Data encryption and decryption method and device, equipment and storage medium

By introducing mask parameters in the multi-key homomorphic encryption scheme, the encryption public key, encryption private key and mask parameters are generated to ensure the secure ciphertext merge, solving the problem of attackers inferring original data, and enhancing the security of the system and the semantic security of the calculation results.

CN120342580AActive Publication Date: 2025-07-18PENG CHENG LAB

Patent Information

Application Number
CN202510829920.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-20
Publication Date
2025-07-18
Estimated Expiration
2045-06-20

AI Technical Summary

Technical Problem

In the existing multi-key homomorphic encryption scheme, attackers can infer the original data by analyzing the correlation between ciphertexts, which poses security risks.

Method used

Each user-side device generates the corresponding mask parameters, and uses the mask parameters to introduce auxiliary data in the homomorphic addition process to ensure that ciphertexts from different sources can be safely merged. Data encryption and decryption are encrypted and decrypted by generating encryption public keys, encryption private keys and mask parameters, and expansion and homomorphic addition calculations are performed using the server-side device.

Benefits of technology

Enhanced security of multi-key encryption system, prevent sensitive plaintext information from leaking, and ensure the semantic security of calculation results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342580A_ABST
    Figure CN120342580A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a data encryption and decryption method and device, equipment and a storage medium, and relates to the technical field of data security. The method comprises the following steps: generating a corresponding encryption public key, an encryption private key and a mask parameter according to a public parameter, encrypting target data by using the encryption public key to obtain encrypted data, sending the mask parameter, the encryption public key and the encrypted data to server equipment, expanding the encrypted data by using the encryption public key by the server equipment to obtain an expanded ciphertext, and sending the expanded ciphertext to the server equipment. And performing homomorphic addition calculation on the extended ciphertext based on the encryption public key and the mask parameter, sending an obtained addition ciphertext to the user side equipment, and performing partial decoding on the addition ciphertext by using the encryption private key to obtain a decoded plaintext. According to the multi-key encryption method, each user side device generates a corresponding mask parameter, in the homomorphic addition process, the mask parameters are utilized to ensure that ciphertexts from different sources can be safely combined, a calculation result keeps semantic security, sensitive information is prevented from being leaked, and the security of a multi-key encryption system is enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data security technology, and in particular, to data encryption and decryption methods, devices, equipment, and storage media. Background Art

[0002] Homomorphic Encryption (HE) is an encryption technology that allows direct computational operations on encrypted data without decrypting the data during the entire computational process. In this way, both the confidentiality of the data can be protected and sensitive information can be processed securely.

[0003] In related technologies, the Multi-Key Homomorphic Encryption (MKHE) scheme supports multiple parties to encrypt data using their respective independent keys and can perform joint computations without decrypting the data. Finally, only authorized parties can decrypt the computation results. Among them, CKKS and BFV are two commonly used schemes in multi-key homomorphic encryption. However, in these two schemes, attackers may infer the original data by analyzing the correlation (such as linear relationship) between ciphertexts, so there are certain security risks. Summary of the Invention

[0004] The main purpose of the embodiments of this application is to propose data encryption and decryption methods, devices, equipment, and storage media to improve the security of the multi-key homomorphic encryption scheme.

[0005] To achieve the above object, a first aspect of the embodiments of this application proposes a data encryption and decryption method, which is applied to a client device. The method includes: Obtain public parameters generated according to security parameters, and generate corresponding encryption public keys, encryption private keys, and mask parameters according to the public parameters; Encrypt target data using the encryption public key to obtain encrypted data, and send the mask parameters, the encryption public key, and the encrypted data to a server device, so that the server device expands the encrypted data using the encryption public key to obtain an extended ciphertext, and performs homomorphic addition calculation on the extended ciphertext based on the encryption public key and the mask parameters, and then sends the obtained addition ciphertext to the client device; Partially decode the received addition ciphertext using the encryption private key to obtain the corresponding decoded plaintext.

[0006] In some embodiments, the public parameters at least include ciphertext modulus, key distribution, Gaussian error distribution, and common reference string. The mask parameters include mask ciphertext and mask key. The generating corresponding encryption public keys, encryption private keys, and mask parameters according to the public parameters includes: Obtain the private key parameters according to the key distribution, obtain the encryption private key according to the private key parameters, and obtain the encryption public key according to the key distribution, the common reference string, the ciphertext modulus, and the Gaussian error distribution; Perform Gadget encryption on the masked random polynomial to obtain the masked key, and encrypt the target data based on the masked random polynomial and the encryption public key to obtain the masked ciphertext.

[0007] In some embodiments, the obtaining the encryption public key according to the key distribution, the common reference string, the ciphertext modulus, and the Gaussian error distribution includes: Generate a first noise term according to the Gaussian error distribution, and obtain a first intermediate term according to the first noise term and the ciphertext modulus; Obtain a second intermediate term based on the private key parameters and the common reference string, sum the first intermediate term and the second intermediate term to obtain a third intermediate term, and obtain the encryption public key according to the third intermediate term and the common reference string.

[0008] In some embodiments, the common parameters further include a plaintext modulus, and the encrypting the target data based on the masked random polynomial and the encryption public key to obtain the masked ciphertext includes: Obtain the product of the masked random polynomial and the encryption public key to obtain a first masked intermediate term, and generate a second noise term and a third noise term according to the Gaussian error distribution; When the encryption algorithm is the first encryption algorithm, obtain a second masked intermediate term according to the second noise term and the third noise term, and obtain the masked ciphertext according to the sum of the first masked intermediate term and the second masked intermediate term; When the encryption algorithm is the second encryption algorithm, obtain masked initial data according to the plaintext modulus, the ciphertext modulus, and the target data, calculate the sum of the masked initial data and the second noise term to obtain a third masked intermediate term, obtain a fourth masked intermediate term according to the third masked intermediate term and the third noise term, and obtain the masked ciphertext according to the sum of the first masked intermediate term and the fourth masked intermediate term.

[0009] In some embodiments, the encrypting the target data using the encryption public key to obtain encrypted data includes: Generate a fourth noise term and a fifth noise term according to the Gaussian error distribution, obtain an encryption distribution parameter according to the key distribution, and calculate the product of the encryption distribution parameter and the encryption public key to obtain a fifth masked intermediate term; When the encryption algorithm is the first encryption algorithm, use the target data as the encryption initial data; when the encryption algorithm is the second encryption algorithm, use the mask initial data as the encryption initial data; Obtain the encrypted data according to the encryption initial data, the fifth noise term, and the fifth mask intermediate term.

[0010] To achieve the above object, a second aspect of the embodiments of the present application is a data encryption and decryption method applied to a server device, and the method includes: Obtain at least one encrypted data from different client devices and corresponding encryption public keys and mask parameters; Obtain the extended public key by obtaining the encryption public keys of at least one other client device, and expand the encrypted data based on the extended public key and the mask parameters to obtain an extended ciphertext; Perform homomorphic addition calculation on at least two extended ciphertexts using the mask parameters to obtain the addition ciphertext corresponding to the client device, and send the addition ciphertext to the corresponding client device; Obtain the decoded plaintext obtained by the client device partially decoding the addition ciphertext using the encryption private key, and aggregate all the decoded plaintexts to obtain the target plaintext.

