Hidden query method and encryption method and device for realizing hidden query

Through multiple encryption and decryption processing between the service provider and the query party, encrypted key-value pairs are generated, which solves the problem of high computational complexity and security efficiency in the existing hidden query methods, and achieves efficient and secure hidden query.

CN120296773APending Publication Date: 2025-07-11ZHEJIANG LOVE ORANGE TECH DEV CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311359525.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-10-18
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

In the existing hidden query methods, the PIR scheme based on homomorphism or keywords has high computational complexity and low query efficiency. However, the PIR scheme based on M-choice 1 cannot be taken into account both the performance and security of the PIR scheme based on M-choice 1. The larger the M, the higher the security, but the lower the efficiency, and the smaller the M, the lower the security.

Method used

Through multiple encryption and decryption processing between the service provider and the query party, an encrypted key-value pair is generated, so that the service provider cannot determine the plaintext key-value pair. The query party obtains the target plaintext value without sensing the plaintext key-value pair, and uses commutational function and asymmetric encryption algorithm to improve computing efficiency.

Benefits of technology

It realizes that the queryer obtains the target plaintext value when the service provider cannot perceive the target plaintext key, which improves the query efficiency and security of hidden queries.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120296773A_ABST
    Figure CN120296773A_ABST
Patent Text Reader

Abstract

One or more embodiments of the present specification provide a hidden query method, and an encryption method and apparatus for implementing hidden query, applied to a service provider, the service provider maintaining a key value pair set, the key value pair set comprising a plurality of encrypted key value pairs, the encryption key value pair is obtained after a corresponding plaintext key value pair is sequentially subjected to first encryption processing implemented by the service party, second encryption processing implemented by a query party and first decryption processing implemented by the service party, and the first decryption processing is used for eliminating the encryption effect of the first encryption processing; the method comprises the following steps: acquiring a target encryption key sent by a query party, wherein the target encryption key is obtained after the query party implements second encryption processing on a target plaintext key; and determining an encryption key value pair matched with the target encryption key from the key value pair set, and returning a target encryption value in the determined encryption key value pair to the query party.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] One or more embodiments of this specification relate to the field of data query, and in particular, to a hidden query method and an encryption method and device for implementing hidden query. Background Art

[0002] Hidden query, also known as Private Information Retrieval (PIR), can be used to protect query conditions and query results. Its goal is to ensure that when a query request is submitted to a service party, the query is completed without the query condition information being perceived. In the key-value pair scenario, hidden query requires the service party to provide the value corresponding to a key to the query party without being able to determine the key to be queried by the query party.

[0003] In related technologies, there are two methods for implementing hidden query: one is the PIR scheme based on homomorphic or keywords, which has high computational complexity and low query efficiency; the other is the PIR scheme based on the oblivious transfer technology of selecting one from M, whose performance and security factor cannot be balanced. The larger M is, the lower the query efficiency and the higher the security. The smaller M is, the higher the query efficiency and the lower the security. Summary of the Invention

[0004] In view of this, one or more embodiments of this specification provide a hidden query method and an encryption method and device for implementing hidden query, which can solve the deficiencies in related technologies.

[0005] To achieve the above object, one or more embodiments of this specification provide the following technical solutions:

[0006] According to a first aspect of one or more embodiments of this specification, a hidden query method is proposed, which is applied to a service party. The service party maintains a key-value pair set, and the key-value pair set contains multiple encrypted key-value pairs. The encrypted key-value pairs are obtained by successively performing a first encryption process by the service party, a second encryption process by the query party, and a first decryption process by the service party on the corresponding plaintext key-value pairs, where the first decryption process is used to eliminate the encryption effect of the first encryption process; the method includes:

[0007] Obtain a target encrypted key sent by the query party, where the target encrypted key is obtained by the query party performing the second encryption process on a target plaintext key;

[0008] Determine an encrypted key-value pair that matches the target encrypted key from the key-value pair set, and return the target encrypted value in the determined encrypted key-value pair to the query party.

[0009] According to a second aspect of one or more embodiments of the present specification, an encryption method for implementing a concealed query is proposed, which is applied to a service provider. The service provider maintains a plurality of plaintext key-value pairs. The method includes:

[0010] Perform a first encryption process on the plurality of plaintext key-value pairs, and send the key-value pairs obtained from the first encryption process to a querying party, so that the querying party performs a second encryption process on the received key-value pairs;

[0011] Perform a first decryption process on the key-value pairs obtained from the second encryption process to obtain a plurality of encrypted key-value pairs; wherein, the first decryption process is used to eliminate the encryption effect of the first encryption process;

[0012] Save a key-value pair set containing the plurality of encrypted key-value pairs for querying a corresponding target encrypted value according to a target encrypted key provided by the querying party; wherein, the target encrypted key is obtained after the querying party performs the second encryption process on a target plaintext key.

[0013] According to a third aspect of one or more embodiments of the present specification, a concealed query method is proposed, which is applied to a querying party. The method includes:

[0014] Perform a second encryption process on a target plaintext key to obtain a target encrypted key, and send the target encrypted key to the service provider; wherein, the service provider maintains a key-value pair set, the key-value pair set contains a plurality of encrypted key-value pairs, and the encrypted key-value pairs are obtained after the corresponding plaintext key-value pairs are successively subjected to a first encryption process performed by the service provider, a second encryption process performed by the querying party, and a first decryption process performed by the service provider. The first decryption process is used to eliminate the encryption effect of the first encryption process;

[0015] When the service provider determines an encrypted key-value pair that matches the target encrypted key from the key-value pair set, receive the target encrypted value in the encrypted key-value pair that matches the target encrypted key returned by the service provider

[0016] According to a fourth aspect of one or more embodiments of the present specification, an encryption method for implementing a concealed query is proposed, which is applied to a querying party. The method includes:

[0017] Receive key-value pairs sent by the service provider; wherein, the service provider maintains a plurality of plaintext key-value pairs, and the received key-value pairs are obtained after the service provider performs a first encryption process on the plurality of plaintext key-value pairs;

[0018] After performing a second encryption process on the received key-value pairs, send them to the service provider, so that the service provider obtains multiple encrypted key-value pairs through a first decryption process and saves them in a key-value pair set. The key-value pair set is used by the service provider to query the corresponding target encrypted value according to the target encrypted key provided by the querying party; wherein, the first decryption process is used to eliminate the encryption effect of the first encryption process, and the target encrypted key is obtained after the querying party performs the second encryption process on the target plaintext key.

[0019] According to a fifth aspect of one or more embodiments of the present specification, a hidden query system is proposed. The system includes a querying party and a service provider. The service provider maintains a key-value pair set, and the key-value pair set contains multiple encrypted key-value pairs. The encrypted key-value pairs are obtained after the corresponding plaintext key-value pairs are successively subjected to a first encryption process performed by the service provider, a second encryption process performed by the querying party, and a first decryption process performed by the service provider. The first decryption process is used to eliminate the encryption effect of the first encryption process; wherein:

[0020] The querying party is used to perform a second encryption process on the target plaintext key to obtain a target encrypted key, and send the target encrypted key to the service provider;

[0021] The service provider is used to determine the encrypted key-value pair that matches the target encrypted key from the key-value pair set, and return the target encrypted value in the determined encrypted key-value pair to the querying party.

