Multi-party security sharing method and device under power data flow, computer equipment and readable storage medium
By building obfuscated circuits and inadvertent transmission protocols, the problem of data leakage in power data circulation is solved, and multi-party security calculations and data security are improved.
Patent Information
- Application Number
- CN202510754943.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-06
- Publication Date
- 2025-08-15
AI Technical Summary
How to achieve multi-party security calculations while protecting power data privacy to ensure that sensitive power data is not leaked, especially how to improve data security during the power data flow.
By building obfuscation circuits and inadvertent transmission protocols, the calculation logic of the power analysis function is issued to obfuscation tables, and the data is divided and decrypted using secret sharing and replacement tags to ensure that the participants do not disclose power analysis data in the joint calculation.
It realizes the safe exchange and processing of power analysis data through multi-party collaboration, reduces the probability of data leakage and improves the security of power analysis data.
Smart Images

Figure CN120498679A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a method, apparatus, computer equipment, computer-readable storage medium, and computer program product for secure multi-party sharing of power data under circulation. Background Art
[0002] Multi-party secure computation (MPC) is a technology that allows participants to collaborate on a computational task while protecting their data privacy. Based on the theories of cryptography and distributed computing, it utilizes cryptographic protocols and algorithms to ensure that participants' private data is not leaked during the computation process. These technologies are commonly used in applications such as electronic elections, threshold signatures, and electronic auctions.
[0003] Power data is highly sensitive, involving commercial secrets and user privacy. The data sharing methods used in related technologies pose a risk of leakage. Implementing multi-party secure computing while ensuring data privacy and preventing the leakage of sensitive power data (such as user electricity usage information and grid operating status) has become an urgent challenge. Summary of the Invention
[0004] Based on this, it is necessary to provide a method, device, computer equipment, computer-readable storage medium and computer program product for multi-party secure sharing of power data in the circulation of power data, which can improve the security of the power analysis data of the participants, in order to address the above technical problems.
[0005] In a first aspect, the present application provides a multi-party secure sharing method for power data circulation, which is applied to a first participant and includes:
[0006] The calculation logic of the power analysis function that the first and second participants need to participate in the calculation is constructed as an obfuscation circuit, and an obfuscation table corresponding to the obfuscation circuit and a first replacement tag are issued to the second participant; the first and second participants each hold a portion of their own and each other's secret components; the secret components are components obtained by secret sharing of the power analysis data held by the participants; and the first replacement tag is a replacement tag corresponding to the actual value of the secret component currently held by the first participant;
[0007] The second party is configured to obtain a second replacement tag through an oblivious transfer protocol; the second replacement tag is a replacement tag corresponding to the true value of the secret component currently held by the second party; the second party is further configured to perform decryption based on the obfuscation table according to the second replacement tag and the first replacement tag to obtain a decryption result replacement tag, and send the decryption result replacement tag to the first party;
[0008] The mapping relationship of the label in the confusion table is replaced according to the received decryption result, a decryption result is determined, and the decryption result is used as the power analysis result of the first participant and the second participant.
[0009] In one embodiment, the method further comprises:
[0010] A plurality of candidate replacement tags are sent to the second participant via an oblivious transfer protocol; the candidate replacement tags are all replacement tags associated with the secret component currently held by the second participant; and the second participant is configured to obtain the second replacement tag from the plurality of candidate replacement tags.
[0011] In one embodiment, the method further comprises:
[0012] secret sharing the power analysis data currently held by the user according to the secret sharing method indicated by the secret sharing model to obtain at least two first secret components to be distributed; wherein the number of the second participant is at least one;
[0013] retaining one of the first secret components, and distributing the other first secret components one by one to one of the second participants;
[0014] Receive a second secret component sent by each second participant, and use the retained first secret component and the received second secret component as the currently held secret component; wherein the second secret component is obtained by secret sharing of the power analysis data currently held by the second participant.
[0015] In one embodiment, the method further comprises:
[0016] Acquire a multi-party secure shared resource; the multi-party secure shared resource is used to indicate resource interaction between the first participant and the second participant; the multi-party secure shared resource includes at least a secret sharing configuration file, an oblivious transfer protocol file, and an obfuscated circuit configuration file;
[0017] The secret sharing configuration file is used to define configuration information of a secret sharing protocol so that data segmentation and reassembly between the first participant and the second participant comply with a predetermined security protocol;
[0018] The oblivious transfer protocol file is used to define the rules and configuration of the oblivious transfer protocol;
[0019] The obfuscation circuit configuration file is used to define configuration information of the obfuscation circuit.
