Transaction data processing system, method, electronic device and readable storage medium
By leveraging the collaborative work of bank servers and control equipment and utilizing encryption technology to generate a fund transfer tree, the security of legitimate user data in telecommunications fraud cases has been resolved, thereby improving both data security and case-handling efficiency.
Patent Information
- Application Number
- CN202210632546.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-06
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2042-06-06
AI Technical Summary
Existing technologies cannot guarantee the security of legitimate users' transaction data when handling telecommunications fraud cases, especially during fund transfers between multiple banks, where legitimate users' data is easily leaked.
By employing the collaborative work of bank servers and control devices in the transaction data processing system, and utilizing symmetric key and public key encryption technologies, bank account information is encrypted to generate a funds transfer tree, ensuring data security, and the data is spliced and analyzed without sharing plaintext data.
It improves the security of transaction data, reduces the possibility of data leakage, protects the information security of legitimate users, improves the case-handling efficiency of anti-fraud agencies, and solves the problem of transactions being irreversible in traditional technologies.
Smart Images

Figure CN115018489B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of communication, in particular to a transaction data processing system and method, an electronic device and a readable storage medium. BACKGROUND
[0002] In recent years, telecommunications fraud cases continue to occur frequently. Criminals transfer fraud funds in the following way: criminal gangs transfer the funds obtained by fraud to multiple accounts for transactions (which may include transactions of legitimate users), which may involve multiple banks, and finally transfer the funds to the behind-the-scenes account. To find the behind-the-scenes account, case handling agencies (such as anti-fraud agencies) usually need to obtain the transaction transfer process (such as a fund transfer graph) of the criminal gang.
[0003] Under the prior art, the fund transfer graph of the criminal gang is usually obtained through data sharing between multiple banks. However, since the transaction transfer process may involve many transactions of legitimate users, it is difficult to ensure the data security of legitimate users. SUMMARY
[0004] The purpose of the embodiments of the present application is to provide a transaction data processing system and method, an electronic device and a readable storage medium, which can improve data security when processing transaction data.
[0005] In one aspect, a transaction data processing system is provided, which includes multiple bank servers and a control device:
[0006] The control device is configured to send a transaction query request to each bank server and splice the transaction trees returned by each bank server to generate a fund transfer tree. The transaction query request includes starting bank account information or leaf nodes in the transaction trees returned by each bank server. Both the transaction trees and the fund transfer tree include bank account ciphertexts of multiple bank account information, which are used to represent transactions between multiple bank accounts.
[0007] Each bank server is configured to determine, when receiving the transaction query request, target bank account information to be queried based on the transaction query request, query associated bank account information of the target bank account information based on the target bank account information, and encrypt the target bank account information and the associated bank account information using encryption keys corresponding to the banks to which the bank account information belongs, respectively, to obtain multiple bank account ciphertexts. The bank server generates a transaction tree based on the bank account ciphertexts and sends the transaction tree to the control device.
[0008] In one embodiment, the control device is configured to:
[0009] When it is determined that the user query instruction is received, the starting bank account information in the user query instruction is obtained, and a transaction query request containing the starting bank account information is sent to the bank to which the starting bank account information belongs; or when it is determined that the transaction tree returned by any bank server is received, the leaf node in the transaction tree is obtained, and a transaction query request containing the leaf node is sent to each bank server, each node in the transaction tree is a bank account ciphertext, and the leaf node is a bank account ciphertext without a child node.
[0010] Each bank server is configured to: when it is determined that the transaction query request containing the starting bank account information is received, determine the initial bank account information contained in the transaction query request as the target bank account information; or when it is determined that the transaction query request containing the leaf node is received, obtain the leaf node contained in the transaction query request, decrypt the leaf node, and determine the decrypted leaf node as the target bank account information.
[0011] In an implementation, each bank server is configured to:
[0012] Based on the target bank account in the target bank account information and the transaction information, the associated bank account and the corresponding transaction timestamp of the associated bank account are obtained, the associated bank account being a bank account that directly or indirectly obtains the transfer-in fund from the target bank account information.
[0013] Based on the transaction timestamp corresponding to the associated bank account, the transaction information of the associated bank account is generated.
[0014] Based on the obtained associated bank account and the corresponding transaction information, the retrieval is performed until a retrieval stop condition is reached.
[0015] In an implementation, each bank server is configured to cyclically perform the following steps until a retrieval stop condition is reached:
[0016] Based on the obtained associated bank account and the corresponding transaction information, the retrieval is performed.
[0017] If it is determined that the retrieval result is empty, it is determined that the retrieval stop condition is reached.
[0018] Otherwise, the next associated bank account information is obtained, the next associated bank account information containing the next associated bank account and the corresponding transaction information of the next associated bank account.
[0019] In an implementation, the associated bank account information contains the associated bank account, and the target bank account information contains the target bank account, and each bank server is configured to:
[0020] From the associated bank account, the associated bank account whose bank to which the associated bank account belongs is the same as the bank to which the target bank account belongs is screened out.
[0021] encrypt the target bank account and the screened associated bank account using a symmetric key corresponding to the bank to which the target bank account belongs, to obtain corresponding bank account ciphertexts;
[0022] encrypt the un-screened associated bank account using a public key corresponding to the bank to which the un-screened associated bank account belongs, to obtain corresponding bank account ciphertexts.
[0023] In an implementation, each bank server is configured to:
[0024] encrypt the target bank account using a symmetric key corresponding to the bank to which the target bank account belongs, to obtain initial bank account ciphertexts;
[0025] If it is determined that the target bank account information is obtained based on a leaf node in the transaction query request, obtain bank account ciphertexts of the target bank account based on the initial bank account ciphertexts and the leaf node corresponding to the target bank account information.
[0026] In an implementation, the control device is configured to:
[0027] For the two target transaction trees, if it is determined that there are matching bank account ciphertexts in the two target transaction trees, splice the two target transaction trees based on the matching bank account ciphertexts.
[0028] The target transaction tree is any one of the transaction trees and the spliced transaction tree.
[0029] In an implementation, the control device is further configured to:
[0030] If it is determined that the root node in one target transaction tree contains a target leaf node in another target transaction tree, determine that the target leaf node and the root node match; the target leaf node is any leaf node in one target transaction tree.
[0031] Splice the target leaf node and the root node.
[0032] In an implementation, the control device is further configured to:
[0033] Analyze each bank account ciphertext in the fund transfer tree to determine an abnormal bank account ciphertext.
[0034] Send the abnormal bank account ciphertext to each bank server, so that each bank server decrypts the abnormal bank account ciphertext using a local symmetric key.
[0035] Receive an abnormal bank account returned by each bank server based on the abnormal bank account ciphertext.
[0036] In one aspect, a method for transaction data processing is provided, which is applied to a control device in a transaction data processing system, the transaction data processing system further comprising a plurality of bank servers, and the method comprises:
[0037] sending a transaction query request to each bank server, the transaction query request comprising starting bank account information or leaf nodes in a transaction tree returned by each bank server;
[0038] receiving the transaction tree returned by each bank server based on the transaction query request, the transaction tree comprising a plurality of bank account ciphertexts obtained by encrypting a plurality of bank account information using an encryption key corresponding to a bank to which the bank account information belongs, and used to represent transactions between the plurality of bank accounts;
[0039] splicing the transaction trees returned by each bank server to generate a fund transfer tree, the fund transfer tree comprising a plurality of bank account ciphertexts obtained by encrypting a plurality of bank account information, and used to represent transactions between the plurality of bank accounts.
[0040] In the above implementation process, the encryption key corresponding to the bank to which the bank account information belongs is used to encrypt the bank account information to generate the fund transfer tree, thereby improving data security.
[0041] In one embodiment, the transaction query request sent to each bank server comprises:
[0042] determining that the starting bank account information in the user query instruction is obtained when the user query instruction is received, and sending the transaction query request comprising the starting bank account information to the bank to which the starting bank account information belongs;
[0043] Alternatively, when the transaction tree returned by any bank server is received, the leaf nodes in the transaction tree are obtained, and the transaction query request comprising the leaf nodes is sent to each bank server, each node in the transaction tree being a bank account ciphertext, and the leaf node being a bank account ciphertext without a child node.
[0044] In the above implementation process, the starting bank account and the leaf node can be used for retrieval.
