Data encryption method and device, data decryption method and device, storage medium and program product

By establishing a lifting mapping relationship between finite fields and residue class rings and using the twisted Edwards curve for encryption, the problem of high computational overhead of the SM2 curve group encryption method is solved, and efficient data encryption is achieved, which is suitable for resource-constrained environments such as IoT devices and smart cards.

CN120602242AActive Publication Date: 2025-09-05BEIJING INFOSEC TECH CO LTD +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511115863.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-08
Publication Date
2025-09-05
Estimated Expiration
2045-08-08

AI Technical Summary

Technical Problem

In the prior art, encryption methods based on the SM2 curve group have huge computational overhead, resulting in low encryption efficiency.

Method used

By establishing a lifting mapping relationship from the twisted Edwards curve on a finite field to the residue class ring, the public key is used to determine the first curve point on the twisted Edwards curve on the finite field, and the algebraic feature is extracted from the second curve point through a mapping function for encryption, generating a first sub-ciphertext and a second sub-ciphertext to form the ciphertext.

Benefits of technology

It significantly reduces the computational overhead in the encryption process, improves encryption efficiency, and is suitable for resource-constrained environments such as IoT devices and smart cards, ensuring security performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602242A_ABST
    Figure CN120602242A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a data encryption method and device, a data decryption method and device, a storage medium and a program product. According to the embodiment of the invention, the method comprises the steps: building a lifting mapping relation between a distorted Edwardholtz curve in a finite field and a distorted Edwardholtz curve on a remaining class ring, and determining a first curve on the distorted Edwardholtz curve in the finite field based on a public key; performing lifting mapping on the first curve point to obtain a second curve point on the twisted Edwardholtz curve on the remaining class rings based on a lifting mapping relation; and extracting algebraic features from the second curve point through a mapping function, performing inverse element transformation calculation to obtain a class function, encrypting the first to-be-encrypted data by using the class function to obtain a first sub-ciphertext, and forming a first ciphertext with the second sub-ciphertext. According to the method and the device, the first to-be-encrypted data is encrypted on the basis of the warping Edwardholtz curve and the lifting mapping relation, so that the calculation overhead in the encryption process is remarkably reduced, and the encryption efficiency is further improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer application technology, and in particular to a data encryption and decryption method, device, storage medium and program product. Background Art

[0002] In today's digital age, data has become a core asset. For security reasons, existing data needs to be encrypted during transmission and storage.

[0003] One commonly used encryption method involves extending the SM2 (elliptic curve public-key cryptography) curve to a residue class ring. This encryption principle is based on the group homomorphism mapping from the SM2 curve group over a finite field to the SM2 curve group over a residue class ring. The public key is used to encrypt the plaintext data, generating the corresponding ciphertext. In practical applications, this encryption method has a significant computational overhead, which directly reduces overall encryption efficiency. Summary of the Invention

[0004] Embodiments of the present application provide a data encryption and data decryption method, device, storage medium, and program product to reduce the computational overhead in the encryption process and thereby improve encryption efficiency.

[0005] An embodiment of the present application provides a data encryption method, including: establishing a lifting mapping relationship between a twisted Edwards curve on a finite field and a twisted Edwards curve on a residue class ring, wherein the lifting mapping relationship is, in an affine coordinate system, a lifting operation based on a P-adic number to keep the adjustment amount of the vertical coordinate h1p; wherein h1 represents the adjustment coefficient of the vertical coordinate, and the adjustment coefficient is associated with the coordinates of the point on the twisted Edwards curve on the finite field to be mapped to the twisted Edwards curve on the residue class ring; p represents a prime number; based on a public key, a first curve point on the twisted Edwards curve on the finite field is determined, and based on the lifting mapping relationship, the first curve point is lifted and mapped to a second curve point on the twisted Edwards curve on the residue class ring; an algebraic feature is extracted from the second curve point by a mapping function, and an inverse transformation is performed on the algebraic feature to obtain a class function of the second curve point; the class function of the second curve point is used to encrypt the first data to be encrypted to obtain a first sub-ciphertext; the first sub-ciphertext and the second sub-ciphertext constitute a first ciphertext; the second sub-ciphertext is generated according to the parameters of the twisted Edwards curve on the finite field.

[0006] An embodiment of the present application also provides a data decryption method, including: obtaining a first ciphertext and a second ciphertext; the first ciphertext and the second ciphertext are encrypted using any one of the data encryption methods; summing the first ciphertext and the second ciphertext to obtain a third ciphertext; sending the third ciphertext to a decryption party so that the decryption party decrypts the third ciphertext to obtain decrypted data, where the decrypted data is the sum of the first data to be encrypted and the second data to be encrypted.

[0007] An embodiment of the present application also provides a data decryption method, including: obtaining a first ciphertext; the first ciphertext is obtained by encrypting the first data to be encrypted using any data encryption method; the first ciphertext includes a first sub-ciphertext and a second sub-ciphertext; the second sub-ciphertext is generated based on the parameters of the twisted Edwards curve on the finite field; using the private key and the second sub-ciphertext to calculate the first decryption curve point of the twisted Edwards curve on the finite field; based on the lifting mapping relationship between the twisted Edwards curve on the finite field and the twisted Edwards curve on the residual class ring, the first decryption curve point is lifted and mapped to the second decryption curve point on the twisted Edwards curve on the residual class ring; extracting algebraic features from the second decryption curve point through a mapping function, and performing inverse transformation calculation on the algebraic features to obtain the class function of the second decryption curve point; using the class function of the second decryption curve point to decrypt the first sub-ciphertext to obtain the first data to be encrypted.

[0008] An embodiment of the present application also provides an electronic device, including: a processor and a memory, the memory being used to store a computer program. When the computer program is executed by the processor, the processor is enabled to implement each step of the data encryption and data decryption method provided in the embodiment of the present application.

[0009] An embodiment of the present application further provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the processor is enabled to implement each step of the data encryption and data decryption method provided in the embodiment of the present application.

[0010] An embodiment of the present application also provides a computer program product, including a computer program / instruction. When the computer program / instruction is executed by a processor, the processor is enabled to implement each step of the data encryption and data decryption method provided in the embodiment of the present application.

[0011] In an embodiment of the present application, a lifting mapping relationship is established between a twisted Edwards curve on a finite field and a twisted Edwards curve on a residual class ring, and a first curve on the twisted Edwards curve on the finite field is determined based on a public key. Based on the lifting mapping relationship, the first curve point is lifted and mapped to a second curve point on the twisted Edwards curve on the residual class ring; a class function is obtained by extracting algebraic features from the second curve point through a mapping function and performing an inverse transformation. The class function is then used to encrypt the first data to be encrypted to obtain a first sub-ciphertext, which is then combined with the second sub-ciphertext generated based on the curve parameters to form the first ciphertext. Based on the twisted Edwards curve, the present application encrypts the first data to be encrypted based on the lifting mapping relationship, significantly reducing the computational overhead in the encryption process and thereby improving encryption efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings: Figure 1 A flowchart of a data encryption method provided by an exemplary embodiment of the present application; Figure 2 A flowchart of a data decryption method provided by an exemplary embodiment of the present application; Figure 3 A flowchart of another data decryption method provided by an exemplary embodiment of the present application; Figure 4 A schematic structural diagram of an electronic device provided as an exemplary embodiment of the present application. DETAILED DESCRIPTION

[0013] To make the purpose, technical solutions, and advantages of this application more clear, the technical solutions of this application will be clearly and completely described below in conjunction with the specific embodiments of this application and the corresponding drawings. Obviously, the embodiments described are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0014] It should be noted that when the embodiments of this application involve user information, the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in the embodiments of this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and provide corresponding operation portals for users to choose to authorize or refuse. In addition, the various models involved in this application (including but not limited to language models or large models) are in compliance with relevant laws and standards.

