Information verification and information response method and device, computer device and storage medium
Patent Information
- Application Number
- CN202510530006.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-24
- Publication Date
- 2026-10-09
- Estimated Expiration
- 2045-04-24
AI Technical Summary
[0004]本发明实施例提供一种信息校验和信息应答方法、装置、计算机设备及存储介质,以解决如何自动化地对查询信息的应答结果进行校验,以准确地得到信息的查询结果的问题
[0011]The beneficial effects of this invention compared to existing technologies are as follows: By acquiring the user's query command received by the client, a predicate function is generated based on the query command. A verification function is constructed by combining the predicate function with preset verification parameters. Using a function secret sharing scheme, the verification function is divided into k first function fragments, and the predicate function is divided into k second function fragments. The k first function fragments are sent to k servers, and the k second function fragments are sent to k servers. The response results from each server are obtained. Each server uses the function secret sharing scheme to perform response calculations on the obtained first function fragments to obtain a first response result, and on the obtained second function fragments to obtain a second response result. The first response results from all servers are reconstructed to obtain a first reconstructed result, and the second response results from all servers are reconstructed to obtain a second reconstructed result. The first and second reconstructed results are verified using preset verification parameters to obtain a query verification result. The query verification result is used to determine the second reconstructed result as the query result when the query passes verification. By combining the predicate function generated by the client with verification parameters, a correction function is obtained. A function secret sharing scheme is used to obtain a first function fragment of the correction function and a second function fragment of the predicate function. Based on the server's response to the first and second function fragments, a first response result and a second response result are obtained. The first and second response results are then reconstructed on the client side, resulting in a first reconstructed result and a second reconstructed result. Based on the first and second reconstructed results and verification parameters, the second reconstructed result is verified to obtain a verification result. If the verification passes, the second reconstructed result is determined as the query result. This automated verification of the response results for query information ensures accurate determination of the query results.
Smart Images

Figure CN120470024B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data processing technology, and in particular to an information verification and response method, apparatus, computer equipment, and storage medium. Background Technology
[0002] In the field of privacy information retrieval, existing technologies are mainly divided into multi-server and single-server approaches. Multi-server approaches are typically based on information theory security. The main purpose of using multi-server privacy information retrieval schemes is to protect user privacy and ensure that the server cannot guide the user to query specific content. It also requires that users can only access the data being queried, with strict access control over the database content. Most current privacy information retrieval solutions require that multiple servers not collude, increasing the difficulty of system implementation and deployment. For example, in the field of information security, when executing complex queries, existing solutions cannot effectively guarantee the authenticity and integrity of data when facing malicious servers. Furthermore, most current privacy information retrieval technologies do not guarantee the verification of query data, thus the authenticity of the data is not guaranteed. At the same time, multi-server communication costs are high, while single-server computing costs are also high.
[0003] Therefore, how to automatically verify the response results of query information in order to accurately obtain the query results has become an urgent problem to be solved. Summary of the Invention
[0004] This invention provides an information verification and response method, apparatus, computer device, and storage medium to solve the problem of how to automatically verify the response results of query information in order to accurately obtain the query results.
[0005] In a first aspect, embodiments of the present invention provide a query information verification method, wherein the query information verification method is applied to a client of a query system, the query system further comprising k servers, where k is an integer greater than 2, including: Obtain the query command received by the user from the client, generate a predicate function based on the query command, and construct a verification function by combining the predicate function with preset verification parameters; Using a function secret sharing scheme, the verification function is divided into k first function fragments, and the predicate function is divided into k second function fragments; The k first function fragments are sent to k servers respectively, and the k second function fragments are sent to the k servers respectively. The response result of each server is obtained. Each server is used to use the function secret sharing scheme to perform response calculation on the obtained first function fragments to obtain a first response result, and to perform response calculation on the obtained second function fragments to obtain a second response result. The first reconstructed result is obtained by reconstructing the first response results of all servers, and the second reconstructed result is obtained by reconstructing the second response results of all servers. Using the preset verification parameters, the first reconstruction result and the second reconstruction result are verified to obtain a query verification result. The query verification result is used to determine the second reconstruction result as the query result when it passes the verification.
[0006] Secondly, embodiments of the present invention provide a query information response method, which is applied to each server of a query system, the query system comprising k servers and clients, where k is an integer greater than 2, and for any server, includes: Obtain the first function fragment and the second function fragment sent by the client, as well as the response database in response to the query command; Extract data elements from the response database, combine the data elements and the first function fragment into a first parameter pair, and combine the data elements and the second function fragment into a second parameter pair; Obtain preset weight parameters, and in each server, perform a chain calculation on the weight parameters, the first function sharding, and the function secret sharing scheme to obtain the first response result; In each server, the weight parameter, the second function sharding, and the function secret sharing scheme are summed to obtain the second response result, and the first response result and the second response result are sent to the client.
