Information verification method and device, information response method and device, computer equipment and storage medium

By using the function secret sharing scheme in the privacy information retrieval system, the checksum predicate function is fragmented and reconstructed on the client, the data authenticity and integrity problems in a multi-server environment are solved, and efficient and secure query results are achieved.

CN120470024APending Publication Date: 2025-08-12PING AN TECH (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510530006.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-24
Publication Date
2025-08-12

AI Technical Summary

Technical Problem

The existing privacy information retrieval scheme cannot effectively ensure the authenticity and integrity of data in a multi-server environment, and the communication and computing costs are high, especially when facing malicious servers, it cannot effectively verify the query results.

Method used

The function secret sharing scheme is used to divide the verification function and predicate function into multiple shards, sent to multiple servers for calculation, and the response results are reconstructed and verified on the client side, and the preset verification parameters are used to ensure the accuracy of the results.

Benefits of technology

It realizes the accuracy of query results automatically in a multi-server environment, improves the security and reliability of the system, and reduces the cost of calculation and communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120470024A_ABST
    Figure CN120470024A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data processing, in particular to an information verification method and device, an information response method and device, computer equipment and a storage medium. Using a function secret sharing scheme to obtain a first function fragment of the correction function and a second function fragment of the predicate function, responding to the first function fragment and the second function fragment according to the server side to obtain a first response result and a second response result, and reconstructing the first response result and the second response result at the client side respectively to obtain a second response result; the first reconstruction result and the second reconstruction result are obtained, the second reconstruction result is verified according to the first reconstruction result, the second reconstruction result and verification parameters, a verification result is obtained, and the second reconstruction result is determined as a query result when the verification result passes. And the response result of the query information is automatically verified so as to accurately obtain the query result of the information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data processing technology, and in particular to an information verification and information response method, device, computer equipment and storage medium. Background Art

[0002] In the field of private information retrieval, existing technologies are mainly divided into multi-server and single-server. Multi-server is usually based on information security. The main purpose of adopting a multi-server private information retrieval solution is to protect user privacy and ensure that the server cannot instruct the user on the specific content of the query. At the same time, it also requires that users can only access the queried data and have strict access control over the database content. Most current privacy information retrieval solutions require that multiple servers cannot collude, increasing the difficulty of system implementation and deployment. For example, in the information security field, when executing complex queries, existing solutions cannot effectively guarantee the authenticity and integrity of data in the face of malicious servers. Most current privacy information retrieval technologies do not verify the query data, thus making data authenticity uncertain. Furthermore, the communication costs of multiple servers are high, while the computational costs of a single server are high.

[0003] Therefore, how to automatically verify the response results of the query information to accurately obtain the query results of the information has become an urgent problem to be solved. Summary of the Invention

[0004] The embodiments of the present invention provide an information verification and information response method, apparatus, computer equipment and storage medium to solve the problem of how to automatically verify the response result of query information to accurately obtain the query result of the information.

[0005] In a first aspect, an embodiment of the present invention provides a query information verification method, which is applied to a client of a query system, wherein the query system further includes k servers, where k is an integer greater than 2, and includes: Obtaining a query instruction from a user received by the client, generating a predicate function based on the query instruction, and constructing a verification function using preset verification parameters in combination with the predicate function; Using a function secret sharing scheme, the verification function is divided into k first function slices, and the predicate function is divided into k second function slices; Sending the k first function slices to k servers respectively, and sending the k second function slices to the k servers respectively, obtaining a response result from each server, wherein each server is configured to use the function secret sharing scheme to perform a response calculation on the obtained first function slice to obtain a first response result, and to perform a response calculation on the obtained second function slice to obtain a second response result; Reconstructing the first response results of all servers to obtain a first reconstruction result, and reconstructing the second response results of all servers to obtain a second reconstruction result; The first reconstruction result and the second reconstruction result are verified using the preset verification parameters to obtain a query verification result, and the query verification result is used to determine that the second reconstruction result is a query result when passing.

[0006] In a second aspect, an embodiment of the present invention provides a query information response method, which is applied to each server of a query system, wherein the query system includes k servers and clients, where k is an integer greater than 2. For any server, the method includes: Obtaining the first function shard and the second function shard sent by the client and a response database in response to the query instruction; Extracting a data element from the response database, combining the data element with the first function slice into a first parameter pair, and combining the data element with the second function slice into a second parameter pair; Obtaining a preset weight parameter, and performing a continuous addition calculation on each server on the weight parameter, the first function shard, and the function secret sharing scheme to obtain the first response result; In each server, the weight parameter, the second function shard, and the function secret sharing scheme are subjected to a continuous addition calculation to obtain the second response result, and the first response result and the second response result are sent to the client.