[0020] In one embodiment, the method further comprises:
[0021] responding to a power analysis data query request input by a user account;
[0022] The power analysis data query request is anonymized to obtain an anonymized power analysis data query request; the anonymized power analysis data query request is used to instruct a database server to return query results that match the power analysis data query request; the technology used for the anonymization processing includes at least one of a virtual private network, a Tor network, a privacy mode, an IP proxy, and encrypted communication.
[0023] In one embodiment, the anonymizing the power analysis data query request includes:
[0024] Obtain anonymization configuration resources; the anonymization configuration resources include at least one of a virtual private network configuration file, a Tor network configuration file, a privacy mode configuration file, an IP proxy configuration file, and an encrypted communication configuration file; the virtual private network configuration file is used to configure and manage a virtual private network connection to hide the real IP address of the user account; the Tor network configuration file is used to configure and manage a Tor network connection to hide the real IP address and identity of the user account by encrypting and forwarding network traffic at multiple layers; the privacy mode configuration file is used to configure the privacy mode of the browser to not record browsing history and cache during browsing; the IP proxy configuration file is used to configure and manage an IP proxy server to forward the power analysis data query request from the real IP address of the user account to the IP address of the proxy server; the encrypted communication configuration file is used to configure an encrypted communication protocol or encrypted communication software to encrypt the communication content of the user account on the network;
[0025] The power analysis data query request is anonymized according to the configuration information in the anonymization configuration resource.
[0026] In a second aspect, the present application further provides a multi-party secure sharing device under power data circulation, which is applied to a first participant and includes:
[0027] A sending module is configured to construct the calculation logic of the power analysis function that the first and second participants need to participate in the calculation into an obfuscation circuit, and send an obfuscation table corresponding to the obfuscation circuit and a first replacement tag to the second participant; the first and second participants each hold a portion of their own and each other's secret components; the secret component is a component obtained by secret sharing of the power analysis data held by the participants; and the first replacement tag is a replacement tag corresponding to the actual value of the secret component currently held by the first participant;
[0028] The second party is configured to obtain a second replacement tag through an oblivious transfer protocol; the second replacement tag is a replacement tag corresponding to the true value of the secret component currently held by the second party; the second party is further configured to perform decryption based on the obfuscation table according to the second replacement tag and the first replacement tag to obtain a decryption result replacement tag, and send the decryption result replacement tag to the first party;
[0029] A decryption module is used to replace the mapping relationship of the label in the confusion table according to the received decryption result, determine the decryption result, and use the decryption result as the power analysis result of the first participant and the second participant.
[0030] In a third aspect, the present application further provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and when the computer program is executed by the processor, the steps of the above method are implemented.
[0031] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, which implements the steps of the above method when executed by a processor.
[0032] In a fifth aspect, the present application further provides a computer program product, comprising a computer program, which implements the steps of the above method when executed by a processor.
[0033] The above-mentioned multi-party secure sharing method, device, computer equipment, computer-readable storage medium and computer program product under the circulation of power data are applied to the first participant, by constructing the calculation logic of the power analysis function that the first participant and the second participant need to participate in the calculation into an obfuscation circuit, and sending the obfuscation table corresponding to the obfuscation circuit and the first replacement tag to the second participant; the first participant and the second participant both hold part of their own and each other's secret components; the secret component is the component obtained by secret sharing of the power analysis data held by the participants; the first replacement tag is the replacement tag corresponding to the true value of the secret component currently held by the first participant; wherein, the second participant is used to obtain the second replacement tag through an oblivious transfer protocol; the second replacement tag is the replacement tag corresponding to the true value of the secret component currently held by the second participant; the second participant is also used to decrypt based on the second replacement tag and the first replacement tag based on the obfuscation table to obtain a decryption result replacement tag, and send the decryption result replacement tag to the first participant; based on the mapping relationship between the received decryption result replacement tag in the obfuscation table, the decryption result is determined, and the decryption result is used as the power analysis result of the first participant and the second participant.
[0034] In this way, the power analysis data is divided into multiple secret components through secret sharing and distributed to different participants. The original data can only be restored under the cooperation of multiple parties. In the joint analysis of power data, based on the oblivious transfer protocol, the participants can securely exchange secret components through the oblivious transfer protocol, and encrypt the input secret component data through the obfuscation circuit, thereby realizing multi-party computing task management based on secret sharing, oblivious transfer, and obfuscation circuit, so as to realize multi-party secure computing function, reduce the probability of the participants' power analysis data being leaked, and improve the security of the participants' power analysis data. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following briefly introduces the drawings required for use in the embodiments of the present application or related technical descriptions. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying any creative work.