[0007] Thirdly, embodiments of the present invention provide a query information verification device, wherein the query information verification method is applied to a client of a query system, and the query system further includes k servers, where k is an integer greater than 2, comprising: The function construction module is used to obtain the query command received by the user from the client, generate a predicate function according to the query command, and construct a verification function by combining the predicate function with preset verification parameters; The function sharding module is used to divide the verification function into k first function shards and the predicate function into k second function shards using a function secret sharing scheme; The response module is used to send the k first function fragments to k servers respectively, send the k second function fragments to the k servers respectively, obtain the response result of each server, and each server is used to use the function secret sharing scheme to perform response calculation on the obtained first function fragments to obtain a first response result, and to perform response calculation on the obtained second function fragments to obtain a second response result; The reconstruction module is used to reconstruct the first response results of all servers to obtain the first reconstruction result, and to reconstruct the second response results of all servers to obtain the second reconstruction result; The verification module is used to verify the first reconstruction result and the second reconstruction result using the preset verification parameters to obtain a query verification result. The query verification result is used to determine the second reconstruction result as the query result when it passes the verification.
[0008] Fourthly, embodiments of the present invention provide a query information response device, wherein the query information response method is applied to each server of a query system, the query system comprising k servers and clients, where k is an integer greater than 2, and for any server, the method includes: The response module is used to obtain the first function fragment and the second function fragment sent by the client, as well as the response database in response to the query command; The data combination module is used to extract data elements from the response database, combine the data elements and the first function fragment into a first parameter pair, and combine the data elements and the second function fragment into a second parameter pair; The calculation module is used to obtain preset weight parameters, and in each server, perform a chain calculation on the weight parameters, the first function sharding, and the function secret sharing scheme to obtain the first response result; The response sending module is used to perform a chain calculation on the weight parameter, the second function sharding, and the function secret sharing scheme in each server to obtain the second response result, and then send the first response result and the second response result to the client.
[0009] Fifthly, embodiments of the present invention provide a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the above-described query information verification method or the above-described query information response method.
[0010] In a sixth aspect, embodiments of the present invention provide a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the above-described query information verification method or the above-described query information response method.
[0011] The beneficial effects of this invention compared to existing technologies are as follows: By acquiring the user's query command received by the client, a predicate function is generated based on the query command. A verification function is constructed by combining the predicate function with preset verification parameters. Using a function secret sharing scheme, the verification function is divided into k first function fragments, and the predicate function is divided into k second function fragments. The k first function fragments are sent to k servers, and the k second function fragments are sent to k servers. The response results from each server are obtained. Each server uses the function secret sharing scheme to perform response calculations on the obtained first function fragments to obtain a first response result, and on the obtained second function fragments to obtain a second response result. The first response results from all servers are reconstructed to obtain a first reconstructed result, and the second response results from all servers are reconstructed to obtain a second reconstructed result. The first and second reconstructed results are verified using preset verification parameters to obtain a query verification result. The query verification result is used to determine the second reconstructed result as the query result when the query passes verification. By combining the predicate function generated by the client with verification parameters, a correction function is obtained. A function secret sharing scheme is used to obtain a first function fragment of the correction function and a second function fragment of the predicate function. Based on the server's response to the first and second function fragments, a first response result and a second response result are obtained. The first and second response results are then reconstructed on the client side, resulting in a first reconstructed result and a second reconstructed result. Based on the first and second reconstructed results and verification parameters, the second reconstructed result is verified to obtain a verification result. If the verification passes, the second reconstructed result is determined as the query result. This automated verification of the response results for query information ensures accurate determination of the query results. Attached Figure Description
[0012] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments of the present invention will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0013] Figure 1 This is a schematic diagram of the application environment of a query information verification method provided in Embodiment 1 of the present invention; Figure 2 This is a flowchart illustrating a query information verification method provided in Embodiment 2 of the present invention; Figure 3 This is a flowchart illustrating a query information verification method provided in Embodiment 3 of the present invention; Figure 4 This is a flowchart illustrating a query information verification method provided in Embodiment 4 of the present invention; Figure 5 This is a flowchart illustrating a query information response method provided in Embodiment 5 of the present invention; Figure 6 This is a flowchart illustrating an information verification device provided in Embodiment Six of the present invention; Figure 7 This is a schematic diagram of the structure of an information query response device provided in Embodiment 7 of the present invention; Figure 8 This is a schematic diagram of the structure of a computer device provided in Embodiment 8 of the present invention. Detailed Implementation
[0014] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0015] like Figure 1 The diagram illustrates an application environment for a query information verification method according to Embodiment 1 of the present invention. The client and server communicate via a connection. The user can provide the server with conditions, requirements, and operation instructions for querying information through the client. The server executes the query based on the content sent by the client, returns the results to the client for verification, and then displays the verification results to the user through the client. This is the query information verification method of the present invention. The client includes, but is not limited to, various personal computers, laptops, smartphones, tablets, and portable wearable devices. The server can be implemented using a standalone server or a server cluster consisting of multiple servers.
