Homomorphic encryption-based security assurance system for big data computation and analysis

By combining data feature extraction, knowledge base-driven encryption, triple simulation computation, and verifiable decryption, this approach solves the problems of missing integrity verification of ciphertext computation results and malicious tampering in homomorphic encrypted big data computation, enabling real-time detection and defense, and constructing a trusted computing environment.

CN120729502BActive Publication Date: 2025-12-09CHINA ACADEMY OF INFORMATION & COMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511179146.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-22
Publication Date
2025-12-09
Estimated Expiration
2045-08-22

AI Technical Summary

Technical Problem

In the process of big data computing and analysis based on homomorphic encryption, the lack of effective mechanisms to verify the integrity of ciphertext computing results and defend against malicious tampering leads to the possibility that the computing output may be modified without being detected, threatening the credibility and security of data analysis.

Method used

By employing a combination of a data feature extraction module, a knowledge base-driven encryption module, a triple simulation calculation module, an arbitration verification module, and a verifiable decryption module, a multi-level verification protocol and zero-knowledge scope proof are achieved by generating a homomorphic evolutionary signature structure that can track the ciphertext operation state, ensuring the integrity and security of the calculation process.

Benefits of technology

It effectively prevents undetected intermediate tampering, detects and isolates malicious injection or computational failures in real time, and builds a closed-loop trusted computing environment. It solves the problems of lack of integrity verification of ciphertext computation results and defense against malicious tampering in homomorphic encryption scenarios, while maintaining the confidentiality of encryption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120729502B_ABST
    Figure CN120729502B_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of data processing, and more particularly to a big data computing and analysis security guarantee system based on homomorphic encryption, comprising a data feature extraction module for generating a structured feature label; a knowledge base driven encryption module for generating a homomorphic evolution signature structure ciphertext with traceable ciphertext operation state; a triple simulation calculation module for outputting three sets of calculation results; an arbitration verification module for executing a multi-level provable verification protocol based on the evolved signature structure, checking data structure integrity, constraint calculation result consistency and analysis vector similarity, and outputting a ciphertext with trusted credentials or an error code; a verifiable decryption module for analyzing the trusted credentials to generate an attribute-based decryption key, performing homomorphic decryption, and then generating an auditable result using zero-knowledge range proof technology and returning the authorized terminal. The dynamic evolution of the signature structure provides calculation process integrity evidence, multi-path cross verification realizes real-time tampering detection, and the auditable result completes end-to-end verification closed loop.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data processing, and in particular to a homomorphic encryption-based big data computing and analysis security guarantee system. BACKGROUND

[0002] Big data computing and analysis faces significant privacy leakage risks when processing massive sensitive information, and needs advanced technology to protect user data confidentiality. A homomorphic encryption scheme provides a solution by allowing direct execution of predetermined mathematical operations on ciphertext. After encryption data is subjected to addition and multiplication operations, the decrypted result is completely consistent with the original plaintext calculation result. Therefore, a third-party computing platform can efficiently deploy complex machine learning or statistical analysis tasks without exposing or decrypting the underlying data content, thus achieving coexistence of privacy protection and computing function in principle and significantly reducing security threats in the data processing process.

[0003] The homomorphic encryption-based big data computing and analysis has the following pain points in security guarantee, i.e., lack of built-in integrity protection mechanism in the process of executing ciphertext computing. The focus of the homomorphic encryption scheme design is to maintain the encrypted state of data during operation to maintain confidentiality, but it does not provide an effective way to verify the correctness of the calculation result or detect malicious tampering behavior, resulting in unauthorized modification of the calculation output without being identified, threatening the credibility and security of data analysis. For example, when executing a clustering algorithm based on homomorphic encryption in a distributed data storage system, if an attacker injects incorrect ciphertext to modify sample point coordinates on the transmission path, it will significantly change the cluster center position and final grouping result. Since the system lacks integrity and consistency verification mechanisms for intermediate ciphertext state and output value, such tampering is difficult to be discovered and defended in real time. SUMMARY

[0004] In view of the deficiencies of the prior art, the present application provides a homomorphic encryption-based big data computing and analysis security guarantee system to solve the technical problem of being unable to effectively verify the integrity of ciphertext calculation results and defend against malicious tampering in the process of homomorphic encryption-based big data computing and analysis.

[0005] To solve the above technical problems, the specific technical solutions of the present application are as follows:

[0006] The homomorphic encryption-based big data computing and analysis security guarantee system provided by the present application comprises:

[0007] The data feature extraction module obtains original data from an external data source, extracts the dimension distribution, time series features and spatial correlation features of the original data, and outputs the structured feature labels generated by the data feature extraction module, including the dimension distribution, time series features and spatial correlation features;

[0008] The knowledge base driven encryption module receives the structured feature label output by the data feature extraction module, matches the corresponding homomorphic encryption strategy from the preset encryption knowledge base, and generates ciphertext with a homomorphic evolution signature structure that can track the operation state of the ciphertext;

[0009] The triple simulation calculation module receives the ciphertext and the homomorphic evolution signature structure output by the knowledge base driven encryption module, and outputs the main calculation path calculation result, the equivalent verification path calculation result and the lightweight pre-judgment path calculation result through the main calculation path, the equivalent verification path and the lightweight pre-judgment path respectively, and the triple simulation calculation module triggers the synchronous evolution of the homomorphic evolution signature structure;

[0010] The arbitration verification module receives the main calculation path calculation result, the equivalent verification path calculation result and the lightweight pre-judgment path calculation result and the evolved homomorphic evolution signature structure output by the triple simulation calculation module, executes a multi-level provable verification protocol, generates a trusted credential, and outputs the ciphertext with the trusted credential or an error code;

[0011] The verifiable decryption module receives the ciphertext with the trusted credential output by the arbitration verification module, parses the attribute access policy recorded in the trusted credential, generates an attribute-based decryption key according to the attribute access policy, performs homomorphic decryption on the ciphertext with the trusted credential using the attribute-based decryption key, obtains plaintext data, generates zero-knowledge range proof based on the cluster center coordinates in the plaintext data, combines the plaintext data and the zero-knowledge range proof into an auditable result, and returns to the authorized terminal.

[0012] Further, the big data calculation and analysis security guarantee system based on homomorphic encryption provided by the application comprises:

[0013] The data capture unit collects the original data of the external data source through a database protocol and an API interface;

[0014] The real-time feature analysis engine performs principal component analysis on the original data to calculate the sparsity ratio, detects periodicity by using the dynamic time warping algorithm, and calculates the spatial grid distribution by using the Geohash encoding;

[0015] The label encoder converts the analysis result into a structured feature label in the format of [data type_dimension number_sensitivity level].

[0016] Further, the big data calculation and analysis security guarantee system based on homomorphic encryption provided by the application comprises:

[0017] The core layer stores the polynomial order and modulus parameters of the homomorphic encryption scheme;

[0018] The strategy layer constructs a decision tree model to map the structured feature label to the encryption strategy ID;

[0019] Example layer, record history encryption ciphertext inflation rate and calculate delay index;

[0020] Wherein, the knowledge base driven encryption module responds to the structured feature label as high-dimensional financial transaction matrix_3000-dimensional_LEVEL3, loads the lattice encryption parameter and constructs the depth of 5 Merkle tree structure as the component part of the homomorphic evolution signature structure of the traceable ciphertext operation state.

