Privacy protection mobile terminal personal signature and business handling method
Through the combination of homomorphic encryption and electronic seals, the security vulnerabilities of privacy data in online business processing are solved, ensuring that data is processed in a ciphertext state, realizing the authenticity and integrity verification of the data source, reducing the risk of privacy leakage, and improving the security and efficiency of business processing.
Patent Information
- Application Number
- CN202510352681.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-25
- Publication Date
- 2025-07-08
AI Technical Summary
There are serious vulnerabilities in privacy data storage, computing and abuse of security in existing online business processing, and traditional encryption technology is difficult to take into account both efficiency and privacy protection, especially when third-party servers rely on decryption processing, there is a computing security risk.
Homomorphic encryption algorithm is used to encrypt user information by negative numbers, generate ciphertext data, and integrate electronic seals to expand and transform them into embedded extensions and seal processing through mobile APP to ensure that the data is transmitted and stored in ciphertext state. Government agencies regularly replace encryption public keys to improve security.
It realizes the authenticity and integrity verification of data sources, reduces the risk of privacy leakage, and ensures the security and privacy protection of data during transmission, storage and calculation.
Smart Images

Figure CN120277690A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of online business processing security technology, and in particular to a privacy-protected mobile terminal personal signature and business processing method. Background Art
[0002] As government affairs are transferred from offline to online, the efficiency of business handling has been significantly improved, which has greatly facilitated the process of handling affairs for the public and enterprises. However, while online business handling brings convenience, it also causes many security risks, including the difficulty in effectively verifying the authenticity and correctness of data sources, and the increasing prominence of data privacy and security issues.
[0003] In order to improve the efficiency of online transaction processing, such as Figure 1 As shown in the figure, the government affairs system of the prior art generally adopts the method of forwarding the request to a third-party cloud server for processing. At the same time, in order to ensure the authenticity and integrity of the data, electronic signature technology is widely used in online business processing. In terms of protecting user privacy data, the existing online business processing mainly adopts traditional encryption technology, such as symmetric encryption or asymmetric encryption. When users handle government affairs, they need to encrypt and submit application materials containing sensitive information. The server will decrypt these materials before performing business logic processing and data matching.
[0004] Existing technical solutions rely too much on third-party servers to completely decrypt user data, which increases the computing security risk to a certain extent. Especially when processing large-scale data, traditional encryption technology can hardly strike a balance between efficiency and privacy protection. More advanced technical means are urgently needed to solve these problems. Summary of the invention
[0005] The purpose of the present invention is to provide a privacy-protected mobile personal signature and business processing method to solve the security loopholes in the storage, calculation and abuse of privacy data in existing online business processing, realize data authenticity verification and privacy protection, and improve the security and efficiency of business processing.
[0006] The purpose of the present invention can be achieved through the following technical solutions:
[0007] A privacy-protected mobile personal signature and business processing method, comprising the following steps:
[0008] Use the homomorphic encryption algorithm to encrypt the user information piece by piece after taking the negative number, generate ciphertext data, and store the ciphertext in the cloud server;
[0009] The user fills in the application materials through the built-in APP on the mobile terminal and extracts the private data of the application materials;
[0010] Encrypt the privacy data one by one using the homomorphic encryption public key, and replace the plaintext privacy data in the application materials with ciphertext data;
[0011] Perform embedded expansion transformation based on the custom data of the current electronic seal data;
[0012] The user-side APP combines with the transformed electronic seal to electronically sign the encrypted application file using the applicant's certificate;
[0013] Send the signed ciphertext application materials to the server side and verify the signature information, extract the extended information in the electronic seal, and process the ciphertext data based on homomorphic operations;
[0014] Feed back the operation result ciphertext to the government agency for decryption and verification to generate the final business approval conclusion.
[0015] Preferably, the government agency regularly replaces the encryption public key, automatically updates the ciphertext data in the cloud server, and synchronizes the new public key through the electronic seal extension item.
[0016] Preferably, the transformation process specifically includes:
[0017] The user-side APP numbers the categories of the ciphertext attributes according to the order of the ciphertext attribute information in the application materials;
[0018] Embed the homomorphic encryption public key, the category and number of the ciphertext attributes, and the description of the ciphertext processing method for different numbers into the custom data extension item of the original electronic seal information.
[0019] Preferably, the category and serial number of the ciphertext attributes are determined by numbering the categories of the ciphertext attribute information in the application materials, and the description of the ciphertext processing method includes the operation processing instructions for the ciphertext with different numbers.
[0020] Preferably, the homomorphic operation performs matching operations or size comparisons on the ciphertext data based on the properties of homomorphic addition or subtraction.
[0021] Advantages of the present invention:
[0022] By combining electronic signature with homomorphic encrypted data, the recipient of the present invention can verify the authenticity of the data source and the integrity of the data content, ensuring the reliability of business processing.
