Data processing method and related device

By splitting the encrypted data and storing the decryption keys on multiple devices, the security issues of user data during hosting and recovery are solved, and the secure recovery and efficient decryption of data are achieved.

WO2025148331A1PCT designated stage expired Publication Date: 2025-07-17HUAWEI TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/114084
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-08
Filing Date
2024-08-23
Publication Date
2025-07-17

AI Technical Summary

Technical Problem

During the process of user data hosting and recovery, the prior art has problems such as user privacy data leakage and inability to decrypt and recover, especially when the terminal device is damaged or lost, the key cannot be restored.

Method used

By splitting the encrypted data into the first encrypted data and the second encrypted data, and storing the N first private keys of the decryption key in N different second devices, the target device cooperates with these devices to decrypt, achieving separation of powers, ensuring that the target data can only be restored when the threshold number is reached.

Benefits of technology

Decrypting the target data without sending the second encrypted data to the second device is achieved, ensuring the security and resilience of the data, and improving the efficiency and success rate of the decryption process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024114084_17072025_PF_FP_ABST
    Figure CN2024114084_17072025_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the embodiments of the present application are a data processing method and a related device, which are used for improving the security of a secret in the process of secret hosting and recovery. The method comprises: acquiring encrypted data stored in a first device, wherein the encrypted data comprises first encrypted data and second encrypted data, the second encrypted data is encrypted data corresponding to target data, a decryption key for the encrypted data comprises N first private keys, the N first private keys are different, the N first private keys are respectively stored in N second devices, the first device and the N second devices are different, and N is an integer greater than or equal to 1; sending the first encrypted data to M second devices among the N second devices; acquiring intermediate data from the M second devices, wherein intermediate data from each second device is obtained on the basis of the first encrypted data and a first private key that is stored in the second device; and obtaining the target data on the basis of M pieces of intermediate data and the second encrypted data.
Need to check novelty before this filing date? Find Prior Art

Description

Data processing method and related equipment

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on January 8, 2024, with application number 202410035794.9 and application name “Data Processing Methods and Related Equipment”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of data security technology, and in particular to a data processing method and related equipment. Background Art

[0003] By uploading user data from a terminal device to the cloud for backup, users can reduce the storage space occupied by user data on the terminal device, synchronize user data across devices, and restore lost user data from the cloud if it is lost. To protect user privacy, user data is stored in the cloud with end-to-end encryption. End-to-end encryption means that user data is encrypted and decrypted on the user's terminal device, and the key is held only by the user's device. User data is transmitted between the terminal device and the cloud in ciphertext, and stored in the cloud in ciphertext. This ensures that user data is not leaked when synchronized and backed up via the cloud.

[0004] The keys used to encrypt and decrypt user data can be stored on the user's terminal device. As long as the keys cannot be stolen by anyone or any device other than the terminal device, the security of the encrypted user data in the cloud can be guaranteed. However, if the terminal device is damaged or lost, the data in the cloud cannot be decrypted or restored. If the keys are fully entrusted to a third party, there is a risk of user data being leaked.

[0005] Summary of the Invention

[0006] This application provides a data processing method and related equipment to solve the security issues of users' private data during the hosting and recovery process.

[0007] A first aspect provides a data processing method. This method can be implemented by a target device corresponding to a target user. The target device can be: The method includes: the target device obtaining encrypted data stored on a first device, the encrypted data including first encrypted data and second encrypted data. The target device then sends the first encrypted data to M of N second devices, so that each of the M second devices processes the first encrypted data using a stored first private key to obtain intermediate data, and returns the intermediate data to the target device. After obtaining the intermediate data from the M second devices, the target device obtains target data based on the M intermediate data and the second encrypted data. The second encrypted data is encrypted data corresponding to the target data, and the decryption key for the encrypted data includes N first private keys, each of the N first private keys being different and stored in N second devices. One of the N second devices stores one of the N first private keys, and the first device and the N second devices are different devices. The intermediate data for each second device is obtained based on the first encrypted data and the first private key stored on the second device. N is an integer greater than or equal to 1. M is an integer greater than or equal to 1. M is an integer greater than or equal to 1, and M is less than or equal to N.

[0008] By storing the encrypted data corresponding to the target data on a first device and the first private key used to decrypt the encrypted data on N second devices, the second device and the N second devices belong to different security domains, thereby achieving separation of powers between the first device and the N second devices. That is, the first device does not access the decryption key, and the second device does not access the ciphertext corresponding to the target data. This ensures that neither the first device nor the N second devices can obtain the target data, and ensures the security of the target data during the hosting and decryption process. The encrypted data can be split into first encrypted data and second encrypted data. The first encrypted data can be processed by the first private key to obtain intermediate data, which is then used to decrypt the second encrypted data. Therefore, when the target data in plaintext needs to be obtained, the second encrypted data can be decrypted to obtain the target data without sending the second encrypted data to the second device. This ensures that the target data can be recovered and that the target data is secure.

[0009] In one possible implementation, N is an integer greater than or equal to 3; M is an integer greater than T and less than or equal to N. T is an integer less than or equal to M and greater than 2, indicating the threshold number of first private keys required to decrypt the encrypted data. Thus, when the encrypted data needs to be restored to target data, all N second devices do not need to participate in the recovery of the target data, ensuring the resilience and efficiency of target data recovery.

[0010] In one possible implementation, threshold recovery of encrypted data can be achieved by splitting the target data. The target data corresponds to N target data shards, and the N target data shards are obtained by splitting the target data in a secret sharing manner. The encrypted data includes N encrypted data shards corresponding to the N target data shards. One encrypted data shard is obtained by encrypting one target data shard using a first public key corresponding to a first private key stored on a second device. Each encrypted data shard includes one corresponding first encrypted data and one second encrypted data. Sending the first encrypted data to M second devices includes: sending the corresponding first encrypted data to each of the M second devices respectively. Thus, when recovering the target data, the first encrypted data in the encrypted data shard can be processed by the M second devices, so that based on the intermediate data obtained by the M second devices, the target device can restore the M encrypted data shards to M target data shards, and further merge the M target data shards to obtain the target data. During the decryption of encrypted data, the second device does not contact the second encrypted data, which can ensure that the target data will not be leaked to the second device. In addition, there is no need for all N second devices to participate in the decryption process, which can improve the efficiency of the decryption process and the success rate of recovering the target data.

[0011] In one possible implementation, obtaining target data based on M intermediate data and second encrypted data includes: obtaining M target data shards based on the M intermediate data and the corresponding M second encrypted data. The M target data shards are data shards among the N target data shards. Then, the target data is obtained based on the M target data shards. Because the N target data shards are split based on secret sharing, when M is greater than or equal to T, the target data can be reconstructed based on the M target data shards. Therefore, the process of recovering the target data does not require the participation of all N second devices, which can improve the success rate and efficiency of target data recovery.

[0012] In one possible implementation, before obtaining the encrypted data stored in the first device, the method further includes: receiving the first public keys corresponding to N second devices, wherein the first public keys corresponding to the N second devices are different. The first public keys corresponding to the N second devices are used to encrypt N target data slices respectively to obtain N encrypted data slices, and the first public key corresponding to one second device is used to encrypt one target data slice. The N encrypted data slices are sent to the first device so that the first device stores the N encrypted data slices. The target data is encrypted using the key provided by the second device, and the encrypted data is stored in the first device. This can achieve isolation of the encrypted data and the key on devices other than the target device, prevent the target data from being leaked to non-target users, and ensure the security of the target data.

[0013] In one possible implementation, threshold recovery of target data can be achieved by splitting the private key. The N first private keys are N private key shards corresponding to the target private key, the N private key shards are obtained by splitting the target private key by secret sharing, the encrypted data is obtained by encrypting the target data with the public key corresponding to the target private key, and the target data is obtained based on the M intermediate data and the second encrypted data, including: obtaining the target intermediate data based on the M intermediate data; obtaining the target data based on the target intermediate data and the second encrypted data. The target private key is split by secret sharing, and the N first private keys are respectively stored on N second devices. In the process of recovering the target data, when the number of second devices participating in recovering the target data is greater than or equal to T, the recovery of the target data can be achieved, thereby improving the resilience of the target data recovery.

[0014] In one possible implementation, before sending the first encrypted data to M of the N second devices, the method includes: performing identity authentication with the M second devices; and after the identity authentication is successful, performing the step of sending the first encrypted data to the M of the N second devices. Sending the first encrypted data to the second devices after the identity authentication is successful can ensure that the target data cannot be obtained by non-target users, thereby ensuring the security of the target data.

[0015] In one possible implementation, performing identity authentication with the M second devices includes performing identity authentication with each of the M second devices via video. Authentication via video eliminates the need for authentication with a third-party authentication agency while ensuring target data security, simplifies the target data recovery process, and improves decryption efficiency.

[0016] In one possible implementation, obtaining intermediate data from M second devices includes: receiving encrypted intermediate data from the M second devices, where the encrypted intermediate data is obtained based on a second public key and the intermediate data, and the intermediate data is in plaintext; and obtaining the intermediate data based on a second private key and the encrypted intermediate data, where the second public key and the second private key form a public-private key pair. Because the intermediate data can be used to recover target data, if both the intermediate data and the encrypted data are leaked, there is a risk of target data leakage. Therefore, encrypting the intermediate data to obtain the encrypted intermediate data and then transmitting the encrypted intermediate data can prevent intermediate data leakage and further ensure the security of the target data.

[0017] The second aspect provides a data processing method. This aspect can be executed by a target device. The method includes: obtaining first public keys corresponding to N second devices; encrypting target data using the first public keys corresponding to the N second devices to obtain encrypted data, the encrypted data including first encrypted data and second encrypted data, the second encrypted data being the encrypted data corresponding to the target data, the decryption key of the encrypted data including N first private keys, the N first private keys being different, the N first private keys being respectively stored in N second devices, one of the N second devices storing one of the N first private keys, the N first private keys being used to process the first encrypted data to obtain intermediate data, the intermediate data being used to process the second encrypted data to obtain the target data; N being an integer greater than or equal to 1; and sending the encrypted data to the first device, the first device and the N second devices being different devices.

[0018] In one possible implementation, N is an integer greater than or equal to 3; M is an integer greater than T and less than or equal to N; T is an integer less than or equal to M and greater than 2, and T indicates a threshold number of first private keys required to decrypt encrypted data.

