Encryption and decryption system and method for user privacy data

By building a user privacy data encryption and decryption system and combining identity authentication, permission management, dynamic encryption and multi-node verification technologies, we have solved the problems of slow speed and security risks in the existing system when processing large amounts of data, achieved efficient and secure data processing and real-time requirements, and formed a multi-level protection system.

CN120658439AInactive Publication Date: 2025-09-16WUXI YIZHI INFORMATION TECHNOLOGY CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510751983.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-06
Publication Date
2025-09-16
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing user privacy data encryption and decryption systems and methods are slow when processing large amounts of data and cannot meet scenarios with high real-time requirements, such as encrypted transmission of high-definition video streams, posing potential security risks.

Method used

It adopts a user privacy data encryption and decryption system, including a data sovereignty layer, a policy engine, a key management layer, a dynamic encryption layer, an intelligent decryption layer, and a security audit and traceability layer. It ensures data security and compliance through technologies such as identity authentication, permission management, dynamic encryption, multi-node verification, and blockchain storage.

Benefits of technology

It achieves multi-level security protection for user privacy data, improves data processing efficiency and security, can flexibly respond to different scenarios and changes, quickly trace the source of operations, and reduce the risk of data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120658439A_ABST
    Figure CN120658439A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of user privacy data encryption and decryption, and discloses a user privacy data encryption and decryption system which comprises a user privacy data encryption and decryption system body. The user privacy data encryption and decryption system body comprises a data sovereignty layer, a strategy engine, a key management layer, a dynamic encryption layer, an intelligent decryption layer and a security audit and traceability layer. According to the user privacy data encryption and decryption system and method, user data privacy is guaranteed through cooperation of all the layers and the whole process from data authority management to encryption and decryption, data is prevented from being accessed and used without authorization, all the layers are clear in division of labor, the data sovereignty layer determines data attribution and access authority, the strategy engine formulates an access strategy, and the user privacy data encryption and decryption efficiency is improved. The key management layer is responsible for key full-life-cycle management, the dynamic encryption layer implements encryption operation, the intelligent decryption layer processes decryption requests, and the architecture enables each function module of the system to perform own functions and is convenient to develop, maintain and manage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of encryption and decryption of user privacy data, and in particular to a system and method for encrypting and decrypting user privacy data. Background Art

[0002] Database encryption technology is an active defense mechanism that prevents data leaks caused by plaintext storage, external hacker attacks that breach perimeter defenses, and data theft from high-privilege internal users. This fundamentally addresses the issue of sensitive database data leakage. Typically, database data is stored and used in plaintext. Loss of data files (or backup files) can lead to serious data leakage. In database drag attacks, plaintext data remains completely confidential to attackers. Therefore, data encryption is necessary to prevent data leakage. For high-privilege users, encrypting sensitive database data can prevent data leakage caused by internal theft. Database encryption provides enhanced permission control independent of the database system's own permission control system. A dedicated encryption system sets access permissions for sensitive data in the database, effectively restricting access to sensitive data by database superusers or other high-privilege users, thereby ensuring data security.

[0003] Currently, the encryption and decryption systems and methods for user privacy data on the market should be very widespread. They can prevent private data from being obtained by unauthorized parties during storage and transmission, such as user bank account information, medical records, etc. After encryption, even if the data is intercepted, its true content cannot be known without the decryption key. However, the existing encryption and decryption systems and methods for user privacy data still have potential security risks during use. For example, some encryption algorithms (such as the asymmetric encryption algorithm RSA) are slow when processing large amounts of data and are not suitable for scenarios with high real-time requirements and large data volumes, such as encrypted transmission of high-definition video streams. Summary of the Invention

[0004] (1) Technical problems solved

[0005] In response to the shortcomings of the existing technology, the present invention provides a system and method for encrypting and decrypting user privacy data, which has the advantages of protecting user privacy, improving data security, meeting compliance requirements and achieving efficient data processing. It solves the problem that the existing system and method for encrypting and decrypting user privacy data still have potential security risks during use. For example, some encryption algorithms (such as the asymmetric encryption algorithm RSA) are slow when processing large amounts of data and are not suitable for scenarios with high real-time requirements and large data volumes, such as the encrypted transmission of high-definition video streams.