[0021] Further, the homomorphic encryption-based big data calculation and analysis security guarantee system disclosed by the application is configured that the threefold simulation calculation module is configured to:

[0022] The main calculation path executes the ciphertext K-means clustering algorithm, and updates the hash value of the third layer of the Merkle tree in the homomorphic evolution signature structure of the traceable ciphertext operation state;

[0023] The equivalent verification path runs the simplified clustering algorithm after performing PCA dimension reduction on the ciphertext, and compresses the BLS accumulation tree in the homomorphic evolution signature structure of the traceable ciphertext operation state to a 3-layer structure;

[0024] The lightweight pre-judgment path adopts homomorphic hash binning to count a histogram, and only retains the top layer signature of the BLS accumulation tree in the homomorphic evolution signature structure of the traceable ciphertext operation state;

[0025] The evolution of the homomorphic evolution signature structure is that the leaf hash value of the Merkle tree in the homomorphic evolution signature structure of the traceable ciphertext operation state is recalculated with the update of the clustering center.

[0026] Further, the homomorphic encryption-based big data calculation and analysis security guarantee system disclosed by the application further comprises:

[0027] The main calculation path maps the data block to the leaf node of the Merkle tree in the homomorphic evolution signature structure of the traceable ciphertext operation state when initializing the homomorphic addition calculation clustering center;

[0028] The binning granularity of the lightweight pre-judgment path determines the hierarchical compression ratio of the BLS accumulation tree in the homomorphic evolution signature structure of the traceable ciphertext operation state corresponding to the equivalent verification path.

[0029] Further, the homomorphic encryption-based big data calculation and analysis security guarantee system disclosed by the application, the multi-level provable verification protocol executed by the arbitration verification module comprises:

[0030] The depth of the Merkle tree in the homomorphic evolution signature structure of the traceable ciphertext operation state is equal to the preset value, and the hierarchical level of the BLS accumulation tree in the homomorphic evolution signature structure of the traceable ciphertext operation state corresponding to the equivalent verification path is within the threshold interval;

[0031] The cluster center distance difference of the main calculation path and the equivalent verification path is constructed to be less than or equal to delta, and a proof byte stream is generated by zk-STARK;

[0032] The cosine similarity of the three result vectors of the main calculation path calculation result, the equivalent verification path calculation result and the lightweight pre-judgment path calculation result is calculated, and when the similarity is less than 0.85, the node isolation is triggered.

[0033] Further, the homomorphic encryption-based big data calculation and analysis security guarantee system can verify the decryption module configured to:

[0034] The attribute-based key generator analyzes the binding relationship strategy of the trusted credential record, and binds the system preset master private key to generate a decryption key.

[0035] The zero-knowledge proof generator generates a range proof of the cluster center coordinates in the main calculation path calculation result using the Bulletproofs protocol, and the proof length is compressed to a logarithmic level.

[0036] Further, the homomorphic encryption-based big data calculation and analysis security guarantee system further comprises:

[0037] The data feature extraction module outputs to the knowledge base driven encryption module: Avro format encapsulates the original data and structured feature labels.

[0038] The triple simulation calculation module outputs to the arbitration verification module: Protobuf encodes the main calculation path calculation result, the equivalent verification path calculation result, the lightweight pre-judgment path calculation result and the homomorphic evolution signature structure ASN.1 descriptor.

[0039] The arbitration verification module outputs to the verifiable decryption module: CBOR encapsulates the ciphertext with trusted credentials and the zk-STARK proof byte stream.

[0040] Further, the homomorphic encryption-based big data calculation and analysis security guarantee system further comprises:

[0041] The structured feature label driven knowledge base driven encryption module dynamically selects the encryption strategy;

[0042] The homomorphic evolution signature structure maintains the integrity of the signature evolution chain in the main calculation path, the equivalent verification path and the lightweight pre-judgment path calculation process.

[0043] The zk-STARK protocol converts the multi-level provable verification protocol into a provable calculation problem.

[0044] The attribute-based decryption and zero-knowledge range proof construct the auditable evidence chain between the arbitration verification module and the verifiable decryption module.

[0045] Further, the homomorphic encryption-based big data computing and analysis security guarantee system provided by the application further comprises:

[0046] The external data source comprises a relational database and a streaming data platform.

[0047] The auditable result output by the verifiable decryption module is returned to the authorized terminal, comprising decrypted plaintext data and a cluster center coordinate range proof.

[0048] Advantages of the application

[0049] The homomorphic evolution signature structure capable of tracing the operation state of ciphertext dynamically maintains the integrity of the computing process, the structure synchronously evolves the Merkle tree hash value and the BLS accumulation tree state in the main computing path, the equivalent verification path and the lightweight pre-judgment path execution, forms a real-time evidence chain covering the whole computing life cycle, effectively prevents intermediate tampering from being discovered, the multi-path cross verification mechanism of the arbitration verification module verifies the integrity of the signature structure through hierarchical checking, the consistency of the arithmetic circuit constraint result, and the cosine similarity of the three-path result vector, realizes real-time detection and isolation of malicious injection or computing failure, and finally the final auditable result set is combined with the homomorphic decryption plaintext data and the zero-knowledge range proof generated by the bulletproof proof protocol, the authorized terminal can backtrack the attribute access policy compliance and verify the numerical boundary, the dynamic signature evolution, multi-level real-time verification and end-to-end auditable evidence chain cooperatively build a closed-loop trusted computing environment, systematically solve the technical problems of ciphertext computing result integrity verification and malicious tampering prevention in the homomorphic encryption scene, and maintain the encryption confidentiality feature. BRIEF DESCRIPTION OF DRAWINGS

[0050] In order to more clearly illustrate the technical solutions of the application, the following will briefly introduce the drawings needed in the embodiments. Obviously, for those skilled in the art, other drawings can also be obtained from the drawings without creative labor.

[0051] Figure 1 The system architecture diagram of the homomorphic encryption-based big data computing and analysis security guarantee system provided by the embodiment of the application. DETAILED DESCRIPTION

[0052] In order to make the objects, technical solutions and advantages of the present application clearer, the technical solutions of the present application will be described clearly and completely below in combination with specific embodiments of the present application and corresponding drawings. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the present application. The technical solutions provided by the embodiments of the present application will be described in detail below in combination with the drawings. In order to better understand the objects of the present application, the present application will be further described in detail below.

[0053] Please refer to Figure 1 The present application provides a big data computing and analysis security guarantee system based on homomorphic encryption, comprising:

[0054] A data feature extraction module acquires original data from an external data source, extracts dimension distribution, time sequence features and spatial correlation features of the original data, and outputs structured feature labels including the dimension distribution, time sequence features and spatial correlation features generated by the data feature extraction module;

[0055] A knowledge base driven encryption module receives the structured feature labels output by the data feature extraction module, matches corresponding homomorphic encryption strategies from a preset encryption knowledge base, and generates ciphertext with a homomorphic evolution signature structure and a traceable ciphertext operation state;

[0056] A triple simulation calculation module receives the ciphertext and the homomorphic evolution signature structure output by the knowledge base driven encryption module, respectively outputs main calculation path calculation results, equivalent verification path calculation results and lightweight prediction path calculation results through a main calculation path, an equivalent verification path and a lightweight prediction path, and triggers synchronous evolution of the homomorphic evolution signature structure;

[0057] An arbitration verification module receives the main calculation path calculation results, the equivalent verification path calculation results and the lightweight prediction path calculation results output by the triple simulation calculation module and the evolved homomorphic evolution signature structure, executes a multi-level provable verification protocol, generates a trusted credential, and outputs ciphertext with the trusted credential or an error code;

[0058] A verifiable decryption module receives the ciphertext with the trusted credential output by the arbitration verification module, parses the attribute access policy recorded in the trusted credential, generates an attribute-based decryption key according to the attribute access policy, performs homomorphic decryption on the ciphertext with the trusted credential using the attribute-based decryption key, obtains plaintext data, generates a zero-knowledge range proof based on the cluster center coordinates in the plaintext data, combines the plaintext data and the zero-knowledge range proof into an auditable result, and returns to an authorized terminal.