[0036] Figure 1 This is a diagram of an application environment of a multi-party secure sharing method for power data circulation in one embodiment;
[0037] Figure 2 1. A flowchart of a method for secure multi-party sharing of power data in an embodiment;
[0038] Figure 3 Schematic diagram of a flow chart of a multi-party secure sharing method for power data circulation in another embodiment;
[0039] Figure 4 A structural block diagram of a multi-party secure sharing device for power data flow in one embodiment;
[0040] Figure 5 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION
[0041] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0042] It should be noted that the terms "first", "second", etc. used in this application may be used to describe various elements, but these elements are not limited by these terms. These terms are only used to distinguish the first element from the second element. The terms "including" and "having" used in this application and any variations thereof are intended to cover non-exclusive inclusions. The term "plurality" used in this application refers to two or more. The term "and / or" used in this application refers to one of the solutions or any combination of multiple solutions.
[0043] The multi-party secure sharing method under power data circulation provided by the embodiment of the present application can be applied to Figure 1 In the application environment shown. The first participant 102 communicates with the second participant 104 through the network. The present method is applied to the first participant 102, and the first participant 102 constructs the calculation logic of the power analysis function that the first participant 102 and the second participant 104 need to participate in the calculation as an obfuscation circuit, and sends the obfuscation table corresponding to the obfuscation circuit, as well as the first replacement label to the second participant 104; the first participant 102 and the second participant 104 both hold part of their own and the other party's secret components; the secret component is the component obtained by secret sharing of the power analysis data held by the participants; the first replacement label is the replacement label corresponding to the real value of the secret component currently held by the first participant 102; the second Participant 104 is configured to obtain a second replacement tag through an oblivious transfer protocol; the second replacement tag is a replacement tag corresponding to the actual value of the secret component currently held by second party 104; second party 104 is further configured to perform decryption based on the obfuscation table using the second replacement tag and the first replacement tag to obtain a decryption result replacement tag, and send the decryption result replacement tag to first party 102; thus, first party 102 determines a decryption result based on the mapping relationship between the received decryption result replacement tag and the obfuscation table, and uses the decryption result as the power analysis result for first party 102 and second party 104. First party 102 and second party 104 may be computer devices, including but not limited to terminals, servers, and systems including terminals and servers.
[0044] In an exemplary embodiment, Figure 2 As shown, a multi-party secure sharing method under power data circulation is provided, and this method is applied to Figure 1 Taking the first participant 102 in the example as an example, the method includes the following steps S210 to S220.
[0045] In step S210, the calculation logic of the power analysis function that the first and second participants need to participate in the calculation is constructed as an obfuscation circuit, and an obfuscation table corresponding to the obfuscation circuit and a first replacement label are sent to the second participant.
[0046] The second participant is a participant other than the first participant who participates in the multi-party secure computing, and the number of the second participant is at least one.
[0047] In actual applications, the first participant and the second participant include but are not limited to the power generation end, the power consumption end, etc.
[0048] The first party and the second party each hold part of their own and the other party's secrets.
[0049] The secret component is the component obtained by secretly sharing the power analysis data held by the participants.
[0050] The power analysis data refers to data related to power analysis, including but not limited to at least one of power generation data, power consumption data, meteorological data, electricity price data, and industrial and commercial data.
[0051] The first participant and the second participant both hold at least one type of power analysis data, and the types of power analysis data held by the first participant and the second participant may be the same or different.
[0052] The first replacement tag is a replacement tag corresponding to the true value of the secret component currently held by the first participant.
[0053] The power analysis function refers to a function that analyzes the power analysis data of the first and second parties. For example, the power analysis function refers to a function used for power load forecasting, power consumption peak and valley analysis, and analysis of the impact of weather on industrial power consumption.
[0054] In the specific implementation, the first participant can obtain the power analysis function that the first participant and the second participant need to participate in the calculation, construct the calculation logic of the power analysis function into a confusion circuit, and generate a confusion table corresponding to the confusion circuit, and send the confusion table and the first replacement label to the second participant.
[0055] In the process of obtaining the secret component, the first participant can secret share the power analysis data currently held by itself according to the secret sharing method indicated by the secret sharing model, such as the addition secret sharing method and the multiplication secret sharing method, to obtain at least two first secret components to be distributed, retain one first secret component, and distribute the other first secret components one by one to a second participant; similarly, the second participant can also secret share the power analysis data currently held by itself according to the secret sharing method indicated by the secret sharing model, to obtain at least two second secret components to be distributed, retain one second secret component, and send one second secret component to the first participant.
[0056] Among them, the secret sharing model refers to a model used for multi-party secure computing to achieve secret sharing.
[0057] In this way, the first party can receive a second secret component sent by each second party respectively, and use the retained first secret component and the received second secret component as the currently held secret components.
