, the target data can only be restored by the user and will not be obtained by other third parties.
[0079] The target user can perform secure hosting and restoration of the target data through the data processing system. The general process of realizing the hosting and restoration of the target data based on the data processing system is as follows: 1.1: The target device obtains the corresponding first public keys from the N second devices, and the target device uses the corresponding first public keys obtained from the N second devices to encrypt the target data to obtain the encrypted data; 1.2: The target device stores the encrypted data on the first device. The encrypted data is a splittable ciphertext, which includes the first encrypted data and the second encrypted data. The first encrypted data is not obtained by encrypting the target data, and the second encrypted data is obtained by encrypting the target data. The first encrypted data can be processed by the first private key corresponding to the first public key to obtain intermediate data, and this intermediate data can be used to decrypt the second encrypted data. 2.1: When it is necessary to restore the encrypted data to the target data, the target device obtains the encrypted data from the first device. 2.2: The target device sends the first encrypted data among them to M second devices among the N second devices. 2.3: The M second devices respectively use the first private keys stored by themselves to process the first encrypted data to obtain the corresponding intermediate data, and send the processed intermediate data to the target device. 2.4: The target device processes the second encrypted data based on the M intermediate data to restore the target data.
[0080] Specifically, the secure hosting and restoration of the target data can include stages such as a key negotiation stage, an encryption stage, and a decryption stage. The key negotiation stage and the encryption stage belong to the process of hosting the target data. The decryption stage belongs to the process of restoring the target data. The following describes the cooperation process of each device in the data processing system in the key negotiation stage, the encryption stage, and the decryption stage respectively.
[0081] In the key negotiation phase, the target device interacts with N second devices to obtain the first public keys corresponding to the N second devices. Among them, the target device / second device can be a mobile phone, a tablet computer, a computer, a wearable device, a vehicle, a drone, a helicopter, an airplane, a ship, a robot, a robotic arm, a smart home device, etc. Embodiments of the present application do not limit the specific technologies and specific device forms adopted by the target device and the second device. The target device and the second device can be devices of the same form, such as both being mobile phones or tablet computers, etc., or the target device and the second device can be devices of different forms, such as the target device being a mobile phone and the second device being a computer, which is not limited here.
[0082] The N second devices respectively store their own first public keys. In one implementation, the first public keys corresponding to the N second devices are the same public key. In another implementation, the first public keys corresponding to the N second devices are different public keys, that is, each of the N second devices corresponds to a first public key, and the first public keys corresponding to different second devices are different. The specific implementations of the first public keys corresponding to the N second devices being the same public key and the first public keys corresponding to the N second devices being different public keys will be described in detail below. In this embodiment, the N second devices also respectively store the first private keys corresponding to their own first public keys. The first public key is used to encrypt the target data, and the first private key is used to recover the target data. In this embodiment, the first private keys among the N second devices are different.
[0083] The N second devices are the devices of N auxiliary users selected by the target user to participate in recovering the target data. For example, a target application program runs on the target device and the N second devices. The target user can select N auxiliary users on the target application program running on the target device. In one implementation, the target user can determine the auxiliary users by inputting the user information of the auxiliary users on the target application program. The user information of the auxiliary users can be the account name, nickname, mobile phone number or user identification (UID) of the auxiliary users, etc. In another implementation, the target user can select N auxiliary users from the friend list displayed on the target application program.
[0084] After the target user selects N auxiliary users, the target device can send a request to the second devices corresponding to the N auxiliary users selected by the target user. In one implementation, the request is used to ask the auxiliary users whether they agree to be the auxiliary users of the target user. The request can be a text message, voice, call request, video request, etc., or the request instructs to display a pop-up window or a notification message on the second device, and asks whether to agree to be the auxiliary user of the target user through the pop-up notification message. After the auxiliary user confirms through the second device that they agree to be the auxiliary user of the target user, the second device can send the first public key corresponding to the second device to the target device. The auxiliary user can input an instruction to confirm that they agree to be the auxiliary user of the target user to the second device by means of voice, gesture, clicking the confirmation button displayed on the screen, entering text, etc. If there is a user among the auxiliary users selected by the target user who does not agree to be the auxiliary user of the target user, the second device corresponding to this user may not send the first public key to the target device. In another implementation, the public key can be publicly released without causing the leakage of the privacy of the auxiliary user. The request is used to request the first public key, that is, after the target user selects the auxiliary user, it is also possible not to ask the auxiliary user whether they agree to be the auxiliary user of the target user, but directly request the first public key corresponding to the second device of the auxiliary user, so as to improve the efficiency of obtaining the first public key.
[0085] The number N of auxiliary users can be set by the user or be the default value of the target application, which is not limited here. N can be an integer greater than or equal to 1. When N is 1 or 2, when restoring the encrypted data to the target data subsequently, the second devices corresponding to all auxiliary users need to participate. When N is greater than or equal to 3, the first public key can be used to encrypt the target data by means of threshold cryptography. When restoring the encrypted data to the target data subsequently, it is not necessary for all N second devices to participate, which can improve the resilience and efficiency of restoring the target data.
[0086] The public-private key pair (the first public key and the first private key) of the second device can be managed by a target application running on the second device. Thus, there is no need to assist the user in manually recording the first public key and the first private key, which can ensure the security of the first private key and reduce the operation difficulty of the assisting user. In a possible implementation, the first public key and the first private key of the second device are generated by a target application running on the second device. When the first public keys of N second devices are the same, the first public key can be determined through negotiation among the N second devices. For example, the N second devices interact and, based on the distributed key generation (DKG) algorithm, split the private key corresponding to the first public key into N first private keys (which can also be referred to as N key shares), and distribute the first public key and the corresponding first private key to the N second devices. The N first private keys are obtained by splitting the target private key corresponding to the first public key using the secret sharing method. Each second device holds one key share but cannot obtain information about other key shares. Examples of the secret sharing method include Shamir secret sharing, Feldman secret sharing, Pederson secret sharing, and verifiable secret sharing (VSS), etc.
[0087] In another possible implementation, the first public key and the first private key of the second device can be obtained from a trusted center of a third party, such as from a certificate authority (CA) or a registration authority (RA) in the public key infrastructure (PKI).
[0088] To further ensure that the target data is not leaked, the first public key and the first private key can be a public-private key pair generated based on the ciphertext-splittable encryption algorithm, such as the above-mentioned Elgamal encryption algorithm, RSA encryption algorithm, or post-quantum encryption algorithm, etc. Thus, the encrypted data obtained by encrypting the target data with the first public key later can be split into a key application part and a message association part.
[0089] In the encryption stage, the target device encrypts the target data using the first public key to obtain the corresponding encrypted data. Then the target device sends the encrypted data to the first device, which stores the encrypted data. The first device and the target device are different devices, so that when the target device fails or is lost, the encrypted data can be obtained from the first device to avoid loss of the encrypted data and ensure that the target data can be restored. The first device can be a private device of the target user, such as a personal computer, a tablet phone, a mobile phone, a hard disk, a removable storage device (such as a USB flash drive, an external hard disk, a CD, etc.), a network attached storage (NAS) device, a home intelligent device, etc. The first device can also be a cloud storage device, such as a cloud server, a network disk or a cloud disk, etc.