[0059] The data feature extraction module obtains raw data from an external data source, and collects the raw data through a data capture unit. The data capture unit uses a database protocol and an application program interface to realize multi-source data access. A real-time feature analysis engine performs principal component analysis on the raw data to calculate dimensionally sparse features, uses a dynamic time warping algorithm to identify periodic features of time series, and uses a geographic hash coding technique to extract spatial grid distribution features. A label encoder integrates the dimensionally distributed features, time series features, and spatial correlation features into a structured feature label. The structured feature label is encoded in a triple format of data type, dimension number, and sensitivity level, and output to a knowledge base driven encryption module. This step provides a data feature basis for subsequent encryption operations.

[0060] After receiving the structured feature label, the knowledge base driven encryption module queries the core layer, strategy layer, and instance layer of the preset encryption knowledge base. The core layer stores homomorphic encryption polynomial order and modulus parameters. The strategy layer maps the structured feature label to an encryption strategy identifier through a decision tree model. The instance layer records historical encryption ciphertext inflation rate and calculation delay indicators. After matching is completed, the module loads corresponding encryption strategy parameters to generate a ciphertext with a homomorphically evolving signature structure of traceable ciphertext operation status. The homomorphically evolving signature structure of traceable ciphertext operation status includes a Merkle tree and a BLS accumulation tree component. The depth of the Merkle tree is dynamically configured according to the feature label. The ciphertext is output to a triple simulation calculation module. This step realizes feature-driven adaptive encryption.

[0061] After receiving the ciphertext and the homomorphically evolving signature structure of traceable ciphertext operation status, the triple simulation calculation module processes in parallel through a main calculation path, an equivalent verification path, and a lightweight prediction path. The main calculation path executes a ciphertext K-means clustering algorithm, and updates the Merkle tree leaf node hash value in the homomorphically evolving signature structure of traceable ciphertext operation status to reflect changes in the cluster center. The equivalent verification path runs a simplified clustering algorithm after performing principal component analysis dimension reduction operation on the ciphertext, and compresses the BLS accumulation tree hierarchical structure in the homomorphically evolving signature structure of traceable ciphertext operation status. The lightweight prediction path uses a homomorphic hash technology to box and count a data histogram, and only retains the top layer signature of the BLS accumulation tree in the homomorphically evolving signature structure of traceable ciphertext operation status. The three paths respectively output the main calculation path calculation result, the equivalent verification path calculation result, and the lightweight prediction path calculation result to an arbitration verification module, and simultaneously trigger the homomorphically evolving signature structure of traceable ciphertext operation status to evolve and maintain integrity.

[0062] The arbitration verification module receives the main computing path calculation result, the equivalent verification path calculation result, the lightweight pre-judgment path calculation result and the homomorphic evolution signature structure of the evolved traceable ciphertext operation state, and executes a multi-level provable verification protocol. The first level checks the consistency of the depth of the Merkle tree of the homomorphic evolution signature structure of the traceable ciphertext operation state with the preset value, and simultaneously verifies whether the BLS accumulation tree level in the corresponding structure of the equivalent verification path is in the effective interval. The second level constructs an arithmetic circuit to constrain the distance difference threshold of the clustering center coordinates of the main computing path and the equivalent verification path, and generates a proof byte stream through a zero-knowledge succinct non-interactive knowledge argument protocol. The third level calculates the direction similarity index of the three groups of vectors of the main computing path calculation result, the equivalent verification path calculation result and the lightweight pre-judgment path calculation result, and activates the node isolation mechanism when the similarity is lower than the threshold. If the verification is passed, the ciphertext with the trusted credential is output to the verifiable decryption module, and if the verification fails, an error code is returned.

[0063] After the verifiable decryption module receives the ciphertext with the trusted credential, the attribute-based key generator parses the attribute access policy recorded in the trusted credential, and binds the system main private key to generate an attribute-based decryption key. The module uses the attribute-based decryption key to perform homomorphic decryption operation on the ciphertext to obtain plaintext data, the zero-knowledge prover extracts the clustering center coordinates in the plaintext data, and applies a bulletproof proof protocol to generate a zero-knowledge range proof of compressed logarithmic length. Finally, the module combines the plaintext data and the zero-knowledge range proof into an auditable result and returns it to the authorized terminal. This step builds an end-to-end evidence chain from decryption verification to result auditing.

[0064] Specifically, the big data computing and analysis security guarantee system based on homomorphic encryption disclosed in the present application comprises:

[0065] A data capture unit acquires original data of external data sources through a database protocol and an API interface;

[0066] A real-time feature analysis engine performs principal component analysis on the original data to calculate a sparse ratio, detects periodicity through a dynamic time warping algorithm, and calculates a spatial grid distribution through Geohash encoding;

[0067] A label encoder converts the analysis result into a structured feature label in the format of [data type dimension number sensitivity level].

[0068] The data capture unit acquires original data of external data sources through a standard database connection protocol and an application program interface. A relational database uses a JDBC or ODBC protocol to establish a connection and execute a structured query to obtain batch data. A streaming data platform receives a data stream in real time through a Kafka or Pulsar message subscription interface. This unit realizes unified access of multi-source heterogeneous data and provides original input for feature analysis.

[0069] The real-time feature analysis engine performs three-dimensional feature extraction on the original data: the principal component analysis algorithm calculates the variance contribution rate between feature dimensions to identify the sparse feature distribution of high-dimensional data; the dynamic time warping algorithm aligns the time series waveform to detect the periodic fluctuation pattern of transaction records or sensor data; the Geohash encoding converts latitude and longitude coordinates into a string prefix matching spatial grid to analyze the geographical location clustering feature. The three types of feature quantization data have inherent properties, forming a set of computable indicators.

[0070] The label encoder receives the dimension sparsity of the principal component analysis output, the periodic intensity coefficient of the dynamic time warping output, and the spatial grid distribution density of the Geohash encoding output, and fuses the three types of indicators into machine-readable structured feature labels. The structured feature label adopts a [data type dimension number sensitivity level] triple format, the data type field identifies categories such as financial transaction matrices or Internet of Things time series data, the dimension number field records the feature vector length, and the sensitivity level field sets a hierarchical identification according to data regulations. The structured feature label is output to the knowledge base driven encryption module to drive subsequent adaptive encryption strategy selection.

[0071] The multi-protocol access capability of the data capture unit solves the problem of multi-source data acquisition; the real-time feature analysis engine quantizes the data dimension distribution, time characteristics and spatial correlation features through PCA dimension reduction, DTW period detection and Geohash spatial encoding algorithms; the label encoder encodes the three types of feature indicators into standardized structured feature labels to form the basis for encryption strategy selection. The module forms a technical closed loop of "original data, feature quantization, label encoding" to provide data feature perception for the system.

[0072] Specifically, the homomorphic encryption-based big data computing and analysis security guarantee system disclosed by the present application comprises:

[0073] The core layer stores the polynomial order and modulus parameters of the homomorphic encryption scheme;

[0074] The strategy layer constructs a decision tree model to map structured feature labels to encryption strategy IDs;

[0075] The instance layer records historical encryption ciphertext inflation rate and calculation delay indicators;

[0076] Among them, the knowledge base driven encryption module responds to the structured feature label being high-dimensional financial transaction matrix_3000 dimensions_LEVEL3, loads the lattice encryption parameter and constructs a Merkle tree structure with a depth of 5 as a component of the homomorphic evolution signature structure of the traceable ciphertext operation state.

