Data decryption method and device, electronic equipment and storage medium

Through the elliptic curve cryptography algorithm, the private key operation and decryption data operation are separated, and the security and efficient decryption of multiple parties are realized, and the problems of unilateral protection of data and inefficient decryption in the existing technology are solved.

CN120433981APending Publication Date: 2025-08-05BEIJING CERTIFICATE AUTHORITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510560785.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-30
Publication Date
2025-08-05

AI Technical Summary

Technical Problem

The existing data protection scheme based on asymmetric encryption algorithm cannot support multi-party data protection, and the decryption efficiency is low, and the key generation difficulty and management complexity are high.

Method used

The elliptic curve cryptography algorithm is used to obtain the target public key and the target elliptic curve points of each participant, and separate the private key operation and decryption data operation processes, so that each participant can perform private key operation in parallel, ensuring the security and controllability of the private key and improving decryption efficiency.

Benefits of technology

On the premise of supporting one or more parties to jointly protect data, the security and controllability of the private keys of each participant are achieved and the data decryption efficiency is improved, the problem of the encryption and decryption permissions being concentrated on one party is solved, and the difficulty of key generation and management complexity is reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120433981A_ABST
    Figure CN120433981A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a data decryption method and device, electronic equipment and a storage medium. The method comprises the following steps: acquiring a target data ciphertext; the target data ciphertext is obtained by encrypting target data according to a target public key based on an elliptic curve cryptographic algorithm, and the target public key is determined according to the public key of each participant; based on an elliptic curve cryptographic algorithm, decrypting the target data ciphertext according to the target elliptic curve point of each participant to obtain a target data plaintext; the target elliptic curve point of each participant is determined by each participant according to the private key of each participant and the temporary elliptic curve point, and the temporary elliptic curve point is determined according to the target data ciphertext. According to the embodiment of the invention, the private key operation process and the decryption data operation process of each participant can be separated on the premise of supporting one or more parties to jointly protect the data, so that each participant can perform private key operation in parallel, the security controllability of the private key of each participant is ensured, and the data decryption efficiency is also improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data processing technology, and in particular to a data decryption method, device, electronic device and storage medium. Background Art

[0002] Traditional data protection schemes based on asymmetric algorithms mainly include the following two types: data encryption schemes based on asymmetric encryption algorithms and data encryption schemes based on collaborative encryption algorithms.

[0003] In practical applications, the main technical idea of a data encryption scheme based on an asymmetric encryption algorithm is to encrypt a certain data using the public key of a single party to obtain the encrypted data. The encrypted data can then only be decrypted using the private key of this single party. This scheme only supports single-party data protection and does not support multi-party data protection. There is a problem of encryption and decryption authority being concentrated in a single party. The main technical idea of a data encryption scheme based on a collaborative encryption algorithm is to pre-split the private key into multiple private key factors and distribute them to multiple parties. The collaborative public key is calculated based on the private keys of the multiple parties to encrypt a certain data to obtain the encrypted data. Although it can support multi-party joint data protection, it not only increases the difficulty of key generation and the complexity of key management, but also requires polling the private key factors held by multiple parties during the data decryption process. Each private key factor must participate in the calculation in a specific execution order to complete the data decryption, resulting in low data decryption efficiency. Summary of the Invention

[0004] The purpose of the embodiments of the present application is to provide a data decryption method, device, electronic device and storage medium, so as to achieve the technical effect of ensuring the security and controllability of the private keys of each participant while supporting one or more parties to jointly protect data, and improving the efficiency of data decryption.

[0005] In a first aspect, an embodiment of the present application provides a data decryption method, comprising:

[0006] Obtaining a ciphertext of target data; wherein the ciphertext of target data is obtained by encrypting the target data using an elliptic curve cryptography algorithm according to a target public key, wherein the target public key is determined based on the public keys of each of the at least one participant;

[0007] Based on the elliptic curve cryptographic algorithm, the target data ciphertext is decrypted according to the target elliptic curve point of each participant to obtain the target data plaintext; wherein, the target elliptic curve point of each participant is determined by each participant based on the private key and temporary elliptic curve point of each participant, and the temporary elliptic curve point is determined based on the target data ciphertext.

[0008] In the above implementation process, during the target data decryption stage, the target data ciphertext is obtained, which is obtained by encrypting the target data according to the target public key based on the elliptic curve cryptography algorithm, and the target public key is determined based on the public key of each participant in at least one participant, and the target elliptic curve point of each participant is obtained, and the target elliptic curve point of each participant is determined by each participant based on the private key and temporary elliptic curve point of each participant, and the temporary elliptic curve point is determined based on the target data ciphertext, and based on the elliptic curve cryptography algorithm, the target data ciphertext is decrypted according to the target elliptic curve point of each participant to obtain the target data plaintext. Under the premise of supporting one or more parties to jointly protect data, the private key operation process of each participant and the decryption data operation process can be separated, so that each participant can perform private key operations in parallel, which not only ensures the security and controllability of the private keys of each participant but also improves the data decryption efficiency.

[0009] Furthermore, the target public key is obtained by performing an addition operation on the public keys of the various participants.

[0010] In the above implementation process, the target public key is obtained by performing an addition operation on the public keys of each participant, which can quickly obtain the target public key and is conducive to improving data encryption efficiency.

[0011] Furthermore, the elliptic curve cryptography algorithm includes an SM2 algorithm; the target data ciphertext is obtained by:

[0012] Generate a first random number, and perform a scalar multiplication operation on the first random number and an elliptic curve base point to obtain a first bit string;

[0013] Performing a scalar multiplication operation on the cofactor and the target public key to obtain a first elliptic curve point;

[0014] When the first elliptic curve point is not a point at infinity, performing a scalar multiplication operation on the first random number and the target public key to obtain a second elliptic curve point;

[0015] determining a first security key according to the second elliptic curve point;

[0016] When the first security key is not an all-zero bit string, encrypting the target data according to the first security key to obtain a second bit string;

[0017] Performing a hash operation on the second elliptic curve point and the target data to obtain a third bit string;

[0018] The target data ciphertext is obtained according to the first bit string, the second bit string and the third bit string.

[0019] In the above implementation process, by encrypting the target data according to the target public key based on the SM2 algorithm in the target data encryption stage, the target data ciphertext is obtained. The high cryptographic security and excellent processing performance of the SM2 algorithm can be utilized to encrypt the target data more securely and efficiently.