[0006] (2) Technical solution

[0007] To achieve the above-mentioned goals of protecting user privacy, improving data security, meeting compliance requirements, and achieving efficient data processing, the present invention provides the following technical solutions: a system for encrypting and decrypting user private data, including a user private data encryption and decryption system body, the user private data encryption and decryption system body including a data sovereignty layer, a policy engine, a key management layer, a dynamic encryption layer, an intelligent decryption layer, and a security audit and traceability layer;

[0008] Data sovereignty layer: Responsible for clarifying the rights and interests of data owners. Through identity authentication and rights management, it determines who owns the data and who has the authority to access and operate the data, thereby ensuring data ownership and control.

[0009] Policy engine: Develops and adjusts data access and processing policies. Policy rules are set by the rule-making unit, and the policy adjustment unit modifies them in real time based on actual conditions, ensuring that data access and operations meet business requirements and security specifications.

[0010] Key management layer: This layer covers the entire lifecycle of key generation, storage, distribution, update, and destruction. It uses post-quantum cryptography and other technologies to generate secure keys, and uses HSM and distributed key sharding technology to store keys, ensuring the security of keys at all stages.

[0011] Dynamic encryption layer: Selects the appropriate encryption algorithm and dynamically adjusts encryption parameters based on data characteristics and security requirements. It integrates a formal verification module to ensure the accuracy and security of the encryption algorithm selection.

[0012] Intelligent decryption layer: After receiving an access request, the decryption request verification unit first verifies the legitimacy of the request using technologies such as TEE+MPC multi-node verification. After the verification is passed, the decryption execution unit performs the decryption operation;

[0013] Security audit and traceability layer: The operation log recording unit uses blockchain + IPFS decentralized storage technology to record data operation logs, the security audit analysis unit analyzes the logs, and the traceability tracking unit is used to trace the source of the operation and the responsible party.

[0014] Preferably, the data sovereignty layer includes an identity authentication unit and a rights management unit;

[0015] Identity authentication unit: Verify the user's true identity and determine whether they are legitimate visitors through biometric recognition, password verification, digital certificates and other technical means;

[0016] Permission management unit: Allocate and manage user access rights to data, such as read, write, modify, and delete permissions, based on user identity and business rules.

[0017] Preferably, the policy engine includes a rule formulation unit and a policy adjustment unit;

[0018] Rule-making unit: Develops data access and processing policy rules based on business needs, security regulations, and other factors. For example, it specifies the operation permissions of specific users on specific data during a specific time period.

[0019] Policy adjustment unit: monitors the system operating environment, business demand changes, etc. in real time, and dynamically adjusts and optimizes the established policy rules.

[0020] Preferably, the key management layer includes a key generation unit, a key storage unit, a key distribution unit, a key update unit and a key destruction unit;

[0021] Key generation unit: uses advanced technologies such as post-quantum cryptography to generate encryption keys to ensure the security of keys in quantum computing environments;

[0022] Key storage unit: HSM (hardware security module) combined with distributed key sharding technology is used to store keys to prevent the keys from being stolen or tampered with;

[0023] Key distribution unit: safely and accurately distributes keys to legitimate users or devices to ensure they can perform encryption and decryption operations normally;

[0024] Key update unit: updates the keys in the system regularly or according to specific trigger conditions to enhance key security;

[0025] Key destruction unit: When a key expires or is no longer in use, it destroys the key securely and completely to prevent security risks caused by residual keys.

[0026] Preferably, the dynamic encryption layer includes an encryption algorithm selection unit and a dynamic encryption adjustment unit;

[0027] Encryption Algorithm Selection Unit: With the help of the integrated formal verification module, the most appropriate algorithm is selected from multiple encryption algorithms based on factors such as data type and security requirements;

[0028] Dynamic encryption adjustment unit: Dynamically adjust encryption parameters, encryption methods, etc. according to data access frequency, security situation, etc.

[0029] Preferably, the intelligent decryption layer includes a decryption request verification unit and a decryption execution unit;

[0030] Decryption request verification unit: uses TEE (Trusted Execution Environment) and MPC (Multi-Party Computing) multi-node verification technology to verify the legality and compliance of decryption requests submitted by users;

[0031] Decryption execution unit: After the decryption request is verified, it performs data decryption operations and converts the encrypted data into plain text for user use.

[0032] Preferably, the security audit and traceability layer includes an operation log recording unit, a security audit analysis unit and a traceability tracking unit;

[0033] Operation log recording unit: Using blockchain and IPFS decentralized storage technology, it records all data operations in the system in real time, including operation time, operation subject, operation content and other information;

[0034] Security audit analysis unit: Analyzes the data collected by the operation log recording unit to detect abnormal operations, safety hazards, etc.

