A cross-border e-commerce backend data security storage method and system

By combining homomorphic encryption and symmetric encryption, we can identify and encrypt non-compliant data in the backend data of cross-border e-commerce, achieve secure storage and analysis of cross-border e-commerce data, solve the compliance problem of cross-border e-commerce data, ensure data security and support multi-party decryption and data analysis.

CN119939630BActive Publication Date: 2025-10-03SHANDONG VOCATIONAL COLLEGE OF ECONOMICS & TRADE
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510076815.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-17
Publication Date
2025-10-03
Estimated Expiration
2045-01-17

AI Technical Summary

Technical Problem

Cross-border e-commerce platforms face data compliance issues across regions and legal systems, and existing technologies lack effective cross-border data security storage solutions.

Method used

A combination of homomorphic encryption and symmetric encryption is used to encrypt cross-border e-commerce backend data. Non-compliant data is identified based on the transaction compliance rules of the e-commerce transaction area, and the encryption key is uploaded to the cloud. Data security is ensured through multiple security protection standards. The seller's server re-encrypts the encrypted ciphertext and transmits it to the buyer's server for decryption and storage.

Benefits of technology

It implements multiple security protection standards for cross-border e-commerce backend data to avoid non-compliant data leakage, supports joint decryption by multiple administrators, accelerates the decryption process, and performs data analysis without decrypting the original data to obtain analysis results of compliant data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939630B_ABST
    Figure CN119939630B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of data security storage, and discloses a cross-border e-commerce background data security storage method and system, the method comprising: collecting cross-border e-commerce background data of an e-commerce transaction area, and identifying non-compliant data in the cross-border e-commerce background data using transaction compliance rules of the e-commerce transaction area; the e-commerce transaction area where the seller is located adopts homomorphic encryption and symmetric encryption to encrypt the compliant data and non-compliant data in the cross-border e-commerce background data respectively, and transmits the encrypted ciphertext to the server of the e-commerce transaction area where the buyer is located; the server of the e-commerce transaction area where the buyer is located stores the encrypted ciphertext, and performs data analysis processing on the stored encrypted ciphertext. The present invention identifies non-compliant data based on the data acquisition method, and adopts different encryption methods for encryption, thereby realizing cross-border e-commerce background data encryption processing of multiple security protection standards, and cross-border transmission and storage of encrypted ciphertext.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data security storage, and in particular to a method and system for securely storing backend data of a cross-border e-commerce company. Background Art

[0002] Cross-border e-commerce, through internet platforms, has broken through geographical and temporal constraints and become one of the primary ways for consumers worldwide to access goods. This booming cross-border e-commerce has also brought with it a series of prominent data security issues, particularly cross-border data compliance. Cross-border e-commerce platforms often involve laws and regulations in different countries and regions, and their data storage and processing must comply with data protection laws in different regions. Existing research primarily focuses on data security issues within a specific region or legal framework, lacking comprehensive compliance solutions across regions and legal systems. Summary of the Invention

[0003] In view of this, the present invention provides a cross-border e-commerce backend data security storage method, which identifies non-compliant data in the cross-border e-commerce backend data during the cross-border e-commerce transaction process according to the transaction compliance rules of the e-commerce transaction area, encrypts the compliant data using homomorphic encryption, and encrypts the non-compliant data using the advanced encryption standard, and uploads the encryption key to the cloud to implement cross-border e-commerce backend data encryption processing with multiple security protection standards; the server in the e-commerce transaction area where the seller is located performs secondary encrypting on the encrypted ciphertext, and transmits the encrypted ciphertext and the message authentication code to the server in the e-commerce transaction area where the buyer is located for decryption, integrity verification and storage.

[0004] To achieve the above-mentioned purpose, the present invention provides a method for securely storing backend data of a cross-border e-commerce company, comprising the following steps:

[0005] S1: Collect cross-border e-commerce backend data from e-commerce transaction areas, identify non-compliant data in the cross-border e-commerce backend data using transaction compliance rules of the e-commerce transaction areas, and divide the cross-border e-commerce backend data into compliant data and non-compliant data, where the e-commerce transaction areas include the e-commerce transaction areas where the buyer is located and the e-commerce transaction areas where the seller is located;

[0006] S2: The e-commerce transaction area where the seller is located uses homomorphic encryption and symmetric encryption to encrypt the compliant data and non-compliant data in the cross-border e-commerce background data, respectively, to obtain the encrypted ciphertext of the cross-border e-commerce background data;

[0007] S3: The server in the e-commerce transaction area where the seller is located transmits the encrypted ciphertext to the server in the e-commerce transaction area where the buyer is located;

[0008] S4: The server in the e-commerce transaction area where the buyer is located stores the encrypted ciphertext and performs data analysis and processing on the stored encrypted ciphertext.

[0009] As a further improvement method of the present invention:

[0010] Optionally, the transaction compliance rules of the e-commerce transaction area are the data protection regulations and information protection laws of the e-commerce transaction area. The transaction compliance rules include transaction data compliance rules, logistics data compliance rules, and user data compliance rules. The data protection regulations and information protection laws issued by the e-commerce transaction area set privacy protection regulations for transaction data, logistics data, and user data in cross-border e-commerce business, constituting transaction data compliance rules, logistics data compliance rules, and user data compliance rules. In step S1, the transaction compliance rules of the e-commerce transaction area are used to identify non-compliant data in the cross-border e-commerce background data, including:

[0011] The transaction data includes the order number, transaction time, payment information, order status, order review, name, quantity, and unit price of the purchased goods. The transaction data compliance rule is to extract the user's private data from the transaction data and check whether the method of obtaining the private data is compliant based on the data protection regulations and information protection laws of the e-commerce transaction area. Private data obtained in an uncompliant manner will be regarded as non-compliant transaction data, and all data in the transaction data other than the non-compliant transaction data will be regarded as compliant transaction data.