[0023] In the present invention, the homomorphic encryption method is adopted for the user and the data source to transmit data to the third-party server to form ciphertext. The third-party cloud server performs business logic operations in the ciphertext state, realizing the availability but invisibility of the privacy data, avoiding data attacks and abuse, and reducing the risk of privacy leakage.
[0024] Of course, it is not necessary for any product implementing the present invention to achieve all the above-mentioned advantages simultaneously. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for describing the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings based on these drawings without creative efforts.
[0026] Figure 1 is a flowchart of the existing online service handling method of the present invention;
[0027] Figure 2 is a flowchart of the present invention;
[0028] Figure 3 is the custom field of the existing electronic seal data item in Embodiment 1 of the present invention;
[0029] Figure 4 is the extended item field of the transformed custom data item in Embodiment 1 of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0030] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some, rather than all, embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art without creative efforts based on the embodiments of the present invention belong to the scope of protection of the present invention.
[0031] In view of the security vulnerabilities in the storage, calculation, and abuse of privacy data that generally exist in the current technical solutions, this patent innovatively proposes a privacy protection mobile personal signature and service handling method. This technical method combines homomorphic encryption technology and electronic signature technology and applies them to the mobile online service handling process, which can further ensure the security of data in the transmission, storage, and calculation links on the basis of ensuring the authenticity and integrity of the data source, making the privacy data available but invisible.
[0032] The business handling center (such as a government agency) has all the information of the user. When processing the user's online business, in order to improve the processing efficiency, the request will be forwarded to the cloud server for processing, but there is a risk of privacy leakage during the transmission and processing. In view of the above problems, the present invention proposes a privacy protection mobile personal signature and service handling method. Please refer to Figure 2 as shown:
[0033] Use the homomorphic encryption algorithm to take the negative of each piece of user information and then encrypt it to generate ciphertext data, and store the ciphertext in the cloud server;
[0034] The user fills in the application materials through the built-in APP on the mobile device and extracts the privacy data of the application materials;
[0035] Use the homomorphic encryption public key to encrypt the privacy data item by item, and replace the plaintext privacy data in the application materials with ciphertext data;
[0036] Conduct embedded extension transformation based on the custom data of the current electronic seal data;
[0037] The user-side APP combines with the transformed electronic seal to electronically sign the encrypted application file using the applicant's certificate;
[0038] Send the signed ciphertext application materials to the server side and verify the signature information, extract the extended information in the electronic seal, and process the ciphertext data based on homomorphic operations;
[0039] Feed back the operation result ciphertext to the government agency for decryption and verification to generate the final business approval conclusion.
[0040] The user opens the mobile APP and enters the business handling page. The APP displays the corresponding fixed-template application materials according to different business types, such as social security application, provident fund withdrawal, etc. The user truthfully fills in all the information according to the template requirements. For example, in the provident fund withdrawal application, the user fills in information such as their name, work unit, monthly income, provident fund account balance, and the amount of provident fund applied for withdrawal.
[0041] After the user fills in the application materials, the user-side APP automatically identifies and extracts the key privacy data in the application materials, such as provident fund account balance, monthly salary income, etc. The APP uses the homomorphic encryption algorithm public key published by the government agency to encrypt these privacy data item by item. Suppose the provident fund account balance is "20,000 yuan", and the APP encrypts it with the public key to obtain the ciphertext E4. After encryption, the APP replaces the plaintext privacy data in the application material template with the homomorphically encrypted ciphertext data to form the encrypted application materials.
[0042] When performing electronic signature, the user-side APP first numbers the categories of the ciphertext attribute information in the order of the ciphertext attribute information in the application materials. For example, the name is numbered 1, the monthly income is numbered 2, the balance of the provident fund account is numbered 4, etc. Then, in the custom data extension item of the original electronic seal information, the homomorphic encryption public key used by the user, the categories and serial numbers of the key attribute information of the electronic file, and the description of the processing methods for ciphertexts with different numbers are added. For example, if it is stipulated that matching operations are performed on ciphertexts numbered 1-6, and number 6 is compared with number 4, these information are recorded in detail in the extension item. Finally, the APP combines the transformed electronic seal and uses the applicant's digital certificate to perform electronic signature on the encrypted application file to ensure the authenticity, non-repudiation and integrity of the source of the application document.
[0043] The government agency regularly replaces the encryption public key, automatically updates the ciphertext data in the cloud server, and synchronizes the new public key through the electronic seal extension item.
[0044] To further ensure the long-term security of the data, the government agency sets up a mechanism for regularly replacing the encryption public key, for example, replacing it every three months. When replacing the public key, first use the newly generated encryption public key to re-encrypt the user information to obtain a new ciphertext. Then, upload the new ciphertext to the cloud server to overwrite the original ciphertext data. During the update process, relevant systems and services will be notified through a secure communication channel to ensure the consistency and availability of the data.