[0077] The core layer is a bottom parameter library of the encrypted knowledge base, and stores core mathematical parameters of the homomorphic encryption scheme. The parameters include basic numerical values such as polynomial ring order and modulus. The polynomial ring order determines the algebraic structure complexity of the ciphertext operation, and the modulus controls the numerical value range of the ciphertext and the noise growth boundary. The core layer parameters provide the mathematical basis for the encryption strategy for the strategy layer, and also constrain the operation feasibility of the encryption instance. When the knowledge base driven encryption module loads the encryption strategy, the core layer parameters are necessary conditions for the initialization of the encryption algorithm, and directly affect the security strength and calculation efficiency of the ciphertext.

[0078] The strategy layer constructs a decision tree model to realize dynamic mapping of the structured feature label to the encryption strategy identifier. The decision tree model takes three fields of the structured feature label as input branches: the data type field determines the encryption scheme type (such as lattice-based encryption or integer encryption), the dimension number field controls the polynomial order selection threshold, and the sensitive level field adjusts the modulus security strength level. The decision tree matches the feature label layer by layer through a pre-defined rule set, and outputs a unique encryption strategy identifier. The identifier triggers the loading of the corresponding parameters of the core layer, and at the same time associates the historical performance record of the instance layer, forming a closed-loop decision chain of “feature input→strategy matching→parameter loading”.

[0079] The instance layer records the performance indicators of the historical encryption operation, including the ciphertext inflation rate and the calculation delay. The ciphertext inflation rate reflects the data volume growth ratio after encryption, and the calculation delay records the encryption operation time overhead. The instance layer data continuously optimizes the mapping rules of the decision tree model through a dynamic updating mechanism, for example, when the ciphertext inflation rate of a specific encryption strategy exceeds the threshold when detecting high-dimensional data, the decision tree will automatically reduce the priority of the strategy. In a specific execution scenario, when the structured feature label is a high-dimensional financial transaction matrix type with a dimension of 3000 and the sensitive level is LEVEL3, the knowledge base driven encryption module loads the lattice-based encryption parameters according to the output of the strategy layer, and simultaneously constructs a Merkle tree structure with a depth of 5 as the basic framework of the homomorphic evolution signature structure for tracing the operation state of the ciphertext. The leaf nodes of the Merkle tree store data block hash values, and the non-leaf nodes maintain the integrity of the operation state of the ciphertext. This structure is dynamically evolved with the ciphertext operation in the subsequent triple simulation calculation module.

[0080] Specifically, the big data calculation and analysis security guarantee system based on homomorphic encryption according to the present application is configured as follows:

[0081] The main calculation path executes the K-means clustering algorithm in the ciphertext state, and updates the hash value of the third layer of the Merkle tree in the homomorphic evolution signature structure for tracing the operation state of the ciphertext;

[0082] The equivalent verification path runs the simplified clustering algorithm after performing PCA dimension reduction on the ciphertext, and compresses the BLS accumulation tree in the homomorphic evolution signature structure for tracing the operation state of the ciphertext to a 3-layer structure.

[0083] The lightweight prediction path adopts a homomorphic hash binning statistical histogram, and only retains the top-layer signature of the BLS accumulation tree in the homomorphic evolution signature structure of the traceable ciphertext operation state;

[0084] The evolution of the homomorphic evolution signature structure is that the Merkle tree leaf hash value in the homomorphic evolution signature structure of the traceable ciphertext operation state is recalculated with the update of the cluster center.

[0085] After receiving the ciphertext and the homomorphic evolution signature structure of the traceable ciphertext operation state output by the knowledge base driven encryption module, the triple simulation calculation module processes data in parallel through the main calculation path, the equivalent verification path and the lightweight prediction path. The main calculation path executes the K-means clustering algorithm in the ciphertext state, which iteratively calculates the cluster center coordinates; each time the cluster center is updated, the Merkle tree leaf node hash value in the homomorphic evolution signature structure of the traceable ciphertext operation state is recalculated, and is updated to the third layer intermediate hash node layer by layer, and the change of the third layer hash value of the Merkle tree directly reflects the change of the data block attribution, providing real-time integrity evidence for subsequent verification. The path outputs the main calculation path calculation result to the arbitration verification module, and synchronizes the signature structure state and the calculation progress.

[0086] The equivalent verification path performs principal component analysis dimension reduction operation on the input ciphertext, reduces the data dimension to optimize the calculation efficiency; after dimension reduction, a simplified clustering algorithm is run to generate an approximate clustering result. In this process, the BLS accumulation tree hierarchical structure in the traceable ciphertext operation state of the homomorphic evolution signature structure is compressed to three layers, and the BLS accumulation tree hierarchical compression is dynamically adjusted based on the dimension reduction ratio, and key accumulator nodes are retained to support fast verification. The path outputs the equivalent verification path calculation result to the arbitration verification module, and forms the basis for cross-checking with the main calculation path.

[0087] The lightweight prediction path adopts a homomorphic hash technique to box the ciphertext data and count the histogram features, and the binning operation divides the data distribution interval according to the preset granularity and counts the number of samples in each interval. This path only retains the top-layer signature of the BLS accumulation tree in the homomorphic evolution signature structure of the traceable ciphertext operation state, the top-layer signature aggregates the bottom-layer data hash value digest, and reduces the storage and transmission overhead. This path outputs the lightweight prediction path calculation result to the arbitration verification module, and provides a fast reference index for anomaly detection.

[0088] The evolution process of the homomorphic evolution signature structure traceable to the ciphertext operation state is driven by three paths: the Merkle tree leaf hash value is recalculated with the main calculation path cluster center coordinate update to ensure data change traceability; the BLS accumulation tree level is compressed by the equivalent verification path dimension reduction operation to balance verification efficiency and accuracy; and the lightweight prediction path binning statistics determines the BLS accumulation tree signature retention strategy to optimize resource utilization. The signature structure evolution maintains the state consistency of the whole calculation period, and the three-path output results and the evolved signature structure are jointly input into the arbitration verification module to build a multi-level verification basis.

[0089] Specifically, the homomorphic encryption-based big data calculation and analysis security guarantee system also includes:

[0090] The main calculation path maps the data blocks to the Merkle tree leaf nodes in the homomorphic evolution signature structure traceable to the ciphertext operation state when initializing the homomorphic addition calculation cluster center.

[0091] The binning granularity of the lightweight prediction path determines the BLS accumulation tree level compression ratio in the homomorphic evolution signature structure traceable to the ciphertext operation state corresponding to the equivalent verification path.

[0092] The main calculation path divides the original data into fixed-size logical block units when initializing the homomorphic addition calculation cluster center. Each data block unit is mapped to a Merkle tree leaf node position in the homomorphic evolution signature structure traceable to the ciphertext operation state, and a one-to-one correspondence is formed between the data block unit and the Merkle tree leaf node. The Merkle tree leaf node stores the hash digest value of the corresponding data block unit, which is generated based on the sample point coordinates in the data block unit. The mapping operation establishes the underlying association between the data entity and the signature structure, and provides a data structure basis for the dynamic evolution of the Merkle tree hash value during the iterative update of the cluster center.

[0093] The binning granularity parameter defines the division accuracy of the data distribution interval when the lightweight prediction path performs the homomorphic hash binning statistics operation. The binning granularity parameter is dynamically configured according to the data characteristics, and the granularity value determines the number and width of the histogram statistics intervals. The binning granularity parameter is also input as a control signal into the equivalent verification path, directly determining the BLS accumulation tree level compression ratio in the homomorphic evolution signature structure traceable to the ciphertext operation state corresponding to the equivalent verification path. When the binning granularity value increases, the BLS accumulation tree level compression ratio is also increased, and the accumulation tree retention level is reduced; when the binning granularity value decreases, the level compression ratio is reduced, and the accumulation tree retention level is increased. This mechanism realizes the collaborative optimization of resource allocation between the lightweight prediction path and the equivalent verification path.