[0012] The logistics data includes the shipping address, receiving address, logistics company name, logistics order number, cargo weight, transportation method, transportation status and customs clearance information; the logistics data compliance rule is to extract the user's private data from the logistics data, and check whether the method of obtaining the private data is compliant based on the data protection regulations and information protection laws of the e-commerce transaction area. Private data obtained in an uncompliant manner will be regarded as logistics uncompliant data, and all data in the logistics data other than the logistics uncompliant data will be regarded as logistics compliant data;

[0013] The user data includes the user's basic information, browsing history, favorites information, purchase history, purchase address, and IP address. Based on the data protection regulations and information protection laws of the e-commerce transaction area, the user data that is not obtained in compliance with regulations is extracted as the user's non-compliant data, and the user data other than the user's non-compliant data is extracted as the user's compliant data.

[0014] Transaction compliance data, logistics compliance data and user compliance data are regarded as compliance data, and transaction non-compliance data, logistics non-compliance data and user non-compliance data are regarded as compliance data.

[0015] Optionally, performing homomorphic encryption on the compliant data includes:

[0016] The compliant data is encoded using UTF-8 encoding, and the text and numbers in the compliant data are converted into integers to obtain the UTF-8 encoding sequence of the compliant data. ;

[0017] Generate homomorphic encryption keys for compliant data, where the homomorphic encryption keys include public key pk=(n,g) and private key sk= , the private key sk is divided into group A, is the ath group of private key parameters, n is two extremely large prime numbers and The product of , g is the public key parameter, let g=n+1;

[0018] The compliance data is encrypted using the public key to obtain the compliance encrypted ciphertext of the compliance data, where the compliance encrypted ciphertext corresponding to the compliance data is :

[0019] ;

[0020] in:

[0021] Represents a random number, and mod represents the remainder operation.

[0022] Optionally, symmetrically encrypting the non-compliant data includes:

[0023] The non-compliant data is encoded using UTF-8 encoding, and the text and numbers in the non-compliant data are converted into integers to obtain the UTF-8 encoding sequence of the non-compliant data. ;

[0024] Generate an initial key, where the initial key is 128 bytes and encode the UTF-8 sequence Divide into multiple sequence matrices, each sequence matrix contains 16 consecutive integers, where the sequence matrix is ​​in the form of 4 rows and 4 columns, and each integer in the sequence matrix is ​​8 bytes;

[0025] Use the initial key to perform 10 rounds of encryption on the sequence matrix to obtain the 10 round keys of the sequence matrix and the encrypted ciphertext corresponding to the sequence matrix;

[0026] The encryption process of each round of the sequence matrix is ​​as follows:

[0027] Obtaining the matrix parameters to be encrypted, wherein during the first round of encryption processing, the matrix parameters to be encrypted are the sequence matrix;

[0028] The matrix parameter to be encrypted is XORed with the round key output in the previous round, and the XOR result is nonlinearly mapped using the 16-row 16-column S matrix and a polynomial to obtain a 4-row 4-column nonlinear mapping matrix. The nonlinear mapping formula is:

[0029] ;

[0030] in:

[0031] Indicates the result of the XOR operation, represents the convolution operator, represents a polynomial, Indicates the result of the XOR operation Perform polynomial operations;

[0032] Perform a circular left shift operation on each row in the nonlinear mapping matrix, where the first row remains unchanged, the second row is shifted left by 1 byte, the third row is shifted left by 2 bytes, and the fourth row is shifted left by 3 bytes;

[0033] Perform column obfuscation on the nonlinear mapping matrix after cyclic left shift and use it as the matrix parameter to be encrypted in the next round. Column obfuscation is to use a fixed matrix to perform linear operations on the column vectors in the nonlinear mapping matrix. If the current round is 10, the nonlinear mapping matrix after cyclic left shift is directly used as the encrypted ciphertext corresponding to the sequence matrix, and the round key for the 10th round is calculated.

[0034] The round key output in the previous round is nonlinearly mapped using the 16-row 16-column S matrix and a polynomial, and then cyclically shifted to the left to obtain the round key output in this round;

[0035] The encrypted ciphertexts of all sequence matrices are used as non-compliant encrypted ciphertexts of non-compliant data, and the 10 round keys and the initial key of all sequence matrices are used as encryption keys of the non-compliant encrypted ciphertexts.

[0036] Optionally, the encrypted ciphertext of the cross-border e-commerce backend data includes the compliant encrypted ciphertext of the compliant data and the non-compliant encrypted ciphertext of the non-compliant data. The A group of private key parameters of the compliant encrypted ciphertext is distributed to A administrator in the e-commerce transaction area where the buyer is located, and the encryption key of the non-compliant encrypted ciphertext is stored in the cloud built by the cloud service provider, and the cloud service provider is responsible for the key security.

[0037] Optionally, in step S3, the server in the e-commerce transaction area where the seller is located transmits the encrypted ciphertext to the server in the e-commerce transaction area where the buyer is located, including:

[0038] The server in the e-commerce transaction area where the seller is located sends a handshake message to the server in the e-commerce transaction area where the buyer is located, wherein the handshake message includes a list of supported encryption algorithms and a random number of the seller's server;

[0039] The server of the e-commerce transaction zone where the buyer is located replies with a response message, including the confirmed encryption algorithm, the buyer's server random number, the digital certificate of the e-commerce transaction zone where the buyer is located, and the public key;

[0040] The e-commerce transaction area where the seller is located verifies the digital certificate, and uses the confirmed encryption algorithm, public key, seller's server random number and buyer's server random number to re-encrypt the encrypted ciphertext as the transmission encrypted ciphertext, and sends the transmission encrypted ciphertext to the server in the e-commerce transaction area where the buyer is located. The server in the e-commerce transaction area where the buyer is located decrypts the transmission encrypted ciphertext to obtain the encrypted ciphertext, and uses a hash-based message authentication code method to check the integrity of the transmission encrypted ciphertext.