[0090] The target device can encrypt the target data in the following ways:
[0091] Encryption method 1: The first public keys of N second devices are different. The target device splits the target data into N target data shards. In a possible implementation, the target device can use the secret sharing method to split the target data into N target data shards, so that the target data can be restored using any at least T target data shards among the N target data shards. T is the threshold value of the number of target data shards required to restore the target data, that is, at least T target data shards are required to restore the target data, and the target data cannot be restored if the number of target data shards is less than T. T is an integer greater than or equal to 1 and less than or equal to N. Then the target device encrypts the N target data shards using N first public keys respectively, that is, one of the N first public keys encrypts one of the N target data shards to obtain the encrypted data, and the encrypted data includes N encrypted data shards. Optionally, the target device can use the secret sharing method to split the target data into N target data shards, so that when the encrypted data is restored to the target data, the target data can be restored based on at least T target data shards among the N target data shards. Thus, when there is a situation where an auxiliary user among the N auxiliary users replaces the device, or there is an auxiliary user who cannot participate in the restoration of the encrypted data in time, or there is an auxiliary user who refuses to participate in the restoration of the encrypted data, etc., the target user can still restore the target data. In another possible implementation, the target device may also not use the secret sharing method to split the target data into N target data shards. In this case, all N second devices need to participate in the target data restoration process.
[0092] Since the first public key is the public key generated by the ciphertext-splittable encryption algorithm, the encrypted data shard obtained by encrypting a target data shard with a first public key includes first encrypted data and second encrypted data. Among them, the first encrypted data is the part where the key can be applied, that is, this part of the encrypted data does not include the target data, and the first encrypted data can be processed by the first private key to obtain intermediate data. The second encrypted data is the message-associated part, that is, the second encrypted data is obtained by encrypting the target data shard, and the second encrypted data can be restored to the plaintext target data shard through the intermediate data.
[0093] Encryption method 2: The first public keys of N second devices are the same, and the target device uses this first public key to encrypt the target data to obtain encrypted data.
[0094] Since the first public key is the public key generated by the ciphertext-splittable encryption algorithm, the encrypted data obtained by encrypting the target data with the first public key includes first encrypted data and second encrypted data. Among them, the first encrypted data is the part where the key can be applied, that is, this part of the encrypted data does not include the ciphertext of the target data, and the first encrypted data can be processed by the first private key to obtain intermediate data. The second encrypted data is the message-associated part, that is, the second encrypted data is obtained by encrypting the target data, and the second encrypted data can be restored to the plaintext target data through the intermediate data.
[0095] After obtaining the encrypted data, the target device sends the encrypted data to the first device for storage. Alternatively, the target device imports the encrypted data into the first device for storage. Since the encryption of the target data is performed on the target device, the first device only stores the encrypted data, does not contact the key and the target data, and the second device only provides the first public key and does not contact the target data, which can ensure the security of the target data.
[0096] In the decryption phase, that is, when the target user needs to decrypt the encrypted data to restore the target data, the target device obtains the encrypted data stored in the first device and decrypts it. In one implementation, the first device is a cloud storage device. When the target device obtains the encrypted data stored in the first device, it may be that the target device downloads the encrypted data from the cloud storage device. In another implementation, the first device is a private device of the target user. When obtaining the encrypted data from the first device, it may be that the target device receives or imports the encrypted data from the first device through a hardware interface, wired or wireless means. The hardware interface is, for example, a USB interface, a serial advanced technology attachment (SATA) interface, etc. Wireless means are, for example, a wireless local area network (WLAN), Bluetooth, Near Link, or near field communication (NFC), etc.
[0097] After the target device obtains the encrypted data, it sends the first encrypted data in the encrypted data to M of the N second devices. The M second devices obtain intermediate data based on the first encrypted data and the first private key. Then the M second devices send the intermediate data to the target device, and the target device reconstructs (restores) the target data based on the intermediate data and the second encrypted data. Here, M is an integer less than or equal to N and greater than or equal to T. M can be equal to N, that is, the M second devices can be all of the N second devices. M can also be less than N, that is, the M second devices can be some of the N second devices. M is greater than or equal to the threshold T to ensure that the target data can be restored.
[0098] The target user can select M auxiliary users from the N auxiliary users through the target device to participate in the restoration of the target data and send the corresponding first encrypted data to the second devices corresponding to the M auxiliary users. To avoid the target data being obtained by non-target users due to factors such as the loss of the target device, the loss of the first device, or the theft of the encrypted data, the target user can be authenticated before restoring the target data. The target device can interact with the M second devices for identity authentication. After the identity authentication of the target user is passed, the target device sends the corresponding first encrypted data to the M second devices.
[0099] In one possible implementation, the target device and the M second devices can authenticate the target user through video. Exemplarily, such as Figure 2As shown, the target application provides a video communication function. Through the video communication function of the target application running on the target device, the user respectively initiates video connection requests to M second devices. The assisting user accepts the video connection requests from the target device through the target application on the second devices. The target device respectively establishes video connections with the M second devices. The video screen on the target device side can be displayed on the M second devices, and the video screen may include the face of the user using the target device. The assisting user can determine whether the user in the video screen is the target user through the video screen displayed on the second device, so as to authenticate the identity of the target user. If the assisting user determines that the user in the video screen is the target user, the assisting user can confirm that the target user has passed the identity authentication through the second device. The second device can send a notification of successful identity authentication to the target device, so that the target device sends the first encrypted data to the second device. There are various ways for the assisting user to confirm that the target user has passed the identity authentication through the second device. In one implementation, the assisting user can confirm that the target user has passed the identity authentication by voice. For example, the assisting user inputs voices such as "confirm" or "confirm passing the identity authentication" to the second device. The target application running on the second device determines that the target user has passed the identity authentication according to the voice of the assisting user, and then sends a notification that the target user has passed the identity authentication to the target device. In another implementation, a button for confirming passing the identity authentication can be displayed on the screen of the second device. For example, a "confirm" button can be displayed on the screen of the second device. The assisting user can click the button to confirm that the target user has passed the identity authentication. The second device responds to the operation of the user clicking the button and sends a notification that the target user has passed the identity authentication to the target device. On the same day, the assisting user can also input an instruction for confirming that the target user has passed the identity authentication to the second device through gestures, keyboards, etc., which is not limited here. It can be understood that Figure 2 The user device, the second device, the number of assisting users, and the user graphical interface in
[0100] It should be noted that in one implementation, the target device can simultaneously establish video connections with the M second devices, and the M second devices authenticate the identity of the target user in the same time period. In another implementation, the target device may not simultaneously establish video connections with the M second devices, that is, the target device can establish video connections with one or more second devices in different time periods, which is not limited here. After the M second devices all confirm that the identity authentication of the target user has passed, the target device respectively sends the first encrypted data to the M second devices to ensure that the target data will not be leaked to non-target users and ensure the security of the target data. Or, it can also be that after K of the M second devices confirm that the identity authentication of the target user has passed, the target device respectively sends the first encrypted data to the M second devices to improve the efficiency of restoring the target data.
[0101] In another possible implementation, the target device and the M second devices can also authenticate the identity of the target user through voice. In yet another possible implementation, the target device and the M second devices can also authenticate the identity through PKI. Since authenticating the identity through PKI is a prior art, it will not be elaborated here.
[0102] After the target user passes the identity authentication, the target device sends the corresponding first encrypted data to the M second devices and receives the intermediate data from the M second devices, so that the target device can recover the target data based on the M intermediate data and the second encrypted data.