[0019] In one possible implementation, the first public keys corresponding to N second devices are different, the target data corresponds to N target data shards, the N target data shards are obtained by splitting the target data through secret sharing, the encrypted data includes N encrypted data shards corresponding to the N target data shards, and one encrypted data shard is obtained by encrypting one target data shard with the first public key corresponding to the first private key stored in a second device, and each encrypted data shard includes one corresponding first encrypted data and one second encrypted data.

[0020] In one possible implementation, the first public keys corresponding to the N second devices are the same, the N first private keys are N private key shards corresponding to the target private key, the N private key shards are obtained by splitting the target private key through secret sharing, and the target private key and the first public key are a public-private key pair.

[0021] A third aspect provides a data processing method. The method includes: a target second device receives first encrypted data, the first encrypted data being part of the encrypted data, the encrypted data including first encrypted data and second encrypted data, the second encrypted data being the encrypted data corresponding to the target data, the decryption key for the encrypted data including N first private keys, the N first private keys being different, the N first private keys being respectively stored in N second devices, one of the N second devices storing one of the N first private keys, the first device and the N second devices being different devices, the target second device being one of the N second devices, and N being an integer greater than or equal to 1. The target second device sends intermediate data, the intermediate data being obtained based on the first encrypted data and the first private key stored in the target second device, the intermediate data being used to restore the second encrypted data to the target data.

[0022] In a possible implementation, the method further includes: the target second device encrypting the intermediate data in plain text to obtain encrypted intermediate data. The target second device sending the intermediate data includes: the target second device sending the encrypted intermediate data.

[0023] A fourth aspect provides an apparatus. This apparatus has the function of implementing the behaviors described in the method examples of the first or second aspects. The beneficial effects can be found in the description of the first or second aspects and are not further elaborated here. This apparatus may be the target device described in the first or second aspects, or it may be a device capable of supporting the target device described in the first or second aspects to implement the functions required by the method provided in the first aspect, such as a chip or chip system.

[0024] In one possible design, the apparatus includes corresponding means or modules for performing the method of the first aspect or the second aspect. For example, the apparatus includes a processing unit (sometimes also referred to as a processing module) and a transceiver unit (sometimes also referred to as a transceiver module). These units (modules) can perform the corresponding functions in the above-mentioned method examples of the first aspect or the second aspect. For details, please refer to the detailed description in the method examples, which will not be repeated here.

[0025] A fifth aspect provides an apparatus. The apparatus has the functionality to implement the behaviors described in the method example of the third aspect. The apparatus may be the target second device described in the third aspect, or it may be a device, such as a chip or chip system, that supports the target device described in the third aspect in implementing the functionality required by the method described in the third aspect.

[0026] In one possible design, the apparatus includes corresponding means or modules for performing the method of the third aspect. For example, the apparatus includes a processing unit (sometimes also referred to as a processing module) and a transceiver unit (sometimes also referred to as a transceiver module). These units (modules) can perform the corresponding functions in the above-mentioned method example of the third aspect. For details, please refer to the detailed description in the method example, which is not repeated here.

[0027] A sixth aspect provides a device. The device includes a processor and a memory. The processor is coupled to the memory, and the processor is configured to execute, based on instructions stored in the memory, the data processing method of the first aspect or any possible implementation of the first aspect, the data processing method of the second aspect or any possible implementation of the second aspect, or the data processing method of the third aspect or any possible implementation of the third aspect.

[0028] In a seventh aspect, an embodiment of the present application provides a chip system, which includes a processor and may also include a memory and / or a communication interface, for implementing the method described in the first aspect, the second aspect, or the third aspect. In one possible implementation, the chip system also includes a memory for storing program instructions and / or data. The chip system can be composed of a chip, or it can include a chip and other discrete devices.

[0029] In an eighth aspect, an embodiment of the present application provides a data processing system, the data processing system comprising a target device for executing the method described in the first aspect and / or the second aspect and a target second device for executing the method described in the third aspect. The communication system may also include a first device.

[0030] In a ninth aspect, the present application provides a computer-readable storage medium storing a computer program. When the computer program is executed, the method in any one of the first to third aspects described above is implemented.

[0031] In a tenth aspect, a computer program product is provided, comprising: a computer program code, wherein when the computer program code is run, the method in any one of the first to third aspects is executed.

[0032] The beneficial effects of the second to tenth aspects and their implementations can refer to the description of the beneficial effects of the first aspect or its implementations. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] FIG1 is a schematic diagram of the architecture of a data processing system provided by the present application;

[0034] FIG2 is a schematic diagram of a scenario of identity authentication through video provided by this application;

[0035] FIG3 is a flow chart of a data processing method provided by the present application;

[0036] FIG4 is a flow chart of another data processing method provided by the present application;

[0037] FIG5 is a flow chart of another data processing method provided by the present application;

[0038] FIG6 is a flow chart of another data processing method provided by the present application;

[0039] FIG7 is a schematic structural diagram of a device provided by the present application;

[0040] FIG8 is a schematic structural diagram of a device provided in this application. DETAILED DESCRIPTION

[0041] The following will describe the technical solutions in the embodiments of this application in conjunction with the accompanying drawings. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.

[0042] In the description of this application, unless otherwise specified, " / " indicates that the objects associated before and after are in an "or" relationship. For example, A / B can represent A or B. "And / or" in this application is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. In addition, in the description of this application, unless otherwise specified, "multiple" refers to two or more than two. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, and c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple.

[0043] In addition, for the sake of clarity in describing the technical solutions of the embodiments of the present application, in the embodiments of the present application, words such as "first" and "second" are used to distinguish between identical or similar items with substantially identical functions and effects. Those skilled in the art will understand that words such as "first" and "second" do not limit the quantity and order of execution, and words such as "first" and "second" do not necessarily limit differences. At the same time, in the embodiments of the present application, words such as "exemplarily" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or technical solution described as "exemplarily" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or advantageous than other embodiments or design solutions. Specifically, the use of words such as "exemplarily" or "for example" is intended to present the relevant probabilities in a concrete manner for easy understanding.

[0044] The following explains the relevant algorithms involved in the embodiments of the present application to facilitate understanding by those skilled in the art.

[0045] (1) Ciphertext can be split and encrypted

[0046] Ciphertext splitting encryption scheme belongs to public key encryption. Its ciphertext consists of two parts: the message-associated component and the key-applicable component. Its encryption and decryption algorithms are expressed in the following grammatical form:

[0047] Encryption: (Cm, Ck): = ENC(pk, m), where Cm is the message-associated part and Ck is the key-applicable part.

[0048] Decryption: DEC(sk,(Cm,Ck)):

[0049] InterM:=KeyAppl(sk,Ck)

[0050] m:=Recover(InterM, Cm)

[0051] Specifically, the decryption algorithm can be divided into two steps: the first step is that the private key sk is applied to the Ck part of the ciphertext, represented by KeyAppl(sk,Ck), to generate the intermediate data InterM; the second step is that InterM and the Cm part of the ciphertext are mixed, represented by Recover(InterM,Cm), to obtain the plaintext.

[0052] All current public-key encryption schemes can be used as ciphertext splitting encryption schemes. The following are three specific ciphertext splitting encryption algorithms. It should be understood that the following three ciphertext splitting encryption algorithms are only examples, and the ciphertext splitting encryption algorithms described in this application may also include other ciphertext splitting encryption algorithms.

[0053] 1. Elgamal encryption: In the Elgamal encryption scheme, a user's public and private key pair is (y = g sk , sk∈Zp), where g is a generator of a multiplicative group of prime order p. The ciphertext generated by encrypting a message m is C1=g r ,C2=my r ,r∈R Zp. Accordingly, the decryption process is In fact, the scheme itself already satisfies the ciphertext splitting requirement: Cm=C2, Ck=C1;

[0054] 2. RSA encryption: Let n = pq, where p and q are large prime numbers. The user's public and private key pair is (e, d), where ed = 1(modφ(n)), where φ is Euler's totient function. The ciphertext generated by encrypting a message m is C = encode(m). e (mod n), and decryption is m = decode(Cd(mod n)). Obviously, RSA ciphertext has only one element, so it is not a ciphertext-split encryption. However, we can use a hybrid encryption mode to transform it into a ciphertext-split encryption as follows:

[0055] Encryption: Select a random symmetric key k, calculate Cm = E(k,m), and then calculate Ck = encode(k) e (mod n), where E(·) is a symmetric encryption algorithm.

[0056] Decryption: First calculate InterM = k = decode(encode(k) e.d (mod n))=KeyAppl(d,Ck), and then calculate m= Recover(InterM,Cm)=D(k,Cm), where D(·) is the symmetric decryption algorithm.

[0057] 3. Post-quantum encryption: The encryption scheme of post-quantum computing is basically based on lattice. We give the basic form of an encryption scheme based on unstructured lattice. Let A∈Zpk×n be a public matrix, where p is a prime number. The user's public and private keys are (B=sk t .A+e,sk∈Zp k ), where sk∈Zp k , is a vector, e∈χ is the noise, and χ is a suitable noise distribution.

[0058] For a message m∈{0,1} kThe encryption is: select r∈R Zp n ,e1,e2∈χ, calculate C1=A.r+e1,C2=B.r+e2+m.

[0059] Decrypted to: m = Apprx (C2-sk t .C1), where Apprx() is an approximate function.

[0060] Comparing this scheme with Elgamal encryption reveals that it can be considered a noisy version of Elgamal encryption. Therefore, the scheme itself can be easily transformed into a ciphertext-splittable encryption scheme: Cm = C2, Ck = C1; InterM = KeyAppl(sk, Ck) = skt.Ck, + e3, where e3∈χ, m = Recover(InterM, Cm) = Apprx(Cm-InterM). The operations in each step are essentially similar to those in Elgamal encryption, differing only in the addition of noise e3 to KeyAppl().

[0061] (2) Secret Sharing

[0062] Assume t, n are positive integers, t≤n, n is the total number of participants in the secret sharing scheme (note P1,…,P n (n participants), t is the threshold. In the (t,n)-Shamir secret sharing scheme, the dealer splits a secret value into n shares and assigns each share (via a secure channel) to one of the n participants for safekeeping. Any number of participants greater than or equal to t+1 can collaboratively recover the secret value using their shares, while any number of participants less than or equal to t cannot. The Shamir secret sharing scheme operates using the Lagrange interpolation theorem.