[0041] Optionally, the hash-based message authentication code method is:

[0042] The server in the e-commerce transaction area where the seller is located obtains the transmission encrypted ciphertext c and the message authentication key key, and generates the message authentication code message(c) for the transmission encrypted ciphertext c:

[0043] ;

[0044] in:

[0045] is the SHA-256 hash function;

[0046] Represents a bitwise exclusive OR operation, Indicates string concatenation;

[0047] Indicates the external filling amount, Indicates the internal padding amount, which is used to fill the message authentication key and fix the length of the message authentication key; the message authentication key is generated by the random number of the seller server and the random number of the buyer server;

[0048] The message authentication code message(c) and the transmission encryption ciphertext c are sent to the server in the e-commerce transaction area where the buyer is located. The server in the e-commerce transaction area where the buyer is located generates a message authentication key key and calculates the message authentication code for the received transmission encryption ciphertext. If the calculation result is consistent with the message authentication code message(c), the integrity check passes. Otherwise, it indicates that the transmission encryption ciphertext has been tampered with.

[0049] Optionally, the server performs data analysis processing on the compliant encrypted ciphertext in the encrypted ciphertext, performs data analysis on the compliant encrypted ciphertext based on the homomorphism of the compliant encrypted ciphertext to obtain data ciphertext, and decrypts the data ciphertext to obtain data analysis results of the compliant data, including:

[0050] The server splits the compliant encrypted ciphertext into several sub-ciphertexts, extracts the sub-ciphertexts describing the quantity and unit price of the purchased goods, performs addition and multiplication operations on the sub-ciphertexts, and obtains the data ciphertext describing the sales volume and revenue of the goods. The server obtains the private key parameters of group A, and uses the private key parameters of group A to decrypt the data ciphertext to obtain the sales volume and revenue of the goods.

[0051] Optionally, the decryption process of the data ciphertext is as follows:

[0052] Get the private key parameters of group A and the ciphertext of the data to be decrypted , based on the private key parameters of group A and the public key n, the first private key parameter is calculated ;

[0053] based on , , calculated and , Indicates calculation of the least common multiple;

[0054] Calculate the data ciphertext respectively and The decryption result ;

[0055] Combine the decryption results to obtain the data ciphertext Corresponding product sales and revenue ,in It is in UTF-8 encoding format.

[0056] In order to solve the above problems, the present invention provides a cross-border e-commerce backend data security storage system, characterized in that the cross-border e-commerce backend data security storage system is deployed in the e-commerce transaction area, and the cross-border e-commerce backend data security storage system includes a server and a data storage device, and the server includes a first encryption module and a second encryption module:

[0057] The first encryption module is used to identify non-compliant data in the cross-border e-commerce background data by using the transaction compliance rules of the e-commerce transaction area, divide the cross-border e-commerce background data into compliant data and non-compliant data, and use homomorphic encryption and symmetric encryption methods to encrypt the compliant data and non-compliant data in the cross-border e-commerce background data respectively to obtain the encrypted ciphertext of the cross-border e-commerce background data;

[0058] The second encryption module is used to perform secondary encryption on the encrypted ciphertext to obtain a transmission encrypted ciphertext, send the transmission encrypted ciphertext to the server in the e-commerce transaction area where the buyer is located, and decrypt the transmission encrypted ciphertext and the data ciphertext;

[0059] The data storage device is used to store encrypted ciphertexts and perform data analysis and processing on compliant encrypted ciphertexts in the encrypted ciphertexts.

[0060] In order to solve the above problem, the present invention further provides an electronic device, comprising:

[0061] a memory storing at least one instruction;

[0062] Communication interfaces to enable electronic equipment to communicate; and

[0063] The processor executes the instructions stored in the memory to implement the above-mentioned cross-border e-commerce background data security storage method.

[0064] In order to solve the above problems, the present invention also provides a computer-readable storage medium, which stores at least one instruction, and the at least one instruction is executed by a processor in an electronic device to implement the above-mentioned cross-border e-commerce background data security storage method.

[0065] Compared with the existing technology, the present invention proposes a cross-border e-commerce backend data security storage method, which has the following advantages:

[0066] First, this scheme proposes a data encryption method. According to the transaction compliance rules of the e-commerce transaction area, non-compliant data in the cross-border e-commerce backend data during the cross-border e-commerce transaction process is identified, and the private data obtained in a non-compliant manner is obtained. The cross-border e-commerce backend data is then divided into compliant data and non-compliant data. The compliant data is encrypted using homomorphic encryption. In the homomorphic encryption process, the private key is divided into multiple private key parameters, so that multiple administrators in the e-commerce transaction area where the buyer is located jointly hold the private key parameters. Only collaboration can complete decryption. The decryption operation based on large numbers is divided into decimal decryption operations based on two prime numbers, thereby accelerating the decryption process. The non-compliant data is encrypted using the Advanced Encryption Standard, and the encryption key is uploaded to the cloud. The cloud service provider is responsible for key security to prevent the leakage of non-compliant data. The cross-border e-commerce backend data encryption processing with multiple security protection standards is implemented. Before the encryption process, random numbers with random positions and random lengths are introduced to encode the cross-border e-commerce backend data. This makes the same plaintext generate different ciphertext each time it is encrypted, breaking the repetitive pattern of the plaintext and preventing attackers from inferring the plaintext by observing the ciphertext.

