Bank asset electronic auction algorithm based on homomorphic encryption

By using Shamir secret sharing and hybrid encryption technology, combined with the Schnorr protocol and quantum-resistant modules, the centralized risks and quantum computing threats in bank asset auctions are resolved, achieving an efficient, secure, and transparent multi-dimensional auction solution.

CN120833207APending Publication Date: 2025-10-24AGRI BANK OF CHINA CO LTD GANSU BRANCH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510769570.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-10
Publication Date
2025-10-24

Smart Images

  • Figure CN120833207A_ABST
    Figure CN120833207A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data security, in particular to a bank asset electronic auction algorithm based on homomorphic encryption, which comprises key generation and distribution, hybrid encryption quotation, threshold decryption and verification and result publication. Compared with the prior art which depends on a non-completely trusted third party to realize the auction process, the scheme adopts a decentralized (t, n) threshold decryption mechanism, combines a Shamir secret sharing technology, splits a private key into multiple parts and distributes the multiple parts to all participants, and decryption needs at least t nodes to cooperate to complete. In the prior art, a centralization risk is caused by dependence on a single third party, and control by an attacker or single-point failure is easily caused; according to the scheme, through distributed key management and threshold verification, third-party dependence is eliminated, it is ensured that even if part of nodes are malicious or invalid, the result can still be safely decrypted and verified, and the collusion attack resistance and fault tolerance of the system are remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data security, and in particular to a bank asset electronic auction algorithm based on homomorphic encryption. BACKGROUND

[0002] Traditional bank asset auctions mainly rely on offline processes or centralized electronic platforms, which have significant defects. In online auction scenarios, existing technologies usually host bidder data and processes through third-party platforms, resulting in centralized trust risks: third parties may cause data leaks due to technical vulnerabilities or internal collusion, and platform single-point failures will directly interrupt the auction process.

[0003] In addition, existing electronic auction algorithms mostly use conventional encryption technologies (such as AES or RSA) to protect data transmission, but the encrypted data needs to be frequently decrypted for price comparison calculations, resulting in repeated exposure of sensitive information and the risk of being attacked by intermediaries or malicious nodes. In terms of fairness, existing solutions lack effective decentralized verification mechanisms, bidders cannot independently verify the legality of the highest price generation process, and the binding relationship between the winning bidder's identity and the bid price relies on third-party notarization, which is prone to disputes. More seriously, traditional algorithms cannot support multi-dimensional attribute (such as price, delivery period) comprehensive bidding, and are difficult to cope with the threat of quantum computing to the encryption system. Although some research attempts to introduce homomorphic encryption technology, it relies on semi-trusted third parties to assist in decryption, fails to achieve a fully decentralized structure, and has low computational efficiency, making it difficult to meet the high concurrency requirements of bank asset auctions.

[0004] These technical bottlenecks result in significant deficiencies in the security, fairness, flexibility, and forward-looking nature of existing electronic auction solutions, necessitating an innovative solution that integrates anti-collusion, full-process privacy protection, and anti-quantum attack capabilities. SUMMARY

[0005] To overcome the problems presented in the above background art, the present application proposes a bank asset electronic auction algorithm based on homomorphic encryption.

[0006] The technical solution of the present application is: a bank asset electronic auction algorithm based on homomorphic encryption, comprising the following steps: S11: Key generation and distribution, all bidders generate private keys and public keys, and split the private keys into threshold shares based on Shamir secret sharing, and aggregate all public keys through a bulletin board server to generate a joint public key and an HMAC key , wherein is a threshold value, n is the number of bidders, The private key of bidder i is generated by a random number, The private key of bidder i The generated threshold fragment, The public key of bidder i, K is the joint public key, T is the HMAC key, g is the generator of the cyclic group, and p is a large prime number, The integer randomly selected by bidder i, Indicates that all operations are performed in the finite field of a large prime number p; S12: Mix the encrypted bid, and all bids of the bidders Encoded as a binary vector , and the original data is encrypted using a symmetric encryption algorithm, and the key parameters are encrypted using ElGamal homomorphic encryption to generate ciphertext , wherein, The homomorphic encryption ciphertext set generated by bidder i, The lth ciphertext block in the ciphertext set, and d is the number of binary encoding bits; S13: Threshold decryption and verification, submit at least t threshold shares of the verifier , and calculate the joint decryption key , decrypt the ciphertext to get the highest bid , wherein, The joint decryption key, T is a public parameter, The threshold share of the private key of bidder i, The highest bid obtained after decryption, The original bid of all bidders; S14: Result publicizing, bulletin board verification consistency to generate anonymous bid number , and broadcast For all bidders to verify, wherein, The anonymous bid number generated by the bulletin board, The keyed-hash message authentication code, The HMAC key, The homomorphic encryption ciphertext of the highest bidder.