[0063] Specifically, the (t,n)-Shamir secret sharing scheme works as follows:

[0064] Assume that q is a prime power, q>n, let F q is a finite field. Assume a0∈F q The secret value to be shared.

[0065] To generate secret shares (Distribute), perform the following operations:

[0066] In F q Select t random elements a1,…,a t , define the polynomial

[0067] Assume that τ1,…,τ n ∈F qis n different non-zero elements known to all n participants, such as the participant's identification information (ID). Calculate s j =f(τ j )mod q, change s j Send to P j , 1≤j≤n.

[0068] Secret recovery (Reconstruct), perform the following operations: any set containing t+1 participants The corresponding tag information is The secret shares held are The recoverable secret value a0 is calculated as follows: in

[0069] Shamir LSSS is an ideal threshold scheme with complete security in the sense of information theory. The correctness and privacy of the scheme are guaranteed by the Lagrange interpolation theorem: for any domain F, any t+1 different elements τ1,…,τ t+1 , and t+1 values ​​s1,…,s t+1 , there exists a unique polynomial f of degree at most t on the field F, satisfying f(τ j )=s j , 1≤j≤t+1.

[0070] (3) Threshold cryptography

[0071] Threshold cryptography addresses this problem by splitting the private key into n (n ≥ 2) shares, each stored locally and on a server. When the private key needs to be used for signing or decryption, t parties (2 ≤ t ≤ n) can collaborate to complete the operation, eliminating the need to reconstruct the private key at any point. The advantage of a threshold key mechanism is that unless an adversary compromises t points, the private key cannot be recovered.

[0072] Threshold cryptography is a distributed version of a public-key encryption or digital signature scheme. It utilizes (t,n)-secret sharing to split a private key into n shares. T+1 holders of these shares can then perform the original cryptographic scheme's functions without recovering the original key. Threshold cryptography is a relatively mature technology. A threshold public-key encryption scheme can be categorized into the following algorithms:

[0073] (PK,(SK1,…,SKn))←DKG(): Distributed Key Generation algorithm, that is, n participants interact and use (t,n)-secret sharing to generate a public key PK and n key shares SKi; each participant holds a key share but cannot obtain information about other key shares.

[0074] C←Enc(PK,m): public key encryption algorithm, same as the original scheme

[0075] m←Dec((SK1,…,SKn),C): Distributed decryption algorithm. ≥t+1 private key holders interact to complete the decryption operation without recovering the original private key. The interactive decryption process does not disclose any information about the individual private key shares.

[0076] Leveraging existing technologies, the aforementioned ciphertext-split Elgamal, ciphertext-split RSA, and ciphertext-split Lattice encryption schemes can all be easily converted into corresponding (t,n)-threshold encryption schemes. It's worth noting that in these (t,n)-threshold encryption schemes, the decryption algorithm can still be divided into the KeyAppl() and Recover() processes. However, each private key share must be applied separately to the KeyAppl() algorithm, generating intermediate values ​​InterMi. The Recover() algorithm then combines these intermediate values ​​InterMi with Cm to calculate the plaintext.

[0077] The following examples illustrate scenarios in which the solution provided by this application can be applied. It is understood that the solution provided by this application can also be applied in other secret hosting and recovery scenarios, which are not listed here one by one.

[0078] In a cloud backup scenario, a user's private data, such as address books, photos, account passwords, etc., can be uploaded to a cloud server for storage. In order to prevent the leakage of the user's private data, the user can use a key to encrypt the private data, and then upload the encrypted private data to the cloud server for storage and backup. The key is generally stored on the user's user device. In situations such as when the user's device is lost or damaged, the key may be lost, and the encrypted private data stored in the cloud server may not be decrypted on other user devices. In order to ensure that the encrypted private data stored in the cloud server can be decrypted on other user devices, the user can entrust the key to a third party for storage. When the user needs to use the key to obtain private data on other user devices, the key can be restored on the other user devices with the assistance of the third party. Based on the solution provided in this application, secure hosting and recovery of keys can be achieved.

[0079] In blockchain scenarios, a user's account consists of an address (public key) and a private key. Users control the digital assets in their account through the use of private keys, which serve as proof of their identity. Transactions can only be confirmed with a signature from the private key. To prevent blockchain private keys from being leaked, stolen, or lost, the solution provided in this application enables secure key custody and recovery.

[0080] As shown in Figure 1, Figure 1 is a schematic diagram of the architecture of a data processing system provided by the present application. The system includes a first device, N second devices and a target device. The target device is used to encrypt the target data to obtain encrypted data corresponding to the target data. The target device is also used to decrypt the encrypted data to obtain the target data. The target data can be a secret that the target user wants to protect and host, such as a password key, a private key, or other keys. The target data can also be other data, such as files, images, videos, or audio. The first device is used to store the encrypted data corresponding to the target data. The N second devices are used to store N first private keys, each second device stores a first private key, and the N first private keys are different. The first device and the N second devices belong to different trust domains, thereby ensuring that the first device and the N second devices will not collude, and can ensure the security of the target data, that is, the target data can only be restored by the user and will not be obtained by other third parties.

[0081] The target user can securely host and recover the target data through the data processing system. The general process for achieving target data hosting and recovery based on the data processing system is as follows: 1.1: The target device obtains the corresponding first public key from N second devices. The target device uses the corresponding first public key obtained from the N second devices to encrypt the target data to obtain encrypted data; 1.2: The target device stores the encrypted data on the first device. The encrypted data is splittable ciphertext, which includes first encrypted data and second encrypted data. The first encrypted data is not obtained by encrypting the target data, while the second encrypted data is obtained by encrypting the target data. The first encrypted data can be processed using the first private key corresponding to the first public key to obtain intermediate data, which can be used to decrypt the second encrypted data. 2.1: When the encrypted data needs to be restored to the target data, the target device obtains the encrypted data from the first device. 2.2: The target device sends the first encrypted data to M of the N second devices. 2.3: Each of the M second devices uses its own stored first private key to process the first encrypted data to obtain corresponding intermediate data, and then sends the processed intermediate data to the target device. 2.4: The target device processes the second encrypted data based on the M intermediate data and restores the target data.

[0082] Specifically, the secure hosting and recovery of target data can include key negotiation, encryption, and decryption phases. The key negotiation and encryption phases are part of the target data hosting process. The decryption phase is part of the target data recovery process. The following describes the collaborative processes of the various devices in the data processing system during the key negotiation, encryption, and decryption phases.

[0083] During the key negotiation phase, the target device interacts with N second devices to obtain the first public keys corresponding to the N second devices. The target device / second device can be a mobile phone, a tablet computer, a computer, a wearable device, a vehicle, a drone, a helicopter, an airplane, a ship, a robot, a robotic arm, a smart home device, etc. The embodiments of the present application do not limit the specific technology and specific device form adopted by the target device and the second device. The target device and the second device can be devices of the same form, such as both being mobile phones or tablet computers, or they can be devices of different forms, such as the target device being a mobile phone and the second device being a computer, which is not limited here.

[0084] The N second devices respectively store their own first public keys. In one implementation, the first public keys corresponding to the N second devices are the same public key. In another implementation, the first public keys corresponding to the N second devices are different public keys, that is, each of the N second devices corresponds to a first public key, and different second devices correspond to different first public keys. The specific implementation of the first public keys corresponding to the N second devices being the same public key and the first public keys corresponding to the N second devices being different public keys will be described in detail below. In this embodiment, the N second devices also respectively store the first private keys corresponding to their own first public keys. The first public key is used to encrypt the target data, and the first private key is used to restore the target data. In this embodiment, the first private keys between the N second devices are different.

[0085] The N second devices are devices of the N auxiliary users selected by the target user to participate in recovering the target data. The target device and the N second devices, for example, run a target application. The target user can select N auxiliary users on the target application running on the target device. In one implementation, the target user can determine the auxiliary user by entering the user information of the auxiliary user on the target application. The user information of the auxiliary user can be the account name, nickname, mobile phone number or user identification (UID) of the auxiliary user, etc. In another implementation, the target user can select N auxiliary users from the friend list displayed on the target application.

[0086] After the target user selects N auxiliary users, the target device may send a request to the second device corresponding to the N auxiliary users selected by the target user. In one implementation, the request is used to ask the auxiliary user whether he agrees to be an auxiliary user of the target user. The request may be a text message, voice, call request or video request, etc., or the request instructs the display of a pop-up window or notification message on the second device, asking through the pop-up notification message whether he agrees to be an auxiliary user of the target user. After the auxiliary user confirms his agreement to be an auxiliary user of the target user through the second device, the second device may send the first public key corresponding to the second device to the target device. The auxiliary user may input an indication of confirming his agreement to be an auxiliary user of the target user to the second device through voice, gestures, clicking a confirmation button displayed on the screen, entering text, etc. If there is a user among the auxiliary users selected by the target user who does not agree to be an auxiliary user of the target user, the second device corresponding to the user may not send the first public key to the target device. In another implementation, the public key can be published publicly without causing the privacy of the auxiliary user to be leaked. The request is used to request the first public key. That is, after the target user selects the auxiliary user, the auxiliary user may not be asked whether he agrees to be the auxiliary user of the target user, but the first public key corresponding to the second device of the auxiliary user may be directly requested, thereby improving the efficiency of obtaining the first public key.

[0087] The number of auxiliary users N can be set by the user or the default value of the target application, and is not limited here. N can be an integer greater than or equal to 1. When N is 1 or 2, the participation of the second devices corresponding to all auxiliary users is required when the encrypted data is subsequently restored to the target data. When N is greater than or equal to 3, the target data can be encrypted using the first public key using a threshold password. When the encrypted data is subsequently restored to the target data, the participation of all N second devices is not required, which can improve the resilience and efficiency of recovering the target data.

[0088] The public-private key pair (first public key and first private key) of the second device can be managed by a target application running on the second device. This eliminates the need for the auxiliary user to manually record the first public key and first private key, ensuring the security of the first private key and reducing the operational difficulty for the auxiliary user. In one possible implementation, the first public key and first private key of the second device are generated by the target application running on the second device. If the first public key of N second devices is the same, the first public key can be determined through negotiation between the N second devices. For example, the N second devices interact and, based on a distributed key generation algorithm (DKG), split the private key corresponding to the first public key into N first private keys (also referred to as N key shares), and distribute the first public key and the corresponding first private keys to the N second devices. The N first private keys are obtained by splitting the target private key corresponding to the first public key using a secret sharing method. Each second device holds one key share but cannot obtain information about the other key shares. Secret sharing methods include, for example, Shamir secret sharing, Feldman secret sharing, Pedersen secret sharing, and verifiable secret sharing (VSS).