[0020] Furthermore, determining the first security key according to the second elliptic curve point includes:

[0021] Determining the first security key according to the second elliptic curve point based on a predefined key derivation function;

[0022] The encrypting the target data according to the first security key to obtain a second bit string includes:

[0023] A bitwise exclusive OR operation is performed on the first security key and the target data to obtain the second bit string.

[0024] In the above implementation process, during the target data encryption stage, based on a predefined key derivation function, the first security key is determined according to the second elliptic curve point, and a bitwise exclusive OR operation is performed on the first security key and the target data to obtain a second bit string. This can utilize the high cryptographic security and support for key length extension of the key derivation function to encrypt the target data more securely and efficiently.

[0025] Furthermore, obtaining the target data ciphertext according to the first bit string, the second bit string, and the third bit string includes:

[0026] The first bit string, the second bit string, and the third bit string are concatenated according to a preset concatenation order to obtain the target data ciphertext.

[0027] In the above implementation process, by splicing the first bit string, the second bit string and the third bit string according to the preset splicing order in the target data encryption stage to obtain the target data ciphertext, it can ensure that the subsequent data decryption stage accurately extracts each bit string in the target data ciphertext for decryption operation, thereby further improving the data decryption efficiency.

[0028] Furthermore, the elliptic curve cryptography algorithm includes an SM2 algorithm, and the target data ciphertext includes a first bit string, a second bit string, and a third bit string;

[0029] Decrypting the target data ciphertext according to the target elliptic curve point of each participant to obtain the target data plaintext includes:

[0030] extracting the first bit string, the second bit string, and the third bit string from the target data ciphertext;

[0031] When the first bit string is an elliptic curve point, performing a scalar multiplication operation on the cofactor and the first bit string to obtain a third elliptic curve point;

[0032] When the third elliptic curve point is not a point at infinity, obtaining a target elliptic curve point of each participant;

[0033] Determining a fourth elliptic curve point based on the target elliptic curve point of each participant, a second random number, and the target public key; wherein the second random number is generated during the process of obtaining the target elliptic curve point of each participant;

[0034] determining a second security key according to the fourth elliptic curve point;

[0035] When the second security key is not an all-zero bit string, decrypt the second bit string according to the second security key to obtain a fourth bit string;

[0036] Performing a hash calculation based on the fourth elliptic curve point and the fourth bit string to obtain a fifth bit string;

[0037] When the fifth bit string is consistent with the third bit string, the target data plaintext is determined to be the fourth bit string.

[0038] In the above implementation process, in the target data decryption stage, based on the SM2 algorithm, the target data ciphertext is decrypted according to the temporary elliptic curve point of each participant to obtain the target data plaintext, and the second random number generated in the process of obtaining the target elliptic curve point of each participant is introduced to protect the transmission of the target elliptic curve point of each participant. This not only can the high cryptographic security and excellent processing performance of the SM2 algorithm be utilized for decryption operations, but also the risk of target data ciphertext leakage can be effectively reduced, preventing the middleman from intercepting the intermediate results of the decryption process and then implementing a decryption process replay attack, or directly decrypting the target data ciphertext based on the intermediate results, thereby ensuring the security of the cipher separation and decryption calculation process, and decrypting the target data more safely and efficiently.

[0039] Furthermore, obtaining the target elliptic curve point of each participant includes:

[0040] generating the second random number, and performing a scalar multiplication operation on the second random number and the elliptic curve base point to obtain a fifth elliptic curve point;

[0041] determining the temporary elliptic curve point according to the first bit string and the fifth elliptic curve point;

[0042] The temporary elliptic curve point is sent to each participant, and a target elliptic curve point of each participant is received.

[0043] In the above implementation process, during the target data decryption stage, a temporary elliptic curve point determined according to the first bit string in the target data ciphertext is uniformly sent to each participant, so that each participant determines the target elliptic curve point of each participant based on the private key and the temporary elliptic curve point of each participant, and receives the target elliptic curve point of each participant. This enables the private key processing operation to be transferred to each participant for parallel execution, thereby separating the private key processing operation from the data decryption operation, and effectively improving the data decryption efficiency.

[0044] In a second aspect, an embodiment of the present application provides a data decryption device, comprising:

[0045] a ciphertext acquisition module, configured to acquire a ciphertext of target data; wherein the ciphertext of target data is obtained by encrypting the target data using an elliptic curve cryptography algorithm according to a target public key, wherein the target public key is determined based on the public keys of each of the at least one participant;

[0046] A ciphertext decryption module is used to decrypt the target data ciphertext based on the elliptic curve cryptographic algorithm and the target elliptic curve point of each participant to obtain the target data plaintext; wherein the target elliptic curve point of each participant is determined by each participant based on the private key of each participant and a temporary elliptic curve point, and the temporary elliptic curve point is determined based on the target data ciphertext.

[0047] In a third aspect, an embodiment of the present application provides an electronic device, comprising a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor; when the processor executes the computer program, the method described above is implemented.

[0048] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, which includes a stored computer program; wherein, when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the method described above.

[0049] In a fifth aspect, an embodiment of the present application provides a computer program product, which includes instructions. When the instructions are executed by a computer, the computer implements the method described above. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without creative work.

[0051] Figure 1 A flowchart of a data decryption method provided in the first embodiment of the present application;

[0052] Figure 2 This is a data flow diagram of the target data encryption stage illustrated in the first embodiment of the present application;

[0053] Figure 3 This is a data flow diagram of the target data decryption stage of another example in the first embodiment of the present application;

[0054] Figure 4 A schematic structural diagram of a data decryption device provided in the second embodiment of the present application;

[0055] Figure 5 A schematic structural diagram of an electronic device provided in the third embodiment of the present application. DETAILED DESCRIPTION

[0056] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.

[0057] It should be noted that in the description of this application, the terms "first" and "second" are used only to distinguish descriptions and should not be understood to indicate or imply relative importance. Furthermore, the step numbers herein are used only to facilitate the explanation of the embodiments of this application and do not limit the order in which the steps are to be executed.

[0058] In related technologies, traditional data protection schemes based on asymmetric algorithms mainly include the following two types: data encryption schemes based on asymmetric encryption algorithms and data encryption schemes based on collaborative encryption algorithms.

