Prepaid Payment Method, Device, Equipment and Storage Medium
The multi-party security calculation algorithm is used to segment and distribute bank data, solving the problem of data privacy leakage in the prepaid model and realizing a secure prepaid payment process.
Patent Information
- Application Number
- CN202210335563.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-03-30
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2042-03-30
AI Technical Summary
In the existing prepaid model, when the fund supervision method involves multi-party data as the basis for transfer of funds, there is a risk of data privacy leakage caused by explicit transmission.
Multi-party security calculation algorithms are used to segment and distribute bank data, and the basis for prepayment is obtained through multi-party security calculations to ensure that the data is transmitted ciphertext between all parties and avoid data integrity leakage.
It realizes secure calculation of prepaid payment while protecting data privacy, prevents data leakage and improves the security of data transmission.
Smart Images

Figure CN114626843B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of information security, and more particularly, to a prepaid payment method, apparatus, device, medium, and program product. Background Art
[0002] The prepaid mode means that a user pays an institution providing services in advance and defers consumption or consumes the purchased services multiple times. For example, the prepaid mode is commonly used in industries such as driving test training, education and training, beauty, and fitness. However, there is a risk that the institution "runs away with the money".
[0003] Ways to supervise prepaid funds have been gradually adopted. For example, the prepaid funds are deposited into a special fund supervision account of a bank, and then the prepaid funds are paid to the institution according to the progress of the user's consumption. Among them, determining the consumption progress can be based on querying information by connecting to the supervisor's system or the institution submitting paper documents as the basis for fund transfer.
[0004] In the process of implementing the concept of the present disclosure, the inventors found that there are at least the following problems in the related art: Currently, the fund supervision method involves using multi-party data as the basis for fund transfer. Whether it is in an electronic or paper form, it uses a plaintext method, which poses a risk of data privacy leakage. Summary of the Invention
[0005] In view of the above problems, the present disclosure provides a prepaid payment method, apparatus, device, medium, and program product for preventing data privacy leakage.
[0006] One aspect of an embodiment of the present disclosure provides a prepaid payment method for the bank side, including: processing first bank data according to a multi-party secure computing algorithm to obtain M second bank data, where M is an integer greater than or equal to 2; distributing the data to R data providers based on the M second bank data, where each of the R data providers and the bank side holds at least one second bank data, and R is an integer greater than or equal to 1; receiving at least one prepaid data distributed by the R data providers, where the prepaid data includes data associated with the prepaid for the user to purchase a first service, the bank side stores the prepaid, and the first bank data is associated with the prepaid data; performing multi-party secure computing on the at least one prepaid data and the at least one second bank data to obtain a second calculation result, where the second calculation result is used as the basis for paying the prepaid.
[0007] According to an embodiment of the present disclosure, the R data providers include an institutional side for providing the first service, and the at least one prepaid data includes at least one second institutional data. The multi-party secure computation on the at least one prepaid data and the at least one second bank data to obtain a second computation result includes: performing multi-party secure computation on the at least one second institutional data and the at least one second bank data to obtain the second computation result.
[0008] According to an embodiment of the present disclosure, the R data providers further include a regulatory side for regulating the prepayment. The at least one prepaid data includes at least one second regulatory data. The multi-party secure computation on the at least one prepaid data and the at least one second bank data to obtain a second computation result includes: performing multi-party secure computation on the at least one second institutional data, the at least one second bank data, and the at least one second regulatory data to obtain the second computation result.
[0009] According to an embodiment of the present disclosure, before receiving at least one second institutional data distributed by the institutional side, it further includes: receiving a first counting request sent by the institutional side, where the first counting request is used to query the first bank data; querying the first bank data in response to the first query request; and sending a first response message to the institutional side according to the preparation status of the first bank data, where the first response message is used to represent the preparation status of the first bank data.
[0010] According to an embodiment of the present disclosure, before processing the first bank data according to the multi-party secure computation algorithm, it further includes: receiving a payment request sent by the institutional side, where the payment request includes the multi-party secure computation algorithm.
[0011] According to an embodiment of the present disclosure, the payment request further includes the multi-party secure computation rules among the institutional side, the regulatory side, and the bank side. The multi-party secure computation on the at least one second institutional data, the at least one second bank data, and the at least one second regulatory data to obtain the second computation result includes: performing the multi-party secure computation according to the multi-party secure computation rules, where the multi-party secure computation rules include the preset conditions for paying the prepayment to the institutional side.
[0012] According to an embodiment of the present disclosure, the method further includes: receiving a first computation result provided by the institutional side and a third computation result provided by the regulatory side; performing computation according to the first computation result, the second computation result, and the third computation result to obtain a fourth computation result; and paying the prepayment to the institutional side when the fourth computation result meets the preset conditions.
[0013] According to an embodiment of the present disclosure, the multi-party secure computing algorithm includes a secret sharing protocol algorithm. Processing the first bank data according to the multi-party secure computing algorithm to obtain M second bank data includes: splitting the first bank data according to the secret sharing protocol algorithm to obtain M secret shares, where the M secret shares include the M second bank data.
[0014] According to an embodiment of the present disclosure, the R data providers include a regulatory side, the regulatory side is used to supervise the prepayment, the at least one prepayment data includes at least one second regulatory data, and performing multi-party secure computing on the at least one prepayment data and the at least one second bank data to obtain a second calculation result includes: performing multi-party secure computing on the at least one second regulatory data and the at least one second bank data to obtain the second calculation result.
[0015] Another aspect of the embodiments of the present disclosure provides a prepayment payment device for the bank side, including: a second processing module, configured to process the first bank data according to a multi-party secure computing algorithm to obtain M second bank data, where M is an integer greater than or equal to 2; a second distribution module, configured to distribute data to R data providers based on the M second bank data, where each of the R data providers and the bank side holds at least one second bank data, and R is an integer greater than or equal to 1; a second receiving module, configured to receive at least one prepayment data distributed by the R data providers, where the prepayment data is data associated with the prepayment for the user to purchase the first service, the bank side stores the prepayment, and the first bank data is associated with the prepayment data; a second calculation module, configured to perform multi-party secure computing on the at least one prepayment data and the at least one second bank data to obtain a second calculation result, where the second calculation result is used as a basis for paying the prepayment.
[0016] Another aspect of the embodiments of the present disclosure provides an electronic device, including: one or more processors; a storage device, configured to store one or more programs, where when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the method as described above.
[0017] Another aspect of the embodiments of the present disclosure further provides a computer-readable storage medium, on which executable instructions are stored, and when the instructions are executed by a processor, the processor is caused to execute the method as described above.
[0018] Another aspect of the embodiments of the present disclosure further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the method as described above is implemented.