[0089] In another possible implementation, the first public key and the first private key of the second device may be obtained from a third-party trusted center, such as a certificate authority (CA) or a registration authority (RA) in a public key infrastructure (PKI).

[0090] To further prevent the target data from being leaked, the first public key and the first private key can be a public-private key pair generated based on a ciphertext-splittable encryption algorithm, such as the aforementioned Elgamal encryption algorithm, RSA encryption algorithm, or post-quantum encryption algorithm. Consequently, the encrypted data obtained by subsequently encrypting the target data using the first public key can be split into a key-applicable portion and a message-associated portion.

[0091] During the encryption phase, the target device uses the first public key to encrypt the target data and obtain the corresponding encrypted data. The target device then sends the encrypted data to the first device, which stores the encrypted data. The first device and the target device are different devices, so that when the target device fails or is lost, the encrypted data can be obtained from the first device, avoiding the loss of encrypted data and ensuring that the target data can be recovered. The first device can be a private device of the target user, such as a personal computer, tablet phone, mobile phone, hard disk, mobile storage device (such as USB flash drive, mobile hard disk, optical disk, etc.), network attached storage (NAS) device, home smart device, etc. The first device can also be a cloud storage device, such as a cloud server, network disk or cloud disk, etc.

[0092] The target device can encrypt the target data in the following ways:

[0093] Encryption method one: the first public keys of the N second devices are different, and the target device splits the target data into N target data slices. In a possible implementation, the target device can use a secret sharing method to split the target data into N target data slices, so that the target data can be restored using any at least T target data slices among the N target data slices. T is the threshold value of the number of target data slices required to restore the target data, that is, at least T target data slices are required to restore the target data, and the target data cannot be restored if the number of target data slices is less than T. T is an integer greater than or equal to 1 and less than or equal to N. The target device then uses the N first public keys to encrypt the N target data slices respectively, that is, one of the N first public keys encrypts one of the N target data slices to obtain encrypted data, and the encrypted data includes N encrypted data slices. Optionally, the target device may split the target data into N target data shards using a secret sharing method, so that when restoring the encrypted data to the target data, the target data can be restored based on at least T of the N target data shards. This allows the target user to still restore the target data even if one of the N auxiliary users changes devices, or is unable to promptly participate in restoring the encrypted data, or refuses to participate in restoring the encrypted data. In another possible implementation, the target device may also split the target data into N target data shards without using a secret sharing method. In this case, all N second devices are required to participate in the target data recovery process.

[0094] Because the first public key is generated by a ciphertext-splittable encryption algorithm, the encrypted data slice obtained by encrypting a target data slice using the first public key includes first encrypted data and second encrypted data. The first encrypted data is the key applicable portion, i.e., this encrypted data does not include the target data. The first encrypted data can be processed using the first private key to generate intermediate data. The second encrypted data is the message-associated portion, i.e., the second encrypted data is generated by encrypting the target data slice. The second encrypted data can be restored to the plaintext target data slice using the intermediate data.

[0095] In the second encryption method, the first public keys of the N second devices are the same, and the target device uses the first public key to encrypt the target data to obtain encrypted data.

[0096] Because the first public key is generated by a ciphertext-splittable encryption algorithm, the encrypted data obtained by encrypting the target data using the first public key includes first encrypted data and second encrypted data. The first encrypted data is the key applicable portion, meaning that this portion of the encrypted data does not include the ciphertext of the target data. The first encrypted data can be processed using the first private key to generate intermediate data. The second encrypted data is the message-associated portion, meaning that the second encrypted data is generated by encrypting the target data. The second encrypted data can be restored to the plaintext target data using the intermediate data.

[0097] After obtaining the encrypted data, the target device sends it to the first device for storage. Alternatively, the target device imports the encrypted data into the first device for storage. Because the target data is encrypted on the target device, the first device only stores the encrypted data and has no access to the key or target data. Furthermore, the second device only provides the first public key and has no access to the target data, ensuring the security of the target data.

[0098] In the decryption stage, that is, when the target user needs to decrypt the encrypted data to restore the target data, the target device obtains the encrypted data stored in the first device, and the target device decrypts it. In one implementation, the first device is a cloud storage device, and the target device obtains the encrypted data stored in the first device, which may be the target device downloading the encrypted data from the cloud storage device. In another implementation, the first device is a private device of the target user, and the encrypted data is obtained from the first device, which may be the target device receiving or importing the encrypted data from the first device through a hardware interface, wired or wireless method, etc. Hardware interfaces include, for example, USB interfaces, serial advanced technology attachment (SATA) interfaces, etc. Wireless interfaces include, for example, wireless local area networks (WLAN), Bluetooth, near link, or near field communication (NFC), etc.

[0099] After the target device obtains the encrypted data, it sends the first encrypted data in the encrypted data to M second devices among the N second devices, and the M second devices obtain intermediate data based on the first encrypted data and the first private key. Then, the M second devices send the intermediate data to the target device, and the target device reconstructs (restores) the target data based on the intermediate data and the second encrypted data. Here, M is an integer less than or equal to N and greater than or equal to T. M can be equal to N, that is, the M second devices can be all second devices among the N second devices. M can also be less than N, that is, the M second devices can be some second devices among the N second devices. M is greater than or equal to the threshold T, thereby ensuring that the target data can be restored.

[0100] The target user can use the target device to select M auxiliary users from N auxiliary users to participate in the recovery of the target data, and then send the corresponding first encrypted data to the second devices corresponding to the M auxiliary users. To prevent the target data from being obtained by non-target users due to factors such as loss of the target device, loss of the first device, or theft of the encrypted data, the target user can be authenticated before the target data is recovered. The target device can interact with the M second devices for identity authentication. After the target user's identity authentication is successful, the target device sends the corresponding first encrypted data to the M second devices.

[0101] In one possible implementation, the target device and the M second devices can authenticate the identity of the target user through video. For example, as shown in FIG2 , the target application provides a video communication function, and the user initiates video connection requests to the M second devices respectively through the video communication function of the target application running on the target device. The auxiliary user accepts the video connection request from the target device through the target application on the second device, and the target device establishes video connections with the M second devices respectively. The video screen of the target device side can be displayed on the M second devices, and the video screen can include the face of the user using the target device. The auxiliary user determines whether the user in the video screen is the target user through the video screen displayed on the second device, so as to authenticate the target user. If the auxiliary user determines that the user in the video screen is the target user, the auxiliary user can confirm that the target user has passed the identity authentication through the second device, and the second device can send a notification of identity authentication success to the target device, so that the target device sends the first encrypted data to the second device. There are many ways for the auxiliary user to confirm that the target user has passed the identity authentication through the second device. In one implementation, the auxiliary user can confirm that the target user has passed the identity authentication through voice, for example, the auxiliary user inputs voice such as "confirm" and "confirm passed identity authentication" to the second device, and the target application running in the second device determines that the target user has passed the identity authentication based on the auxiliary user's voice, and then sends a notification to the target device that the target user has passed the identity authentication. In another implementation, the screen on the second device can display a button for confirming that the identity authentication has passed. For example, the screen of the second device can display an "OK" button, and the auxiliary user can click the button to confirm that the target user has passed the identity authentication. The second device responds to the user's operation of clicking the button and sends a notification to the target device that the target user has passed the identity authentication. On the same day, the auxiliary user can also input instructions to confirm that the target user has passed the identity authentication to the second device through gestures, keyboards, etc., which are not limited here. It can be understood that the user device, second device, number of auxiliary users, and user graphical interface in Figure 2 are only for illustration and should not be understood as limitations on this application.

[0102] It should be noted that, in one implementation, the target device can simultaneously establish a video connection with M second devices, and the M second devices perform identity authentication on the target user in the same time period. In another implementation, the target device may not simultaneously establish a video connection with the M second devices, that is, the target device may establish a video connection with one or more second devices in different time periods, which is not limited here. After the M second devices all confirm that the identity authentication of the target user is successful, the target device can send the first encrypted data to the M second devices respectively to ensure that the target data will not be leaked to non-target users, thereby ensuring the security of the target data. Alternatively, after K second devices out of the M second devices confirm that the identity authentication of the target user is successful, the target device can send the first encrypted data to the M second devices respectively to improve the efficiency of recovering the target data.

[0103] In another possible implementation, the target device and the M second devices may further perform identity authentication of the target user via voice. In yet another possible implementation, the target device and the M second devices may further perform identity authentication via PKI. Identity authentication via PKI is an existing technology and will not be further described here.

[0104] After the target user passes identity authentication, the target device sends the corresponding first encrypted data to the M second devices and receives the intermediate data from the M second devices, so that the target device can restore the target data based on the M intermediate data and the second encrypted data.

[0105] The encrypted data obtained using the above-mentioned encryption method 1 includes N first encrypted data slices, each encrypted using the first public key of a second device. Each encrypted data slice includes corresponding first encrypted data and second encrypted data. The first encrypted data is the applicable portion of the key, and the second encrypted data is the encrypted data corresponding to the target data slice. The target device sends the first encrypted data from each of the M encrypted data slices to the corresponding second device. The second device corresponding to each encrypted data slice is the second device that provided the first public key used to encrypt the target data slice to obtain the encrypted data slice, i.e., the second device that obtained the first public key used to encrypt the encrypted data slice. This second device holds the first private key corresponding to the first public key, enabling the first encrypted data in the encrypted data slice to be accurately processed using the first private key. After receiving the corresponding first encrypted data, the second device decrypts the first encrypted data using its stored first private key to obtain the corresponding intermediate data. The second device then sends the intermediate data to the target device. After receiving the intermediate data from the M second devices, the target device uses the M intermediate data to process the corresponding second encrypted data, obtaining the M target data slices. The target device then reconstructs the M target data slices into target data through Lagrange interpolation calculation.