[0094] The data block mapping of the main computing path provides initial leaf node data for the Merkle tree of the homomorphic evolution signature structure that can track the ciphertext operation state, so that the Merkle tree can track the state change at the granularity of the ciphertext data block. The binning granularity parameter of the lightweight prediction path controls the balance between the calculation verification overhead and the accuracy of the equivalent verification path by adjusting the BLS accumulation tree level compression ratio. The cooperative operation of the two paths on the homomorphic evolution signature structure of the traceable ciphertext operation state forms a technical closed loop: the Merkle tree leaf node is initialized based on the data block of the main computing path, the BLS accumulation tree level is dynamically controlled by the binning granularity of the lightweight prediction path, and the signature structure evolution process synchronously supports the integrity maintenance requirements of the three paths.

[0095] The homomorphic evolution signature structure of the traceable ciphertext operation state reflects the change of the cluster center coordinate of the main computing path through the Merkle tree leaf node hash update, adapts to the dimension reduction calculation requirement of the equivalent verification path through the BLS accumulation tree level compression, and responds to the binning statistical characteristics of the lightweight prediction path through the top signature retention strategy. The structure continuously maintains the verifiability of data state and calculation operation during the parallel execution of the three paths, and provides the arbitration verification module with a complete integrity evidence chain covering the entire calculation life cycle. The cross-path control mechanism realizes on-demand allocation of computing resources, avoiding additional performance loss introduced by signature structure maintenance.

[0096] Specifically, the multi-level provable verification protocol executed by the arbitration verification module of the homomorphic encryption-based big data computing and analysis security guarantee system includes:

[0097] The Merkle tree depth of the homomorphic evolution signature structure of the traceable ciphertext operation state is equal to a preset value, and the BLS accumulation tree level of the homomorphic evolution signature structure of the traceable ciphertext operation state corresponding to the equivalent verification path is within a threshold interval;

[0098] The cluster center distance difference between the main computing path and the equivalent verification path is constrained by the arithmetic circuit, and the proof byte stream is generated by zk-STARK;

[0099] The cosine similarity of the three result vectors of the main computing path calculation result, the equivalent verification path calculation result and the lightweight prediction path calculation result is calculated, and when the similarity is less than 0.85, the node isolation is triggered.

[0100] The arbitration verification module receives the main calculation path calculation result, the equivalent verification path calculation result, the lightweight pre-judgment path calculation result and the homomorphic evolution signature structure of the evolved traceable ciphertext operation state output by the triple simulation calculation module, and executes the first level verification operation of the multi-level provable verification protocol. The first level verification operation verifies whether the Merkle tree depth in the homomorphic evolution signature structure of the traceable ciphertext operation state is equal to the preset depth value, and simultaneously verifies whether the BLS accumulation tree level in the homomorphic evolution signature structure of the traceable ciphertext operation state corresponding to the equivalent verification path is within the preset threshold interval. The verification reflects the data integrity state based on the Merkle tree depth, and the BLS accumulation tree level indicates the effective range of dimension reduction calculation; if the depth or level exceeds the preset range, it indicates that the signature structure may be subjected to unauthorized modification, and the verification process is directly interrupted. This step establishes the data structure integrity basis for subsequent verification and ensures that the calculation process is not tampered with.

[0101] After completing the first level verification, the second level verification operation constructs an arithmetic circuit to constrain the distance difference between the cluster center coordinates output by the main calculation path and the equivalent verification path to be less than a preset difference threshold. The arithmetic circuit converts the cluster center coordinate difference into a polynomial constraint relationship, defines a mathematical verifiable condition, generates a compressed proof byte stream through a zero-knowledge succinct non-interactive knowledge argument protocol, and the proof byte stream encapsulates the correctness evidence of the calculation process. This level of verification focuses on the consistency of the results of the main calculation path and the equivalent verification path, and if the distance difference exceeds the threshold, the proof generation fails, indicating abnormal calculation logic. The protocol execution depends on the signature structure integrity confirmed by the first level verification, providing input basis for the third level verification.

[0102] The third level verification operation calculates the direction similarity index of the three result vectors of the main calculation path calculation result, the equivalent verification path calculation result and the lightweight pre-judgment path calculation result; when the direction similarity is lower than a preset similarity threshold, a node isolation mechanism is triggered. The direction similarity calculation uses the cosine similarity algorithm to evaluate the deviation degree of the three vectors in the spatial distribution; the node isolation mechanism suspends the calculation task of the abnormal node to prevent the spread of incorrect results. This level of verification integrates the output consistency of the three paths, and the direction similarity lower than the threshold indicates malicious tampering or calculation failure, and the proof byte stream output based on the second level verification supplements the auditable evidence. The multi-level protocol forms a progressive verification chain, covering the trusted verification requirements from data structure to calculation result.

[0103] Specifically, the homomorphic encryption-based big data calculation and analysis security guarantee system disclosed by the present application can verify the decryption module, which is configured to:

[0104] The attribute-based key derivation device analyzes the binding relationship strategy of the trusted credential record, binds the system preset master private key to generate a decryption key;

[0105] The zero-knowledge prover generates a range proof of the cluster center coordinates in the main calculation path calculation result by adopting a Bulletproofs protocol, and the length of the proof is compressed to a logarithmic level.

[0106] The verifiable decryption module receives the ciphertext with trusted credentials output by the arbitration verification module, and first processes the trusted credentials by the attribute-based key derivation module. The attribute-based key derivation module analyzes the binding relationship strategy recorded in the trusted credentials, which defines the mapping rules of user attributes and data access permissions. The binding relationship strategy constructs access control conditions based on role attributes, data classification and other elements. The attribute-based key derivation module binds the system preset master private key to generate an attribute-based decryption key through a key derivation algorithm. The attribute-based decryption key strictly matches the binding relationship strategy to ensure that the decryption operation conforms to the predefined access policy, which provides an authorization basis for subsequent homomorphic decryption.

[0107] After key derivation, the verifiable decryption module performs homomorphic decryption on the ciphertext with trusted credentials using the attribute-based decryption key. The homomorphic decryption process converts the ciphertext into plaintext data, which includes the cluster center coordinates and sample point information output by the main calculation path. The decryption operation depends on the effectiveness of the attribute-based decryption key. If the binding relationship strategy fails or the master private key does not match, the decryption process is interrupted and an error is returned. This step restores the original data state and prepares the input for result verification.

[0108] After obtaining the plaintext data, the zero-knowledge prover extracts the cluster center coordinates from the plaintext data. The zero-knowledge prover generates a range proof of the cluster center coordinates using the Bulletproofs protocol, and the range proof is based on the boundary of the coordinate value to construct mathematical constraints. The Bulletproofs protocol applies recursive combination technology to optimize the proof structure, efficiently compressing the proof data volume to a compact form and reducing storage and transmission overhead. The range proof does not disclose the actual coordinate value, but only verifies whether the value is within the preset range, supporting subsequent audit of authorized terminals.

[0109] Finally, the verifiable decryption module combines the plaintext data and the range proof into an auditable result. The combination operation integrates the decryption data and the cryptographic proof to form a complete output package, and the auditable result is returned to the authorized terminal through a secure channel. The authorized terminal verifies the validity of the cluster center coordinates based on the range proof, and confirms that the data processing process conforms to the access policy. The key generation of the attribute-based key derivation module, the homomorphic decryption operation and the generation of the range proof form a progressive technology chain, realizing end-to-end verifiability from ciphertext decryption to result audit.

[0110] Specifically, the big data calculation and analysis security guarantee system based on homomorphic encryption according to the present application further comprises:

[0111] The data feature extraction module outputs to the knowledge base driven encryption module: the Avro format encapsulates the original data and the structured feature label.