[0007] In a third aspect, an embodiment of the present invention provides a query information verification device, wherein the query information verification method is applied to a client of a query system, wherein the query system further includes k servers, where k is an integer greater than 2, including: A function construction module is used to obtain a query instruction from a user received by a client, generate a predicate function according to the query instruction, and construct a verification function using preset verification parameters in combination with the predicate function; a function sharding module, configured to divide the verification function into k first function shards and the predicate function into k second function shards using a function secret sharing scheme; a response module, configured to send the k first function slices to k servers respectively, and send the k second function slices to the k servers respectively, and obtain a response result from each server, wherein each server is configured to use the function secret sharing scheme to perform a response calculation on the obtained first function slice to obtain a first response result, and to perform a response calculation on the obtained second function slice to obtain a second response result; a reconstruction module, configured to reconstruct the first response results of all servers to obtain a first reconstruction result, and reconstruct the second response results of all servers to obtain a second reconstruction result; A verification module is used to verify the first reconstruction result and the second reconstruction result using the preset verification parameters to obtain a query verification result, and the query verification result is used to determine that the second reconstruction result is a query result when passing.

[0008] In a fourth aspect, an embodiment of the present invention provides a query information response device, wherein the query information response method is applied to each server of a query system, wherein the query system includes k servers and clients, where k is an integer greater than 2, and for each server, includes: A response module, configured to obtain the first function shard and the second function shard sent by the client and a response database in response to the query instruction; a data combination module, configured to extract data elements from the response database, combine the data elements with the first function slice into a first parameter pair, and combine the data elements with the second function slice into a second parameter pair; a calculation module, configured to obtain a preset weight parameter, and perform a continuous addition calculation on the weight parameter, the first function shard, and the function secret sharing scheme in each server to obtain the first response result; The response sending module is used to perform a continuous addition calculation on the weight parameter, the second function shard, and the function secret sharing scheme in each server to obtain the second response result, and send the first response result and the second response result to the client.

[0009] In a fifth aspect, an embodiment of the present invention provides a computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the above-mentioned query information verification method or the above-mentioned query information response method when executing the computer program.

[0010] In a sixth aspect, an embodiment of the present invention provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the computer program implements the above-mentioned query information verification method or the above-mentioned query information response method.

[0011] Compared with the prior art, the present invention has the following beneficial effects: by obtaining the query instruction of the user received by the client, generating a predicate function according to the query instruction, using preset verification parameters in combination with the predicate function to construct a verification function, using a function secret sharing scheme, dividing the verification function into k first function slices, and dividing the predicate function into k second function slices, sending the k first function slices to k servers respectively, and sending the k second function slices to k servers respectively, obtaining the response result of each server, each server is used to use the function secret sharing scheme to perform response calculation on the obtained first function slice to obtain a first response result, and to perform response calculation on the obtained second function slice to obtain a second response result, reconstructing the first response results of all servers to obtain a first reconstruction result, reconstructing the second response results of all servers to obtain a second reconstruction result, using preset verification parameters, verifying the first reconstruction result and the second reconstruction result to obtain a query verification result, and the query verification result is used to determine that the second reconstruction result is the query result when passed. The correction function is obtained by combining the predicate function generated by the client with the verification parameter, and a function secret sharing scheme is used to obtain a first function slice of the correction function and a second function slice of the predicate function. The server responds to the first function slice and the second function slice to obtain a first response result and a second response result. The first response result and the second response result are respectively reconstructed on the client to obtain a first reconstruction result and a second reconstruction result. The second reconstruction result is verified based on the first reconstruction result, the second reconstruction result, and the verification parameter to obtain a verification result. If the second reconstruction result passes, it is determined that the second reconstruction result is the query result. The response result of the query information is automatically verified to accurately obtain the query result of the information. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments of the present invention. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0013] Figure 1 This is a schematic diagram of an application environment of a query information verification method provided by the first embodiment of the present invention; Figure 2 This is a flow chart of a query information verification method provided by Embodiment 2 of the present invention; Figure 3 This is a flowchart of a query information verification method provided by Example 3 of the present invention; Figure 4 This is a flow chart of a query information verification method provided by the fourth embodiment of the present invention; Figure 5 This is a flowchart of a query information response method provided in Example 5 of the present invention; Figure 6 This is a flow chart of a query information verification device provided by Embodiment 6 of the present invention; Figure 7 This is a schematic diagram of the structure of a query information response device provided by Embodiment 7 of the present invention; Figure 8 This is a structural diagram of a computer device provided in Example 8 of the present invention. DETAILED DESCRIPTION

[0014] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0015] like Figure 1 As shown, it is a schematic diagram of the application environment of a query information verification method provided by the first embodiment of the present invention, wherein the client and the server are connected for communication, and the user can provide the conditions, requirements and operation instructions for querying information to the server by operating the client, and the server is used to execute the query result according to the relevant content sent by the client, and return it to the client for query information verification, and present the query information verification result to the user through the client, the query information verification method of the present invention. Among them, the client includes but is not limited to various personal computers, laptops, smart phones, tablet computers and portable wearable devices and other computer devices. The computer device corresponding to the server can be implemented with an independent server or a server cluster composed of multiple servers.