[0016] like Figure 2 The diagram shown is a flowchart illustrating a query information verification method according to Embodiment 2 of the present invention. This query information verification method is applied to the client of a query system, which further includes k servers, where k is an integer greater than 2. The query information verification method may include the following steps: Step S201: Obtain the query command received by the client from the user, generate a predicate function based on the query command, and construct a verification function by combining the predicate function with preset verification parameters.
[0017] In this system, the client is the interface through which users interact with the query system. Just as the browser acts as the client, receiving our search queries, the client in this query system is responsible for receiving the explicitly stated query requirements from the user.
[0018] A predicate function is a function that returns a Boolean value (true or false) to describe the conditions of a query. Simply put, it acts like a "filter," determining whether data meets the given conditions. During the generation process, the client parses the query command, transforming it into a mathematical or logical expression to generate the predicate function. These parameters are pre-set by the system and possess a certain level of security and uniqueness, similar to encryption keys or specific encoding rules. Their purpose is to ensure the authenticity and integrity of the results during subsequent verification, preventing data tampering. The client multiplies the pre-set verification parameters with the generated predicate function to form a new function, the verification function.
[0019] For example, in the field of information security, a user uses a query system to query the age distribution of customers whose products are sold between 500 and 1000 yuan. Then, "query the age distribution of customers whose products are sold between 500 and 1000 yuan" is the query instruction received by the client. For "the above query the age distribution of customers whose prices are between 500 and 1000 yuan", a predicate function is obtained, and a verification function is formed by combining it with the verification parameters.
[0020] Step S202: Using a function secret sharing scheme, the verification function is divided into k first function slices, and the predicate function is divided into k second function slices.
[0021] The function secret sharing scheme is a cryptographic technique whose core idea is to divide a secret (in this scenario, the verification function and the predicate function) into multiple parts (shards), and then distribute these shards to different participants (here, the server). These shards, viewed individually, do not contain the complete secret information; only when a sufficient number (usually all) of the shards are collected can the original secret be reconstructed. This technique effectively prevents a single participant from obtaining the complete secret, thereby improving data security.
[0022] In a query system with k servers, after splitting the validation function into k first function shards, each server holds only one shard. Even if a server is maliciously attacked or its information is leaked, the attacker cannot recover the complete validation function from a single shard. This is because each shard is only a part of the validation function and does not contain the function's complete logic and information.
[0023] For example, in a financial data query system, the verification function contains complex encryption algorithms and verification rules. By fragmenting it, attackers can be prevented from obtaining the complete verification logic, thereby protecting the security of financial data.
[0024] In this distributed computing approach, multiple servers can process their respective first function partitions in parallel, improving computational efficiency. Each server can independently compute its own partition, and the results are then aggregated. This approach fully utilizes the computing resources of multiple servers, reducing overall computation time.
[0025] For example, when processing large-scale data queries, a single server may not be able to complete the calculation in a reasonable amount of time. However, by sharding the validation function and distributing it to multiple servers, the response speed of the query can be significantly improved.
[0026] In this context, the predicate function represents the specific conditions of the user's query. Dividing it into k second-function shards protects the privacy of the query conditions. Each server only knows the shards it holds and cannot infer the complete query conditions.
[0027] For example, in a medical data query system, when a user queries "patient information with a certain rare disease and an age within a specific range", after the predicate function is fragmented, the server cannot know the specific disease name and age range from its own fragment, thus protecting the patient's privacy and the confidentiality of the query.
[0028] If a server fails or loses data, the system can still reconstruct the predicate function by collecting the remaining fragments because other servers still hold other fragments of the predicate function. This allows the system to continue operating even when some servers encounter problems, improving the system's reliability and fault tolerance.
[0029] For example, in a distributed storage system, a server may fail to function properly due to hardware failure or network problems, but through function sharding technology, the system can continue to complete the query task by utilizing shards from other servers.
[0030] Step S203: Send k first function fragments to k servers respectively, send k second function fragments to k servers respectively, obtain the response result of each server, and each server uses the function secret sharing scheme to perform response calculation on the obtained first function fragments to obtain the first response result, and to perform response calculation on the obtained second function fragments to obtain the second response result.