[0035] Source tracing unit: traces the source of data operations and determines the responsible party based on operation logs and audit analysis results.

[0036] A method for encrypting and decrypting user private data, including the above-mentioned system for encrypting and decrypting user private data, and the operating steps are as follows:

[0037] Step 1: After the original data enters the system, it first reaches the data sovereignty layer. The identity authentication unit verifies the identity of the data owner. After confirmation, the permission management unit assigns the corresponding data operation permissions to the owner and adds the owner permission identifier.

[0038] Step 2: Data with owner permission identifiers enters the policy engine. The rule-making unit generates access policies for the data based on preset business rules and security policies. The policy adjustment unit can optimize and adjust the policies based on real-time conditions.

[0039] Step 3: The encryption algorithm selection unit uses the integrated formal verification module to select a suitable algorithm from multiple encryption algorithms based on data type and security requirements. The dynamic encryption adjustment unit further dynamically adjusts encryption parameters to complete the data encryption operation.

[0040] Step 4: The encrypted data is stored in the designated storage location;

[0041] Step 5: The user initiates a request to access the encrypted data;

[0042] Step 6: The access request enters the policy engine to verify whether the request complies with the previously established access policy;

[0043] Step 7: If the access request passes the policy verification, it enters the intelligent decryption layer. The decryption request verification unit uses TEE+MPC multi-node verification technology to verify the legitimacy of the decryption request. After the verification passes, the decryption execution unit performs the decryption operation and converts the encrypted data into plaintext.

[0044] Step 8: Regardless of whether the decryption successfully outputs the data or access is denied due to unsatisfied conditions, the relevant operations will enter the security audit and traceability layer. The operation log recording unit uses blockchain + IPFS decentralized storage technology to record operation information, the security audit analysis unit analyzes the operation log, and the traceability tracking unit can trace the source of the operation when necessary.

[0045] (3) Beneficial effects

[0046] Compared with the existing technology, the present invention provides a system and method for encrypting and decrypting user privacy data, which has the following beneficial effects:

[0047] 1. This system and method for encrypting and decrypting user privacy data protects user data privacy through collaboration at all levels, from data permission management to encryption and decryption, to prevent unauthorized access and use of data. Each level has a clear division of labor: the data sovereignty layer determines data ownership and access rights, the policy engine formulates access policies, the key management layer is responsible for key lifecycle management, the dynamic encryption layer implements encryption operations, the intelligent decryption layer processes decryption requests, and the security audit and traceability layer records audit information. This architecture enables each functional module of the system to perform its duties, facilitating development, maintenance, and management.

[0048] 2. This system and method for encrypting and decrypting user privacy data forms a multi-layer security protection system through data sovereignty confirmation, policy control, key management, encryption and decryption, and audit traceability. It ensures the security of data in storage, transmission, and use in multiple links, reduces the risks of data leakage and illegal access, enhances the overall security performance of the system, and achieves multi-layer protection, which is safe and reliable.

[0049] 3. This system and method for encrypting and decrypting user privacy data can dynamically adjust encryption strategies and access rules based on data characteristics, security requirements, etc. through a dynamic encryption layer and policy engine. The key management layer can also dynamically manage keys. This dynamic management mechanism allows the system to flexibly respond to different scenarios and changes, improving operational efficiency and adaptability.

[0050] 4. This system and method for encrypting and decrypting user privacy data records and analyzes data operations through security auditing and traceability layers. Once a security issue occurs, the source of the operation and the responsible party can be quickly traced, which helps to handle security incidents in a timely manner and improve security strategies. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] Figure 1 Schematic diagram of the system of the present invention;

[0052] Figure 2 This is a flow chart of the system of the present invention;

[0053] Figure 3 This is a schematic diagram of the data sovereignty layer of the present invention;

[0054] Figure 4 This is a schematic diagram of the strategy engine of the present invention;

[0055] Figure 5 This is a schematic diagram of the key management layer of the present invention;

[0056] Figure 6 This is a schematic diagram of the dynamic encryption layer of the present invention;

[0057] Figure 7 This is a schematic diagram of the intelligent decryption layer of the present invention;

[0058] Figure 8 Schematic diagram of the security audit and traceability layer of the present invention. DETAILED DESCRIPTION

[0059] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0060] See also Figure 1-8 A user privacy data encryption and decryption system includes a user privacy data encryption and decryption system body, which includes a data sovereignty layer, a policy engine, a key management layer, a dynamic encryption layer, an intelligent decryption layer, and a security audit and traceability layer;

[0061] Data sovereignty layer: Responsible for clarifying the rights and interests of data owners. Through identity authentication and rights management, it determines who owns the data and who has the authority to access and operate the data, thereby ensuring data ownership and control.