[0016] like Figure 2 FIG. 1 is a flow chart of a query information verification method provided in a second embodiment of the present invention. The query information verification method is applied to a client of a query system, wherein the query system further includes k servers, where k is an integer greater than 2. The query information verification method may include the following steps: Step S201: obtaining a query instruction from a user received by a client, generating a predicate function according to the query instruction, and constructing a verification function by combining the predicate function with preset verification parameters.

[0017] The client is the interface through which users interact with the query system. Just like when we enter search terms in a browser, the browser is the client, which receives the query request we enter. In this query system, the client is responsible for receiving the query requirements clearly expressed by the user.

[0018] A predicate function is a function that returns a Boolean value (true or false) and is used to describe query conditions. Simply put, it acts like a "filter," determining whether data meets the requirements based on given conditions. During the generation process, the client parses the query instruction and converts it into a mathematical or logical expression to generate the predicate function. These parameters are pre-set by the system and have a certain degree of security and uniqueness, similar to encryption keys or specific encoding rules. Their function is to ensure the authenticity and integrity of the results during the subsequent verification process and prevent data tampering. The client multiplies the preset verification parameters with the generated predicate function to form a new function, namely the verification function.

[0019] For example, in the field of information security, a user uses a query system to query the age distribution of customers whose transaction prices are between 500 and 1,000 yuan. In this case, "query the age distribution of customers whose transaction prices are between 500 and 1,000 yuan" is the query instruction received by the client. For "the above query on the age distribution of customers whose transaction prices are between 500 and 1,000 yuan", a predicate function is obtained and combined with verification parameters to form a verification function.

[0020] Step S202 : using a function secret sharing scheme, dividing the verification function into k first function slices, and dividing the predicate function into k second function slices.

[0021] Functional secret sharing is a cryptographic technique whose core idea is to split a secret (in this scenario, the verification function and predicate function) into multiple parts (shards) and then distribute these shards to different participants (in this case, servers). Individually, these shards do not contain the complete secret information. Only when a sufficient number (usually all) of the shards are collected can the original secret be reconstructed. This technique effectively prevents a single participant from obtaining the complete secret, thereby improving data security.

[0022] In a query system with k servers, the verification function is split into k first-function shards. Each server only holds one of the shards. Even if a server is attacked or leaks information, the attacker cannot recover the complete verification function from a single shard. This is because each shard is only a part of the verification function and does not contain the function's entire logic and information.

[0023] For example, in a financial data query system, the verification function contains complex encryption algorithms and verification rules. Sharding it can prevent attackers from obtaining the complete verification logic, thereby protecting the security of financial data.

[0024] Multiple servers can process their respective first function shards in parallel, improving computational efficiency. Each server independently computes its own shard and aggregates the results. This distributed computing approach fully utilizes the computing resources of multiple servers and reduces overall computation time.

[0025] For example, when processing large-scale data queries, a single server may not be able to complete the calculation within a reasonable time. By sharding and distributing the verification function to multiple servers, the query response speed can be significantly improved.

[0026] The predicate function represents the specific conditions of the user's query. Dividing it into k second-function shards can protect the privacy of the query conditions. Each server only knows the shards it holds and cannot infer the complete query conditions.

[0027] For example, in a medical data query system, a user queries for "information of patients with a rare disease and within a specific age range." After the predicate function is sharded, the server cannot learn the specific disease name and age range from its own shards, thereby protecting the patient's privacy and the confidentiality of the query.

[0028] If a server fails or data is lost, the system can still reconstruct the predicate function by collecting the remaining shards, as other servers still hold the remaining shards. This allows the system to continue operating even when some servers have problems, improving system reliability and fault tolerance.

[0029] For example, in a distributed storage system, a server may not work properly due to hardware failure or network problems, but through function sharding technology, the system can use shards of other servers to continue to complete the query task.

[0030] Step S203: Send k first function slices to k servers respectively, and send k second function slices to k servers respectively, and obtain the response result of each server. Each server is used to use the function secret sharing scheme to perform response calculation on the obtained first function slice to obtain the first response result, and to perform response calculation on the obtained second function slice to obtain the second response result.