[0103] For the encrypted data obtained by the above encryption method 1, it includes N first encrypted data fragments. Each encrypted data fragment is encrypted by the first public key of a second device. Each encrypted data fragment includes the corresponding first encrypted data and second encrypted data. The first encrypted data is the key-applicable part, and the second encrypted data is the encrypted data corresponding to the target data fragment. The target device sends the first encrypted data in the M encrypted data fragments to the corresponding second devices respectively. The second device corresponding to the encrypted data fragment is the second device that provides the first public key used to encrypt the target data fragment to obtain this encrypted data fragment, that is, the second device to which the first public key used to obtain this encrypted data fragment belongs. This second device holds the first private key corresponding to this first public key, so that the first encrypted data in this encrypted data fragment can be processed by the accurate first private key. After receiving the corresponding first encrypted data, the second device decrypts the first encrypted data using the first private key stored in itself to obtain the corresponding intermediate data. Then the second device sends the intermediate data to the target device. After receiving the intermediate data of the M second devices, the target device processes the corresponding second encrypted data with the M intermediate data respectively to obtain M target data fragments. Then the target device reconstructs the M target data fragments into the target data through Lagrange interpolation calculation.
[0104] The encrypted data obtained by encrypting according to the above encryption method 2, that is, the encrypted data obtained by encrypting the target data with a first public key, includes first encrypted data and second encrypted data. The first encrypted data is the key-applicable part, and the second encrypted data is the encrypted data corresponding to the target data. The target device sends the first encrypted data to M second devices respectively, that is, the first encrypted data sent by the target device to the M second devices is the same. The M second devices each store a first private key, and the M first private keys are M private key shards (key shares) among N private key shards of the first private key corresponding to the first public key (referred to as the target private key in this application). Different second devices use the first private key stored by themselves to process the first encrypted data to obtain corresponding intermediate data. Then the M second devices send the intermediate data obtained by each of them to the target device. After receiving the intermediate data of the M second devices, the target device performs a merging (reconstruction) process on the M intermediate data to obtain target intermediate data. Since the M intermediate data are obtained by processing the first encrypted data with M private key shards, the M intermediate data can be regarded as M intermediate data shards of the target intermediate data, and the target device can reconstruct the M intermediate data into the target intermediate data by Lagrange interpolation calculation. Then the target device uses the target intermediate data to process the second encrypted data to obtain the target data.
[0105] Thus, without restoring the target private key, the target device restores the encrypted data to the target data. And in the decryption stage, the second device only processes the key-applicable part (the first encrypted data) of the encrypted data and does not touch the encrypted data related to the target data. Even if M second devices collude, they cannot obtain the target data. The first device does not touch the key, and the second device does not touch the ciphertext corresponding to the target data, which can ensure that the target data will not be leaked to non-target users and guarantee the security of the target data. And when N is greater than or equal to 3, the target data or the target private key shards are shared secretly. In the decryption stage, when the number of second devices participating in decryption reaches the threshold value T, the target data can be restored, and it is not necessary for all N second devices to participate in the decryption of the encrypted data, which can improve the success rate and efficiency of restoring the target data and make the restoration of the target data resilient.
[0106] It should be noted that the target devices in the encryption phase and the decryption phase can be different devices. For example, the third device is used in the encryption phase, and the fourth device is used in the decryption phase. The third device and the fourth device can be of the same type or different types. For example, in cases where the target user loses the third device, or the third device is damaged, or the third device is replaced with the fourth device, etc., the target data in the third device may be lost. Then, the target user can import or download the encrypted data from the first device to the fourth device, obtain the intermediate data through the interaction between the target application running on the fourth device and the second device, and use the intermediate data to restore the encrypted data to the target data, so that the target data exists on the fourth device. Of course, the target devices in the encryption phase and the decryption phase can be the same device. For example, if the target device is formatted or the target data is deleted after damage repair, the target data can be restored on the target through the solution provided in this application.
[0107] As Figure 3 shown, Figure 3 FIG. is a schematic flowchart of a data processing method provided by this application. This embodiment is implemented based on Figure 1 the data processing system shown. In this embodiment, the resilience of secret recovery is ensured by splitting the target data into N target data shards and encrypting them separately. This embodiment includes the following steps:
[0108] S301: The target device obtains the first public keys of N second devices.
[0109] Each of the N second devices holds a public-private key pair (pk i , sk i ), where i is an integer greater than or equal to 1 and less than or equal to N. For any second device i among the N second devices, pk i is the first public key held by the second device i, and sk i is the first private key held by the second device i. The first public keys held by the N second devices are different, and the first private keys held by the N second devices are also different.
[0110] The N second devices are devices selected by the target device to assist in restoring the encrypted data. The process of the target device interacting with the N second devices to obtain the first public keys can refer to the relevant description of the key negotiation phase in the corresponding Figure 1 embodiment, so it will not be elaborated here.
[0111] The public-private key pair (pk i , sk iis a public-private key pair generated based on a ciphertext-splittable encryption algorithm, such as the Elgamal encryption algorithm, the RSA encryption algorithm, or a post-quantum encryption algorithm, etc. Thus, the ciphertext encrypted based on the ciphertext-splittable encryption algorithm can be split into a key-applicable part and a message-correlated part. When decrypting the ciphertext subsequently, the second device can only process the key-applicable part without obtaining the message-correlated part, which can ensure the security of the target data during transmission and decryption.
[0112] S302: The target device encrypts N target data shards corresponding to the target data using N first public keys to obtain encrypted data, where the encrypted data includes N encrypted data shards, and each encrypted data shard includes first encrypted data and second encrypted data.
[0113] The target device can split the target data s using the secret sharing method to obtain N target data shards {s i} i=1,2,...,N . Then, the target device uses N first public keys {pk i} i=1,2,...,N to encrypt the N target data shards {s i} i=1,2,...,N to obtain encrypted data including N encrypted data shards Among them, one of the N first public keys, pk i is used to encrypt one of the N target data shards, s i to obtain the corresponding encrypted data shard That is, the N first public keys and the N target data shards are in one-to-one correspondence.
[0114] Among them, any encrypted data shard in the N encrypted data shards includes first encrypted data and second encrypted data The first encrypted data is the key-applicable part, and the second encrypted data is the message-correlated part. The first encrypted data is not directly processed from the target data shard s i , that is, the first encrypted data does not contain the target data shard-related information and cannot obtain or deduce the target data shard s from the first encrypted data alone i . The second encrypted data is processed from the target data shard s i .
[0115] S303: The target device sends the encrypted data to the first device.
[0116] The target device obtains the encrypted data corresponding to the target data After that, the encrypted data is sent to the first device for storage. In this embodiment, the first device and the N second devices are different devices. Thus, it is ensured that there is isolation between the first device and the N second devices, that is, the first device and the N second devices belong to different trust domains, and the first device and the N second devices cannot collude to recover the target data. For the explanation of the first device and the interaction between the target device and the first device, reference can be made to the relevant description above, which will not be elaborated here.
[0117] S304: The first device stores the encrypted data.
[0118] In this embodiment, the first device only stores the encrypted data, and does not store the key for decrypting the encrypted data or a partial key for decrypting the encrypted data. The second device provides the key for encrypting and decrypting the target data, and does not store the encrypted data corresponding to the target data. Thus, the separation of powers between the first device and the N second devices can be realized. In the case where the first device and the N second devices belong to different trust domains, neither the first device nor the N second devices can obtain the target data, thereby ensuring that the target data will not be leaked to non-target users and ensuring the security of the target data.