[0112] The triple simulation calculation module outputs to the arbitration verification module: Protobuf encoding main calculation path calculation result, equivalent verification path calculation result, lightweight pre-judgment path calculation result three groups of data and homomorphic evolution signature structure ASN.1 descriptor;

[0113] The arbitration verification module outputs to the verifiable decryption module: CBOR encapsulates the ciphertext with trusted credentials and the zk-STARK proof byte stream.

[0114] The data output to the knowledge base driven encryption module by the data feature extraction module is encapsulated in Avro format. The Avro format defines a structured data mode, and the mode description includes original data types, dimension distribution characteristics and structured feature label fields. The original data is stored in binary serialization, and the structured feature label is encoded in the form of key-value pair; the Avro mode evolution capability supports the expansion of the feature label field, and adapts to the format change of different data sources. This encapsulation format provides a self-describing data structure for the knowledge base driven encryption module, and the encryption strategy matching operation can directly parse the feature label field.

[0115] The data output to the arbitration verification module by the triple simulation calculation module is encoded by Protobuf protocol. Protobuf defines a message structure including three independent fields: the main calculation path calculation result field stores the coordinate vector of the ciphertext clustering center, the equivalent verification path calculation result field stores the dimension reduction clustering result, and the lightweight pre-judgment path calculation result field stores the histogram statistical vector. The homomorphic evolution signature structure uses ASN.1 abstract syntax description, and the ASN.1 descriptor declares the Merkle tree depth, BLS accumulation tree level and node hash algorithm identifier. Protobuf encoding realizes efficient serialization, reduces the data parsing overhead of the arbitration verification module, and the ASN.1 descriptor ensures the cross-platform compatibility of the signature structure.

[0116] The data output to the verifiable decryption module by the arbitration verification module is encapsulated in CBOR format. The CBOR binary object is organized into two nested structures: the ciphertext structure with trusted credentials stores the homomorphic encryption ciphertext byte stream and trusted credential metadata, and the zk-STARK proof byte stream structure stores the proof data packet generated by the arithmetic circuit. The trusted credential metadata records the attribute access policy hash value and the binding relationship policy version number. The simplicity of the CBOR format optimizes the efficiency of the ciphertext transmission, and the nested structure design maintains the logical association of the ciphertext and the proof data.

[0117] Specifically, the homomorphic encryption-based big data calculation and analysis security guarantee system disclosed by the application further comprises:

[0118] The structured feature label driven knowledge base driven encryption module selects the encryption strategy dynamically;

[0119] The homomorphic evolution signature structure maintains the integrity of the signature evolution chain in the main calculation path, the equivalent verification path, and the lightweight prediction path calculation process.

[0120] The zk-STARK protocol converts the multi-level provable verification protocol into a provable computation problem.

[0121] Attribute-based decryption and zero-knowledge range proof construct the auditable evidence chain of the arbitration verification module to the verifiable decryption module link.

[0122] The structured feature label, as the output of the data feature extraction module, drives the knowledge base driven encryption module to dynamically select the encryption strategy. The structured feature label contains data type, dimension number, and sensitive level fields, and the knowledge base driven encryption module parses these fields to query the policy layer decision tree model of the pre-set encryption knowledge base; the decision tree model matches the structured feature label to the encryption strategy identifier, dynamically loads the corresponding encryption parameters of the core layer. This process realizes adaptive encryption strategy selection based on data features, providing a strategy basis for subsequent ciphertext generation.

[0123] The homomorphic evolution signature structure evolves synchronously in the main calculation path, the equivalent verification path, and the lightweight prediction path calculation process, maintaining the integrity of the signature evolution chain. The main calculation path executes the K-means clustering algorithm in the ciphertext to update the Merkle tree leaf hash value in the homomorphic evolution signature structure, the equivalent verification path reduces the dimension to compress the BLS accumulation tree level in the homomorphic evolution signature structure, and the lightweight prediction path counts the bins to retain the top signature of the BLS accumulation tree in the homomorphic evolution signature structure. The signature evolution chain calculates the operation sequence through the hash node and accumulator state change record, ensuring the traceability of the state in the whole calculation period, and providing integrity input for the arbitration verification module.

[0124] The zk-STARK protocol converts the multi-level provable verification protocol into a provable computation problem. The multi-level provable verification protocol includes signature structure verification, arithmetic circuit constraint distance difference calculation, and result vector similarity calculation, and the zk-STARK protocol constructs an arithmetic circuit to package these verification steps as polynomial constraint relationships, generating a compressed proof byte stream. This conversion realizes efficient cryptographic encapsulation of the verification process, and the proof byte stream serves as output to support subsequent auditable links, relying on the integrity input of the homomorphic evolution signature structure.

[0125] Attribute-based decryption and zero-knowledge range proof construct an auditable evidence chain between the arbitration verification module and the verifiable decryption module. The verifiable decryption module generates a decryption key using an attribute-based key derivation to perform homomorphic decryption and obtain plaintext data. The zero-knowledge proof generator extracts the plaintext clustering center coordinates to generate a range proof using the bulletproof proof protocol. The range proof constructs mathematical constraints based on numerical boundaries and combines plaintext data to form an auditable result. The evidence chain covers the entire process of decryption authorization, data recovery and result verification. The zk-STARK proof byte stream input provides a verification basis to realize end-to-end responsibility tracing.

[0126] Specifically, the homomorphic encryption-based big data computing and analysis security guarantee system also includes:

[0127] The external data source includes a relational database and a streaming data platform.

[0128] The auditable result output by the verifiable decryption module is returned to the authorized terminal, including the decrypted plaintext data and the range proof of the clustering center coordinates.

[0129] The external data source includes two types of data access objects, namely, a relational database and a streaming data platform. The relational database provides structured data access through a standard database connection protocol, and the system calls a structured query statement to obtain batch raw data. The streaming data platform transmits real-time data streams based on a message queue protocol, and the system continuously collects time series data by subscribing to a consumption interface. Both types of data sources are processed by a data capture unit of a data feature extraction module. The data capture unit adapts to different protocol interfaces and converts raw data into an internal processing format. This design supports seamless access to heterogeneous data sources and provides a multi-modal input basis for feature extraction.

[0130] The auditable result generated by the verifiable decryption module includes decrypted plaintext data and range proof of clustering center coordinates. The plaintext data is a set of sample points and clustering center coordinates output by homomorphic decryption. The range proof is constructed using a bulletproof proof protocol and generates mathematical constraint evidence based on the numerical boundaries of the clustering center coordinates. The auditable result is returned to the authorized terminal through a secure transmission channel. The transmission channel uses a two-way authentication mechanism to establish an encrypted session. After receiving the result, the authorized terminal first verifies the validity of the range proof to confirm that the coordinate values are not out of bounds, and then performs subsequent analysis operations based on the plaintext data.

[0131] The technical scheme of the present application dynamically maintains the integrity of the calculation process through the homomorphic evolution signature structure that can track the operation state of the ciphertext. The signature structure is generated during the initialization of the knowledge base driven encryption module and includes a Merkle tree and a BLS accumulation tree component. When the three simulation calculation modules of the main calculation path, the equivalent verification path and the lightweight prediction path are executed in parallel, the signature structure is synchronously evolved: the main calculation path updates the Merkle tree leaf hash value to reflect the change of the cluster center, the equivalent verification path compresses the BLS accumulation tree level to adapt to the dimension reduction calculation demand, and the lightweight prediction path retains the top layer signature of the BLS accumulation tree to optimize resources. The signature evolution process records the ciphertext operation state in real time, forming an integrity evidence chain covering the entire calculation life cycle, and tampering with the intermediate calculation results by an attacker will destroy the consistency of the signature structure and be detected.