[0045] In one embodiment, the transaction trees returned by each bank server are spliced to generate the fund transfer tree, comprising:
[0046] if it is determined that the root node in a target transaction tree of the transaction trees comprises a target leaf node in another target transaction tree, it is determined that the target leaf node and the root node match, the target transaction tree being any one of the transaction trees and the spliced transaction tree, and the target leaf node being any leaf node in the target transaction tree;
[0047] splicing the target leaf node and the root node.
[0048] In the implementation process, the transaction trees can be spliced to obtain the fund transfer tree.
[0049] In an implementation, the method is further used for:
[0050] analyzing the bank account ciphertexts in the fund transfer tree to determine abnormal bank account ciphertexts;
[0051] sending the abnormal bank account ciphertexts to the bank servers, so that the bank servers respectively decrypt the abnormal bank account ciphertexts using local symmetric keys;
[0052] receiving abnormal bank accounts returned by the bank servers based on the abnormal bank account ciphertexts.
[0053] In the implementation process, only the abnormal bank account ciphertexts are decrypted by the bank servers, thereby ensuring the data security of legitimate users.
[0054] In one aspect, a transaction data processing method is provided, which is applied to any bank server in a transaction data processing system, and the transaction data processing system further includes a control device. The method includes:
[0055] determining, when a transaction query request is received, target bank account information to be queried based on the transaction query request; the transaction query request includes starting bank account information or leaf nodes in a transaction tree returned by the bank servers;
[0056] querying associated bank account information of the target bank account information based on the target bank account information;
[0057] encrypting the target bank account information and the associated bank account information using encryption keys set by banks to which the bank account information belongs, respectively, to obtain a plurality of bank account ciphertexts;
[0058] generating a transaction tree based on the bank account ciphertexts;
[0059] sending the transaction tree to the control device, so that the control device splices the transaction trees returned by the bank servers to generate a fund transfer tree; the transaction tree and the fund transfer tree both include bank account ciphertexts of a plurality of bank account information encrypted, and are both used to represent transactions between the plurality of bank accounts.
[0060] In the implementation process, the bank account ciphertexts are generated by encrypting the bank account information using the encryption keys set by the banks to which the bank account information belongs, thereby improving the data security.
[0061] In an implementation, when it is determined that the transaction query request is received, target bank account information to be queried is determined based on the transaction query request, including:
[0062] When it is determined that the transaction query request containing the initial bank account information is received, the initial bank account information contained in the transaction query request is determined as the target bank account information;
[0063] Alternatively, when it is determined that the transaction query request containing the leaf node is received, the leaf node contained in the transaction query request is obtained, the leaf node is decrypted, and the decrypted leaf node is determined as the target bank account information.
[0064] In the above implementation process, the target bank account information can be determined based on the initial bank account and the leaf node for subsequent retrieval.
[0065] In an implementation, based on the target bank account information, the associated bank account information of the target bank account information is queried, including:
[0066] Based on the target bank account in the target bank account information and the transaction information, retrieval is performed to obtain the associated bank account and the corresponding transaction timestamp of the associated bank account, the associated bank account being a bank account that directly or indirectly obtains the transferred fund from the target bank account information;
[0067] Based on the transaction timestamp corresponding to the associated bank account, transaction information of the associated bank account is generated;
[0068] Based on the obtained associated bank account and the corresponding transaction information, retrieval is performed until a retrieval stop condition is reached.
[0069] In the above implementation process, the associated bank account that directly or indirectly obtains the transferred fund from the target bank account can be obtained through retrieval.
[0070] In an implementation, based on the obtained associated bank account and the corresponding transaction information, retrieval is performed until a retrieval stop condition is reached, including:
[0071] The following steps are repeatedly performed until the retrieval stop condition is reached:
[0072] Based on the obtained associated bank account and the corresponding transaction information, retrieval is performed;
[0073] If it is determined that the retrieval result is empty, it is determined that the retrieval stop condition is reached;
[0074] Otherwise, the next associated bank account information is obtained, the next associated bank account information containing the next associated bank account and the corresponding transaction information.
[0075] In an embodiment, the associated bank account information includes an associated bank account, the target bank account information includes a target bank account, and the target bank account information and the associated bank account information are respectively encrypted using an encryption key corresponding to the bank to which the bank account information belongs, to obtain a plurality of bank account ciphertexts, including:
[0076] From the associated bank accounts, the associated bank accounts whose banks are the same as the bank to which the target bank account belongs are screened out;
[0077] The target bank account and the screened-out associated bank accounts are respectively encrypted using a symmetric key corresponding to the bank to which the target bank account belongs, to obtain corresponding bank account ciphertexts;
[0078] The un-screened associated bank accounts are encrypted using a public key corresponding to the bank to which the un-screened associated bank accounts belong, to obtain corresponding bank account ciphertexts.
[0079] In the above implementation process, the public key of the bank to which the cross-bank account belongs is used for encryption to obtain the bank account ciphertext, so as to splice the subsequent transaction tree.
[0080] In an embodiment, the target bank account information is encrypted using a symmetric key corresponding to the bank to which the target bank account belongs, to obtain a corresponding bank account ciphertext, including:
[0081] If it is determined that the target bank account information is obtained based on a leaf node in the transaction query request, the target bank account is encrypted using a symmetric key corresponding to the bank to which the target bank account belongs, to obtain an initial bank account ciphertext;
[0082] Based on the initial bank account ciphertext and the leaf node corresponding to the target bank account information, the bank account ciphertext of the target bank account is obtained.
[0083] In the above implementation process, the encryption results encrypted using the public key and the symmetric key are obtained to splice the subsequent transaction tree.
[0084] On the one hand, a transaction data processing apparatus is provided, which is applied to a control device in a transaction data processing system, and the transaction data processing system further includes a plurality of bank servers, including:
[0085] A sending unit is configured to send a transaction query request to each bank server, and the transaction query request includes starting bank account information or a leaf node in a transaction tree returned by each bank server;
[0086] The returning unit is configured to receive the transaction trees returned by the bank servers based on the transaction query request; the transaction trees contain a plurality of bank account ciphertexts obtained by encrypting a plurality of bank account information using an encryption key corresponding to a bank to which the bank account information belongs, and used to represent transactions among the plurality of bank accounts.
[0087] The splicing unit is configured to splice the transaction trees returned by the bank servers to generate a fund transfer tree; the fund transfer tree contains a plurality of bank account ciphertexts obtained by encrypting a plurality of bank account information, and used to represent transactions among the plurality of bank accounts.
[0088] In an embodiment, the sending unit is configured to:
[0089] determine, when the user query instruction is received, the starting bank account information in the user query instruction, and send the transaction query request containing the starting bank account information to the bank to which the starting bank account information belongs;
[0090] Alternatively, determine, when the transaction tree returned by any bank server is received, the leaf node in the transaction tree, and send the transaction query request containing the leaf node to each bank server; each node in the transaction tree is a bank account ciphertext, and the leaf node is a bank account ciphertext without a child node.
[0091] In an embodiment, the splicing unit is configured to:
[0092] determine that the target leaf node and the root node match if the root node in a target transaction tree of the transaction trees contains the target leaf node in another target transaction tree; the target transaction tree is any one of the transaction trees and the spliced transaction tree, and the target leaf node is any leaf node in a target transaction tree;
[0093] splice the target leaf node and the root node.
[0094] In an embodiment, the splicing unit is further configured to:
[0095] analyze each bank account ciphertext in the fund transfer tree to determine an abnormal bank account ciphertext;
[0096] send the abnormal bank account ciphertext to each bank server, so that each bank server decrypts the abnormal bank account ciphertext using a local symmetric key;
[0097] receive an abnormal bank account returned by each bank server based on the abnormal bank account ciphertext.
[0098] In one aspect, a transaction data processing apparatus is provided, which is applied to any bank server in a transaction data processing system, and the transaction data processing system further includes a control device, which includes:
[0099] determining unit, configured to determine, when receiving a transaction query request, target bank account information to be queried based on the transaction query request, wherein the transaction query request contains starting bank account information or leaf nodes in a transaction tree returned by each bank server;
[0100] querying unit, configured to query associated bank account information of the target bank account information based on the target bank account information;
[0101] encryption unit, configured to respectively encrypt the target bank account information and the associated bank account information by using encryption keys corresponding to banks to which the bank account information belongs, to obtain a plurality of bank account ciphertexts;
[0102] generating unit, configured to generate a transaction tree based on the plurality of bank account ciphertexts;
[0103] sending unit, configured to send the transaction tree to a control device, so that the control device splices the transaction trees returned by the bank servers to generate a fund transfer tree, wherein the transaction tree and the fund transfer tree both contain bank account ciphertexts of a plurality of bank account information encrypted, and both are used to represent transactions between the plurality of bank accounts.