[0007] As preferred, when all bids of the bidders Encoded as a binary vector , and the original data is encrypted using a symmetric encryption algorithm, and the key parameters are encrypted using ElGamal homomorphic encryption to generate ciphertext , specifically includes: S21: Encrypt the original bid data using the AES algorithm to generate ; S22: Use ElGamal homomorphic encryption for the highest price comparison parameter, which satisfies , and only when the decryption is completed to verify details, wherein is the bid of bidder i the lth bit in the encoded binary vector, is encrypted using the joint public key K the encrypted homomorphic ciphertext, is the power of the joint public key K.

[0008] As a preferred, when submitting the threshold shares of at least t verifiers and calculating the joint decryption key , decrypting the ciphertext to obtain , specifically includes: S31: using the Schnorr protocol to verify the zero-knowledge proof of the threshold shares of t verifiers , and the verification formula is: , wherein is a public parameter, s is the response value of the Schnorr protocol, R is a temporarily generated commitment value, is the partial decryption key provided by verifier j, and c is a random challenge value generated by the verifier; S32: if the verification fails, triggering the smart contract to automatically freeze the malicious node's deposit.

[0009] As a preferred, when generating and distributing the key, it also includes dynamic member management, wherein the dynamic member management includes the following steps: A11: when a new bidder joins, the bulletin board updates the joint public key and the threshold value , wherein is the updated joint public key after the new bidder joins, is the public key of the new bidder, is the dynamically adjusted threshold value; A12: when the support node is offline and exits, the remaining nodes reconstruct the threshold shares and update the key.

[0010] As a preferred, after the hybrid encryption bid, it also includes anonymous bid number generation, wherein the specific steps of the anonymous bid number generation include: S41: generation stage, combined with ring signature technology and HMAC algorithm to generate a unique identifier, ensuring that it cannot be associated with the specific bidder identity; S42: verification stage, verifying the legality of the generated unique identifier through the ring signature public key set.

[0011] As a preferred, the algorithm integrates a post-quantum secure module, and the quantum secure module is used for: A21: switching to a lattice-based homomorphic encryption scheme when a quantum attack threat is detected; A22: replacing the traditional process with an anti-quantum threshold decryption protocol to ensure long-term security.

[0012] As a preferred, at least t verifiers' threshold shares are submitted , and a joint decryption key is calculated , the multiple auction parameters are encoded into a weighted vector when the ciphertext is decrypted to get the highest bid, and the highest score is determined by homomorphic calculation to determine the highest bidder, wherein the weight distribution of the weighted vector is self-defined.

[0013] As a preferred, it also includes malicious behavior detection, which specifically includes: S51: In the threshold decryption phase, if the decryption results are inconsistent, the bulletin board traces the abnormal nodes through ring signature; S52: The smart contract automatically executes the punishment logic, including canceling the qualification, deducting the margin and publicly recording the abnormal record.

[0014] As a preferred, the anonymous bid number is generated after the bulletin board verifies the consistency , and broadcast for all bidders to verify, which specifically includes: A31: local verification, bidders confirm the legality of the results through ; A32: on-chain evidence, write into the blockchain, and ensure that the results cannot be tampered with through smart contract timestamp and hash value.

[0015] As a preferred, the algorithm is stored and transmitted through the following steps: S61: sparse matrix compression technology is used for the ciphertext matrix, only the non-zero elements and position indexes are retained; S62: use homomorphic hash to aggregate multi-round interaction data, reduce the communication rounds to within 3 rounds.