[0015] In the prior art, extending SM2 (an elliptic curve public-key cryptography algorithm based on the Weierstrass curve) to a residual class ring involves excessive conditional branches and inverse computations, requiring coordinate transformations. This results in significant computational overhead for the encryption method, which reduces overall encryption efficiency. In an embodiment of the present application, a lifting mapping relationship is established between a twisted Edwards curve on a finite field and a twisted Edwards curve on a residual class ring. A first curve on the twisted Edwards curve on the finite field is determined based on a public key. Based on the lifting mapping relationship, points on the first curve are lifted and mapped to second curve points on the twisted Edwards curve on the residual class ring. Algebraic features are extracted from the second curve points using a mapping function and inversely transformed to obtain a class function. This class function is then used to encrypt first data to obtain a first sub-ciphertext, which is then combined with a second sub-ciphertext generated based on curve parameters to form the first ciphertext. Based on the twisted Edwards curve, the present application encrypts the first data to be encrypted based on the lifting mapping relationship, significantly reducing the computational overhead during the encryption process and thereby improving encryption efficiency.

[0016] The following describes in detail the technical solutions provided by various embodiments of the present application in conjunction with the accompanying drawings.

[0017] Figure 1 The following is a flow chart of a data encryption method provided by an exemplary embodiment of the present application. Figure 1 As shown, the method includes: S101. Establishing a lifting mapping relationship between a twisted Edwards curve on a finite field and a twisted Edwards curve on a residue class ring. The lifting mapping relationship is that, in an affine coordinate system, a lifting operation based on a p-adic number is performed so that the mapping maintains an adjustment amount of the ordinate by h1p; wherein h1 represents an adjustment coefficient of the ordinate, and the adjustment coefficient is associated with the coordinates of a point on the twisted Edwards curve on the finite field to be mapped to the twisted Edwards curve on the residue class ring; and p represents a prime number. S102: Determine a first curve point on the twisted Edwards curve over the finite field based on the public key, and perform a lifting mapping on the first curve point to convert it into a second curve point on the twisted Edwards curve over the residue class ring based on a lifting mapping relationship; S103, extracting algebraic features from the second curve point by using a mapping function, and performing inverse element transformation calculation on the algebraic features to obtain a class function of the second curve point; S104. Encrypt the first data to be encrypted using the class function of the second curve point to obtain a first sub-ciphertext; the first sub-ciphertext and the second sub-ciphertext constitute a first ciphertext; the second sub-ciphertext is generated according to the parameters of the twisted Edwards curve over a finite field.

[0018] In the embodiment of the present application, it can be applied to the encryption side. The twisted Edwards curve is a special form of elliptic curve, and its standard equation is ax 2 +y 2 =1+dx 2 y 2 , where a and d represent the parameters of the twisted Edwards curve, which are constants in the domain and satisfy a≠d and ad≠=0. The twisted Edwards curve is a generalized form of the Edwards curve, and its flexibility is enhanced by introducing the twist parameter a. When performing addition and point doubling operations on elliptic curves, the calculation formula of the twisted Edwards curve is simpler and more efficient than that of the traditional Weierstrass curve (such as that used in SM2). For example, when calculating the addition of two points, its formula is symmetric, and the number of multiplication and addition operations required is relatively small. This allows the twisted Edwards curve to complete cryptographic operations, such as key generation, more quickly while ensuring security performance in resource-constrained environments, such as IoT devices and smart cards.

[0019] Among them, the distorted Edwards curve parameters can include E ed (Fp), G and q, etc. Among them, E ed (Fp) represents the twisted Edwards curve defined on the finite field Fp, and G represents the twisted Edwards curve E ed The base point of order q on (Fp), where q is a positive integer.

[0020] In the embodiments of the present application, a finite field is an algebraic structure containing a finite number of elements, in which addition, subtraction, multiplication, and division (except division by zero) all satisfy the commutative, associative, and distributive laws. The size of the finite field is a prime power, which can be denoted as Fq, where q=p n (p is a prime number, n is a positive integer); when n = 1, it is called the prime field Fp, whose elements are the integers {0, 1, 2, …, p − 1}, and arithmetic operations are defined modulo p. In cryptography, the coefficients and point coordinates of the twisted Edwards curve equation can be taken from a finite field, ensuring that all operations are closed within a finite set, providing security guarantees for cryptographic protocols.

[0021] In the embodiment of the present application, the remainder class ring refers to the integer ring of the module, whose elements are the remainder classes [0], [1], ..., [module -1], and addition and multiplication are defined as modular operations. When the module is a prime number p, the remainder class ring degenerates into a finite field; but when the module is a composite number (such as module = p k , k≥2), is a non-domain ring. In this application, the residual class ring refers to Z / p k Z (k>1), that is, modulo p kThe ring whose elements can be expressed as a P-adic expansion. In this application, k is 2, that is, the residual class ring is Z / p 2 Z, modulo p 2 When encrypting data, the residual class ring can be used to construct a lifting map by using the 2 The above operation can be decomposed into iterative calculations modulo p to reduce the complexity of the overall encryption and thus improve encryption efficiency.

[0022] In an embodiment of the present application, data to be encrypted is encrypted by establishing a lifting mapping relationship between a twisted Edwards curve on a finite field and a twisted Edwards curve on a residue class ring, wherein the established lifting mapping relationship refers to establishing a lifting mapping from a twisted Edwards curve defined on a finite field to a twisted Edwards curve defined on a residue class ring. The lifting mapping relationship is, in an affine coordinate system, a lifting operation based on a p-adic number such that the mapping maintains an adjustment amount of the ordinate by h1p. h1 represents an adjustment coefficient for the ordinate, and the adjustment coefficient is associated with the coordinates of a point on the twisted Edwards curve on the finite field to be mapped to the twisted Edwards curve on the residue class ring.

[0023] Among them, p-adic numbers are an important mathematical tool in number theory. Its core idea is to construct a new number system structure based on a fixed prime number p. It can provide a number system construction method that is completely different from real numbers. Based on the "radix expansion" of the prime number p, it is used to analyze the local behavior of integers and rational numbers under the prime number p. P-adic numbers define absolute values ​​through p-adic assignments: for any non-zero rational number x, it can be expressed as a power of p multiplied by a fraction that is relatively prime to p. The p-adic assignment v p(x) is the exponent of the power, and the p-advanced absolute value is defined as |x|p=p {-v_p(x)} This means that when x contains more factors of p (for example, x can be divided by a high power of p), its p-adic absolute value is smaller, which is exactly the opposite of the behavior of the absolute value of real numbers. p It is obtained by completing the rational numbers with respect to this p-adic absolute value, where each element can be uniquely represented as a p-adic expansion extending infinitely to the left, such as ... + a2p 2 +a1p+a0+a {-1} p {-1} +..., coefficient a i All are from the integer range of 0 to p-1. This expansion direction is in sharp contrast to the characteristic of real decimals extending to the right, which makes P-adic numbers have unique advantages in analyzing the power behavior of integers modulo p, and in gradually improving the solutions modulo p to higher modulos p. k The solution plays a key role.