[0031] In step S202, the verification function has been divided into k first function fragments, and the predicate function has been divided into k second function fragments. These k servers are crucial components of the query system; they will be responsible for subsequent computations. The system will send each of the k first function fragments and the k second function fragments to one of the k servers. In other words, each server receives one first function fragment and one second function fragment. This distribution method ensures that the different parts of the function are processed in a distributed manner, improving computational parallelism and efficiency, while also enhancing system security because a single server cannot obtain complete function information.
[0032] After receiving the first and second function fragments, each server will perform response calculations using the function secret sharing scheme mentioned in step S202. The function secret sharing scheme is an encryption technique that allows servers to perform calculations without knowing the complete function or the original data, thereby protecting data privacy.
[0033] The server performs response calculations on the first function fragment obtained, obtaining a first response result. The server then performs response calculations on the second function fragment obtained, obtaining a second response result. The second function fragment is derived from the predicate function, which is generated based on the user's query command and used to determine whether the data meets the query conditions. Therefore, the second response result is related to the core condition judgment of the query.
[0034] After completing the calculation, the server sends the first and second response results back to the client. The client receives these responses to prepare for subsequent reconstruction and verification steps. These responses contain intermediate results from the various servers' data processing, which the client uses to obtain the final query result.
[0035] For example, suppose there are three servers (k = 3): server A, server B, and server C. The client sends the first function fragments F1A, F1B, and F1C to these three servers respectively, and also sends the second function fragments F2A, F2B, and F2C to them respectively. Server A performs calculations in its own data area, calculating the first response result as 15 according to F1A and the second response result as 3 according to F2A. Server B calculates the first response result as 20 and the second response result as 4. Server C calculates the first response result as 25 and the second response result as 5. Then, these three servers send their respective first and second response results back to the client. The client then receives the response results from all servers, preparing for subsequent reconstruction and verification.
[0036] Step S204: Reconstruct the first response results of all servers to obtain the first reconstruction result, and reconstruct the second response results of all servers to obtain the second reconstruction result.
[0037] In step S203, each server performs independent computation based on the received function fragments and returns the first and second response results to the client. However, these results are scattered, and each server's computation is only a part of the overall computation. The purpose of step S204 is to integrate the response results of all servers to recover the complete and meaningful results, namely the first and second reconstruction results.
[0038] The first response result is obtained by each server calculating the first function shard. The first function shard is the part after the verification function is split, so the first response result reflects the calculation of the verification function on the data subsets of each server. Through a specific reconstruction algorithm (usually related to the function secret sharing scheme), the client combines the first response results of all servers to recover the complete verification function calculation result, i.e., the first reconstruction result.
[0039] For example, the verification function is a simple linear function f(x) = af, which is split into k function fragments and distributed to k servers. Each server calculates its corresponding first response result based on its own data. After collecting the first response results from all servers, the client adds these results or performs other operations according to the reconstruction rules in the function secret sharing scheme to finally obtain the complete calculation result of f(x), which is the first reconstruction result.
[0040] The second response result is obtained by each server calculating the second function shards. The second function shards are the parts after the predicate function has been split, and the predicate function is used to determine whether the data meets the user's query conditions. Therefore, the second response result reflects the calculation of the predicate function on the data subsets of each server. The client also uses a specific reconstruction algorithm to integrate the second response results from all servers to obtain the complete predicate function calculation result, i.e., the second reconstruction result.
[0041] For example, the predicate function f is split into k function fragments and distributed to k servers. Each server calculates the number of elements that meet the conditions based on its own data as the second response result. After collecting the second response results from all servers, the client adds these results together to obtain the total number of elements that meet the conditions in the entire dataset, which is the second reconstruction result.
[0042] Optionally, the first response result is summed to obtain the reconstructed first reconstruction result.
[0043] The sum of the second response results is calculated to obtain the reconstructed second reconstruction result.
[0044] The expression for the first reconstruction result generated by the K servers is: , i∈K; In the formula, This is the first reconstruction result. Let k be the i-th first function slice, where k is an integer greater than 2.
[0045] The expression for the second reconstruction result is: , i∈K; In the formula, This is the second reconstruction result. The i-th second function is sliced.
[0046] Step S205: Using preset verification parameters, verify the first reconstruction result and the second reconstruction result to obtain a query verification result. The query verification result is used to determine the second reconstruction result as the query result when it passes the verification.
[0047] In step S201, a verification function is constructed using preset verification parameters combined with a predicate function. These preset verification parameters are the key basis for the verification process, defining the relationship that should be satisfied between the first reconstruction result and the second reconstruction result.