[0067] At the same time, this solution proposes a method for cross-border data transmission and storage. The server in the e-commerce transaction area where the seller is located performs secondary encryption on the encrypted ciphertext to obtain the transmission encrypted ciphertext and the message authentication code, and transmits the transmission encrypted ciphertext and the message authentication code to the server in the e-commerce transaction area where the buyer is located for decryption and storage. Based on the homomorphism of the compliant encrypted ciphertext, data analysis is performed on the compliant encrypted ciphertext, where the data analysis method includes addition and multiplication operations to obtain the data ciphertext, and the data ciphertext is decrypted to obtain the data analysis results of the compliant data. Data analysis is achieved without decrypting the original data to obtain product sales and revenue. BRIEF DESCRIPTION OF THE DRAWINGS

[0068] Figure 1 A schematic diagram of a process for securely storing backend data for cross-border e-commerce provided by one embodiment of the present invention;

[0069] Figure 2 A functional module diagram of a cross-border e-commerce backend data security storage system provided by one embodiment of the present invention;

[0070] Figure 2 Middle: 100 cross-border e-commerce backend data security storage system, 101 first encryption module, 102 second encryption module, 103 data storage device;

[0071] Figure 3 A cross-border communication diagram between a cross-border e-commerce backend data security storage system provided by one embodiment of the present invention;

[0072] The purpose, features and advantages of the present invention will be further described with reference to the accompanying drawings and in conjunction with the embodiments. DETAILED DESCRIPTION

[0073] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0074] The embodiments of the present application provide a method for securely storing backend data for cross-border e-commerce. The execution subject of the method includes, but is not limited to, at least one of electronic devices such as a server and a terminal that can be configured to execute the method provided by the embodiments of the present application. In other words, the method for securely storing backend data for cross-border e-commerce can be executed by software or hardware installed on a terminal device or a server device, and the software can be a blockchain platform. The server includes, but is not limited to, a single server, a server cluster, a cloud server, or a cloud server cluster.

[0075] Reference Figure 1 , embodiment 1 of the present invention is:

[0076] S1: Collect cross-border e-commerce background data from e-commerce transaction areas, use transaction compliance rules of e-commerce transaction areas to identify non-compliant data in the cross-border e-commerce background data, and divide the cross-border e-commerce background data into compliant data and non-compliant data. The e-commerce transaction areas include the e-commerce transaction areas where the buyer is located and the e-commerce transaction areas where the seller is located.

[0077] The transaction compliance rules of the e-commerce transaction area are the data protection regulations and information protection laws of the e-commerce transaction area. The transaction compliance rules include transaction data compliance rules, logistics data compliance rules, and user data compliance rules. The data protection regulations and information protection laws issued by the e-commerce transaction area set privacy protection regulations for transaction data, logistics data, and user data in cross-border e-commerce business, constituting transaction data compliance rules, logistics data compliance rules, and user data compliance rules. In step S1, the transaction compliance rules of the e-commerce transaction area are used to identify non-compliant data in the cross-border e-commerce background data, including:

[0078] The transaction data includes the order number, transaction time, payment information, order status, order evaluation, name, quantity and unit price of the purchased goods, where the order status includes completed or uncompleted. The transaction data compliance rule is to extract the user's private data from the transaction data and check whether the method of obtaining the private data is compliant based on the data protection regulations and information protection laws of the e-commerce transaction area. Private data obtained in an uncompliant manner will be regarded as non-compliant transaction data, and data in the transaction data other than the non-compliant transaction data will be regarded as compliant transaction data. Specifically, payment information and order evaluation will be regarded as private data in the transaction data.

[0079] The logistics data includes the shipping address, receiving address, logistics company name, logistics order number, cargo weight, transportation method, transportation status and customs clearance information, where the transportation status includes whether the goods have been received or not received. The logistics data compliance rule is to extract the user's private data from the logistics data, and check whether the method of obtaining the private data is compliant based on the data protection regulations and information protection laws of the e-commerce transaction area. The private data obtained in an uncompliant manner is regarded as logistics uncompliant data, and the data in the logistics data other than the logistics uncompliant data is regarded as logistics compliant data. Specifically, the shipping address, receiving address, customs clearance information and logistics order number are regarded as private data in the logistics data.

[0080] The user data includes the user's basic information, browsing history, favorites information, purchase history, purchase address, and IP address. Based on the data protection regulations and information protection laws of the e-commerce transaction area, the user data that is not obtained in compliance with regulations is extracted as the user's non-compliant data, and the user data other than the user's non-compliant data is extracted as the user's compliant data.

[0081] As an embodiment of the present invention, taking GDPR (General Data Protection Regulation) and CCPA (California Consumer Privacy Act) as examples, GDPR requires that data must be collected and processed in a legal and transparent manner, and the privacy data obtained must obtain explicit user consent, especially sensitive data. Data that the user does not agree to is non-compliant data, and data transmitted to countries outside the EU must meet security requirements. Data that meets GDPR is considered compliant data in the EU region. If the e-commerce transaction area is located in the EU region, it is necessary to screen non-compliant data based on GDPR; CCPA requires that users have the right to know the purpose and use of personal data collection. Data that the user is unclear about the purpose and use is non-compliant data. Users have the right to request to view, delete or prohibit the sale of their personal data. Sensitive personal information (such as financial information, geographic location, etc.) must be especially protected. Data that meets CCPA is considered compliant data in the California region. If the e-commerce transaction area is located in the California region, it is necessary to screen non-compliant data based on CCPA.

[0082] Transaction compliance data, logistics compliance data and user compliance data are regarded as compliance data, and transaction non-compliance data, logistics non-compliance data and user non-compliance data are regarded as compliance data.

[0083] S2: The e-commerce transaction area where the seller is located uses homomorphic encryption and symmetric encryption to encrypt the compliant data and non-compliant data in the cross-border e-commerce background data respectively, and obtains the encrypted ciphertext of the cross-border e-commerce background data.