[0062] Policy engine: Develops and adjusts data access and processing policies. Policy rules are set by the rule-making unit, and the policy adjustment unit modifies them in real time based on actual conditions, ensuring that data access and operations meet business requirements and security specifications.

[0063] Key management layer: This layer covers the entire lifecycle of key generation, storage, distribution, update, and destruction. It uses post-quantum cryptography and other technologies to generate secure keys, and uses HSM and distributed key sharding technology to store keys, ensuring the security of keys at all stages.

[0064] Dynamic encryption layer: Selects the appropriate encryption algorithm and dynamically adjusts encryption parameters based on data characteristics and security requirements. It integrates a formal verification module to ensure the accuracy and security of the encryption algorithm selection.

[0065] Intelligent decryption layer: After receiving an access request, the decryption request verification unit first verifies the legitimacy of the request using technologies such as TEE+MPC multi-node verification. After the verification is passed, the decryption execution unit performs the decryption operation;

[0066] Security audit and traceability layer: The operation log recording unit uses blockchain + IPFS decentralized storage technology to record data operation logs, the security audit analysis unit analyzes the logs, and the traceability tracking unit is used to trace the source of the operation and the responsible party.

[0067] In the case implementation, the data sovereignty layer includes the identity authentication unit and the permission management unit;

[0068] Identity authentication unit: Verifies the user's true identity through biometric recognition, password verification, digital certificates and other technical means to determine whether the user is a legitimate visitor. Strict checkpoints are set at the data access entrance to prevent illegal users from impersonating legitimate users to access data, avoiding security risks such as data leakage and tampering. It is the primary barrier to ensure data security. Through multiple technical means to verify identity, improve the accuracy and reliability of identity authentication, and enhance user trust in system security.

[0069] Permission management unit: Allocate and manage user access rights to data, such as read, write, modify, and delete, based on user identity and business rules. Finely divide data operation permissions based on user identity and business rules to ensure that users can only operate on data within the authorized scope, avoid data integrity damage and loss of confidentiality due to abuse of permissions, and ensure that data is used within a legal and compliant framework.

[0070] Among them, the identity authentication unit can effectively resist identity fraud attacks, such as preventing hackers from illegally obtaining data access rights by stealing account passwords, etc., ensuring that only the real data owner or authorized user can enter the system's subsequent operation process. The permission management unit can realize differentiated permission management for different user roles. For example, ordinary employees, managers, administrators and other different roles in the enterprise have different access rights to internal enterprise data, ensuring the reasonable and orderly flow of data within the organization.

[0071] In the case implementation, the policy engine includes a rule formulation unit and a policy adjustment unit;

[0072] Rule-making unit: Develops data access and processing policy rules based on business needs, security regulations, and other factors. For example, it specifies the operational permissions of specific users for specific data within a specific time period. This establishes a rule system for data access and processing, ensuring that system operations have clear basis and guidelines, standardizing data operation processes, ensuring that data use complies with business objectives and security requirements, and preventing data security incidents and business violations from a system level.

[0073] Policy Adjustment Unit: Monitors the system operating environment, business demand changes, etc. in real time, and dynamically adjusts and optimizes the established policy rules to enable the system to have dynamic adaptability and respond promptly to changes in the external environment (such as updates to laws and regulations, evolution of security threats) and changes in internal business needs (such as business process restructuring, new business launches), ensuring that policy rules always conform to actual conditions and continuously provide effective protection for data security and normal business operations.

[0074] Among them, the rule-making unit can formulate different access strategies for different types of data (such as sensitive financial data, general business data, etc.), realize the classification and grading management of data, and improve the refinement and security of data management. When the enterprise expands new business areas, the policy adjustment unit can quickly adjust the data access strategy to ensure that the new business-related data can be accessed and processed under the premise of complying with security regulations and business needs.

[0075] In the case implementation, the key management layer includes the key generation unit, key storage unit, key distribution unit, key update unit and key destruction unit;

[0076] Key Generation Unit: This unit uses advanced technologies such as post-quantum cryptography to generate encryption keys, ensuring key security in quantum computing environments. It also uses post-quantum cryptography to generate keys, proactively defending against future threats to traditional cryptography from quantum computing. This provides a long-term, secure, and reliable key foundation for data encryption, ensuring data confidentiality in the quantum computing era.