[0022] According to a sixth aspect of one or more embodiments of the present specification, an encryption system for implementing a hidden query is proposed. The system includes a querying party and a service provider; wherein:

[0023] The querying party is used to perform a second encryption process on the key-value pairs received from the service provider, and return the key-value pairs obtained through the second encryption process to the service provider; wherein, the received key-value pairs are obtained after the service provider performs a first encryption process on multiple plaintext key-value pairs maintained by it;

[0024] The service provider is used to perform a first decryption process on the key-value pairs after the second encryption process to obtain multiple encrypted key-value pairs, and save a key-value pair set containing the multiple encrypted key-value pairs for querying the corresponding target encrypted value according to the target encrypted key provided by the querying party; wherein, the first decryption process is used to eliminate the encryption effect of the first encryption process, and the target encrypted key is obtained after the querying party performs the second encryption process on the target plaintext key.

[0025] According to a seventh aspect of one or more embodiments of the present specification, an electronic device is proposed, including:

[0026] A processor;

[0027] A memory for storing processor-executable instructions;

[0028] Wherein, the processor realizes the steps of the method described in the first aspect or the second aspect by running the executable instructions.

[0029] According to the eighth aspect of one or more embodiments of this specification, a computer-readable storage medium is provided, on which computer instructions are stored, and when the instructions are executed by a processor, the steps of the method described in the first aspect or the second aspect are realized.

[0030] According to the ninth aspect of one or more embodiments of this specification, a computer program is provided, and when the program is executed by a processor, the steps of the method described in the first aspect or the second aspect are realized.

[0031] As can be seen from the above technical solutions, in the stealth query method provided by one or more embodiments of this specification, the service party maintains not plaintext key-value pairs, but encrypted key-value pairs, and the encrypted key-value pairs are obtained by successively performing a first encryption process implemented by the service party, a second encryption process implemented by the query party, and a first decryption process implemented by the service party on the corresponding plaintext key-value pairs. Since the first decryption process can eliminate the encryption effect of the first encryption process, the generation process of the encrypted key-value pairs is equivalent to the query party performing a second encryption process on the plaintext key-value pairs without perceiving the plaintext key-value pairs, and the service party cannot decrypt the second encryption process, that is, the service party cannot determine the plaintext key-value pairs corresponding to the encrypted key-value pairs. On the one hand, when the query party has a query requirement, it only needs to provide the service party with the target encrypted key obtained by performing a second encryption process on the target plaintext key to be queried, and the service party can return the target encrypted value matching the target encrypted key, so that the query party can perform a second decryption process corresponding to the second encryption process on the target encrypted value to obtain the target plaintext value, thereby enabling the query party to obtain the target plaintext value without the service party perceiving the target plaintext key, that is, realizing stealth query; on the other hand, in the above stealth query process, the service party only needs to find the encrypted key-value pair in the key-value pair set that matches the target encrypted key and return the target encrypted value in the determined encrypted key-value pair to the query party. The computational complexity of this process is small, thereby improving the query efficiency of the stealth query. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] Figure 1 is an architecture diagram of a data query system provided by an exemplary embodiment.

[0033] Figure 2 is a flowchart of a stealth query method provided by an exemplary embodiment.

[0034] Figure 3It is a flowchart of an encryption method for implementing a stealth query provided by an exemplary embodiment.

[0035] Figure 4 It is a schematic diagram of a scrambling process provided by an exemplary embodiment.

[0036] Figure 5 It is a flowchart of another stealth query method provided by an exemplary embodiment.

[0037] Figure 6 It is a flowchart of another encryption method for implementing a stealth query provided by an exemplary embodiment.

[0038] Figure 7 It is a schematic structural diagram of a device provided by an exemplary embodiment.

[0039] Figure 8 It is a block diagram of a stealth query device provided by an exemplary embodiment.

[0040] Figure 9 It is a block diagram of an encryption device for implementing a stealth query provided by an exemplary embodiment.

[0041] Figure 10 It is a block diagram of another stealth query device provided by an exemplary embodiment.

[0042] Figure 11 It is a block diagram of another encryption device for implementing a stealth query provided by an exemplary embodiment. Detailed implementation manners

[0043] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with one or more embodiments of this specification. On the contrary, they are only examples of devices and methods consistent with some aspects of one or more embodiments of this specification as detailed in the appended claims.

[0044] It should be noted that: In other embodiments, the steps of the corresponding methods are not necessarily executed in the order shown and described in this specification. In some other embodiments, the steps included in the method may be more or less than those described in this specification. In addition, a single step described in this specification may be decomposed into multiple steps for description in other embodiments; and multiple steps described in this specification may also be combined into a single step for description in other embodiments.

[0045] The user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this specification are all information and data authorized by the user or fully authorized by all parties. Moreover, the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of the relevant countries and regions, and corresponding operation entrances are provided for users to choose to authorize or reject.

[0046] First, some concepts involved in this specification are introduced:

[0047] Homomorphic Encryption. Homomorphic encryption is a cryptographic technology based on the computational complexity theory of mathematical problems. Its main idea is to encrypt data through an encryption function with homomorphic properties, so that any operation that can be performed on plaintext can be carried out on the encrypted data without decrypting the data. That is to say, a series of complex operations and analyses can be performed on the encrypted information without affecting its confidentiality. However, to meet the requirements of its homomorphic characteristics, the process of processing plaintext data into homomorphic ciphertext or homomorphic ciphertext into corresponding plaintext data involves relatively high computational complexity, resulting in relatively low computational efficiency.

[0048] Oblivious Transfer (OT). Oblivious transfer enables the querying party to obtain certain information input by the service party inadvertently, protecting the privacy of both the service party and the querying party. Taking the 1-out-of-M OT protocol as an example, its principle is as follows: The service party holds two pieces of information m0 and m1, the querying party inputs a selection bit b ∈ {0, 1,..., M}, and then the service party transfers the information m b to the querying party. The service party does not know which piece of information the other party has selected, and the querying party does not obtain the other M - 1 pieces of information of the other party. It can be seen that by making the value of M larger, higher security can be achieved, but it will also cause a larger amount of encrypted and decrypted data, an increase in data transmission volume, etc., resulting in a reduction in efficiency; conversely, if the value of M is reduced to improve efficiency, the security will be reduced.

[0049] Key-Value Pair. A key-value pair is the implementation of the mapping in the mathematical concept in programming languages. A set of key-value pairs includes a key and a value, where: the key is used as the index of the element, and the value represents the data stored and read.

[0050] To further illustrate one or more embodiments of this specification, the following embodiments are provided:

[0051] Figure 1It is an architecture diagram of a data query system provided by an exemplary embodiment. As Figure 1 shown, the architecture diagram includes: a query party 11 and a service party 12.

[0052] The query party 11 and the service party 12 can be any type of client device used by a user, or a physical server of an independent host, or a virtual server hosted by a host cluster. This specification does not limit this.

[0053] When there is a data query requirement, the query party 11 can send the target key to be queried to the service party 12. As Figure 1 shown, the service party 12 maintains multiple key-value pairs. The service party 12 can determine the key-value pair that matches the target key and return the value in the determined key-value pair as the target value to the query party 11. For example: If the target key is key 1, then the service party 12 can determine that the key-value pair that matches the target key is the Figure 1 first key-value pair shown, and thus determine that the target value is value 1.