[0019] One or more of the above embodiments have the following beneficial effects: Compared with the prior art that uses plain text data to confirm prepaid payment, the disclosed embodiment uses a multi-party secure computing method to divide the first bank data into M second bank data and distribute them. Each of the R data providers and the bank side holds at least one second bank data, and performs multi-party secure computing based on at least one prepaid data distributed by the R data providers to obtain a second computing result, which is used as the basis for paying the prepaid fee. Therefore, data ciphertext transmission can be achieved, and each party does not have the complete data of the other parties, thereby avoiding the technical effect of data privacy leakage. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] The above contents and other objects, features and advantages of the present disclosure will become more apparent through the following description of the embodiments of the present disclosure with reference to the accompanying drawings, in which:
[0021] Figure 1 The application scenario diagram of the prepaid payment method according to the embodiment of the present disclosure is schematically shown;
[0022] Figure 2 A flowchart of a prepaid payment method according to an embodiment of the present disclosure is schematically shown;
[0023] Figure 3 A flowchart of a prepaid payment method according to another embodiment of the present disclosure is schematically shown;
[0024] Figure 4 A flowchart of a prepaid payment method according to another embodiment of the present disclosure is schematically shown;
[0025] Figure 5 A flowchart of a prepaid payment method according to another embodiment of the present disclosure is schematically shown;
[0026] Figure 6 Schematically shows an architecture diagram of a multi-party secure computing system for implementing a prepaid payment method according to an embodiment of the present disclosure;
[0027] Figure 7 The structure block diagram of the prepaid payment device for the institution side according to the embodiment of the present disclosure is schematically shown;
[0028] Figure 8 The structure block diagram of the prepaid payment device for the bank side according to the embodiment of the present disclosure is schematically shown;
[0029] Figure 9 The structure block diagram of the prepaid payment device for the supervisory side according to the embodiment of the present disclosure is schematically shown;
[0030] Figure 10A block diagram of an electronic device suitable for implementing a prepaid payment method according to an embodiment of the present disclosure is schematically shown. Detailed implementation manners
[0031] To facilitate understanding of the technical solution of the present application, some technical terms related to the present application are introduced below.
[0032] Data provider: In the process of prepaid payment, the data source for providing relevant data. It may include the institutional side, the regulatory side, or other parties associated with prepaid.
[0033] Institutional side: Used to provide the first service to users. The first service can be an intangible human service or the provision of physical products. Users pay a prepaid fee to purchase the first service.
[0034] Bank side: Stores the prepaid fees of users. Exemplarily, the institutional side may open a prepaid supervision account on the bank side to receive the prepaid fees of users. The institutional side has the right to request payment for the funds in the prepaid supervision account, and the bank side can gradually transfer the prepaid fees to the funds account of the institutional side according to the service situation provided by the institutional side.
[0035] Regulatory side: Used to supervise prepaid fees. Specifically, the regulatory side may include the records of users' consumption of the first service and may also supervise the payment progress of prepaid fees on the bank side.
[0036] Multi-party secure computation: Refers to the process of collaborative computation among a group of mutually untrusted participants while protecting data privacy.
[0037] Multi-party secure computation algorithm: An algorithm that obtains ciphertext data from plaintext data to achieve the purpose of protecting data privacy and supports the completion of multi-party secure computation.
[0038] Secret sharing protocol: The reason why secret sharing can protect data security is mainly achieved by splitting and storing the secret, that is, the secret data is split into several secret shares and distributed to multiple parties for management, so as to achieve the purpose of risk dispersion and intrusion tolerance.
[0039] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are only exemplary and are not intended to limit the scope of the present disclosure. In the following detailed description, for the sake of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure. However, obviously, one or more embodiments can also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessarily confusing the concepts of the present disclosure.
[0040] In the technical solutions of the present disclosure, for the processing of collection, storage, use, processing, transmission, provision, disclosure, and application of the user's personal information, etc., the authorization or consent of the user has been obtained, which complies with the provisions of relevant laws and regulations, takes necessary confidentiality measures, and does not violate public order and good customs.
[0041] With the gradual introduction of supporting regulations related to data security protection, the importance of data privacy protection has become increasingly prominent. The embodiments of the present disclosure overcome the current risk of data privacy leakage and provide a method, device, equipment, medium, and program product for prepaid transfer through collaborative computing based on multi-party data.
[0042] The prepaid payment method of the embodiments of the present disclosure can perform multi-party secure computing by the institutional side and the bank side, or can perform multi-party secure computing by the regulatory side and the bank side, or can perform multi-party secure computing by the institutional side, the bank side, and the regulatory side. Therefore, it can achieve the technical effect of transmitting data in ciphertext, and each party does not master the complete data of other parties, avoiding data privacy leakage.
[0043] Figure 1 An application scenario diagram of the prepaid payment method according to the embodiments of the present disclosure is schematically shown.
[0044] As Figure 1 shown, the application scenario 100 according to this embodiment may include terminal devices 101, 102, 103, a network 104, an institutional side server 105, a bank side server 106, and a regulatory side server 107. The network 104 is used as a medium to provide a communication link between at least two of the terminal devices 101, 102, 103, the network 104, the institutional side server 105, the bank side server 106, and the regulatory side server 107. The network 104 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.
[0045] The user can use the terminal devices 101, 102, 103 to interact with at least one of the institutional side server 105, the bank side server 106, and the regulatory side server 107 through the network 104 to receive or send messages, etc. Various communication client applications may be installed on the terminal devices 101, 102, 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (only for example).
[0046] The terminal devices 101, 102, 103 may be various electronic devices with a display screen and supporting web browsing, including but not limited to smart phones, tablet computers, laptop portable computers, and desktop computers, etc.
[0047] The institution-side server 105, the bank-side server 106, and the regulatory-side server 107 may be servers that provide various services. For example, they may be back-end management servers (only for illustration) that support the websites browsed by users using the terminal devices 101, 102, and 103. The back-end management server may analyze and process data such as user requests received, and feedback the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal devices.
[0048] According to an embodiment of the present disclosure, the institution-side server 105 may store prepaid data for users to purchase services provided by the institution side. The bank-side server 106 may store bank data associated with the prepaid data, such as prepaid account data. The regulatory-side server 107 may store regulatory data associated with the prepaid data, such as whether the user has consumed.
[0049] It should be understood that Figure 1 the numbers of the terminal devices, the network, and the servers in
[0050] are merely illustrative. According to the implementation requirements, there may be any number of terminal devices, networks, and servers. Figure 1 Based on the Figures 2 to 6 scenario described below, the prepaid payment method of the embodiments of the present disclosure will be described in detail through
[0051] Figure 2 FIG. schematically shows a flowchart of the prepaid payment method according to an embodiment of the present disclosure.
[0052] As Figure 2 shown, the prepaid payment method of this embodiment may include operation S210 to operation S240.
[0053] In operation S210, the first bank data is processed according to a multi-party secure computing algorithm to obtain M second bank data, where M is an integer greater than or equal to 2;
[0054] Exemplarily, the multi-party secure computing algorithm may include a homomorphic encryption algorithm, a differential privacy algorithm, a garbled circuit algorithm, an oblivious transfer algorithm, and a secret sharing protocol algorithm, etc.