[0031] In step S202, the validation function is divided into k first function slices, and the predicate function is divided into k second function slices. The k servers here are important components of the query system, responsible for subsequent computations. The system sends these k first function slices to each of the k servers, and also sends the k second function slices to each of the k servers. In other words, each server receives one first function slice and one second function slice. This distribution ensures decentralized processing of each function component, improving computational parallelism and efficiency while also enhancing system security, as a single server cannot obtain complete function information.

[0032] After receiving the first and second function fragments, each server uses the function secret sharing scheme mentioned in step S202 to perform a response calculation. Function secret sharing is an encryption technique that allows servers to perform calculations without knowing the complete function and original data, thereby protecting the privacy of the data.

[0033] The server performs a response calculation on the first function slice obtained, obtaining a first response result. The server then performs a response calculation on the second function slice obtained, obtaining a second response result. The second function slice is split from the predicate function. The predicate function is generated based on the user's query instruction and is used to determine whether the data meets the query conditions. Therefore, the second response result is related to the core query condition judgment.

[0034] After the server completes the calculation, it sends the first and second responses back to the client. The client receives these responses and prepares for subsequent reconstruction and verification steps. These responses contain the intermediate results of each server's data processing, which the client uses to obtain the final query result.

[0035] For example, suppose there are three servers (k = 3): Server A, Server B, and Server C. The client sends the first function fragments F1A, F1B, and F1C to each of these three servers, and also sends the second function fragments F2A, F2B, and F2C to each of them. Server A performs calculations in its own data area, and the first response calculated according to F1A is 15, and the second response calculated according to F2A is 3. Server B calculates the first response as 20, and the second response as 4. Server C calculates the first response as 25, and the second response as 5. Then, each of the three servers sends its first and second response results back to the client. The client then receives the response results from all servers, preparing for subsequent reconstruction and verification.

[0036] Step S204: reconstruct the first response results of all servers to obtain a first reconstructed result, and reconstruct the second response results of all servers to obtain a second reconstructed result.

[0037] In step S203, each server completes independent computation based on the received function slices and returns the first and second response results to the client. However, these results are distributed, with each server's computation representing only a portion of the overall computation. The purpose of step S204 is to integrate the response results from all servers to recover a complete and meaningful result, namely the first and second reconstruction results.

[0038] The first response is calculated by each server on the first function shard. The first function shard is the split portion of the verification function, so the first response reflects the verification function calculation on each server's data subset. Using a specific reconstruction algorithm (usually related to the function secret sharing scheme), the client combines the first response results of all servers to recover the complete verification function calculation result, which is the first reconstruction result.

[0039] For example, consider a simple linear function f(x)=af, split into k function slices and distributed to k servers. Each server calculates a corresponding first-response result based on its own data. After collecting the first-response results from all servers, the client adds them together or performs other operations according to the reconstruction rules in the secret sharing scheme to obtain the complete calculation result of f(x), which is the first-response result.

[0040] The second response is calculated by each server on the second function slice. The second function slice is the split portion of the predicate function, which determines whether the data meets the user's query criteria. Therefore, the second response reflects the calculation of the predicate function on each server's data subset. The client also uses a specific reconstruction algorithm to integrate the second response results of all servers to obtain the complete predicate function calculation result, namely the second reconstruction result.

[0041] For example, a predicate function f is split into k function slices and distributed to k servers. Each server calculates the number of elements that meet the condition based on its own data as the second response result. After collecting the second response results from all servers, the client adds them together to obtain the total number of elements that meet the condition for the entire dataset, which is the second reconstruction result.

[0042] Optionally, the first response result is summed to obtain the reconstructed first reconstruction result.

[0043] The second response result is summed up to obtain a reconstructed second reconstruction result.

[0044] The expression of the first reconstruction result generated by the K servers is: , i∈K; Where, is the first reconstruction result, is the i-th first function slice, and k is an integer greater than 2.

[0045] The expression of the second reconstruction result is: , i∈K; Where, is the second reconstruction result, Slice the i-th second function.

[0046] Step S205 : Using preset verification parameters, verify the first reconstruction result and the second reconstruction result to obtain a query verification result. The query verification result is used to determine that the second reconstruction result is the query result when passing.

[0047] In step S201, a verification function is constructed using a preset verification parameter combined with a predicate function. This preset verification parameter is the key basis of the verification process, and defines the relationship that should be satisfied between the first reconstruction result and the second reconstruction result.