[0058] For example, assuming there is only one second party, the first party currently holds power analysis data including voltage data V, and the second party currently holds power analysis data including current data I. The first and second parties split their respective power analysis data into secret components and exchange some of these secret components: the first party splits the voltage data V into VA (which it maintains) and VB (which it sends to the second party), while the second party splits the current data I into IA (which it sends to the first party) and IB (which it maintains). After exchanging their respective secret components, the first party currently holds the secret components VA and IA, while the second party currently holds the secret components VB and IB.
[0059] Furthermore, after receiving the obfuscation table and the first replacement label sent by the first participant, the second participant can obtain the second replacement label through the oblivious transfer protocol. The second replacement label is the replacement label corresponding to the true value of the secret component currently held by the second participant. The second participant is also used to decrypt based on the obfuscation table according to the second replacement label and the first replacement label, obtain the decryption result replacement label, and send the decryption result replacement label to the first participant.
[0060] Step S220: replace the mapping relationship of the label in the obfuscation table according to the received decryption result, determine the decryption result, and use the decryption result as the power analysis result of the first participant and the second participant.
[0061] In a specific implementation, after receiving the decryption result replacement label, the first participant can determine the decryption result based on the mapping relationship of the decryption result replacement label in the confusion table, and use the decryption result as the power analysis result of the first participant and the second participant.
[0062] For example, continuing with the previous example, the power analysis function can be a power calculation function: P = V × I. The power calculation function and comparison logic P ≥ T (power threshold) are converted into an obfuscation circuit. The decryption result replacement tag returned by the second party to the first party can be a replacement tag used to indicate whether the power is overloaded. The first party determines the decryption result based on the mapping relationship between the received decryption result replacement tag and the decryption result, thereby determining whether the final decryption result is overloaded or not. The mapping relationship represents the mapping relationship between the decryption result replacement tag and the decryption result. For example, if the decryption result replacement tag Z1 corresponds to an overload decryption result in the obfuscation table, and the decryption result replacement tag Z2 corresponds to an underload decryption result in the obfuscation table, the first party can quickly determine the decryption result based on the mapping relationship between the received decryption result replacement tags in the obfuscation table. The decryption result can be used as the power analysis result for the first and second parties. In this way, by combining secret sharing, oblivious transfer, and obfuscation circuits, the first and second parties can complete joint computations while protecting the privacy of their respective power analysis data, preventing the leakage of their respective power analysis data.
[0063] In some embodiments, when the second party is in the process of obtaining the second replacement tag, the first party can send multiple candidate replacement tags to the second party through an oblivious transfer protocol. The candidate replacement tags are all replacement tags associated with the secret component currently held by the second party, and the second party can determine the second replacement tag from the multiple candidate replacement tags based on the true value of the secret component currently held by itself.
[0064] In the above-mentioned multi-party secure sharing method under the circulation of power data, it is applied to the first participant, by constructing the calculation logic of the power analysis function that the first participant and the second participant need to participate in the calculation into an obfuscation circuit, and sending the obfuscation table corresponding to the obfuscation circuit and the first replacement label to the second participant; the first participant and the second participant both hold part of their own and each other's secret components; the secret component is the component obtained by secret sharing of the power analysis data held by the participants; the first replacement label is the replacement label corresponding to the true value of the secret component currently held by the first participant; wherein, the second participant is used to obtain the second replacement label through the oblivious transfer protocol; the second replacement label is the replacement label corresponding to the true value of the secret component currently held by the second participant; the second participant is also used to decrypt based on the second replacement label and the first replacement label based on the obfuscation table to obtain a decryption result replacement label, and send the decryption result replacement label to the first participant; according to the mapping relationship between the received decryption result replacement label in the obfuscation table, the decryption result is determined, and the decryption result is used as the power analysis result of the first participant and the second participant.
[0065] In this way, the power analysis data is divided into multiple secret components through secret sharing and distributed to different participants. The original data can only be restored under the cooperation of multiple parties. In the joint analysis of power data, based on the oblivious transfer protocol, the participants can securely exchange secret components through the oblivious transfer protocol, and encrypt the input secret component data through the obfuscation circuit, thereby realizing multi-party computing task management based on secret sharing, oblivious transfer, and obfuscation circuit, so as to realize multi-party secure computing function, reduce the probability of the participants' power analysis data being leaked, and improve the security of the participants' power analysis data.
[0066] In some embodiments, the method further includes: acquiring a multi-party secure shared resource; the multi-party secure shared resource is used to indicate resource interaction between the first participant and the second participant.
[0067] The multi-party secure shared resources at least include a secret sharing configuration file, an oblivious transfer protocol file, and an obfuscated circuit configuration file.