[0055] In operation S220, based on the M second bank data, data is distributed to R data providers, where each of the R data providers and the bank side holds at least one second bank data, and R is an integer greater than or equal to 1;
[0056] In operation S230, at least one prepaid data distributed by the R data providers is received, where the prepaid data includes data associated with the prepayment for the user to purchase the first service, the bank side stores the prepayment, and the first bank data is associated with the prepaid data;
[0057] In operation S240, multi-party secure computation is performed on at least one prepaid data and at least one second bank data to obtain a second computation result, where the second computation result is used as the basis for paying the prepaid fee.
[0058] Compared with the confirmation of prepaid payment using plaintext data in the prior art, in the embodiments of the present disclosure, by means of multi-party secure computation, the first bank data is segmented into M second bank data and distributed. Each of the R data providers and the bank side holds at least one second bank data, and multi-party secure computation is performed based on at least one prepaid data distributed by the R data providers to obtain a second computation result, which is used as the basis for paying the prepaid fee. Therefore, it is possible to achieve encrypted data transmission, and each party does not have the complete data of other parties, avoiding the technical effect of data privacy leakage.
[0059] Figure 3 A flowchart of a prepaid payment method according to another embodiment of the present disclosure is schematically shown.
[0060] According to an embodiment of the present disclosure, the R data providers include an institutional side, the institutional side is used to provide the first service, and the at least one prepaid data includes at least one second institutional data. The following will be further described in conjunction with Figure 3 Further description.
[0061] As Figure 3 shown, the prepaid payment method of this embodiment includes operation S301 to operation S308.
[0062] In operation S301, the institutional side processes the first institutional data according to a multi-party secure computation algorithm to obtain N second institutional data, where the first institutional data includes the prepaid data for the user to purchase the first service.
[0063] Taking the secret sharing protocol algorithm as an example, the first institutional data can be segmented by means of secret splitting according to the secret sharing protocol algorithm to obtain N secret shares, where the N secret shares include N second institutional data.
[0064] The first institutional data can be segmented according to the algorithm content to obtain multiple second institutional data. Moreover, these multiple second institutional data can participate in subsequent multi-party collaborative computations.
[0065] Exemplarily, the institution may refer to intangible services provided by a driving school, an education and training institution, a vocational training institution, a beauty salon, a fitness institution or a consulting institution, or may also refer to tangible services provided by other institutions, such as tangible products. The tangible product may be prepaid by the user, and the institution provides the product once or multiple times within a certain period in the future.
[0066] Taking a driving school as an example, when a user purchases the driving license test training service of a driving school, they usually pay a one-time fee. The driving school will conduct phased training according to the tests of subjects 1 to 4, and carry out the next stage of training based on the user's passing progress. Among them, the first institution data may include prepaid data, such as user identification, purchase time, passed test subjects, settled fees, failed test subjects, unsettled fees, total prepaid amount, etc. The second institution data can be obtained by splitting some or all of the data among them. For example, splitting the unsettled fees and the total prepaid amount, and the user identification can also be split. This is to avoid the leakage of the user's personal privacy information.
[0067] Exemplarily, for example, the first institution data is the set S i , an N*K-dimensional generation matrix G can be obtained by using multiple random numbers i . Then, a K-dimensional vector A is obtained by splicing K-1 random numbers with the set Si i . Finally, G i and A i are operated on to obtain N second institution data (only for example).
[0068] In operation S302, the institution side distributes data to the bank side based on the N second institution data. Among them, each of the institution side and the bank side holds at least one second institution data, and N is an integer greater than or equal to 2.
[0069] According to the embodiments of the present disclosure, the bank side holds part of the data of the institution side, not all of the data of the institution side. In other words, the data transmission between the institution side and the bank side can prevent being attacked and causing the leakage of user data, thereby improving the security of the data.
[0070] In operation S303, the bank side receives at least one second institution data distributed by the institution side. Among them, since the second institution data is split from the first institution data, at least one second institution data also includes the prepaid data of the user's purchase of the first service.
[0071] In operation S304, the bank side processes the first bank data according to the multi-party secure computing algorithm to obtain M second bank data, and M is an integer greater than or equal to 2.
[0072] Exemplarily, the first bank data may include data such as institution side identification, prepaid supervision account, total amount of this account, paid amount, payment method, institution side capital account, etc. The second bank data can be obtained by splitting some or all of the first bank data.
[0073] Taking the secret sharing protocol algorithm as an example, both the institution side and the bank side use this algorithm. The bank side also uses the method of secret splitting to split the first bank data according to the secret sharing protocol algorithm, obtaining M secret shares, where the M secret shares include M second bank data. The splitting methods used by the institution side and the bank side can be the same, which will not be elaborated here.
[0074] In operation S305, the bank side distributes data to the institution side based on the M second bank data, where each party of the institution side and the bank side holds at least one second bank data.
[0075] According to an embodiment of the present disclosure, the institution side can hold part of the bank side's data regarding the first service, and this part of the data is used to compare with the institution side's data to determine whether it meets the prepaid payment conditions. The data transmitted from the bank side to the institution side is not plaintext data, and it can protect data privacy even if attacked. Since the institution side does not hold the first bank data, it can also prevent the bank side's data from being known by the institution side, thus avoiding data leakage.
[0076] In operation S306, the institution side receives at least one second bank data distributed by the bank side. Among them, since the first bank data is associated with the prepaid data, at least one second bank data split from it is associated with the prepaid data.
[0077] In operation S307, multi-party secure computation is performed on at least one second institution data and at least one second bank data to obtain a first computation result, where the first computation result is used as the basis for paying the prepaid fee.
[0078] In operation S308, multi-party secure computation is performed on at least one second institution data and at least one second bank data to obtain a second computation result, where the second computation result is used as the basis for paying the prepaid fee.
[0079] Exemplarily, the process of obtaining the second institution data or the second bank data is the ciphertext processing stage, and the process of collaborative computation is the privacy computation stage in multi-party secure computation. By involving both the bank side and the institution side in the computation, the computation result can be obtained under the premise of protecting data privacy. And the first computation result and the second computation result determine whether to perform prepaid payment.
[0080] According to an embodiment of the present disclosure, for example, in the scenario of driving school training, after user A passes the first subject, the bank can obtain the passing result of user A. And perform computation based on the first institution data and the first bank data provided by the institution side's request for payment. For example, the first computation result is that the bank pays 1000 yuan for the first subject. The second computation result is that the institution requests to pay 1000 yuan for the first subject. If the two match, then a prepaid payment of 1000 yuan can be made.
[0081] It should be noted that although the above embodiments describe the various operations in a sequential order, the present disclosure does not limit the order between the various operations on the premise that the effect of protecting data privacy in the embodiments of the present disclosure can be achieved. For example, operation S304 may be executed before operation S301 or may be executed simultaneously.