[0104] In an implementation manner, the determining unit is configured to:
[0105] when receiving the transaction query request containing the starting bank account information, determine the starting bank account information contained in the transaction query request as the target bank account information;
[0106] or, when receiving the transaction query request containing the leaf nodes, acquire the leaf nodes contained in the transaction query request, decrypt the leaf nodes, and determine the decrypted leaf nodes as the target bank account information.
[0107] In an implementation manner, the querying unit is configured to:
[0108] perform retrieval based on the target bank account in the target bank account information and transaction information, to obtain an associated bank account and a corresponding transaction timestamp of the associated bank account, the associated bank account being a bank account that directly or indirectly obtains transferred funds from the target bank account information;
[0109] generate transaction information of the associated bank account based on the transaction timestamp corresponding to the associated bank account;
[0110] perform retrieval based on the obtained associated bank account and the corresponding transaction information, until a retrieval stop condition is reached.
[0111] In an implementation manner, the querying unit is configured to:
[0112] The following steps are executed in a loop until a search stop condition is reached:
[0113] Based on the obtained associated bank account and its corresponding transaction information, search is performed;
[0114] If it is determined that the search result is empty, it is determined that the search stop condition is reached;
[0115] Otherwise, the next associated bank account information is obtained, the next associated bank account information comprising a next associated bank account and its corresponding transaction information.
[0116] In an implementation form, the associated bank account information comprises an associated bank account, the target bank account information comprises a target bank account, and the encryption unit is configured to:
[0117] From the associated bank account, filter out the associated bank account whose bank is the same as the bank to which the target bank account belongs;
[0118] Using a symmetric key corresponding to the bank to which the target bank account belongs, encrypt the target bank account and the filtered associated bank account respectively to obtain corresponding bank account ciphertexts;
[0119] Using a public key corresponding to the bank to which the unfiltered associated bank account belongs, encrypt the unfiltered associated bank account to obtain corresponding bank account ciphertexts.
[0120] In an implementation form, the encryption unit is configured to:
[0121] If it is determined that the target bank account information is obtained based on a leaf node in the transaction query request, using a symmetric key corresponding to the bank to which the target bank account belongs, encrypt the target bank account to obtain an initial bank account ciphertext;
[0122] Based on the initial bank account ciphertext and the leaf node corresponding to the target bank account information, obtain the bank account ciphertext of the target bank account.
[0123] In an aspect, an electronic device is provided, comprising a processor and a memory, the memory storing computer readable instructions which, when executed by the processor, perform the steps of the method provided in any of the various optional implementation forms of the transaction data processing described above.
[0124] In an aspect, a computer readable storage medium is provided, storing a computer program thereon, the computer program, when executed by a processor, performing the steps of the method provided in any of the various optional implementation forms of the transaction data processing described above.
[0125] In one aspect, a computer program product is provided that, when run on a computer, causes the computer to perform the steps of the methods provided in any of the various optional implementations of transaction data processing described above.
[0126] Other features and advantages of the present application will be set forth in the following description, and in part will be apparent from the description, or can be learned by practice of the application. The objects and other advantages of the present application will be realized and attained by the structure particularly pointed out in the written description and claims thereof as well as the appended drawings. BRIEF DESCRIPTION OF DRAWINGS
[0127] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments of the present application. It should be understood that the following drawings only show some of the embodiments of the present application, and therefore should not be considered as a limitation to the scope, and for those skilled in the art, other related drawings can also be obtained without creative labor on the basis of these drawings.
[0128] Figure 1 An architecture schematic diagram of a transaction data processing system provided by the embodiments of the present application;
[0129] Figure 2 A flowchart of a transaction data processing method provided by the embodiments of the present application;
[0130] Figure 3 A schematic diagram of a transaction tree generation provided by the embodiments of the present application Figure 1 ;
[0131] Figure 4 A schematic diagram of a transaction tree generation provided by the embodiments of the present application Figure 2 ;
[0132] Figure 5 A schematic diagram of a transaction tree generation provided by the embodiments of the present application Figure 3 ;
[0133] Figure 6 A schematic diagram of a search stop provided by the embodiments of the present application;
[0134] Figure 7 A schematic diagram of a fund transfer tree provided by the embodiments of the present application;
[0135] Figure 8 A structure block diagram of a transaction data processing device provided by the embodiments of the present application Figure 1 ;
[0136] Figure 9 A structure block diagram of a transaction data processing device provided by the embodiments of the present application Figure 2 ;
[0137] Figure 10 Fig. 1 is a schematic diagram of a structure of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0138] The technical solutions in the embodiments of the present application will be clearly and completely described in connection with the accompanying drawings of the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application. The components of the embodiments of the present application described and shown in the accompanying drawings can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the claimed present application, but only represents selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of protection of the present application.
[0139] It should be noted that: similar reference numerals and letters represent similar items in the following drawings, therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. Meanwhile, in the description of the present application, the terms "first", "second", etc. are only used to distinguish the description, and cannot be understood as indicating or implying relative importance.
[0140] First, some terms involved in the embodiments of the present application are explained to facilitate understanding by those skilled in the art.
[0141] Terminal device: can be a mobile terminal, a fixed terminal or a portable terminal, such as a mobile phone, a station, a unit, a device, a multimedia computer, a multimedia tablet, an Internet node, a communicator, a desktop computer, a laptop computer, a notebook computer, a netbook computer, a tablet computer, a personal communication system device, a personal navigation device, a personal digital assistant, an audio / video player, a digital camera / camcorder, a positioning device, a television receiver, a radio broadcast receiver, an electronic book device, a game device, or any combination thereof, including accessories and peripherals of these devices or any combination thereof. It is also foreseeable that the terminal device can support any type of interface for users (such as wearable devices) and the like.
[0142] Server: can be a standalone physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, and basic cloud computing services such as big data and artificial intelligence platforms.
[0143] In order to improve data security when processing transaction data, the embodiments of the present application provide a transaction data processing system, method, electronic device and readable storage medium.
[0144] Referring to Figure 1 As shown in the figure, an architecture schematic diagram of a transaction data processing system provided by the embodiments of the present application. The transaction data processing system comprises a plurality of bank servers and a control device. The control device is an electronic device, which can be a server or a terminal device.
[0145] The control device is configured to send a transaction query request to each bank server, and splice the transaction trees returned by each bank server to generate a fund transfer tree, wherein the transaction query request comprises starting bank account information, or the leaf nodes in the transaction trees returned by each bank server.
[0146] The transaction tree and the fund transfer tree each comprise a plurality of bank account information encrypted bank account ciphertexts, and each is used to represent transactions between a plurality of bank accounts, wherein the bank account information at least comprises a bank account.
[0147] Each bank server is configured to, when receiving the transaction query request, determine target bank account information to be queried based on the transaction query request, query associated bank account information of the target bank account information based on the target bank account information, and encrypt the target bank account information and the associated bank account information respectively using an encryption key corresponding to the bank to which each bank account information belongs, to obtain a plurality of bank account ciphertexts, and generate a transaction tree based on the bank account ciphertexts, and send the transaction tree to the control device.
[0148] In the embodiments of the present application, the associated bank account information obtained by querying is encrypted by the symmetric key of each bank server itself, and the fund transfer tree for fraud account analysis is generated based on the bank account ciphertexts, without the need for data sharing, and each bank server can only encrypt and decrypt the bank account information of its own bank, reducing the possibility of data leakage and improving data security.
[0149] In one implementation, when the control device sends a transaction query request to each bank server, any of the following methods can be used:
[0150] Method 1: When receiving a user query instruction, obtaining starting bank account information in the user query instruction, and sending a transaction query request comprising the starting bank account information to the bank to which the starting bank account information belongs.
[0151] As an example, the starting bank account information is the bank account information of the victim. In this way, a transaction query can be performed through the bank account information of the victim to determine the fund transfer process in subsequent steps.