[0016] The beneficial effects of the present application are: 1. Compared with the prior art which relies on a non-fully trusted third party to realize the auction process (there is a collusion attack risk), the present scheme uses a decentralized (t, n) threshold decryption mechanism combined with Shamir secret sharing technology to split the private key into multiple parts and distribute them to all participants. The decryption needs at least t nodes to cooperate. The existing technology relies on a single third party, which leads to centralized risk and is easy to be manipulated by attackers or single-point failure; the present scheme eliminates the dependence on the third party through distributed key management and threshold verification, ensuring that even if some nodes are malicious or fail, the result can still be safely decrypted and verified, significantly improving the system's ability to resist collusion attacks and fault tolerance; 2. Compared to existing technologies that use traditional encryption algorithms (which require frequent decryption and expose sensitive data, posing a risk of data leakage), this solution uses a hybrid encryption architecture, combining symmetric encryption (AES) to protect original data and ElGamal homomorphic encryption to process key parameters. Existing technologies are inefficient or lack security due to plaintext calculations or single encryption methods. This solution uses homomorphic encryption to support direct calculation of the highest price using ciphertext, decrypting and verifying details only in the final stage. This achieves encryption throughout the entire data transmission, storage, and calculation process, ensuring efficiency while eliminating the risk of data leakage, and balancing security and practicality. 3. Unlike existing technologies that fail to account for the threat of quantum computing (traditional encryption algorithms face the risk of future cracking), this solution integrates a quantum-resistant encryption module, supports seamless switching to a lattice-based FHE (fully homomorphic encryption), and uses the Gentry-Sahai-Waters threshold protocol instead of the ElGamal process. Existing technologies, relying on discrete logarithms or the problem of large number factorization, are unable to withstand quantum attacks. This solution, through post-quantum algorithms and a dynamic protocol switching mechanism, ensures that the system automatically activates the quantum-resistant module upon detecting a quantum threat, ensuring long-term data security and addressing the forward-looking security flaws of existing technologies. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Fig. 1 Shown is a flowchart of the bank asset electronic auction algorithm based on homomorphic encryption of the present invention; Fig. 2 Shown is a flowchart of threshold decryption and verification in the bank asset electronic auction algorithm based on homomorphic encryption of the present invention. DETAILED DESCRIPTION

[0018] The present invention will be further described below with reference to the accompanying drawings and examples.

[0019] See also Figs. 1-2 The present invention provides an embodiment: a bank asset electronic auction algorithm based on homomorphic encryption, comprising the following steps: S11: Key generation and distribution. All bidders generate private keys and public keys, and split the private keys into Threshold share Distribute and aggregate all public keys through the bulletin board server to generate a joint public key and the HMAC key ,in, is the threshold value, n is the number of bidders, is the private key of bidder i, generated by a random number, The private key of bidder i The generated threshold fragments, is the public key of bidder i, K is the joint public key, T is the HMAC key, g is the generator of the cyclic group, p is a large prime number, is an integer randomly selected by bidder i, denotes that all operations are performed in the finite field of a large prime number p; S12: hybrid encryption bidding, encrypting all bidders' bids into binary vectors and encrypting the original data using a symmetric encryption algorithm and homomorphically encrypting the key parameters using ElGamal to generate ciphertexts wherein, is a set of homomorphic encryption ciphertexts generated by bidder i, is the lth ciphertext block in the ciphertext set, and d is the number of binary encoded bits; S13: threshold decryption and verification, submitting threshold shares of at least t verifiers and calculating the joint decryption key to decrypt the ciphertext to obtain the highest bid wherein, is the joint decryption key, T is a public parameter, is a threshold share of the private key of bidder i, is the highest bid obtained after decryption, is the original bid of all bidders; S14: result publicization, generating an anonymous bid number after the bulletin board verifies consistency and broadcasting for verification by all bidders, wherein, is the anonymous bid number generated by the bulletin board, is a keyed-hash message authentication code, is the HMAC key, is the homomorphic encryption ciphertext of the highest bidder.