[0024] In an embodiment of the present application, p-adic numbers are used to expand the ordinates of points on a twisted Edwards curve on a residue class ring. Specifically, when establishing a lifting mapping relationship between a twisted Edwards curve on a finite field and a twisted Edwards curve on a residue class ring, a point on the twisted Edwards curve on the residue class ring is randomly selected as the third curve point (x, y). When mapping the fourth curve point (x′, y′) on the finite field to the third curve point (x, y) on the residue class ring, using the solution condition x = x′, the ordinate y of the third curve point needs to be expanded by p-adic numbers. By performing a p-adic number expansion on the ordinate y, the complex curve point mapping problem can be decomposed into multiple solutions involving terms of different powers of p, thereby simplifying the processing of the mapping equation. Furthermore, the conditions of the curve equation can be gradually satisfied modulo different powers of p, thereby ensuring that the mapped points satisfy the equation of the twisted Edwards curve on the residue class ring.

[0025] Among them, in the affine coordinate system, the lifting operation of P-adic numbers can "lift" the coordinate elements on the finite field to the corresponding elements in the residual class ring. There is no need for coordinate conversion, and the lifting can be completed directly through the lifting operation based on P-adic numbers, avoiding the additional overhead caused by the asymmetry of the curve form. Specifically, due to the equation symmetry of the twisted Edwards curve, the lifting mapping can ensure that the derivative in the lifting mapping is non-zero, which can explain that the twisted Edwards curve on the finite field can be lifted based on the P-adic number, making the calculation of the adjustment amount h1p more direct; at the same time, for the calculation of subsequent class functions, it is easier to handle on the residual class ring, reducing the modular inverse operation during encryption. This advantage stems from the intrinsic geometric properties of the twisted Edwards curve: there are no singular points in the affine plane, and all points can be represented by finite coordinates, making the iterative process of the lifting mapping (such as from module p to module p) 2 ) requires only linear adjustments rather than high-order iterations, thereby improving encryption speed while maintaining security.

[0026] In an embodiment of the present application, the relationship between the public key and the private key is established through scalar multiplication on an elliptic curve. Based on the twisted Edwards curve on a finite field, a private key and a public key can be generated. Specifically, a random integer d between 0 and q1 can be generated as a private key. Among them, q can represent the order in the twisted Edwards curve parameter. Afterwards, the private key d is used to generate the public key Q, and the public key Q=[d]G is generated by performing a scalar multiplication operation on the twisted Edwards curve parameter base point G and the private key d, where Q∈E ed (Fp), G∈E ed(Fp), Q represents the public key, and G represents the base point in the Twisted Edwards curve parameters. [] represents scalar multiplication, which multiplies a point on the Twisted Edwards curve by an integer (scalar). Essentially, scalar multiplication involves repeatedly adding that point to the Twisted Edwards curve a number of times, determined by the value of the scalar. For example, if the scalar is d and the curve point is C1, then [d]C1 means adding C1 to itself d times.

[0027] In short, the private key is the base for generating the public key, and the public key is the result of scalar multiplication of the private key and the base point. This relationship allows the private key to be used for decryption, while the public key is used for encryption. It is also difficult to reverse engineer the private key from the public key, ensuring the security of data encryption.

[0028] Among them, using the twisted Edwards curve parameters, a point on the twisted Edwards curve over a finite field can be generated as a partial ciphertext. Specifically, a random number r between 0 and q1 can be generated, and the random number and the twisted Edwards curve parameters can be used to generate a point C1=r[G]∈E ed (Fp), C1 represents a partial ciphertext that can be used to construct a complete ciphertext. For ease of description, the partial ciphertext represented by C1 can be called the second sub-ciphertext.

[0029] In the embodiment of the present application, the first curve point on the twisted Edwards curve over the finite field can be generated using the public key. Specifically, the first curve point C2 = [r] Q ∈ E can be generated using the random number r and the public key. ed (Fp), C2 represents the twisted Edwards curve E on the finite field ed The first curve point on (Fp) can be used to encrypt the data to be encrypted to obtain an encrypted ciphertext, which can be called a first sub-ciphertext and can form a complete ciphertext with the above-mentioned second sub-ciphertext.

[0030] For ease of description, a curve point on the twisted Edwards curve over a finite field may be referred to as a first curve point, and a curve point on the twisted Edwards curve over a residual class ring may be referred to as a second curve point.

[0031] In an embodiment of the present application, based on the lifting mapping relationship described in the above embodiment, a first curve point can be lifted and mapped to a second curve point on a twisted Edwards curve on a residual class ring. While the point sets on the twisted Edwards curve on a finite field and the twisted Edwards curve on a residual class ring do not correspond one-to-one, through a specific lifting mapping relationship, each point on the finite field curve can be uniquely lifted to a specific point on the residual class ring curve.

[0032] Furthermore, the algebraic features are extracted from the second curve point through the mapping function, and the algebraic features are inversely transformed to obtain the class function of the second curve point. The class function of the second curve point can be calculated using the following formula (1), in preparation for further using the class function of the second curve point to encrypt the first data to be encrypted: b= (1) in, represents the second curve point, Represents the first curve point, q represents the order of the twisted Edwards curve on the finite field, Φ represents the lifting mapping from the twisted Edwards on the finite field to the twisted Edwards on the residue class ring; b represents the class function of the second curve point, f represents the mapping function, and modp represents the modulus p.

[0033] Among them, [q]ΦC2 represents the q after the first curve point is lifted and mapped. - The algebraic feature is a numerical attribute extracted from the coordinates of the second curve point, reflecting the essence of its algebraic structure. Let the second curve point be the input point, and perform the extraction operation through the mapping function f to input the algebraic feature. The inverse element transformation calculation refers to multiplying the algebraic feature f([q]ΦC2) by the multiplication inverse element q under the modulus p. −1 modp, get the class function of the second curve point =b.

[0034] Furthermore, the first data to be encrypted can be encrypted using the class function of the second curve point to obtain a first sub-ciphertext, wherein the encrypted first sub-ciphertext has an additively homomorphic encryption property.

[0035] The above-mentioned encryption with homomorphic properties can include multiple implementations such as encryption with additive homomorphic properties or encryption with multiplicative homomorphic properties. As an optional implementation, when the first data to be encrypted is encrypted using the class function of the second curve point, it can be implemented as encryption with additive homomorphic properties. Then, the first data to be encrypted is encrypted using the class function of the second curve point. The method for obtaining the first sub-ciphertext can be to add the class function of the first curve point and the first data to be encrypted to obtain the first sub-ciphertext. Specifically, the following formula (2) can be used to calculate the first sub-ciphertext: c=m+b modp(2) Wherein, c represents the first sub-ciphertext, m represents the first data to be encrypted, b represents the class function of the second curve, mod represents the modulo operation, and p represents the parameter of the twisted Edwards curve.

[0036] Optionally, when the first data to be encrypted is encrypted using the class function of the second curve point, encryption with a multiplication homomorphic property can be realized. Then, the first data to be encrypted is encrypted using the class function of the second curve point to obtain a first sub-ciphertext. Specifically, the following formula (3) can be used to calculate the first sub-ciphertext: c = mbmodp (3) Wherein, c represents the first sub-ciphertext, m represents the first data to be encrypted, b represents the class function of the second curve, mod represents the modulo operation, and p represents the parameter of the twisted Edwards curve.