[0152] Method 2: When receiving the transaction tree returned by any bank server, obtain the leaf nodes in the transaction tree, and send a transaction query request containing the leaf nodes to each bank server.
[0153] Each node in the transaction tree is a bank account ciphertext, and the leaf node is a bank account ciphertext without a child node.
[0154] If there is a cross-bank transfer in the fund transfer process, a transaction tree of one bank can be obtained, and based on the leaf nodes of the transaction tree, queries can be performed in other banks.
[0155] In an embodiment, when each bank server determines the target bank account information to be queried, any of the following methods can be used:
[0156] Method 1: When receiving a transaction query request containing starting bank account information, the starting bank account information contained in the transaction query request is determined as the target bank account information.
[0157] Method 2: When receiving a transaction query request containing a leaf node, the leaf node contained in the transaction query request is obtained, the leaf node is decrypted using a local private key, and the decrypted leaf node is determined as the target bank account information.
[0158] In an embodiment, when each bank server performs retrieval, the following steps can be used:
[0159] Based on the target bank account in the target bank account information and the transaction information, retrieval is performed to obtain associated bank accounts and their corresponding transaction timestamps, the associated bank account being a bank account that directly or indirectly receives funds from the target bank account information; based on the transaction timestamps corresponding to the associated bank accounts, transaction information of the associated bank accounts is generated; and based on the obtained associated bank accounts and their corresponding transaction information, retrieval is performed until a retrieval stop condition is reached.
[0160] In one embodiment, each bank server is configured to perform the following steps in a loop until a search stop condition is reached: search based on the obtained associated bank account and its corresponding transaction information; if it is determined that the search result is empty, then it is determined that the search stop condition is reached, otherwise, obtain a next associated bank account and its corresponding transaction timestamp that matches the transaction information, the next associated bank account being a bank account that directly or indirectly received the fund from the target bank account; obtain next associated bank account information based on the transaction timestamp of the next associated bank account, the next associated bank account information comprising the next associated bank account and its corresponding transaction information; and if it is determined that the bank to which the associated bank account belongs is different from the bank to which the next associated bank account belongs, then it is determined that the search stop condition is reached.
[0161] In this way, the associated bank account can be searched until the transaction is stopped or cross-bank transaction is performed.
[0162] In one embodiment, each bank server is configured to perform the following steps when encrypting the bank account information:
[0163] From the associated bank accounts, filter out the associated bank accounts that belong to the same bank as the target bank account; encrypt the target bank account and the filtered associated bank accounts using the symmetric key corresponding to the bank to which the target bank account belongs to obtain the corresponding bank account ciphertext; and encrypt the unfiltered associated bank accounts using the public key corresponding to the bank to which the unfiltered associated bank accounts belong to obtain the corresponding bank account ciphertext.
[0164] In this way, the symmetric public key of the bank itself can be used to encrypt the bank account information of the bank itself, and the public key of the bank to which the cross-bank (i.e., other banks) bank account information belongs can be used to encrypt the cross-bank bank account information.
[0165] In one embodiment, each bank server is configured to perform the following steps when encrypting the non-starting bank account information:
[0166] Encrypt the target bank account using the symmetric key corresponding to the bank to which the target bank account belongs to obtain initial bank account ciphertext; if it is determined that the target bank account information is obtained based on a leaf node in the transaction query request, then obtain the bank account ciphertext of the target bank account based on the initial bank account ciphertext and the leaf node corresponding to the target bank account information; otherwise, determine the initial bank account ciphertext as the bank account ciphertext of the target bank account.
[0167] In this way, the symmetric encryption result (i.e., the bank account ciphertext obtained by using the symmetric key encryption) and the asymmetric encryption result (i.e., the bank account ciphertext obtained by using the public key encryption) of the bank account number across the lines can be combined into the final bank account ciphertext.
[0168] In an embodiment, when the control device splices the transaction trees, the following steps can be used:
[0169] For the two target transaction trees, if it is determined that there is a matching bank account ciphertext in the two target transaction trees, the two target transaction trees are spliced based on the matching bank account ciphertext; wherein the target transaction tree is any one of the transaction trees and the spliced transaction trees.
[0170] In this way, the transaction trees of different bank servers can be spliced to obtain the fund transfer tree of the fund transfer design of multiple banks.
[0171] In an embodiment, when the control device splices the two target transaction trees, the following steps can be used:
[0172] If it is determined that the root node in one of the target transaction trees contains a target leaf node in the other target transaction tree, it is determined that the target leaf node and the root node match; the target leaf node is any leaf node in one of the target transaction trees; the target leaf node and the root node are spliced to obtain a spliced node, which is obtained by performing an XOR operation on the target leaf node and the root node.
[0173] In this way, based on the bank account ciphertext determined based on the public key, the matching leaf node can be determined, and in the splicing process, the bank account ciphertext determined based on the public key is removed, and only the bank account ciphertext obtained by using the symmetric key encryption is retained, so that each node in the obtained fund transfer tree is the bank account ciphertext obtained by using the symmetric key encryption.
[0174] In an embodiment, after the control device obtains the fund transfer tree, the following steps can be used to determine the abnormal bank account based on the fund transfer tree:
[0175] Each bank account ciphertext in the fund transfer tree is analyzed to determine an abnormal bank account ciphertext; the abnormal bank account ciphertext is sent to each bank server, so that each bank server decrypts the abnormal bank account ciphertext using a local symmetric key; and receiving the abnormal bank account returned by each bank server based on the abnormal bank account ciphertext.
[0176] In this way, after obtaining the fund transfer tree, the abnormal bank account ciphertext can be analyzed through the fund transfer process in the fund transfer tree, and then the abnormal bank account (such as the bank account of a fraud gang) can be obtained through the abnormal bank account ciphertext of each bank.
[0177] In the embodiment of the application, the fund transfer tree is obtained through the interaction between the control device of the anti-fraud agency and the server of the bank, which can promote the safe cooperation between the anti-fraud agency and the bank under the premise of ensuring the safety of the bank and the legal account information, and can improve the case handling efficiency of the anti-fraud agency. The process of operation does not need the support of a trusted third party, and only the bank participating in the case and the anti-fraud agency need to search and operate data, so there is no problem of a trusted third party. Furthermore, in the above embodiment, each bank uses its own public key and symmetric key to encrypt the bank account information of its own bank to form a ciphertext transaction tree. When the private key or symmetric key of any bank is leaked, it will not affect the data security of other banks. It can solve the problem of the influence of dishonest participants on the data security of other banks. Further, in the above embodiment, the fund transfer tree based on symmetric key encryption can be obtained. Since the symmetric encryption algorithm is a deterministic cryptographic algorithm, that is, the ciphertext after the same data is encrypted each time is the same, after obtaining multiple transaction trees, the transaction trees can be spliced based on the matched nodes to obtain the fund transfer tree, thereby realizing the reverse rotation of the transaction and solving the problem of the transaction unable to rotate under the traditional technology. The anti-fraud agency wants to decrypt the suspicious bank account ciphertext, and only needs to send the suspicious bank account ciphertext to the bank for decryption, thereby solving the problem of needing to spend a large amount of storage space to maintain the hash table under the traditional technology.
[0178] The application discloses a new anti-fraud evidence collection method. First, the bank uses the symmetric key of the bank to encrypt the account of the bank in the transaction branch, and uses the public key password to encrypt the cross-bank account to obtain a ciphertext transaction tree. Second, the bank sends the ciphertext transaction tree to the anti-fraud agency. This design can avoid using a trusted third party, because the anti-fraud agency obtains ciphertext data, and cannot obtain any information about plaintext from the ciphertext data, thereby ensuring the data security of the bank. Finally, after layer-by-layer query iteration, the anti-fraud agency generates a complete ciphertext fund transfer graph (i.e., a fund transfer tree).
[0179] Referring to Figure 2 FIG. 1 is a flowchart of a method for processing transaction data according to an embodiment of the application. FIG. 2 is a schematic diagram of a transaction data processing system according to an embodiment of the application. Figure 2 The method for processing transaction data of the transaction data processing system in Figure 1 The method for processing transaction data of the transaction data processing system in
[0180] Step 200: The control device sends a transaction query request to each bank server.
[0181] Specifically, the transaction query request contains the starting bank account information, or the leaf nodes in the transaction tree returned by each bank server.