[0054] The goal of the stealth query is to ensure that when the query party submits a query request to the service party, the query is completed without the query condition information being perceived. Combining Figure 1 scenarios, the stealth query requires the service party 12 to provide the query party 11 with the target value corresponding to the target key without being able to perceive the target key.

[0055] In the related art, there are two methods to implement the stealth query: one is the PIR scheme based on homomorphic or keywords, which has a high computational complexity and low query efficiency; the other is the PIR scheme based on the oblivious transfer technology of 1-out-of-M. The performance and security coefficient of this scheme cannot be balanced. The larger M is, the lower the query efficiency and the higher the security. The smaller M is, the higher the query efficiency and the lower the security.

[0056] To solve the deficiencies in the related art, this specification proposes a new stealth query method.

[0057] Figure 2 It is a flowchart of a stealth query method provided by an exemplary embodiment. As Figure 2 shown, this method is applied to the service party. The service party maintains a set of key-value pairs. The set of key-value pairs contains multiple encrypted key-value pairs. The encrypted key-value pairs are obtained by successively performing a first encryption process by the service party, a second encryption process by the query party, and a first decryption process by the service party on the corresponding plaintext key-value pairs, where the first decryption process is used to eliminate the encryption effect of the first encryption process; it may include the following steps:

[0058] Step 202: Obtain the target encryption key sent by the querying party. The target encryption key is obtained after the querying party performs the second encryption process on the target plaintext key.

[0059] Those skilled in the art should understand that the "multiple" mentioned in this specification can be specifically interpreted as "two or more". Therefore, the multiple plaintext key-value pairs mentioned above can be understood as two or more plaintext key-value pairs.

[0060] Before providing query services to the querying party, the service party and the querying party need to perform encryption and decryption processes on the key-value pairs maintained by the service party first. Figure 3 It is a flowchart of an encryption method for implementing concealed query provided by an exemplary embodiment. As Figure 3 shown, this method is applied to the service party. The service party maintains multiple plaintext key-value pairs, and may include the following steps:

[0061] Step 302: Perform the first encryption process on the multiple plaintext key-value pairs, and send the key-value pairs obtained from the first encryption process to the querying party, so that the querying party performs the second encryption process on the received key-value pairs.

[0062] For the sake of data security, the service party cannot directly send the plaintext key-value pairs it maintains to the querying party for encryption. Therefore, the service party needs to perform the first encryption process on the plaintext key-value pairs first, so that the key-value pairs received by the querying party are the key-value pairs after the first encryption process, rather than the plaintext key-value pairs. Since the querying party cannot decrypt the first encryption process performed by the service party, the data security of the plaintext key-value pairs maintained by the service party is guaranteed.

[0063] After receiving the key-value pairs obtained from the first encryption process, the querying party can perform the second encryption process on the received key-value pairs. The purpose of this second encryption process is to ensure that the service party cannot determine the plaintext key-value pairs corresponding to the key-value pairs obtained after the second encryption process.

[0064] Step 304: Perform the first decryption process on the key-value pairs obtained from the second encryption process to obtain multiple encrypted key-value pairs; wherein, the first decryption process is used to eliminate the encryption effect of the first encryption process.

[0065] The service party can obtain the key-value pairs obtained from the second encryption process from the querying party and perform the first decryption process on the obtained key-value pairs, thereby eliminating the encryption effect of the first encryption process. In other words, the encryption and decryption processes in Step 302 and Step 304 are equivalent to: ensuring that the querying party cannot obtain the plaintext key-value pairs, and the querying party performs the second encryption process on the plaintext key-value pairs maintained by the service party.

[0066] Step 306, save the key-value pair set containing the multiple encrypted key-value pairs for querying the corresponding target encrypted value according to the target encrypted key provided by the querying party; wherein, the target encrypted key is obtained after the querying party performs the second encryption process on the target plaintext key.

[0067] In this embodiment, by performing the first encryption process, the second encryption process, and the first decryption process on the plaintext key-value pair, the encrypted key-value pair is obtained, so that the service provider cannot determine the plaintext key-value pair corresponding to the encrypted key-value pair, laying a foundation for the hidden query. And during the encryption and decryption processes, the querying party does not obtain the plaintext key-value pair, ensuring the security of the data.

[0068] The target plaintext key may refer to the unencrypted key to be queried by the querying party, and the target encrypted key is obtained after the querying party performs the second encryption process on the target plaintext key.

[0069] Step 204, determine the encrypted key-value pair that matches the target encrypted key from the key-value pair set, and return the target encrypted value in the determined encrypted key-value pair to the querying party.

[0070] Since the key in the encrypted key-value pair maintained by the service provider is also obtained after the secondary encryption process performed by the querying party, if there is a plaintext key-value pair that matches the target plaintext key among the multiple plaintext key-value pairs maintained by the service provider, then there is an encrypted key-value pair that matches the target encrypted key in the key-value pair set maintained by the service provider. And since the service provider cannot decrypt the secondary encryption process performed by the querying party, the service provider cannot determine the target plaintext key corresponding to the target encrypted key, nor can it determine the plaintext key-value pair corresponding to the encrypted key-value pair.

[0071] The service provider can return the target encrypted value in the determined encrypted key-value pair to the querying party. The encrypted key-value pair is obtained by the service provider and the querying party performing encryption and decryption on the plaintext key-value pair, so the encrypted key-value pair contains the encrypted key corresponding to the plaintext key and the encrypted value corresponding to the plaintext value. The target encrypted value may be the encrypted value in the encrypted key-value pair that matches the target encrypted key. After the querying party receives the target encrypted value, the querying party can perform the second decryption process on the target encrypted value, and this second decryption process can eliminate the encryption effect of the second encryption process, thereby obtaining the corresponding target plaintext value, and this target plaintext value is the value corresponding to the unencrypted key to be queried by the querying party.

[0072] In the above process, the service provider cannot determine the target plaintext key corresponding to the target encrypted key, nor can it determine the plaintext key-value pair corresponding to the encrypted key-value pair, and the querying party finally obtains the required target plaintext value, so the hidden query is realized.

[0073] In this embodiment, the service party maintains encrypted key-value pairs instead of plaintext key-value pairs. The encrypted key-value pairs are obtained by sequentially performing a first encryption process by the service party, a second encryption process by the querying party, and a first decryption process by the service party on the corresponding plaintext key-value pairs. Since the first decryption process can eliminate the encryption effect of the first encryption process, the generation process of the encrypted key-value pairs is equivalent to the querying party performing a second encryption process on the plaintext key-value pairs without perceiving the plaintext key-value pairs, and this second encryption process cannot be decrypted by the service party, that is, the service party cannot determine the plaintext key-value pairs corresponding to the encrypted key-value pairs. On the one hand, when the querying party has a query need, it only needs to provide the target encrypted key obtained by performing a second encryption process on the target plaintext key to be queried to the service party, and the service party can return the target encrypted value that matches the target encrypted key, so that the querying party can perform a second decryption process corresponding to the second encryption process on the target encrypted value to obtain the target plaintext value, thereby enabling the querying party to obtain the target plaintext value without the service party perceiving the target plaintext key, that is, achieving a concealed query. On the other hand, in the above concealed query process, the service party only needs to find the encrypted key-value pair that matches the target encrypted key from the key-value pair set and return the target encrypted value in the determined encrypted key-value pair to the querying party. The computational complexity of this process is small, thus improving the query efficiency of the concealed query.