[0059] In practical applications, the main technical idea of a data encryption scheme based on an asymmetric encryption algorithm is to encrypt a certain data using the public key of a single party to obtain the encrypted data. The encrypted data can then only be decrypted using the private key of this single party. This scheme only supports single-party data protection and does not support multi-party data protection. There is a problem of encryption and decryption authority being concentrated in a single party. The main technical idea of a data encryption scheme based on a collaborative encryption algorithm is to pre-split the private key into multiple private key factors and distribute them to multiple parties. The collaborative public key is calculated based on the private keys of the multiple parties to encrypt a certain data to obtain the encrypted data. Although it can support multi-party joint data protection, it not only increases the difficulty of key generation and the complexity of key management, but also requires polling the private key factors held by multiple parties during the data decryption process. Each private key factor must participate in the calculation in a specific execution order to complete the data decryption, resulting in low data decryption efficiency.

[0060] To this end, the present application proposes a data decryption method, which obtains the target data ciphertext in the target data decryption stage, the target data ciphertext is obtained by encrypting the target data according to the target public key based on the elliptic curve cryptography algorithm, and the target public key is determined based on the public key of each participant in at least one participant, and obtains the target elliptic curve point of each participant, the target elliptic curve point of each participant is determined by each participant based on the private key and temporary elliptic curve point of each participant, and the temporary elliptic curve point is determined based on the target data ciphertext, and based on the elliptic curve cryptography algorithm, the target data ciphertext is decrypted according to the target elliptic curve point of each participant to obtain the target data plaintext. Under the premise of supporting one or more parties to jointly protect data, the private key operation process of each participant and the decryption data operation process can be separated, so that each participant can perform private key operations in parallel, which not only ensures the security and controllability of the private keys of each participant but also improves the data decryption efficiency.

[0061] The method provided in the embodiment of the present application can be executed by a relevant terminal device, and the following description will be given using the data processing end as an example of the execution subject.

[0062] Please see Figure 1 , Figure 1 The first embodiment of the present application provides a data decryption method, which includes steps S101 to S102:

[0063] S101. Obtain target data ciphertext; wherein the target data ciphertext is obtained by encrypting the target data using an elliptic curve cryptography algorithm according to a target public key, where the target public key is determined based on the public keys of each of at least one participant;

[0064] S102. Based on the elliptic curve cryptography algorithm, the target data ciphertext is decrypted according to the target elliptic curve point of each participant to obtain the target data plaintext; wherein, the target elliptic curve point of each participant is determined by each participant according to the private key of each participant and the temporary elliptic curve point, and the temporary elliptic curve point is determined based on the target data ciphertext.

[0065] As an example, for data to be protected, ie, target data, at least one participant jointly protects the target data.

[0066] It should be noted that each participant in the at least one participant refers to the entity involved in data protection. This can be a mobile phone, tablet, or computer terminal device with communication capabilities held by an individual, a mobile phone, tablet, or computer terminal device with communication capabilities held by an organization, or a server-side device such as a cryptographic machine, cryptographic card, or other server equipped with a cryptographic module. Each participant has an independent and complete key pair, namely a public key and a private key. The data processing end refers to the terminal device trusted by the at least one participant to perform data encryption and decryption. This can be a terminal with a program running in a trusted execution environment, such as a trusted execution environment (TEE), or a platform built on a trusted execution environment.

[0067] In the target data encryption stage, the data processing end obtains the public key of each participant of the at least one participant, obtains the public key of each participant, determines the target public key based on the public key of each participant, and encrypts the target data according to the target public key based on the elliptic curve cryptography algorithm to obtain the target data ciphertext.

[0068] In actual applications, the target data encryption operation may also be performed by other devices trusted by at least one participant for data encryption and decryption.

[0069] In the target data decryption stage, the data processing end obtains the target data ciphertext and the target elliptic curve point of each participant, where the target elliptic curve point of each participant is determined by each participant based on the private key and temporary elliptic curve point of each participant. The temporary elliptic curve point is determined based on the target data ciphertext, and based on the elliptic curve cryptography algorithm, the target data ciphertext is decrypted according to the target elliptic curve point of each participant to obtain the target data plaintext.

[0070] In practical applications, the data processing end can first determine a temporary elliptic curve point based on the target data ciphertext after obtaining the target data ciphertext, and send the temporary elliptic curve point to each participant. Then, after receiving the temporary elliptic curve point, each participant extracts each participant's respective private key from each participant's respective key pair, determines each participant's respective target elliptic curve point based on each participant's respective private key and the temporary elliptic curve point, and sends each participant's respective target elliptic curve point to the data processing end. At this time, the data processing end can obtain each participant's target elliptic curve point.

[0071] In related technologies, data encryption schemes based on asymmetric encryption algorithms require that the party whose public key is used to encrypt the data must also use the party whose private key is used to decrypt the data. This only supports single-party data protection, not multi-party data protection, and results in the concentration of encryption and decryption authority on a single party. Data encryption schemes based on collaborative encryption algorithms require that the private key be split into multiple private key factors and distributed to multiple parties to collaborate on data encryption and decryption. While this supports multi-party data protection, it increases the difficulty of key generation and the complexity of key management. Furthermore, during the data decryption process, the private key factors held by multiple parties must be polled, requiring each private key factor to participate in the calculation in a specific execution order in order to complete data decryption, resulting in low data decryption efficiency.

[0072] In the target data encryption phase, a target public key determined based on the public keys of each participant is selected, and the target data is encrypted based on the target public key based on the elliptic curve cryptography algorithm to obtain the target data ciphertext. The target data can be encrypted based on the independent and complete public key of each participant, which not only supports joint data encryption by one or more parties, but also solves the problem of data encryption authority being concentrated in a single party. In addition, there is no need to split the key, effectively reducing the difficulty of key generation and the complexity of key management. In the target data decryption phase, after each participant determines its own target elliptic curve point based on its own private key and a temporary elliptic curve point determined based on the target data ciphertext, the target data ciphertext is decrypted based on the target elliptic curve point of each participant based on the elliptic curve cryptography algorithm to obtain the target data plaintext. The target data ciphertext can be decrypted based on the independent and complete private key of each participant, and the private key processing operation is transferred to each participant for parallel execution, separating the private key processing operation from the data decryption operation. This not only supports joint data decryption by one or more parties, but also solves the problem of data decryption authority being concentrated in a single party. In addition, there is no need to poll the private keys of each party to perform decryption operations in sequence, effectively improving data decryption efficiency.