[0020] As described above, the present application solves the problems of centralized trust risk, data leakage risk, and collusion attack in traditional auctions by relying on a third party by using a (t, n) threshold key distribution mechanism based on Shamir secret sharing to split the private key of the bidder into distributed shares and manage them jointly by multiple parties, generating a joint public key K and an HMAC key T in combination with the bulletin board server to achieve decentralized key agreement; at the same time, hybrid encryption technology (AES+ElGamal) is used to encrypt the bid data throughout the process, and the highest price is restored through threshold decryption collaboration, significantly improving the security, fairness, and anti-repudiation of the system.

[0021] As a preferred, all bidders' bids are encoded into binary vectors and encrypt the original data using a symmetric encryption algorithm, and generate ciphertext by homomorphic encryption of ElGamal on key parameters , and specifically comprising: S21: encrypting the original bid data using the AES algorithm to generate ; S22: using homomorphic encryption of ElGamal on the highest price comparison parameter, satisfying , and only releasing to verify details, wherein, is the bid of bidder i the lth bit in the encoded binary vector, is the homomorphic ciphertext after encryption using the joint public key K , is the power of the joint public key K.

[0022] As described above, the present application generates symmetric ciphertext by encrypting the original bid data using the AES algorithm, and generates key parameters by homomorphic encryption of ElGamal, and only releases details after decryption, overcoming the low efficiency or risk of exposure of sensitive information caused by single encryption method in the prior art, realizing data full life cycle protection and efficient ciphertext calculation, and balancing high security and low calculation overhead.

[0023] As a preferred, when submitting the threshold shares of at least t verifiers and calculating the joint decryption key , the decrypted ciphertext is , specifically comprising: S31: performing zero-knowledge proof verification on the threshold shares of t verifiers using the Schnorr protocol, and the verification formula is: , wherein, is a public parameter, s is the response value of the Schnorr protocol, R is a temporarily generated commitment value, is the partial decryption key provided by verifier j, and c is the random challenge value generated by the verifier; S32: if the verification fails, triggering the smart contract to automatically freeze the malicious node's deposit.

[0024] As described above, the present application performs zero-knowledge proof verification on the threshold shares using the Schnorr protocol, and introduces a smart contract to automatically freeze the deposit of a malicious node, solving the problem of unverifiable private key fragmentation authenticity and missing punishment mechanism in traditional solutions, ensuring the legality and anti-collusion ability of threshold decryption, and improving the deterrence of malicious behavior.

[0025] As preferred, when the key generation and distribution are performed, dynamic member management is further included, wherein the dynamic member management comprises the following steps: A11: When a new bidder joins, the bulletin board updates the joint public key And the threshold value , wherein, is the joint public key updated after the new bidder joins, is the public key of the new bidder, is the dynamically adjusted threshold value; A12: When the support node is offline and exits, the threshold share is reconstructed and the key is updated by the remaining nodes.

[0026] As described above, the present application dynamically adjusts the joint public key and the threshold value, supports the seamless joining of new nodes or the safe exit of old nodes, overcomes the poor scalability and insufficient fault tolerance caused by the fixed node pool, realizes the elastic and scalable distributed auction network, and adapts to large-scale dynamic participation scenarios.

[0027] As preferred, after the hybrid encryption bid is made, anonymous bid number generation is further included, wherein the specific steps of the anonymous bid number generation comprise: S41: Generation phase, combined with ring signature technology and HMAC algorithm to generate a unique identifier to ensure that it cannot be associated with a specific bidder identity; S42: Verification phase, the legality of the generated unique identifier is verified by the ring signature public key set.

[0028] As described above, the present application generates an anonymous bid number by XORing the ring signature and the HMAC value, and verifies the legality by using the ring public key set in the verification phase, solves the problem that the bid number can be associated with the real identity in the traditional scheme, realizes the completely anonymous bidder identity protection and result verifiability, and ensures that the privacy and fairness are both up to standard.