[0011] In some embodiments, the mask parameters include a mask key. The expanding the extended ciphertext based on the extended public key and the mask parameters to obtain an extended ciphertext includes: Calculate the difference value between each extended public key and the corresponding encryption public key, and accumulate the difference values to obtain a total difference value; Perform an outer product operation on the total difference value and the mask key to obtain the extended ciphertext, and the extended ciphertext includes a plaintext component and a public key component.

[0012] In some embodiments, the mask parameters further include a mask ciphertext. The performing homomorphic addition calculation on at least two extended ciphertexts using the mask parameters to obtain the addition ciphertext corresponding to the client device includes: Obtain the encryption public key, the mask ciphertext, and the mask key corresponding to each extended ciphertext respectively; Obtain the plaintext component and the public key component in the extended ciphertext, and add the plaintext components to obtain a plaintext addition term; For each mask key, perform mask expansion according to all the mask keys to obtain a mask expansion key; Obtain the extended update ciphertext corresponding to each extended ciphertext according to the plaintext addition term, the mask ciphertext, and the mask expansion key, and obtain the addition ciphertext based on the extended update ciphertext.

[0013] For achieving the above object, a third aspect of the embodiments of the present application provides a data encryption and decryption device, which is applied to a client device. The device includes: A key generation module: configured to obtain public parameters generated according to security parameters, and generate a corresponding encryption public key, an encryption private key, and a mask parameter according to the public parameters; An encryption module: configured to encrypt target data using the encryption public key to obtain encrypted data, and send the mask parameter, the encryption public key, and the encrypted data to a server device, so that the server device expands the encrypted data using the encryption public key to obtain an expanded ciphertext, and performs a homomorphic addition calculation on the expanded ciphertext based on the encryption public key and the mask parameter, and then sends the obtained addition ciphertext to the client device; A decryption module: configured to perform partial decoding on the received addition ciphertext using the encryption private key to obtain a corresponding decoded plaintext.

[0014] For achieving the above object, a fourth aspect of the embodiments of the present application provides a data encryption and decryption device, which is applied to a server device. The device includes: A parameter acquisition module: configured to acquire at least one encrypted data from different client devices and corresponding encryption public keys and mask parameters; An expansion module: configured to obtain an expansion public key by acquiring the encryption public keys of at least one other client device, and expand the encrypted data based on the expansion public key and the mask parameter to obtain an expanded ciphertext; A homomorphic calculation module: configured to perform a homomorphic addition calculation on at least two expanded ciphertexts using the mask parameter to obtain the addition ciphertext of the corresponding client device, and send the addition ciphertext to the corresponding client device; A plaintext aggregation module: configured to acquire the decoded plaintext obtained by the client device performing partial decoding on the addition ciphertext using the encryption private key, and aggregate all the decoded plaintexts to obtain a target plaintext.

[0015] For achieving the above object, a fifth aspect of the embodiments of the present application provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the method described in the first aspect or the second aspect above is implemented.

[0016] For achieving the above object, a sixth aspect of the embodiments of the present application provides a storage medium, which is a storage medium that stores a computer program. When the computer program is executed by a processor, the method described in the first aspect or the second aspect above is implemented.

[0017] The data encryption and decryption method, device, equipment, and storage medium provided by the embodiments of the present application obtain public parameters generated according to security parameters, generate corresponding encryption public keys, encryption private keys, and mask parameters according to the public parameters, encrypt target data using the encryption public key to obtain encrypted data, and send the mask parameters, encryption public key, and encrypted data to the server device, so that the server device expands the encrypted data using the encryption public key to obtain an extended ciphertext, and performs homomorphic addition calculation on the extended ciphertext based on the encryption public key and mask parameters, and then sends the obtained addition ciphertext to the user device, and partially decodes the received addition ciphertext using the encryption private key to obtain the corresponding decoded plaintext. In the embodiments of the present application, each user device generates corresponding mask parameters to participate in the subsequent calculation process. During the process of performing homomorphic addition, auxiliary data is introduced using the mask parameters to ensure that ciphertexts from different sources can be safely merged, and the calculation results still maintain semantic security. An attacker cannot distinguish whether two different ciphertexts correspond to the same plaintext, thereby preventing the leakage of sensitive plaintext information and enhancing the security of the multi-key encryption system. Description of the Drawings

[0018] Figure 1 is a flowchart of the data encryption and decryption method provided by the embodiments of the present application.

[0019] Figure 2 is a flowchart of generating corresponding encryption public key, encryption private key, and homomorphic addition parameters according to public parameters provided by the embodiments of the present application.

[0020] Figure 3 is a flowchart of obtaining an encryption public key according to key distribution, common reference string, ciphertext modulus, and Gaussian error distribution provided by the embodiments of the present application.

[0021] Figure 4 is a flowchart of encrypting target data using a masked random polynomial and an encryption public key to obtain a masked ciphertext provided by the embodiments of the present application.

[0022] Figure 5 is a flowchart of encrypting target data using an encryption public key to obtain encrypted data provided by the embodiments of the present application.

[0023] Figure 6 is another flowchart of the data encryption and decryption method provided by the embodiments of the present application.

[0024] Figure 7 is a flowchart of expanding an extended ciphertext based on an extended public key and a mask parameter to obtain an extended ciphertext provided by the embodiments of the present application.

[0025] Figure 8It is a flowchart for performing homomorphic addition calculation on at least two extended ciphertexts using mask parameters to obtain the addition ciphertext of the corresponding client device provided by an embodiment of the present application.

[0026] Figure 9 It is a schematic diagram of the overall process of the data encryption and decryption method provided by an embodiment of the present application.

[0027] Figure 10 It is a block diagram of the structure of a data encryption and decryption device provided by another embodiment of the present application.

[0028] Figure 11 It is another block diagram of the structure of a data encryption and decryption device provided by another embodiment of the present application.

[0029] Figure 12 It is a schematic diagram of the hardware structure of an electronic device provided by an embodiment of the present application. Detailed implementation manners

[0030] In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0031] It should be noted that although the functional modules are divided in the device schematic diagram and the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order from the module division in the device or the flowchart.

[0032] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present application belongs. The terms used herein are only for the purpose of describing the embodiments of the present application and are not intended to limit the present application.

[0033] Homomorphic encryption (HE) is an encryption technology that allows direct computational operations on encrypted data without decrypting the data throughout the computational process. In this way, both the confidentiality of the data can be protected and sensitive information can be processed securely.

[0034] In the related art, the Multi-Key Homomorphic Encryption (MKHE) scheme supports multiple parties to encrypt data using their respective independent keys, and can perform joint calculations without decrypting the data. Finally, only authorized parties can decrypt the calculation results. Among them, CKKS and BFV are two commonly used schemes in multi-key homomorphic encryption. However, in these two schemes, an attacker may infer the original data by analyzing the correlation (such as linear relationship) between ciphertexts, so there are certain security risks.