[0037] Further, output ciphertext .in, Indicates using the public key (pk) to perform an encryption operation on the plaintext m (i.e., the first data to be encrypted); = This shows that the ciphertext C consists of two components: represents a twisted Edwards curve point on a finite field (i.e., the second sub-ciphertext), and c represents the first sub-ciphertext generated by a class function based on the second curve point.

[0038] In an optional embodiment, a lifting mapping relationship between a twisted Edwards curve on a finite field and a twisted Edwards curve on a residual class ring is established, including: randomly selecting any curve point on the twisted Edwards curve on the residual class ring as a third curve point (x, y), and randomly selecting any curve point on the twisted Edwards curve on the finite field as a fourth curve point (x′, y′); solving the mapping equation with x=x′ as the solution condition and the goal of mapping the fourth curve point (x′, y′) to the third curve point (x, y), so as to obtain an adjustment coefficient for mapping the ordinate of the fourth curve point to the ordinate of the third curve point The expression is related to the coordinates of the fourth curve point (x′, y′); according to the adjustment coefficient The expression and prime number p are used to calculate the adjustment amount of the vertical coordinate of the fourth curve point as h1p; based on the adjustment amount h1p, the coordinates of the third curve point are re-expressed as (x′, y′) using the fourth curve point (x′, y′ ) to obtain the lifting mapping relationship, which is expressed as (x′, y′)→(x′, y′ ).

[0039] Among them, any curve point on the twisted Edwards curve on the residual class ring is randomly selected as the third curve point (x, y) to select a starting point on the residual class ring to provide a target position for the subsequent establishment of the mapping relationship; any curve point on the twisted Edwards curve on the finite field is randomly selected as the fourth curve point (x′, y′), and similarly, a starting point is selected on the finite field to establish a corresponding relationship with the point on the residual class ring.

[0040] In this case, we avoid solving the coupled equations of x and y simultaneously and reduce the problem to a single variable linear equation. By establishing a mapping equation, we can transform the fourth curve point on the finite field into the third curve point on the residual class ring. By taking x = x′ as the solution condition, we can derive the adjustment coefficient that maps the ordinate of the fourth curve point to the ordinate of the third curve point. This expression shows how the ordinate y′ of a curve point on the finite field is adjusted to obtain the ordinate y of the curve point on the residual class ring. Because different fourth curve points (x′, y′) have different coordinates, the expression for the adjustment coefficient h1 is related to the coordinates of the fourth curve point.

[0041] Furthermore, after obtaining the adjustment coefficient h1, the adjustment amount of the ordinate is calculated as h1p using the prime number p of the finite field. This is because the order of the finite field is p, and in the sense of modulo p, the adjustment amount h1p can be used to adjust the ordinate on the finite field to the residue class ring.

[0042] Based on the adjustment amount h1p, the coordinates of the third curve point are re-expressed as (x′, y′) using the fourth curve point (x′, y′). ) to obtain the lifting mapping relationship, which is expressed as (x′, y′)→(x′, y′ ), which means that when mapping the fourth curve point (x′, y′) on a finite field to the third curve point on the residue class ring, the abscissa remains x′, while the ordinate is adjusted to y′ + h1p. This mapping relationship "lifts" the curve point on the twisted Edwards curve from the finite field to the residue class ring. The introduction of the adjustment factor h1p ensures that the lifted point satisfies the equation of the twisted Edwards curve on the residue class ring and maintains a connection with the point on the finite field. For example, if the fourth curve point is (2, 3), the adjustment factor h1 is calculated to be 1, and the prime number p = 5, then the adjustment factor is 1×5=5, and the ordinate of the third curve point after the lifting mapping is 3+5=8 (further modular operations may be required in the residue class ring, depending on the modulus of the residue class ring). Through the above process, a lifting mapping relationship between twisted Edwards curves on finite fields and twisted Edwards curves on the residue class ring is established, providing fundamental mathematical tools and conversion mechanisms for subsequent cryptographic applications, such as encryption.

[0043] In an optional embodiment, with x=x′ as the solution condition, the mapping equation is solved with the fourth curve point (x′, y′) mapped to the third curve point (x, y) as the goal to obtain the adjustment coefficient for mapping the ordinate of the fourth curve point to the ordinate of the third curve point. The expression includes: constructing the mapping equation f(x, y) from the twisted Edwards curve on the finite field to the twisted Edwards curve on the residual class ring according to the third curve point (x, y) = ; where a and d represent the parameters of the twisted Edwards curve on the residue class ring; the ordinate y of the third curve point is expanded by a p-adic number according to the prime number p to obtain the expression of the ordinate y= ;in, Represents the constant term of the ordinate y when modulo p, that is, y≡ modp, h2 means the vertical coordinate y is modulo p 3 The quadratic term coefficient when , Represents a higher order power term of p; with x=x′ as the solution condition, x′, y= Substitute the mapping equation and solve it with the square of the prime number p to obtain the expression of the adjustment coefficient of the vertical coordinate: .

[0044] in, Indicates that y modulo p 2 The linear coefficient when y≡ + pmodp 2 , higher order terms are O(p 3 ). ≡ means that two numbers have the same remainder when modulo a certain number. For example, a≡b(modm) means that a−b is a multiple of m, that is, m∣(a−b).

[0045] In an optional embodiment, x=x′ is used as the solution condition, and x′, y= Substitute the mapping equation and solve it with the square of the prime number p to obtain the expression of the adjustment coefficient of the vertical coordinate: , including: taking x=x′ as the solution condition, and changing x′, y= Substitute the mapping equation as the first equation to be solved. The first equation to be solved is: f(x′,y)=ax′ 2 +( ) 2 −1−dx′ 2 ( ) 2 Grouping by the power of p, we get: f(x′,y)=[a(x′) 2 +h0 2 −1−d(x′) 2 h0 2]+[2h0h1−2d(x′) 2 h0h1]p+[(2h0h2+h1 2 )−d(x′) 2 (2h0h2+h1 2 )]p 2 +O(p 3 ) Among them, [a(x′) 2 +h0 2 −1−d(x′) 2 h0 2 ] is a constant term (p 0 ), [2h0h1−2d(x′) 2 h0h1]p is a first-order term (p 1 )、[(2h0h2+h1 2 )−d(x′) 2 (2h0h2+h1 2 )]p 2 is the quadratic term (p 2 ).

[0046] Take the first equation to be solved f(x′,y)=[a(x′) 2 +h0 2 −1−d(x′) 2 h0 2 ]+[2h0h1−2d(x′) 2 h0h1]p+[(2h0h2+h1 2 )−d(x′) 2 (2h0h2+h1 2 )]p 2 +O(p 3 ) is equal to 0 as the solution condition, solve the first equation to be solved, and get the constant term h0= ;when ,but , Substitute the constant term h0 into the first equation to be solved to obtain the second equation to be solved: f(x′, y′)=ax′ 2 +y′ 2 −1−dx′ 2 y′ 2 .

[0047] The second equation to be solved is solved with the condition that the second equation to be solved is congruent with 0 in the case of the modular operation of the square of the prime number p, that is: f(x′, y′)=ax′ 2 +y′ 2 −1−dx′ 2 y′ 2 ≡0(modp).

[0048] Therefore, f(x′, y′) is an integer multiple of p, which is expressed as f(x′, y′)=kp, where k is a random number.