[0084] Performing homomorphic encryption on the compliant data includes:

[0085] The compliant data is encoded using UTF-8 encoding, and the text and numbers in the compliant data are converted into integers to obtain the UTF-8 encoding sequence of the compliant data. As a preferred embodiment of the present invention, in the UTF-8 encoding process, a random number is added to the integer using a preset encoding rule, so that the same plaintext generates a different ciphertext each time it is encrypted, breaking the repetitive pattern of the plaintext and preventing attackers from inferring the plaintext by observing the ciphertext. The position where the random number is added to the integer num is :

[0086] ;

[0087] in:

[0088] is the length of an integer, is a preset integer length threshold;

[0089] like , then add a random number in front of the integer num, if , then add a random number after the integer num, the length of the random number is ;

[0090] Generate homomorphic encryption keys for compliant data, where the homomorphic encryption keys include public key pk=(n,g) and private key sk= , the private key sk is divided into group A, is the ath group of private key parameters, n is two extremely large prime numbers and The product of , g is the public key parameter, let g=n+1;

[0091] The compliance data is encrypted using the public key to obtain the compliance encrypted ciphertext of the compliance data, where the compliance encrypted ciphertext corresponding to the compliance data is :

[0092] ;

[0093] in:

[0094] Represents a random number, mod represents the remainder operation;

[0095] Specifically, the private key parameters The representation is: ,in:

[0096] ;

[0097] ;

[0098] ;

[0099] in:

[0100] Is the first private key parameter, the first private key parameter Divided into ,satisfy ;

[0101] Indicates calculation of the least common multiple;

[0102] Represents the second private key parameter, Indicates the third private key parameter.

[0103] Symmetrically encrypting the non-compliant data includes:

[0104] The non-compliant data is encoded using UTF-8 encoding, and the text and numbers in the non-compliant data are converted into integers to obtain the UTF-8 encoding sequence of the non-compliant data. ;

[0105] Generate an initial key, where the initial key is 128 bytes and encode the UTF-8 sequence Divide into multiple sequence matrices, each sequence matrix contains 16 consecutive integers, where the sequence matrix is ​​in the form of 4 rows and 4 columns, and each integer in the sequence matrix is ​​8 bytes;

[0106] Use the initial key to perform 10 rounds of encryption on the sequence matrix to obtain the 10 round keys of the sequence matrix and the encrypted ciphertext corresponding to the sequence matrix;

[0107] The encryption process of each round of the sequence matrix is ​​as follows:

[0108] Obtaining the matrix parameters to be encrypted, wherein during the first round of encryption processing, the matrix parameters to be encrypted are the sequence matrix;

[0109] The matrix parameter to be encrypted is XORed with the round key output in the previous round, and the XOR result is nonlinearly mapped using the 16-row 16-column S matrix and a polynomial to obtain a 4-row 4-column nonlinear mapping matrix. The nonlinear mapping formula is:

[0110] ;

[0111] in:

[0112] Indicates the result of the XOR operation, represents the convolution operator, represents a polynomial, Indicates the result of the XOR operation Perform polynomial operations;

[0113] Perform a circular left shift operation on each row in the nonlinear mapping matrix, where the first row remains unchanged, the second row is shifted left by 1 byte, the third row is shifted left by 2 bytes, and the fourth row is shifted left by 3 bytes;

[0114] Perform column obfuscation on the nonlinear mapping matrix after cyclic left shift and use it as the matrix parameter to be encrypted in the next round. Column obfuscation is to use a fixed matrix to perform linear operations on the column vectors in the nonlinear mapping matrix. If the current round is 10, the nonlinear mapping matrix after cyclic left shift is directly used as the encrypted ciphertext corresponding to the sequence matrix, and the round key for the 10th round is calculated.

[0115] The round key output in the previous round is nonlinearly mapped using the 16-row 16-column S matrix and a polynomial, and then cyclically shifted to the left to obtain the round key output in this round;

[0116] The encrypted ciphertexts of all sequence matrices are used as non-compliant encrypted ciphertexts of non-compliant data, and the 10 round keys and the initial key of all sequence matrices are used as encryption keys of the non-compliant encrypted ciphertexts.

[0117] The encrypted ciphertext of the cross-border e-commerce backend data includes the compliant encrypted ciphertext of compliant data and the non-compliant encrypted ciphertext of non-compliant data. The A group of private key parameters of the compliant encrypted ciphertext is distributed to A administrator of the e-commerce transaction area where the buyer is located, and the encryption key of the non-compliant encrypted ciphertext is stored in the cloud built by the cloud service provider, and the cloud service provider is responsible for the key security.

[0118] S3: The server in the e-commerce transaction area where the seller is located transmits the encrypted ciphertext to the server in the e-commerce transaction area where the buyer is located.

[0119] The server in the e-commerce transaction area where the seller is located sends a handshake message to the server in the e-commerce transaction area where the buyer is located, wherein the handshake message includes a list of supported encryption algorithms and a random number of the seller's server;

[0120] The server of the e-commerce transaction zone where the buyer is located replies with a response message, including the confirmed encryption algorithm, the buyer's server random number, the digital certificate of the e-commerce transaction zone where the buyer is located, and the public key;

[0121] The e-commerce transaction area where the seller is located verifies the digital certificate, and uses the confirmed encryption algorithm, public key, seller's server random number and buyer's server random number to re-encrypt the encrypted ciphertext as the transmission encrypted ciphertext, and sends the transmission encrypted ciphertext to the server in the e-commerce transaction area where the buyer is located. The server in the e-commerce transaction area where the buyer is located decrypts the transmission encrypted ciphertext to obtain the encrypted ciphertext, and uses a hash-based message authentication code method to check the integrity of the transmission encrypted ciphertext.