[0106] The encrypted data obtained by encrypting the target data using the second encryption method described above, that is, the encrypted data obtained by encrypting the target data using a first public key, includes the first encrypted data and the second encrypted data. The first encrypted data is the key applicable part, and the second encrypted data is the encrypted data corresponding to the target data. The target device sends the first encrypted data to M second devices respectively, that is, the first encrypted data sent by the target device to the M second devices are the same. The M second devices respectively store the first private key, and the M first private keys are the M private key fragments in the N private key fragments (key shares) of the private key corresponding to the first public key (referred to as the target private key in this application). Different second devices use the first private key stored by themselves to process the first encrypted data to obtain the corresponding intermediate data. Then the M second devices send the intermediate data obtained by each of them to the target device. After the target device receives the intermediate data of the M second devices, it merges (reconstructs) the M intermediate data to obtain the target intermediate data. Because the M intermediate data are obtained by processing the first encrypted data using the M private key shards, the M intermediate data can be considered as M intermediate data shards of the target intermediate data. The target device can use Lagrange interpolation to reconstruct the M intermediate data into the target intermediate data. The target device then uses the target intermediate data to process the second encrypted data to obtain the target data.

[0107] Thus, without recovering the target private key, the target device recovers the encrypted data to the target data, and in the decryption phase, the second device only processes the key applicable portion (first encrypted data) in the encrypted data, and does not touch the encrypted data related to the target data. Even if N second devices collude, they cannot obtain the target data. The first device does not touch the key, and the second device does not touch the ciphertext corresponding to the target data, which can ensure that the target data will not be leaked to non-target users, ensuring the security of the target data. Moreover, when N is greater than or equal to 3, the target data or target private key is fragmented by secret sharing. In the decryption phase, the target data can be restored when the number of second devices participating in the decryption reaches the threshold value T. It is not necessary for all N second devices to participate in the decryption of the encrypted data, which can improve the success rate and efficiency of recovering the target data and make the recovery of the target data resilient.

[0108] It should be noted that the target devices in the encryption phase and the decryption phase can be different devices. For example, the third device is used in the encryption phase and the fourth device is used in the decryption phase. The third device and the fourth device can be devices of the same type or different types. For example, if the target user loses the third device, or the third device is damaged, or the third device is replaced with a fourth device, etc., the target data in the third device may be lost. The target user can then import or download the encrypted data from the first device to the fourth device, obtain intermediate data through the target application running on the fourth device and interact with the second device, and use the intermediate data to restore the encrypted data to the target data, so that the target data is on the fourth device. Of course, the target device in the encryption phase and the decryption phase can be the same device. For example, if the target data is deleted after the target device is formatted or damaged, the target data can be restored on the target through the solution provided in this application.

[0109] As shown in Figure 3, Figure 3 is a flow chart of a data processing method provided by this application. This embodiment is implemented based on the data processing system shown in Figure 1. In this embodiment, the target data is split into N target data fragments and encrypted separately to ensure the resilience of secret recovery. This embodiment includes the following steps:

[0110] S301: The target device obtains the first public keys of N second devices.

[0111] N second devices each hold a public-private key pair (pk i ,sk i ), where i is an integer greater than or equal to 1 and less than or equal to N. For any second device i among the N second devices, pk i The first public key held by the second device i, sk i The first private key held by the second device i is different from the first public key held by the N second devices, and the first private keys held by the N second devices are also different.

[0112] The N second devices are devices selected by the target device to assist in recovering the encrypted data. The process of the target device interacting with the N second devices to obtain the first public key can be referred to the relevant description of the key negotiation phase in the embodiment corresponding to FIG1 , so it will not be repeated here.

[0113] The public-private key pair (pk i ,sk i) is a public-private key pair generated using a ciphertext-splittable encryption algorithm, such as the Elgamal encryption algorithm, the RSA encryption algorithm, or a post-quantum encryption algorithm. Thus, ciphertext encrypted using the ciphertext-splittable encryption algorithm can be split into a key-applicable portion and a message-associated portion. When subsequently decrypting the ciphertext, the second device can process only the key-applicable portion without obtaining the message-associated portion, thereby ensuring the security of the target data during transmission and decryption.

[0114] S302: The target device uses N first public keys to encrypt N target data slices corresponding to the target data to obtain encrypted data, where the encrypted data includes N encrypted data slices, and each encrypted data slice includes first encrypted data and second encrypted data.

[0115] The target device can use secret sharing to slice the target data s and obtain N target data slices {s i}i=1,2,...,N. Then, the target device uses N first public keys {pk i}i=1,2,...,N for N target data shards {s i}i=1,2,...,N are encrypted, and the encrypted data obtained includes N encrypted data fragments Among them, one of the N first public keys pk i Used to encrypt one target data shard among N target data shards. i , get the corresponding encrypted data fragment That is, the N first public keys correspond one-to-one to the N target data shards.

[0116] Among them, any encrypted data shard among the N encrypted data shards Including first encrypted data and the second encrypted data First encrypted data This is the applicable part of the key, the second encrypted data This is the message association part. The first encrypted data Not sharding the target data i Directly processed, that is, the first encrypted data Does not contain relevant information about the target data shard, and cannot be obtained from only the first encrypted data Get or derive target data shards i . Second encrypted data The target data is sharded i Obtained through processing.

[0117] S303: The target device sends the encrypted data to the first device.

[0118] The target device obtains the encrypted data corresponding to the target data After that, the encrypted data The data is sent to the first device for storage. In this embodiment, the first device and the N second devices are different devices. This ensures isolation between the first device and the N second devices. That is, the first device and the N second devices belong to different trust domains, and the first device and the N second devices cannot collude to recover the target data. For an explanation of the first device and the interaction between the target device and the first device, please refer to the relevant description above and will not be repeated here.

[0119] S304: The first device stores the encrypted data.

[0120] In this embodiment, the first device only stores the encrypted data, but does not store the key or partial key used to decrypt the encrypted data. The second device provides the key used to encrypt and decrypt the target data, but does not store the encrypted data corresponding to the target data. This achieves separation of authority between the first device and the N second devices. If the first device and the N second devices belong to different trust domains, neither the first device nor the N second devices can obtain the target data, thereby ensuring that the target data is not leaked to non-target users and ensuring the security of the target data.

[0121] S305: The target device obtains the encrypted data from the first device.

[0122] It should be noted that the target device in S301-S303 and the target devices in S305, S306, and S309-S310 all refer to the devices used by the target user. The target device in S301-S303 and the target devices in S305, S306, and S309-S310 may be the same device or different devices. For example, if the target device involved in encrypting the target data (the target device in S301-S303) is lost or damaged, and the target user needs to restore the target data on another device, then the target device in S301-S303 and the target device in S305, S306, and S309-S310 are different devices. For example, in the case where the target data stored in the target device involved in encrypting the target data is destroyed, such as the target data stored in the target device is deleted or the storage unit storing the target data is damaged, and the target user expects to restore the target data on the target device, then the target device in S301-S303 is the same device as the target device in S305, S306, S309-S310.

[0123] When the encrypted data needs to be restored to the target data, the target device obtains the encrypted data from the first device. If the first device is a cloud storage device, the target device can download the target data from the first device. If the first device is a private device of the target user, the target device can receive the encrypted data from the first device via wired and / or wireless means.

[0124] S306: The target device sends the corresponding first encrypted data to the M second devices respectively.

[0125] Where M is an integer less than or equal to N and greater than or equal to T. T is the threshold value for the number of target data slices required to restore the target data from the target data slice. When N is 1 or 2, N = M = T. That is, when the number of auxiliary users selected by the target user is less than or equal to 2, all auxiliary users must participate in decrypting the encrypted data. When N is greater than or equal to 3, M can be less than or equal to N. That is, when the number of auxiliary users selected by the target user is greater than or equal to 3, all or some of the auxiliary users can participate in decrypting the encrypted data.

[0126] The M second devices may be devices corresponding to the M auxiliary users selected by the target user from the N second auxiliary users. Alternatively, the M second devices may be devices among the N second devices that are capable of assisting in decrypting the encrypted data. For example, the M second devices may still hold the first private key used to process the first encrypted data. For another example, the target user may send a request to the N second devices via the target device to participate in decrypting the encrypted data, inviting the corresponding auxiliary users to assist in decrypting the encrypted data. The M second devices may be devices of the auxiliary users who agree to participate in decrypting the encrypted data.

[0127] To ensure that the target data is not leaked to non-target users, before the target device sends the corresponding first encrypted data to the M second devices, the target device and the M second devices may interact to authenticate the identity of the user holding the target device. After the user holding the target device passes the identity authentication, i.e., after confirming that the user holding the target device is the target user, the target device sends the corresponding first encrypted data to the M second devices. The target device and the M second devices can authenticate each other through video or PKI. The target user's identity authentication process can be referred to the description of the decryption stage in the relevant content corresponding to Figure 1 above, and will not be repeated here.

[0128] Since the N encrypted data slices in the encrypted data are encrypted by the first public keys provided by the N second devices, the first encrypted data in the encrypted data slices needs to be processed with the corresponding first private key during the decryption of the encrypted data slices. The encrypted data slice corresponding to the second device refers to the encrypted data slice obtained by processing the target data slice based on the first public key provided by the second device, and the first encrypted data corresponding to the second device is the first encrypted data in the encrypted data slice corresponding to the second device. For example, the second device i holds a public-private key pair (pk i ,sk i ), the target device uses the first public key pk of the second device i i Shard the target data i Process and obtain encrypted data fragments The first encrypted data corresponding to the second device i is For encrypted data sharding The first encrypted data in The public-private key pair (pk i ,sk i ) in the private key sk i Only by processing can accurate intermediate data be obtained, thereby ensuring that the target data can be successfully restored. Therefore, the target device sends the corresponding first encrypted data to the second device i. To make the first encrypted data Can be accurately the first private key sk i to be processed.

[0129] The target device sends corresponding first encrypted data to each of the M second devices. In one possible implementation, the N second devices have an order, for example, and the N encrypted data slices in the encrypted data are stored in the order of the corresponding second devices. Thus, the target device can determine the first encrypted data corresponding to the M second devices according to the order of the N second devices and the order of the N encrypted data slices in the encrypted data, so that the target device can accurately send the corresponding first encrypted data to the M second devices. There are many ways to determine the order of the N second devices, for example, it can be determined based on the account name, nickname, UID, etc. of the corresponding auxiliary user, and it can also be determined based on the time sequence of the auxiliary users who agree to be the target user, which is not limited here. In another possible implementation, during the process of encrypting the N target data slices using the first public keys of the N second devices to obtain the N encrypted data slices, the target device can establish a mapping relationship between the second device and the corresponding encrypted data slice, and store the mapping relationship and the encrypted data in the first device. When the target data needs to be restored, the mapping relationship and the encrypted data can be obtained from the first device, and then the target device can send the corresponding first encrypted data to each of the M second devices according to the mapping relationship.