[0045] Among them, the above-mentioned transformation process specifically includes:
[0046] The user-side APP numbers the categories of the ciphertext attributes in the order of the ciphertext attribute information in the application materials;
[0047] Embed the homomorphic encryption public key, the categories and numbers of the ciphertext attributes, and the description of the processing methods for ciphertexts with different numbers in the custom data extension item of the original electronic seal information.
[0048] The categories and serial numbers of the ciphertext attributes are determined by numbering the categories of the ciphertext attribute information in the application materials, and the description of the ciphertext processing method includes the operation processing instructions for ciphertexts with different numbers.
[0049] The government agency sorts out all user information, and according to data categories such as name, monthly income, provident fund account balance, etc., uses the homomorphic encryption algorithm to encrypt each piece of user information after taking the negative. For example, for the user's monthly income information of "5,000 yuan", first convert it into a numerical form, then take the negative "-5,000", and then use the encryption public key to encrypt "-5,000" to obtain the ciphertext E2. After the encryption is completed, all the ciphertext data is sent and stored in a third-party cloud server. During the storage process, the data will be reasonably indexed and marked for subsequent quick retrieval and use.
[0050] Homomorphic operations perform matching operations or size comparisons on ciphertext data based on the properties of homomorphic addition or subtraction.
[0051] It should be noted that the government agency selects a suitable homomorphic encryption algorithm, such as the Paillier algorithm, from various homomorphic encryption algorithms according to its own business characteristics, data scale, and security requirements. In the system initialization stage, the government agency uses the selected algorithm to generate a pair of keys, namely the encryption public key and the corresponding decryption private key. This pair of keys will be used for subsequent encryption and decryption operations of user information to ensure data security.
[0052] Example 1
[0053] 1. The government agency uses the homomorphic encryption algorithm to encrypt each piece of user information after taking the negative, and sends and stores the ciphertext in a third-party cloud server. Considering the data privacy risks that may be brought by the key security, the government agency can regularly replace the encryption public key and update the newly encrypted ciphertext to the cloud server. As shown in the following table.
[0054]
[0055] 2. The user fills in the application materials in a fixed template (such as social security application, provident fund withdrawal, etc.) through the mobile APP. For example: (Name) applies for provident fund withdrawal, his / her work unit is (Work unit), monthly income is (Monthly income) yuan, provident fund account balance is (Provident fund account balance) yuan, and the amount of provident fund applied for withdrawal is (Withdrawal amount) yuan.
[0056] 3. Encryption of the requesting party's privacy data:
[0057] 4. The user-side APP extracts all key privacy data (such as provident fund account balance, monthly salary income, etc.) from the application materials, and encrypts these privacy data one by one using the public key of the homomorphic encryption algorithm to obtain ciphertexts E1.....En. Replace the plaintext privacy data in the application material template with the homomorphically encrypted ciphertext data. For example: (E1) applies for provident fund withdrawal, his / her work unit is (E2), monthly income is (E3) yuan, provident fund account balance is (E4) yuan, and the amount of provident fund applied for withdrawal is (E5) yuan.
[0058] 5. Electronic seal data extension and transformation. For the sake of easy understanding, the existing ASN.1 definition of electronic seal data is as follows Figure 3 shown. The client APP numbers the categories of the ciphertext attribute information in the order of the ciphertext attribute information in the application materials. As shown in the above table, when performing electronic signature, the client APP first numbers the categories of the ciphertext attribute information in the order of the ciphertext attribute information in the application materials. For example, the name is numbered 1, the monthly income is numbered 2, the provident fund account balance is numbered 4, etc. Then, in the custom data extension item of the original electronic seal information, add the homomorphic encryption public key used by the user, the category and serial number of the key attribute information of the electronic file, and the description of the processing method for ciphertexts with different numbers. For example, if it is stipulated that the ciphertexts numbered 1-6 are to be subjected to a matching operation, and the number 6 is to be compared with the number 4 for size processing, then these information are detailedly recorded in the extension item. The fields of the custom data item extension item after transformation are as shown in the appendix Figure 4 shown.
[0059] Finally, the APP combines the transformed electronic seal and uses the applicant's digital certificate to perform an electronic signature on the encrypted application file to ensure the authenticity, non-repudiation, and integrity of the source of the application document.
[0060] 6. Signature verification: After the server receives the signed ciphertext application materials uploaded by the user, it first verifies the electronic signature. The server uses the public key corresponding to the user's digital certificate to decrypt the electronic signature and obtain the digest value in the signature information. At the same time, the server performs a hash calculation on the ciphertext application materials to obtain a new digest value. Compare these two digest values. If they are the same, it means that the signature is valid, the source of the application materials is real and has not been tampered with; if they are different, the application materials are rejected for processing, and an error prompt is returned to the user.