[0182] The starting bank account information contains the starting bank account and its corresponding transaction information. The transaction information is used to filter the transaction records of the starting bank account fund transfer. In an embodiment, the starting bank account is the bank account of the victim. The transaction information is used to filter the transaction records of the victim transferring money to the fraud gang through the starting bank account. As an example, the transaction information is the transaction timestamp of the victim transferring money to the fraud gang through the starting bank account.
[0183] In practical applications, the transaction information can be set according to the actual application scenario, such as the transaction time period, the bank to which the bank account of the fund transfer belongs, etc.
[0184] In an embodiment, the bank to which the starting bank account belongs first searches based on the starting bank account information to obtain the associated bank account information of the starting bank account, and generates a transaction tree based on the starting bank account information and the associated bank account information, and returns the transaction tree to the control device. When the control device determines that the transaction tree is received, the leaf nodes in the transaction tree are obtained, and the transaction query request containing the leaf nodes is sent to each bank server until it is determined that the search stop condition is reached.
[0185] The associated bank account information can be one or multiple, including the associated bank account and its corresponding transaction timestamp. The associated bank account is the bank account that directly or indirectly obtains the fund transfer from the starting bank account.
[0186] In an embodiment, when step 200 is performed, the control device can use any of the following ways:
[0187] Method 1: When it is determined that the user query instruction is received, the starting bank account information in the user query instruction is obtained, and the transaction query request containing the starting bank account information is sent to the bank to which the starting bank account information belongs.
[0188] Method 2: When it is determined that the transaction tree returned by any bank server is received, the leaf nodes in the transaction tree are obtained, and the transaction query request containing the leaf nodes is sent to each bank server.
[0189] Each node in the transaction tree is a bank account ciphertext. The bank account ciphertext is obtained by encrypting the target bank account information or the associated bank account information. The leaf node is a bank account ciphertext without child nodes.
[0190] Step 201: Each bank server determines the target bank account information to be queried based on the transaction query request upon receiving the transaction query request.
[0191] When performing step 201, each bank server can adopt any of the following manners:
[0192] Manner 1: When determining that the transaction query request containing the initial bank account information is received, the initial bank account information contained in the transaction query request is determined as the target bank account information.
[0193] Manner 2: When determining that the transaction query request containing the leaf node is received, the leaf node contained in the transaction query request is obtained, and the leaf node is decrypted, and the decrypted leaf node is determined as the target bank account information.
[0194] It should be noted that each bank server is provided with a symmetric key K and a key pair. The symmetric key is generated based on a symmetric encryption algorithm. Data encrypted by the symmetric key is decrypted by the symmetric key. The same symmetric key is used to encrypt the same data multiple times, and the encrypted data obtained is the same. As an example, the symmetric keys of the banks are: bank 1: K1, bank 2: K2, bank 3: K3, and the symmetric key belongs to each bank.
[0195] The key pair is generated using an asymmetric encryption algorithm, including a public key PK and a private key SK. As an example, data encrypted by the public key is decrypted by the private key. The same public key is used to encrypt the same data multiple times, and the encrypted data obtained is different. The symmetric keys of different bank servers are different, and the key pairs are also different. The public keys of each bank server are public. As an example, the key pairs of multiple banks include: bank 1: (PK1, SK1), bank 2: (PK2, SK2), and bank 3: (PK3, SK3), wherein the public key set {PK1, PK2, PK3} is public.
[0196] In an implementation, for a target bank server in each bank server, if it is determined that the bank account information belongs to the target bank server, the target bank server uses the symmetric key to encrypt and decrypt the bank account information, otherwise, the public key and the private key of the bank to which the bank account information belongs are used to encrypt and decrypt the bank account information. The target bank server is any one of the bank servers.
[0197] Step 202: Each bank server queries the associated bank account information of the target bank account information based on the target bank account information.
[0198] Specifically, when performing step 202, each bank server can adopt the following steps:
[0199] S2021: Based on the target bank account information and the transaction information, search to obtain the associated bank account and its corresponding transaction timestamp.
[0200] As an example, the transaction information is a transaction timestamp, and the account information (including the target bank account information and the associated bank account information) includes the transaction timestamp of the bank account (such as the target bank account and the associated bank account). The transaction timestamp is the time of the bank account transfer. The associated bank account is the bank account that directly or indirectly obtains the incoming funds from the target bank account information. As an example, the user transfers from the target bank account to the associated bank account at the transaction timestamp.
[0201] In practical applications, the transaction information can be set according to the actual application scenario, such as other information such as the transaction object, which is not limited here.
[0202] S2022: Based on the transaction timestamp corresponding to the associated bank account, generate the transaction information of the associated bank account.
[0203] S2023: Based on the obtained associated bank account and its corresponding transaction information, search until the search stop condition is reached.
[0204] In an embodiment, when S2023 is performed, the following steps are performed in a loop until the search stop condition is reached:
[0205] Based on the obtained associated bank account and its corresponding transaction information, search; if it is determined that the search result is empty, it is determined that the search stop condition is reached; otherwise, obtain the next associated bank account information, which includes the next associated bank account and its corresponding transaction information. As an example, the transaction information corresponding to the next associated bank account is a transaction timestamp.
[0206] As an example, when the transaction stops, the next associated bank account cannot be searched, and the search result is empty. As another example, if the associated bank account is a cross-bank account (i.e., a cross-bank transaction), the next associated bank account cannot be searched, and the search result is also empty.
[0207] Step 203: Each bank server uses the encryption key corresponding to the bank to which the bank account information belongs to respectively encrypt the target bank account information and the associated bank account information, and obtains multiple bank account ciphertexts.
[0208] Specifically, when step 203 is performed, each bank server can use the following steps:
[0209] S2031: From the associated bank account, filter out the associated bank account whose bank is the same as the bank of the target bank account.
[0210] S2032: Use the symmetric key corresponding to the bank of the target bank account to encrypt the target bank account and the filtered associated bank account, respectively, to obtain the corresponding bank account ciphertext.
[0211] S2033: Use the public key corresponding to the bank of the unfiltered associated bank account to encrypt the unfiltered associated bank account to obtain the corresponding bank account ciphertext.
[0212] Step 204: Each bank server generates a transaction tree based on each bank account ciphertext.
[0213] In one embodiment, the bank accounts (e.g., target bank account and associated bank account) in the bank account information are encrypted to obtain bank account ciphertext, and a transaction tree is generated based on each bank account ciphertext and its corresponding transaction information.
[0214] In one embodiment, the bank accounts (e.g., target bank account and associated bank account) in the bank account information are encrypted to obtain bank account ciphertext, and a transaction tree is generated based on each bank account ciphertext.
[0215] Further, a plaintext transaction tree can also be generated based on each bank account information (target bank account information and / or associated bank account information), and then each bank account information in the transaction tree is encrypted using the above encryption method to obtain an updated transaction tree.
[0216] That is, the execution order of the generation step of the transaction tree and the encryption step of the bank account information is not limited.
[0217] As an example, the anti-fraud agency determines that the Victim (i.e., the initial bank account of the victim) is a bank account of Bank 1 according to the characteristics of the account number of the Victim, and sends the Victim and the timestamp t when the victim was deceived to Bank 1. Bank 1 searches for [t, Victim] through bank server 1, and stops searching when no next transaction or cross-border transaction is found, and finally searches out the plaintext transaction tree. If the last layer (i.e., each leaf node) of the transaction tree involves cross-border transfer, since Bank 1 cannot query the transactions generated after cross-border transfer, only the bank corresponding to the cross-border account (i.e., the bank account of Bank 1) can query the subsequent transaction information (i.e., associated account information), therefore, after the cross-border account is determined, the next round of query is performed through the bank to which the cross-border account belongs.
[0218] Step 205: Each bank server sends the transaction tree to the control device.
[0219] It should be noted that, for the convenience of description, in the embodiments of the present application, X represents a bank account number, X1 represents an encrypted bank account number information obtained based on symmetric key encryption, and X2 represents an encrypted bank account number information obtained based on public key encryption.
[0220] Step 206: The control device receives the transaction trees returned by the bank servers based on the transaction query request.
[0221] Specifically, if it is determined that the transaction tree is received, step 200 is performed, otherwise, step 207 is performed.
[0222] Step 207: The control device splices the transaction trees returned by the bank servers to generate a fund transfer tree.
[0223] In actual application, the timing of transaction tree splicing can be set according to the actual application scenario, which is not limited here.