[0122] The hash-based message authentication code method is:

[0123] The server in the e-commerce transaction area where the seller is located obtains the transmission encrypted ciphertext c and the message authentication key key, and generates the message authentication code message(c) for the transmission encrypted ciphertext c:

[0124] ;

[0125] in:

[0126] is the SHA-256 hash function;

[0127] Represents a bitwise exclusive OR operation, Indicates string concatenation;

[0128] Indicates external padding, consisting of repeated 0x5C bytes. Indicates the internal padding, consisting of repeated 0x36 bytes, used to fill the message authentication key and fix the length of the message authentication key; the message authentication key is generated by the random number of the seller server and the random number of the buyer server;

[0129] The message authentication code message(c) and the transmission encryption ciphertext c are sent to the server in the e-commerce transaction area where the buyer is located. The server in the e-commerce transaction area where the buyer is located generates a message authentication key key and calculates the message authentication code for the received transmission encryption ciphertext. If the calculation result is consistent with the message authentication code message(c), the integrity check passes. Otherwise, it indicates that the transmission encryption ciphertext has been tampered with.

[0130] S4: The server in the e-commerce transaction area where the buyer is located stores the encrypted ciphertext and performs data analysis and processing on the stored encrypted ciphertext.

[0131] The server performs data analysis on the compliant encrypted ciphertext in the encrypted ciphertext, performs data analysis on the compliant encrypted ciphertext based on the homomorphism of the compliant encrypted ciphertext to obtain data ciphertext, and decrypts the data ciphertext to obtain data analysis results of the compliant data, including:

[0132] The server splits the compliant encrypted ciphertext into several sub-ciphertexts, extracts the sub-ciphertexts describing the quantity and unit price of the purchased goods, performs addition and multiplication operations on the sub-ciphertexts, and obtains the data ciphertext describing the sales volume and revenue of the goods. The server obtains the private key parameters of group A, and uses the private key parameters of group A to decrypt the data ciphertext to obtain the sales volume and revenue of the goods.

[0133] The decryption process of the data ciphertext is as follows:

[0134] Get the private key parameters of group A and the ciphertext of the data to be decrypted , based on the private key parameters of group A and the public key n, the first private key parameter is calculated ;

[0135] based on , , calculated and , Indicates calculation of the least common multiple;

[0136] Calculate the data ciphertext respectively and The decryption result:

[0137] ;

[0138] ;

[0139] in:

[0140] Data ciphertext In prime numbers The decryption result on Data ciphertext In prime numbers The decryption result on ;

[0141] Combine the decryption results to obtain the data ciphertext Corresponding product sales and revenue ,in It is in UTF-8 encoding format. As an embodiment of the present invention, the reverse rule of the encoding rule in the UTF-8 encoding process is removed. Random numbers in .

[0142] As a preferred embodiment of the present invention, the large number decryption operation based on n is divided into two types based on and The decimal decryption operation is performed to accelerate the decryption process. The merging method used is:

[0143] .

[0144] Example 2:

[0145] like Figure 2 , which is a functional module diagram of a cross-border e-commerce background data security storage system provided by an embodiment of the present invention, which can implement the cross-border e-commerce background data security storage method in Example 1.

[0146] According to the functions implemented, the cross-border e-commerce backend data security storage system may include a first encryption module 101, a second encryption module 102, and a data storage device 103. The module described in the present invention may also be referred to as a unit, which refers to a series of computer program segments that can be executed by an electronic device processor and can perform fixed functions, and is stored in the memory of the electronic device.

[0147] The first encryption module 101 is used to identify non-compliant data in the cross-border e-commerce background data by using the transaction compliance rules of the e-commerce transaction area, divide the cross-border e-commerce background data into compliant data and non-compliant data, and use homomorphic encryption and symmetric encryption methods to encrypt the compliant data and non-compliant data in the cross-border e-commerce background data respectively to obtain the encrypted ciphertext of the cross-border e-commerce background data;

[0148] The second encryption module 102 is used to perform secondary encryption on the encrypted ciphertext to obtain the transmission encrypted ciphertext, send the transmission encrypted ciphertext to the server in the e-commerce transaction area where the buyer is located, and decrypt and perform integrity verification on the transmission encrypted ciphertext and the data ciphertext;

[0149] The data storage device 103 is used to store the encrypted ciphertext and perform data analysis and processing on the compliant encrypted ciphertext in the encrypted ciphertext.

[0150] In detail, each module in the cross-border e-commerce backend data security storage system 100 in the embodiment of the present invention adopts the same Figure 1 The same technical means are used as the cross-border e-commerce background data security storage method described in, and can produce the same technical effects, so I will not go into details here.

[0151] Example 3:

[0152] like Figure 3As shown, it is a cross-border communication diagram between the cross-border e-commerce background data security storage system provided by an embodiment of the present invention, which can realize that the server in the e-commerce transaction area where the seller is located in Example 1 transmits the encrypted ciphertext to the server in the e-commerce transaction area where the buyer is located, and the server in the e-commerce transaction area where the seller is located performs secondary encryption on the encrypted ciphertext to obtain the transmission encrypted ciphertext and the message authentication code, and transmits the transmission encrypted ciphertext and the message authentication code to the server in the e-commerce transaction area where the buyer is located for decryption and storage.

[0153] It should be understood that the embodiment is for illustration only and the scope of the patent application is not limited to this structure.

[0154] It should be noted that the serial numbers of the above-mentioned embodiments of the present invention are for descriptive purposes only and do not represent the advantages or disadvantages of the embodiments. In addition, the terms "including", "comprising" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, device, article or method comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, device, article or method. In the absence of further restrictions, an element defined by the sentence "including a ..." does not exclude the presence of other identical elements in the process, device, article or method comprising the element.

[0155] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better embodiment. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in each embodiment of the present invention.

[0156] The above are only preferred embodiments of the present invention and are not intended to limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made using the contents of the present invention description and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.