[0068] The secret sharing configuration file is used to define configuration information of the secret sharing protocol so that data segmentation and reassembly between the first participant and the second participant comply with a predetermined security protocol.
[0069] Among them, the oblivious transfer protocol file is used to define the rules and configuration of the oblivious transfer protocol to ensure that the participants can exchange data securely without leaking additional information.
[0070] Among them, the obfuscated circuit configuration file is used to define the configuration information of the obfuscated circuit to ensure that the participants can perform calculations without exposing the input.
[0071] In some further embodiments, the multi-party secure shared resources may also include at least one of a multi-party computing task table, a multi-party computing task configuration file, a multi-party computing communication protocol file, a multi-party computing task status file, a multi-party computing task log file, and a multi-party computing performance evaluation file.
[0072] Among them, the multi-party computing task table is used to manage and schedule various multi-party computing tasks.
[0073] Among them, the multi-party computing task configuration file is used to define the configuration information of the multi-party computing task and specify the task parameters, such as the participating parties, computing targets, and algorithms used.
[0074] Among them, the multi-party computing communication protocol file is used to define the communication protocol between the participants in the multi-party computing, ensuring that the necessary information can be exchanged securely between the participants.
[0075] The multi-party computing task status file is used to record the status information of the multi-party computing task, track the progress and status of the task, and help monitor the execution of the multi-party computing task.
[0076] The multi-party computing task log file is used to record the log information of the multi-party computing task and save key events during the task execution for auditing and troubleshooting.
[0077] The multi-party computing performance evaluation file is used to evaluate the performance of multi-party computing tasks, helping to understand the effectiveness of the tasks and identify areas for improvement.
[0078] In some further embodiments, when a user account retrieves power analysis data from a database associated with a participant, a hidden query can be used to prevent the database server from obtaining information related to the user's query statement, thereby protecting the user's query privacy. Hidden query, also known as private information retrieval, is a strategy for protecting user query privacy.
[0079] Specifically, taking the first participant as an example, the first participant can respond to the power analysis data query request input by the user account. The power analysis data query request refers to a query request for retrieving power analysis data. The first participant can respond to the power analysis data query request input by the user account, anonymize the power analysis data query request, and obtain an anonymized power analysis data query request. The anonymized power analysis data query request is used to instruct the database server associated with the first participant to return a query result that matches the power analysis data query request.
[0080] Among them, the technologies used for anonymization processing include at least one of Virtual Private Network (VPN), Tor network, privacy mode, IP proxy, and encrypted communication.
[0081] Among them, virtual private networks (VPNs) transmit data by establishing dedicated network connections, hiding the user's real IP address. The Tor network uses multiple layers of encryption and forwarding network traffic to hide the user's real IP address and identity. Privacy mode allows browsing the web without recording browsing history, caching, or using cookies (data stored on the user's local terminal). IP proxies can forward power analysis data query requests from the user's real IP address to the proxy server's IP address. Encrypted communications use encryption protocols or encrypted communication software to protect the content of user account communications on the network. Furthermore, hidden queries also involve advanced cryptographic techniques, such as asymmetric encryption and oblivious transfer. These techniques can construct encrypted communication channels for data exchange during multi-party queries, and conduct hidden queries through data obfuscation, data encryption, data transmission, data decryption, and precise matching models.
[0082] In some embodiments, anonymizing the power analysis data query request includes: obtaining an anonymization configuration resource; and anonymizing the power analysis data query request according to configuration information in the anonymization configuration resource.
[0083] The anonymization configuration resource includes at least one of a virtual private network configuration file, a Tor network configuration file, a privacy mode configuration file, an IP proxy configuration file, and an encrypted communication configuration file.
[0084] The VPN configuration file is used to configure and manage VPN connections, hiding the real IP address of the user account. By establishing an encrypted private network connection to transmit data, the user's identity and location privacy are protected.
[0085] The Tor network configuration file is used to configure and manage Tor network connections, which hide the real IP address and identity of the user account through multiple layers of encryption and forwarding of network traffic. By providing an anonymous network connection, the source of the user's query is difficult to trace.
[0086] The privacy mode profile is used to configure the browser's privacy mode so that browsing history, caching, and cookies are not recorded during browsing, preventing the user's browsing behavior from being tracked and recorded.
[0087] The IP proxy configuration file is used to configure and manage the IP proxy server, which forwards power analysis data query requests from the user's real IP address to the proxy server's IP address. The proxy server hides the user's real IP address and protects the user's account identity.
[0088] The encrypted communication profile is used to configure an encrypted communication protocol or software to encrypt user account communications on the network, ensuring that user account queries are not eavesdropped or tampered with during transmission.