[0048] The client uses the preset verification parameters to verify the first reconstruction result and the second reconstruction result. Specifically, it checks whether the first reconstruction result and the second reconstruction result conform to the relationship defined by the verification function. If so, the verification is considered to have passed; otherwise, the verification fails. When the query verification result passes, it means that the calculations of each server in the entire query process are correct, and there are no errors or tampering in the processing and transmission of the data. At this time, the second reconstruction result is determined as the final query result because it is calculated based on the predicate function and reflects the satisfaction of the user's query conditions on the entire data set. If the verification result fails, it means that there may be errors in the query process, such as server calculation errors, data transmission errors, or data tampering. In this case, it is necessary to re-query or take other error correction measures.

[0049] For example, the preset verification parameter is 5, the predicate function is f, and the check function is f(x)=5×f. If f(x)=5×f, the verification passes, and the second reconstruction result is the final query result; if f(x)≠5×f, the verification fails.

[0050] In an embodiment of the present application, a query instruction of a user received by a client is obtained, a predicate function is generated according to the query instruction, a verification function is constructed by combining the predicate function with preset verification parameters, a function secret sharing scheme is used to divide the verification function into k first function slices, and the predicate function is divided into k second function slices, the k first function slices are sent to k servers respectively, and the k second function slices are sent to k servers respectively, and a response result of each server is obtained. Each server is used to use the function secret sharing scheme to perform a response calculation on the obtained first function slice to obtain a first response result, and to perform a response calculation on the obtained second function slice to obtain a second response result. The first response results of all servers are reconstructed to obtain a first reconstruction result, the second response results of all servers are reconstructed to obtain a second reconstruction result, and the first reconstruction result and the second reconstruction result are verified using preset verification parameters to obtain a query verification result. The query verification result is used to determine that the second reconstruction result is the query result when passed. The correction function is obtained by combining the predicate function generated by the client with the verification parameter, and a function secret sharing scheme is used to obtain a first function slice of the correction function and a second function slice of the predicate function. The server responds to the first function slice and the second function slice to obtain a first response result and a second response result. The first response result and the second response result are respectively reconstructed on the client to obtain a first reconstruction result and a second reconstruction result. The second reconstruction result is verified based on the first reconstruction result, the second reconstruction result, and the verification parameter to obtain a verification result. If the second reconstruction result passes, it is determined that the second reconstruction result is the query result. The response result of the query information is automatically verified to accurately obtain the query result of the information.

[0051] like Figure 3 FIG. 1 is a flow chart of a query information verification method provided in Embodiment 3 of the present invention. In step S202, the function secret sharing scheme is used to divide the verification function into k first function slices and the predicate function into k second function slices. The method may include the following steps: Step S301: Obtain preset security parameters and obtain a splitting algorithm based on a function secret sharing scheme.

[0052] Step S302: The security parameter and the verification function are combined into a verification parameter pair, and a splitting algorithm is used to combine the verification parameter pair to perform function shard calculation to obtain k first function shards corresponding to the verification function.

[0053] Step S303 , the security parameter and the predicate function are combined into a predicate parameter pair, and a splitting algorithm is used to combine the predicate parameter pair to perform function shard calculation to obtain k second function shards corresponding to the predicate function.

[0054] The security parameter is a preset parameter, typically an integer, that controls the security strength of the encryption scheme. A larger security parameter increases the security of the scheme, but also increases computational overhead. The security parameter can be determined based on the results of multiple experiments on the overall scheme.

[0055] According to the definition of a functional secret sharing scheme, a splitting algorithm is a deterministic algorithm that takes as input a security parameter and the original function and outputs multiple function shards. The specific implementation of the splitting algorithm depends on the FSS scheme used (e.g., FSS based on pseudorandom functions or FSS based on homomorphic encryption).

[0056] The expression of the first function slice of the verification function is: ; Where g is the calibration function, For the kth function slice of the verification function, is a security parameter, FSS.Gen is the splitting algorithm of the functional secret sharing scheme, and K is an integer greater than 2.

[0057] The expression for generating the second function fragment corresponding to the verification function for k servers is: ; ; Where, is a safety parameter, is the predicate function, is the kth function shard of the predicate function, FSS.Gen is the splitting algorithm of the function secret sharing scheme, and K is an integer greater than 2.

[0058] In this embodiment, a function secret sharing scheme is used to split the verification function and the predicate function into k shards respectively, ensuring that a single shard does not leak the original function information. The shards can independently calculate partial results, and the client can restore the complete function value by combining the shard results. This mechanism supports distributed computing and result verification while protecting privacy.

[0059] like Figure 4 FIG. 2 is a flow chart of a query information verification method according to a fourth embodiment of the present invention. In step S205, the first reconstruction result and the second reconstruction result are verified using preset verification parameters to obtain a query verification result. The query verification result is used to determine that the second reconstruction result is the query result when passing the verification. The method may include the following steps: Step S401 : multiplying the second reconstruction result by a preset verification parameter to obtain a result to be verified.