[0224] In an embodiment, when step 207 is performed, any of the following methods can be used:
[0225] Method 1: When any transaction tree is received, the transaction tree splicing is performed until it is determined that the search is completed, and the latest spliced transaction tree is determined as the fund transfer tree.
[0226] Method 2: When the search is completed, the received transaction trees are spliced to generate the fund transfer tree.
[0227] In an embodiment, for two target transaction trees, if it is determined that there is a matching bank account number ciphertext in the two target transaction trees, the two target transaction trees are spliced based on the matching bank account number ciphertext. The target transaction tree is any one of the transaction trees and the spliced transaction tree.
[0228] In an embodiment, when the two target transaction trees are spliced, the following steps can be used:
[0229] If it is determined that the root node in one of the target transaction trees contains a target leaf node in the other target transaction tree, it is determined that the target leaf node and the root node match; the target leaf node and the root node are spliced to obtain a spliced node.
[0230] Wherein, the target leaf node is any leaf node in one of the target transaction trees, and the root node is any leaf node in the other target transaction tree. Further, after the control device generates the fund transfer tree, the fund transfer tree can also be analyzed to obtain an abnormal bank account number. The spliced node is obtained by performing XOR operation on the target leaf node and the root node.
[0231] In one implementation, the following steps can be used when obtaining an unusual bank account:
[0232] The abnormal bank account information is sent to the servers of each bank, and each bank server decrypts the abnormal bank account information using its local symmetric key; the abnormal bank account information is then received from each bank server based on the abnormal bank account information.
[0233] In practical applications, the specific analysis methods for encrypted data of abnormal bank accounts can be set according to the actual application scenario, and no restrictions are imposed here.
[0234] The following is combined Figures 3-6 ,right Figure 1 The methods for processing transaction data in the process are illustrated with examples.
[0235] See Figure 3 The image shown is a schematic diagram of a transaction tree generation method. Figure 1 . Figure 3 This example illustrates the first round of transaction data querying. The banks are designated Bank 1, Bank 2, and Bank 3, with corresponding symmetric keys K1, K2, and K3, and public keys PK1, PK2, and PK3, respectively. The victim's initial bank account and the timestamp of the fraud are [Victim, t]. The anti-fraud agency sends [Victim, t] to Bank 1. Bank 1 uses Bank Server 1 to retrieve [t, Victim], obtaining multiple associated bank accounts (i.e., associated bank accounts A, D, B, and C) and their corresponding transaction timestamps. A plaintext transaction tree is then generated based on Victim, A, D, B, and C. Associated bank accounts A and D belong to Bank 1, while associated bank accounts B and C belong to Bank 2 and Bank 3, respectively.
[0236] Bank 1, through Bank Server 1, uses a symmetric key K1 to encrypt its own bank accounts (i.e., the initial bank account Victim, and associated bank accounts A and D), obtaining the encrypted bank account information, namely Victim1, A1, and D1. Bank Server 1 uses an asymmetric encryption algorithm, employing the public key PK2 of Bank 2 (the associated bank account B), to encrypt the cross-bank account, obtaining B2. Similarly, Bank Server 1 uses an asymmetric encryption algorithm, employing the public key PK3 of Bank 3 (the associated bank account C), to encrypt the cross-bank account, obtaining C2. Based on Victim1, A1, D1, B2, and C2, a ciphertext transaction tree is obtained and sent to the anti-fraud agency. It should be noted that the anti-fraud agency processes the transaction data through control equipment.
[0237] In this way, the control device can only obtain the encrypted transaction tree and cannot distinguish the specific transaction information, thus protecting user privacy and improving data security.
[0238] See Figure 4 The image shown is a schematic diagram of a transaction tree generation method. Figure 2 Combining Figure 3 This section provides an example of the second round of transaction inquiries. Anti-fraud agencies obtain information by controlling devices. Figure 5 The system generates a transaction tree and retrieves the outermost leaf nodes (A1, B2, and C2) from the received transaction tree. It then sends each leaf node and its corresponding transaction timestamp to the respective bank servers. Each bank server decrypts each leaf node using its own symmetric key and public key to obtain its own successfully decrypted bank account number (each bank can only decrypt its own account number). Specifically, Bank 1 decrypts A1 using K1 through Bank Server 1 to obtain A. Bank 2 decrypts B2 using its private key SK2 through Bank Server 2 to obtain B. Bank 3 decrypts C2 using its private key SK3 through Bank Server 3 to obtain C.
[0239] In this way, the control device does not need to distinguish which bank each leaf node belongs to. Instead, it sends all leaf nodes to each bank's server, simplifying the cumbersome operation of the control device. Each bank can only successfully decrypt its own bank account number, but cannot decrypt the bank accounts of other banks, thus ensuring data security between banks.
[0240] Next, bank 1 performs a search based on A and its corresponding transaction timestamp, and the search result is empty, so the search is stopped due to transaction stop. Bank 2 performs a search based on B and its corresponding transaction timestamp, and obtains multiple associated bank accounts, i.e., G (the bank to which G belongs is bank 2), I (the bank to which I belongs is bank 2), J (the bank to which J belongs is bank 1), and K (the bank to which K belongs is bank 3). Bank 3 performs a search based on C and its corresponding transaction timestamp, and obtains multiple associated bank accounts, i.e., L (the bank to which L belongs is bank 3), M (the bank to which M belongs is bank 3), N (the bank to which N belongs is bank 3), and O (the bank to which O belongs is bank 2). Each bank generates a transaction tree in plaintext based on the decrypted bank account and the searched associated bank account by using the bank server of the bank itself, and respectively encrypts the bank account to which the bank itself belongs by using the symmetric key, and encrypts the cross-bank account (i.e., the associated bank account belonging to other banks) by using the public key of the bank to which the cross-bank account belongs, to obtain the bank account ciphertext of each bank, and for the bank account X (e.g., B and C) decrypted successfully by the bank itself, splices X1 and X2 of X to obtain the new bank account ciphertext (X1||X2) of X, and further obtains the transaction tree of the ciphertext of each bank. The bank account ciphertext of bank 2 is B1||B2, G1, I1, J2, and K2 in sequence. The bank account ciphertext of bank 3 is C1||C2, L1, M1, N1, and O2 in sequence.
[0241] It should be noted that the form of X1||X2 is used to simultaneously retain X1 and X2 of the bank account in the bank account ciphertext, and the purpose is to splice between different transaction trees subsequently. As an example, the leaf node of one transaction tree is B2 and C2, and the root node of another transaction tree is B1||B2, it is determined that B2 and B1||B2 are matched (i.e., the decrypted bank account is the same bank account), then the two transaction trees can be spliced based on the matched node, and further, B2 can be removed (i.e., the repeated part in the two bank account ciphertexts) in the splicing process, so that the final obtained fund transfer tree has the following characteristics: each bank account ciphertext is obtained by using the symmetric key of the bank to which the bank account belongs, and the encryption result of the same bank account at any time is the same, so that the fund transfer tree can achieve transaction reversal.
[0242] Referring to Figure 3 , a schematic diagram of transaction tree generation is shown. Figure 5 . Figure 5 for the third round of transaction data query is described. Figure 4 , the control device obtains Figure 4 the transaction tree generated in the transaction tree generation, and sends the outermost leaf node in the transaction tree and the corresponding transaction timestamp to the bank server of each bank. Each bank server performs a search based on the outermost leaf node and the corresponding transaction timestamp. Figure 6The similar principle is used for searching and encryption to obtain the ciphertext transaction tree of each bank account. Bank 1 obtains P based on J and the corresponding transaction timestamp via bank server 1, and encrypts each bank account to obtain the bank account ciphertexts J1||J2 and P1. Bank 2 obtains the associated bank accounts G, I, Q, and R based on O and the corresponding transaction timestamp via bank server 2, and encrypts each bank account to obtain the bank account ciphertexts O1||O2, G1, I1, Q1, and R1. Bank 3 obtains the associated bank accounts L, M, and N based on K and the corresponding transaction timestamp via bank server 3, and encrypts each bank account to obtain the bank account ciphertexts K1||K2, L1, M1, and N1. Bank 3 searches based on N and the corresponding transaction timestamp via bank server 3, and the search result is empty.