[0048] The client uses preset validation parameters to validate the first and second reconstruction results. Specifically, it checks whether the first and second reconstruction results conform to the relationship defined by the validation function. If they do, the validation is considered successful; otherwise, it fails. When the query validation result passes, it indicates that the calculations of each server during the entire query process were correct, and there were no errors or tampering in data processing and transmission. At this point, the second reconstruction result is determined as the final query result because it is calculated based on the predicate function and reflects the satisfaction of the user's query conditions across the entire dataset. If the validation result fails, it indicates that there may be errors in the query process, such as server calculation errors, data transmission errors, or data tampering. In this case, it is necessary to re-run the query or take other error correction measures.
[0049] For example, the preset verification parameter is 5, the predicate function is f, and the verification function is f(x) = 5 × f. If f(x) = 5 × f, the verification passes and the second reconstruction result is the final query result; if f(x) ≠ 5 × f, the verification fails.
[0050] In this embodiment, the system obtains a user's query command received by the client, generates a predicate function based on the query command, constructs a verification function using preset verification parameters and the predicate function, divides the verification function into k first function fragments and the predicate function into k second function fragments using a function secret sharing scheme, sends the k first function fragments to k servers, sends the k second function fragments to k servers, obtains the response result from each server, and uses the function secret sharing scheme to perform response calculation on the obtained first function fragments to obtain a first response result and on the obtained second function fragments to obtain a second response result. The first response results from all servers are reconstructed to obtain a first reconstructed result, and the second response results from all servers are reconstructed to obtain a second reconstructed result. The first and second reconstructed results are verified using preset verification parameters to obtain a query verification result. The query verification result is used to determine the second reconstructed result as the query result when the query passes the verification. By combining the predicate function generated by the client with verification parameters, a correction function is obtained. A function secret sharing scheme is used to obtain a first function fragment of the correction function and a second function fragment of the predicate function. Based on the server's response to the first and second function fragments, a first response result and a second response result are obtained. The first and second response results are then reconstructed on the client side, resulting in a first reconstructed result and a second reconstructed result. Based on the first and second reconstructed results and verification parameters, the second reconstructed result is verified to obtain a verification result. If the verification passes, the second reconstructed result is determined as the query result. This automated verification of the response results for query information ensures accurate determination of the query results.
[0051] like Figure 3 The diagram shown is a flowchart of a query information verification method provided in Embodiment 3 of the present invention. The use of a function secret sharing scheme in step S202, which divides the verification function into k first function fragments and the predicate function into k second function fragments, may include the following steps: Step S301: Obtain the preset security parameters and obtain the splitting algorithm according to the function secret sharing scheme.
[0052] Step S302: Combine the security parameters and the verification function into a verification parameter pair, and use a splitting algorithm to perform function sharding calculation in combination with the verification parameter pair to obtain k first function shards of the corresponding verification function.
[0053] Step S303: Combine the security parameters and the predicate function into a predicate parameter pair, and use a splitting algorithm to perform function partitioning calculation in combination with the predicate parameter pair to obtain k second function partitions of the corresponding predicate function.
[0054] The security parameter is a preset parameter, usually an integer, used to control the security strength of the encryption scheme. A higher security parameter results in greater security but also increases computational overhead. The security parameter can be determined based on the results of multiple experiments with the overall scheme.
[0055] According to the definition of a function secret sharing scheme, the splitting algorithm is a deterministic algorithm that takes security parameters and the original function as input and outputs multiple function fragments. The specific implementation of the splitting algorithm depends on the FSS scheme used (such as FSS based on pseudo-random functions or FSS based on homomorphic encryption).
[0056] The expression for the first function slice of the verification function is: ; In the formula, g is the verification function. For the k-th function segment of the verification function, For security parameters, FSS.Gen is the splitting algorithm for the function secret sharing scheme, and K is an integer greater than 2.
[0057] The expression for generating the second function fragment corresponding to the verification function for k servers is: ; ; In the formula, For safety parameters, For predicate functions, FSS.Gen is the k-th function slice of the predicate function, where K is an integer greater than 2.
[0058] In this embodiment, the function secret sharing scheme splits the verification function and the predicate function into k fragments respectively, ensuring that no single fragment leaks the original function information. Each fragment can independently calculate part of the result, and the client can recover the complete function value by combining the fragment results. This mechanism protects privacy while supporting distributed computing and result verification.
[0059] like Figure 4 The diagram shown is a flowchart of a query information verification method provided in Embodiment 4 of the present invention. In step S205, preset verification parameters are used to verify the first reconstruction result and the second reconstruction result to obtain a query verification result. The query verification result is used to determine the second reconstruction result as the query result when it passes the verification. This step may include the following steps: Step S401: Multiply the second reconstruction result with the preset verification parameters to obtain the result to be verified.