[0073] The embodiment of the present application obtains the target data ciphertext during the target data decryption stage. The target data ciphertext is obtained by encrypting the target data according to the target public key based on the elliptic curve cryptography algorithm. The target public key is determined based on the public key of each participant of at least one participant. The target elliptic curve point of each participant is obtained. The target elliptic curve point of each participant is determined by each participant based on the private key and temporary elliptic curve point of each participant. The temporary elliptic curve point is determined based on the target data ciphertext. Based on the elliptic curve cryptography algorithm, the target data ciphertext is decrypted according to the target elliptic curve point of each participant to obtain the target data plaintext. Under the premise of supporting one or more parties to jointly protect data, the private key operation process of each participant and the decryption data operation process can be separated, so that each participant can perform private key operations in parallel, which not only ensures the security and controllability of the private keys of each participant but also improves the data decryption efficiency.

[0074] In an optional embodiment, the target public key is obtained by performing an addition operation on the public keys of each participant.

[0075] As an example, in the target data encryption stage, after obtaining the public keys of each participant, the data processing end performs an addition operation on the public keys of each participant to obtain the target public key.

[0076] For example, assuming that the public keys of the various participants are P1, P2, ..., Pm, where m is the total number of at least one participant, then the target public key P = P1 + P2 + ... + Pm.

[0077] The embodiment of the present application obtains the target public key by performing an addition operation on the public keys of each participant, which can quickly obtain the target public key and is conducive to improving data encryption efficiency.

[0078] In an optional embodiment, the elliptic curve cryptography algorithm includes an SM2 algorithm; the target data ciphertext is obtained in the following manner: generating a first random number, and performing a scalar multiplication operation based on the first random number and the elliptic curve base point to obtain a first bit string; performing a scalar multiplication operation based on the cofactor and the target public key to obtain a first elliptic curve point; when the first elliptic curve point is not an infinity point, performing a scalar multiplication operation based on the first random number and the target public key to obtain a second elliptic curve point; determining a first security key based on the second elliptic curve point; when the first security key is not an all-zero bit string, encrypting the target data based on the first security key to obtain a second bit string; performing a hash operation based on the second elliptic curve point and the target data to obtain a third bit string; obtaining the target data ciphertext based on the first bit string, the second bit string and the third bit string.

[0079] For example, elliptic curve cryptography (ECC) is a public-key cryptography scheme whose mathematical foundation is the computational difficulty of elliptic discrete logarithms on an Abelian additive group constructed from rational points on an elliptic curve. Its security relies on the difficulty of finding discrete logarithms on an elliptic curve over a finite field. In ECC, a base point G is typically chosen to generate a cyclic subgroup. The order of this subgroup (i.e., the number of elements in the subgroup) is denoted by n, while the number of points on the entire elliptic curve is denoted by N. Since the points on the elliptic curve form an Abelian additive group, according to Lagrange's theorem, n must be a divisor of N, and the cofactor h = N / n. In other words, the cofactor h is the ratio of the order of the entire elliptic curve group to the order of the subgroup generated by the selected base point.

[0080] The SM2 algorithm is an elliptic curve public key cryptography algorithm with the characteristics of high cryptographic complexity, fast processing speed and low machine performance consumption.

[0081] In the target data encryption stage, the data processing end selects the SM2 algorithm, and after obtaining the target public key, encrypts the target data according to the target public key based on the SM2 algorithm to obtain the target data ciphertext. Specifically, the target data ciphertext is obtained in the following manner: generate a first random number, and perform a scalar multiplication operation based on the first random number and the elliptic curve base point to obtain a first bit string; perform a scalar multiplication operation based on the cofactor and the target public key to obtain a first elliptic curve point; when the first elliptic curve point is not an infinity point, perform a scalar multiplication operation based on the first random number and the target public key to obtain a second elliptic curve point; determine the first security key based on the second elliptic curve point; when the first security key is not an all-zero bit string, encrypt the target data based on the first security key to obtain a second bit string; perform a hash operation based on the second elliptic curve point and the target data to obtain a third bit string; obtain the target data ciphertext based on the first bit string, the second bit string and the third bit string.

[0082] In practical applications, a scalar multiplication operation is performed on the first random number and the elliptic curve base point to obtain an elliptic curve point. After obtaining the elliptic curve point, the data type of the elliptic curve point needs to be converted into a bit string to obtain a first bit string.

[0083] It should be noted that the all-zero bit string refers to a bit string in which all bits are zero, for example, a bit string "00000000" in which all eight bits are zero.

[0084] In the target data encryption stage, the embodiment of the present application encrypts the target data according to the target public key based on the SM2 algorithm to obtain the target data ciphertext. This can utilize the high cryptographic security and excellent processing performance of the SM2 algorithm to encrypt the target data more securely and efficiently.

[0085] In an optional implementation of this embodiment, determining the first security key based on the second elliptic curve point includes: determining the first security key based on the second elliptic curve point based on a predefined key derivation function; encrypting the target data based on the first security key to obtain the second bit string includes: performing a bitwise exclusive OR operation on the first security key and the target data to obtain the second bit string.

[0086] As an example, a key derivation function (KDF) is typically used to generate a sufficiently long random key from a short initial key, which can improve the quality and security of the key. A key derivation function is defined in advance for target data.

[0087] In practical applications, the data type of the first security key determined from the second elliptic curve point is a bit string. To ensure the efficient execution of a subsequent bitwise exclusive OR operation, a key derivation function can be predefined based on the bit length of the target data. Based on the key derivation function, the second elliptic curve point is used to determine a first security key with the same number of bits as the target data.

[0088] In the target data encryption stage, the data processing end selects the SM2 algorithm, and after obtaining the target public key, encrypts the target data according to the target public key based on the SM2 algorithm to obtain the target data ciphertext. Specifically, the target data ciphertext is obtained in the following manner: generate a first random number, and perform a scalar multiplication operation based on the first random number and the elliptic curve base point to obtain a first bit string; perform a scalar multiplication operation based on the cofactor and the target public key to obtain a first elliptic curve point; when the first elliptic curve point is not an infinity point, perform a scalar multiplication operation based on the first random number and the target public key to obtain a second elliptic curve point; based on a predefined key derivation function, determine the first security key according to the second elliptic curve point; when the first security key is not an all-zero bit string, perform a bitwise exclusive OR operation based on the first security key and the target data to obtain a second bit string; perform a hash operation based on the second elliptic curve point and the target data to obtain a third bit string; obtain the target data ciphertext based on the first bit string, the second bit string and the third bit string.