[0077] Key storage unit: HSM (Hardware Security Module) combined with distributed key sharding technology is used to store keys to prevent them from being stolen or tampered with. Using HSM and distributed key sharding technology, keys are stored in a decentralized manner and protected by the hardware security module, effectively preventing keys from being stolen by external attacks or tampered with by internal personnel, ensuring the security of the key storage link and thus maintaining the security of the entire encryption system.

[0078] Key distribution unit: Safely and accurately distributes keys to legitimate users or devices to ensure that they can perform encryption and decryption operations normally. It is responsible for delivering keys safely and accurately to legitimate users or devices to ensure the smooth operation of encryption and decryption operations. It is the key link connecting key generation and use, ensuring that legitimate users can obtain keys in a timely manner to conduct business and maintain the normal operation of the system.

[0079] Key update unit: Updates keys in the system regularly or according to specific trigger conditions to enhance key security. By updating keys regularly or according to specific conditions, it increases the uncertainty and security of keys, reduces the risk of key cracking, responds to changes in security threats in a timely manner, and continuously ensures the effectiveness of data encryption.

[0080] Key destruction unit: When a key expires or is no longer used, it will be destroyed safely and completely to prevent the security risks caused by the residual key. After the key has completed its mission, it will be destroyed safely and completely to prevent the illegal use of the residual key, eliminate potential security risks, and ensure the security and integrity of the data encryption system.

[0081] Among them, post-quantum cryptography is a cryptographic technology that is resistant to quantum computing attacks. Traditional cryptographic algorithms may be quickly cracked under the powerful computing power of quantum computing. Post-quantum cryptography is based on algorithms constructed from mathematical problems such as lattice cryptography, hash cryptography, and multivariate cryptography. It can ensure the security and confidentiality of key generation even in the face of quantum computers.

[0082] An HSM (Hardware Security Module) is a hardware device specifically designed to protect and manage cryptographic keys. It provides a secure environment for key storage and related cryptographic operations through physical isolation, security chips, and other technical means. In terms of computing, an HSM can perform high-speed and secure encryption and decryption operations. For example, it uses built-in algorithms to encrypt and store keys, and quickly decrypts them when needed to provide them to legitimate users. The operation process is protected by hardware security mechanisms.

[0083] Distributed key sharding divides the complete key into multiple fragments and stores them in different nodes. Based on secret sharing algorithms such as the Shamir secret sharing scheme, these fragments alone cannot restore the key. Only when a sufficient number of fragments are collected can the key be reconstructed. This method increases the security of key storage and prevents key leakage due to the compromise of a single node.

[0084] In the case implementation, the dynamic encryption layer includes an encryption algorithm selection unit and a dynamic encryption adjustment unit;

[0085] Encryption Algorithm Selection Unit: With the help of an integrated formal verification module, the most appropriate algorithm is selected from a variety of encryption algorithms based on factors such as data type and security requirements. The integrated formal verification module rigorously verifies and analyzes multiple encryption algorithms. It evaluates the security, efficiency, and applicability of different algorithms based on factors such as data sensitivity, data type (such as text, image, video), and security requirements of the application scenario, ultimately selecting the algorithm that best meets the current data encryption needs.

[0086] Dynamic encryption adjustment unit: Dynamically adjusts encryption parameters and encryption methods based on data access frequency, security situation, and other conditions, and continuously monitors data access frequency. For example, frequent recent access to certain sensitive data may indicate a security risk. At the same time, it pays attention to security situations, such as the emergence of new attack methods or vulnerabilities in the network. Based on this monitoring information, it dynamically adjusts encryption parameters (such as key length, number of encryption rounds, etc.) and even switches encryption methods to adapt to the ever-changing security environment.

[0087] Among them, the encryption algorithm selection unit can ensure that the selected encryption algorithm can provide security protection of appropriate strength for the data, avoid insufficient or excessive data encryption due to improper algorithm selection, and cause waste of resources, and ensure the confidentiality of data during storage and transmission. The dynamic encryption adjustment unit can make the encryption process dynamically adaptable, able to respond to security threats in a timely manner, always maintain the effectiveness of data encryption, and prevent data leakage due to the cracking of static encryption methods.