[0035] Based on this, the embodiments of the present application provide a data encryption and decryption method, device, equipment and storage medium. By generating corresponding mask parameters for each client device to participate in the subsequent calculation process, in the process of performing homomorphic addition, auxiliary data is introduced using the mask parameters to ensure that ciphertexts from different sources can be safely merged, and the calculation results still maintain semantic security. An attacker cannot distinguish whether two different ciphertexts correspond to the same plaintext, thereby preventing the leakage of sensitive plaintext information and enhancing the security of the multi-key encryption system.

[0036] The embodiments of the present application provide a data encryption and decryption method, device, equipment and storage medium, which will be specifically described through the following embodiments. First, the data encryption and decryption method in the embodiments of the present application will be described.

[0037] The data encryption and decryption method provided by the embodiments of the present application relates to the field of data security technology. The data encryption and decryption method provided by the embodiments of the present application can be applied to client devices, or to server devices, or can also be a computer program running on client devices or server devices. For example, the computer program can be a native program or software module in the operating system; it can be a local (Native) application (Application, APP), that is, a program that needs to be installed in the operating system to run, such as a client that supports data encryption and decryption, that is, a program that only needs to be downloaded to the browser environment to run; it can also be a small program that can be embedded in any APP. In short, the above computer program can be any form of application program, module or plug-in. Among them, the client device communicates with the server device through the network. This data encryption and decryption method can be executed by the client device or the server device, or jointly executed by the client device and the server device.

[0038] In some embodiments, the client device may be a smart phone, a tablet computer, a laptop computer, a desktop computer, a smart watch, a server, or the like. The server device may be an independent server or a cloud server device that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, Content Delivery Network (CDN), and big data and artificial intelligence platforms; it may also be a service node in a blockchain system, and the service nodes in the blockchain system form a Peer To Peer (P2P) network, and the P2P protocol is an application layer protocol running on top of the Transmission Control Protocol (TCP) protocol. The client device and the server device may be connected through communication connection methods such as Bluetooth, Universal Serial Bus (USB), or network, and this embodiment does not make any restrictions here.

[0039] This application can be used in many general or special computer system environments or configurations. For example: personal computers, servers, handheld or portable devices, tablet devices, multi-processor systems, microprocessor-based systems, set-top boxes, programmable consumer electronic devices, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and so on. This application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. This application can also be practiced in a distributed computing environment where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.

[0040] The data encryption and decryption method in the embodiments of this application is described below. First, its execution process on the client device is described.

[0041] Figure 1 is an optional flowchart of the data encryption and decryption method provided by the embodiments of this application. Figure 1 The method in may include but is not limited to steps 110 to 130. At the same time, it can be understood that this embodiment does not specifically limit the order of steps 110 to 130 in, and the order of steps can be adjusted according to actual needs, or some steps can be reduced or added. Figure 1 The order of steps 110 to 130 in can be adjusted according to actual needs, or some steps can be reduced or added.

[0042] Step 110: Obtain the public parameters generated according to the security parameters, and generate the corresponding encryption public key, encryption private key, and mask parameters based on the public parameters.

[0043] In one embodiment, multiple client devices can be network - connected to the server device for a multi - key homomorphic encryption process. First, the server device can generate a public parameter according to the security parameters to define the specific execution process of homomorphic encryption.

[0044] In one embodiment, the server device can use an initialization algorithm to generate the public parameters according to the security parameters. Among them, the public parameters at least include the ciphertext modulus, plaintext modulus, key distribution, Gaussian error distribution, and common reference string. The initialization algorithm is expressed as:

[0045] Among them, represents the initialization algorithm, represents the security parameters, represents the public parameters. Specifically, , N represents the ring dimension of the polynomial ring R, represents the ciphertext modulus in the CKKS / BFV scheme, is the plaintext modulus in the CKKS / BFV scheme, represents the key distribution, which is used to define the probability distribution with a small bound of the relevant key on the polynomial ring R, represents the Gaussian error distribution, and , represents the number of terms of the polynomial, represents the common reference string. Among them, is randomly sampled from the uniform distribution .

[0046] In one embodiment, the security parameters can be set according to actual requirements. For example, , which represents 128 - bit security. The ring dimension N can take . For the CKKS scheme, the plaintext modulus t represents the scaling factor of floating - point encoding, such as t = . For the BFV scheme, the plaintext modulus t represents the modulus of integer plaintext, such as t = 65537. The ciphertext modulus Q is used to control the noise growth to ensure the correctness of decryption. For example, . The key distribution can be a Gaussian distribution with a mean of 0 and a standard deviation of . The Gaussian error distribution is used to define the distribution of encryption noise, aiming to enhance security and prevent linear algebra attacks, etc. For example, it can be set as , the value of needs to be large enough to improve security. For example, , represents rounding up. It can be understood that the above only illustrates the public parameters and does not represent a limitation thereof. Different security parameters can correspond to different public parameters.

[0047] In one embodiment, an encryption public key, an encryption private key, a mask parameter, etc. are obtained by using a key calculation algorithm, where the key calculation algorithm is expressed as:

[0048] where, represents the encryption private key, represents the encryption public key, represents the mask parameter.

[0049] In one embodiment, the mask parameter includes a mask ciphertext and a mask key. Referring to Figure 2 , Figure 2 is a flowchart for generating a corresponding encryption public key, encryption private key, and homomorphic addition parameter according to public parameters provided by an embodiment of the present application, specifically including the following steps: Step 210: Obtain a private key parameter according to a key distribution, obtain an encryption private key according to the private key parameter, and obtain an encryption public key according to the key distribution, a public reference string, a ciphertext modulus, and a Gaussian error distribution.

[0050] In one embodiment, the encryption private key is expressed as:

[0051] where s represents the private key parameter, and the private key parameter s is obtained according to the key distribution and is expressed as , that is, s is obtained by randomly sampling in the key distribution, and then the encryption private key is obtained.

[0052] Next, calculate the encryption public key. Referring to Figure 3 , Figure 3 is a flowchart for obtaining an encryption public key according to a key distribution, a public reference string, a ciphertext modulus, and a Gaussian error distribution provided by an embodiment of the present application, specifically including the following steps: Step 310: Generate a first noise term according to the Gaussian error distribution, and obtain a first intermediate term according to the first noise term and the ciphertext modulus.

[0053] In one embodiment, a first noise term is randomly sampled from the Gaussian error distribution and is expressed as: , where the first noise term is a random polynomial sampled from the Gaussian error distribution, and the coefficient mean is 0, and the standard deviation is .

[0054] Then, to avoid noise expansion, the ciphertext modulus Q is used to prevent coefficient overflow, and the first noise term is calculated only from the ciphertext modulus and mapped to the interval [-Q / 2, Q / 2). The first intermediate term is expressed as:

[0055] Step 320: Obtain a second intermediate term based on the private key parameter and the common reference string, sum the first intermediate term and the second intermediate term to obtain a third intermediate term, and obtain the encryption public key according to the third intermediate term and the common reference string.

[0056] In one embodiment, the second intermediate term is expressed as:

[0057] Therefore, the third intermediate term is expressed as:

[0058] In one embodiment, the encryption public key , and , whereby the encryption public key is obtained according to the third intermediate term and the common reference string .