[0119] S305: The target device obtains the encrypted data from the first device.
[0120] It should be noted that the target device in S301 - S303 and the target device in S305, S306, S309 - S310 both refer to the device used by the target user. The target device in S301 - S303 and the target device in S305, S306, S309 - S310 may be the same device or different devices. For example, in the case where the target device (the target device in S301 - S303) participating in encrypting the target data is lost, damaged, etc., the target user needs to recover the target data on another device, then the target device in S301 - S303 and the target device in S305, S306, S309 - S310 are different devices. For example, in the case where the target data stored in the target device participating in encrypting the target data is destroyed, such as the target data stored in the target device is deleted or the storage unit storing the target data is damaged, etc., and the target user expects to recover the target data on the target device, then the target device in S301 - S303 and the target device in S305, S306, S309 - S310 are the same device.
[0121] When the encrypted data needs to be restored to the target data, the target device obtains the encrypted data from the first device. When the first device is a cloud storage device, the target device can download the target data from the first device. When the first device is a private device of the target user, the target device can receive the encrypted data from the first device in a wired and / or wireless manner.
[0122] S306: The target device sends the corresponding first encrypted data to M second devices respectively.
[0123] Where M is an integer less than or equal to N and greater than or equal to T. T is the threshold value of the number of target data slices required to restore the target data by fragmenting the target data. When the value of N is 1 or 2, N = M = T, that is, when the number of auxiliary users selected by the target user is less than or equal to 2, all auxiliary users need to participate in decrypting the encrypted data. When the value of N is greater than or equal to 3, M can be less than or equal to N, that is, when the number of auxiliary users selected by the target user is greater than or equal to 3, all auxiliary users can participate in decrypting the encrypted data, or some users can participate.
[0124] The M second devices can be the devices corresponding to the M auxiliary users selected by the target user among the N second auxiliary users. Or, the M second devices are the devices among the N second devices that meet the conditions for assisting in decrypting the encrypted data. For example, the M second devices still hold the first private key used to process the first encrypted data. Also for example, the target user sends a request to participate in decrypting the encrypted data to the N second devices through the target device to invite the corresponding auxiliary users to assist in decrypting the encrypted data, and the M second devices are the devices of the auxiliary users who agree to participate in decrypting the encrypted data.
[0125] To ensure that the target data is not leaked to non-target users, before the target device sends the corresponding first encrypted data to the M second devices, the target device and the M second devices can also interact to authenticate the identity of the user holding the target device. After the user holding the target device passes the identity authentication, that is, after it is confirmed that the user holding the target device is the target user, the target device sends the corresponding first encrypted data to the M second devices. The target device and the M second devices can perform identity authentication through methods such as video or PKI. The identity authentication process of the target user can refer to the relevant description in the decryption stage in the relevant content above, so it will not be elaborated here. Figure 1 For the corresponding relevant description in the decryption stage in the relevant content, it will not be elaborated here.
[0126] Since the N encrypted data shards in the encrypted data are respectively obtained by encrypting with the first public keys provided by N second devices, in the process of decrypting the encrypted data shards, the corresponding first private key needs to be used to process the first encrypted data in the encrypted data shards. The encrypted data shard corresponding to the second device refers to the encrypted data shard obtained by processing the target data shard based on the first public key provided by the second device, and the first encrypted data corresponding to the second device is the first encrypted data in the encrypted data shard corresponding to the second device. For example, the second device i holds the public-private key pair (pk i , sk i ). The target device processes the target data shard s i according to the first public key pk i of the second device i to obtain the encrypted data shard The first encrypted data corresponding to the second device i is For the first encrypted data in the encrypted data shard the private key sk in the public-private key pair (pk i , sk i ) held by the second device i i needs to be used for processing in order to obtain accurate intermediate data, thereby ensuring that the target data can be successfully restored. Therefore, the target device sends the corresponding first encrypted data to the second device i so that the first encrypted data can be accurately processed by the first private key sk i .
[0127] The target device sends corresponding first encrypted data to M second devices respectively. In a possible implementation, there is an order among the N second devices. For example, the N encrypted data shards in the encrypted data are stored in the order of the corresponding second devices. Thus, the target device can determine the first encrypted data corresponding to the M second devices according to the order of the N second devices and the order of the N encrypted data shards in the encrypted data, so that the target device can accurately send the corresponding first encrypted data to the M second devices. There are various ways to determine the order of the N second devices. For example, it can be determined according to the account names, nicknames, UIDs, etc. of the corresponding auxiliary users, or it can also be determined according to the chronological order of the auxiliary users who agree to be the auxiliary users of the target user. There is no limit here. In another possible implementation, when the target device encrypts N target data shards with the first public keys of the N second devices to obtain N encrypted data shards, it can establish a mapping relationship between the second device and the corresponding encrypted data shard, and store the mapping relationship and the encrypted data in the first device. When it is necessary to recover the target data, the mapping relationship and the encrypted data can be obtained from the first device. Furthermore, the target device sends the corresponding first encrypted data to the M second devices respectively according to the mapping relationship.
[0128] In this embodiment, the target device only sends the first encrypted data to the second device, and the first encrypted data does not contain the relevant information of the target data. Therefore, in the process of recovering the target data, the second device does not come into contact with the ciphertext (the second encrypted data) corresponding to the target data. Even if the M second devices collude, they cannot recover the target data, which can ensure the security of the target data.
[0129] S307: Each of the M second devices processes the received first encrypted data with the stored first private key to obtain intermediate data.
[0130] After each of the M second devices receives the corresponding first encrypted data, it processes the received first encrypted data with the first private key stored in itself to obtain the corresponding intermediate data. For example, the private key sk i in the public-private key pair (pk i , sk i ) used by the second device i processes the received first encrypted data to obtain the intermediate data InterMi. For the implementation of processing the first encrypted data with the first private key to obtain the intermediate data, refer to the relevant description of the ciphertext-splittable encryption algorithm, which will not be elaborated here.
[0131] S308: The M second devices send the intermediate data to the target device.
[0132] After each of the M second devices calculates the intermediate data, it sends the intermediate data to the target device.
[0133] S309: The target device processes the corresponding second encrypted data among the M second encrypted data using the M intermediate data respectively to obtain M target data shards.
[0134] After the target device receives the M intermediate data {InterM i} i=1,2,...,M it processes the corresponding second encrypted data among the M second encrypted data using the M intermediate data {InterM i} i=1,2,...,M to obtain M target data shards {s i} i=1,2,...,M . For the implementation of obtaining the target data shards by processing the second encrypted data with the intermediate data, refer to the relevant description of the ciphertext-splitable encryption algorithm, which will not be elaborated here.
[0135] The second encrypted data corresponding to the intermediate data is the second encrypted data in the encrypted data shard to which the first encrypted data corresponding to this intermediate data belongs. For example, the first encrypted data corresponding to the intermediate data InterMi is this first encrypted data The encrypted data shard to which it belongs is The second encrypted data corresponding to the intermediate data InterMi is then the second encrypted data in this encrypted data shard Using the intermediate data InterM i the second encrypted data can be restored to the target data shard s i that is, the target data shard in ciphertext state is restored to the target data shard in plaintext state.
[0136] S310: The target device obtains the target data based on the M target data shards.
[0137] After the target device obtains the M target data shards, it can merge the M target data shards to obtain the target data. Specifically, the target device can reconstruct the M target data shards into the target data through Lagrange interpolation calculation.