[0082] According to an embodiment of the present disclosure, the R data providers further include a supervision side, the supervision side is used to supervise the prepayment, and the at least one prepayment data includes at least one second supervision data. The following will be further described in conjunction with Figure 4 Further description.
[0083] Figure 4 The flowchart of the prepayment method according to another embodiment of the present disclosure is schematically shown.
[0084] As Figure 4 shown, the prepayment method of this embodiment includes operation S401 to operation S408.
[0085] In operation S401, the supervision side processes the first supervision data according to the multi-party secure computing algorithm to obtain S second supervision data, where S is an integer greater than or equal to 2.
[0086] Exemplarily, the supervision side may be an industry association, a government agency or a third-party non-governmental agency. For example, in the scenario of driving test training, the supervision side may be the traffic management department, and the first supervision data may include the results of the user taking the driver's license test, such as whether the user passes the second subject. In the scenario of education and training, the supervision side may be an industry association, and the association may obtain the number of class hours of training provided by the educational institution to the user and obtain the number of class hours of training that the user has confirmed to have participated in. The bank side can communicate with the supervision side regularly to pay the prepayment to the institution side with reference to the first supervision data.
[0087] Exemplarily, the multi-party secure computing algorithm includes a secret sharing protocol algorithm. The supervision side uses the method of secret splitting to split the first supervision data according to the secret sharing protocol algorithm to obtain S secret shares, where the S secret shares include S second supervision data.
[0088] In operation S402, the supervision side distributes data to the bank side based on the S second supervision data, where each of the bank side and the supervision side holds at least one second supervision data.
[0089] According to an embodiment of the present disclosure, the bank side may hold part of the supervision data of the prepayment for the user to purchase the first service by the supervision side. The data transmission between the bank side and the supervision side is not in plain text transmission, and data leakage can be prevented even if attacked. In addition, it can also avoid the leakage situation that may occur when the bank side holds all the supervision data in the original method.
[0090] In operation S403, the bank side receives at least one second regulatory data distributed by the regulatory side, where at least one second regulatory data is associated with prepaid data.
[0091] In operation S404, the bank side processes the first bank data according to a multi-party secure computing algorithm to obtain M second bank data, where M is an integer greater than or equal to 2.
[0092] In operation S405, the bank side distributes data to the regulatory side based on the M second bank data, where each of the institution side, the regulatory side, and the bank side holds at least one second bank data, and M is an integer greater than or equal to 3.
[0093] In operation S406, the regulatory side receives at least one second bank data distributed by the bank side.
[0094] Exemplarily, the regulatory side can hold part of the bank side's data to facilitate supervision and auditing during the prepaid payment process.
[0095] In operation S407, the regulatory side performs multi-party secure computing on at least one second regulatory data and at least one second bank data to obtain a second calculation result, where the second calculation result is used as the basis for paying the prepaid fee.
[0096] In operation S408, the bank side performs multi-party secure computing on at least one second regulatory data and at least one second bank data to obtain a third calculation result, where the third calculation result is used as the basis for paying the prepaid fee.
[0097] According to an embodiment of the present disclosure, the bank side and the regulatory side can respectively hold part of the bank data and part of the regulatory data for collaborative computing, which can not only improve the security level of the data but also perform prepaid payment based on the second calculation result and the third calculation result.
[0098] It should be noted that although the above embodiments describe each operation in a sequential order, the present disclosure does not limit the order between each operation on the premise that the effect of protecting data privacy in the embodiments of the present disclosure can be achieved.
[0099] For ease of understanding, in the following embodiments, in combination with the scenario of a 20-hour English training course in an education and training institution, through Figure 5 and Figure 6 describe the prepaid payment process in which the institution side, the bank side, and the regulatory side participate in multi-party secure computing. For example, each class hour is 100 yuan, and after every 5 class hours of the course, a prepaid payment can be made to the education and training institution. The 2000 yuan tuition fee for the user to purchase the English training course is stored in the prepaid supervision account on the bank side.
[0100] Figure 5 A flowchart of a prepaid payment method according to another embodiment of the present disclosure is schematically shown. Figure 6 An architecture diagram of a multi-party secure computing system for implementing a prepaid payment method according to an embodiment of the present disclosure is schematically shown.
[0101] As Figure 5 shown, the prepaid payment method of this embodiment includes operations S501 to S529. As Figure 6 shown, the multi-party secure computing system 600 may include a data service unit A601 and a computing engine unit A602 deployed on the institutional side, a data service unit B603, a computing engine unit B604, a scheduling unit 605, and an algorithm unit 606 deployed on the bank side, and a data service unit C608 and a computing engine unit C607 deployed on the regulatory side.
[0102] In operation S501, the institutional-side data service unit A601 sends a first data query request to the bank side, where the first data query request is used to query at least one second bank data. A second data query request is sent to the regulatory side, where the second data query request is used to query at least one second regulatory data.
[0103] Exemplarily, the role of the first data query request is to determine whether the bank side is ready for the bank data required for this collaborative calculation. The role of the second data query request is to determine whether the regulatory side is ready for the regulatory data required for this collaborative calculation. If the bank side or the regulatory side is not ready for the data, then processing the first institutional data is avoided to waste resources.
[0104] In operation S502, the bank-side data service unit B603 receives the first data query request sent by the institutional side, where the first data query request is used to query first bank data.
[0105] Exemplarily, querying the first bank data by the first data query request is substantially the same as querying the second bank data above. The first data query request may include information such as an institutional-side identifier, a user identifier, the consumption progress of the first service, and the requested payment amount. The bank side may query whether there is relevant information and whether collaborative calculation can be performed based on this information.
[0106] In operation S503, the regulatory-side data service unit C608 receives the second data query request sent by the institutional side, where the second data query request is used to query first regulatory data.
[0107] Exemplarily, the second counting request for querying the first regulatory data is substantially the same as the above-mentioned query for the second regulatory data. The second counting request may include information such as the institutional side identifier, user identifier, consumption progress of the first service, and requested payment amount. The regulatory side may query whether there is relevant information based on this information and whether collaborative calculation can be performed.
[0108] According to an embodiment of the present disclosure, the institutional side holds some data of the regulatory side and the bank side and can participate in the collaborative calculation to confirm the prepaid payment result and improve the data security.
[0109] In operation S504, the bank-side data service unit B603 queries the first bank data in response to the first query request. According to the preparation status of the first bank data, a first response message is sent to the institutional side, where the first response message is used to characterize the preparation status of the first bank data.
[0110] Exemplarily, the bank side may query information such as the account of the education and training institution, the prepaid amount, the paid amount, the unpaid amount, or the total amount of this user.
[0111] In operation S505, the institutional-side data service unit A601 receives the first response message returned by the bank side according to the counting request, where the first response message is used to characterize the preparation status of the bank side for at least one second bank data.