[0059] Step 220: Perform Gadget encryption on the masked random polynomial to obtain a masked key, and encrypt the target data based on the masked random polynomial and the encryption public key to obtain a masked ciphertext.

[0060] In one embodiment, a random polynomial is selected as the masked random polynomial, and the random polynomial is subjected to Gadget encryption to obtain the masked key .

[0061] First, the Gadget decomposition process is introduced. Among them, the Gadget decomposition process can be defined as a mapping , which satisfies the following conditions. For all : 1) There exists a constant vector such that

[0062] where the constant vector can be a power basis vector. For example: , where B is the decomposition radix, for example B = 2, and the purpose is to represent any b by a linear combination of basis vectors.

[0063] For each coefficient b k of b (k ∈ [0, N - 1]), calculate its representation under the constant vector :

[0064] Among them, represents a coefficient, and the coefficients are recombined into a polynomial: , to obtain:

[0065] Among them, X represents the independent variable of the polynomial.

[0066] Therefore, it can be obtained that:

[0067] 2) The coefficient of is small, that is, there exists a constant .

[0068] The above constant vector is called the Gadget vector, and is a compact representation with bounded coefficients, and the mapping can be regarded as the right inverse of the inner product operation , ensuring .

[0069] Next, perform the Gadget encryption process according to the above Gadget decomposition process.

[0070] For the given target data and the encryption private key , where , the masked key obtained by performing Gadget encryption on the masked random polynomial is defined as a pair of vectors . If the following relationship is satisfied, then is called the masked key of :

[0071] Among them, represents the inner product operation.

[0072] In one embodiment, after having the masked key, the masked ciphertext can be calculated. Referring to Figure 4 , Figure 4 is the flowchart of encrypting the target data into the masked ciphertext based on the masked random polynomial and the encryption public key provided by the embodiment of the present application, which specifically includes the following steps: Step 410: Obtain the first masked intermediate term by multiplying the masked random polynomial and the encryption public key, and generate the second noise term and the third noise term according to the Gaussian error distribution.

[0073] In one embodiment, the first masked intermediate term is expressed as: Sampling is performed according to the Gaussian error distribution to generate a second noise term and a third noise term , which is expressed as .

[0074] Step 420: When the encryption algorithm is the first encryption algorithm, a second masked intermediate term is obtained according to the second noise term and the third noise term, and a masked ciphertext is obtained according to the sum of the first masked intermediate term and the second masked intermediate term.

[0075] In one embodiment, when is selected as the first encryption algorithm, a structured binary tuple is formed according to the second noise term and the third noise term, which is expressed as . The binary tuple is a binary polynomial vector. Taking the modulus of the binary tuple with respect to the ciphertext modulus, a second masked intermediate term is obtained, which is expressed as:

[0076] Next, a masked ciphertext is obtained according to the sum of the first masked intermediate term and the second masked intermediate term, which is expressed as:

[0077] where represents the masked ciphertext.

[0078] Step 430: When the encryption algorithm is the second encryption algorithm, masked initial data is obtained according to the plaintext modulus, the ciphertext modulus, and the target data, the sum of the masked initial data and the second noise term is calculated to obtain a third masked intermediate term, a fourth masked intermediate term is obtained according to the third masked intermediate term and the third noise term, and a masked ciphertext is obtained according to the sum of the first masked intermediate term and the fourth masked intermediate term.

[0079] In one embodiment, the BFV algorithm is selected as the second encryption algorithm, and the masked initial data obtained according to the plaintext modulus, the ciphertext modulus, and the target data is expressed as:

[0080] Then, the sum of the masked initial data and the second noise term is calculated to obtain a third masked intermediate term, which is expressed as:

[0081] where represents rounding to the nearest integer.

[0082] Next, a structured binary tuple is formed according to the third masked intermediate term and the third noise term, and then the modulus of the binary tuple with respect to the ciphertext modulus is taken to obtain a fourth masked intermediate term, which is expressed as:

[0083] Finally, the masked ciphertext is obtained based on the sum of the middle term of the first mask and the middle term of the fourth mask, expressed as:

[0084] It can be understood that the encryption algorithm can be set according to actual requirements, and the calculation process of the masked ciphertext for different encryption algorithms is as described above.

[0085] Step 120: Encrypt the target data using the encryption public key to obtain encrypted data, and send the mask parameter, the encryption public key, and the encrypted data to the server device.

[0086] In one embodiment, the encryption process is described as , referring to Figure 5 , Figure 5 FIG. is a flowchart of encrypting target data using an encryption public key provided by an embodiment of the present application, specifically including the following steps: Step 510: Generate a fourth noise term and a fifth noise term according to the Gaussian error distribution, obtain an encryption distribution parameter according to the key distribution, and calculate the product of the encryption distribution parameter and the encryption public key to obtain a fifth masked middle term.

[0087] In one embodiment, first sample to generate a fourth noise term according to the Gaussian error distribution and a fifth noise term , and obtain an encryption distribution parameter according to the key distribution , expressed as . Next, calculate the product of the encryption distribution parameter and the encryption public key to obtain a fifth masked middle term, expressed as: .

[0088] Step 520: When the encryption algorithm is the first encryption algorithm, use the target data as the encryption initial data, and when the encryption algorithm is the second encryption algorithm, use the masked initial data as the encryption initial data.

[0089] In one embodiment, if the encryption algorithm is the first encryption algorithm , use the target data as the encryption initial data, and when the encryption algorithm is the second encryption algorithm BFV, use the masked initial data as the encryption initial data.

[0090] Step 530: Obtain the encrypted data according to the encryption initial data, the fifth noise term, and the fifth masked middle term.

[0091] In one embodiment, in the first encryption algorithm , the encrypted data is expressed as:

[0092] When using the second encryption algorithm BFV, the encrypted data is represented as:

[0093] After obtaining the encrypted data, the mask parameter, the encryption public key, and the encrypted data are sent to the server device. At this time, the server device may receive relevant data sent by multiple different client devices. It can use the encryption public key to expand different encrypted data to obtain the corresponding expanded ciphertext for each client device, and then perform homomorphic addition calculation on the expanded ciphertext based on the encryption public key and the mask parameter, and send the obtained addition ciphertext to different client devices. The data processing process of the server device will be described in detail in the following embodiments.

[0094] Step 130: Use the encryption private key to perform partial decoding on the received addition ciphertext to obtain the corresponding decoded plaintext.

[0095] In one embodiment, assume that a certain client device receives the addition ciphertext , and the addition ciphertext also includes ciphertext data corresponding to other client devices. At this time, after the client device receives the addition ciphertext, it uses the corresponding encryption private key to perform partial decoding on it. Here, partial decoding means that the client device can only use its own encryption private key to decode the ciphertext component related to itself to obtain the corresponding decrypted plaintext. This process is expressed as:

[0096] Among them, represents the encryption private key of the i-th client device, represents the ciphertext component corresponding to the i-th client device in the addition ciphertext, represents the partial decoding algorithm, represents the decoded plaintext corresponding to the i-th client device.

[0097] Next, the execution process of the data encryption and decryption method in the embodiments of the present application on the server device will be described.