[0089] In the embodiment of the present application, during the target data encryption stage, based on a predefined key derivation function and according to a second elliptic curve point, a first security key is determined, and a bitwise exclusive OR operation is performed on the first security key and the target data to obtain a second bit string. This can utilize the high cryptographic security and support for key length extension of the key derivation function to encrypt the target data more securely and efficiently.

[0090] In another optional implementation of this embodiment, obtaining the target data ciphertext based on the first bit string, the second bit string and the third bit string includes: splicing the first bit string, the second bit string and the third bit string according to a preset splicing order to obtain the target data ciphertext.

[0091] As an example, in order to accurately extract each bit string in the target data ciphertext for decryption operation in the subsequent target data decryption stage, the bit string splicing order can be set according to actual application requirements to obtain a preset splicing order.

[0092] After obtaining the first bit string, the second bit string and the third bit string, the data processing end splices the first bit string, the second bit string and the third bit string according to a preset splicing order to obtain the target data ciphertext.

[0093] For example, assuming that the preset splicing order is “first bit string→third bit string→second bit string”, the target data ciphertext is “first bit string||third bit string||second bit string”, where “||” represents splicing.

[0094] In the target data encryption stage, the embodiment of the present application obtains the target data ciphertext by splicing the first bit string, the second bit string and the third bit string in a preset splicing order. This can ensure that the subsequent data decryption stage accurately extracts each bit string in the target data ciphertext for decryption operation, thereby further improving the data decryption efficiency.

[0095] In order to explain the above target data encryption stage more clearly, Figure 2 As shown in the figure, the specific process of the data processing end obtaining the target data ciphertext is as follows:

[0096] 1. Request the public key of each of the m participants;

[0097] 2. Obtain the public keys P1, P2, ..., Pm of m participants;

[0098] 3. Based on the public keys P1, P2, ..., Pm of the m participants, determine the target public key P = P1 + P2 + ... + Pm;

[0099] 4. Based on the SM2 algorithm, the target data M is encrypted according to the target public key P to obtain the target data ciphertext C, as follows:

[0100] (1) Generate a first random number k, where k∈[1,n-1], n is the order of the elliptic curve, and perform a scalar multiplication operation on the first random number k and the elliptic curve base point G to obtain a first bit string C1=[k]G;

[0101] (2) Perform scalar multiplication based on the cofactor h and the target public key P to obtain the first elliptic curve point S = [h]P;

[0102] (3) If the first elliptic curve point S is a point at infinity on the elliptic curve, report an error and exit;

[0103] (4) When the first elliptic curve point S is not a point at infinity, a scalar multiplication operation is performed based on the first random number k and the target public key P to obtain a second elliptic curve point (x1, y1) = [k]P;

[0104] (5) Based on a predefined key derivation function and the second elliptic curve point (x1, y1), determine a first security key t = KDF(x2||y2, klen), where klen is the bit length of the target data M;

[0105] (6) If the first security key t is an all-zero bit string, report an error and exit;

[0106] (7) When the first security key t is not an all-zero bit string, the target data M is encrypted according to the first security key t to obtain a second bit string C2=M⊕t, where ⊕ represents a bitwise exclusive OR operation;

[0107] (8) Perform a hash operation on the second elliptic curve point (x1, y1) and the target data M to obtain a third bit string C3 = Hash(x2||M||y2);

[0108] (9) According to the first bit string C1, the second bit string C2 and the third bit string C3, the target data ciphertext C=C1||C3||C2 is obtained.

[0109] In an optional embodiment, the elliptic curve cryptography algorithm includes an SM2 algorithm, the target data ciphertext includes a first bit string, a second bit string, and a third bit string; the decrypting the target data ciphertext according to the target elliptic curve point of each participant to obtain the target data plaintext includes: extracting the first bit string, the second bit string, and the third bit string from the target data ciphertext; when the first bit string is an elliptic curve point, performing a scalar multiplication operation based on the cofactor and the first bit string to obtain a third elliptic curve point; when the third elliptic curve point is not an infinity point, obtaining the target elliptic curve point of each participant; determining a fourth elliptic curve point based on the target elliptic curve point of each participant, a second random number, and a target public key; wherein the second random number is generated during the process of obtaining the target elliptic curve point of each participant; determining a second security key based on the fourth elliptic curve point; when the second security key is not an all-zero bit string, decrypting the second bit string according to the second security key to obtain a fourth bit string; performing a hash calculation based on the fourth elliptic curve point and the fourth bit string to obtain a fifth bit string; and determining that the target data plaintext is the fourth bit string when the fifth bit string is consistent with the third bit string.

[0110] As an example, the target data ciphertext encrypted based on the SM2 algorithm includes a first bit string, a second bit string and a third bit string. Under this premise, the elliptic curve cryptography algorithm selects the SM2 algorithm.

[0111] In the target data decryption phase, the data processing end obtains the target data ciphertext, selects the SM2 algorithm for the target data ciphertext, and obtains the target elliptic curve point of each participant, wherein the target elliptic curve point of each participant is determined by each participant based on the private key and temporary elliptic curve point of each participant, and the temporary elliptic curve point is determined based on the target data ciphertext, and based on the SM2 algorithm, the target data ciphertext is decrypted according to the target elliptic curve point of each participant to obtain the target data plaintext. Specifically, the target data plaintext is obtained in the following manner: extracting the first bit string, the second bit string and the third bit string from the target data ciphertext; when the first bit string is an elliptic curve point, performing scalar operation based on the cofactor and the first bit string multiplication operation to obtain a third elliptic curve point; when the third elliptic curve point is not a point at infinity, obtain the target elliptic curve point of each participant; determine the fourth elliptic curve point based on the target elliptic curve point of each participant, the second random number and the target public key; wherein the second random number is generated in the process of obtaining the target elliptic curve point of each participant; determine the second security key based on the fourth elliptic curve point; when the second security key is not an all-zero bit string, decrypt the second bit string based on the second security key to obtain a fourth bit string; perform a hash calculation based on the fourth elliptic curve point and the fourth bit string to obtain a fifth bit string; when the fifth bit string is consistent with the third bit string, determine that the target data plaintext is the fourth bit string.