[0061] 7. Extended information extraction and parsing: After the signature verification passes, the server extracts the extended information in the electronic seal, including the homomorphic encryption public key, the category and number of attributes, and the processing method for ciphertexts with different numbers. For example, the description of the ciphertext processing method extracted is "The number 2 (monthly income) is subjected to a matching operation, and the number 4 (provident fund withdrawal amount) is compared with the number 6 (provident fund balance) for size processing.
[0062] 8. Homomorphic operation processing: The server completes the ciphertext data processing according to the parsed ciphertext processing method, using the homomorphic addition or the deformed homomorphic subtraction property (the homomorphic addition property can be expressed as By encrypting -b to obtain E(-b), the homomorphic subtraction can be realized The deformed homomorphic subtraction property can be used to complete the matching operation and compare sizes in the case of ciphertext. Taking the monthly income matching operation as an example, the server obtains the monthly income ciphertext Ea in the electronic file. By retrieving the ciphertext E-b of the corresponding applicant's monthly income stored in the cloud server by the government agency, the homomorphic cryptography operation is performed to obtain Ea - E-b. Then, the ciphertext Ea - E-b is forwarded to the government agency for decryption D(Ea - E-b) = a - b. If the decryption result is 0, it means the matching is successful; otherwise, the matching fails. For the comparison of the provident fund withdrawal amount and the provident fund balance, after the server performs database matching in the same way as above, the homomorphic subtraction property is used to compare the two sizes, and the calculation result is fed back to the government agency.
[0063] 9. Result feedback and business approval: The server repeats the above data processing steps, traverses each piece of attribute information, and feeds back the final logical operation result to the government agency. The government agency conducts the next business approval based on these results. For example, in the provident fund withdrawal business, if all verification and comparison results meet the specified conditions, the government agency will approve the user's withdrawal application; if there are non-conforming situations, the application will be rejected and the user will be informed of the reasons.
[0064] It should be noted that the homomorphic encryption algorithm adaptively selects a suitable algorithm according to aspects such as the performance, security, and applicable scenarios of the algorithm. For example, when dealing with integer operations, the Paillier algorithm is selected, and when dealing with approximate calculations, the BGV algorithm can be selected. Similarly, the ciphertext processing methods in different business scenarios will be different, and the ciphertext processing methods are also adaptively adjusted according to various considerations such as the actual business situation.
[0065] The above content is only an example and explanation of the concept of the present invention. Those skilled in the art of this technical field make various modifications or supplements to the described specific embodiments or use similar methods to replace them. As long as they do not deviate from the concept of the invention or exceed the scope defined by this claim book, they should fall within the protection scope of the present invention.
Claims
1. A method for mobile personal signature and business handling with privacy protection, characterized in that, It includes the following steps: Use the homomorphic encryption algorithm to take the negative of each piece of user information and then encrypt it to generate ciphertext data, and store the ciphertext in the cloud server; The user fills in the application materials through the built-in APP on the mobile device and extracts the privacy data of the application materials; Use the homomorphic encryption public key to encrypt the privacy data item by item, and replace the plaintext privacy data in the application materials with ciphertext data; Conduct embedded expansion transformation based on the custom data of the current electronic seal data; The user-side APP combines the transformed electronic seal and uses the applicant's certificate to electronically sign the encrypted application file; Send the signed ciphertext application materials to the server side, verify the signature information, extract the extended information in the electronic seal, and process the ciphertext data based on homomorphic operations; Feed back the operation result ciphertext to the government agency for decryption and verification to generate the final business approval conclusion.
2. The method for a privacy-protected mobile personal seal and business handling according to claim 1, characterized in that, The government agency regularly replaces the encryption public key, automatically updates the ciphertext data in the cloud server, and synchronizes the new public key through the electronic seal extension item.
3. A method for personal signature and business handling on a mobile device with privacy protection according to claim 1, characterized in that, The specific transformation process includes: The user-side APP numbers the categories of ciphertext attributes according to the order of ciphertext attribute information in the application materials; Embed the homomorphic encryption public key, the categories and numbers of ciphertext attributes, and the description of the processing methods for ciphertexts with different numbers in the custom data extension item of the original electronic seal information.
4. A method for personal signature and business handling on a mobile device with privacy protection according to claim 3, characterized in that, The categories and serial numbers of the ciphertext attributes are determined by numbering the categories of ciphertext attribute information in the application materials, and the description of the ciphertext processing method includes the operation processing instructions for ciphertexts with different numbers.
5. A method for a privacy - protected mobile personal signature and business handling according to claim 1, characterized in that, The homomorphic operation performs matching operations or size comparisons on the ciphertext data based on the properties of homomorphic addition or subtraction.