[0098] In one embodiment, referring to Figure 6 , Figure 6 is another flowchart of the data encryption and decryption method provided by the embodiments of the present application, including the following steps: Step 610: Obtain at least one piece of encrypted data, the corresponding encryption public key, and mask parameter from different client devices.

[0099] In one embodiment, the server device receives at least one piece of encrypted data, the corresponding encryption public key, and mask parameter from different client devices.

[0100] Step 620: Obtain the encryption public keys of at least one other client device to get the extended public key, and extend the encrypted data based on the extended public key and the mask parameter to obtain the extended ciphertext.

[0101] In one embodiment, for the i-th client device, its own encryption public key and the encryption public keys of other client devices are used together as the extended public key, denoted as . Referring to Figure 7 , Figure 7 is the flowchart for extending the extended ciphertext based on the extended public key and the mask parameter provided by the embodiments of the present application, which specifically includes the following steps: Step 710: Calculate the difference value between each extended public key and the corresponding encryption public key, and accumulate the difference values to obtain the total difference value.

[0102] In one embodiment, if the encryption public key is denoted as , where b represents the component related to the key in the encryption public key, a represents the noise term, and is the perturbation term of the key component. At this time, calculate the difference value between each extended public key and the key component in the corresponding encryption public key, denoted as: , where represents the i-th extended public key, and b represents the current encryption public key. Therefore, the total difference value is denoted as:

[0103] where n represents the number of extended public keys, that is, the number of client devices.

[0104] Step 720: Perform an outer product operation on the total difference value and the mask key to obtain the extended ciphertext.

[0105] In one embodiment, the process of extending the i-th encrypted ciphertext to obtain the extended ciphertext is described as:

[0106] where represents the encrypted ciphertext corresponding encryption public key. The calculation process of the extended ciphertext is denoted as:

[0107]

[0108]

[0109] where represents the outer product operation, denotes the result of key expansion of the encryption public key and the i-th extended public key, and , while , and for the rest the value is 0. It can be understood that for , the result obtained is .

[0110] It can be understood that in the above embodiments, the encrypted data is expanded using its own mask key, and the mask key is encrypted by the Gadget, rather than encrypting a single-bit data on the basis of the general mask to increase the identity information, thus avoiding the problem of high computational complexity caused by the quadratic growth of the space and time complexity in N (the number of participants) as the bit length of the ciphertext increases.

[0111] Step 630: Perform homomorphic addition calculation on at least two extended ciphertexts using the mask parameter to obtain the addition ciphertext of the corresponding user equipment, and send the addition ciphertext to the corresponding user equipment.

[0112] In one embodiment, referring to Figure 8 , Figure 8 is the flowchart of using the mask parameter to perform homomorphic addition calculation on at least two extended ciphertexts to obtain the addition ciphertext of the corresponding user equipment provided by the embodiment of the present application, which specifically includes the following steps: Step 810: Obtain the encryption public key, mask ciphertext, and mask key corresponding to each extended ciphertext respectively.

[0113] In one embodiment, taking the extended ciphertext and as an example. The corresponding encryption public key is , and the mask parameters are respectively: , where , respectively represent the mask ciphertext, , respectively represent the mask key.

[0114] Step 820: Obtain the plaintext component and public key component in the extended ciphertext, and add the plaintext components to obtain the plaintext addition term.

[0115] In one embodiment, the extended ciphertext includes a plaintext component and a public key component, expressed as , taking as the plaintext part, and as the public key component. Add the plaintext components to obtain the corresponding plaintext addition term, expressed as:

[0116] Step 830: For each masking key, perform masking expansion based on all the masking keys to obtain the masked expansion key.

[0117] In one embodiment, for the masking key , its masked expansion key is represented as:

[0118] For the masking key , its masked expansion key is represented as:

[0119] Step 840: Obtain the extended updated ciphertext corresponding to each extended ciphertext based on the plaintext summation term, the masked ciphertext, and the masked expansion key, and obtain the additive ciphertext based on the extended updated ciphertext.

[0120] In one embodiment, the extended updated ciphertext corresponding to the extended ciphertext is represented as:

[0121] The extended updated ciphertext corresponding to the extended ciphertext is represented as:

[0122] Aggregate all the extended updated ciphertexts to obtain the final additive ciphertext , and this process is represented as:

[0123]

[0124] Step 640: Obtain the decoded plaintext obtained by the client device partially decoding the additive ciphertext using the encryption private key, and aggregate all the decoded plaintexts to obtain the target plaintext.

[0125] In one embodiment, after obtaining the additive ciphertext, send the additive ciphertext to the client device. The client device partially decodes the ciphertext component related to itself to obtain the corresponding decoded plaintext , and then the client device sends the decoded plaintext to the server device. The server device aggregates the decoded plaintexts to obtain the target plaintext. This process is represented as:

[0126] In one embodiment, referring to Figure 9 , Figure 9 is the overall flowchart of the data encryption and decryption method provided in the embodiment of the present application.

[0127] First, the server device or other servers act as the establishment end, respond to the requests of the client devices, and generate public parameters according to the security parameters and send the public parameters to all client devices. Subsequently, different client devices use the key calculation algorithm to generate their respective encryption public keys, encryption private keys, and mask parameters. This process is expressed as: . Then the client device executes process, encrypt the target data using the encryption public key to obtain encrypted data. Send the encrypted data to the server device for evaluation.

[0128] At this time, the server device executes process, expand at least one encrypted data from different client devices to obtain the corresponding expanded ciphertext. At the same time, perform this homomorphic addition operation on different expanded ciphertexts to obtain the addition ciphertext . Return the addition ciphertext as the calculation result ciphertext to the client device.

[0129] Next, the client device performs partial decoding on the addition ciphertext to obtain the corresponding decoded plaintext , and return the corresponding decoded plaintext to the server device. The server device executes to aggregate the decoded plaintext to obtain the target plaintext.

[0130] In this process, the specific execution process of the embodiment of the present application can be described as: in the server device, the mask expansion key and the mask ciphertext are used as the mask information (ciphertext) of the client device. Among them, the mask ciphertext and the encrypted data are generated by the same client device (e.g., client device P).

[0131] When the client device P performs joint decryption with another client device P', the decryption process is described as:

[0132] Among them, and are the noise terms generated by decryption and . In this way, the encrypted data of the client device P can be expanded to the expanded ciphertext , and be decrypted to:

[0133] Assume Decryption noise , so the decryption process is described as:

[0134] Therefore, if , then there is , and the decryption is successful.

[0135] However, due to , and:

[0136] Among them, , it can be seen that is a large non-negligible noise.

[0137] Therefore, the above equation does not hold. In order to control the growth of noise and ensure the correctness of the evaluation calculation of the multi-key ciphertext after masking, the embodiment of the present application adopts the Gadget decomposition technology to reduce the growth, ensuring , thereby ensuring .

[0138] Among them, the purpose of Gadget decomposition is to represent the elements in the ring as a compact and structured linear combination of predefined basis elements. By using the Gadget decomposition technology, the multiplication operation of any ring element can be efficiently performed in the homomorphic environment, while avoiding the generation of excessive noise. Specifically in the embodiment of the present application, the masked extended key is generated, where is the Gadget encryption of the masked random polynomial , and then based on the extension algorithm generates , so it can be obtained that: , and the decryption is successful.