[0112] For example, the first response message may be the data readiness information of the bank side.
[0113] In operation S506, the regulatory-side data service unit C608 queries the first regulatory data in response to the second query request. According to the preparation status of the first regulatory data, a second response message is sent to the institutional side, where the second response message is used to characterize the preparation status of the first regulatory data.
[0114] Exemplarily, the first regulatory data may include the identifier of the institutional side, user identifier, English training course information, the number of class hours the user has participated in, or the fee information for a single class hour, etc.
[0115] In operation S507, the institutional-side data service unit A601 receives the second response message returned by the regulatory side according to the counting request, where the second response message is used to characterize the preparation status of the regulatory side for at least one second regulatory data.
[0116] For example, the second response message may be the data readiness information of the regulatory side.
[0117] In operation S508, the institutional side generates a payment request, where the payment request includes the multi-party secure calculation rules among the institutional side, the regulatory side, and the bank side, and the multi-party secure calculation rules include multi-party secure calculation algorithms.
[0118] According to the embodiments of the present disclosure, the payment request can be used as a trigger switch to start the multi-party secure computing task, wherein the multi-party secure computing algorithm facilitates the unified data processing process of all parties and improves the accuracy of the computing results.
[0119] Exemplarily, after receiving the ready response from the regulatory agency and the bank, the institution-side data service unit A601 queries and processes the institution's data and initiates a task request to the multi-party computing system 500 .
[0120] After receiving the task request, the scheduling unit 605 requests the algorithm unit 606 for the content of the multi-party security calculation rules, where the calculation rules include defining the data provider and data source of the calculation task, the result recipient, and the calculation logic (checking whether the reserved information on the institution side is consistent with the reserved information on the regulatory side, checking whether the amount to be settled on the institution side is less than the amount that can be settled on the regulatory side, checking whether the total settlement amount on the institution side is equal to the amount to be settled on the institution side * the unit price of the account on the regulatory association side, checking whether the total settlement amount on the institution side is less than the account balance on the bank side, the order of secret share transmission, such as which part of the secret share each party transmits to the other party, or randomly transmitting the secret share), etc.
[0121] In operation S509, before processing the first institution data according to the multi-party secure computing algorithm, it also includes: sending the payment request to the bank side and / or the regulatory side.
[0122] In some embodiments, after the scheduling unit 605 obtains the calculation rules, it can be returned to the institution side, and the institution side generates a payment request according to the calculation rules and sends it to the calculation engine unit A602, the calculation engine unit B604 and the calculation engine unit C607.
[0123] In some embodiments, after the scheduling unit 605 obtains the calculation rule, it can directly send it to the calculation engine unit A602, the calculation engine unit B604 and the calculation engine unit C607 respectively. Then, the institution side can generate a payment request, which includes the calculation rule or an identifier corresponding to the calculation rule. The bank side and the regulatory side can execute the calculation rule according to the payment request.
[0124] In operation S510, the bank side receives the payment request sent by the institution side.
[0125] In operation S511, the supervision side receives the payment request sent by the institution side.
[0126] In operation S512, the computing engine unit A602 on the institution side obtains the first institution data (ie, the institution data file) from the data service unit A601, and processes it according to the multi-party secure computing algorithm to obtain N second institution data.
[0127] In operation S513, the institutional-side computing engine unit A602 distributes data to the bank side based on N second institutional data, and / or distributes data to the regulatory side based on N second institutional data. Each of the institutional side, the regulatory side, and the bank side holds at least one second institutional data. In this case, N is an integer greater than or equal to 3.
[0128] For example, after the institutional-side data service unit A601 receives a data sending request from the computing engine unit A602, it encrypts the user identification, the quantity / amount to be settled, the reserved information, and the total settlement amount through the secret sharing protocol of multi-party secure computation and then sends them to the computing engine unit A602. The computing engine unit A602 retains one copy of the encrypted data after secret sharing and sends the other two copies to the computing engine unit B604 and the computing engine unit C607 respectively.
[0129] In operation S514, the bank-side computing engine unit B604 receives at least one second institutional data distributed by the institutional side.
[0130] In operation S515, the regulatory-side computing engine unit C607 receives at least one second institutional data distributed by the institutional side.
[0131] In operation S516, the bank-side computing engine unit B604 obtains the first bank data (i.e., the bank data file) from the data service unit B603 and processes the first bank data according to the multi-party secure computation algorithm to obtain M second bank data, where M is an integer greater than or equal to 2.
[0132] Exemplarily, after the data service unit B603 receives a data sending request from the computing engine unit B604, it encrypts the identity ID and the account balance through the secret sharing protocol of multi-party secure computation and then sends them to the computing engine unit B604. The computing engine unit B604 retains one copy of the encrypted data after secret sharing and sends the other two copies to the computing engine unit A602 and the computing engine unit C607 respectively.
[0133] In operation S517, the bank-side computing engine unit B604 distributes data to the institutional side based on M second bank data, and / or distributes data to the regulatory side based on M second bank data. Among them, each of the institutional side, the regulatory side, and the bank side holds at least one second bank data. In this case, M is an integer greater than or equal to 3.
[0134] In operation S518, the institutional-side computing engine unit A602 receives at least one second bank data distributed by the bank side.
[0135] In operation S519, the regulatory-side computing engine unit C607 receives at least one second bank data distributed by the bank side.
[0136] In operation S520, the regulatory-side computing engine unit C607 obtains first regulatory data (i.e., a regulatory data file) from the data service unit C608, and processes the first regulatory data according to a multi-party secure computing algorithm to obtain S second regulatory data, where S is an integer greater than or equal to 2.
[0137] In operation S521, the regulatory-side computing engine unit C607 distributes data to the bank side based on the S second regulatory data, and / or distributes data to the institution side based on the S second regulatory data, where each of the institution side, the regulatory side, and the bank side holds at least one second regulatory data, and S is an integer greater than or equal to 3.
[0138] Exemplarily, after the data service unit C608 receives a send data request from the computing engine unit C607, it encrypts the identity ID, reserved information, settleable quantity, and subject unit price through a secret sharing protocol for multi-party secure computing and sends them to the computing engine unit C607. The computing engine unit C607 retains one copy of the encrypted data after secret sharing, and sends the other two copies to the computing engine unit A602 and the computing engine unit B604 respectively.
[0139] According to an embodiment of the present disclosure, the institution side holds some data of the regulatory side and the bank side and can participate in collaborative computing to confirm the prepaid payment result and improve the security of the data.
[0140] In operation S522, the bank-side computing engine unit B604 receives at least one second regulatory data distributed by the regulatory side.
[0141] In operation S523, the institution-side computing engine unit A602 receives at least one second regulatory data distributed by the regulatory side.
[0142] In operation S524, the institution-side computing engine unit A602 performs multi-party secure computing on at least one second institution data, at least one second bank data, and at least one second regulatory data to obtain a first calculation result.