[0132] The arbitration verification module receives the three-path calculation results and the evolved signature structure, and implements real-time tampering detection through a multi-level provable verification protocol. The first level verification checks the consistency of the Merkle tree depth in the signature structure with the preset value, and simultaneously verifies whether the BLS accumulation tree level corresponding to the equivalent verification path is in the effective interval, to confirm that the data structure has not been modified unauthorized. The second level verification constructs an arithmetic circuit to constrain the distance difference threshold of the cluster center of the main calculation path and the equivalent verification path, generates a proof byte stream through the zk-STARK protocol, and mathematically verifies the logical correctness of the result. The third level verification calculates the cosine similarity of the three groups of vectors of the main calculation path calculation result, the equivalent verification path calculation result and the lightweight prediction path calculation result, and triggers the node isolation mechanism when the similarity is lower than the threshold, to block the diffusion of malicious injection or calculation failure. The multi-level verification forms a progressive defense from data integrity to result consistency.

[0133] The verifiable decryption module parses the binding relationship strategy of the trusted credential record through the attribute-based key derivation, generates an attribute-based decryption key to perform homomorphic decryption, and obtains the plaintext data; the zero-knowledge proof generator extracts the cluster center coordinates to generate a zero-knowledge range proof of compressed logarithmic level length through the bulletproof proof protocol. The plaintext data and the range proof are combined into an auditable result and returned to the authorized terminal, which can verify the validity of the coordinate value boundary based on the range proof, and simultaneously backtrack the compliance of the attribute access strategy. The auditable evidence chain realizes end-to-end responsibility tracing from ciphertext decryption to result output.

[0134] The dynamic evolution of the signature structure provides a process integrity anchor point, the multi-path cross verification realizes real-time blocking of tampering, and the auditable result completes the terminal verifiable closed loop. The three mechanisms maintain the homomorphic encryption confidentiality feature while cooperatively building a systematic defense system, solving the integrity verification and malicious tampering prevention problem in the ciphertext calculation scene.

[0135] The embodiment of the application aims at the problems of missing integrity verification and malicious tamper prevention in homomorphic encryption scenarios, and constructs a closed-loop technical solution. In a typical application scenario of financial transaction data analysis, an external data source includes historical transaction records of a relational database and real-time transaction streams of a streaming data platform. A data capture unit of a data feature extraction module collects database data through a JDBC protocol and acquires stream data through a Kafka consumption interface. A real-time feature analysis engine performs principal component analysis on transaction data to detect 3000-dimensional feature sparsity, applies a dynamic time warping algorithm to identify transaction frequency periodic fluctuations, and uses Geohash encoding to analyze IP address space aggregation features. A label encoder outputs a 3000-dimensional LEVEL3 structured feature label of a high-dimensional financial transaction matrix to a knowledge base driven encryption module.

[0136] The knowledge base driven encryption module queries an encrypted knowledge base strategy layer, a decision tree model matches a LEVEL3 sensitive level to trigger a lattice encryption scheme, and loads core layer polynomial order parameters. When the module generates ciphertext, a Merkle tree with a depth of 5 is constructed as a homomorphic evolution signature structure basic framework of a traceable ciphertext operation state, and the Merkle tree leaf node stores transaction data block hash values. The initial state of the structure is transmitted to a triple simulation calculation module through ciphertext.

[0137] The triple simulation calculation module starts three-path parallel calculation: the main calculation path executes the iterative update of the transaction data clustering center by the K-means clustering algorithm in the encrypted state, and the leaf hash value of the Merkle tree of the corresponding data block is recalculated and the third layer intermediate node hash is updated synchronously every time the center coordinate is updated; the equivalent verification path executes PCA dimension reduction to 500 dimensions on the ciphertext transaction data, runs simplified clustering, and compresses the BLS accumulation tree in the homomorphic evolution signature structure of the traceable ciphertext operation state to a 3-layer structure; the lightweight prediction path only retains the top layer signature of the BLS accumulation tree by binning and counting the transaction amount distribution histogram according to the preset granularity. The signature structure evolution process records the calculation operation sequence in real time, and the main calculation path maps the transaction data block to the Merkle tree leaf node in the initialization stage, which establishes a data anchor point for subsequent integrity verification.

[0138] The arbitration verification module performs multi-level verification after receiving the three-path output: the first level checks the compliance of the Merkle tree with a depth of 5 and the BLS accumulation tree with a level of 3, the second level constructs an arithmetic circuit to constrain the distance difference threshold of the clustering center of the main calculation path and the equivalent verification path, and generates a proof byte stream through zk-STARK; the third level calculates the cosine similarity index of the three-path result vector, and triggers the isolation of the calculation node when an abnormal deviation is detected. The multi-level protocol identifies the tampering behavior of the attacker injected fake transaction ciphertext, and blocks the transmission of the error result.

[0139] The verifiable decryption module attribute base key derivation parses the auditor role policy of the trusted credential record, binds the system master private key to generate a decryption key. After the homomorphic decryption obtains the plaintext transaction clustering result, the zero-knowledge proof generator generates a clustering center coordinate range proof using Bulletproofs, and proves that the transaction amount distribution does not exceed the boundary. Finally, the Avro format encapsulated plaintext data and range proof are returned to the authorized terminal as an auditable result, and the auditor verifies the validity of the numerical value and the compliance of the policy.

[0140] PCA (Principal Component Analysis)

[0141] PCA refers to Principal Component Analysis, which is a statistical dimension reduction method. In the real-time feature analysis engine of the data feature extraction module of the present application, PCA is used to calculate the feature sparsity ratio of the original data dimension, project high-dimensional data into low-dimensional space through orthogonal transformation, extract key feature vectors and eliminate redundant dimensions, and provide a dimension distribution analysis basis for structured feature label generation.

[0142] K-means (K-means Clustering Algorithm)

[0143] K-means refers to K-means Clustering Algorithm, which is an unsupervised machine learning method. In the main calculation path of the triple simulation calculation module, K-means performs clustering calculation in the ciphertext state, assigns data groups by iteratively updating the distance between sample points and cluster centers, and drives the Merkle tree hash value update in the homomorphic evolution signature structure of the traceable ciphertext operation state.

[0144] BLS Accumulator Tree (Boneh-Lynn-Shacham Accumulator Tree)

[0145] BLS Accumulator Tree refers to a cryptographic accumulator tree structure based on the Boneh-Lynn-Shacham signature scheme. In the homomorphic evolution signature structure of the traceable ciphertext operation state, the BLS Accumulator Tree is used to efficiently aggregate data hash values and generate short proofs; when the equivalent verification path performs dimension reduction calculation, it dynamically compresses its level, and the lightweight pre-judgment path only retains its top signature to optimize verification efficiency.

[0146] The technical features of the present application are explained as follows:

[0147] zk-STARK refers to Zero-Knowledge Scalable Transparent Argument of Knowledge. In the arbitration verification module, zk-STARK converts the arithmetic circuit constraints in the multi-level provable verification protocol into verifiable computing statements, generates proof byte streams without leaking the original data, and realizes efficient cryptographic verification of the correctness of the calculation results.

[0148] Bulletproofs refers to Bulletproofs Protocol, which is a non-interactive zero-knowledge range proof scheme. In the verifiable decryption module, Bulletproofs generates logarithmic length range proofs for the cluster center coordinates, compresses the evidence volume through inner product optimization technology, and enables authorized terminals to verify the value boundary without exposing the specific coordinates.

[0149] ASN.1 refers to Abstract Syntax Notation One, which is a cross-platform data description standard. In the output of the triple simulation calculation module, the ASN.1 descriptor defines the tree depth, node hash algorithm, and other properties of the homomorphic evolution signature structure that can track the operation state of the ciphertext, ensuring that the arbitration verification module can parse the signature structure hierarchy.

[0150] Protobuf refers to Protocol Buffers, which is a high-efficiency data serialization format developed by Google. In the data transmission from the triple simulation calculation module to the arbitration verification module, Protobuf encodes three groups of data: the calculation results of the main calculation path, the calculation results of the equivalent verification path, and the calculation results of the lightweight prediction path, realizing low-overhead cross-platform parsing.