[0130] In this embodiment, the target device only sends the first encrypted data to the second device, and the first encrypted data does not contain relevant information of the target data. Therefore, during the process of recovering the target data, the second device does not touch the ciphertext corresponding to the target data (the second encrypted data). Even if M second devices conspire, they cannot recover the target data, which can ensure the security of the target data.

[0131] S307: Each of the M second devices uses the stored first private key to process the received first encrypted data to obtain intermediate data.

[0132] After receiving the corresponding first encrypted data, each of the M second devices processes the received first encrypted data using the first private key stored in the device to obtain the corresponding intermediate data. i ,sk i ) in the private key sk i The first encrypted data received The first encrypted data is processed according to the first private key to obtain the intermediate data. Please refer to the relevant description of the ciphertext split encryption algorithm for the implementation of obtaining the intermediate data. It will not be repeated here.

[0133] S308: The M second devices send intermediate data to the target device.

[0134] After each of the M second devices obtains the intermediate data through calculation, the M second devices send the intermediate data to the target device.

[0135] S309: The target device uses the M intermediate data to process corresponding second encrypted data in the M second encrypted data to obtain M target data fragments.

[0136] The target device receives M intermediate data {InterM i}i=1,2,...,M, use M intermediate data {InterM i}i=1,2,...,M process the corresponding second encrypted data in the M second encrypted data to obtain M target data fragments {s i}i=1,2,...,M. The implementation of processing the second encrypted data according to the intermediate data to obtain the target data fragments can be found in the relevant description of the ciphertext splittable encryption algorithm, which will not be repeated here.

[0137] The second encrypted data corresponding to the intermediate data is the second encrypted data in the encrypted data slice to which the first encrypted data corresponding to the intermediate data belongs. For example, the first encrypted data corresponding to the intermediate data InterMi is The first encrypted data The encrypted data shard to which it belongs is The second encrypted data corresponding to the intermediate data InterMi is the encrypted data fragment The second encrypted data in Using Intermediate Data InterM i , the second encrypted data can be Restore to target data shards i , that is, restoring the target data shard in the ciphertext state to the target data shard in the plaintext state.

[0138] S310: The target device obtains target data according to M target data slices.

[0139] After the target device obtains the M target data slices, it can merge the M target data slices to obtain the target data. Specifically, the target device can reconstruct the M target data slices into the target data through Lagrange interpolation calculation.

[0140] In this embodiment, the target device encrypts the target data using the first public key provided by N second devices to obtain encrypted data, and stores the encrypted data on the first device, achieving separation of powers between the first and second devices and rendering the target data unrecoverable by either the first or second device. Furthermore, the target data is split into N target data shards through secret sharing, and each of the N target data shards is encrypted to obtain N encrypted data shards. This allows the target data to be reconstructed by restoring at least T of the N encrypted data shards, thereby improving the resilience of target data recovery. Furthermore, each encrypted data shard in the encrypted data is calculated based on the first public key in the ciphertext-splittable encryption algorithm, so that each encrypted data shard can be split into first encrypted data and second encrypted data. The first encrypted data can be processed by the first private key corresponding to the first public key to obtain intermediate data, and the intermediate data is used to process the second encrypted data to obtain the target data shard. Therefore, the target device can only send the first encrypted data to the second device without sending the ciphertext (second encrypted data) corresponding to the target data shard to the second device. The target device can restore the target data based on the intermediate data and the second encrypted data returned by the second device. Therefore, the target device restores the target data without the second device contacting the ciphertext corresponding to the target data. This can ensure that the target data will not be leaked to non-target users, and can ensure the security of the target data in the encryption and decryption stages.

[0141] As shown in Figure 4, Figure 4 is a flow chart of another data processing method provided by this application. This embodiment is implemented based on the data processing system shown in Figure 1. The difference from the data processing method corresponding to Figure 3 is that this embodiment ensures the resilience of secret recovery by splitting the target private key into N private key shards. This embodiment includes the following steps:

[0142] S401: The target device obtains first public keys corresponding to N second devices.

[0143] In this embodiment, the first public key corresponding to the N second devices is the same, and the first public key and the target private key form a public-private key pair. The first public key and the target private key are generated based on a ciphertext splittable encryption algorithm. The N second devices can be distributed based on DKG to achieve key distribution. Specifically, through DKG, the target private key is split into N key shares (i.e., N first private keys) {sk i i = 1, 2, ..., N, meaning that N first private keys are private key shards of the target private key. Each second device then distributes one of the N first private keys. Each second device holds both the first public key and one first private key. The N first private keys are different. The N second devices can use either a temporary ciphertext-splittable public-private key pair or a long-term ciphertext-splittable public-private key pair, without limitation.

[0144] The process of the target device interacting with the N second devices to obtain the first public key can be found in the description of the key agreement phase in the embodiment corresponding to FIG1 , and is therefore not further described here. Optionally, in one possible implementation, since the first public keys of the N second devices are the same, the target device may also interact with one of the N second devices to obtain the first public key.

[0145] S402: The target device encrypts the target data using the first public key to obtain encrypted data, where the encrypted data includes first encrypted data and second encrypted data.

[0146] In this embodiment, the target device may not fragment the target data, but may encrypt the target data using the first public key to obtain encrypted data (C m ,C k ). The encrypted data (C m ,C k ) includes the first encrypted data C k and the second encrypted data C m The first encrypted data C k The key applicable part, the second encrypted data C m is the ciphertext corresponding to the target data.

[0147] S403: The target device sends the encrypted data to the first device.

[0148] The target device obtains the encrypted data (C m ,C k ) and then encrypt the data (C m ,C k ) is sent to the first device for storage, thereby separating the powers of the key holder (the second device) and the ciphertext custodian (the first device). Except for the target device, other devices cannot hold the second encrypted data and the key at the same time, thereby ensuring that the target data cannot be obtained or restored by other devices and that the encrypted data is not leaked.

[0149] S404: The first device stores the encrypted data.

[0150] S405: The target device obtains the encrypted data from the first device.

[0151] It should be noted that the target device in S401-S403 and the target device in S405, S406, and S309-S310 all refer to the device used by the target user. The target device in S401-S403 and the target device in S305, S406, and S409-S410 may be the same device or different devices. For example, if the target device involved in encrypting the target data (the target device in S401-S403) is lost or damaged, and the target user needs to restore the target data on another device, then the target device in S401-S403 and the target device in S405, S406, and S409-S410 are different devices. For example, in the case where the target data stored in the target device that participates in encrypting the target data is destroyed, such as the target data stored in the target device is deleted or the storage unit storing the target data is damaged, and the target user expects to restore the target data on the target device, then the target device in S401-S403 is the same device as the target device in S405, S406, S409-S410.

[0152] When the encrypted data needs to be restored to the target data, the target device obtains the encrypted data from the first device. If the first device is a cloud storage device, the target device can download the target data from the first device. If the first device is a private device of the target user, the target device can receive the encrypted data from the first device via wired and / or wireless means.

[0153] S406: The target device sends the first encrypted data to the M second devices.

[0154] In this embodiment, the target device sends the first encrypted data C to each of the M second devices. k Since the encrypted data is encrypted with a first public key, the target data is not split, so the first encrypted data C sent by the target device to the M second devices is k are the same.

[0155] S407: Each of the M second devices uses the stored first private key to process the first encrypted data to obtain intermediate data.

[0156] Each second device receives the first encrypted data C k After that, the first encrypted data is processed using the first private key held by itself to obtain the corresponding intermediate data. Since the first private keys of the M second devices are different, the obtained intermediate data are also different.

[0157] S408: The M second devices send intermediate data to the target device.

[0158] S409: The target device obtains target intermediate data according to the M intermediate data.

[0159] The target device receives the intermediate data {InterM i After i=1,2,...,M, the M intermediate data are merged to obtain the target intermediate data InterM. Since the first private keys held by the M second devices are obtained by sharding the target private key, the intermediate data obtained by processing the first encrypted data with the first private key can be considered a shard of the target intermediate data. Therefore, before using the intermediate data to process the second encrypted data, the M intermediate data must be merged to restore the target intermediate data. The target device can reconstruct the target intermediate data from the M intermediate data using Lagrange interpolation.

[0160] S410: The target device obtains target data according to the target intermediate data and the second encrypted data.

[0161] After the target device obtains the target intermediate data InterM, it uses the target intermediate data InterM to process the second encrypted data C m , obtain the target data s and complete the recovery of the target data.

[0162] In this embodiment, the target device encrypts the target data using the first public key provided by the second device to obtain encrypted data, and stores the encrypted data on the first device, thereby achieving a separation of powers between the first and second devices and preventing the first and second devices from recovering the target data. Furthermore, the target private key is split into N first private keys through DKG, so that when recovering the target data, the first encrypted data can be processed using the first private keys of M of the N second devices to obtain M intermediate data. Based on the M intermediate data and the second encrypted data, the target data can be reconstructed without recovering the target private key. When N is greater than or equal to 3, it is not necessary for all N second devices to participate in recovering the target data, which can improve the resilience of target data recovery. Furthermore, the encrypted data is calculated based on the first public key in the ciphertext-splittable encryption algorithm, so that the encrypted data can be split into first encrypted data and second encrypted data. The first encrypted data can be processed by the first private key corresponding to the first public key to obtain intermediate data, and the intermediate data is used to process the second encrypted data to obtain the target data fragment. Therefore, the target device can only send the first encrypted data to the second device without sending the ciphertext (second encrypted data) corresponding to the target data fragment to the second device. The target device can restore the target data based on the intermediate data and the second encrypted data returned by the second device. Therefore, the target device restores the target data without the second device contacting the ciphertext corresponding to the target data. This can ensure that the target data will not be leaked to non-target users, and can ensure the security of the target data in the encryption and decryption stages.