[0074] In one embodiment, the first encryption process and the first decryption process use a first function to encrypt and decrypt the key and a second function to encrypt and decrypt the value, and the second encryption process uses a third function to encrypt the key and a fourth function to encrypt the value; wherein, the first function and the third function satisfy the commutative law, and the second function and the fourth function satisfy the commutative law.

[0075] To intuitively explain the above encryption and decryption processes, formulas are used here for detailed description.

[0076] The first encryption process performed by the service party on the plaintext key-value pairs can specifically be: encrypting the key in the plaintext key-value pairs through a first key and a first function, and encrypting the value in the plaintext key-value pairs through a third key and a third function. The specific formulas are as follows:

[0077] c1 = f1(key, y1);

[0078] c2 = g1(value, y2);

[0079] Wherein, key represents the key in the plaintext key-value pair, value represents the value in the plaintext key-value pair, y1 represents the first key, y2 represents the third key, f1 represents the first function, g1 represents the third function, c1 represents the key in the key-value pair obtained by the first encryption process, and c2 represents the value in the key-value pair obtained by the first encryption process.

[0080] The second encryption process performed by the querying party on the key-value pairs obtained after the first encryption process can specifically be: encrypting c1 with the second key and the second function, and encrypting c2 with the fourth key and the fourth function. The specific formulas are as follows:

[0081] d1 = f2(c1, x1);

[0082] d2 = g2(c2, x2);

[0083] Among them, x1 represents the second key, x2 represents the fourth key, f2 represents the second function, g2 represents the fourth function, d1 represents the key in the key-value pairs obtained after the second encryption process, and d2 represents the value in the key-value pairs obtained after the second encryption process.

[0084] The first decryption process performed by the service party on the key-value pairs obtained after the second encryption process can specifically be: decrypting d1 with the first key and the first function, and decrypting d2 with the fourth key and the fourth function. The specific formulas are as follows:

[0085] e1 = f1(d1, y1);

[0086] e2 = g1(d2, y2);

[0087] Among them, y1 represents the first key, e1 represents the key in the encrypted key-value pairs, and e2 represents the value in the encrypted key-value pairs.

[0088] The first function and the third function satisfy the commutative law, and the second function and the fourth function satisfy the commutative law. The formulas are expressed as follows:

[0089] f1[f2(a, b), c] = f2[f1(a, c), b];

[0090] g[g2(a, b), c] = g2[g1(a, c), b];

[0091] Among them, a, b, and c are fictional variables.

[0092] Since c1 is obtained by inputting the key (key) in the plaintext key-value pairs and the first key (y1) into the first function (f1) for calculation, so inputting c1 and y1 into f1 can also calculate the key. Combining with the characteristics of the commutative law, e1 can be deduced as follows:

[0093] e1 = f1(d1, y1) = f1[f2(c1, x1), y1] = f2[f1(c1, y1), x1] = f2(key, x1);

[0094] This result can be regarded as performing a second encryption process on the key in the plaintext key-value pair through the second key and the second function. Therefore, the target encryption key can be matched with the key in the encrypted key-value pair.

[0095] Similarly, after obtaining the target encrypted value, the querying party can decrypt it through the fourth key and the fourth function, and the formula is as follows:

[0096] value = g2(e2, x2).

[0097] In this embodiment, due to the property of the commutative law, the service party and the querying party can perform encryption and decryption on the key-value pair through function operations with low computational complexity, thereby accelerating the calculation speed and improving the query efficiency of the private query.

[0098] Furthermore, the first function and the third function are irreversible functions, and the first function and / or the third function implement encryption and decryption using an asymmetric encryption algorithm.

[0099] A symmetric encryption algorithm refers to an encryption algorithm that uses the same key for encryption and decryption, and an asymmetric encryption algorithm refers to an encryption algorithm that uses different keys for encryption and decryption. Compared with the symmetric encryption algorithm, the asymmetric encryption algorithm can ensure the security of data to a greater extent. Therefore, the algorithm used for the first encryption process can be an asymmetric encryption algorithm, so as to ensure that the querying party cannot obtain the plaintext key-value pair and guarantee the security of the data. The function corresponding to the asymmetric encryption algorithm is an irreversible function.

[0100] Based on the foregoing embodiment, f1 is an irreversible function, and the first key includes a first encryption key y1 and a first decryption key y′1. The specific formula is as follows:

[0101] c1 = f1(key, y1);

[0102] e1 = f1(d1, y′1).

[0103] On this basis, the second function and the fourth function can be reversible functions, and in this case, the algorithm used for the second encryption process is a symmetric encryption algorithm; the second function and the fourth function can be irreversible functions, and in this case, the algorithm used for the second encryption process is an asymmetric encryption algorithm. This specification does not limit this.

[0104] In this embodiment, by setting the algorithm used for the first encryption and decryption process as an asymmetric encryption algorithm, it is ensured to a greater extent that the querying party cannot obtain the plaintext key-value pair, thereby guaranteeing the security of the data.

[0105] In one embodiment, the method further includes: before the service party performs a first encryption process on the plaintext key-value pair, performing a confusion process on the plaintext value in the plaintext key-value pair, so that the length relationship between the values in each of the confused plaintext key-value pairs is different from the length relationship between the original plaintext values.

[0106] In actual situations, the length relationship between the values in each encrypted key-value pair maintained by the service party may, to a certain extent, expose the corresponding plaintext key-value pair. Using the variables in the above formula: the length relationship between values corresponds to the length relationship between e2. The service party can deduce the value corresponding to e2 based on the length relationship between e2. For example, there are three plaintext key-value pairs: (1, 1), (2, 1111), (3, 2222), and the encrypted key-value pairs obtained after encryption and decryption processes are: (s, x), (h, xxxx), (q, yyyy). The service party can deduce that the plaintext key-value pair corresponding to (s, x) is (1, 1) based on the length.

[0107] The confusion process may refer to the process performed through a confusion function. The characteristics of the confusion function are:

[0108] fusion(a, b) = c;

[0109] fusionInvert(a, c) = b;

[0110] where fusion represents the confusion function, and fusionInvert represents the inverse confusion function corresponding to fusion.

[0111] Before the service party performs a first encryption process on the plaintext key-value pair, performing a confusion process on the plaintext value in the plaintext key-value pair can eliminate the influence of the length relationship between values on the concealed query. The specific formula is as follows:

[0112] c2 = g1[fusion(a, value), y2];

[0113] value = fusionInvert[g2(e2, x2), a];

[0114] where a is the confusion variable used in the confusion process, and this confusion variable needs to be negotiated and determined by the query party and the service party.

[0115] In this embodiment, by performing a confusion process on the plaintext value in the plaintext key-value pair, the length relationship between the values in each of the confused plaintext key-value pairs is different from the length relationship between the original plaintext values, thereby preventing the service party from deducing the plaintext key-value pair corresponding to the encrypted key-value pair based on the length relationship between the values in the encrypted key-value pair.