[0138] In this embodiment, the target device encrypts the target data using the first public keys provided by N second devices to obtain encrypted data, and stores the encrypted data in the first device, realizing the separation of powers between the first device and the second devices, so that neither the first device nor the second devices can recover the target data. Moreover, the target data is split into N target data shards by means of secret sharing, and the N target data shards are encrypted respectively to obtain N encrypted data shards, such that when recovering the target data, at least T encrypted data shards among the N encrypted data shards can be recovered into target data shards, and thus the target data can be reconstructed, which can improve the resilience of target data recovery. Further, each encrypted data shard in the encrypted data is calculated based on the first public key in the ciphertext-splittable encryption algorithm, such that each encrypted data shard can be split into a first encrypted data and a second encrypted data. The first encrypted data can be processed by the first private key corresponding to the first public key to obtain intermediate data, and the intermediate data is used to process the second encrypted data to obtain the target data shard. Therefore, the target device can only send the first encrypted data to the second device without sending the ciphertext (the second encrypted data) corresponding to the target data shard to the second device. Based on the intermediate data and the second encrypted data returned by the second device, the target device can recover the target data, so that the target device can recover the target data without the second device accessing the ciphertext corresponding to the target data, which can ensure that the target data will not be leaked to non-target users and can ensure the security of the target data in the encryption stage and the decryption stage.
[0139] As Figure 4 shown, Figure 4 is a schematic flowchart of another data processing method provided by this application. This embodiment is implemented based on Figure 1 the data processing system shown. The difference between the data processing method corresponding to Figure 3 is that in this embodiment, the resilience of secret recovery is ensured by splitting the target private key into N private key shards. This embodiment includes the following steps:
[0140] S401: The target device obtains the first public keys corresponding to N second devices.
[0141] In this embodiment, the first public keys corresponding to the N second devices are the same, and the first public key and the target private key are a pair of public-private key pairs. The first public key and the target private key are generated based on the ciphertext-splittable encryption algorithm. Among the N second devices, key distribution can be realized based on DKG. Specifically, through DKG, the target private key is split into N key shares (i.e., N first private keys) {sk i} i=1,2,...,N, that is, N first private keys are the private key shards of the target private key. Then each second device distributes one of the N first private keys. Each second device holds the first public key and one first private key. The N first private keys are different. The N second devices can use the temporarily encrypted split public-private key pair or the long-term encrypted split public-private key pair, which is not restricted here.
[0142] For the process in which the target device interacts with the N second devices to obtain the first public key, reference can be made to Figure 1 the relevant description in the key negotiation phase in the corresponding embodiment, so it will not be elaborated here. Optionally, in a possible implementation manner, since the first public keys of the N second devices are the same, the target device can also interact with one of the N second devices to obtain the first public key.
[0143] S402: The target device encrypts the target data using the first public key to obtain encrypted data, where the encrypted data includes first encrypted data and second encrypted data.
[0144] In this embodiment, the target device may not fragment the target data, but use the first public key to encrypt the target data to obtain encrypted data (C m , C k ). This encrypted data (C m , C k ) includes first encrypted data C k and second encrypted data C m . The first encrypted data C k is the key-applicable part, and the second encrypted data C m is the ciphertext corresponding to the target data.
[0145] S403: The target device sends the encrypted data to the first device.
[0146] After obtaining the encrypted data (C m , C k ), the target device sends the encrypted data (C m , C k ) to the first device for storage, so as to separate the authority of the key holder (the second device) from the ciphertext trustee (the first device). Except for the target device, no other device can hold the second encrypted data and the key at the same time, thus ensuring that the target data cannot be obtained or restored by other devices and ensuring that the encrypted data is not leaked.
[0147] S404: The first device stores the encrypted data.
[0148] S405: The target device retrieves the encrypted data from the first device.
[0149] It should be noted that the target devices in S401 - S403 and those in S405, S406, S309 - S310 all refer to the devices used by the target user. The target devices in S401 - S403 and those in S305, S406, S409 - S410 may be the same device or different devices. For example, in the case where the target device (the target device in S401 - S403) participating in encrypting the target data is lost, damaged, etc., and the target user needs to recover the target data on another device, then the target devices in S401 - S403 and those in S405, S406, S409 - S410 are different devices. For example, in the case where the target data stored in the target device participating in encrypting the target data is destroyed, such as the target data stored in the target device is deleted or the storage unit storing the target data is damaged, etc., and the target user expects to recover the target data on the target device, then the target devices in S401 - S403 and those in S405, S406, S409 - S410 are the same device.
[0150] When the encrypted data needs to be restored to the target data, the target device obtains the encrypted data from the first device. When the first device is a cloud storage device, the target device can download the target data from the first device. When the first device is a private device of the target user, the target device can receive the encrypted data from the first device by wired and / or wireless means.
[0151] S406: The target device sends the first encrypted data to M second devices.
[0152] In this embodiment, the target device sends the first encrypted data C to each of the M second devices. k . Since the encrypted data is obtained by encrypting with a first public key and the target data is not split, the first encrypted data C sent by the target device to the M second devices k is the same.
[0153] S407: Each of the M second devices processes the first encrypted data with the stored first private key to obtain intermediate data.
[0154] After each second device receives the first encrypted data C k , it processes the first encrypted data with the first private key it holds to obtain the corresponding intermediate data. Since the first private keys of the M second devices are different, the obtained intermediate data is also different.
[0155] S408: The M second devices send the intermediate data to the target device.
[0156] S409: The target device obtains the target intermediate data based on the M intermediate data.
[0157] The target device receives intermediate data {InterM from M second devices i} i=1,2,...,M After that, the M pieces of intermediate data are merged to obtain the target intermediate data InterM. Since the first private keys held by the M second devices are obtained by fragmenting the target private key, the intermediate data obtained by processing the first encrypted data with the first private key can be regarded as fragments of the target intermediate data. Therefore, before using the intermediate data to process the second encrypted data, it is necessary to merge the M pieces of intermediate data to restore the target intermediate data. The target device can reconstruct the M pieces of intermediate data into the target intermediate data through Lagrange interpolation calculation.
[0158] S410: The target device obtains the target data based on the target intermediate data and the second encrypted data.
[0159] After the target device obtains the target intermediate data InterM, it uses the target intermediate data InterM to process the second encrypted data C m to obtain the target data s, completing the restoration of the target data.
[0160] In this embodiment, the target device encrypts the target data using the first public key provided by the second device to obtain the encrypted data, and stores the encrypted data in the first device, realizing the separation of powers between the first device and the second device, so that neither the first device nor the second device can restore the target data. Moreover, by using DKG to split the target private key into N first private keys, when restoring the target data, M of the N second devices can process the first encrypted data with their first private keys to obtain M pieces of intermediate data. Based on the M pieces of intermediate data and the second encrypted data, the target data can be reconstructed without restoring the target private key. When N is greater than or equal to 3, it is not necessary for all N second devices to participate in restoring the target data, which can improve the resilience of target data restoration. Further, the encrypted data is calculated based on the first public key in the ciphertext-splittable encryption algorithm, so that the encrypted data can be split into the first encrypted data and the second encrypted data. The first encrypted data can be processed by the first private key corresponding to the first public key to obtain intermediate data, and the intermediate data is used to process the second encrypted data to obtain target data fragments. Thus, the target device can only send the first encrypted data to the second device without sending the ciphertext (the second encrypted data) corresponding to the target data fragments. Based on the intermediate data and the second encrypted data returned by the second device, the target device can restore the target data. Therefore, the target device can restore the target data without the second device accessing the ciphertext corresponding to the target data, which can ensure that the target data will not be leaked to non-target users and can ensure the security of the target data in the encryption and decryption phases.