[0089] In still other embodiments, the anonymization configuration resource may further include at least one of an asymmetric encryption algorithm configuration file, an oblivious transmission configuration file, and a data obfuscation and precise matching model configuration file.
[0090] The asymmetric encryption algorithm configuration file is used to configure an asymmetric encryption algorithm for data encryption and decryption. This is done using a public and private key pair to ensure secure data transmission. This asymmetric encryption algorithm prevents third-party interception of user account query data during transmission.
[0091] The oblivious transfer profile is used to configure oblivious transfer technology and build an encrypted communication channel for data exchange during multi-party queries. This ensures that during a multi-party query, each participant can only obtain the necessary information and cannot access the data of other participants.
[0092] The Data Obfuscation and Precision Matching Model configuration files are used to configure data obfuscation technology and precision matching models, enabling data obfuscation and precise matching after decryption. Data obfuscation technology protects data privacy while ensuring the accuracy of query results.
[0093] In this way, based on hidden query technology, an encrypted communication channel for data exchange during multi-party queries is established. Through data obfuscation, data encryption, data transmission, data decryption, and precise matching models, hidden queries are carried out. This supports joint analysis of power data circulation and effectively ensures data security. By integrating multi-party secure computing and hidden query technology, secure sharing and privacy protection of power data among multiple parties can be achieved.
[0094] In another embodiment, Figure 3 As shown, a flowchart of a multi-party secure sharing method under power data circulation is provided, which is applied to a first participant and includes the following steps:
[0095] Step S310: Acquire multi-party secure shared resources.
[0096] Step S320 : performing secret sharing on the power analysis data currently held by the user according to the secret sharing method indicated by the secret sharing model to obtain at least two first secret components to be distributed.
[0097] Step S330: retain one first secret component, and distribute the other first secret components one by one to a second participant.
[0098] Step S340: Receive a second secret component sent by each second participant, and use the retained first secret component and the received second secret component as the currently held secret components.
[0099] Step S350: construct the calculation logic of the power analysis function that the first and second participants need to participate in the calculation into an obfuscation circuit, and send the obfuscation table corresponding to the obfuscation circuit and the first replacement label to the second participant.
[0100] Step S360: Send multiple candidate replacement tags to the second participant via the oblivious transfer protocol.
[0101] Step S370: replace the mapping relationship of the label in the obfuscation table according to the received decryption result, determine the decryption result, and use the decryption result as the power analysis result of the first participant and the second participant.
[0102] It should be noted that the specific limitations of the above steps can be found in the specific limitations of a multi-party secure sharing method under power data circulation described above.
[0103] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily performed in sequence in the order indicated by the arrows. Unless clearly stated herein, the execution of these steps is not strictly limited in order, and these steps can be performed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above may include multiple steps or multiple stages, and these steps or stages are not necessarily performed at the same time, but can be performed at different times, and the execution order of these steps or stages is not necessarily performed in sequence, but can be performed in turn or alternately with at least a portion of the steps or stages in other steps or other steps. It is understandable that the various steps in different embodiments can be freely combined as needed, and the various non-contradictory schemes formed by the combination all fall within the scope of protection of this application.
[0104] Based on the same inventive concept, embodiments of the present application also provide a device for securely sharing power data under multi-party flow, which is used to implement the aforementioned method for securely sharing power data under multi-party flow. The solution provided by this device is similar to the solution described in the aforementioned method. Therefore, the specific limitations of one or more embodiments of the device for securely sharing power data under multi-party flow provided below can be found in the aforementioned method for securely sharing power data under multi-party flow, and will not be repeated here.
[0105] In an exemplary embodiment, Figure 4 As shown, a multi-party secure sharing device for power data flow is provided, which is applied to a first participant and includes: a sending module 410 and a decryption module 420, wherein:
[0106] The sending module 410 is configured to construct the computational logic of the power analysis function that the first and second participants need to participate in the computation into an obfuscation circuit, and send an obfuscation table corresponding to the obfuscation circuit and a first replacement tag to the second participant; the first and second participants each hold a portion of their own and each other's secret components; the secret components are components obtained by secret sharing of the power analysis data held by the participants; and the first replacement tag is a replacement tag corresponding to the actual value of the secret component currently held by the first participant;
[0107] Among them, the second participant is used to obtain a second replacement tag through an oblivious transfer protocol; the second replacement tag is a replacement tag corresponding to the true value of the secret component currently held by the second participant; the second participant is also used to decrypt based on the confusion table according to the second replacement tag and the first replacement tag, obtain a decryption result replacement tag, and send the decryption result replacement tag to the first participant.