Claims

1. A cross-border e-commerce background data security storage method, characterized in that: The method comprises: S1: Collect cross-border e-commerce backend data from the e-commerce transaction area, identify non-compliant data in the cross-border e-commerce backend data using the transaction compliance rules of the e-commerce transaction area, and divide the cross-border e-commerce backend data into compliant data and non-compliant data. The cross-border e-commerce backend data refers to various data forms generated and used in cross-border e-commerce business, including transaction data, logistics data, and user data. The e-commerce transaction area is the area where the two parties to the transaction in the cross-border e-commerce business are located, where the e-commerce transaction area includes the e-commerce transaction area where the buyer is located and the e-commerce transaction area where the seller is located. The cross-border e-commerce backend data is collected by the seller; S2: The e-commerce transaction area where the seller is located uses homomorphic encryption and symmetric encryption to encrypt the compliant data and non-compliant data in the cross-border e-commerce background data, respectively, to obtain the encrypted ciphertext of the cross-border e-commerce background data; S3: The server in the e-commerce transaction area where the seller is located transmits the encrypted ciphertext to the server in the e-commerce transaction area where the buyer is located; S4: The server in the e-commerce transaction area where the buyer is located stores the encrypted ciphertext and performs data analysis and processing on the stored encrypted ciphertext; Performing homomorphic encryption on the compliant data includes: The compliant data is encoded using UTF-8 encoding, and the text and numbers in the compliant data are converted into integers to obtain the UTF-8 encoding sequence of the compliant data. ; Generate homomorphic encryption keys for compliant data, where the homomorphic encryption keys include public key pk=(n,g), private key , the private key sk is divided into group A, is the ath group of private key parameters, n is two extremely large prime numbers and The product of , g is the public key parameter, let g=n+1; The compliance data is encrypted using the public key to obtain the compliance encrypted ciphertext of the compliance data, where the compliance encrypted ciphertext corresponding to the compliance data is : ; in: Represents a random number, mod represents the remainder operation; The private key parameters The representation is: ,in: ; ; ; in: Is the first private key parameter, the first private key parameter Divided into ,satisfy ; Indicates calculation of the least common multiple; Represents the second private key parameter, Indicates the third private key parameter.

2. A cross-border e-commerce backend data security storage method according to claim 1, characterized in that: The transaction compliance rules of the e-commerce transaction area are the data protection regulations and information protection laws of the e-commerce transaction area. The transaction compliance rules include transaction data compliance rules, logistics data compliance rules, and user data compliance rules. The data protection regulations and information protection laws issued by the e-commerce transaction area set privacy protection regulations for transaction data, logistics data, and user data in cross-border e-commerce business, constituting transaction data compliance rules, logistics data compliance rules, and user data compliance rules. In step S1, the transaction compliance rules of the e-commerce transaction area are used to identify non-compliant data in the cross-border e-commerce background data, including: The transaction data includes the order number, transaction time, payment information, order status, order review, name, quantity, and unit price of the purchased goods. The transaction data compliance rule is to extract the user's private data from the transaction data and check whether the method of obtaining the private data is compliant based on the data protection regulations and information protection laws of the e-commerce transaction area. Private data obtained in an uncompliant manner will be regarded as non-compliant transaction data, and all data in the transaction data other than the non-compliant transaction data will be regarded as compliant transaction data. The logistics data includes the shipping address, receiving address, logistics company name, logistics order number, cargo weight, transportation method, transportation status and customs clearance information; the logistics data compliance rule is to extract the user's private data from the logistics data, and check whether the method of obtaining the private data is compliant based on the data protection regulations and information protection laws of the e-commerce transaction area. Private data obtained in an uncompliant manner will be regarded as logistics uncompliant data, and all data in the logistics data other than the logistics uncompliant data will be regarded as logistics compliant data; The user data includes the user's basic information, browsing history, favorites information, purchase history, purchase address, and IP address. Based on the data protection regulations and information protection laws of the e-commerce transaction area, the user data that is not obtained in compliance with regulations is extracted as the user's non-compliant data, and the user data other than the user's non-compliant data is extracted as the user's compliant data. Transaction compliance data, logistics compliance data, and user compliance data are considered compliance data, and transaction non-compliance data, logistics non-compliance data, and user non-compliance data are considered non-compliance data; Symmetrically encrypting the non-compliant data includes: The non-compliant data is encoded using UTF-8 encoding, and the text and numbers in the non-compliant data are converted into integers to obtain the UTF-8 encoding sequence of the non-compliant data. ; Generate an initial key, where the initial key is 128 bytes and encode the UTF-8 sequence Divide into multiple sequence matrices, each sequence matrix contains 16 consecutive integers, where the sequence matrix is ​​in the form of 4 rows and 4 columns, and each integer in the sequence matrix is ​​8 bytes; Use the initial key to perform 10 rounds of encryption on the sequence matrix to obtain the 10 round keys of the sequence matrix and the encrypted ciphertext corresponding to the sequence matrix; The encryption process of each round of the sequence matrix is ​​as follows: Obtaining the matrix parameters to be encrypted, wherein during the first round of encryption processing, the matrix parameters to be encrypted are the sequence matrix; The matrix parameter to be encrypted is XORed with the round key output in the previous round, and the XOR result is nonlinearly mapped using the 16-row 16-column S matrix and a polynomial to obtain a 4-row 4-column nonlinear mapping matrix. The nonlinear mapping formula is: ; in: Indicates the result of the XOR operation, represents the convolution operator, represents a polynomial, Indicates the result of the XOR operation Perform polynomial operations; Perform a circular left shift operation on each row in the nonlinear mapping matrix, where the first row remains unchanged, the second row is shifted left by 1 byte, the third row is shifted left by 2 bytes, and the fourth row is shifted left by 3 bytes; Perform column obfuscation on the nonlinear mapping matrix after cyclic left shift and use it as the matrix parameter to be encrypted in the next round. Column obfuscation is to use a fixed matrix to perform linear operations on the column vectors in the nonlinear mapping matrix. If the current round is 10, the nonlinear mapping matrix after cyclic left shift is directly used as the encrypted ciphertext corresponding to the sequence matrix, and the round key for the 10th round is calculated. The round key output in the previous round is nonlinearly mapped using the 16-row 16-column S matrix and a polynomial, and then cyclically shifted to the left to obtain the round key output in this round; The encrypted ciphertexts of all sequence matrices are used as non-compliant encrypted ciphertexts of non-compliant data, and the 10 round keys and the initial key of all sequence matrices are used as encryption keys of the non-compliant encrypted ciphertexts.