[0116] Further, the obfuscation processing of the plaintext value in the plaintext key-value pair includes: obfuscating the plaintext value in the plaintext key-value pair according to the plaintext key in the plaintext key-value pair.

[0117] The obfuscation variable in the previous embodiment can be directly set to key, and the specific formula is as follows:

[0118] c2 = g1[fusion(key, value), y2];

[0119] value = fusionInvert[g2(e2, x2), key];

[0120] This enables the querying party and the service party to avoid negotiating the obfuscation variable. On the one hand, it reduces the data transmission volume and saves network bandwidth; on the other hand, it can improve the query efficiency of the concealed query.

[0121] In one embodiment, the multiple key-value pairs obtained by the second encryption processing are provided to the service party for the first decryption processing after being shuffled by the querying party.

[0122] The service party sends the multiple key-value pairs obtained by the first decryption processing to the querying party. If the querying party returns the key-value pairs obtained by the second encryption processing to the service party in the order of receiving the key-value pairs, it may cause the service party to infer the corresponding plaintext key-value pairs based on the order of the returned key-value pairs. Therefore, the querying party needs to shuffle the multiple key-value pairs obtained after the second encryption processing before returning them to the service party.

[0123] As Figure 4 shown, assume that the service party sends three key-value pairs to the querying party, namely: the first key-value pair (1, 1), the second key-value pair (2, 2), and the third key-value pair (3, 3). The querying party can perform the second encryption processing on these three key-value pairs respectively to obtain the second encryption results: (a, a), (b, b), (c, c). Among them, (1, 1) corresponds to (a, a), (2, 2) corresponds to (b, b), and (3, 3) corresponds to (c, c). After shuffling the second encryption results and returning them to the service party, the originally ranked first (a, a) is now ranked second, the originally ranked second (b, b) is now ranked third, and the originally ranked third (c, c) is now ranked first, making it impossible for the service party to infer the corresponding plaintext key-value pairs from the order of arrangement.

[0124] In this embodiment, before the querying party returns the multiple key-value pairs obtained after the second encryption processing to the service party, by shuffling these multiple key-value pairs, the service party cannot infer the plaintext key-value pairs corresponding to the multiple key-value pairs from the order of arrangement, ensuring the concealment of the key-value pairs.

[0125] This specification also proposes a stealth query method for the querying party, as well as an encryption method for implementing stealth queries.

[0126] Figure 5 It is a flowchart of a stealth query method provided by an exemplary embodiment. As Figure 5 shown, this method is applied to the querying party and may include the following steps:

[0127] Step 502, perform a second encryption process on the target plaintext key to obtain a target encrypted key, and send the target encrypted key to the service party; wherein, the service party maintains a key-value pair set, the key-value pair set contains multiple encrypted key-value pairs, and the encrypted key-value pairs are obtained by successively performing a first encryption process implemented by the service party, a second encryption process implemented by the querying party, and a first decryption process implemented by the service party on the corresponding plaintext key-value pairs, and the first decryption process is used to eliminate the encryption effect of the first encryption process;

[0128] Step 504, when the service party determines an encrypted key-value pair that matches the target encrypted key from the key-value pair set, receive the target encrypted value in the encrypted key-value pair that matches the target encrypted key returned by the service party.

[0129] As described above, the first encryption process and the first decryption process use a first function to encrypt and decrypt the key and a second function to encrypt and decrypt the value, and the second encryption process uses a third function to encrypt the key and a fourth function to encrypt the value; wherein, the first function and the third function satisfy the commutative law, and the second function and the fourth function satisfy the commutative law.

[0130] As described above, the first function and the third function are irreversible functions, and the first function and / or the third function use an asymmetric encryption algorithm to implement encryption and decryption.

[0131] As described above, the plaintext value in the plaintext key-value pair is subjected to a confusion process by the service party and then the first encryption process is performed, so that the length relationship between the values in each confused plaintext key-value pair is different from the length relationship between the original plaintext values.

[0132] As described above, during the confusion process, the plaintext value in the plaintext key-value pair can be confused according to the plaintext key in the plaintext key-value pair.

[0133] As described above, the multiple key-value pairs obtained by the second encryption process are provided to the service party for the first decryption process after being disordered by the querying party.

[0134] In this embodiment, the service party maintains encrypted key-value pairs instead of plaintext key-value pairs. The encrypted key-value pairs are obtained by sequentially performing a first encryption process by the service party, a second encryption process by the query party, and a first decryption process by the service party on the corresponding plaintext key-value pairs. Since the first decryption process can eliminate the encryption effect of the first encryption process, the generation process of the encrypted key-value pairs is equivalent to the query party performing a second encryption process on the plaintext key-value pairs without perceiving the plaintext key-value pairs, and this second encryption process cannot be decrypted by the service party, that is, the service party cannot determine the plaintext key-value pairs corresponding to the encrypted key-value pairs. On the one hand, when the query party has a query requirement, it only needs to provide the service party with the target encrypted key obtained by performing the second encryption process on the target plaintext key to be queried. The service party can then return the target encrypted value that matches the target encrypted key, enabling the query party to perform the second decryption process corresponding to the second encryption process on the target encrypted value to obtain the target plaintext value, thereby enabling the query party to obtain the target plaintext value without the service party perceiving the target plaintext key, that is, realizing the hidden query. On the other hand, in the above hidden query process, the service party only needs to find the encrypted key-value pair in the key-value pair set that matches the target encrypted key and return the target encrypted value in the determined encrypted key-value pair to the query party. The computational complexity of this process is small, thus improving the query efficiency of the hidden query.

[0135] Figure 6 is a flowchart of an encryption method for implementing a hidden query provided by an exemplary embodiment. As Figure 6 shown, this method is applied to the query party and may include the following steps:

[0136] Step 602, receiving key-value pairs sent by the service party; wherein, the service party maintains multiple plaintext key-value pairs, and the received key-value pairs are obtained by the service party performing a first encryption process on the multiple plaintext key-value pairs.

[0137] Step 604, performing a second encryption process on the received key-value pairs and then sending them to the service party, so that the service party obtains multiple encrypted key-value pairs through a first decryption process and saves them in the key-value pair set. The key-value pair set is used by the service party to query the corresponding target encrypted value according to the target encrypted key provided by the query party; wherein, the first decryption process is used to eliminate the encryption effect of the first encryption process, and the target encrypted key is obtained by the query party performing the second encryption process on the target plaintext key.

[0138] As described above, the first encryption process and the first decryption process use a first function to encrypt and decrypt the key and a second function to encrypt and decrypt the value, and the second encryption process uses a third function to encrypt the key and a fourth function to encrypt the value; wherein, the first function and the third function satisfy the commutative law, and the second function and the fourth function satisfy the commutative law.

[0139] As described above, the first function and the third function are irreversible functions, and the first function and / or the third function use an asymmetric encryption algorithm to implement encryption and decryption.

[0140] As described above, before sending the multiple key-value pairs obtained through the second encryption process to the service party, the multiple key-value pairs obtained through the second encryption process are shuffled.

[0141] In this embodiment, by performing a first encryption process, a second encryption process, and a first decryption process on the plaintext key-value pairs, encrypted key-value pairs are obtained, so that the service party cannot determine the plaintext key-value pairs corresponding to the encrypted key-value pairs, laying a foundation for the hidden query, and the query party does not obtain the plaintext key-value pairs during the encryption and decryption process, ensuring the security of the data.