[0161] Since the intermediate data obtained by the second device through processing the first encrypted data using the first private key can be used to recover the target data, if an attacker steals the encrypted data and acts as a man-in-the-middle to steal the intermediate data when the second device interacts with the target device, the target data will be leaked. Therefore, to further improve the security of the target data, the present application also provides the following embodiments. As Figure 5 shown, Figure 5 is a schematic flowchart of another data processing method provided by the present application. Based on the corresponding data processing method embodiment in Figure 3 this embodiment, a step of the target device interacting with N second devices to exchange the keys held by the target device is added. Moreover, the second device encrypts the intermediate data using the key provided by the target device and sends the encrypted intermediate data to the target device. The key provided by the target device can be the public key in the asymmetric key or the symmetric key, and there is no limitation here. In this embodiment, an example is given where the target device provides the second public key to M second devices. This embodiment includes the following steps:
[0162] S501: The target device obtains the first public keys of N second devices.
[0163] S502: The target device uses the N first public keys to encrypt N target data shards corresponding to the target data, obtaining encrypted data, where the encrypted data includes N encrypted data shards, and each encrypted data shard includes first encrypted data and second encrypted data.
[0164] S503: The target device sends the encrypted data to the first device.
[0165] S504: The first device stores the encrypted data.
[0166] S505: The target device obtains the encrypted data from the first device.
[0167] For the descriptions of S501 - S505, reference can be made to the relevant descriptions in S301 - S305 respectively, and details are not elaborated here.
[0168] S506: The target device sends the second public key to M second devices.
[0169] It should be noted that S506 can also be executed before S501, or after S501. Alternatively, S506 can be executed before S507, or after S507. Or, S506 and S507 can be executed simultaneously, that is, the second public key and the first encrypted data corresponding to the second device i are sent to the second device i through the same message
[0170] In a possible implementation, the target device can publish a second public key to M second devices via a video connection. For example, the second public key can be announced by the target device through voice broadcast, and then the auxiliary users corresponding to the M second devices record the second public key. Alternatively, after the M second devices confirm that the target user has passed the identity authentication, the target application running on the target device generates a public-private key pair (including the second public key and the second private key), and then sends the second public key to the M second devices.
[0171] In a possible implementation, the target device can generate a pair of public-private key pairs, so that the second public keys sent by the target device to the M second devices are the same, which can reduce the implementation complexity of the target device. In another possible implementation, the target device can generate multiple pairs of public-private key pairs, and the second public keys sent to the M second devices can be different. For example, the second public keys sent by the target device to the M second devices are different from each other, or the target device groups the M second devices, with each group including one or more second devices, and the second public keys sent by the target device to the second devices within each group are the same, while the second public keys between different groups are different.
[0172] S507: The target device sends the corresponding first encrypted data to the M second devices.
[0173] S507 is similar to S306, so it will not be elaborated here.
[0174] S508: Each of the M second devices uses the stored first private key to process the received first encrypted data to obtain intermediate data.
[0175] S508 is similar to S307, so it will not be elaborated here.
[0176] S509: Each of the M second devices encrypts the obtained intermediate data using the second public key to obtain encrypted intermediate data.
[0177] Before the second device sends the intermediate data to the target device, it encrypts the intermediate data using the second public key to obtain encrypted intermediate data, thereby ensuring the security of the intermediate data during the transmission process. Even if an attacker obtains the encrypted intermediate data, they cannot decrypt it, thus being able to prevent the attacker from obtaining the target data based on the intermediate data and avoid the leakage of the target data.
[0178] S510: The M second devices send the encrypted intermediate data to the target device.
[0179] S511: The target device uses the second private key to decrypt each of the M encrypted intermediate data to obtain the M intermediate data in plaintext state.
[0180] After receiving M encrypted intermediate data, the target device decrypts each encrypted intermediate data using the second private key to obtain M intermediate data in plaintext state.
[0181] S512: The target device processes the corresponding second encrypted data among the M second encrypted data using the M intermediate data respectively to obtain M target data shards.
[0182] S512 is similar to S309, so it will not be elaborated here.
[0183] S513: The target device obtains the target data based on the M target data shards.
[0184] S513 is similar to S310, so it will not be elaborated here.
[0185] In this embodiment, the target device sends the second public key to M second devices, so that the M second devices can use the second public key to encrypt the intermediate data into encrypted intermediate data and then send it to the target device, avoiding the intermediate data being stolen or tampered with during the transmission process, improving the security of the intermediate data during the transmission process, further reducing the possibility of target data leakage, and ensuring the security of the target data.
[0186] As Figure 6 shown, Figure 6 is a schematic flowchart of another data processing method provided by this application. Based on the corresponding data processing method embodiment, this embodiment adds the step of the target device interacting with N second devices to exchange the keys held by the target device. Moreover, the second device encrypts the intermediate data using the key provided by the target device and sends the intermediate data in encrypted state to the target device. The key provided by the target device can be the public key in the asymmetric key or the symmetric key, which is not limited here. In this embodiment, the case where the target device provides the second public key to M second devices is taken as an example for illustration. This embodiment includes the following steps: Figure 4 S601: The target device obtains the first public keys corresponding to N second devices.
[0187] S602: The target device encrypts the target data using the first public key to obtain encrypted data, where the encrypted data includes first encrypted data and second encrypted data.
[0188] S603: The target device sends the encrypted data to the first device.
[0189] S604: The first device stores the encrypted data.
[0190] S605: The target device obtains the encrypted data from the first device.
[0191] S605: The target device obtains the encrypted data from the first device.
[0192] For S601 - S605, please refer to the relevant descriptions in S401 - S405 respectively, which will not be elaborated here.
[0193] S606: The target device sends the second public key to M second devices.
[0194] It should be noted that S606 can also be executed before S601, or after S601. Or, S606 can be executed before S607, or after S607. Or, S606 and S607 can be executed simultaneously, that is, the second public key and the first encrypted data C are sent to the second device i through the same message. k 。
[0195] For the method by which the target device sends the second public key to M second devices, please refer to the relevant description in S506, so it will not be elaborated here.
[0196] S607: The target device sends the first encrypted data to M second devices.
[0197] S607 is similar to S406, so it will not be elaborated here.
[0198] S608: Each of the M second devices processes the first encrypted data using the stored first private key to obtain intermediate data.
[0199] S608 is similar to S407, so it will not be elaborated here.
[0200] S609: Each of the M second devices encrypts the obtained intermediate data using the second public key to obtain encrypted intermediate data.
[0201] S610: The M second devices send the encrypted intermediate data to the target device.
[0202] S611: The target device decrypts each of the M encrypted intermediate data using the second private key to obtain M intermediate data in plaintext state.
[0203] S612: The target device obtains target intermediate data based on the M intermediate data.
[0204] S512 is similar to S409, so it will not be elaborated here.
[0205] S613: The target device obtains the target data based on the target intermediate data and the second encrypted data.
[0206] S613 is similar to S410, so it will not be elaborated here.