[0143] According to an embodiment of the present disclosure, the institution side performs multi-party secure computing according to multi-party secure computing rules, where the multi-party secure computing rules include preset conditions for paying prepaid fees to the institution side.
[0144] The preset conditions include, for example, whether there is an amount greater than 500 yuan in the prepaid regulatory account on the bank side. Information confirmed by the regulatory side to the user, such as whether the user has participated in 5 class hours of training. That is, it is determined whether the conditions for making a prepaid payment are met through multi-party secure computing rules.
[0145] In operation S525, the bank-side computing engine unit B604 performs multi-party secure computing on at least one second institutional data, at least one second bank data, and at least one second regulatory data to obtain a second calculation result.
[0146] According to an embodiment of the present disclosure, the bank side performs multi-party secure computing according to the multi-party secure computing rules in the payment request.
[0147] In operation S526, the regulatory-side computing engine unit C607 performs multi-party secure computing on at least one second institutional data, at least one second bank data, and at least one second regulatory data to obtain a third calculation result.
[0148] According to an embodiment of the present disclosure, the regulatory-side computing engine unit C607 performs multi-party secure computing according to the multi-party secure computing rules in the payment request.
[0149] In operation S527, the institutional-side computing engine unit A602 sends the first calculation result, such as sending it to the bank side.
[0150] In operation S528, the regulatory-side computing engine unit C607 sends the third calculation result, such as sending it to the bank side.
[0151] In operation S529, the scheduling unit 605 receives the first calculation result provided by the institutional side and the third calculation result provided by the regulatory side. Calculate according to the first calculation result, the second calculation result, and the third calculation result to obtain a fourth calculation result. When the fourth calculation result meets the preset conditions, prepaid fees are paid to the institutional side.
[0152] Exemplarily, after the institutional side, the regulatory side, and the bank side cooperate to complete the ciphertext calculation, they notify the scheduling unit 605 of their respective calculation results, and the scheduling unit 605 sends the calculation results to the bank-side data service unit B504. After receiving the calculation results, if the data service unit B504 determines that it meets the preset conditions for payment, it feeds back to the fund management system for prepaid fee transfer.
[0153] According to an embodiment of the present disclosure, it is possible to automatically process institutional party personnel data, industry association or government affairs party personnel training or examination data, and bank fund data, and through the secure fusion of multi-party data, thereby protecting the privacy of data of all parties. Integrating the multi-party secure computing technology into the bank fund supervision system has the characteristics of strong versatility, wide scalability, and secure and controllable processing process.
[0154] In some embodiments, for example, to compare whether the amount requested for payment by the institutional side is less than or equal to the amount in the bank-side supervision account, the secret shares of all parties can be calculated for the difference, and then the results output by all parties are calculated for fusion.
[0155] First, the institution side requests a prepayment of 500 yuan for training 5 class hours for the user. Dividing it can obtain 200 yuan, 100 yuan, and 200 yuan. Then, the total amount in the capital supervision account on the bank side is 2000 yuan. Dividing it can obtain 100 yuan, 50 yuan, and 1850 yuan. Next, the institution side, the bank side, and the supervision side can respectively hold 200 yuan, 100 yuan, and 200 yuan of the requested payment amount, and respectively hold 100 yuan, 50 yuan, and 1850 yuan of the total amount. Secondly, the institution side, the bank side, and the supervision side respectively calculate the differences between the total amount and the requested payment amount, such as -100 yuan, -50 yuan, and 1650 yuan, which are the first calculation result, the second calculation result, and the third calculation result. Finally, the bank side sums up -100 yuan, -50 yuan, and 1650 yuan to obtain 1500 yuan (i.e., the fourth calculation result). The fourth calculation result is positive, indicating that there is a condition to pay 500 yuan to the institution side.
[0156] Similarly, the attended class hours on the supervision side and the attended class hours on the institution side can be calculated, or other data can be collaboratively calculated. When the preset conditions are met, the prepayment is paid to the institution side.
[0157] According to the embodiments of the present disclosure, no plaintext data is transmitted between the institution side, the bank side, and the supervision side. Even if an attacker obtains some data, the leakage of user privacy data can be avoided. The data stored by each of the three parties is inconsistent. It may compare the data between any two parties. Since the third party does not hold all the data of the other two parties, the data will not be leaked to the third party. The effect of protecting data privacy while enabling prepayment is achieved.
[0158] It should be noted that although the above embodiments describe the various operations in a sequential order, on the premise that the effect of protecting data privacy in the embodiments of the present disclosure can be achieved, the present disclosure does not limit the order between the various operations.
[0159] Based on the above prepayment payment method, the present disclosure also provides a prepayment payment device applied to the institution side, the bank side, and the supervision side respectively. The following will be combined with Figures 6 to 8 Describe the device in detail.
[0160] Figure 7 The structural block diagram of the prepayment payment device for the institution side according to the embodiments of the present disclosure is schematically shown.
[0161] As Figure 7 shown, the prepayment payment device 700 of this embodiment includes a first processing module 710, a first distribution module 720, a first receiving module 730, and a first calculation module 740.
[0162] The first processing module 710 may perform operation S301 to process the first institutional data according to the multi-party secure computation algorithm to obtain N pieces of second institutional data, where the first institutional data includes the prepayment data of the user for purchasing the first service.
[0163] The first distribution module 720 may perform operation S302 to distribute data to the bank side based on the N pieces of second institutional data, where each party of the institutional side and the bank side holds at least one piece of second institutional data, and N is an integer greater than or equal to 2.
[0164] According to an embodiment of the present disclosure, the first distribution module 720 may perform operation S403 to distribute data to the supervision side based on M pieces of second bank data, where each party of the institutional side, the supervision side, and the bank side holds at least one piece of second bank data, and M is an integer greater than or equal to 3.
[0165] The first receiving module 730 may perform operation S306 to receive at least one piece of second bank data distributed by the bank side, where the at least one piece of second bank data is associated with the prepayment data.
[0166] According to an embodiment of the present disclosure, the first receiving module 730 may perform operation S407 to receive at least one piece of second supervision data distributed by the supervision side, where the at least one piece of second supervision data is associated with the prepayment data.
[0167] The first calculation module 740 may perform operation S307 to perform multi-party secure computation on the at least one piece of second institutional data and the at least one piece of second bank data to obtain a first calculation result, where the first calculation result is used as the basis for paying the prepayment.
[0168] According to an embodiment of the present disclosure, the first calculation module 740 may perform operation S524 to perform multi-party secure computation on the at least one piece of second institutional data, the at least one piece of second bank data, and the at least one piece of second supervision data to obtain a first calculation result.
[0169] Figure 8 Schematically shows a structural block diagram of a prepayment payment device for the bank side according to an embodiment of the present disclosure.
[0170] As Figure 8 shown, the prepayment payment device 800 of this embodiment includes a second processing module 810, a second distribution module 820, a second receiving module 830, and a second calculation module 840.