[0243] Referring to Figure 6 , a schematic diagram of search stop is shown. Figure 5 The search stop is determined when the search result is empty. The control device receives the transaction trees returned by the bank servers in Figure 7 , and sends the leaf nodes in each transaction tree to the bank servers. When the search results of the bank servers are all empty, the search stop is determined. Bank server 1 searches based on P and the corresponding transaction timestamp, and the search result is empty. Bank server 2 searches based on Q and R and the corresponding transaction timestamps, respectively, and the search results are empty. Bank server 3 searches based on N and M and the corresponding transaction timestamps, respectively, and the search results are empty. Finally, the bank servers return the search results to the control device.
[0244] Referring to Figure 6 , a schematic diagram of a fund transfer tree is shown. After the control device determines the search stop based on the search results returned in Figures 3-5 , the control device splices the ciphertext transaction trees generated in Figure 7 to obtain the fund transfer tree shown in Figure 7 . The control device determines that I1 has the phenomenon of fund rotation, i.e., I1-K1 and O1-I1, through the fund transfer tree in Figure 8 , and can obtain O1-I1-K1. Therefore, I1 is determined to be an abnormal bank account ciphertext, and the abnormal bank account ciphertext is sent to the bank servers for decryption to obtain the returned abnormal bank account I.
[0245] In this embodiment, to ensure the control device can connect each transaction tree, a public-key encryption method is cleverly applied, allowing the leaf nodes of the transaction tree to match and connect with the root nodes of the next-level transaction tree. Furthermore, to enable transaction reversal in the transaction fund tree, a symmetric key is cleverly used, ensuring that the encryption results for the same bank account are identical, thus allowing for the reversal of fund flows based on the bank account ciphertext. Moreover, to prevent information leakage due to multiple banks' betrayal, each bank account in the plaintext transaction tree is encrypted using the symmetric key and public key of its respective bank. Even if multiple banks betray, it will not affect the information security of other banks. For example, if Bank 1 and Bank 2 betray, i.e., leak their private keys and symmetric keys to the attacker, the attacker can only decrypt the ciphertext of the bank accounts of Bank 1 and Bank 2, and cannot decrypt the ciphertext of other banks' bank accounts. Therefore, the interests of other banks cannot be affected, thus eliminating the incentive for banks to betray. During fund transfers, bank accounts may be either suspicious or legitimate, not necessarily criminal. Banks typically don't want to disclose all information of legitimate users to anti-fraud agencies' control devices. To ensure the security of legitimate users' bank account information, the fund transfer tree ultimately obtained by the control device is encrypted and can only be decrypted selectively. Specifically, after analyzing and identifying the encrypted data of suspicious accounts (i.e., abnormal bank account data), the data is then decrypted through the bank's server to obtain the suspicious account information (i.e., abnormal bank account information), thus protecting innocent accounts. To ensure bank data security, plaintext data from each bank does not leave their local machine; the data is encrypted before being sent to the control device. To avoid third-party distrust issues, tasks can be completed through data interaction between the bank and the control device, without the need for third-party involvement. To ensure the control device can complete queries even when it cannot distinguish between cross-bank accounts, the control device does not need to differentiate which bank the account belongs to; it can directly send each leaf node to the respective bank for decryption. Each bank can only successfully decrypt its own account information. This eliminates the need to store large amounts of hash databases and other data, reducing the storage burden on banks.
[0246] Based on the same inventive concept, this application also provides a transaction data processing apparatus. Since the principle of the above apparatus and equipment in solving the problem is similar to that of a transaction data processing method, the implementation of the above apparatus can refer to the implementation of the method, and the repeated parts will not be described again.
[0247] like Figure 1 The diagram shown is a structural schematic of a transaction data processing apparatus provided in an embodiment of this application. Figure 9 ,include:
[0248] The control device is applied to a transaction data processing system, and the transaction data processing system further comprises a plurality of bank servers, including:
[0249] The sending unit 801 is configured to send a transaction query request to each bank server, and the transaction query request comprises starting bank account information or leaf nodes in a transaction tree returned by each bank server;
[0250] The returning unit 802 is configured to receive a transaction tree returned by each bank server based on the transaction query request, and the transaction tree comprises a plurality of bank account ciphertexts obtained by encrypting a plurality of bank accounts using an encryption key corresponding to a bank to which the bank account belongs, and used to represent transactions between the plurality of bank accounts.
[0251] The splicing unit 803 is configured to splice the transaction trees returned by each bank server to generate a fund transfer tree, and the fund transfer tree comprises a plurality of bank account ciphertexts obtained by encrypting a plurality of bank account information, and used to represent transactions between the plurality of bank accounts.
[0252] In an embodiment, the sending unit 801 is configured to:
[0253] When it is determined that the user query instruction is received, obtain starting bank account information in the user query instruction, and send a transaction query request comprising the starting bank account information to a bank to which the starting bank account information belongs;
[0254] Alternatively, when it is determined that the transaction tree returned by any bank server is received, obtain leaf nodes in the transaction tree, and send a transaction query request comprising the leaf nodes to each bank server, each node in the transaction tree is a bank account ciphertext, and the leaf node is a bank account ciphertext without a child node.
[0255] In an embodiment, the splicing unit 803 is configured to:
[0256] If it is determined that a root node in a target transaction tree of the transaction trees comprises a target leaf node in another target transaction tree, it is determined that the target leaf node and the root node match, the target transaction tree is any one of the transaction trees and the spliced transaction tree, and the target leaf node is any leaf node in the target transaction tree;
[0257] Splice the target leaf node and the root node.
[0258] In an embodiment, the splicing unit 803 is further configured to:
[0259] Analyze each bank account ciphertext in the fund transfer tree to determine an abnormal bank account ciphertext;
[0260] The abnormal bank account ciphertext is sent to each bank server, so that each bank server respectively decrypts the abnormal bank account ciphertext by using a local symmetric key;
[0261] The abnormal bank account returned by each bank server based on the abnormal bank account ciphertext is received.
[0262] As shown in Figure 2 , which is a structure schematic diagram of a transaction data processing apparatus provided by an embodiment of the present application, Figure 10 , comprising:
[0263] The determination unit 901 is configured to determine, when receiving a transaction query request, target bank account information to be queried based on the transaction query request; the transaction query request contains starting bank account information or leaf nodes in a transaction tree returned by each bank server;
[0264] The query unit 902 is configured to query associated bank account information of the target bank account information based on the target bank account information;
[0265] The encryption unit 903 is configured to respectively encrypt the target bank account information and the associated bank account information by using an encryption key set by a bank to which each bank account information belongs, to obtain a plurality of bank account ciphertexts;
[0266] The generation unit 904 is configured to generate a transaction tree based on the plurality of bank account ciphertexts;
[0267] The sending unit 905 is configured to send the transaction tree to a control device, so that the control device splices the transaction trees returned by each bank server to generate a fund transfer tree; the transaction tree and the fund transfer tree both contain bank account ciphertexts of a plurality of bank account information encrypted, and are both used to represent transactions between the plurality of bank accounts.
[0268] In an embodiment, the determination unit 901 is configured to:
[0269] When receiving the transaction query request containing the starting bank account information, determine the initial bank account information contained in the transaction query request as the target bank account information;
[0270] Alternatively, when receiving the transaction query request containing the leaf nodes, acquire the leaf nodes contained in the transaction query request, decrypt the leaf nodes, and determine the decrypted leaf nodes as the target bank account information.
[0271] In an embodiment, the query unit 902 is configured to:
[0272] Based on the target bank account in the target bank account information and the transaction information, a search is performed to obtain an associated bank account and a corresponding transaction timestamp of the associated bank account, and the associated bank account is a bank account that directly or indirectly obtains the transfer-in fund from the target bank account information.
[0273] Based on the transaction timestamp corresponding to the associated bank account, transaction information of the associated bank account is generated.
[0274] Based on the obtained associated bank account and the corresponding transaction information, a search is performed until a search stop condition is reached.
[0275] In an embodiment, the query unit 902 is configured to:
[0276] The following steps are repeatedly performed until a search stop condition is reached:
[0277] Based on the obtained associated bank account and the corresponding transaction information, a search is performed.
[0278] If it is determined that the search result is empty, it is determined that the search stop condition is reached.
[0279] Otherwise, the next associated bank account information is obtained, and the next associated bank account information includes the next associated bank account and the corresponding transaction information of the next associated bank account.