3. A cross-border e-commerce backend data security storage method according to claim 1, characterized in that: The encrypted ciphertext of the cross-border e-commerce backend data includes the compliant encrypted ciphertext of compliant data and the non-compliant encrypted ciphertext of non-compliant data. The A group of private key parameters of the compliant encrypted ciphertext is distributed to A administrator of the e-commerce transaction area where the buyer is located, and the encryption key of the non-compliant encrypted ciphertext is stored in the cloud built by the cloud service provider, and the cloud service provider is responsible for the key security.

4. A cross-border e-commerce backend data security storage method according to claim 1, characterized in that: The S3 step includes: The server in the e-commerce transaction area where the seller is located sends a handshake message to the server in the e-commerce transaction area where the buyer is located, wherein the handshake message includes a list of supported encryption algorithms and a random number of the seller's server; The server of the e-commerce transaction zone where the buyer is located replies with a response message, including the confirmed encryption algorithm, the buyer's server random number, the digital certificate of the e-commerce transaction zone where the buyer is located, and the public key; The e-commerce transaction area where the seller is located verifies the digital certificate, and uses the confirmed encryption algorithm, public key, seller's server random number and buyer's server random number to re-encrypt the encrypted ciphertext as the transmission encrypted ciphertext, and sends the transmission encrypted ciphertext to the server in the e-commerce transaction area where the buyer is located. The server in the e-commerce transaction area where the buyer is located decrypts the transmission encrypted ciphertext to obtain the encrypted ciphertext, and uses a hash-based message authentication code method to check the integrity of the transmission encrypted ciphertext.

5. A cross-border e-commerce backend data security storage method according to claim 4, characterized in that: The hash-based message authentication code method is: The server in the e-commerce transaction area where the seller is located obtains the transmission encrypted ciphertext c and the message authentication key key, and generates the message authentication code message(c) for the transmission encrypted ciphertext c: ; in: is the SHA-256 hash function; Represents a bitwise exclusive OR operation, Indicates string concatenation; Indicates the external filling amount, Indicates the internal padding amount, which is used to fill the message authentication key and fix the length of the message authentication key; the message authentication key is generated by the random number of the seller server and the random number of the buyer server; The message authentication code message(c) and the transmission encryption ciphertext c are sent to the server in the e-commerce transaction area where the buyer is located. The server in the e-commerce transaction area where the buyer is located generates a message authentication key key and calculates the message authentication code for the received transmission encryption ciphertext. If the calculation result is consistent with the message authentication code message(c), the integrity check passes. Otherwise, it indicates that the transmission encryption ciphertext has been tampered with.

6. A cross-border e-commerce backend data security storage method according to claim 1, characterized in that: The server performs data analysis on the compliant encrypted ciphertext in the encrypted ciphertext, performs data analysis on the compliant encrypted ciphertext based on the homomorphism of the compliant encrypted ciphertext to obtain data ciphertext, and decrypts the data ciphertext to obtain data analysis results of the compliant data, including: The server splits the compliant encrypted ciphertext into several sub-ciphertexts, extracts the sub-ciphertexts describing the quantity and unit price of the purchased goods, performs addition and multiplication operations on the sub-ciphertexts, and obtains the data ciphertext describing the sales volume and revenue of the goods. The server obtains the private key parameters of group A, and uses the private key parameters of group A to decrypt the data ciphertext to obtain the sales volume and revenue of the goods.

7. A cross-border e-commerce backend data security storage method according to claim 6, characterized in that: The decryption process of the data ciphertext is as follows: Get the private key parameters of group A and the ciphertext of the data to be decrypted , based on the private key parameters of group A and the public key n, the first private key parameter is calculated ; based on , , calculated and , Indicates calculation of the least common multiple; Calculate the data ciphertext respectively and The decryption result ; Combine the decryption results to obtain the data ciphertext Corresponding product sales and revenue ,in It is in UTF-8 encoding format.

8. A cross-border e-commerce backend data security storage system, characterized by: The cross-border e-commerce backend data security storage system is deployed in the e-commerce transaction area. The cross-border e-commerce backend data security storage system includes a server and a data storage device. The server includes a first encryption module and a second encryption module: The first encryption module is used to identify non-compliant data in the cross-border e-commerce background data by using the transaction compliance rules of the e-commerce transaction area, divide the cross-border e-commerce background data into compliant data and non-compliant data, and use homomorphic encryption and symmetric encryption methods to encrypt the compliant data and non-compliant data in the cross-border e-commerce background data respectively to obtain the encrypted ciphertext of the cross-border e-commerce background data; The second encryption module is used to perform secondary encryption on the encrypted ciphertext to obtain a transmission encrypted ciphertext, send the transmission encrypted ciphertext to the server in the e-commerce transaction area where the buyer is located, and decrypt the transmission encrypted ciphertext and the data ciphertext; The data storage device is used to store the encrypted ciphertext and perform data analysis and processing on the compliant encrypted ciphertext in the encrypted ciphertext; To implement a cross-border e-commerce background data security storage method as described in any one of claims 1-7.

Citation Information

Patent Citations

  • Data cross-border flow control method based on block chain technology

    CN116303762A

  • Cross-domain data compliance mutual trust calculation method

    CN119202084A