[0108] The decryption module 420 is used to replace the mapping relationship of the label in the confusion table according to the received decryption result, determine the decryption result, and use the decryption result as the power analysis result of the first participant and the second participant.
[0109] In one embodiment, the sending module 410 is further used to send multiple candidate replacement tags to the second participant through an oblivious transfer protocol; the candidate replacement tags are all replacement tags associated with the secret component currently held by the second participant; and the second participant is used to obtain the second replacement tag from the multiple candidate replacement tags.
[0110] In one embodiment, the device further includes: a sharing module, configured to perform secret sharing on the power analysis data currently held by itself according to a secret sharing method indicated by a secret sharing model, to obtain at least two first secret components to be distributed; wherein the number of the second participants is at least one; retaining one first secret component, and distributing the other first secret components one by one to one second participant; receiving a second secret component sent by each second participant, and using the retained first secret component and the received second secret component as the currently held secret components; wherein the second secret component is obtained by secret sharing the power analysis data currently held by the second participant.
[0111] In one embodiment, the device further includes: an acquisition module for acquiring multi-party secure shared resources; the multi-party secure shared resources are used to indicate resource interaction between the first participant and the second participant; the multi-party secure shared resources include at least a secret sharing configuration file, an oblivious transfer protocol file and an obfuscation circuit configuration file; the secret sharing configuration file is used to define configuration information of the secret sharing protocol so that data segmentation and reorganization between the first participant and the second participant comply with a predetermined security protocol; the oblivious transfer protocol file is used to define rules and configuration of the oblivious transfer protocol; the obfuscation circuit configuration file is used to define configuration information of the obfuscation circuit.
[0112] In one embodiment, the device further includes: a query module for responding to a power analysis data query request input by a user account; anonymizing the power analysis data query request to obtain an anonymized power analysis data query request; the anonymized power analysis data query request is used to instruct a database server to return a query result that matches the power analysis data query request; the technology used for the anonymization processing includes at least one of a virtual private network, a Tor network, a privacy mode, an IP proxy, and encrypted communication.
[0113] In one embodiment, the query module is specifically used to obtain anonymization configuration resources; the anonymization configuration resources include at least one of a virtual private network configuration file, a Tor network configuration file, a privacy mode configuration file, an IP proxy configuration file, and an encrypted communication configuration file; the virtual private network configuration file is used to configure and manage a virtual private network connection to hide the real IP address of the user account; the Tor network configuration file is used to configure and manage a Tor network connection to hide the real IP address and identity of the user account through multiple layers of encryption and forwarding of network traffic; the privacy mode configuration file is used to configure the privacy mode of the browser to not record browsing history and cache during browsing; the IP proxy configuration file is used to configure and manage an IP proxy server to forward the power analysis data query request from the real IP address of the user account to the IP address of the proxy server; the encrypted communication configuration file is used to configure an encrypted communication protocol or encrypted communication software to encrypt the communication content of the user account on the network; according to the configuration information in the anonymization configuration resource, the power analysis data query request is anonymized.
[0114] Each module in the aforementioned multi-party secure sharing device for power data flow can be implemented in whole or in part through software, hardware, or a combination thereof. Each module can be embedded in or independent of a processor in a computer device in hardware form, or can be stored in a computer device memory in software form, so that the processor can call and execute the corresponding operations of each module.
[0115] In an exemplary embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as shown in FIG. Figure 5As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O) and a communication interface. The processor, memory and input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the computer device is used to store confusion table data. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a multi-party secure sharing method under power data circulation is realized.
[0116] Those skilled in the art will understand that Figure 5 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0117] In one embodiment, a computer device is further provided, including a memory and a processor. The memory stores a computer program, and the processor implements the steps in the above method embodiments when executing the computer program.
[0118] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.
[0119] In one embodiment, a computer program product is provided, including a computer program, which implements the steps in the above method embodiments when executed by a processor.
[0120] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.
[0121] Those skilled in the art will understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. In particular, any reference to memory, database, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The databases involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the various embodiments provided herein may be, but are not limited to, general-purpose processors, central processing units (CPUs), graphics processing units (GPUs), digital signal processors (DSPs), programmable logic devices (PLDs), quantum computing-based data processing logic devices, artificial intelligence (AI) processors, and the like.
[0122] The technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.
[0123] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.