[0171] The second processing module 810 may perform operation S210 to process the first bank data according to the multi-party secure computation algorithm to obtain M pieces of second bank data, where M is an integer greater than or equal to 2.
[0172] The second distribution module 820 may perform operation S220 to distribute data to R data providers based on the M second bank data, where each of the R data providers and the bank side holds at least one second bank data, and R is an integer greater than or equal to 1.
[0173] According to an embodiment of the present disclosure, the second distribution module 820 may perform operation S405 to distribute data to the regulatory side based on M second bank data.
[0174] The second receiving module 830 may perform operation S230 to receive at least one prepaid data distributed by the R data providers, where the prepaid data includes data associated with the prepayment for a user to purchase a first service, the prepayment is stored on the bank side, and the first bank data is associated with the prepaid data.
[0175] According to an embodiment of the present disclosure, the second receiving module 830 may perform operation S403 to receive at least one second regulatory data distributed by the regulatory side.
[0176] The second calculation module 840 may perform operation S240 to perform multi-party secure calculation on the at least one prepaid data and the at least one second bank data to obtain a second calculation result, where the second calculation result is used as a basis for paying the prepayment.
[0177] According to an embodiment of the present disclosure, the second calculation module 840 may perform operation S525 to perform multi-party secure calculation on at least one second institution data, at least one second bank data, and at least one second regulatory data to obtain a second calculation result.
[0178] According to an embodiment of the present disclosure, the prepaid payment device 800 may further include a fusion calculation module that performs operation S529 to receive a first calculation result provided by the institution side and a third calculation result provided by the regulatory side. Calculate according to the first calculation result, the second calculation result, and the third calculation result to obtain a fourth calculation result. When the fourth calculation result meets a preset condition, pay the prepayment to the institution side.
[0179] Figure 9 A structural block diagram of a prepaid payment device for the regulatory side according to an embodiment of the present disclosure is schematically shown.
[0180] As Figure 9 shown, the prepaid payment device 900 of this embodiment includes a third processing module 910, a third distribution module 920, a third receiving module 930, and a third calculation module 940.
[0181] The third processing module 910 may perform operation S401 to process the first regulatory data according to a multi-party secure computing algorithm, obtaining S second regulatory data, where S is an integer greater than or equal to 2.
[0182] The third distribution module 920 may perform operation S402 to distribute data to the bank side based on the S second regulatory data. Among them, each party on the bank side and the regulatory side holds at least one second regulatory data, and the bank side stores the prepayment for the user to purchase the first service from the institution side.
[0183] According to an embodiment of the present disclosure, the third distribution module 920 may perform operation S521 to distribute data to the institution side based on the S second regulatory data.
[0184] The third receiving module 930 may perform operation S406 to receive at least one second bank data distributed by the bank side. Among them, the first regulatory data and the at least one second bank data are associated with the prepayment.
[0185] According to an embodiment of the present disclosure, the third receiving module 930 may perform operation S503 to receive at least one second institution data distributed by the institution side.
[0186] The third computing module 940 may perform operation S407 to perform multi-party secure computing on the at least one second regulatory data and the at least one second bank data, obtaining a third computing result. Among them, the third computing result is used as the basis for paying the prepayment.
[0187] According to an embodiment of the present disclosure, the third computing module 940 may perform operation S526 to perform multi-party secure computing on the at least one second institution data, the at least one second bank data, and the at least one second regulatory data, obtaining a third computing result.
[0188] It should be noted that the implementation manners, the technical problems solved, the functions achieved, and the technical effects achieved by each module / unit / sub-unit, etc. in the device partial embodiments are respectively the same as or similar to those of the corresponding steps in the method partial embodiments, and will not be elaborated herein.
[0189] According to an embodiment of the present disclosure, any multiple modules in the prepayment payment device 700, the prepayment payment device 800, or the prepayment payment device 900 may be combined and implemented in one module, or any one of the modules may be split into multiple modules. Or, at least part of the functions of one or more of these modules may be combined with at least part of the functions of other modules and implemented in one module.
[0190] According to an embodiment of the present disclosure, at least one module in the prepaid payment device 700, the prepaid payment device 800, or the prepaid payment device 900 can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on a substrate, a system in a package, an application specific integrated circuit (ASIC), or any other reasonable way of integrating or packaging circuits, etc., implemented by hardware or firmware, or implemented in any one of the three implementation manners of software, hardware, and firmware, or in an appropriate combination of any several of them. Alternatively, at least one module in the prepaid payment device 700, the prepaid payment device 800, or the prepaid payment device 900 can be at least partially implemented as a computer program module, and when the computer program module is run, it can execute corresponding functions.
[0191] Figure 10 FIG. schematically shows a block diagram of an electronic device suitable for implementing the prepaid payment method according to an embodiment of the present disclosure.
[0192] As Figure 10 shown, the electronic device 1000 according to an embodiment of the present disclosure includes a processor 1001, which can perform various appropriate actions and processes according to a program stored in a read only memory (ROM) 1002 or a program loaded from a storage section 1008 into a random access memory (RAM) 1003. The processor 1001 can include, for example, a general microprocessor (such as a CPU), an instruction set processor, and / or a related chipset, and / or a dedicated microprocessor (such as an application specific integrated circuit (ASIC)), etc. The processor 1001 can also include on-board memory for caching purposes. The processor 1001 can include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.
[0193] In the RAM 1003, various programs and data required for the operation of the electronic device 1000 are stored. The processor 1001, the ROM 1002, and the RAM 1003 are connected to each other through a bus 1004. The processor 1001 performs various operations of the method flow according to an embodiment of the present disclosure by executing the program in the ROM 1002 and / or the RAM 1003. It should be noted that the program can also be stored in one or more memories other than the ROM 1002 and the RAM 1003. The processor 1001 can also perform various operations of the method flow according to an embodiment of the present disclosure by executing the program stored in one or more memories.
[0194] According to an embodiment of the present disclosure, the electronic device 1000 may further include an input / output (I / O) interface 1005, and the input / output (I / O) interface 1005 is also connected to the bus 1004. The electronic device 1000 may further include one or more of the following components connected to the I / O interface 1005: an input portion 1006 including a keyboard, a mouse, etc. An output portion 1007 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc. A storage portion 1008 including a hard disk, etc. And a communication portion 1009 including a network interface card such as a LAN card, a modem, etc. The communication portion 1009 performs communication processing via a network such as the Internet. The drive 1010 is also connected to the I / O interface 1005 as needed. A removable medium 1011, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 1010 as needed so that a computer program read from it can be installed into the storage portion 1008 as needed.
[0195] The present disclosure also provides a computer-readable storage medium, which may be included in the device / device / system described in the above embodiments. It may also exist separately without being assembled into the device / device / system. The above computer-readable storage medium carries one or more programs, and when the above one or more programs are executed, the method according to the embodiments of the present disclosure is implemented.