[0207] In this embodiment, the target device sends the second public key to M second devices, so that the M second devices can use the second public key to encrypt the intermediate data into encrypted intermediate data and then send it to the target device, avoiding the intermediate data being stolen or tampered with during the transmission process, improving the security of the intermediate data during the transmission process, further reducing the possibility of the target data leakage, and ensuring the security of the target data.
[0208] The following introduces the apparatus for implementing the above method in the embodiments of the present application with reference to the accompanying drawings.
[0209] As Figure 7 shown, Figure 7 is a schematic structural diagram of an apparatus provided by the present application. The apparatus 700 includes a processing module 701 and a transceiver module 702. This apparatus can be the above-mentioned user device or second device. For example, this apparatus can be a mobile phone, a tablet computer, a computer, a smart home device, a smart wearable device, an in-vehicle computer, a server, etc. This apparatus can also be a functional module or a hardware module (such as a chip or a chip system, etc.) in the user device, the first device or the second device.
[0210] When the apparatus 700 is an apparatus for implementing the Figures 3 - 6 steps performed by the user device in, the processing module 701 is used to obtain the encrypted data stored in the first device. The encrypted data includes the first encrypted data and the second encrypted data. The second encrypted data is the encrypted data corresponding to the target data. The decryption key of the encrypted data includes N first private keys, and the N first private keys are different. The N first private keys are respectively stored in N second devices. One of the N second devices stores one of the N first private keys. The first device and the N second devices are different devices; N is an integer greater than or equal to 1. The transceiver module 702 is used to send the first encrypted data to M second devices among the N second devices; M is an integer greater than or equal to 1; M is an integer greater than or equal to 1, and M is less than or equal to N. The processing module 701 is used to obtain the intermediate data from the M second devices. The intermediate data of each second device is obtained according to the first encrypted data and the first private key stored in the second device. The processing module 701 is used to obtain the target data according to the M intermediate data and the second encrypted data.
[0211] In a possible implementation manner, N is an integer greater than or equal to 3; M is greater than T and less than or equal to N; T is less than or equal to M and greater than 2, and T indicates the threshold number of first private keys required to decrypt the encrypted data.
[0212] In a possible implementation, the target data corresponds to N target data shards, and the N target data shards are obtained by splitting the target data through secret sharing. The encrypted data includes N encrypted data shards corresponding to the N target data shards. An encrypted data shard is obtained by encrypting a target data shard with a first public key corresponding to a first private key stored in a second device. Each encrypted data shard includes 1 corresponding first encrypted data and 1 second encrypted data. The transceiver module 702 is configured to send the corresponding first encrypted data to each of the M second devices respectively.
[0213] In a possible implementation, the processing module 701 is configured to obtain M target data shards according to the M intermediate data and the corresponding M second encrypted data, and the M target data shards are data shards among the N target data shards; and obtain the target data according to the M target data shards.
[0214] In a possible implementation, the transceiver module 702 is configured to receive the first public keys corresponding to the N second devices, and the first public keys corresponding to the N second devices are different. The processing module 701 is configured to encrypt the N target data shards respectively with the first public keys corresponding to the N second devices to obtain N encrypted data shards, and the first public key corresponding to a second device is used to encrypt a target data shard. The transceiver module 702 is configured to send the N encrypted data shards to the first device so that the first device stores the N encrypted data shards.
[0215] In a possible implementation, the N first private keys are N private key shards corresponding to the target private key, and the N private key shards are obtained by splitting the target private key through secret sharing. The encrypted data is obtained by encrypting the target data with the public key corresponding to the target private key. The processing module 701 is configured to obtain the target intermediate data according to the M intermediate data; and obtain the target data according to the target intermediate data and the second encrypted data.
[0216] In a possible implementation, the processing module 701 is configured to perform identity authentication with the M second devices; after the identity authentication is passed, the transceiver module 702 is configured to send the first encrypted data to M of the N second devices.
[0217] In a possible implementation, the processing module 701 is configured to perform identity authentication with the M second devices through video respectively.
[0218] In a possible implementation, the transceiver module 702 is configured to receive the encrypted intermediate data from the M second devices, and the encrypted intermediate data is obtained according to the second public key and the intermediate data, and the intermediate data is in plaintext state. The processing module 701 is configured to obtain the intermediate data according to the second private key and the encrypted intermediate data, and the second public key and the second private key are a pair of public-private key pairs.
[0219] In a possible implementation, a transceiver module 702 is configured to receive first public keys corresponding to N second devices. A processing module 701 is configured to encrypt target data using the first public keys corresponding to the N second devices to obtain encrypted data, where the encrypted data includes first encrypted data and second encrypted data. The second encrypted data is the encrypted data corresponding to the target data. The decryption key of the encrypted data includes N first private keys, and the N first private keys are different. The N first private keys are respectively stored in the N second devices. One of the N second devices stores one of the N first private keys. The N first private keys are used to process the first encrypted data to obtain intermediate data, and the intermediate data is used to process the second encrypted data to obtain the target data. N is an integer greater than or equal to 1.
[0220] When the device 700 is a device for implementing Figures 3 - 6 the steps executed by the second device in, the transceiver module 702 is configured to receive first encrypted data, where the first encrypted data is part of the encrypted data in the encrypted data. The encrypted data includes first encrypted data and second encrypted data. The second encrypted data is the encrypted data corresponding to the target data. The decryption key of the encrypted data includes N first private keys, and the N first private keys are different. The N first private keys are respectively stored in the N second devices. One of the N second devices stores one of the N first private keys. The first device and the N second devices are different devices. The target second device is one of the N second devices. N is an integer greater than or equal to 1. The transceiver module 702 is configured to send intermediate data, where the intermediate data is obtained according to the first encrypted data and the first private key stored in the target second device, and the intermediate data is used to restore the second encrypted data to the target data.
[0221] In a possible implementation, the processing module 701 is configured to encrypt the intermediate data in plaintext state to obtain encrypted intermediate data. The transceiver module 702 is configured to send the encrypted intermediate data.
[0222] As Figure 8 shown, Figure 8 FIG. is a schematic structural diagram of a device provided by the present application. In this embodiment, the device 800 may be a device with computing power such as a server, a server cluster, a computer, a tablet computer, a smart wearable device, a smart home device, a car computer, a smart phone, etc.
[0223] The device 800 includes a bus 801, a processor 802, a communication interface 803, and a memory 804. The processor 802, the memory 804, and the communication interface 803 communicate with each other through the bus 801.
[0224] The bus 801 can be a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, or the like. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 8 it is only represented by a thick line in Figure 8 , but this does not mean that there is only one bus or one type of bus.
[0225] The processor 802 can be any one or more of processors such as a Central Processing Unit (CPU), a Graphics Processing Unit (GPU), a Micro Processor (MP), or a Digital Signal Processor (DSP).
[0226] The memory 804 can include volatile memory, such as Random Access Memory (RAM). The memory 804 can also include non-volatile memory, such as Read-Only Memory (ROM), flash memory, a Hard Disk Drive (HDD), or a Solid State Drive (SSD).
[0227] Among them, the memory 804 can be used to store software codes related to data processing methods, and the processor 802 can execute the steps of the data processing methods or schedule other units to implement corresponding functions.
[0228] It should be understood that the data processing device 800 can be a centralized or distributed device, and the processor 802 in the data processing device 800 can be a hardware circuit (such as an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), a general-purpose processor, a digital signal processor (DSP), a microprocessor or a microcontroller, etc.), or a combination of these hardware circuits. For example, the processor can be a hardware system with the function of executing instructions, such as a CPU, a DSP, etc., or a hardware system without the function of executing instructions, such as an ASIC, an FPGA, etc., or a combination of the above hardware systems without the function of executing instructions and the hardware system with the function of executing instructions.