[0151] CBOR refers to Concise Binary Object Representation, which is a lightweight binary data packaging format. The arbitration verification module uses CBOR to package the ciphertext with trusted credentials and zk-STARK proof byte streams to the verifiable decryption module, and the nested structure design maintains the logical association between the ciphertext and the proof.

Claims

1. A secure system for big data computation and analysis based on homomorphic encryption, characterized in that, The method comprises the following steps: a data feature extraction module acquires original data and extracts the dimension distribution, time series features and spatial correlation features of the original data, and outputs structured feature labels generated by the data feature extraction module, including the dimension distribution, time series features and spatial correlation features; a knowledge base driven encryption module receives the structured feature labels output by the data feature extraction module, matches corresponding homomorphic encryption strategies from a preset encryption knowledge base, and generates ciphertext with a homomorphic evolution signature structure and a traceable ciphertext operation state; a triple simulation calculation module receives the ciphertext and the homomorphic evolution signature structure output by the knowledge base driven encryption module, and outputs main calculation path calculation results, equivalent verification path calculation results and lightweight prediction path calculation results through a main calculation path, an equivalent verification path and a lightweight prediction path, respectively. The triple simulation calculation module triggers the synchronous evolution of the homomorphic evolution signature structure; an arbitration verification module receives the main calculation path calculation results, the equivalent verification path calculation results and the lightweight prediction path calculation results output by the triple simulation calculation module, and the evolved homomorphic evolution signature structure, executes a multi-level provable verification protocol, generates a trusted credential, and outputs the ciphertext with the trusted credential or an error code; a verifiable decryption module receives the ciphertext with the trusted credential output by the arbitration verification module, parses the attribute access policy recorded in the trusted credential, generates an attribute-based decryption key according to the attribute access policy, performs homomorphic decryption on the ciphertext with the trusted credential using the attribute-based decryption key, obtains plaintext data, generates zero-knowledge range proof based on the cluster center coordinates in the plaintext data, combines the plaintext data and the zero-knowledge range proof into an auditable result, and returns to the authorized terminal.

2. The homomorphic encryption based big data computing and analyzing security assurance system according to claim 1, characterized in that, The data feature extraction module comprises: a data capture unit acquires original data from external data sources through a database protocol and an API interface; a real-time feature analysis engine performs principal component analysis on the original data to calculate the sparsity ratio, and detects periodicity using a dynamic time warping algorithm, and calculates the spatial grid distribution using Geohash encoding; a label encoder converts the analysis results into a structured feature label in the format of [data type_dimension number_sensitivity level].

3. The homomorphic encryption based big data computing and analytics security assurance system of claim 2, wherein, The encryption knowledge base comprises: a core layer storing polynomial order and modulus parameters of a homomorphic encryption scheme; a strategy layer constructing a decision tree model to map structured feature labels to encryption strategy IDs; an instance layer recording historical encryption ciphertext inflation rates and computing delay indicators; wherein, in response to the structured feature label being a high-dimensional financial transaction matrix_3000 dimensions_LEVEL3, the knowledge base driven encryption module loads lattice encryption parameters and constructs a Merkle tree structure with a depth of 5 as a component of the homomorphic evolution signature structure of the traceable ciphertext operation state.

4. The homomorphic encryption based big data computing and analyzing security assurance system according to claim 3, characterized in that, The triple simulation calculation module is configured to: the main calculation path executes a ciphertext K-means clustering algorithm and updates the hash value of the third layer of the Merkle tree in the homomorphic evolution signature structure of the traceable ciphertext operation state; the equivalent verification path runs a simplified clustering algorithm on the ciphertext after performing PCA dimension reduction, and compresses the BLS accumulation tree in the homomorphic evolution signature structure of the traceable ciphertext operation state to a 3-layer structure; The lightweight pre-judgment path adopts a homomorphic hash binning statistical histogram, and only retains a BLS accumulation tree top signature in a homomorphic evolution signature structure of a traceable ciphertext operation state; The evolution of the homomorphic evolution signature structure is that the Merkle tree leaf hash value in the homomorphic evolution signature structure of the traceable ciphertext operation state is recalculated with the update of the cluster center.

5. The homomorphic encryption based big data computing and analytics security system of claim 4, wherein, Further comprising: The main calculation path maps the data block to a Merkle tree leaf node in the homomorphic evolution signature structure of the traceable ciphertext operation state when initializing the homomorphic addition calculation cluster center; The binning granularity of the lightweight pre-judgment path determines the hierarchical compression ratio of the BLS accumulation tree in the homomorphic evolution signature structure of the traceable ciphertext operation state corresponding to the equivalent verification path.

6. The homomorphic encryption based big data computing and analyzing security assurance system according to claim 5, wherein, The multi-level provable verification protocol executed by the arbitration verification module includes: The depth of the Merkle tree in the homomorphic evolution signature structure of the traceable ciphertext operation state is equal to a preset value, and the hierarchical level of the BLS accumulation tree in the homomorphic evolution signature structure of the traceable ciphertext operation state corresponding to the equivalent verification path is within a threshold interval; An arithmetic circuit is constructed to constrain the distance difference between the cluster centers of the main calculation path and the equivalent verification path to be less than or equal to δ, and a proof byte stream is generated by zk-STARK; The cosine similarity of three result vectors of the main calculation path calculation result, the equivalent verification path calculation result and the lightweight pre-judgment path calculation result is calculated, and when the similarity is less than 0.85, node isolation is triggered.

7. The homomorphic encryption based big data computing and analyzing security assurance system according to claim 6, wherein, The verifiable decryption module is configured to: An attribute-based key generator that analyzes the binding relationship strategy of the trusted credential record, binds the system pre-installed master private key to generate a decryption key; A zero-knowledge prover that generates a range proof of the cluster center coordinates in the main calculation path calculation result using the Bulletproofs protocol, and compresses the proof length to a logarithmic level.

8. The homomorphic encryption based big data computing and analyzing security assurance system of claim 7, wherein, Further comprising: The data feature extraction module outputs to the knowledge base driven encryption module: Avro format encapsulates raw data and structured feature labels; The triple simulation calculation module outputs to the arbitration verification module: Protobuf encodes three groups of data of the main calculation path calculation result, the equivalent verification path calculation result and the lightweight pre-judgment path calculation result, and the ASN.1 descriptor of the homomorphic evolution signature structure; The arbitration verification module outputs to the verifiable decryption module: CBOR encapsulates the ciphertext with trusted credentials and the zk-STARK proof byte stream.

9. The homomorphic encryption based big data computing and analytics security system of claim 8, wherein, Further comprising: The structured feature label driven knowledge base driven encryption module dynamically selects the encryption strategy; The homomorphic evolution signature structure maintains the integrity of the signature evolution chain in the main calculation path, the equivalent verification path and the lightweight pre-judgment path calculation process; The zk-STARK protocol converts the multi-level provable verification protocol into a provable computation problem; The attribute-based decryption and zero-knowledge range proof construct an auditable evidence chain between the arbitration verification module and the verifiable decryption module.

10. The homomorphic encryption based big data computing and analytics security system of claim 9, wherein, Further comprising: The external data source includes a relational database and a streaming data platform; The auditable result output by the verifiable decryption module is returned to the authorized terminal, including the decrypted plaintext data and the range proof of the cluster center coordinates.

Citation Information

Patent Citations

  • Unmanned aerial vehicle anonymous authentication and identity remote identification method, unmanned aerial vehicle and supervision equipment thereof

    CN119675874A

  • Data security method and system based on privacy calculation and multifunctional encryption

    CN120454974A