[0112] Among them, by introducing a second random number generated in the process of obtaining the target elliptic curve point of each participant, and determining the fourth elliptic curve point according to the target elliptic curve point of each participant, the second random number and the target public key, the target elliptic curve point of each participant can be protected from transmission to avoid replay attacks. At the same time, it is ensured that even if the target elliptic curve point of each participant is intercepted, the final decryption cannot be completed, effectively reducing the risk of target data ciphertext leakage.

[0113] In the target data decryption stage, the embodiment of the present application decrypts the target data ciphertext based on the temporary elliptic curve point of each participant based on the SM2 algorithm to obtain the target data plaintext, and introduces a second random number generated in the process of obtaining the target elliptic curve point of each participant to protect the transmission of the target elliptic curve point of each participant. It can not only utilize the high cryptographic security and excellent processing performance of the SM2 algorithm to perform decryption operations, but also effectively reduce the risk of target data ciphertext leakage, prevent the middleman from intercepting the intermediate results of the decryption process and then implementing a decryption process replay attack, or directly decrypt the target data ciphertext based on the intermediate results, thereby ensuring the security of the cipher separation and decryption calculation process, and decrypting the target data more safely and efficiently.

[0114] In an optional implementation of this embodiment, obtaining the target elliptic curve point of each participant includes: generating a second random number, and performing a scalar multiplication operation based on the second random number and the elliptic curve base point to obtain a fifth elliptic curve point; determining a temporary elliptic curve point based on the first bit string and the fifth elliptic curve point; sending the temporary elliptic curve point to each participant, and receiving the target elliptic curve point of each participant.

[0115] As an example, in the target data decryption stage, after the data processing end obtains the target data ciphertext, the SM2 algorithm is selected for the target data ciphertext, and the target elliptic curve point of each participant is obtained. Specifically, the target elliptic curve point of each participant is obtained in the following manner: a second random number is generated, and a scalar multiplication operation is performed based on the second random number and the elliptic curve base point to obtain a fifth elliptic curve point; a temporary elliptic curve point is determined based on the first bit string and the fifth elliptic curve point; the temporary elliptic curve point is sent to each participant, and the target elliptic curve point of each participant is received, and based on the SM2 algorithm, the target data ciphertext is decrypted based on the target elliptic curve point of each participant to obtain the target data plaintext. Specifically, the target data plaintext is obtained in the following manner: the first bit string, the second bit string and the third bit string are extracted from the target data ciphertext. bit string; when the first bit string is an elliptic curve point, perform a scalar multiplication operation based on the cofactor and the first bit string to obtain a third elliptic curve point; when the third elliptic curve point is not a point at infinity, obtain the target elliptic curve point of each participant; determine the fourth elliptic curve point based on the target elliptic curve point of each participant, the second random number and the target public key; wherein the second random number is generated in the process of obtaining the target elliptic curve point of each participant; determine the second security key based on the fourth elliptic curve point; when the second security key is not an all-zero bit string, decrypt the second bit string based on the second security key to obtain a fourth bit string; perform a hash calculation based on the fourth elliptic curve point and the fourth bit string to obtain a fifth bit string; when the fifth bit string is consistent with the third bit string, determine that the target data plaintext is the fourth bit string.

[0116] In the target data decryption phase, the embodiment of the present application uniformly sends a temporary elliptic curve point determined according to the first bit string in the target data ciphertext to each participant, so that each participant determines the target elliptic curve point of each participant based on the private key and the temporary elliptic curve point of each participant, and receives the target elliptic curve point of each participant. This can transfer the private key processing operation to each participant for parallel execution, separate the private key processing operation from the data decryption operation, and effectively improve the data decryption efficiency.

[0117] In order to explain the above target data decryption stage more clearly, Figure 3As shown in the figure, the specific process of the data processing end obtaining the target data plaintext is as follows:

[0118] 1. Obtain the target data ciphertext C=C1||C3||C2;

[0119] 2. Extract the first bit string C1, the second bit string C2, and the third bit string C3 from the target data ciphertext C;

[0120] 3. If the first bit string C1 is not an elliptic curve point, an error is reported and the process exits.

[0121] 4. When the first bit string C1 is an elliptic curve point, perform a scalar multiplication operation on the cofactor h and the first bit string C1 to obtain a third elliptic curve point S' = [h] C1;

[0122] 5. If the third elliptic curve point S' is at infinity, an error is reported and the program exits.

[0123] 6. When the third elliptic curve point S' is not a point at infinity, obtain the target elliptic curve points Q1, Q2, ..., Qm of the m participants as follows:

[0124] (1) Generate a second random number k', and perform a scalar multiplication operation on the second random number k' and the elliptic curve base point G to obtain a fifth elliptic curve point k'G;

[0125] (2) Determine a temporary elliptic curve point Q = C1 - k'G based on the first bit string C1 and the fifth elliptic curve point k'G;

[0126] (3) Send a temporary elliptic curve point Q to each of the m participants and receive the target elliptic curve points Q1, Q2, ..., Qm from each of the m participants, where Qi = diQ, Qi is the target elliptic curve point of the i-th participant among the m participants, di is the private key of the i-th participant, and i = {1, 2, ..., m};

[0127] 7. Obtain the public keys P1, P2, ..., Pm of m participants;

[0128] 8. Based on the public keys P1, P2, ..., Pm of the m participants, determine the target public key P = P1 + P2 + ... + Pm;

[0129] 9. Determine a fourth elliptic curve point (x2, y2) = (Q1 + Q2 + ... Qn) + k'P based on the target elliptic curve points Q1, Q2, ..., Qm of the m participants, the second random number k', and the target public key P;

[0130] 10. Determine, based on a predefined key derivation function and from the fourth elliptic curve point (x2, y2), a second security key t'=KDF(x2||y2, klen'), where klen' is the length of the second bit string;

[0131] 11. If the second security key t' is an all-zero bit string, report an error and exit;

[0132] 12. If the second security key t' is not an all-zero bit string, decrypt the second bit string C2 according to the second security key t' to obtain a fourth bit string C4 = C2⊕t', where ⊕ represents a bitwise exclusive OR operation;

[0133] 13. Perform a hash calculation based on the fourth elliptic curve point (x2, y2) and the fourth bit string C4 to obtain a fifth bit string C5 = Hash(x2||C4||y2);

[0134] 14. When the fifth bit string C5 is consistent with the third bit string C3, the target data plaintext M' is determined to be the fourth bit string C4.