[0088] In the case implementation, the intelligent decryption layer includes a decryption request verification unit and a decryption execution unit;

[0089] Decryption request verification unit: Utilizes TEE (Trusted Execution Environment) and MPC (Multi-Party Computing) multi-node verification technology to verify the legitimacy and compliance of decryption requests submitted by users. Utilizes the trusted execution environment provided by TEE to ensure that operations related to decryption requests are executed in a secure and isolated environment to prevent interference from malware or illegal programs. Combined with MPC multi-node verification technology, the legitimacy (such as whether the requester's identity is legal and whether they have the corresponding permissions, etc.) and compliance (whether they comply with data access policies, etc.) of decryption requests are verified on multiple nodes, and the reliability of verification results is improved through multi-node cross-verification.

[0090] Decryption execution unit: After the decryption request is verified, it performs data decryption operations and converts the encrypted data into plain text for the user to use. After the decryption request passes the legality and compliance verification of the verification unit, it performs data decryption operations based on the algorithm and key used in the previous encryption, and converts the encrypted ciphertext data into plain text data that the user can understand and use.

[0091] Among them, the decryption request verification unit can strictly control the entrance to data decryption, prevent illegal users or unauthorized users from submitting decryption requests, effectively prevent data from being illegally decrypted, and ensure data security. The decryption execution unit can realize the conversion of encrypted data into usable data, meet the legitimate users' access and use needs for data, and ensure data availability.

[0092] In the case implementation, the security audit and traceability layer includes the operation log recording unit, the security audit analysis unit and the traceability tracking unit;

[0093] Operation log recording unit: Using blockchain and IPFS decentralized storage technology, it records all data operation behaviors in the system in real time, including operation time, operation subject, operation content and other information. By utilizing the distributed ledger characteristics of blockchain and the content-addressed storage mechanism of IPFS, whenever data operation occurs in the system, such as data reading, writing, modification, and deletion, the unit will immediately capture the operation time, operation subject (such as user account, device identification, etc.), operation content (such as specific modified data fields, newly added data records, etc.), and other information, and record this information on the blockchain in the form of encrypted hash values. At the same time, the relevant operation log files are stored in the IPFS network. Due to the chain structure and encryption characteristics of the blockchain, the new record will be linked to the previous record, forming an unalterable operation log chain;

[0094] Security Audit Analysis Unit: Analyzes data collected by the operation log recording unit to detect abnormal operations and security risks. It continuously obtains recorded data from the operation log recording unit and uses data analysis algorithms and a security rule base to conduct in-depth analysis of the operation logs. By comparing normal operation patterns with abnormal behavior characteristics, it detects whether there are security risks such as unauthorized access, unauthorized operations, and frequent abnormal data modifications. For example, if a user is found to have performed abnormally frequent read operations on a large amount of sensitive data in a short period of time, which does not meet their normal business needs, an alert will be triggered.

[0095] Source tracing unit: Based on the operation log and audit analysis results, trace the source of data operations and determine the responsible party. After the security audit analysis unit detects an abnormal operation or a security incident, the source tracing unit conducts reverse tracing based on the information recorded in the operation log, such as operation timestamp, user identity, device network address and other clues, combined with the audit analysis results. Through multi-dimensional information correlation analysis, it determines the source of the data operation and clarifies which user, device or system module caused the relevant problem.

[0096] Among them, the operation log recording unit can provide a true, complete, and tamper-proof original data basis for security auditing and traceability, ensuring that all data operations can be traced. Once a security problem occurs, the operation process can be restored through these log records to provide a basis for subsequent analysis and responsibility determination. The security audit analysis unit can promptly discover potential security problems and illegal operations during system operation, and issue early warnings before or in the early stages of security incidents so that security management personnel can take measures quickly to reduce data security risks and ensure the stability and safety of the system. After a security incident occurs, the traceability tracking unit can quickly and accurately locate the responsible party, which helps to take timely remedial measures, such as banning illegal accounts and repairing system vulnerabilities. At the same time, it also provides a reference basis for subsequent security policy adjustments and improvements to prevent similar security incidents from happening again.

[0097] A method for encrypting and decrypting user private data, including the above-mentioned system for encrypting and decrypting user private data, and the operating steps are as follows:

[0098] Step 1: After the original data enters the system, it first reaches the data sovereignty layer. The identity authentication unit verifies the identity of the data owner. After confirmation, the permission management unit assigns the corresponding data operation permissions to the owner and adds the owner permission identifier.

[0099] Step 2: Data with owner permission identifiers enters the policy engine. The rule-making unit generates access policies for the data based on preset business rules and security policies. The policy adjustment unit can optimize and adjust the policies based on real-time conditions.