[0060] Step S402 , determining whether the result to be verified is consistent with the first reconstruction result; if it is consistent with the first reconstruction result, determining the second reconstruction result as the query result.

[0061] The expression for determining whether the result to be verified conforms to the first reconstruction result is: ; Where, is the first reconstruction result, is the second reconstruction result, For validation parameters.

[0062] like Figure 5 FIG. 1 is a flow chart of a query information response method provided in Embodiment 5 of the present invention. The query information response method is applied to each server of a query system. The query system includes k servers and clients, where k is an integer greater than 2. For any server, the following steps may be included: Step S501: Acquire the first function shard and the second function shard sent by the client and a response database in response to the query instruction.

[0063] Step S502: extract data elements from the response database, combine the data elements and the first function slice into a first parameter pair, and combine the data elements and the second function slice into a second parameter pair.

[0064] Step S503: Obtain a preset weight parameter, and perform a continuous addition calculation on the weight parameter, the first function shard, and the function secret sharing scheme in each server to obtain a first response result.

[0065] Step S504: In each server, a continuous addition calculation is performed on the weight parameter, the second function shard, and the function secret sharing scheme to obtain a second response result, and the first response result and the second response result are sent to the client.

[0066] The expression of the first response data of k servers is: , i∈K; Where, is the first response data of the i-th server, For response data, For the first function slice, is the weight parameter, [N] is an integer greater than zero; The expression of the second response data of the k servers is: , i∈K; Where, is the second response data of the i-th server, For response data, Slice the second function, is the weight parameter, and [N] is an integer greater than zero.

[0067] Optionally, the first response results from all servers are combined as a first response data set, and the second response results from all servers are combined as a second response data set; The first response data set and the second response data set are used as a response parameter pair and sent to the client.

[0068] The first response results from all servers are combined into a first response dataset, and the second response results are combined into a second response dataset. These two datasets are then sent to the client as a response parameter pair. By default, k servers need to send their results separately, for a total of 2k messages (each server sends the first and second response results). After the combination, only two messages need to be sent (the first and second response datasets), reducing network overhead. The client directly receives two complete datasets, eliminating the need to collect and organize results from different servers one by one.

[0069] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0070] like Figure 6 FIG2 is a schematic diagram of a query information verification device provided in a sixth embodiment of the present invention. The query information verification device corresponds one-to-one with the query information verification method in the above embodiment. The query information verification method is applied to a client of a query system, wherein the query system further includes k servers, where k is an integer greater than 2. The query information verification device includes a function construction module 61, a function sharding module 62, a response module 63, a reconstruction module 64, and a verification module 65. Each functional module is described in detail as follows: Function construction module 61 is used to obtain the user's query instruction received by the client, generate a predicate function according to the query instruction, and use the predicate function in combination with the preset verification parameters to construct a verification function; a function sharding module 62 for dividing the verification function into k first function shards and dividing the predicate function into k second function shards using a function secret sharing scheme; A response module 63 is configured to send k first function shards to k servers respectively, and send k second function shards to k servers respectively, and obtain a response result from each server. Each server is configured to use a function secret sharing scheme to perform a response calculation on the obtained first function shards to obtain a first response result, and to perform a response calculation on the obtained second function shards to obtain a second response result. a reconstruction module 64, configured to reconstruct the first response results of all servers to obtain a first reconstruction result, and reconstruct the second response results of all servers to obtain a second reconstruction result; The verification module 65 is used to verify the first reconstruction result and the second reconstruction result using preset verification parameters to obtain a query verification result. The query verification result is used to determine that the second reconstruction result is the query result when passing.

[0071] Optionally, the function sharding module 62 includes: An algorithm acquisition unit is used to obtain preset security parameters and obtain a splitting algorithm according to a function secret sharing scheme; A first shard obtaining unit is configured to combine the security parameter and the verification function into a verification parameter pair, and perform function shard calculation on the verification parameter pair using a splitting algorithm to obtain k first function shards corresponding to the verification function; The second shard obtaining unit is used to combine the security parameter and the predicate function into a predicate parameter pair, use the splitting algorithm to combine the predicate parameter pair, perform function shard calculation, and obtain k second function shards corresponding to the predicate function.

[0072] Optionally, the reconstruction module 64 includes: A first reconstruction unit is configured to perform sum calculation on the first response result to obtain a reconstructed first reconstruction result; The second reconstruction unit is configured to perform sum calculation on the second response result to obtain a reconstructed second reconstruction result.