Claims
1. A multi-party secure sharing method for power data circulation, characterized in that: Applied to a first party, the method includes: The calculation logic of the power analysis function that the first and second participants need to participate in the calculation is constructed as an obfuscation circuit, and an obfuscation table corresponding to the obfuscation circuit and a first replacement tag are issued to the second participant; the first and second participants each hold a portion of their own and each other's secret components; the secret components are components obtained by secret sharing of the power analysis data held by the participants; and the first replacement tag is a replacement tag corresponding to the actual value of the secret component currently held by the first participant; The second party is configured to obtain a second replacement tag through an oblivious transfer protocol; the second replacement tag is a replacement tag corresponding to the true value of the secret component currently held by the second party; the second party is further configured to perform decryption based on the obfuscation table according to the second replacement tag and the first replacement tag to obtain a decryption result replacement tag, and send the decryption result replacement tag to the first party; The mapping relationship of the label in the confusion table is replaced according to the received decryption result, a decryption result is determined, and the decryption result is used as the power analysis result of the first participant and the second participant.
2. The method according to claim 1, characterized in that The method further comprises: A plurality of candidate replacement tags are sent to the second participant via an oblivious transfer protocol; the candidate replacement tags are all replacement tags associated with the secret component currently held by the second participant; and the second participant is configured to obtain the second replacement tag from the plurality of candidate replacement tags.
3. The method according to claim 1, characterized in that The method further comprises: secret sharing the power analysis data currently held by the user according to the secret sharing method indicated by the secret sharing model to obtain at least two first secret components to be distributed; wherein the number of the second participant is at least one; retaining one of the first secret components, and distributing the other first secret components one by one to one of the second participants; Receive a second secret component sent by each second participant, and use the retained first secret component and the received second secret component as the currently held secret component; wherein the second secret component is obtained by secret sharing of the power analysis data currently held by the second participant.
4. The method according to claim 1, wherein The method further comprises: Acquire a multi-party secure shared resource; the multi-party secure shared resource is used to indicate resource interaction between the first participant and the second participant; the multi-party secure shared resource includes at least a secret sharing configuration file, an oblivious transfer protocol file, and an obfuscated circuit configuration file; The secret sharing configuration file is used to define configuration information of a secret sharing protocol so that data segmentation and reassembly between the first participant and the second participant comply with a predetermined security protocol; The oblivious transfer protocol file is used to define the rules and configuration of the oblivious transfer protocol; The obfuscation circuit configuration file is used to define configuration information of the obfuscation circuit.
5. The method according to claim 1, wherein The method further comprises: responding to a power analysis data query request input by a user account; The power analysis data query request is anonymized to obtain an anonymized power analysis data query request; the anonymized power analysis data query request is used to instruct a database server to return query results that match the power analysis data query request; the technology used for the anonymization processing includes at least one of a virtual private network, a Tor network, a privacy mode, an IP proxy, and encrypted communication.
6. The method according to claim 5, characterized in that The anonymizing the power analysis data query request includes: Obtain anonymization configuration resources; the anonymization configuration resources include at least one of a virtual private network configuration file, a Tor network configuration file, a privacy mode configuration file, an IP proxy configuration file, and an encrypted communication configuration file; the virtual private network configuration file is used to configure and manage a virtual private network connection to hide the real IP address of the user account; the Tor network configuration file is used to configure and manage a Tor network connection to hide the real IP address and identity of the user account by encrypting and forwarding network traffic at multiple layers; the privacy mode configuration file is used to configure the privacy mode of the browser to not record browsing history and cache during browsing; the IP proxy configuration file is used to configure and manage an IP proxy server to forward the power analysis data query request from the real IP address of the user account to the IP address of the proxy server; the encrypted communication configuration file is used to configure an encrypted communication protocol or encrypted communication software to encrypt the communication content of the user account on the network; The power analysis data query request is anonymized according to the configuration information in the anonymization configuration resource.
7. A multi-party secure sharing device for power data flow, characterized in that: Applied to a first participant, the apparatus includes: A sending module is configured to construct the calculation logic of the power analysis function that the first and second participants need to participate in the calculation into an obfuscation circuit, and send an obfuscation table corresponding to the obfuscation circuit and a first replacement tag to the second participant; the first and second participants each hold a portion of their own and each other's secret components; the secret component is a component obtained by secret sharing of the power analysis data held by the participants; and the first replacement tag is a replacement tag corresponding to the actual value of the secret component currently held by the first participant; The second party is configured to obtain a second replacement tag through an oblivious transfer protocol; the second replacement tag is a replacement tag corresponding to the true value of the secret component currently held by the second party; the second party is further configured to perform decryption based on the obfuscation table according to the second replacement tag and the first replacement tag to obtain a decryption result replacement tag, and send the decryption result replacement tag to the first party; A decryption module is used to replace the mapping relationship of the label in the confusion table according to the received decryption result, determine the decryption result, and use the decryption result as the power analysis result of the first participant and the second participant.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.