[0100] Step 3: The encryption algorithm selection unit uses the integrated formal verification module to select a suitable algorithm from multiple encryption algorithms based on data type and security requirements. The dynamic encryption adjustment unit further dynamically adjusts encryption parameters to complete the data encryption operation.

[0101] Step 4: The encrypted data is stored in the designated storage location;

[0102] Step 5: The user initiates a request to access the encrypted data;

[0103] Step 6: The access request enters the policy engine to verify whether the request complies with the previously established access policy;

[0104] Step 7: If the access request passes the policy verification, it enters the intelligent decryption layer. The decryption request verification unit uses TEE+MPC multi-node verification technology to verify the legitimacy of the decryption request. After the verification passes, the decryption execution unit performs the decryption operation and converts the encrypted data into plaintext.

[0105] Step 8: Regardless of whether the decryption successfully outputs the data or access is denied due to unsatisfied conditions, the relevant operations will enter the security audit and traceability layer. The operation log recording unit uses blockchain + IPFS decentralized storage technology to record operation information, the security audit analysis unit analyzes the operation log, and the traceability tracking unit can trace the source of the operation when necessary.

[0106] To sum up, the system and method for encrypting and decrypting user privacy data protects user data privacy through collaboration at all levels, from data permission management to encryption and decryption, to prevent unauthorized access and use of data. Each level has a clear division of labor: the data sovereignty layer determines data ownership and access rights, the policy engine formulates access policies, the key management layer is responsible for key lifecycle management, the dynamic encryption layer implements encryption operations, the intelligent decryption layer processes decryption requests, and the security audit and traceability layer records audit information. This architecture enables each functional module of the system to perform its duties, facilitating development, maintenance, and management.

[0107] In addition, through data sovereignty confirmation, policy control, key management, encryption and decryption, and audit tracing, a multi-layer security protection system is formed, which ensures the security of data in storage, transmission, and use in multiple links, reduces the risks of data leakage and illegal access, enhances the overall security performance of the system, and achieves multi-layer protection, which is safe and reliable. The dynamic encryption layer and policy engine can dynamically adjust encryption policies and access rules according to data characteristics, security requirements, etc. The key management layer can also dynamically manage keys. This dynamic management mechanism allows the system to flexibly respond to different scenarios and changes, improve operational efficiency and adaptability, and record and analyze data operations through security audits and traceability layers. Once a security problem occurs, the source of the operation and the responsible party can be quickly traced, which helps to handle security incidents in a timely manner and improve security policies.

[0108] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.

[0109] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.

Claims

1. A user privacy data encryption and decryption system, including a user privacy data encryption and decryption system body, characterized by: The user privacy data encryption and decryption system includes a data sovereignty layer, a policy engine, a key management layer, a dynamic encryption layer, an intelligent decryption layer, and a security audit and traceability layer. Data sovereignty layer: Responsible for clarifying the rights and interests of data owners. Through identity authentication and rights management, it determines who owns the data and who has the authority to access and operate the data, thereby ensuring data ownership and control. Policy engine: Develops and adjusts data access and processing policies. Policy rules are set by the rule-making unit, and the policy adjustment unit modifies them in real time based on actual conditions, ensuring that data access and operations meet business requirements and security specifications. Key management layer: This layer covers the entire lifecycle of key generation, storage, distribution, update, and destruction. It uses post-quantum cryptography and other technologies to generate secure keys, and uses HSM and distributed key sharding technology to store keys, ensuring the security of keys at all stages. Dynamic encryption layer: Selects the appropriate encryption algorithm and dynamically adjusts encryption parameters based on data characteristics and security requirements. It integrates a formal verification module to ensure the accuracy and security of the encryption algorithm selection. Intelligent decryption layer: After receiving an access request, the decryption request verification unit first verifies the legitimacy of the request using technologies such as TEE+MPC multi-node verification. After the verification is passed, the decryption execution unit performs the decryption operation; Security audit and traceability layer: The operation log recording unit uses blockchain + IPFS decentralized storage technology to record data operation logs, the security audit analysis unit analyzes the logs, and the traceability tracking unit is used to trace the source of the operation and the responsible party.

2. A system and method for encrypting and decrypting user private data according to claim 1, characterized in that: The data sovereignty layer includes an identity authentication unit and a rights management unit; Identity authentication unit: Verify the user's true identity and determine whether they are legitimate visitors through biometric recognition, password verification, digital certificates and other technical means; Permission management unit: Allocate and manage user access rights to data, such as read, write, modify, and delete permissions, based on user identity and business rules.