[0163] Since the intermediate data obtained by the second device using the first private key to process the first encrypted data can be used to restore the target data, if an attacker steals the encrypted data and acts as an intermediary to steal the intermediate data when the second device and the target device exchange the intermediate data, the target data will be leaked. Therefore, in order to further improve the security of the target data, the present application also provides the following embodiments. As shown in Figure 5, Figure 5 is a flow chart of another data processing method provided by the present application. Based on the data processing method embodiment corresponding to Figure 3, this embodiment adds a step in which the target device exchanges the key held by the target device with N second devices, and the second device uses the key provided by the target device to encrypt the intermediate data and send the encrypted intermediate data to the target device. The key provided by the target device can be a public key in an asymmetric key or a symmetric key, which is not limited here. In this embodiment, the target device providing a second public key to M second devices is used as an example for explanation. This embodiment includes the following steps:

[0164] S501: The target device obtains the first public keys of N second devices.

[0165] S502: The target device uses N first public keys to encrypt N target data slices corresponding to the target data to obtain encrypted data, where the encrypted data includes N encrypted data slices, and each encrypted data slice includes first encrypted data and second encrypted data.

[0166] S503: The target device sends the encrypted data to the first device.

[0167] S504: The first device stores the encrypted data.

[0168] S505: The target device obtains the encrypted data from the first device.

[0169] S501-S505 can refer to the relevant descriptions in S301-S305 respectively, and will not be repeated here.

[0170] S506: The target device sends the second public key to the M second devices.

[0171] It should be noted that S506 can be executed before or after S501. Alternatively, S506 can be executed before or after S507. Alternatively, S506 and S507 can be executed simultaneously, that is, the second public key and the first encrypted data corresponding to the second device i are sent to the second device i through the same message.

[0172] In one possible implementation, the target device may publish the second public key to the M second devices via a video connection. For example, the second public key may be announced by the target device via voice, and then the auxiliary users corresponding to the M second devices record the second public key. Alternatively, after the M second devices confirm that the target user has passed identity authentication, the target application running on the target device generates a public-private key pair (including the second public key and the second private key), and then sends the second public key to the M second devices.

[0173] In one possible implementation, the target device may generate a public-private key pair so that the second public key sent by the target device to the M second devices is the same, thereby reducing the complexity of the target device implementation. In another possible implementation, the target device may generate multiple public-private key pairs, and the second public keys sent to the M second devices may be different. For example, the second public keys sent by the target device to the M second devices are different from each other, or the target device divides the M second devices into groups, each group including one or more second devices, and the second public keys sent by the target device to the second devices in each group are the same, while the second public keys sent by different groups are different.

[0174] S507: The target device sends the corresponding first encrypted data to the M second devices.

[0175] S507 is similar to S306, so it will not be described here in detail.

[0176] S508: Each of the M second devices uses the stored first private key to process the received first encrypted data to obtain intermediate data.

[0177] S508 is similar to S307, so it will not be described here in detail.

[0178] S509: The M second devices each encrypt the obtained intermediate data using the second public key to obtain encrypted intermediate data.

[0179] Before the second device sends the intermediate data to the target device, it uses the second public key to encrypt the intermediate data to obtain encrypted intermediate data, thereby ensuring the security of the intermediate data during transmission. Even if an attacker obtains the encrypted intermediate data, he cannot decrypt the encrypted intermediate data, thereby preventing the attacker from obtaining the target data based on the intermediate data and preventing the leakage of the target data.

[0180] S510: M second devices send encrypted intermediate data to the target device.

[0181] S511: The target device uses the second private key to decrypt the M encrypted intermediate data respectively to obtain M intermediate data in plain text state.

[0182] After receiving the M encrypted intermediate data, the target device uses the second private key to decrypt each encrypted intermediate data to obtain M intermediate data in plain text.

[0183] S512: The target device uses the M intermediate data to process corresponding second encrypted data in the M second encrypted data to obtain M target data fragments.

[0184] S512 is similar to S309 and will not be described here in detail.

[0185] S513: The target device obtains target data according to the M target data slices.

[0186] S513 is similar to S310, so it will not be described here.

[0187] In this embodiment, the target device sends the second public key to M second devices, so that the M second devices can use the second public key to encrypt the intermediate data into encrypted intermediate data and then send it to the target device, thereby preventing the intermediate data from being stolen or tampered with during the transmission process, and can improve the security of the intermediate data during the transmission process, further reduce the possibility of target data leakage, and ensure the security of the target data.

[0188] As shown in Figure 6, Figure 6 is a flow chart of another data processing method provided by the present application. Based on the data processing method embodiment corresponding to Figure 4, this embodiment adds a step in which the target device interacts with N second devices to exchange the key held by the target device, and the second device uses the key provided by the target device to encrypt the intermediate data and send the encrypted intermediate data to the target device. The key provided by the target device can be a public key in an asymmetric key or a symmetric key, which is not limited here. In this embodiment, the target device provides a second public key to M second devices as an example for explanation. This embodiment includes the following steps:

[0189] S601: The target device obtains first public keys corresponding to N second devices.

[0190] S602: The target device encrypts the target data using the first public key to obtain encrypted data, where the encrypted data includes first encrypted data and second encrypted data.

[0191] S603: The target device sends the encrypted data to the first device.

[0192] S604: The first device stores the encrypted data.

[0193] S605: The target device obtains the encrypted data from the first device.

[0194] For S601-S605, please refer to the relevant descriptions in S401-S405 respectively, and will not be repeated here.

[0195] S606: The target device sends the second public key to the M second devices.

[0196] It should be noted that S606 can be executed before S601 or after S601. Alternatively, S606 can be executed before S607 or after S607. Alternatively, S606 and S607 can be executed simultaneously, that is, the second public key and the first encrypted data C are sent to the second device i through the same message. k .

[0197] The manner in which the target device sends the second public key to the M second devices can be found in the relevant description of S506, so it will not be repeated here.

[0198] S607: The target device sends the first encrypted data to the M second devices.

[0199] S607 is similar to S406, so it will not be described here.

[0200] S608: Each of the M second devices uses the stored first private key to process the first encrypted data to obtain intermediate data.

[0201] S608 is similar to S407, so it will not be described here.

[0202] S609: The M second devices each encrypt the obtained intermediate data using the second public key to obtain encrypted intermediate data.

[0203] S610: M second devices send encrypted intermediate data to the target device.

[0204] S611: The target device uses the second private key to decrypt the M encrypted intermediate data respectively to obtain M intermediate data in plain text state.

[0205] S612: The target device obtains target intermediate data according to the M intermediate data.

[0206] S512 is similar to S409 and will not be described here in detail.

[0207] S613: The target device obtains target data according to the target intermediate data and the second encrypted data.

[0208] S613 is similar to S410, so it will not be described here.

[0209] In this embodiment, the target device sends the second public key to M second devices, so that the M second devices can use the second public key to encrypt the intermediate data into encrypted intermediate data and then send it to the target device, thereby preventing the intermediate data from being stolen or tampered with during the transmission process, and can improve the security of the intermediate data during the transmission process, further reduce the possibility of target data leakage, and ensure the security of the target data.

[0210] The following describes the device used to implement the above method in the embodiment of the present application with reference to the accompanying drawings.

[0211] As shown in Figure 7, Figure 7 is a schematic diagram of the structure of a device provided by this application. Device 700 includes a processing module 701 and a transceiver module 702. The device can be the user device or the second device mentioned above. For example, the device can be a mobile phone, a tablet computer, a computer, a smart home device, a smart wearable device, an in-vehicle computer, a server, etc. The device can also be a functional module or hardware module (such as a chip or chip system, etc.) in the user device, the first device, or the second device.

[0212] When the apparatus 700 is used to implement the steps performed by the user device in Figures 3-6, the processing module 701 is configured to obtain encrypted data stored on a first device. The encrypted data includes first encrypted data and second encrypted data. The second encrypted data is encrypted data corresponding to the target data. The decryption key for the encrypted data includes N first private keys. The N first private keys are different and stored in N second devices. One of the N second devices stores one of the N first private keys. The first device and the N second devices are different devices. N is an integer greater than or equal to 1. The transceiver module 702 is configured to send the first encrypted data to M of the N second devices. M is an integer greater than or equal to 1. M is an integer greater than or equal to 1 and less than or equal to N. The processing module 701 is configured to obtain intermediate data from the M second devices. The intermediate data of each second device is obtained based on the first encrypted data and the first private key stored in the second device. The processing module 701 is configured to obtain the target data based on the M intermediate data and the second encrypted data.

[0213] In one possible implementation, N is an integer greater than or equal to 3; M is an integer greater than T and less than or equal to N; T is an integer less than or equal to M and greater than 2, and T indicates a threshold number of first private keys required to decrypt encrypted data.

[0214] In one possible implementation, the target data corresponds to N target data slices, each of which is obtained by splitting the target data through secret sharing. The encrypted data includes N encrypted data slices corresponding to the N target data slices. Each encrypted data slice is encrypted using a first public key corresponding to a first private key stored on a second device. Each encrypted data slice includes one corresponding first encrypted data and one corresponding second encrypted data. The transceiver module 702 is configured to send the corresponding first encrypted data to each of the M second devices.

[0215] In one possible implementation, the processing module 701 is used to obtain M target data shards based on M intermediate data and corresponding M second encrypted data, where the M target data shards are data shards among the N target data shards; and obtain target data based on the M target data shards.

[0216] In one possible implementation, transceiver module 702 is configured to receive first public keys corresponding to N second devices, where the first public keys corresponding to the N second devices are different. Processing module 701 is configured to encrypt N target data slices using the first public keys corresponding to the N second devices, respectively, to obtain N encrypted data slices. The first public key corresponding to one second device is used to encrypt one target data slice. Transceiver module 702 is configured to send the N encrypted data slices to the first device, so that the first device stores the N encrypted data slices.

[0217] In one possible implementation, the N first private keys are N private key shards corresponding to a target private key, the N private key shards being obtained by splitting the target private key through secret sharing, and the encrypted data being obtained by encrypting the target data using the public key corresponding to the target private key. Processing module 701 is configured to obtain target intermediate data based on the M intermediate data and obtain target data based on the target intermediate data and the second encrypted data.

[0218] In a possible implementation, the processing module 701 is configured to perform identity authentication with M second devices; after the identity authentication is passed, the transceiver module 702 is configured to send the first encrypted data to M second devices among the N second devices.

[0219] In a possible implementation, the processing module 701 is configured to perform identity authentication with each of the M second devices through video.

[0220] In one possible implementation, the transceiver module 702 is configured to receive encrypted intermediate data from M second devices, where the encrypted intermediate data is obtained based on the second public key and the intermediate data, and the intermediate data is in plaintext. The processing module 701 is configured to obtain the intermediate data based on the second private key and the encrypted intermediate data, where the second public key and the second private key form a public-private key pair.