[0139] Next, it is described that the encryption and decryption methods of the embodiment of the present application satisfy semantic security and correctness.

[0140] First, semantic security means that even if an attacker knows the public parameters and the encryption public key , it is impossible to infer any information about the plaintext from the ciphertext. Assume that the information that the attacker may obtain is composed of the distribution .

[0141] For a given security parameter , the encryption process of the embodiment of the present application can ensure the following computational indistinguishability:

[0142]

[0143] Among them, represents the encryption process for data . represents the encryption process for data . represents using as the masked random polynomial for the masking process, represents using as the masked random polynomial for the masking process.

[0144] It can be seen that regardless of whether the plaintext to be encrypted is μ or another random plaintext μ′, since the encryption distribution parameter obtained according to the key distribution is unknown during the encryption process in the embodiments of the present application, and the random polynomial cannot be accessed again after modification, the final distribution of the encrypted data is independent of the data itself. Therefore, the following relational expression can be ensured to be satisfied: . Additionally, regardless of whether the random polynomial r or another random polynomial r′ is used in the masking process, the algorithm also satisfies the following computational indistinguishability , and semantic security can be achieved.

[0145] Speaking of correctness, correctness ensures that after the masking process and the decryption process, the decrypted plaintext obtained is still consistent with the target data (which may carry controllable noise) that is the original plaintext.

[0146] For any , let , then there is:

[0147] Among them, , and there is:

[0148] Among them, . Combining the above results, it can be obtained that:

[0149] Among them, . It can be seen that the data encryption and decryption method of the embodiments of the present application can also meet the correctness.

[0150] The core point of the embodiments of the present application lies in introducing a brand-new masking scheme and designing it in the form of The mask decryption process, so that the encrypted data of the client device P can be masked as the extended ciphertext and be successfully decrypted into , thereby ensuring the privacy of the encrypted data among multiple parties, effectively solving the security problem of data leakage in the multi-key homomorphic encryption scenario in the related technology, and using the mask parameter to ensure the correctness of the homomorphic calculation process, thereby significantly improving the security and practicability of the system.

[0151] For example, for party, the equation , where is the encrypted data encrypted by party, are respectively and the encrypted private keys of the party. This solution is used to mask the encrypted target data . In this process, the attacker cannot obtain any information about the target data from the mask key , while the server device as the evaluator can effectively derive the solution for any selected identity. In short, the mask scheme of the embodiments of the present application ensures that when performing homomorphic calculations, the encrypted data from different client devices can be safely merged, while preventing the leakage of sensitive plaintext information, thereby enhancing the security of the multi-key encryption system.

[0152] The technical solution provided by the embodiments of the present application is to obtain public parameters generated according to security parameters, generate corresponding encryption public keys, encryption private keys and mask parameters according to the public parameters, encrypt the target data using the encryption public key to obtain encrypted data, and send the mask parameters, encryption public keys and encrypted data to the server device, so that the server device expands the encrypted data using the encryption public key to obtain the extended ciphertext, and performs homomorphic addition calculation on the extended ciphertext based on the encryption public key and mask parameters, and then sends the obtained addition ciphertext to the client device, and uses the encryption private key to perform partial decoding on the received addition ciphertext to obtain the corresponding decoded plaintext. In the embodiments of the present application, each client device generates corresponding mask parameters to participate in the subsequent calculation process. During the homomorphic addition process, auxiliary data is introduced using the mask parameters to ensure that ciphertexts from different sources can be safely merged, and the calculation result still remains semantically secure. The attacker cannot distinguish whether two different ciphertexts correspond to the same plaintext, thereby preventing the leakage of sensitive plaintext information and enhancing the security of the multi-key encryption system.

[0153] The embodiments of the present application further provide a data encryption and decryption device, which is applied to the client device and can implement the above data encryption and decryption method. Referring to Figure 10 , the device includes: Key generation module 1010: It is used to obtain public parameters generated according to security parameters, and generate corresponding encryption public key, encryption private key and mask parameters according to the public parameters.

[0154] Encryption module 1020: It is used to encrypt target data with the encryption public key to obtain encrypted data, and send the mask parameters, encryption public key and encrypted data to the server device, so that the server device expands the encrypted data with the encryption public key to obtain an extended ciphertext, and performs homomorphic addition calculation on the extended ciphertext based on the encryption public key and mask parameters, and then sends the obtained additive ciphertext to the user device.

[0155] Decryption module 1030: It is used to perform partial decoding on the received additive ciphertext with the encryption private key to obtain the corresponding decoded plaintext.

[0156] In one embodiment, the public parameters at least include ciphertext modulus, key distribution, Gaussian error distribution and common reference string, and the key generation module 1010 is further used for: Obtain private key parameters according to the key distribution, obtain the encryption private key according to the private key parameters, and obtain the encryption public key according to the key distribution, the common reference string, the ciphertext modulus, and the Gaussian error distribution; Perform Gadget encryption on the mask random polynomial to obtain the mask key, and encrypt the target data based on the mask random polynomial and the encryption public key to obtain the mask ciphertext.

[0157] In one embodiment, the key generation module 1010 is further used for: Generate a first noise term according to the Gaussian error distribution, and obtain a first intermediate term according to the first noise term and the ciphertext modulus; Obtain a second intermediate term based on the private key parameters and the common reference string, sum the first intermediate term and the second intermediate term to obtain a third intermediate term, and obtain the encryption public key according to the third intermediate term and the common reference string.

[0158] In one embodiment, the key generation module 1010 is further used for: Obtain the product of the mask random polynomial and the encryption public key to obtain a first mask intermediate term, and generate a second noise term and a third noise term according to the Gaussian error distribution; When the encryption algorithm is the first encryption algorithm, obtain a second mask intermediate term according to the second noise term and the third noise term, and obtain the mask ciphertext according to the sum of the first mask intermediate term and the second mask intermediate term; When the encryption algorithm is the second encryption algorithm, mask initial data is obtained based on the plaintext modulus, the ciphertext modulus, and the target data. The sum of the mask initial data and the second noise term is calculated to obtain a third masked intermediate term. A fourth masked intermediate term is obtained based on the third masked intermediate term and the third noise term. The masked ciphertext is obtained based on the sum of the first masked intermediate term and the fourth masked intermediate term.

[0159] In one embodiment, the encryption module 1020 is further configured to: Generate a fourth noise term and a fifth noise term according to the Gaussian error distribution, obtain an encryption distribution parameter based on the key distribution, and calculate the product of the encryption distribution parameter and the encryption public key to obtain a fifth masked intermediate term; When the encryption algorithm is the first encryption algorithm, the target data is used as the encryption initial data. When the encryption algorithm is the second encryption algorithm, the mask initial data is used as the encryption initial data; The encrypted data is obtained based on the encryption initial data, the fifth noise term, and the fifth masked intermediate term.

[0160] The specific implementation manner of the data encryption and decryption device in this embodiment is basically the same as that of the above data encryption and decryption method applied to the user equipment, and will not be elaborated here.