3. The user privacy data encryption and decryption system according to claim 1, characterized in that: The policy engine includes a rule formulation unit and a policy adjustment unit; Rule-making unit: Develops data access and processing policy rules based on business needs, security regulations, and other factors. For example, it specifies the operation permissions of specific users on specific data during a specific time period. Policy adjustment unit: monitors the system operating environment, business demand changes, etc. in real time, and dynamically adjusts and optimizes the established policy rules.

4. The user privacy data encryption and decryption system according to claim 1, characterized in that: The key management layer includes a key generation unit, a key storage unit, a key distribution unit, a key update unit and a key destruction unit; Key generation unit: uses advanced technologies such as post-quantum cryptography to generate encryption keys to ensure the security of keys in quantum computing environments; Key storage unit: HSM (hardware security module) combined with distributed key sharding technology is used to store keys to prevent the keys from being stolen or tampered with; Key distribution unit: safely and accurately distributes keys to legitimate users or devices to ensure they can perform encryption and decryption operations normally; Key update unit: updates the keys in the system regularly or according to specific trigger conditions to enhance key security; Key destruction unit: When a key expires or is no longer in use, it destroys the key securely and completely to prevent security risks caused by residual keys.

5. The user privacy data encryption and decryption system according to claim 1, characterized in that: The dynamic encryption layer includes an encryption algorithm selection unit and a dynamic encryption adjustment unit; Encryption Algorithm Selection Unit: With the help of the integrated formal verification module, the most appropriate algorithm is selected from multiple encryption algorithms based on factors such as data type and security requirements; Dynamic encryption adjustment unit: Dynamically adjust encryption parameters, encryption methods, etc. according to data access frequency, security situation, etc.

6. The user privacy data encryption and decryption system according to claim 1, characterized in that: The intelligent decryption layer includes a decryption request verification unit and a decryption execution unit; Decryption request verification unit: uses TEE (Trusted Execution Environment) and MPC (Multi-Party Computing) multi-node verification technology to verify the legality and compliance of decryption requests submitted by users; Decryption execution unit: After the decryption request is verified, it performs data decryption operations and converts the encrypted data into plain text for user use.

7. The user privacy data encryption and decryption system according to claim 1, characterized in that: The security audit and traceability layer includes an operation log recording unit, a security audit analysis unit, and a traceability tracking unit; Operation log recording unit: Using blockchain and IPFS decentralized storage technology, it records all data operations in the system in real time, including operation time, operation subject, operation content and other information; Security audit analysis unit: Analyzes the data collected by the operation log recording unit to detect abnormal operations, safety hazards, etc. Source tracing unit: traces the source of data operations and determines the responsible party based on operation logs and audit analysis results.

8. A method for encrypting and decrypting user private data, comprising the system for encrypting and decrypting user private data according to claims 1-7, characterized in that: The steps are as follows: Step 1: After the original data enters the system, it first reaches the data sovereignty layer. The identity authentication unit verifies the identity of the data owner. After confirmation, the permission management unit assigns the corresponding data operation permissions to the owner and adds the owner permission identifier. Step 2: Data with owner permission identifiers enters the policy engine. The rule-making unit generates access policies for the data based on preset business rules and security policies. The policy adjustment unit can optimize and adjust the policies based on real-time conditions. Step 3: The encryption algorithm selection unit uses the integrated formal verification module to select a suitable algorithm from multiple encryption algorithms based on data type and security requirements. The dynamic encryption adjustment unit further dynamically adjusts encryption parameters to complete the data encryption operation. Step 4: The encrypted data is stored in the designated storage location; Step 5: The user initiates a request to access the encrypted data; Step 6: The access request enters the policy engine to verify whether the request complies with the previously established access policy; Step 7: If the access request passes the policy verification, it enters the intelligent decryption layer. The decryption request verification unit uses TEE+MPC multi-node verification technology to verify the legitimacy of the decryption request. After the verification passes, the decryption execution unit performs the decryption operation and converts the encrypted data into plaintext. Step 8: Regardless of whether the decryption successfully outputs the data or access is denied due to unsatisfied conditions, the relevant operations will enter the security audit and traceability layer. The operation log recording unit uses blockchain + IPFS decentralized storage technology to record operation information, the security audit analysis unit analyzes the operation log, and the traceability tracking unit can trace the source of the operation when necessary.

Citation Information

Cited By

  • Workflow authority control method and system based on quantum encryption mechanism

    CN121150950A