[0049] The solution process for the second equation to be solved is as follows: Substitute f(x′, y′) = kp into f(x′, y′) = ax′ 2 +y′ 2 −1−dx′ 2 y′ 2 ≡0(modp), and extract the first term, we get: f(x′,y′)=kp+2y′h1p(1−dx′ 2 )+p 2 [2y′h2(1−dx′ 2 )+h1 2 (1−dx′ 2 )]+O(p 3 )=kp+2y′h1p(1−dx′ 2 )+p 2 ⋅M+O(p 3 ) Where M = 2y′h 2 (1−dx′ 2 )+h1 2 (1−dx′ 2 ) is the coefficient of the second-order term.

[0050] For f(x′,y′)=kp+2y′h1p(1−dx′ 2 )+p 2 [2y′h2(1−dx′ 2 )+h1 2 (1−dx′ 2 )]+O(p 3 )=kp+2y′h1p(1−dx′ 2 )+p 2 ⋅M+O(p 3 ) Application Model 2 After the congruence conditions, we get: k+2y′h1(1−dx′ 2 )≡0(modp) k+2y′h1(1−dx′ 2 )≡0(modp) to get: 2y′h1(1−dx′ 2 )≡−k(modp) Since the twisted Edwards curve is non-singular and the cryptographic parameters ensure that y′=0 and x′2=1 / d(modp), the denominator 2y′h1(1−dx′2 ) is reversible in a finite field.

[0051] Further, solve 2y′h1(1−dx′ 2 )≡−k(modp), we get: h1≡ (modp) Since f(x′, y′)=kp, we get k=f(x′, y′) / p, and substituting k=f(x′, y′) / p into h1≡ (modp), the expression of the adjustment coefficient of the vertical coordinate is: .

[0052] Through the above process, the fourth curve point (x′, y′) on the finite field is mapped to the third curve point (x′, y′+h1p) on the residual class ring, thus establishing a lifting mapping relationship. During the mapping process, the horizontal coordinate x′ remains unchanged, which means that no complex calculations or adjustments are required. Therefore, the direct lifting mapping reduces the number of calculation steps and simplifies the operation. In addition, the vertical coordinate y′ is lifted through a simple linear adjustment, that is, the adjustment amount h1p is added to the original vertical coordinate y′. The adjustment amount h1p here is obtained through precalculation, while the expression of h1 is related to the twisted Edwards curve parameters and the coordinates of the point on the finite field. However, once determined, the calculation process becomes direct and efficient.

[0053] More importantly, through the P-adic expansion, the mapping equation can be solved step by step under different moduli. This step-by-step solution method decomposes the complex nonlinear equation solution problem into multiple simple linear problems, thereby reducing the computational complexity.

[0054] Based on the simplicity of the above-mentioned lifting mapping relationship, it becomes efficient and easy to implement the lifting mapping of curve points on the twisted Edwards curve on the finite field to curve points on the twisted Edwards curve on the residue class ring, and then the encryption of the first data to be encrypted is completed based on the lifting mapping relationship, which can significantly reduce the computational overhead in the encryption process and thus improve the encryption efficiency.

[0055] In an optional embodiment, a fifth curve point on the twisted Edwards curve on a finite field is determined based on the second data to be encrypted, and the fifth curve point is lifted and mapped to a sixth curve point on the twisted Edwards curve on the residue class ring based on a lifting mapping relationship; algebraic features are lifted from the sixth curve point by a mapping function, and the algebraic features are inversely transformed to obtain a class function of the sixth curve point; the second data to be encrypted is encrypted using the class function of the sixth curve point to obtain a third sub-ciphertext; the third sub-ciphertext and the fourth sub-ciphertext constitute the second ciphertext; the fourth sub-ciphertext is generated based on the parameters of the twisted Edwards curve on the finite field; the first ciphertext and the second ciphertext are added to obtain a third ciphertext; the third ciphertext is sent to a decryption party for the decryption party to decrypt the third ciphertext to obtain third data to be encrypted; wherein, the third data to be encrypted is the sum of the first data to be encrypted and the second data to be encrypted.

[0056] Among them, the detailed implementation methods and beneficial effects of each step of encrypting the second data to be encrypted to obtain the second ciphertext in the method of this embodiment are the same as the steps of encrypting the first data to be encrypted to obtain the first ciphertext in the aforementioned embodiment, and this step has been described in detail in the aforementioned embodiment, and will not be elaborated here.

[0057] Among them, the result obtained by decrypting after performing the sum operation on the first sub-ciphertext and the third sub-ciphertext is consistent with the result obtained by directly performing the sum operation on the first data to be encrypted and the second data to be encrypted. By using the above-mentioned encryption method with additive homomorphic properties to encrypt the data to be encrypted, it can be achieved that in the process of data transmission, when it involves summing up multiple data to be encrypted, the multiple ciphertexts obtained by encrypting the multiple data to be encrypted can be directly summed up, and the result obtained by summing up the multiple ciphertexts can be decrypted, and the same result as the result obtained by summing up the multiple data to be encrypted can be obtained, thereby avoiding the situation of decrypting the ciphertext and data leakage during the data transmission process, and can be applied to data transmission scenarios involving untrusted environments, such as cloud environments. At the same time, based on the data encryption method for encrypting the data to be encrypted based on the lifting mapping relationship in the embodiment of the present application, homomorphic encryption can be performed, which can significantly reduce the computational overhead in the homomorphic encryption process, thereby improving encryption efficiency.

[0058] Alternatively, for the encrypted plaintext m (i.e., the data to be encrypted), the ciphertext C = (C1, c) can be obtained, and for any constant k∈M, k·C = ([k] C1, kc mod p). This equation shows that the result obtained by decrypting the ciphertext C after performing a scalar multiplication operation k·C is the same as the result obtained by encrypting the plaintext m after performing a scalar multiplication operation km. By utilizing this encryption method with the scalar multiplication homomorphic property to encrypt the encrypted data, when scalar multiplication operations are required on the ciphertext during data transmission and processing, [k] C1 (curve point scalar multiplication) and kc mod p (modular operation) can be efficiently performed directly in the ciphertext domain, without the need for decryption and subsequent calculation. Decrypting the result of this scalar multiplication operation accurately restores the value of km, effectively avoiding the risk of data leakage caused by decryption in untrusted environments.

[0059] In particular, in scenarios such as privacy-preserving machine learning and secure outsourced computing, data owners can upload encrypted data to a cloud server and authorize the cloud server to directly perform scalar multiplication operations (such as weight adjustment, feature scaling, and other key operations) on the ciphertext according to the methods in the embodiments of this application without accessing the original data. This not only maintains data confidentiality but also significantly reduces the local computing burden, providing a cryptographic foundation for resource-constrained devices to achieve efficient and secure privacy-preserving computing in a cloud environment.

[0060] Figure 2 The following is a flow chart of a data decryption method provided by an exemplary embodiment of the present application. Figure 2 As shown, the method includes: S201. Obtain a first ciphertext and a second ciphertext; the first ciphertext and the second ciphertext are obtained by encrypting using any one of the data encryption methods; S202, summing the first ciphertext and the second ciphertext to obtain a third ciphertext; S203: Send the third ciphertext to a decryption party, so that the decryption party decrypts the third ciphertext to obtain decrypted data, where the decrypted data is the sum of the first data to be encrypted and the second data to be encrypted.

[0061] The detailed implementation and beneficial effects of steps S201 - S202 in the method of this embodiment have been described in detail in the aforementioned embodiments and will not be elaborated on here.