[0142] As described above, the plaintext value in the plaintext key-value pair is subjected to the first encryption process after being obfuscated by the service party, so that the length relationship between the values in each obfuscated plaintext key-value pair is different from the length relationship between the original plaintext values.

[0143] As described above, during the obfuscation process, the plaintext value in the plaintext key-value pair can be obfuscated according to the plaintext key in the plaintext key-value pair.

[0144] This specification also proposes a hidden query system including a query party and a service party. The system includes: a query party and a service party. The service party maintains a key-value pair set, and the key-value pair set includes multiple encrypted key-value pairs. The encrypted key-value pairs are obtained by sequentially performing a first encryption process implemented by the service party, a second encryption process implemented by the query party, and a first decryption process implemented by the service party on the corresponding plaintext key-value pairs, wherein the first decryption process is used to eliminate the encryption effect of the first encryption process; wherein:

[0145] The query party is used to perform a second encryption process on the target plaintext key to obtain a target encrypted key, and send the target encrypted key to the service party;

[0146] The service party is used to determine the encrypted key-value pair matching the target encrypted key from the key-value pair set, and return the target encrypted value in the determined encrypted key-value pair to the query party.

[0147] As described above, the first encryption process and the first decryption process encrypt and decrypt the key using a first function, and encrypt and decrypt the value using a second function. The second encryption process encrypts the key using a third function and encrypts the value using a fourth function. Among them, the first function and the third function satisfy the commutative law, and the second function and the fourth function satisfy the commutative law.

[0148] As described above, the first function and the third function are irreversible functions, and the first function and / or the third function implement encryption and decryption using an asymmetric encryption algorithm.

[0149] As described above, the plaintext value in the plaintext key-value pair is subjected to a confusion process by the service party and then the first encryption process is performed, so that the length relationship between the values in each plaintext key-value pair after the confusion process is different from the length relationship between the original plaintext values; and / or, the multiple key-value pairs obtained by the second encryption process are scrambled by the query party and then provided to the service party to perform the first decryption process.

[0150] As described above, during the confusion process, the plaintext value in the plaintext key-value pair can be confused according to the plaintext key in the plaintext key-value pair.

[0151] This specification also proposes an encryption system for implementing a hidden query. The system includes: a query party and a service party; where:

[0152] The query party is used to perform a second encryption process on the key-value pair received from the service party and return the key-value pair obtained by the second encryption process to the service party. Among them, the received key-value pair is obtained after the service party performs a first encryption process on multiple plaintext key-value pairs maintained.

[0153] The service party is used to perform a first decryption process on the key-value pair after the second encryption process to obtain multiple encrypted key-value pairs, and save a key-value pair set containing the multiple encrypted key-value pairs for querying a corresponding target encrypted value according to the target encrypted key provided by the query party. Among them, the first decryption process is used to eliminate the encryption effect of the first encryption process, and the target encrypted key is obtained after the query party performs the second encryption process on the target plaintext key.

[0154] As described above, the first encryption process and the first decryption process encrypt and decrypt the key using a first function, and encrypt and decrypt the value using a second function. The second encryption process encrypts the key using a third function and encrypts the value using a fourth function. Among them, the first function and the third function satisfy the commutative law, and the second function and the fourth function satisfy the commutative law.

[0155] As described above, the first function and the third function are irreversible functions, and the first function and / or the third function implement encryption and decryption using an asymmetric encryption algorithm.

[0156] As described above, the plaintext values in the plaintext key-value pairs are subjected to confusion processing by the service provider and then the first encryption processing is performed, so that the length relationship between the values in each of the confused plaintext key-value pairs is different from the length relationship between the original plaintext values; and / or, the multiple key-value pairs obtained by the second encryption processing are scrambled by the querying party and then provided to the service provider to perform the first decryption processing.

[0157] As described above, during the confusion processing, the plaintext values in the plaintext key-value pairs can be confused according to the plaintext keys in the plaintext key-value pairs.

[0158] Figure 7 is a schematic structural diagram of a device provided by an exemplary embodiment. Please refer to Figure 7 , at the hardware level, the device includes a processor 702, an internal bus 704, a network interface 706, a memory 709, and a non-volatile memory 710. Of course, there may also be other hardware required for other functions. One or more embodiments of this specification can be implemented in a software manner. For example, the processor 702 reads the corresponding computer program from the non-volatile memory 710 into the memory 708 and then runs it. Of course, in addition to the software implementation manner, one or more embodiments of this specification do not exclude other implementation manners, such as a logic device or a combination of software and hardware, etc. That is to say, the execution subject of the following processing flow is not limited to each logic unit, and can also be hardware or a logic device.

[0159] Please refer to Figure 8 , a stealth query device can be applied to a device as shown in Figure 8 to implement the technical solution of this specification. The device is applied to the service provider, and the service provider maintains a set of key-value pairs. The set of key-value pairs contains multiple encrypted key-value pairs, and the encrypted key-value pairs are obtained by successively performing the first encryption processing by the service provider, the second encryption processing by the querying party, and the first decryption processing by the service provider on the corresponding plaintext key-value pairs, where the first decryption processing is used to eliminate the encryption effect of the first encryption processing; the device may include:

[0160] An obtaining unit 802, configured to obtain a target encrypted key sent by the querying party, where the target encrypted key is obtained by the querying party performing the second encryption processing on a target plaintext key;

[0161] A feedback unit 804, configured to determine, from the set of key-value pairs, an encrypted key-value pair that matches the target encryption key, and return the target encrypted value in the determined encrypted key-value pair to the querying party.

[0162] Optionally, for the first encryption process and the first decryption process, a first function is used to encrypt and decrypt the key, and a second function is used to encrypt and decrypt the value; for the second encryption process, a third function is used to encrypt the key and a fourth function is used to encrypt the value.

[0163] Wherein, the first function and the third function satisfy the commutative law, and the second function and the fourth function satisfy the commutative law.

[0164] Optionally, the first function and the third function are irreversible functions, and the first function and / or the third function implement encryption and decryption using an asymmetric encryption algorithm.

[0165] Optionally, the method further includes:

[0166] A confusion unit 806, configured to perform a confusion process on the plaintext value in the plaintext key-value pair before the service party performs the first encryption process on the plaintext key-value pair, so that the length relationship between the values in each of the confused plaintext key-value pairs is different from the length relationship between the original plaintext values.

[0167] Optionally, the confusion unit 806 is specifically configured to:

[0168] Perform a confusion process on the plaintext value in the plaintext key-value pair according to the plaintext key in the plaintext key-value pair.

[0169] Optionally, the multiple key-value pairs obtained by the second encryption process are provided to the service party for the first decryption process after being shuffled by the querying party.

[0170] Please refer to Figure 9 , an encryption device for implementing a hidden query can be applied to a device as shown in Figure 9 to implement the technical solution of this specification. The device is applied to the service party, and the service party maintains multiple plaintext key-value pairs. The device may include:

[0171] A first implementation unit 902, configured to perform a first encryption process on the multiple plaintext key-value pairs, and send the key-value pairs obtained by the first encryption process to the querying party, so that the querying party performs a second encryption process on the received key-value pairs;

[0172] A second implementation unit 904, configured to perform a first decryption process on the key-value pairs obtained by the second encryption process to obtain multiple encrypted key-value pairs; wherein, the first decryption process is used to eliminate the encryption effect of the first encryption process.