[0161] This application embodiment also provides a data encryption and decryption device, which is applied to a server device and can implement the above data encryption and decryption method. Referring to Figure 11 , the device includes: A parameter acquisition module 1110: configured to acquire at least one encrypted data from different user equipment and the corresponding encryption public key and mask parameter.

[0162] An expansion module 1120: configured to acquire the encryption public keys of at least one other user equipment to obtain an expanded public key, and expand the encrypted data based on the expanded public key and the mask parameter to obtain an expanded ciphertext.

[0163] A homomorphic calculation module 1130: configured to perform homomorphic addition calculation on at least two expanded ciphertexts by using the mask parameter to obtain the addition ciphertexts corresponding to the user equipment, and send the addition ciphertexts to the corresponding user equipment.

[0164] A plaintext aggregation module 1140: configured to acquire the decoded plaintexts obtained by the user equipment partially decoding the addition ciphertexts by using the encryption private key, and aggregate all the decoded plaintexts to obtain the target plaintext.

[0165] In one embodiment, the expansion module 1120 is further configured to: Calculate the difference value between each of the extended public keys and the corresponding encryption public key, and accumulate the difference values to obtain a total difference value; Perform an outer product operation on the total difference value and the mask key to obtain the extended ciphertext, where the extended ciphertext includes a plaintext component and a public key component.

[0166] In one embodiment, the mask parameter further includes a masked ciphertext, and the homomorphic calculation module 1130 is further configured to: Obtain the encryption public key, the masked ciphertext, and the mask key corresponding to each of the extended ciphertexts; Obtain the plaintext component and the public key component in the extended ciphertext, and add the plaintext components to obtain a plaintext addition term; For each of the mask keys, perform mask expansion according to all the mask keys to obtain a mask expansion key; Obtain an extended updated ciphertext corresponding to each of the extended ciphertexts according to the plaintext addition term, the masked ciphertext, and the mask expansion key, and obtain the addition ciphertext based on the extended updated ciphertext.

[0167] The specific implementation manner of the data encryption and decryption device in this embodiment is basically the same as that of the data encryption and decryption method applied to the server device described above, and will not be elaborated here.

[0168] An embodiment of the present application further provides an electronic device, including: At least one memory; At least one processor; At least one program; The program is stored in the memory, and the processor executes the at least one program to implement the data encryption and decryption method described above in the present application. The electronic device may be any intelligent terminal including a mobile phone, a tablet computer, a personal digital assistant (Personal Digital Assistant, PDA), an in-vehicle computer, etc.

[0169] Please refer to Figure 12 , Figure 12 which schematically shows the hardware structure of an electronic device in another embodiment. The electronic device includes: A processor 1201, which can be implemented by using a general-purpose central processing unit (Central Processing Unit, CPU), a microprocessor, an application-specific integrated circuit (Application Specific Integrated Circuit, ASIC), or one or more integrated circuits, etc., and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present application; The memory 1202 can be implemented in forms such as Read-Only Memory (ROM), static storage devices, dynamic storage devices, or Random Access Memory (RAM). The memory 1202 can store the operating system and other application programs. When implementing the technical solutions provided in the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 1202 and are called by the processor 1201 to execute the data encryption and decryption method of the embodiments of this application; The input / output interface 1203 is used to implement information input and output; The communication interface 1204 is used to implement communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.); The bus 1205 transmits information between various components of the device (such as the processor 1201, the memory 1202, the input / output interface 1203, and the communication interface 1204); Among them, the processor 1201, the memory 1202, the input / output interface 1203, and the communication interface 1204 achieve communication connections with each other inside the device through the bus 1205.

[0170] The embodiments of this application also provide a storage medium. The storage medium is a storage medium that stores a computer program. When the computer program is executed by a processor, the above-mentioned data encryption and decryption method is implemented.

[0171] As a non-transitory storage medium, the memory can be used to store non-transitory software programs and non-transitory computer-executable programs. In addition, the memory can include high-speed random access memory and can also include non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory optionally includes a memory remotely set relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above networks include but are not limited to the Internet, enterprise intranets, local area networks, mobile communication networks, and their combinations.

[0172] The data encryption and decryption method, apparatus, device, and storage medium provided by the embodiments of the present application obtain public parameters generated according to security parameters, generate corresponding encryption public keys, encryption private keys, and mask parameters based on the public parameters, encrypt target data using the encryption public key to obtain encrypted data, and send the mask parameters, encryption public key, and encrypted data to a server device, so that the server device expands the encrypted data using the encryption public key to obtain an expanded ciphertext, performs homomorphic addition calculation on the expanded ciphertext based on the encryption public key and mask parameters, and then sends the obtained addition ciphertext to a user device, and uses the encryption private key to perform partial decoding on the received addition ciphertext to obtain the corresponding decoded plaintext. In the embodiments of the present application, each user device generates corresponding mask parameters to participate in the subsequent calculation process. During the homomorphic addition process, auxiliary data is introduced using the mask parameters to ensure that ciphertexts from different sources can be safely merged, and the calculation result still remains semantically secure. An attacker cannot distinguish whether two different ciphertexts correspond to the same plaintext, thereby preventing the leakage of sensitive plaintext information and enhancing the security of the multi-key encryption system.

[0173] The embodiments described in the embodiments of the present application are used to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art know that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.

[0174] Those skilled in the art can understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than those shown, or combine certain steps, or different steps.

[0175] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0176] Those of ordinary skill in the art can understand that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices can be implemented as software, firmware, hardware, and their appropriate combinations.

[0177] In the description of the present application and the above-mentioned drawings, the terms "first", "second", "third", "fourth", etc. (if any) are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.

[0178] It should be understood that in the present application, "at least one (item)" means one or more, and "a plurality" means two or more. "And / or" is used to describe the association relationship of associated objects and indicates that three relationships can exist. For example, "A and / or B" can mean: only A exists, only B exists, and both A and B exist simultaneously. Among them, A and B can be singular or plural. The character " / " generally indicates that the associated objects before and after are in an "or" relationship. "At least one (one) of the following" or similar expressions refer to any combination of these items, including any combination of single items (ones) or plural items (ones). For example, at least one (one) of a, b, or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.

[0179] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the above-mentioned division of units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling, direct coupling, or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of devices or units can be in electrical, mechanical, or other forms.

[0180] The units described above as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0181] In addition, in each embodiment of the present application, each functional unit can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.

[0182] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in each embodiment of the present application. The foregoing storage medium includes: various media that can store programs such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.

[0183] The preferred embodiments of the embodiments of the present application have been described above with reference to the accompanying drawings, and thus do not limit the scope of rights of the embodiments of the present application. Any modifications, equivalent replacements, and improvements made by those skilled in the art without departing from the scope and essence of the embodiments of the present application shall be within the scope of rights of the embodiments of the present application.

Claims

1. A data encryption and decryption method, characterized in that, Applied to a client device, the method includes: Obtaining public parameters generated according to security parameters, and generating a corresponding encryption public key, encryption private key, and mask parameter based on the public parameters; Encrypting target data using the encryption public key to obtain encrypted data, and sending the mask parameter, the encryption public key, and the encrypted data to a server device, so that the server device expands the encrypted data using the encryption public key to obtain an expanded ciphertext, and performs a homomorphic addition calculation on the expanded ciphertext based on the encryption public key and the mask parameter, and then sends the obtained addition ciphertext to the client device; Partially decoding the received addition ciphertext using the encryption private key to obtain a corresponding decoded plaintext.