[0062] Among them, the decryption party is a trusted entity holding a private key, which can perform lifting mapping and function-like calculations, and is not limited in the embodiments of this application. For example, it can be an authorized decryption module in a cloud server or an Internet of Things gateway. Through the above-mentioned data decryption method, the decryption party can directly perform addition operations on the ciphertext and verify the results without decrypting the original data. Its core function is to achieve "data available but invisible" secure computing, while protecting data privacy, supporting the secure aggregation of multi-party data, and avoiding the risk of key exposure caused by intermediate decryption.

[0063] For example, suppose p = 17, public key = 3, and private key = 6. Encrypted data: First ciphertext D1 = 2, C1 = 2*3 = 6 mod 17; second ciphertext D2 = 3, C2 = 3*3 = 9 mod 17. The summed ciphertext is C3 = C1 + C2 = 6 + 9 = 15 mod 17. Decrypted ciphertext: D = 15*6 = 90 mod 17 = 90 - 5*17 = 90 - 85 = 5 mod 1. Therefore, the decrypted result, 5, equals the first ciphertext D1 + the second ciphertext D2 = 2 + 3 = 5, demonstrating additive homomorphism.

[0064] Figure 3 A flowchart of another data decryption method provided by an exemplary embodiment of the present application. Figure 3 As shown, the method includes: S301. Obtain a first ciphertext; the first ciphertext is obtained by encrypting first data to be encrypted using any data encryption method; the first ciphertext includes a first sub-ciphertext and a second sub-ciphertext; the second sub-ciphertext is generated based on parameters of a twisted Edwards curve over a finite field; S302, using the private key and the second sub-ciphertext to calculate and obtain a first decryption curve point of the twisted Edwards curve over the finite field; S303: Based on the lifting mapping relationship between the twisted Edwards curve on the finite field and the twisted Edwards curve on the residue class ring, lift the decryption curve point to a second decryption curve point on the twisted Edwards curve on the residue class ring; S304: extracting algebraic features from the second decrypted curve point using a mapping function, and performing inverse transformation calculation on the algebraic features to obtain a class function of the second decrypted curve point; S305 : Decrypt the first sub-ciphertext using the class function of the second decryption curve point to obtain the first data to be encrypted.

[0065] The detailed implementation and beneficial effects of step S301 in the method of this embodiment have been described in detail in the aforementioned embodiments and will not be elaborated on here.

[0066] The first decrypted curve point of the twisted Edwards curve on the finite field is obtained by calculating the private key d and the second sub-ciphertext. Specifically, the first decrypted curve point of the twisted Edwards curve on the finite field can be obtained by calculating the private key and the second sub-ciphertext according to the following formula (4): C1'=[d]C1(4) Wherein, C1' represents the first decryption curve point, d represents the private key, and C1 represents the second sub-ciphertext.

[0067] In the embodiment of the present application, based on the lifting mapping relationship between the twisted Edwards curve on the finite field and the twisted Edwards curve on the residual class ring, the first decryption curve point is lifted and mapped to the second decryption curve point on the twisted Edwards curve on the residual class ring. The second decryption curve point can be calculated according to the following formula (5): = (5) in, Denotes the decrypted second elliptic curve point, C1' denotes the first decrypted curve point, q denotes the order of the twisted Edwards curve over the finite field, and Φ denotes the lifting mapping between the twisted Edwards curve over the finite field and the twisted Edwards curve over the residue class ring.

[0068] In the embodiment of the present application, after determining the second decryption curve point, the algebraic feature can be extracted from the second decryption curve point by using a mapping function, and the algebraic feature can be inversely transformed to obtain the class function of the second decryption curve point. The class function of the second decryption curve point is used for decryption. The class function of the second decryption curve point can be calculated using the following formula (6): (6) in, represents the class function of the second decryption curve point, f represents the mapping function, modp represents the modulus p; Φ represents the lifting map from the twisted Edwards on the finite field to the twisted Edwards on the residue class ring; represents the second decrypted elliptic curve point, and C1' represents the first decrypted curve point.

[0069] Among them, the method of this embodiment uses a mapping function to extract algebraic features from the second decryption curve point and performs inverse transformation calculation on the algebraic features, which is the same as the implementation method of extracting algebraic features from the second curve point through a mapping function and performing inverse transformation calculation on the algebraic features in the previous embodiment to obtain the class function of the second curve point, and the detailed implementation method and beneficial effects have been described in detail in the previous embodiment, and will not be elaborated here.

[0070] The first sub-ciphertext can be decrypted using the analog function of the second decryption curve point according to the decryption method corresponding to the encryption method. In this embodiment, the decryption method of decrypting the first sub-ciphertext using the analog function of the second decryption curve point can be implemented in multiple ways.

[0071] As an optional implementation, the first data to be encrypted can be obtained by adding the class function of the second decryption curve point and the first sub-ciphertext. Specifically, m=c modp, where m represents the first data to be encrypted, c represents the first sub-ciphertext, represents the class function of the second decrypted curve point, mod represents the modulo operation, and p represents the parameter of the distorted Edwards curve.

[0072] As another optional implementation, the first data to be encrypted can be obtained by multiplying the first sub-ciphertext by the analogous function of the second decryption curve point. Then, the first sub-ciphertext and the analogous function of the second decryption curve point can be used to calculate the quotient to obtain the first data to be encrypted. Specifically, m=c 1 modp, where m represents the first data to be encrypted, c represents the first sub-ciphertext, represents the class function of the second decrypted curve point, mod represents the modulo operation, and p represents the parameter of the distorted Edwards curve.

[0073] The detailed implementation and beneficial effects of each step in the method of this embodiment have been described in detail in the aforementioned embodiments and will not be elaborated here.

[0074] In addition, some of the processes described in the above embodiments and the accompanying drawings include multiple operations that appear in a specific order, but it should be clearly understood that these operations may not be executed in the order in which they appear in this article or may be executed in parallel. The serial numbers of the operations, such as 101, 102, etc., are only used to distinguish between different operations, and the serial numbers themselves do not represent any order of execution. In addition, these processes may include more or fewer operations, and these operations may be executed in sequence or in parallel. It should be noted that the descriptions of "first", "second", etc. in this article are used to distinguish different messages, devices, modules, etc., and do not represent a sequential order, nor do they limit "first" and "second" to different types.

[0075] Figure 4 This is a schematic diagram of an electronic device structure provided by an exemplary embodiment of the present application. Figure 3 As shown, the electronic device includes: a memory 44 and a processor 45.

[0076] The memory 44 is used to store computer programs and can be configured to store various other data to support operations on the electronic device. Examples of such data include instructions for any application or method operating on the electronic device, the first data to be encrypted, the first curve point, and class functions.

[0077] The memory 44 may be implemented by any type of volatile or non-volatile memory device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk, or optical disk.

[0078] The processor 45 is coupled to the memory 44 and is configured to execute a computer program in the memory 44 to: establish a lifting mapping relationship between a twisted Edwards curve on a finite field and a twisted Edwards curve on a residue class ring, wherein the lifting mapping relationship is that, in an affine coordinate system, a lifting operation based on a p-adic number is performed so that the mapping maintains an adjustment amount of the ordinate as h1p; wherein h1 represents an adjustment coefficient of the ordinate, and the adjustment coefficient is associated with the coordinates of a point on the twisted Edwards curve on the finite field to be mapped to the twisted Edwards curve on the residue class ring; p represents a prime number; based on the formula The key determines a first curve point on the twisted Edwards curve on a finite field, and lifts and maps the first curve point to a second curve point on the twisted Edwards curve on the residue class ring based on a lifting mapping relationship; extracts algebraic features from the second curve point through a mapping function, and performs inverse transformation calculation on the algebraic features to obtain a class function of the second curve point; uses the class function of the second curve point to encrypt the first data to be encrypted to obtain a first sub-ciphertext; the first sub-ciphertext and the second sub-ciphertext constitute a first ciphertext; the second sub-ciphertext is generated according to the parameters of the twisted Edwards curve on the finite field.