[0229] The present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a computer, it implements the data processing method flow of any of the above method embodiments.
[0230] Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be described herein again.
[0231] The present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a computer, it implements the data processing method flow of any of the above method embodiments.
[0232] Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be described herein again.
[0233] In several embodiments provided by the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be in an electrical or other form.
[0234] The unit described as a separation component may or may not be physically separated. The component shown as a unit may or may not be a physical unit, that is, it may be located in one place or distributed over multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0235] In addition, each functional unit in various embodiments of the present application may be integrated into a processing unit, may exist separately as individual physical units, or two or more units may be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0236] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the technical solution of the present application can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, read-only memory), random access memories (RAM, random access memory), magnetic disks, or optical discs that can store program codes.
Claims
1. A data processing method, characterized in that, The method includes: Obtaining encrypted data stored in a first device, where the encrypted data includes first encrypted data and second encrypted data, the second encrypted data being the encrypted data corresponding to target data, the decryption key of the encrypted data including N first private keys, the N first private keys being different, the N first private keys being respectively stored in N second devices, one of the N second devices storing one of the N first private keys, the first device and the N second devices being different devices; N is an integer greater than or equal to 1; Sending the first encrypted data to M of the N second devices; M is an integer greater than or equal to 1; M is an integer greater than or equal to 1 and M is less than or equal to N; Obtaining intermediate data from the M second devices, the intermediate data of each second device being obtained according to the first encrypted data and the first private key stored in the second device; Obtaining the target data according to the M intermediate data and the second encrypted data.
2. The method according to claim 1, characterized in that N is an integer greater than or equal to 3; M is an integer greater than T and less than or equal to N; T is an integer less than or equal to M and greater than 2, and T indicates the threshold number of first private keys required to decrypt the encrypted data.
3. The method according to claim 2, characterized in that, The target data corresponds to N target data shards, the N target data shards being obtained by splitting the target data through secret sharing, the encrypted data including N encrypted data shards corresponding to the N target data shards, one encrypted data shard being obtained by encrypting one target data shard with the first public key corresponding to the first private key stored in one second device, each encrypted data shard including 1 corresponding first encrypted data and 1 second encrypted data; The sending the first encrypted data to M second devices includes: Sending the corresponding first encrypted data to each of the M second devices respectively.
4. The method according to claim 3, wherein The obtaining the target data according to the M intermediate data and the second encrypted data includes: Obtaining M target data shards according to the M intermediate data and the corresponding M second encrypted data, the M target data shards being data shards among the N target data shards; Obtaining the target data according to the M target data shards.
5. The method according to claim 3 or 4, characterized in that, Before obtaining the encrypted data stored in the first device, it further includes: Receiving the first public keys corresponding to the N second devices, the first public keys corresponding to the N second devices being different; Respectively encrypting the N target data shards with the first public keys corresponding to the N second devices to obtain the N encrypted data shards, the first public key corresponding to one second device being used to encrypt one target data shard; Sending the N encrypted data shards to the first device so that the first device stores the N encrypted data shards.
6. The method according to claim 2, wherein The N first private keys are N private key shards corresponding to the target private key. The N private key shards are obtained by splitting the target private key through secret sharing. The encrypted data is obtained by encrypting the target data with the public key corresponding to the target private key. Obtaining the target data according to M pieces of the intermediate data and the second encrypted data includes: Obtaining target intermediate data according to M pieces of the intermediate data; Obtaining the target data according to the target intermediate data and the second encrypted data.
7. The method according to any one of claims 1 to 6, characterized in that, Before sending the first encrypted data to M second devices among the N second devices, it includes: Performing identity authentication with the M second devices; After the identity authentication is passed, performing the step of sending the first encrypted data to M second devices among the N second devices.
8. The method according to claim 7, characterized in that Performing the identity authentication with the M second devices includes: Performing the identity authentication with the M second devices respectively through video.
9. The method according to any one of claims 1 to 8, characterized in that, Obtaining the intermediate data from the M second devices includes: Receiving encrypted intermediate data from the M second devices. The encrypted intermediate data is obtained according to a second public key and the intermediate data, and the intermediate data is in plain text; Obtaining the intermediate data according to a second private key and the encrypted intermediate data. The second public key and the second private key are a pair of public-private key pairs.
10. A data processing method, characterized in that, The method includes: Obtaining first public keys corresponding to N second devices; Using the first public keys corresponding to the N second devices to encrypt the target data to obtain encrypted data. The encrypted data includes first encrypted data and second encrypted data. The second encrypted data is the encrypted data corresponding to the target data. The decryption key of the encrypted data includes N first private keys. The N first private keys are different. The N first private keys are respectively stored in the N second devices. One second device among the N second devices stores one of the N first private keys. The N first private keys are used to process the first encrypted data to obtain intermediate data, and the intermediate data is used to process the second encrypted data to obtain the target data; N is an integer greater than or equal to 1; Sending the encrypted data to a first device. The first device and the N second devices are different devices.
11. The method according to claim 10, wherein N is an integer greater than or equal to 3; M is an integer greater than T and less than or equal to N; T is an integer less than or equal to M and greater than 2. T indicates the threshold number of first private keys required to decrypt the encrypted data.
12. The method according to claim 11, wherein The first public keys corresponding to the N second devices are different. The target data corresponds to N target data shards. The N target data shards are obtained by splitting the target data through secret sharing. The encrypted data includes N encrypted data shards corresponding to the N target data shards. One encrypted data shard is obtained by encrypting one target data shard with the first public key corresponding to the first private key stored in one second device. Each encrypted data shard includes 1 corresponding first encrypted data and 1 second encrypted data.
13. The method according to claim 11, wherein The first public keys corresponding to the N second devices are the same. The N first private keys are N private key shards corresponding to the target private key. The N private key shards are obtained by splitting the target private key through a secret sharing method. The target private key and the first public key form a public-private key pair.
14. A data processing method, characterized in that, The method includes: The target second device receives first encrypted data. The first encrypted data is part of the encrypted data. The encrypted data includes the first encrypted data and second encrypted data. The second encrypted data is the encrypted data corresponding to the target data. The decryption key of the encrypted data includes N first private keys. The N first private keys are different. The N first private keys are respectively stored in N second devices. One of the N second devices stores one of the N first private keys. The first device and the N second devices are different devices. The target second device is one of the N second devices. N is an integer greater than or equal to 1. The target second device sends intermediate data. The intermediate data is obtained based on the first encrypted data and the first private key stored in the target second device. The intermediate data is used to recover the second encrypted data into the target data.
15. The method according to claim 14, wherein The method further includes: The target second device encrypts the intermediate data in plaintext state to obtain encrypted intermediate data. The target second device sending the intermediate data includes: The target second device sends the encrypted intermediate data.
16. A device, characterized in that, The apparatus includes a module for executing the data processing method according to any one of claims 1 to 15.
17. A device, characterized in that, The device includes a processor and a memory. The processor is coupled to the memory. The processor is configured to execute the data processing method according to any one of claims 1 - 15 based on instructions stored in the memory.
18. A readable storage medium, characterized in that, A computer program or instruction is stored in the storage medium. When the computer program or instruction is executed by a communication device, the data processing method according to any one of claims 1 to 15 is implemented.