[0029] As preferred, the algorithm integrates a post-quantum secure module, and the quantum secure module is used for: A21: When a quantum attack threat is detected, switch to a lattice-based homomorphic encryption scheme; A22: Replace the traditional process with a quantum-resistant threshold decryption protocol to ensure long-term security.

[0030] As described above, the present application dynamically switches to the lattice-based FHE encryption and Gentry-Sahai-Waters threshold decryption protocol after detecting quantum attacks, solves the long-term security risk that the traditional ElGamal algorithm cannot resist quantum computing, realizes the smooth transition of quantum attack resistance, and guarantees the continuous security of the system in the future cryptographic environment As preferred, in the threshold share and calculate the joint decryption key , and the highest bid is obtained by decrypting the ciphertext to get the highest bid, wherein the multiple auction parameters are encoded into a weighted vector, and the highest score is determined by homomorphic calculation of the comprehensive score, and the highest score is the highest bid, wherein the weight distribution of the weighted vector is self-defined.

[0031] As described above, the application encodes multi-dimensional attributes (price, time) into a weighted vector, and determines the highest score based on homomorphic calculation of the comprehensive score, breaking through the limitations of single price bidding, supporting multi-dimensional decision-making under complex auction rules, and improving the applicability and flexibility of the algorithm in financial asset pricing, supply chain auction and other scenarios.

[0032] As a preferred embodiment, it also includes malicious behavior detection, which specifically includes: S51: In the threshold decryption phase, if the decryption results are inconsistent, the bulletin board traces the abnormal node through ring signature; S52: The smart contract automatically executes the punishment logic, including canceling the qualification, deducting the deposit and publicly recording the abnormality.

[0033] As described above, the application traces the abnormal node through ring signature and triggers the smart contract to automatically execute the punishment logic (cancel the qualification and deduct the deposit), solving the problem of difficult post-tracing of malicious behavior in traditional solutions, realizing real-time abnormal detection and automatic disposal, and significantly improving the robustness and compliance of the system.

[0034] As a preferred embodiment, the bulletin board generates an anonymous bid number after verifying consistency , and broadcasts for all bidders to verify, specifically including: A31: Local verification, bidders verify to confirm the legality of the result; A32: On-chain storage, write into the blockchain, and ensure that the result cannot be tampered with through smart contract timestamp and hash value.

[0035] As described above, the application writes the result into the chain and binds the timestamp and hash value through the dual mechanism of local verification and blockchain storage, solving the problem of easily tampered results and lack of transparency in traditional solutions, realizing non-repudiation of auction results, full traceability and cross-institutional trusted verification, and providing strong technical support for financial supervision.

[0036] As a preferred embodiment, the algorithm is stored and transmitted through the following steps: S61: Sparse matrix compression technology is used on the ciphertext matrix, only the non-zero elements and position indexes are retained; S62: Use homomorphic hash to aggregate multi-round interaction data, reduce the communication rounds to within 3 rounds.

[0037] As described above, the present application optimizes the storage of ciphertext matrix by sparse matrix compression technology (only non-zero elements and indexes are reserved), and aggregates multi-round interaction data by homomorphic hash, so that the communication rounds are compressed to within 3 rounds, solving the problem of excessive storage and transmission overhead in high concurrency scenarios, and significantly improving the execution efficiency and resource utilization of the algorithm in large-scale auctions.

[0038] The embodiments of the present application are described in detail above in combination with the drawings, but the present application is not limited to the above-described embodiments, and various changes can be made within the knowledge of those skilled in the art without departing from the purpose of the present application.

Claims

1. A homomorphic encryption based algorithm for electronic auction of bank assets, characterized in that: The method comprises the following steps: S11: key generation and distribution, all bidders generate private keys and public keys, and split the private keys into threshold shares based on Shamir secret sharing, and aggregate all public keys to generate a joint public key and an HMAC key through a bulletin board server; S12: hybrid encryption bidding, all bidders' bids are encoded into a binary vector, and the original data is encrypted using a symmetric encryption algorithm, and the key parameters are encrypted using ElGamal homomorphic encryption to generate ciphertext; S13: threshold decryption and verification, submit at least t threshold shares of the verifiers, calculate the joint decryption key, and decrypt the ciphertext to obtain the highest bid; S14: result publicity, the bulletin board generates an anonymous bid number after verifying consistency and broadcasts it for all bidders to verify.