[0079] In an optional embodiment, the processor 45 establishes a lifting mapping relationship between the twisted Edwards curve on the finite field and the twisted Edwards curve on the residual class ring, including: randomly selecting any curve point on the twisted Edwards curve on the residual class ring as the third curve point (x, y), and randomly selecting any curve point on the twisted Edwards curve on the finite field as the fourth curve point (x′, y′); using x=x′ as a solution condition and mapping the fourth curve point (x′, y′) to the third curve point (x, y) as a goal to solve the mapping equation, so as to obtain an adjustment coefficient for mapping the ordinate of the fourth curve point to the ordinate of the third curve point The expression is related to the coordinates of the fourth curve point (x′, y′); according to the adjustment coefficient The expression and prime number p are used to calculate the adjustment amount of the vertical coordinate of the fourth curve point as h1p; based on the adjustment amount h1p, the coordinates of the third curve point are re-expressed as (x′, y′) using the fourth curve point (x′, y′ ) to obtain the lifting mapping relationship, which is expressed as (x′, y′)→(x′, y′ ).

[0080] In an optional embodiment, the processor 45 solves the mapping equation with x=x′ as the solution condition and with the fourth curve point (x′, y′) mapped to the third curve point (x, y) as the goal, to obtain the adjustment coefficient for mapping the ordinate of the fourth curve point to the ordinate of the third curve point. The expression includes: constructing the mapping equation f(x, y) from the twisted Edwards curve on the finite field to the twisted Edwards curve on the residual class ring according to the third curve point (x, y) = ; where a and d represent the parameters of the twisted Edwards curve on the residue class ring; the ordinate y of the third curve point is expanded by a p-adic number according to the prime number p to obtain the expression of the ordinate y= ;in, represents the constant term of the ordinate y modulo p, and h2 represents the constant term of the ordinate y modulo p 3 The quadratic term coefficient when , Represents a higher order power term of p; with x=x′ as the solution condition, x′, y= Substitute the mapping equation and solve it with the square of the prime number p to obtain the expression of the adjustment coefficient of the vertical coordinate: .

[0081] In an optional embodiment, the processor 45 takes x=x′ as the solution condition and converts x′, y= Substitute the mapping equation and solve it with the square of the prime number p to obtain the expression of the adjustment coefficient of the vertical coordinate: , including: taking x=x′ as the solution condition, and changing x′, y= Substitute the mapping equation as the first equation to be solved; solve the first equation to be solved with the first equation to be solved being equal to 0 as the solution condition to obtain the constant term h0; substitute the constant term h0 into the first equation to be solved to obtain the second equation to be solved; solve the second equation to be solved with the second equation to be solved being congruent with 0 in the case of a modular operation of the square of the prime number p as the solution condition to obtain the expression of the adjustment coefficient of the ordinate: .

[0082] In an optional embodiment, the processor 45 determines the fifth curve point on the twisted Edwards curve on the finite field based on the second data to be encrypted, and lifts and maps the fifth curve point to the sixth curve point on the twisted Edwards curve on the residue class ring based on the lifting mapping relationship; extracts the algebraic feature from the sixth curve point through the mapping function, and performs inverse transformation calculation on the algebraic feature to obtain the class function of the sixth curve point; uses the class function of the sixth curve point to encrypt the second data to be encrypted to obtain a third sub-ciphertext; the third sub-ciphertext and the fourth sub-ciphertext constitute the second ciphertext; the fourth sub-ciphertext is generated according to the parameters of the twisted Edwards curve on the finite field; the first ciphertext and the second ciphertext are added to obtain a third ciphertext; the third ciphertext is sent to the decryption party for the decryption party to decrypt the third ciphertext to obtain the third data to be encrypted; wherein, the third data to be encrypted is the sum of the first data to be encrypted and the second data to be encrypted.

[0083] In an optional embodiment, the processor 45 obtains a first ciphertext and a second ciphertext; the first ciphertext and the second ciphertext are encrypted using any data encryption method; the first ciphertext and the second ciphertext are added to obtain a third ciphertext; the third ciphertext is sent to a decryption party so that the decryption party decrypts the third ciphertext to obtain decrypted data, which is the sum of the first data to be encrypted and the second data to be encrypted.

[0084] In an optional embodiment, the processor 45 obtains a first ciphertext; the first ciphertext is obtained by encrypting the first data to be encrypted using any data encryption method; the first ciphertext includes a first sub-ciphertext and a second sub-ciphertext; the second sub-ciphertext is generated based on the parameters of the twisted Edwards curve on the finite field; the first decryption curve point of the twisted Edwards curve on the finite field is calculated using the private key and the second sub-ciphertext; based on the lifting mapping relationship between the twisted Edwards curve on the finite field and the twisted Edwards curve on the residual class ring, the first decryption curve point is lifted and mapped to the second decryption curve point on the twisted Edwards curve on the residual class ring; the algebraic feature is extracted from the second decryption curve point by the mapping function, and the algebraic feature is inversely transformed to obtain the class function of the second decryption curve point; the first sub-ciphertext is decrypted using the class function of the second decryption curve point to obtain the first data to be encrypted.

[0085] Further, if Figure 4 As shown, the electronic device also includes: a communication component 46, a display 47, a power component 48, an audio component 49 and other components. Figure 4 Only some components are shown schematically, which does not mean that the electronic device only includes Figure 4 Components shown.

[0086] Accordingly, an embodiment of the present application further provides a computer-readable storage medium storing a computer program, which, when executed, can implement the steps that can be performed by the electronic device in the above method embodiment.

[0087] above Figure 4 The communication component is configured to facilitate wired or wireless communication between the device where the communication component is located and other devices. The device where the communication component is located can access a wireless network based on a communication standard, such as WiFi, 2G, 3G, 4G / LTE, 5G and other mobile communication networks, or a combination thereof. In an exemplary embodiment, the communication component receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component also includes a near field communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented based on radio frequency identification (RFID) technology, infrared data association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology and other technologies.

[0088] above Figure 4 The display includes a screen, which may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touch screen to receive input signals from a user. The touch panel includes one or more touch sensors to sense touches, slides, and gestures on the touch panel. The touch sensors may not only sense the boundaries of a touch or slide action, but also detect the duration and pressure associated with the touch or slide action.

[0089] above Figure 4 The power supply component in a device provides power to various components of the device in which the power supply component is located. The power supply component may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to the device in which the power supply component is located.

[0090] above Figure 4 The audio component in the device may be configured to output and / or input audio signals. For example, the audio component includes a microphone (MIC), which is configured to receive external audio signals when the device where the audio component is located is in an operating mode, such as a call mode, a recording mode, and a voice recognition mode. The received audio signal may be further stored in a memory or sent via a communication component. In some embodiments, the audio component further includes a speaker for outputting audio signals.

[0091] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0092] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0093] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0094] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0095] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.

[0096] Memory may include non-permanent storage in a computer-readable medium, in the form of random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.

[0097] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can be implemented using any method or technology for information storage. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change RAM (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media, such as modulated data signals and carrier waves.