[0173] A storage unit 906, configured to store a set of key-value pairs including the multiple encrypted key-value pairs for querying a corresponding target encrypted value according to a target encrypted key provided by the querying party; wherein, the target encrypted key is obtained after the querying party performs the second encryption process on a target plaintext key.

[0174] Optionally, for the first encryption process and the first decryption process, a first function is used to encrypt and decrypt the key, and a second function is used to encrypt and decrypt the value; for the second encryption process, a third function is used to encrypt the key, and a fourth function is used to encrypt the value.

[0175] Wherein, the first function and the third function satisfy the commutative law, and the second function and the fourth function satisfy the commutative law.

[0176] Optionally, the first function and the third function are irreversible functions, and the first function and / or the third function implement encryption and decryption using an asymmetric encryption algorithm.

[0177] As described above, the plaintext value in the plaintext key-value pair is subjected to the first encryption process after being obfuscated by the service party, so that the length relationship between the values in each obfuscated plaintext key-value pair is different from the length relationship between the original plaintext values; and / or, the multiple key-value pairs obtained after the second encryption process are provided to the service party for the first decryption process after being disordered by the querying party.

[0178] As described above, during the obfuscation process, the plaintext value in the plaintext key-value pair can be obfuscated according to the plaintext key in the plaintext key-value pair.

[0179] Please refer to Figure 10 A hidden query device can be applied to a device as shown in Figure 10 to implement the technical solution of this specification. The device is applied to the querying party; the device may include:

[0180] A sending unit 1002, configured to perform a second encryption process on a target plaintext key to obtain a target encrypted key, and send the target encrypted key to the service party; wherein, the service party maintains a set of key-value pairs, the set of key-value pairs includes multiple encrypted key-value pairs, and the encrypted key-value pairs are obtained by sequentially performing the first encryption process implemented by the service party, the second encryption process implemented by the querying party, and the first decryption process implemented by the service party on corresponding plaintext key-value pairs, and the first decryption process is used to eliminate the encryption effect of the first encryption process.

[0181] A receiving unit 1004, configured to receive a target encrypted value in the encrypted key-value pair that matches the target encryption key and is returned by the service provider when the service provider determines an encrypted key-value pair that matches the target encryption key from the set of key-value pairs.

[0182] Optionally, for the first encryption process and the first decryption process, a first function is used to encrypt and decrypt the key, and a second function is used to encrypt and decrypt the value; for the second encryption process, a third function is used to encrypt the key and a fourth function is used to encrypt the value.

[0183] Wherein, the first function and the third function satisfy the commutative law, and the second function and the fourth function satisfy the commutative law.

[0184] Optionally, the first function and the third function are irreversible functions, and the first function and / or the third function implement encryption and decryption using an asymmetric encryption algorithm.

[0185] As described above, the plaintext value in the plaintext key-value pair is subjected to the first encryption process after being obfuscated by the service provider, so that the length relationship between the values in each obfuscated plaintext key-value pair is different from the length relationship between the original plaintext values; and / or, the multiple key-value pairs obtained by the second encryption process are provided to the service provider for the first decryption process after being shuffled by the querying party.

[0186] As described above, during the obfuscation process, the plaintext value in the plaintext key-value pair can be obfuscated according to the plaintext key in the plaintext key-value pair.

[0187] Please refer to Figure 11 , an encryption device for implementing stealth query can be applied to a device as shown in Figure 11 to implement the technical solution of this specification. This device is applied to the querying party; the device may include:

[0188] A receiving unit 1102, configured to receive key-value pairs sent by a service provider; wherein, the service provider maintains multiple plaintext key-value pairs, and the received key-value pairs are obtained after the service provider performs a first encryption process on the multiple plaintext key-value pairs.

[0189] A sending unit 1104, configured to perform a second encryption process on the received key-value pairs and then send them to the service provider, so that the service provider obtains multiple encrypted key-value pairs through the first decryption process and stores them in a set of key-value pairs. The set of key-value pairs is used by the service provider to query a corresponding target encrypted value according to a target encryption key provided by the querying party; wherein, the first decryption process is used to eliminate the encryption effect of the first encryption process, and the target encryption key is obtained after the querying party performs the second encryption process on a target plaintext key.

[0190] Optionally, it further includes:

[0191] A processing unit 1106, configured to perform a scrambling process on multiple key-value pairs obtained through the second encryption process before sending the multiple key-value pairs obtained through the second encryption process to the service party.

[0192] Optionally, the first encryption process and the first decryption process use a first function to encrypt and decrypt keys and a second function to encrypt and decrypt values, and the second encryption process uses a third function to encrypt keys and a fourth function to encrypt values;

[0193] Wherein, the first function and the third function satisfy the commutative law, and the second function and the fourth function satisfy the commutative law.

[0194] Optionally, the first function and the third function are irreversible functions, and the first function and / or the third function use an asymmetric encryption algorithm to perform encryption and decryption.

[0195] As mentioned above, the plaintext value in the plaintext key-value pair is subjected to a confusion process by the service party and then the first encryption process is performed, so that the length relationship between the values in each plaintext key-value pair after the confusion process is different from the length relationship between the original plaintext values.

[0196] As mentioned above, during the confusion process, the plaintext value in the plaintext key-value pair can be confused according to the plaintext key in the plaintext key-value pair.

[0197] The system, device, module or unit illustrated in the above embodiments can be specifically implemented by a computer chip or an entity, or by a product with a certain function. A typical implementation device is a computer, and the specific form of the computer can be a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email transceiver device, a game console, a tablet computer, a wearable device, or a combination of any several of these devices.

[0198] In a typical configuration, a computer includes one or more processors (CPUs), an input / output interface, a network interface, and a memory.

[0199] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM), and / or non-volatile memory in the form of, for example, read-only memory (ROM) or flash memory (flash RAM). The memory is an example of a computer-readable medium.

[0200] A computer-readable medium includes permanent and non-permanent, removable and non-removable media that can implement information storage by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory, or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD), or other optical storage, magnetic cassette tapes, disk storage, quantum memory, graphene-based storage media, or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device. As defined herein, a computer-readable medium does not include transitory computer-readable media, such as modulated data signals and carrier waves.

[0201] Regarding the computer-readable medium (or, computer-readable storage medium) described above or in any other form, computer instructions can be stored thereon, and when executed by a processor, one or more of the above-described embodiments are implemented, thereby implementing the technical solutions of this specification.

[0202] This specification also proposes a computer program that, when executed by a processor, implements one or more of the above-described embodiments, thereby implementing the technical solutions of this specification. Among them, the computer program can be specifically recorded on the computer-readable medium described above or in any other form, and this specification does not limit this.

[0203] It should also be noted that the term "comprising", "including", or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, commodity, or device comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, commodity, or device. Without further limitation, an element defined by the statement "comprising one..." does not exclude the existence of additional identical elements in the process, method, commodity, or device comprising the said element.