[0135] Please see Figure 4 , Figure 4 A schematic diagram of the structure of a data decryption device provided in the second embodiment of the present application. The second embodiment of the present application provides a data decryption device, comprising: a ciphertext acquisition module 201, for acquiring a target data ciphertext; wherein the target data ciphertext is obtained by encrypting the target data according to a target public key based on an elliptic curve cryptographic algorithm, and the target public key is determined based on the public key of each participant in at least one participant; a ciphertext decryption module 202, for decrypting the target data ciphertext based on an elliptic curve cryptographic algorithm and a target elliptic curve point of each participant to obtain a target data plaintext; wherein the target elliptic curve point of each participant is determined by each participant according to the private key of each participant and a temporary elliptic curve point, and the temporary elliptic curve point is determined based on the target data ciphertext.

[0136] In an optional embodiment, the target public key is obtained by performing an addition operation on the public keys of each participant.

[0137] In an optional embodiment, the elliptic curve cryptography algorithm includes an SM2 algorithm; the target data ciphertext is obtained in the following manner: generating a first random number, and performing a scalar multiplication operation based on the first random number and the elliptic curve base point to obtain a first bit string; performing a scalar multiplication operation based on the cofactor and the target public key to obtain a first elliptic curve point; when the first elliptic curve point is not an infinity point, performing a scalar multiplication operation based on the first random number and the target public key to obtain a second elliptic curve point; determining a first security key based on the second elliptic curve point; when the first security key is not an all-zero bit string, encrypting the target data based on the first security key to obtain a second bit string; performing a hash operation based on the second elliptic curve point and the target data to obtain a third bit string; obtaining the target data ciphertext based on the first bit string, the second bit string and the third bit string.

[0138] In an optional embodiment, determining the first security key based on the second elliptic curve point includes: determining the first security key based on the second elliptic curve point based on a predefined key derivation function; encrypting the target data based on the first security key to obtain the second bit string includes: performing a bitwise exclusive OR operation on the first security key and the target data to obtain the second bit string.

[0139] In an optional embodiment, obtaining the target data ciphertext based on the first bit string, the second bit string and the third bit string includes: splicing the first bit string, the second bit string and the third bit string in a preset splicing order to obtain the target data ciphertext.

[0140] In an optional embodiment, the elliptic curve cryptography algorithm includes an SM2 algorithm, the target data ciphertext includes a first bit string, a second bit string, and a third bit string; the decrypting the target data ciphertext according to the target elliptic curve point of each participant to obtain the target data plaintext includes: extracting the first bit string, the second bit string, and the third bit string from the target data ciphertext; when the first bit string is an elliptic curve point, performing a scalar multiplication operation based on the cofactor and the first bit string to obtain a third elliptic curve point; when the third elliptic curve point is not an infinity point, obtaining the target elliptic curve point of each participant; determining a fourth elliptic curve point based on the target elliptic curve point of each participant, a second random number, and a target public key; wherein the second random number is generated during the process of obtaining the target elliptic curve point of each participant; determining a second security key based on the fourth elliptic curve point; when the second security key is not an all-zero bit string, decrypting the second bit string according to the second security key to obtain a fourth bit string; performing a hash calculation based on the fourth elliptic curve point and the fourth bit string to obtain a fifth bit string; and determining that the target data plaintext is the fourth bit string when the fifth bit string is consistent with the third bit string.

[0141] In an optional embodiment, obtaining the target elliptic curve point of each participant includes: generating a second random number, and performing a scalar multiplication operation based on the second random number and the elliptic curve base point to obtain a fifth elliptic curve point; determining a temporary elliptic curve point based on the first bit string and the fifth elliptic curve point; sending the temporary elliptic curve point to each participant, and receiving the target elliptic curve point of each participant.

[0142] The implementation process of the functions and effects of each module in the above-mentioned device is specifically described in the implementation process of the corresponding steps in the above-mentioned method, and will not be repeated here.

[0143] Please see Figure 5 , Figure 5 This is a schematic diagram of the structure of an electronic device provided in the third embodiment of the present application. The third embodiment of the present application provides an electronic device 30, comprising a processor 301, a memory 302, and a computer program stored in the memory 302 and configured to be executed by the processor 301; when the processor 301 executes the computer program, it implements the method described in the first embodiment of the present application and can achieve the same beneficial effects as described above.

[0144] In which, when the processor 301 reads the computer program from the memory 302 through the bus 303 and executes the computer program, it can implement the method of any embodiment included in the method described in the first embodiment of the present application.

[0145] Processor 301 can process digital signals and can include various computing architectures, such as a complex instruction set computer architecture, a reduced instruction set computer architecture, or an architecture that implements a combination of multiple instruction sets. In some examples, processor 301 can be a microprocessor.

[0146] The memory 302 can be used to store instructions executed by the processor 301 or data related to the execution of instructions. These instructions and / or data may include code for implementing some or all functions of one or more modules described in the embodiments of this application. The processor 301 of the embodiment of the present disclosure can be used to execute the instructions in the memory 302 to implement the method described in the first embodiment of this application. The memory 302 includes dynamic random access memory, static random access memory, flash memory, optical storage, or other memory known to those skilled in the art.

[0147] The fourth embodiment of the present application provides a computer-readable storage medium, which includes a stored computer program; wherein, when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the method described in the first embodiment of the present application, and can achieve the same beneficial effects as the method described in the first embodiment of the present application.

[0148] The fifth embodiment of the present application provides a computer program product, which includes instructions. When the instructions are executed by a computer, the computer implements the method described in the first embodiment of the present application and can achieve the same beneficial effects.

[0149] The method described in the first embodiment of the present application can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in each embodiment of the present application are executed in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, a core network device, an OAM (Open Application Model), or other programmable device.

[0150] The computer program or instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer program or instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired or wireless method. The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium, such as a floppy disk, a hard disk, or a magnetic tape; an optical medium, such as a digital video disk; or a semiconductor medium, such as a solid-state drive. The computer-readable storage medium may be a volatile or non-volatile storage medium, or may include both volatile and non-volatile types of storage media.