[0098] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.

[0099] The foregoing is merely an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included within the scope of the claims of the present application.

Claims

1. A data encryption method, characterized in that: include: Establishing a lifting mapping relationship between a twisted Edwards curve on a finite field and a twisted Edwards curve on a residue class ring, wherein the lifting mapping relationship is such that, in an affine coordinate system, the mapping maintains an adjustment amount of the ordinate by h1p through a lifting operation based on a p-adic number; wherein h1 represents an adjustment coefficient of the ordinate, and the adjustment coefficient is associated with the coordinates of a point on the twisted Edwards curve on the finite field to be mapped to the twisted Edwards curve on the residue class ring; and p represents a prime number; Determine a first curve point on the twisted Edwards curve over the finite field based on the public key, and perform lifting mapping on the first curve point to a second curve point on the twisted Edwards curve over the residue class ring based on the lifting mapping relationship; Extracting algebraic features from the second curve point by using a mapping function, and performing an inverse transformation calculation on the algebraic features to obtain a class function of the second curve point; The first data to be encrypted is encrypted using the class function of the second curve point to obtain a first sub-ciphertext; the first sub-ciphertext and the second sub-ciphertext constitute a first ciphertext; the second sub-ciphertext is generated according to the parameters of the twisted Edwards curve on the finite field.

2. The method according to claim 1, characterized in that The step of establishing a lifting mapping relationship between a twisted Edwards curve on a finite field and a twisted Edwards curve on a residual class ring includes: Randomly select any curve point on the twisted Edwards curve on the residual class ring as the third curve point (x, y), and randomly select any curve point on the twisted Edwards curve on the finite field as the fourth curve point (x′, y′); With x=x′ as the solution condition, the mapping equation is solved with the goal of mapping the fourth curve point (x′, y′) to the third curve point (x, y) to obtain the adjustment coefficient for mapping the ordinate of the fourth curve point to the ordinate of the third curve point. An expression for , which is related to the coordinates of the fourth curve point (x′, y′); According to the adjustment coefficient The expression and prime number p are used to calculate the adjustment amount of the vertical coordinate of the fourth curve point as h1p; Based on the adjustment amount h1p, the coordinates of the third curve point are re-expressed as (x′, y′) using the fourth curve point (x′, y′). ) to obtain the lifting mapping relationship, which is expressed as (x′, y′)→(x′, y′ ).

3. The method according to claim 2, characterized in that With x=x′ as the solution condition, the mapping equation is solved with the goal of mapping the fourth curve point (x′, y′) to the third curve point (x, y) to obtain the adjustment coefficient for mapping the ordinate of the fourth curve point to the ordinate of the third curve point. Expressions include: According to the third curve point (x, y), a mapping equation f(x, y)= is constructed from the twisted Edwards curve on the finite field to the twisted Edwards curve on the residual class ring. ; Wherein, a and d represent the parameters of the twisted Edwards curve on the residual class ring; The ordinate y of the third curve point is expanded by P-number according to the prime number p, so as to obtain the expression of the ordinate y as y= ;in, represents the constant term of the ordinate y modulo p, and h2 represents the constant term of the ordinate y modulo p 3 The quadratic term coefficient when , represents a higher-order power term of p; Take x=x′ as the solution condition, and replace x′, y= Substitute the mapping equation and solve the mapping equation after substitution with 0 in the case of a modulo operation of the square of the prime number p to obtain the expression of the adjustment coefficient of the ordinate: .

4. The method according to claim 3, characterized in that Take x=x′ as the solution condition, and replace x′, y= Substitute the mapping equation and solve the mapping equation after substitution with 0 in the case of a modulo operation of the square of the prime number p to obtain the expression of the adjustment coefficient of the ordinate: ,include: Take x=x′ as the solution condition, and replace x′, y= Substitute the mapping equation as the first equation to be solved; Solving the first equation to be solved with the condition that the first equation to be solved is equal to 0 to obtain a constant term h0; Substituting the constant term h0 into the first equation to be solved to obtain a second equation to be solved, and using the second equation to be solved being congruent to 0 in a modular operation of the square of the prime number p as a solution condition, solving the second equation to be solved, and obtaining the expression of the adjustment coefficient of the ordinate as follows: .

5. The method according to claim 1, wherein Also includes: Determine a fifth curve point on the twisted Edwards curve on the finite field based on the second to-be-encrypted data, and perform lifting mapping on the fifth curve point to obtain a sixth curve point on the twisted Edwards curve on the residue class ring based on the lifting mapping relationship; Extracting algebraic features from the sixth curve point by a mapping function, and performing inverse element transformation calculation on the algebraic features to obtain a class function of the sixth curve point; Encrypting the second data to be encrypted using the class function of the sixth curve point to obtain a third sub-ciphertext; the third sub-ciphertext and the fourth sub-ciphertext constitute a second ciphertext; the fourth sub-ciphertext is generated according to the parameters of the twisted Edwards curve over the finite field; Adding the first ciphertext and the second ciphertext to obtain a third ciphertext; The third ciphertext is sent to a decryption party so that the decryption party decrypts the third ciphertext to obtain third data to be encrypted; wherein the third data to be encrypted is the sum of the first data to be encrypted and the second data to be encrypted.

6. A data decryption method, characterized in that: include: Obtain a first ciphertext and a second ciphertext; the first ciphertext and the second ciphertext are encrypted using the method according to any one of claims 1 to 4; Adding the first ciphertext and the second ciphertext to obtain a third ciphertext; The third ciphertext is sent to a decryption party so that the decryption party decrypts the third ciphertext to obtain decrypted data, where the decrypted data is the sum of the first data to be encrypted and the second data to be encrypted.

7. A data decryption method, characterized in that: include: Obtain a first ciphertext; the first ciphertext is obtained by encrypting the first data to be encrypted using the method according to any one of claims 1 to 4; the first ciphertext includes a first sub-ciphertext and a second sub-ciphertext; the second sub-ciphertext is generated based on parameters of a twisted Edwards curve over a finite field; Obtaining a first decryption curve point of the twisted Edwards curve on the finite field by calculating using the private key and the second sub-ciphertext; Based on a lifting mapping relationship between a twisted Edwards curve on a finite field and a twisted Edwards curve on a residue class ring, lifting and mapping the first decryption curve point to a second decryption curve point on the twisted Edwards curve on the residue class ring; Extracting algebraic features from the second decrypted curve point using a mapping function, and performing an inverse transformation calculation on the algebraic features to obtain a class function of the second decrypted curve point; The first sub-ciphertext is decrypted using the class function of the second decryption curve point to obtain the first data to be encrypted.

8. An electronic device, characterized in that: include: A processor and a memory, wherein the memory is used to store a computer program, and when the computer program is executed by the processor, the processor is enabled to implement the steps in the method according to any one of claims 1 to 7.

9. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the processor is enabled to implement the steps of the method according to any one of claims 1 to 7.

10. A computer program product, characterized in that The method comprises a computer program / instruction, which, when executed by a processor, enables the processor to implement the steps of the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Data encryption method, data processing method, data decryption method and electronic equipment

    CN113254985A

  • Data encryption method and data decryption method

    CN115834185A

  • Apparatus and method for generating public key and generating and verifying signature

    CN120226006A

  • Open key ciphering device, open key ciphering and deciphering device, and deciphering program recording medium

    JP1999174955A

  • Devices and processes for generating public keys and for generating and verifying signatures

    WO2024100108A1