[0221] In one possible implementation, the transceiver module 702 is configured to receive first public keys corresponding to N second devices. The processing module 701 is configured to encrypt target data using the first public keys corresponding to the N second devices to obtain encrypted data, where the encrypted data includes first encrypted data and second encrypted data, where the second encrypted data is encrypted data corresponding to the target data. The decryption key for the encrypted data includes N first private keys, where the N first private keys are different and are stored in the N second devices, respectively. One of the N second devices stores one of the N first private keys. The N first private keys are used to process the first encrypted data to obtain intermediate data, and the intermediate data is used to process the second encrypted data to obtain the target data. N is an integer greater than or equal to 1.

[0222] When the apparatus 700 is a device for implementing the steps performed by the second device in Figures 3-6, the transceiver module 702 is configured to receive first encrypted data, where the first encrypted data is partially encrypted data within the encrypted data, the encrypted data including the first encrypted data and the second encrypted data, the second encrypted data being encrypted data corresponding to the target data, the decryption key for the encrypted data including N first private keys, the N first private keys being different, the N first private keys being respectively stored in N second devices, one of the N second devices storing one of the N first private keys, the first device and the N second devices being different devices, the target second device being one of the N second devices, and N being an integer greater than or equal to 1. The transceiver module 702 is configured to send intermediate data, where the intermediate data is obtained based on the first encrypted data and the first private key stored in the target second device, and the intermediate data is used to restore the second encrypted data to the target data.

[0223] In a possible implementation, the processing module 701 is configured to encrypt the intermediate data in plain text to obtain the encrypted intermediate data, and the transceiver module 702 is configured to send the encrypted intermediate data.

[0224] As shown in Figure 8, which is a schematic diagram of the structure of a device provided by this application, in this embodiment, the device 800 can be a server, server cluster, computer, tablet computer, smart wearable device, smart home device, car computer, smart phone, or other device with computing power.

[0225] The device 800 includes a bus 801 , a processor 802 , a communication interface 803 , and a memory 804 . The processor 802 , the memory 804 , and the communication interface 803 communicate with each other via the bus 801 .

[0226] Bus 801 may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. Buses can be categorized as address buses, data buses, and control buses. For ease of illustration, FIG8 shows only one thick line, but this does not imply that there is only one bus or only one type of bus.

[0227] The processor 802 may be any one or more of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).

[0228] The memory 804 may include volatile memory, such as random access memory (RAM). The memory 804 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard drive (HDD), or solid state drive (SSD).

[0229] The memory 804 may be used to store software codes related to the data processing method, and the processor 802 may execute the steps of the data processing method and may also schedule other units to implement corresponding functions.

[0230] It should be understood that the data processing device 800 can be a centralized or distributed device, and the processor 802 in the data processing device 800 can be a hardware circuit (such as an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), a general-purpose processor, a digital signal processor (DSP), a microprocessor or a microcontroller, etc.), or a combination of these hardware circuits. For example, the processor can be a hardware system with an instruction execution function, such as a CPU, DSP, etc., or a hardware system without an instruction execution function, such as an ASIC, FPGA, etc., or a combination of the above-mentioned hardware systems without an instruction execution function and hardware systems with an instruction execution function.

[0231] The present application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a computer, implements the data processing method flow of any of the above-mentioned method embodiments.

[0232] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0233] The present application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a computer, implements the data processing method flow of any of the above-mentioned method embodiments.

[0234] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0235] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical or other forms.

[0236] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0237] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0238] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the technical solution of the present application can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

Claims

1. A data processing method, characterized in that The method includes: Obtaining encrypted data stored in a first device, where the encrypted data includes first encrypted data and second encrypted data, the second encrypted data being the encrypted data corresponding to target data, the decryption key of the encrypted data including N first private keys, the N first private keys being different, the N first private keys being respectively stored in N second devices, one of the N second devices storing one of the N first private keys, the first device and the N second devices being different devices; N is an integer greater than or equal to 1; Sending the first encrypted data to M second devices among the N second devices; M is an integer greater than or equal to 1; M is an integer greater than or equal to 1 and less than or equal to N; Obtaining intermediate data from the M second devices, the intermediate data of each second device being obtained based on the first encrypted data and the first private key stored in the second device; Obtaining the target data based on the M intermediate data and the second encrypted data.

2. The method according to claim 1, wherein N is an integer greater than or equal to 3; M is an integer greater than T and less than or equal to N; T is an integer less than or equal to M and greater than 2, and T indicates the threshold number of first private keys required to decrypt the encrypted data.

3. The method according to claim 2, wherein The target data corresponds to N target data shards, the N target data shards being obtained by splitting the target data through a secret sharing method, the encrypted data including N encrypted data shards corresponding to the N target data shards, one encrypted data shard being obtained by encrypting one target data shard with the first public key corresponding to the first private key stored in one second device, each encrypted data shard including 1 corresponding first encrypted data and 1 second encrypted data; The sending the first encrypted data to M second devices includes: Sending the corresponding first encrypted data to each of the M second devices respectively.

4. The method according to claim 3, wherein The obtaining the target data based on the M intermediate data and the second encrypted data includes: Obtaining M target data shards based on the M intermediate data and the corresponding M second encrypted data, the M target data shards being data shards among the N target data shards; Obtaining the target data based on the M target data shards.

5. The method according to claim 3 or 4, characterized in that, Before obtaining the encrypted data stored in the first device, it further includes: Receiving the first public keys corresponding to the N second devices, the first public keys corresponding to the N second devices being different; Respectively encrypting the N target data shards with the first public keys corresponding to the N second devices to obtain the N encrypted data shards, the first public key corresponding to one second device being used to encrypt one target data shard; Sending the N encrypted data shards to the first device so that the first device stores the N encrypted data shards.

6. The method according to claim 2, wherein The N first private keys are N private key shards corresponding to the target private key. The N private key shards are obtained by splitting the target private key through secret sharing. The encrypted data is obtained by encrypting the target data with the public key corresponding to the target private key. Obtaining the target data according to M pieces of the intermediate data and the second encrypted data includes: Obtaining target intermediate data according to M pieces of the intermediate data; Obtaining the target data according to the target intermediate data and the second encrypted data.

7. The method according to any one of claims 1 to 6, characterized in that Before sending the first encrypted data to M second devices among the N second devices, it includes: Performing identity authentication with the M second devices; After the identity authentication is passed, performing the step of sending the first encrypted data to M second devices among the N second devices.

8. The method according to claim 7, characterized in that Performing identity authentication with the M second devices includes: Performing the identity authentication with the M second devices respectively through video.

9. The method according to any one of claims 1 to 8, characterized in that Obtaining the intermediate data from the M second devices includes: Receiving encrypted intermediate data from the M second devices. The encrypted intermediate data is obtained according to a second public key and the intermediate data, and the intermediate data is in plaintext state; Obtaining the intermediate data according to a second private key and the encrypted intermediate data. The second public key and the second private key are a pair of public-private key pairs.

10. A data processing method, characterized in that, The method includes: Obtaining first public keys corresponding to N second devices; Using the first public keys corresponding to the N second devices to encrypt the target data to obtain encrypted data. The encrypted data includes first encrypted data and second encrypted data. The second encrypted data is the encrypted data corresponding to the target data. The decryption key of the encrypted data includes N first private keys. The N first private keys are different. The N first private keys are respectively stored in the N second devices. One second device among the N second devices stores one of the N first private keys. The N first private keys are used to process the first encrypted data to obtain intermediate data, and the intermediate data is used to process the second encrypted data to obtain the target data; N is an integer greater than or equal to 1; Sending the encrypted data to a first device, where the first device and the N second devices are different devices.

11. The method according to claim 10, wherein N is an integer greater than or equal to 3; M is an integer greater than T and less than or equal to N; T is an integer less than or equal to M and greater than 2, and T indicates the threshold number of first private keys required to decrypt the encrypted data.

12. The method according to claim 11, wherein The first public keys corresponding to the N second devices are different. The target data corresponds to N target data shards. The N target data shards are obtained by splitting the target data through secret sharing. The encrypted data includes N encrypted data shards corresponding to the N target data shards. One encrypted data shard is obtained by encrypting one target data shard with the first public key corresponding to the first private key stored in one second device. Each encrypted data shard includes 1 corresponding first encrypted data and 1 second encrypted data.

13. The method according to claim 11, wherein The first public keys corresponding to the N second devices are the same. The N first private keys are N private key shards corresponding to the target private key. The N private key shards are obtained by splitting the target private key through a secret sharing method. The target private key and the first public key form a pair of public-private key pairs.

14. A data processing method, characterized in that, The method includes: The target second device receives first encrypted data. The first encrypted data is part of the encrypted data. The encrypted data includes the first encrypted data and second encrypted data. The second encrypted data is the encrypted data corresponding to the target data. The decryption key of the encrypted data includes N first private keys. The N first private keys are different. The N first private keys are respectively stored in N second devices. One of the N second devices stores one of the N first private keys. The first device and the N second devices are different devices. The target second device is one of the N second devices. N is an integer greater than or equal to 1. The target second device sends intermediate data. The intermediate data is obtained based on the first encrypted data and the first private key stored in the target second device. The intermediate data is used to restore the second encrypted data to the target data.

15. The method according to claim 14, characterized in that, The method further includes: The target second device encrypts the intermediate data in plaintext state to obtain encrypted intermediate data. The target second device sending the intermediate data includes: The target second device sends the encrypted intermediate data.

16. A device, characterized in that, The device includes a module for performing the data processing method according to any one of claims 1 to 15.

17. A device, characterized in that, The device includes a processor and a memory. The processor is coupled to the memory. The processor is configured to execute the data processing method according to any one of claims 1-15 based on instructions stored in the memory.

18. A readable storage medium, characterized in that, A computer program or instructions are stored in the storage medium. When the computer program or instructions are executed by a communication device, the data processing method according to any one of claims 1 to 15 is implemented.

Citation Information

Patent Citations

  • Data encryption processing method and device, data decryption processing method and device and electronic equipment

    CN112602289A

  • Data processing method, device and system

    CN114337994A

  • Threshold encryption and decryption method and device for group member data protection and computer equipment

    CN115834122A

  • Threshold encryption using homomorphic signatures

    US20160072623A1