[0060] Step S402: Determine whether the result to be verified matches the first reconstruction result. If it matches the first reconstruction result, then determine the second reconstruction result as the query result.
[0061] The expression for determining whether the result to be verified conforms to the first reconstruction result is: ; In the formula, This is the first reconstruction result. This is the second reconstruction result. To verify the parameters.
[0062] like Figure 5 The diagram shown is a flowchart of a query information response method provided in Embodiment 5 of the present invention. The query information response method is applied to each server of a query system, which includes k servers and clients, where k is an integer greater than 2. For any server, the following steps may be included: Step S501: Obtain the first function fragment, the second function fragment, and the response database in response to the query command sent by the client.
[0063] Step S502: Extract data elements from the response database, combine the data elements and the first function fragments into a first parameter pair, and combine the data elements and the second function fragments into a second parameter pair.
[0064] Step S503: Obtain the preset weight parameters. In each server, perform a chain calculation on the weight parameters, the first function sharding, and the function secret sharing scheme to obtain the first response result.
[0065] Step S504: In each server, the weight parameter, the second function sharding, and the function secret sharing scheme are summed to obtain the second response result, and the first response result and the second response result are sent to the client.
[0066] The expressions for the first response data from the k servers are: , i∈K; In the formula, This is the first response data from the i-th server. In response to the data, For the first function, slice [N] is the weight parameter, where [N] is a positive integer. The expression for the second response data of the k servers is: , i∈K; In the formula, This is the second response data from the i-th server. In response to the data, For the second function, slice [N] is the weight parameter, and [N] is a positive integer.
[0067] Optionally, the first response results from all servers are merged into a first response dataset, and the second response results from all servers are merged into a second response dataset. The first and second response datasets are used as response parameter pairs and sent to the client.
[0068] The process involves merging the first response results from all servers into a first response dataset, and the second response results into a second response dataset. These two datasets are then sent to the client as response parameter pairs. By default, k servers would need to send their results separately, resulting in a total of 2k messages (each server sending the first and second response results). After merging, only two messages need to be sent (the first and second response datasets), reducing network overhead. The client directly receives two complete datasets without needing to collect and process results from different servers individually.
[0069] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0070] like Figure 6 The diagram shown is a schematic of a query information verification device provided in Embodiment Six of the present invention. This query information verification device corresponds one-to-one with the query information verification method in the above embodiments. The query information verification method is applied to the client of the query system, which also includes k servers, where k is an integer greater than 2. The query information verification device includes a function construction module 61, a function sharding module 62, a response module 63, a reconstruction module 64, and a verification module 65. Detailed descriptions of each functional module are as follows: The function construction module 61 is used to obtain the query command received by the user from the client, generate a predicate function based on the query command, and construct a verification function by combining the predicate function with preset verification parameters. Function sharding module 62 is used to divide the verification function into k first function shards and the predicate function into k second function shards using a function secret sharing scheme; The response module 63 is used to send k first function fragments to k servers respectively, send k second function fragments to k servers respectively, and obtain the response result of each server. Each server is used to use the function secret sharing scheme to perform response calculation on the obtained first function fragments to obtain the first response result, and to perform response calculation on the obtained second function fragments to obtain the second response result. The reconstruction module 64 is used to reconstruct the first response results of all servers to obtain a first reconstruction result, and to reconstruct the second response results of all servers to obtain a second reconstruction result; The verification module 65 is used to verify the first reconstruction result and the second reconstruction result using preset verification parameters to obtain a query verification result. The query verification result is used to determine the second reconstruction result as the query result when it passes the verification.
[0071] Optionally, the above function slicing module 62 includes: The algorithm acquisition unit is used to acquire preset security parameters and obtain the splitting algorithm according to the function secret sharing scheme; The first slice acquisition unit is used to combine security parameters and verification functions into verification parameter pairs, and use a splitting algorithm to combine the verification parameter pairs to perform function slice calculation to obtain k first function slices corresponding to the verification function. The second slice acquisition unit is used to combine the security parameters and the predicate function into predicate parameter pairs, and use a splitting algorithm to combine the predicate parameter pairs to perform function slice calculation, thereby obtaining k second function slices corresponding to the predicate function.
[0072] Optionally, the aforementioned refactoring module 64 includes: The first reconstruction unit is used to perform a sum calculation on the first response result to obtain the reconstructed first reconstruction result. The second reconstruction unit is used to perform summation calculation on the second response result to obtain the reconstructed second reconstruction result.