2. The data encryption and decryption method according to claim 1, wherein The public parameters at least include a ciphertext modulus, a key distribution, a Gaussian error distribution, and a common reference string. The mask parameter includes a mask ciphertext and a mask key. The generating a corresponding encryption public key, encryption private key, and mask parameter based on the public parameters includes: Obtaining a private key parameter according to the key distribution, obtaining the encryption private key according to the private key parameter, and obtaining the encryption public key according to the key distribution, the common reference string, the ciphertext modulus, and the Gaussian error distribution; Performing Gadget encryption on a mask random polynomial to obtain the mask key, and encrypting target data based on the mask random polynomial and the encryption public key to obtain the mask ciphertext.

3. The data encryption and decryption method according to claim 2, wherein The obtaining the encryption public key according to the key distribution, the common reference string, the ciphertext modulus, and the Gaussian error distribution includes: Generating a first noise term according to the Gaussian error distribution, and obtaining a first intermediate term according to the first noise term and the ciphertext modulus; Obtaining a second intermediate term based on the private key parameter and the common reference string, summing the first intermediate term and the second intermediate term to obtain a third intermediate term, and obtaining the encryption public key according to the third intermediate term and the common reference string.

4. The data encryption and decryption method according to claim 2, wherein The public parameters further include a plaintext modulus. The encrypting target data based on the mask random polynomial and the encryption public key to obtain the mask ciphertext includes: Obtaining a product of the mask random polynomial and the encryption public key to obtain a first mask intermediate term, and generating a second noise term and a third noise term according to the Gaussian error distribution; When the encryption algorithm is a first encryption algorithm, obtaining a second mask intermediate term according to the second noise term and the third noise term, and obtaining the mask ciphertext according to a sum of the first mask intermediate term and the second mask intermediate term; When the encryption algorithm is a second encryption algorithm, obtaining a mask initial data according to the plaintext modulus, the ciphertext modulus, and the target data, calculating a sum of the mask initial data and the second noise term to obtain a third mask intermediate term, obtaining a fourth mask intermediate term according to the third mask intermediate term and the third noise term, and obtaining the mask ciphertext according to a sum of the first mask intermediate term and the fourth mask intermediate term.

5. The data encryption and decryption method according to claim 4, wherein The encrypting target data using the encryption public key to obtain encrypted data includes: Generate a fourth noise term and a fifth noise term according to the Gaussian error distribution, obtain an encryption distribution parameter according to the key distribution, and calculate the product of the encryption distribution parameter and the encryption public key to obtain a fifth masked intermediate term; When the encryption algorithm is the first encryption algorithm, use the target data as the encryption initial data. When the encryption algorithm is the second encryption algorithm, use the masked initial data as the encryption initial data; Obtain the encrypted data according to the encryption initial data, the fifth noise term, and the fifth masked intermediate term.

6. A data encryption and decryption method, characterized in that Applied to a server device, the method includes: Obtain at least one encrypted data from different client devices and the corresponding encryption public keys and masking parameters; Obtain the encryption public keys of at least one other client device to obtain an extended public key, and expand the encrypted data based on the extended public key and the masking parameters to obtain an extended ciphertext; Perform a homomorphic addition calculation on at least two of the extended ciphertexts using the masking parameters to obtain the addition ciphertexts corresponding to the corresponding client devices, and send the addition ciphertexts to the corresponding client devices; Obtain the decoded plaintext obtained by the client device partially decoding the addition ciphertext using the encryption private key, and aggregate all the decoded plaintexts to obtain the target plaintext.

7. The data encryption and decryption method according to claim 6, wherein The masking parameters include a masking key. The expanding the extended ciphertext based on the extended public key and the masking parameters includes: Calculate the difference value between each extended public key and the corresponding encryption public key, and accumulate the difference values to obtain a total difference value; Perform an outer product operation on the total difference value and the masking key to obtain the extended ciphertext, and the extended ciphertext includes a plaintext component and a public key component.

8. The data encryption and decryption method according to claim 7, characterized in that The masking parameters further include a masking ciphertext. The performing a homomorphic addition calculation on at least two of the extended ciphertexts using the masking parameters to obtain the addition ciphertexts corresponding to the corresponding client devices includes: Obtain the encryption public key, the masking ciphertext, and the masking key corresponding to each extended ciphertext; Obtain the plaintext component and the public key component in the extended ciphertext, and add the plaintext components to obtain a plaintext addition term; For each masking key, perform masking expansion according to all the masking keys to obtain a masked expansion key; Obtain the extended update ciphertext corresponding to each extended ciphertext according to the plaintext addition term, the masking ciphertext, and the masked expansion key, and obtain the addition ciphertext based on the extended update ciphertext.

9. A data encryption and decryption device, characterized in that, Applied to a client device, the apparatus includes: A key generation module: configured to obtain a public parameter generated according to a security parameter, and generate a corresponding encryption public key, an encryption private key, and a masking parameter according to the public parameter; Encryption module: It is used to encrypt the target data with the encryption public key to obtain encrypted data, and send the mask parameter, the encryption public key and the encrypted data to the server device, so that the server device expands the encrypted data with the encryption public key to obtain an expanded ciphertext, and performs a homomorphic addition calculation on the expanded ciphertext based on the encryption public key and the mask parameter, and then sends the obtained addition ciphertext to the client device; Decryption module: It is used to perform partial decoding on the received addition ciphertext with the encryption private key to obtain the corresponding decoded plaintext.

10. A data encryption and decryption device, characterized in that, Applied to a server device, the device includes: Parameter acquisition module: It is used to acquire at least one encrypted data, the corresponding encryption public key and mask parameter from different client devices; Expansion module: It is used to obtain an extended public key by acquiring the encryption public keys of at least one other client device, and expand the encrypted data based on the extended public key and the mask parameter to obtain an expanded ciphertext; Homomorphic calculation module: It is used to perform a homomorphic addition calculation on at least two of the expanded ciphertexts with the mask parameter to obtain the addition ciphertexts of the corresponding client devices, and send the addition ciphertexts to the corresponding client devices; Plaintext aggregation module: It is used to obtain the decoded plaintext obtained by the client device performing partial decoding on the addition ciphertext with the encryption private key, and aggregate all the decoded plaintexts to obtain the target plaintext.

11. An electronic device, characterized in that, The electronic device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the data encryption and decryption method according to any one of claims 1 to 8.

12. A storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the data encryption and decryption method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Multi-party computing method and system based on fully homomorphic encryption and related equipment

    CN114696990A

  • Data security aggregation method and system based on multi-homomorphic attributes

    CN116933899A

  • Data privacy protection method based on dynamic multi-key fully homomorphic encryption

    CN118264461A

  • Polynomial multiplication of encrypted values

    CN118402204A

  • Compact state data parallel sorting method and system based on fully homomorphic encryption

    CN119496603A

Cited By

  • Secret key packaging method and device

    CN122226285A

  • Key encapsulation methods and devices

    CN122226285B