[0196] According to an embodiment of the present disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, for example, it may include but is not limited to: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, device, or device. For example, according to an embodiment of the present disclosure, the computer-readable storage medium may include the above-described ROM 1002 and / or RAM 1003 and / or one or more memories other than ROM 1002 and RAM 1003.
[0197] Embodiments of the present disclosure also include a computer program product, which includes a computer program that contains program code for executing the method shown in the flowchart. When the computer program product runs in a computer system, the program code is used to cause the computer system to implement the method provided by the embodiments of the present disclosure.
[0198] When the computer program is executed by the processor 1001, the above functions defined in the system / apparatus of the embodiments of the present disclosure are executed. According to an embodiment of the present disclosure, the above-described systems, apparatuses, modules, units, etc. can be implemented by computer program modules.
[0199] In one embodiment, the computer program can rely on tangible storage media such as optical storage devices, magnetic storage devices, etc. In another embodiment, the computer program can also be transmitted and distributed in the form of signals on a network medium, and downloaded and installed through the communication part 1009, and / or installed from the removable medium 1011. The program code included in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.
[0200] In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 1009, and / or installed from the removable medium 1011. When the computer program is executed by the processor 1001, the above functions defined in the system of the embodiments of the present disclosure are executed. According to an embodiment of the present disclosure, the above-described systems, devices, apparatuses, modules, units, etc. can be implemented by computer program modules.
[0201] According to an embodiment of the present disclosure, the program code for executing the computer program provided in the embodiments of the present disclosure can be written in any combination of one or more programming languages. Specifically, these computing programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include but are not limited to, such as Java, C++, python, the "C" language, or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, by using an Internet service provider to connect through the Internet).
[0202] The above describes the embodiments of the present disclosure. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present disclosure. Although the embodiments are described separately above, this does not mean that the measures in each embodiment cannot be used advantageously in combination. The scope of the present disclosure is defined by the appended claims and their equivalents. Without departing from the scope of the present disclosure, those skilled in the art can make various substitutions and modifications, and these substitutions and modifications should all fall within the scope of the present disclosure.
Claims
1. A prepaid payment method for the bank side, comprising: Processing first bank data according to a multi-party secure computation algorithm to obtain M second bank data, where M is an integer greater than or equal to 2; Distributing data to R data providers based on the M second bank data, wherein each of the R data providers and the bank side holds at least one second bank data, and R is an integer greater than or equal to 1; Receiving at least one prepaid data distributed by the R data providers, wherein the prepaid data includes data associated with the prepayment for the user to purchase the first service, the prepaid data is processed according to a multi-party secure computation algorithm, the bank side stores the prepaid amount, and the first bank data is associated with the prepaid data; Performing multi-party secure computation on the at least one prepaid data and the at least one second bank data to obtain a second computation result, wherein the second computation result is used as the basis for paying the prepaid amount.
2. The method according to claim 1, wherein The R data providers include an institution side, the institution side is used to provide the first service, the at least one prepaid data includes at least one second institution data, and performing multi-party secure computation on the at least one prepaid data and the at least one second bank data to obtain a second computation result includes: Performing multi-party secure computation on the at least one second institution data and the at least one second bank data to obtain the second computation result.
3. The method according to claim 2, wherein, The R data providers further include a supervision side, the supervision side is used to supervise the prepaid amount, the at least one prepaid data includes at least one second supervision data, and performing multi-party secure computation on the at least one prepaid data and the at least one second bank data to obtain a second computation result includes: Performing multi-party secure computation on the at least one second institution data, the at least one second bank data and the at least one second supervision data to obtain the second computation result.
4. The method according to claim 3, wherein, Before receiving at least one second institution data distributed by the institution side, it further includes: Receiving a first counting request sent by the institution side, wherein the first counting request is used to query the first bank data; Querying the first bank data in response to the first query request; Sending a first response message to the institution side according to the preparation status of the first bank data, wherein the first response message is used to represent the preparation status of the first bank data.
5. The method according to claim 4, wherein Before processing the first bank data according to the multi-party secure computation algorithm, it further includes: Receiving a payment request sent by the institution side, wherein the payment request includes the multi-party secure computation algorithm.
6. The method according to claim 5, wherein, The payment request further includes the multi-party secure computation rules among the institution side, the supervision side and the bank side, and performing multi-party secure computation on the at least one second institution data, the at least one second bank data and the at least one second supervision data to obtain the second computation result includes: Performing the multi-party secure computation according to the multi-party secure computation rules, wherein the multi-party secure computation rules include the preset conditions for paying the prepaid amount to the institution side.
7. The method according to claim 6, wherein, It further includes: Receiving the first calculation result provided by the institution side and the third calculation result provided by the supervision side; Calculating according to the first calculation result, the second calculation result and the third calculation result to obtain a fourth calculation result; Paying the prepaid fee to the institution side when the fourth calculation result meets the preset conditions.
8. The method according to claim 1, wherein, The multi-party secure calculation algorithm includes a secret sharing protocol algorithm. The processing of the first bank data according to the multi-party secure calculation algorithm to obtain M second bank data includes: Dividing the first bank data according to the secret sharing protocol algorithm to obtain M secret shares, where the M secret shares include the M second bank data.
9. The method according to claim 1, wherein, The R data providers include the supervision side. The supervision side is used to supervise the prepaid fee. The at least one prepaid fee data includes at least one second supervision data. The performing multi-party secure calculation on the at least one prepaid fee data and the at least one second bank data to obtain a second calculation result includes: Performing multi-party secure calculation on the at least one second supervision data and the at least one second bank data to obtain the second calculation result.
10. A prepaid payment device for the bank side, comprising: A second processing module, configured to process the first bank data according to a multi-party secure calculation algorithm to obtain M second bank data, where M is an integer greater than or equal to 2; A second distribution module, configured to distribute data to R data providers based on the M second bank data, where each of the R data providers and the bank side holds at least one second bank data, and R is an integer greater than or equal to 1; A second receiving module, configured to receive at least one prepaid fee data distributed by the R data providers, where the prepaid fee data includes data associated with the prepaid fee for the user to purchase the first service, the prepaid fee data is processed according to a multi-party secure calculation algorithm, the bank side stores the prepaid fee, and the first bank data is associated with the prepaid fee data; A second calculation module, configured to perform multi-party secure calculation on the at least one prepaid fee data and the at least one second bank data to obtain a second calculation result, where the second calculation result is used as the basis for paying the prepaid fee.
11. An electronic device, comprising: One or more processors; A storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the method according to any one of claims 1 to 9.
12. A computer-readable storage medium, on which executable instructions are stored, and when the instructions are executed by a processor, the processor is caused to execute the method according to any one of claims 1 to 9.
13. A computer program product, comprising a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 9 is implemented.
Citation Information
Patent Citations
Multi-party data interaction method and system based on secure multi-party computing
CN114239032A