[0073] Optionally, the verification module 65 includes: a unit for obtaining a result to be verified, configured to calculate a product of the second reconstruction result and the preset verification parameter to obtain a result to be verified; The judgment unit is used to judge whether the result to be verified is consistent with the first reconstruction result, and if it is consistent with the first reconstruction result, determine the second reconstruction result as the query result.

[0074] like Figure 7 As shown, a query information response device provided in Embodiment 7 of the present invention is provided. This query information verification device corresponds one-to-one with the query information verification method in the above-mentioned embodiment. The query information response method is applied to each server of the query system. The query system includes k servers and clients, where k is an integer greater than 2. For each server, the query information response device includes a response module 71, a data combination module 72, a calculation module 73, and a response sending module 74. The functional modules are described in detail as follows: A response module 71 is configured to obtain the first function shard and the second function shard sent by the client and a response database in response to the query instruction; A data combination module 72 is configured to extract data elements from the response database, combine the data elements and the first function slice into a first parameter pair, and combine the data elements and the second function slice into a second parameter pair; The calculation module 73 is used to obtain a preset weight parameter, and perform a continuous addition calculation on the weight parameter, the first function shard, and the function secret sharing scheme in each server to obtain a first response result; The response sending module 74 is used to perform continuous addition calculations on the weight parameters, the second function shards, and the function secret sharing scheme in each server to obtain a second response result, and send the first response result and the second response result to the client.

[0075] Optionally, the response sending module 74 includes: a data merging unit, configured to merge the first response results from all servers into a first response data set, and merge the second response results from all servers into a second response data set; The response sending unit is configured to take the first response data set and the second response data set as a response parameter pair and send the result to the client.

[0076] For the specific limitations of the query information verification device, please refer to the limitations of the query information verification method above. For the specific limitations of the query information response device, please refer to the limitations of the query information response method above, and will not be repeated here. The various modules in the query information verification device and the query information response device can be implemented in whole or in part through software, hardware, or a combination thereof. Each of the above modules can be embedded in or independent of the processor in the computer device in hardware form, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of each of the above modules.

[0077] like Figure 8 The figure shows a schematic diagram of the structure of a computer device provided in Example 8 of the present invention. The computer device includes a processor, a memory, a network interface, and a database connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, a query information verification method is implemented.

[0078] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the query information verification method in the above embodiment is implemented. For example, Figures 2 to 4 As shown, or the query information response method in the above embodiment is implemented, for example Figures 5 and 6 Alternatively, when the processor executes the computer program, the functions of the modules / units in the embodiment of the query information verification device or the query information response device are realized, for example Figure 6 The function construction module 61, function sharding module 62, response module 63, reconstruction module 64, and verification module 65 are shown. Figure 7 The functions of the response module 71, data combination module 72, calculation module 73, and response sending module 74 are not described here in detail to avoid repetition.

[0079] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the query information verification method in the above embodiment is implemented, such as Figures 2 to 4 As shown, the query information response method in the above embodiment is implemented, as shown in Figures 5 and 6 Alternatively, when the computer program is executed by the processor, the functions of each module / unit in the embodiment of the query information verification device are realized, for example Figure 6 The function construction module 61, function sharding module 62, response module 63, reconstruction module 64, and verification module 65 are shown. Figure 7 To avoid repetition, the functions of the response module 71, data combination module 72, calculation module 73, and response sending module 74 are not described here in detail. The computer-readable storage medium may be non-volatile or volatile.

[0080] Those skilled in the art will understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), Synchronous Link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0081] Those skilled in the art will clearly understand that for the sake of convenience and brevity of description, only the division of the above-mentioned functional units and modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.

[0082] The embodiments described above are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention, and should all be included in the scope of protection of the present invention.

Claims

1. A query information verification method, characterized in that: The query information verification method is applied to a client of a query system, wherein the query system further includes k servers, where k is an integer greater than 2, including: Obtaining a query instruction from a user received by the client, generating a predicate function based on the query instruction, and constructing a verification function using preset verification parameters in combination with the predicate function; Using a function secret sharing scheme, the verification function is divided into k first function slices, and the predicate function is divided into k second function slices; Sending the k first function slices to k servers respectively, and sending the k second function slices to the k servers respectively, obtaining a response result from each server, wherein each server is configured to use the function secret sharing scheme to perform a response calculation on the obtained first function slice to obtain a first response result, and to perform a response calculation on the obtained second function slice to obtain a second response result; Reconstructing the first response results of all servers to obtain a first reconstruction result, and reconstructing the second response results of all servers to obtain a second reconstruction result; The first reconstruction result and the second reconstruction result are verified using the preset verification parameters to obtain a query verification result, and the query verification result is used to determine that the second reconstruction result is a query result when passing.