[0073] Optionally, the verification module 65 mentioned above includes: The verification result acquisition unit is used to multiply the second reconstruction result with the preset verification parameters to obtain the verification result; The judgment unit is used to determine whether the result to be verified conforms to the first reconstruction result. If it conforms to the first reconstruction result, the second reconstruction result is determined to be the query result.
[0074] like Figure 7 As shown, this is a query information response device provided in Embodiment 7 of the present invention. This query information verification device corresponds one-to-one with the query information verification method in the above embodiments. The query information response method is applied to each server of the query system, which includes k servers and clients, where k is an integer greater than 2. For any server, the query information response device includes a response module 71, a data combination module 72, a calculation module 73, and a response sending module 74. Detailed descriptions of each functional module are as follows: Response module 71 is used to obtain the first function fragment and the second function fragment sent by the client, as well as the response database in response to the query command; Data combination module 72 is used to extract data elements from the response database, combine the data elements and the first function fragments into a first parameter pair, and combine the data elements and the second function fragments into a second parameter pair; The calculation module 73 is used to obtain preset weight parameters, and in each server, it performs a chain calculation on the weight parameters, the first function sharding, and the function secret sharing scheme to obtain the first response result; The response sending module 74 is used to perform a chain calculation on the weight parameter, the second function sharding, and the function secret sharing scheme in each server to obtain the second response result, and then send the first response result and the second response result to the client.
[0075] Optionally, the above-mentioned response sending module 74 includes: The data merging unit is used to merge the first response results from all servers into a first response dataset, and to merge the second response results from all servers into a second response dataset. The response sending unit is used to send the first response dataset and the second response dataset as a response parameter pair to the client.
[0076] For specific limitations regarding the query information verification device, please refer to the limitations regarding the query information verification method above. For specific limitations regarding the query information response device, please refer to the limitations regarding the query information response method above; these will not be repeated here. Each module in the aforementioned query information verification device and query information response device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in the computer device in hardware form, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each module.
[0077] like Figure 8 The diagram shown is a schematic representation of a computer device structure according to Embodiment 8 of the present invention. The computer device includes a processor, a memory, a network interface, and a database connected via a system bus. The processor provides computing and control capabilities. The memory includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The network interface is used to communicate with external terminals via a network connection. When the computer program is executed by the processor, it implements a query information verification method.
[0078] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the information query verification method described in the above embodiments, for example... Figures 2 to 4 As shown, or to implement the query information response method in the above embodiments, for example... Figures 5 to 6 As shown, to avoid repetition, it will not be described again here. Alternatively, when the processor executes the computer program, it implements the functions of each module / unit in this embodiment of the query information verification device or query information response device, for example... Figure 6 The module shown includes function construction module 61, function fragmentation module 62, response module 63, reconstruction module 64, and verification module 65. Figure 7 The functions of the response module 71, data combination module 72, calculation module 73, and response sending module 74 shown are not described again here to avoid repetition.
[0079] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When executed by a processor, the computer program implements the query information verification method described in the above embodiments, such as... Figures 2 to 4 As shown, the query information response method in the above embodiments is implemented as follows: Figures 5 to 6 As shown, to avoid repetition, it will not be described again here. Alternatively, when the computer program is executed by the processor, it implements the functions of each module / unit in this embodiment of the query information verification device, for example... Figure 6 The module shown includes function construction module 61, function fragmentation module 62, response module 63, reconstruction module 64, and verification module 65. Figure 7 The functions of the response module 71, data combination module 72, calculation module 73, and response sending module 74 shown are not described again here to avoid repetition. The computer-readable storage medium can be non-volatile or volatile.
[0080] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. This computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in a variety of forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0081] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is used as an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.
[0082] The above-described embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.
Claims
1. A method for verifying query information, characterized in that, The query information verification method is applied to the client of the query system, which also includes k servers, where k is an integer greater than 2, including: Obtain the query command received by the user from the client, generate a predicate function based on the query command, and construct a verification function by combining the predicate function with preset verification parameters; Using a function secret sharing scheme, the verification function is divided into k first function fragments, and the predicate function is divided into k second function fragments; The k first function fragments are sent to k servers respectively, and the k second function fragments are sent to the k servers respectively. The response result of each server is obtained. Each server is used to use the function secret sharing scheme to perform response calculation on the obtained first function fragments to obtain a first response result, and to perform response calculation on the obtained second function fragments to obtain a second response result. The first reconstructed result is obtained by reconstructing the first response results of all servers, and the second reconstructed result is obtained by reconstructing the second response results of all servers. Using the preset verification parameters, the first reconstruction result and the second reconstruction result are verified to obtain a query verification result. The query verification result is used to determine the second reconstruction result as the query result when it passes the verification.