[0151] In summary, the embodiments of the present application provide a data decryption method, device, electronic device and storage medium, the data decryption method including: obtaining a target data ciphertext; wherein, the target data ciphertext is obtained by encrypting the target data according to a target public key based on an elliptic curve cryptographic algorithm, and the target public key is determined based on the public key of each participant in at least one participant; based on the elliptic curve cryptographic algorithm, the target data ciphertext is decrypted according to the target elliptic curve point of each participant to obtain the target data plaintext; wherein, the target elliptic curve point of each participant is determined by each participant according to the private key and temporary elliptic curve point of each participant, and the temporary elliptic curve point is determined based on the target data ciphertext. The embodiment of the present application obtains the target data ciphertext during the target data decryption stage. The target data ciphertext is obtained by encrypting the target data according to the target public key based on the elliptic curve cryptography algorithm. The target public key is determined based on the public key of each participant of at least one participant. The target elliptic curve point of each participant is obtained. The target elliptic curve point of each participant is determined by each participant based on the private key and temporary elliptic curve point of each participant. The temporary elliptic curve point is determined based on the target data ciphertext. Based on the elliptic curve cryptography algorithm, the target data ciphertext is decrypted according to the target elliptic curve point of each participant to obtain the target data plaintext. Under the premise of supporting one or more parties to jointly protect data, the private key operation process of each participant and the decryption data operation process can be separated, so that each participant can perform private key operations in parallel, which not only ensures the security and controllability of the private keys of each participant but also improves the data decryption efficiency.

[0152] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely schematic. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions and operations of the devices, methods and computer program products according to multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of the code, and the module, program segment or a part of the code contains one or more executable instructions for implementing the specified logical functions. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or action, or can be implemented using a combination of dedicated hardware and computer instructions.

[0153] In addition, the functional modules in each embodiment of the present application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0154] If the functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0155] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any modifications or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

Claims

1. A data decryption method, characterized in that: include: Obtaining a ciphertext of target data; wherein the ciphertext of target data is obtained by encrypting the target data using an elliptic curve cryptography algorithm according to a target public key, wherein the target public key is determined based on the public keys of each of the at least one participant; Based on the elliptic curve cryptographic algorithm, the target data ciphertext is decrypted according to the target elliptic curve point of each participant to obtain the target data plaintext; wherein, the target elliptic curve point of each participant is determined by each participant based on the private key and temporary elliptic curve point of each participant, and the temporary elliptic curve point is determined based on the target data ciphertext.

2. The method according to claim 1, characterized in that The target public key is obtained by performing an addition operation on the public keys of the various participants.

3. The method according to claim 1, characterized in that The elliptic curve cryptographic algorithm includes the SM2 algorithm; the target data ciphertext is obtained by: Generate a first random number, and perform a scalar multiplication operation on the first random number and an elliptic curve base point to obtain a first bit string; Performing a scalar multiplication operation on the cofactor and the target public key to obtain a first elliptic curve point; When the first elliptic curve point is not a point at infinity, performing a scalar multiplication operation on the first random number and the target public key to obtain a second elliptic curve point; determining a first security key according to the second elliptic curve point; When the first security key is not an all-zero bit string, encrypting the target data according to the first security key to obtain a second bit string; Performing a hash operation on the second elliptic curve point and the target data to obtain a third bit string; The target data ciphertext is obtained according to the first bit string, the second bit string and the third bit string.

4. The method according to claim 3, characterized in that The determining the first security key according to the second elliptic curve point includes: Determining the first security key according to the second elliptic curve point based on a predefined key derivation function; The encrypting the target data according to the first security key to obtain a second bit string includes: A bitwise exclusive OR operation is performed on the first security key and the target data to obtain the second bit string.

5. The method according to claim 3, characterized in that The obtaining the target data ciphertext according to the first bit string, the second bit string, and the third bit string includes: The first bit string, the second bit string, and the third bit string are concatenated according to a preset concatenation order to obtain the target data ciphertext.

6. The method according to any one of claims 1 to 5, characterized in that The elliptic curve cryptographic algorithm includes an SM2 algorithm, and the target data ciphertext includes a first bit string, a second bit string, and a third bit string; Decrypting the target data ciphertext according to the target elliptic curve point of each participant to obtain the target data plaintext includes: extracting the first bit string, the second bit string, and the third bit string from the target data ciphertext; When the first bit string is an elliptic curve point, performing a scalar multiplication operation on the cofactor and the first bit string to obtain a third elliptic curve point; When the third elliptic curve point is not a point at infinity, obtaining a target elliptic curve point of each participant; Determining a fourth elliptic curve point based on the target elliptic curve point of each participant, a second random number, and the target public key; wherein the second random number is generated during the process of obtaining the target elliptic curve point of each participant; determining a second security key according to the fourth elliptic curve point; When the second security key is not an all-zero bit string, decrypt the second bit string according to the second security key to obtain a fourth bit string; Performing a hash calculation based on the fourth elliptic curve point and the fourth bit string to obtain a fifth bit string; When the fifth bit string is consistent with the third bit string, the target data plaintext is determined to be the fourth bit string.

7. The method according to claim 6, characterized in that The obtaining of the target elliptic curve point of each participant includes: generating the second random number, and performing a scalar multiplication operation on the second random number and the elliptic curve base point to obtain a fifth elliptic curve point; determining the temporary elliptic curve point according to the first bit string and the fifth elliptic curve point; The temporary elliptic curve point is sent to each participant, and a target elliptic curve point of each participant is received.

8. A data decryption device, characterized in that: include: a ciphertext acquisition module, configured to acquire a ciphertext of target data; wherein the ciphertext of target data is obtained by encrypting the target data using an elliptic curve cryptography algorithm according to a target public key, wherein the target public key is determined based on the public keys of each of the at least one participant; A ciphertext decryption module is used to decrypt the target data ciphertext based on the elliptic curve cryptographic algorithm and the target elliptic curve point of each participant to obtain the target data plaintext; wherein the target elliptic curve point of each participant is determined by each participant based on the private key of each participant and a temporary elliptic curve point, and the temporary elliptic curve point is determined based on the target data ciphertext.

9. An electronic device, characterized in that: The method comprises a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor; when the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium includes a stored computer program; wherein, when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the method according to any one of claims 1 to 7.