2. The query information verification method according to claim 1, characterized in that: The method of using a function secret sharing scheme to divide the verification function into k first function slices and to divide the predicate function into k second function slices comprises: Obtaining preset security parameters and obtaining a splitting algorithm according to the function secret sharing scheme; The security parameter and the verification function form a verification parameter pair, and the splitting algorithm is used in combination with the verification parameter pair to perform function sharding calculation to obtain k first function shards corresponding to the verification function; The security parameter and the predicate function are combined into a predicate parameter pair, and the splitting algorithm is used in combination with the predicate parameter pair to perform function shard calculation to obtain k second function shards corresponding to the predicate function.

3. The query information verification method according to claim 1, characterized in that: The reconstructing the first response results of all servers to obtain a first reconstruction result, and reconstructing the second response results of all servers to obtain a second reconstruction result, includes: Performing sum calculation on the first response result to obtain the reconstructed first reconstruction result; The second response result is summed up to obtain the reconstructed second reconstruction result.

4. The query information verification method according to claim 1, characterized in that: The using the preset verification parameters to verify the first reconstruction result and the second reconstruction result to obtain a query verification result, wherein the query verification result is used to determine that the second reconstruction result is a query result when passing, includes: Multiplying the second reconstruction result by the preset verification parameter to obtain a result to be verified; It is determined whether the result to be verified is consistent with the first reconstruction result; if it is consistent with the first reconstruction result, the second reconstruction result is determined to be the query result.

5. A query information response method, characterized in that: The query information response method is applied to each server of a query system, wherein the query system includes k servers and the client according to any one of claims 1 to 4, where k is an integer greater than 2, and for each server, includes: Obtaining the first function shard and the second function shard sent by the client and a response database in response to the query instruction; Extracting a data element from the response database, combining the data element with the first function slice into a first parameter pair, and combining the data element with the second function slice into a second parameter pair; Obtaining a preset weight parameter, and performing a continuous addition calculation on each server on the weight parameter, the first function shard, and the function secret sharing scheme to obtain the first response result; In each server, the weight parameter, the second function shard, and the function secret sharing scheme are subjected to a continuous addition calculation to obtain the second response result, and the first response result and the second response result are sent to the client.

6. The query information response method according to claim 5, characterized in that: The sending the first response result and the second response result to the client includes: Merging the first response results from all servers into a first response data set, and merging the second response results from all servers into a second response data set; The first response data set and the second response data set are used as a response parameter pair and sent to the client.

7. A query information verification device, characterized in that: The query information verification method is applied to a client of a query system, wherein the query system further includes k servers, where k is an integer greater than 2, including: A function construction module is used to obtain a query instruction from a user received by a client, generate a predicate function according to the query instruction, and construct a verification function using preset verification parameters in combination with the predicate function; a function sharding module, configured to divide the verification function into k first function shards and the predicate function into k second function shards using a function secret sharing scheme; a response module, configured to send the k first function slices to k servers respectively, and send the k second function slices to the k servers respectively, and obtain a response result from each server, wherein each server is configured to use the function secret sharing scheme to perform a response calculation on the obtained first function slice to obtain a first response result, and to perform a response calculation on the obtained second function slice to obtain a second response result; a reconstruction module, configured to reconstruct the first response results of all servers to obtain a first reconstruction result, and reconstruct the second response results of all servers to obtain a second reconstruction result; A verification module is used to verify the first reconstruction result and the second reconstruction result using the preset verification parameters to obtain a query verification result, and the query verification result is used to determine that the second reconstruction result is a query result when passing.

8. A query information response device, characterized in that: The query information response method is applied to each server of a query system, wherein the query system includes k servers and the client according to any one of claims 1 to 4, where k is an integer greater than 2, and for each server, includes: A response module, configured to obtain the first function shard and the second function shard sent by the client and a response database in response to the query instruction; a data combination module, configured to extract data elements from the response database, combine the data elements with the first function slice into a first parameter pair, and combine the data elements with the second function slice into a second parameter pair; a calculation module, configured to obtain a preset weight parameter, and perform a continuous addition calculation on the weight parameter, the first function shard, and the function secret sharing scheme in each server to obtain the first response result; The response sending module is used to perform a continuous addition calculation on the weight parameter, the second function shard, and the function secret sharing scheme in each server to obtain the second response result, and send the first response result and the second response result to the client.

9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the query information verification method according to any one of claims 1 to 4 or the query information response method according to any one of claims 5 to 6 is implemented.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the query information verification method according to any one of claims 1 to 4 or the query information response method according to any one of claims 5 to 6 is implemented.