2. The homomorphic encryption based algorithm for electronic auction of bank assets as claimed in claim 1 wherein: When all bidders' bids are encoded into a binary vector, and the original data is encrypted using a symmetric encryption algorithm, and the key parameters are encrypted using ElGamal homomorphic encryption to generate ciphertext, it specifically includes: S21: encrypting the original quote data using the AES algorithm to generate ; S22: Use ElGamal homomorphic encryption for the highest price comparison parameter, satisfying and only release to verify details, where, is the bid of bidder i the lth bit in the encoded binary vector, is the homomorphic ciphertext encrypted using the joint public key K , and is the power of the joint public key K.

3. The homomorphic encryption based algorithm for electronic auction of bank assets as claimed in claim 2 wherein: When at least t threshold shares of the verifiers are submitted, and the joint decryption key is calculated, and the ciphertext is decrypted to obtain the highest bid, it specifically includes: S31: zero-knowledge proof verification of t threshold shares of the verifiers using the Schnorr protocol; S32: if the verification fails, trigger the smart contract to automatically freeze the malicious node's deposit.

4. The homomorphic encryption based bank asset e-auction algorithm of claim 3, wherein: When key generation and distribution are performed, dynamic member management is also included, wherein the dynamic member management comprises the following steps: A11: when a new bidder joins, the bulletin board updates the joint public key and the threshold value A12: when the support node is offline and exits, the threshold shares are reconstructed by the remaining nodes and the key is updated.

5. The homomorphic encryption based algorithm for electronic auction of bank assets as claimed in claim 4 wherein: After hybrid encryption bidding, anonymous bid number generation is also included, wherein the specific steps of anonymous bid number generation include: S41: generation phase, generate a unique identifier by combining ring signature technology and HMAC algorithm to ensure that it cannot be associated with a specific bidder's identity; S42: verification phase, verify the legality of the generated unique identifier through the ring signature public key set.

6. The homomorphic encryption based bank asset e-auction algorithm as claimed in claim 5, wherein: The algorithm integrates a post-quantum secure module, and the quantum secure module is used for: A21: when a quantum attack threat is detected, switch to a lattice-based homomorphic encryption scheme; A22: replace the traditional process with a quantum-resistant threshold decryption protocol to ensure long-term security.

7. The homomorphic encryption based bank asset e-auction algorithm as claimed in claim 6, wherein: When at least t threshold shares of the verifiers are submitted, and the joint decryption key is calculated, and the ciphertext is decrypted to obtain the highest bid, multiple auction parameters are encoded into a weighted vector, and the highest score is determined by comprehensive scoring through homomorphic calculation, and the highest score is the highest bid, wherein the weight distribution of the weighted vector is self-defined.

8. The homomorphic encryption based bank asset e-auction algorithm of claim 7, wherein: It also includes malicious behavior detection, which specifically includes: S51: in the threshold decryption stage, if the decryption results are inconsistent, the bulletin board traces the abnormal node through ring signature; S52: the smart contract automatically executes the punishment logic, including canceling the qualification, deducting the deposit, and publicly recording the abnormality.

9. The homomorphic encryption based bank asset e-auction algorithm as claimed in claim 8, wherein: When the bulletin board verifies consistency and generates an anonymous bid number and broadcasts it for all bidders to verify, it specifically includes: A31: Local verification, bidder passes Confirm result legitimacy; A32: On-chain notarization, write to blockchain, timestamp and hash by smart contract to ensure results are not tamperable. write to blockchain, timestamp and hash by smart contract to ensure results are not tamperable.

10. The homomorphic encryption based bank asset e-auction algorithm as claimed in claim 9, wherein: The algorithm is stored and transmitted through the following steps: S61: sparse matrix compression technology is used for the ciphertext matrix, only the non-zero elements and position indexes are retained; S62: aggregate the multi-round interaction data using homomorphic hash, reduce the communication rounds to within 3 rounds.