[0204] The above describes specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the acts or steps recited in the claims may be performed in a different order than in the embodiments and still achieve the desired results. Additionally, the processes depicted in the figures do not necessarily require the particular order shown or sequential order to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0205] The terms used in one or more embodiments of this specification are for the purpose of describing particular embodiments only and are not intended to limit one or more embodiments of this specification. The singular forms "a", "the", and "said" used in one or more embodiments of this specification and the appended claims are also intended to include the plural forms unless the context clearly dictates otherwise. It should also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items.

[0206] It should be understood that although the terms first, second, third, etc. may be used in one or more embodiments of this specification to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other. For example, without departing from the scope of one or more embodiments of this specification, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "when" or "upon" or "in response to determining".

[0207] The above is only the preferred embodiment of one or more embodiments of this specification and is not intended to limit one or more embodiments of this specification. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of one or more embodiments of this specification shall be included within the scope of protection of one or more embodiments of this specification.

Claims

1. A method for concealed query, characterized in that, Applied to the service provider, the service provider maintains a set of key-value pairs, the set of key-value pairs includes multiple encrypted key-value pairs, and the encrypted key-value pairs are obtained by successively performing a first encryption process implemented by the service provider, a second encryption process implemented by the querying party, and a first decryption process implemented by the service provider on the corresponding plaintext key-value pairs, wherein the first decryption process is used to eliminate the encryption effect of the first encryption process; The method includes: Obtain the target encrypted key sent by the querying party, where the target encrypted key is obtained by the querying party performing the second encryption process on the target plaintext key; Determine the encrypted key-value pair that matches the target encrypted key from the set of key-value pairs, and return the target encrypted value in the determined encrypted key-value pair to the querying party.

2. The method according to claim 1, wherein The first encryption process and the first decryption process use a first function to encrypt and decrypt the key, and use a second function to encrypt and decrypt the value. The second encryption process uses a third function to encrypt the key and a fourth function to encrypt the value; Wherein, the first function and the third function satisfy the commutative law, and the second function and the fourth function satisfy the commutative law.

3. The method according to claim 2, wherein The first function and the third function are irreversible functions, and the first function and / or the third function implement encryption and decryption using an asymmetric encryption algorithm.

4. The method according to claim 1, wherein The method further includes: Before the service provider performs the first encryption process on the plaintext key-value pairs, perform a confusion process on the plaintext values in the plaintext key-value pairs, so that the length relationship between the values in each of the confused plaintext key-value pairs is different from the length relationship between the original plaintext values.

5. The method according to claim 4, wherein The performing a confusion process on the plaintext values in the plaintext key-value pairs includes: Perform a confusion process on the plaintext value in the plaintext key-value pair according to the plaintext key in the plaintext key-value pair.

6. The method according to claim 1, characterized in that The multiple key-value pairs obtained by the second encryption process are provided to the service provider to perform the first decryption process after being disordered by the querying party.

7. An encryption method for implementing hidden queries, characterized in that, Applied to the service provider, the service provider maintains multiple plaintext key-value pairs, and the method includes: Perform a first encryption process on the multiple plaintext key-value pairs, and send the key-value pairs obtained by the first encryption process to the querying party, so that the querying party performs a second encryption process on the received key-value pairs; Perform a first decryption process on the key-value pairs obtained by the second encryption process to obtain multiple encrypted key-value pairs; wherein, the first decryption process is used to eliminate the encryption effect of the first encryption process; Save the set of key-value pairs containing the multiple encrypted key-value pairs for querying the corresponding target encrypted value according to the target encrypted key provided by the querying party; wherein, the target encrypted key is obtained by the querying party performing the second encryption process on the target plaintext key.

8. A method for stealth query, characterized in that, Applied to the querying party, the method includes: Perform a second encryption process on the target plaintext key to obtain a target encryption key, and send the target encryption key to the service provider; wherein, the service provider maintains a key-value pair set, the key-value pair set contains multiple encrypted key-value pairs, and the encrypted key-value pairs are obtained by the corresponding plaintext key-value pairs after the first encryption process implemented by the service provider, the second encryption process implemented by the querying party, and the first decryption process implemented by the service provider in sequence, and the first decryption process is used to eliminate the encryption effect of the first encryption process; In the case where the service provider determines an encrypted key-value pair that matches the target encryption key from the key-value pair set, receive the target encrypted value in the encrypted key-value pair that matches the target encryption key returned by the service provider.

9. An encryption method for realizing a concealed query, characterized in that, Applied to a querying party, the method includes: Receive key-value pairs sent by the service provider; wherein, the service provider maintains multiple plaintext key-value pairs, and the received key-value pairs are obtained by the service provider performing a first encryption process on the multiple plaintext key-value pairs; Perform a second encryption process on the received key-value pairs and then send them to the service provider, so that the service provider obtains multiple encrypted key-value pairs through the first decryption process and saves them to the key-value pair set, and the key-value pair set is used by the service provider to query the corresponding target encrypted value according to the target encryption key provided by the querying party; wherein, the first decryption process is used to eliminate the encryption effect of the first encryption process, and the target encryption key is obtained by the querying party performing the second encryption process on the target plaintext key.

10. The method according to claim 9, wherein Further includes: Before sending the multiple key-value pairs obtained through the second encryption process to the service provider, perform a scrambling process on the multiple key-value pairs obtained through the second encryption process.

11. A concealed query system, characterized in that, The system includes: a querying party and a service provider, the service provider maintains a key-value pair set, the key-value pair set contains multiple encrypted key-value pairs, and the encrypted key-value pairs are obtained by the corresponding plaintext key-value pairs after the first encryption process implemented by the service provider, the second encryption process implemented by the querying party, and the first decryption process implemented by the service provider in sequence, wherein the first decryption process is used to eliminate the encryption effect of the first encryption process; wherein: The querying party is used to perform a second encryption process on the target plaintext key to obtain a target encryption key, and send the target encryption key to the service provider; The service provider is used to determine an encrypted key-value pair that matches the target encryption key from the key-value pair set, and return the target encrypted value in the determined encrypted key-value pair to the querying party.

12. According to the system of claim 11, wherein, The plaintext value in the plaintext key-value pair is subjected to a confusion process by the service provider and then the first encryption process is performed, so that the length relationship between the values in each of the confused plaintext key-value pairs is different from the length relationship between the original plaintext values; And / or, The multiple key-value pairs obtained through the second encryption process are provided to the service provider to perform the first decryption process after being scrambled by the querying party.

13. An encryption system for implementing stealth queries, characterized in that, The system includes: a querying party and a service provider; wherein: The querying party is configured to perform a second encryption process on the key-value pairs received from the service party, and return the key-value pairs obtained from the second encryption process to the service party; wherein the received key-value pairs are obtained after the service party performs a first encryption process on multiple plaintext key-value pairs it maintains. The service party is configured to perform a first decryption process on the key-value pairs after the second encryption process to obtain multiple encrypted key-value pairs, and save a key-value pair set containing the multiple encrypted key-value pairs for querying a corresponding target encrypted value according to a target encrypted key provided by the querying party; wherein the first decryption process is used to eliminate the encryption effect of the first encryption process, and the target encrypted key is obtained after the querying party performs the second encryption process on a target plaintext key.

14. An electronic device, characterized in that, Comprising: A processor; A memory for storing instructions executable by the processor; Wherein, the processor realizes the steps of the method according to any one of claims 1-10 by running the executable instructions.