2. The query information verification method according to claim 1, characterized in that, The method of using function secret sharing divides the verification function into k first function fragments and the predicate function into k second function fragments, including: Obtain preset security parameters and, based on the function secret sharing scheme, obtain the splitting algorithm; The security parameter and the verification function are combined to form a verification parameter pair. The splitting algorithm is used in conjunction with the verification parameter pair to perform function sharding calculation, thereby obtaining k first function shards corresponding to the verification function. The security parameters and the predicate function are combined to form a predicate parameter pair. The splitting algorithm is then used in conjunction with the predicate parameter pair to perform function slicing calculation, resulting in k second function slices corresponding to the predicate function.
3. The query information verification method according to claim 1, characterized in that, The process of reconstructing the first response results of all servers to obtain a first reconstructed result, and reconstructing the second response results of all servers to obtain a second reconstructed result, includes: The sum of the first response results is calculated to obtain the reconstructed first reconstruction result. The second response result is summed to obtain the reconstructed second result.
4. The query information verification method according to claim 1, characterized in that, The first reconstruction result and the second reconstruction result are verified using the preset verification parameters to obtain a query verification result. This query verification result is used to determine the second reconstruction result as the query result when it passes the verification, including: The second reconstruction result is multiplied by the preset verification parameters to obtain the result to be verified. Determine whether the result to be verified conforms to the first reconstruction result. If it conforms to the first reconstruction result, then determine the second reconstruction result as the query result.
5. A method for responding to a query, characterized in that, The query response method is applied to each server of the query system, which includes k servers and a client as described in any one of claims 1 to 4, where k is an integer greater than 2. For any server, it includes: Obtain the first function fragment and the second function fragment sent by the client, as well as the response database in response to the query command; Extract data elements from the response database, combine the data elements and the first function fragment into a first parameter pair, and combine the data elements and the second function fragment into a second parameter pair; Obtain preset weight parameters, and in each server, perform a chain calculation on the weight parameters, the first function sharding, and the function secret sharing scheme to obtain the first response result; In each server, the weight parameter, the second function sharding, and the function secret sharing scheme are summed to obtain the second response result, and the first response result and the second response result are sent to the client.
6. The query information response method according to claim 5, characterized in that, Sending the first response result and the second response result to the client includes: The first response results from all servers are merged into a first response dataset, and the second response results from all servers are merged into a second response dataset. The first response dataset and the second response dataset are used as a response parameter pair and sent to the client.
7. A query information verification device, characterized in that, The query information verification method is applied to the client of the query system, which also includes k servers, where k is an integer greater than 2, including: The function construction module is used to obtain the query command received by the user from the client, generate a predicate function according to the query command, and construct a verification function by combining the predicate function with preset verification parameters; The function sharding module is used to divide the verification function into k first function shards and the predicate function into k second function shards using a function secret sharing scheme; The response module is used to send the k first function fragments to k servers respectively, send the k second function fragments to the k servers respectively, obtain the response result of each server, and each server is used to use the function secret sharing scheme to perform response calculation on the obtained first function fragments to obtain a first response result, and to perform response calculation on the obtained second function fragments to obtain a second response result; The reconstruction module is used to reconstruct the first response results of all servers to obtain the first reconstruction result, and to reconstruct the second response results of all servers to obtain the second reconstruction result; The verification module is used to verify the first reconstruction result and the second reconstruction result using the preset verification parameters to obtain a query verification result. The query verification result is used to determine the second reconstruction result as the query result when it passes the verification.
8. A query information response device, characterized in that, The query response method is applied to each server of the query system, which includes k servers and a client as described in any one of claims 1 to 4, where k is an integer greater than 2. For any server, it includes: The response module is used to obtain the first function fragment and the second function fragment sent by the client, as well as the response database in response to the query command; The data combination module is used to extract data elements from the response database, combine the data elements and the first function fragment into a first parameter pair, and combine the data elements and the second function fragment into a second parameter pair; The calculation module is used to obtain preset weight parameters, and in each server, perform a chain calculation on the weight parameters, the first function sharding, and the function secret sharing scheme to obtain the first response result; The response sending module is used to perform a chain calculation on the weight parameter, the second function sharding, and the function secret sharing scheme in each server to obtain the second response result, and then send the first response result and the second response result to the client.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the query information verification method according to any one of claims 1 to 4 or the query information response method according to any one of claims 5 to 6.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the query information verification method according to any one of claims 1 to 4 or the query information response method according to any one of claims 5 to 6.
Citation Information
Patent Citations
Data access method and system, computer storage medium and terminal equipment
CN117473020A
Method for generating and verifying security information obtained by means of biometric readings
WO2007113888A1