[0280] In an embodiment, the encryption unit 903 is configured to:
[0281] From the associated bank account, the associated bank account whose bank belongs to the same bank as the bank to which the target bank account belongs is filtered out.
[0282] The target bank account and the filtered associated bank account are respectively encrypted using a symmetric key corresponding to the bank to which the target bank account belongs, to obtain corresponding bank account ciphertexts.
[0283] The unfiltered associated bank account is encrypted using a public key corresponding to the bank to which the unfiltered associated bank account belongs, to obtain a corresponding bank account ciphertext.
[0284] In an embodiment, the encryption unit 903 is configured to:
[0285] If it is determined that the target bank account information is obtained based on the leaf node in the transaction query request, the target bank account is encrypted using a symmetric key corresponding to the bank to which the target bank account belongs, to obtain an initial bank account ciphertext.
[0286] Based on the initial bank account ciphertext and the leaf node corresponding to the target bank account information, the bank account ciphertext of the target bank account is obtained.
[0287] The transaction data processing system, method, electronic device and readable storage medium provided in the embodiments of the present application, the transaction data processing system comprises a plurality of bank servers and a control device, the control device is configured to send a transaction query request to each bank server, and splice the transaction trees returned by each bank server to generate a fund transfer tree, the transaction query request comprises starting bank account information or a leaf node in the transaction tree returned by each bank server, the bank account ciphertext after encryption of the plurality of bank account information is contained in the transaction tree and the fund transfer tree, and is used to represent the transaction between the plurality of bank accounts; each bank server is configured to, when receiving the transaction query request, determine the target bank account information to be queried based on the transaction query request, query the associated bank account information of the target bank account information based on the target bank account information, encrypt the target bank account information and the associated bank account information respectively by using the encryption key set by the bank to which each bank account information belongs, obtain the plurality of bank account ciphertexts, generate the transaction tree based on the plurality of bank account ciphertexts, and send the transaction tree to the control device. In this way, the data security can be improved when the transaction data is processed.
[0288] Figure 10 A structural schematic diagram of an electronic device 1000 is shown. Referring to Figure 10 As shown, the electronic device 1000 comprises a processor 1010 and a memory 1020, and optionally, a power supply 1030, a display unit 1040, and an input unit 1050.
[0289] The processor 1010 is the control center of the electronic device 1000, connects various components by using various interfaces and lines, executes various functions of the electronic device 1000 by running or executing the software programs and / or data stored in the memory 1020, and thus monitors the electronic device 1000 as a whole.
[0290] In the embodiments of the present application, the processor 1010 executes each step in the above embodiments when calling the computer program stored in the memory 1020.
[0291] Optionally, the processor 1010 can include one or more processing units; preferably, the processor 1010 can integrate an application processor and a modem processor, wherein the application processor mainly processes the operating system, user interface, and applications, etc., and the modem processor mainly processes wireless communication. It can be understood that the above-mentioned modem processor can also not be integrated into the processor 1010. In some embodiments, the processor, the memory, and the like can be implemented on a single chip, and in some embodiments, they can also be implemented on separate chips, respectively.
[0292] The memory 1020 can mainly include a program storage area and a data storage area, wherein the program storage area can store the operating system, various applications, etc., and the data storage area can store the data created according to the use of the electronic device 1000, etc. In addition, the memory 1020 can include a high-speed random access memory, and can also include a non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other volatile solid-state memory device, etc.
[0293] The electronic device 1000 further includes a power supply 1030 (such as a battery) for supplying power to each component, which can be logically connected to the processor 1010 through a power management system, so as to realize the functions of managing charging, discharging, and power consumption, etc. through the power management system.
[0294] The display unit 1040 can be used to display the information input by the user or provided to the user, and various menus of the electronic device 1000, etc., and in the embodiments of the present application, it is mainly used to display the display interface of each application in the electronic device 1000 and the objects such as text, pictures, etc. displayed in the display interface. The display unit 1040 can include a display panel 1041. The display panel 1041 can be configured in the form of a liquid crystal display (LCD), an organic light-emitting diode (OLED), etc.
[0295] The input unit 1050 can be used to receive the information such as numbers or characters input by the user. The input unit 1050 can include a touch panel 1051 and other input devices 1052. The touch panel 1051, also known as a touch screen, can collect the touch operation of the user on or near it (such as the operation of the user using a finger, a touch pen, etc. on or near the touch panel 1051).
[0296] Specifically, the touch panel 1051 can detect a user's touch operation, and detect signals caused by the touch operation, convert the signals into touch coordinates, send the touch coordinates to the processor 1010, and receive commands from the processor 1010 and execute the commands. In addition, the touch panel 1051 can be implemented in various types such as a resistive type, a capacitive type, an infrared type, and a surface acoustic wave type. The other input device 1052 can include one or more of a physical keyboard, a function key (such as a volume control key, a power on / off key, etc.), a trackball, a mouse, a joystick, etc.
[0297] Of course, the touch panel 1051 can cover the display panel 1041, and when the touch panel 1051 detects a touch operation thereon or nearby, the touch panel 1051 transmits the touch operation to the processor 1010 to determine a type of the touch event, and then the processor 1010 provides a corresponding visual output on the display panel 1041 according to the type of the touch event. Although in the above description, the touch panel 1051 and the display panel 1041 are implemented as two independent components to realize the input and output functions of the electronic device 1000, in some embodiments, the touch panel 1051 and the display panel 1041 can be integrated to realize the input and output functions of the electronic device 1000. Figure 10
[0298] The electronic device 1000 can further include one or more sensors, such as a pressure sensor, a gravity acceleration sensor, a proximity light sensor, etc. Of course, according to the needs in specific applications, the above electronic device 1000 can further include a camera and other components, since these components are not the components mainly used in the embodiments of the present application, they are not shown in the above description, and will not be described in detail. Figure 10
[0299] Those skilled in the art can understand that Figure 1 The above electronic device is only an example, and does not constitute a limitation on the electronic device, and can include more or fewer components than the diagram, or combine certain components, or different components.
[0300] In the embodiments of the present application, a computer readable storage medium has a computer program stored thereon, and the computer program is executed by a processor to enable a communication device to perform each step in the above embodiments.
[0301] For the convenience of description, each part is described as a module (or unit) according to function. Of course, in the implementation of the present application, the functions of each module (or unit) can be implemented in the same or multiple software or hardware.
[0302] Those skilled in the art will appreciate that embodiments of the present application can be readily used as software, hardware, or a combination of software and hardware. In one embodiment, the present application can be implemented as a computer program product, which can include a computer readable storage medium having stored, embodied, in it or transported by it computer program code. The computer readable storage medium can be a tangible computer readable storage medium storing the code. Medium can refer to a computer- readable medium. Examples of computer- readable mediums include an electronic, magnetic, optical, electromagnetic, infrared, and semiconductor system, apparatus, or device, or a propagation medium. Examples of a computer-readable medium include an electrical connection between a
[0303] The present application is described in reference to the drawings, which are as follows. Figure 1 Figure 1
[0304] Figure 1 Figure 1
[0305] Figure 1
[0306]
[0307] Obviously, many modifications and variations of the present application are possible in light of the above teachings. It is, therefore, to be understood that within the scope of the appended claims and their equivalents, the application can be practiced otherwise than as specifically described.
Claims
1. A transaction data processing system, characterized by, The transaction data processing system comprises a plurality of bank servers and a control device: The control device is configured to send a transaction query request to each bank server, and splice transaction trees returned by the bank servers to generate a fund transfer tree, the transaction query request comprising starting bank account information, or leaf nodes in the transaction trees returned by the bank servers, the transaction trees and the fund transfer tree each comprising a plurality of bank account ciphertexts obtained by encrypting bank account information, and each being used to represent transactions between a plurality of bank accounts; the transaction tree is obtained by splicing a splicing node obtained by performing an exclusive or operation on a target leaf node of a target transaction tree and a root node of another target transaction tree, or is obtained by splicing based on matching bank account ciphertexts in the two target transaction trees; Each bank server is configured to, upon receiving the transaction query request, determine target bank account information to be queried based on the transaction query request, query associated bank account information of the target bank account information based on the target bank account information, encrypt the target bank account information and the associated bank account information respectively using an encryption key set by a bank to which each bank account belongs, obtain a plurality of bank account ciphertexts, generate a transaction tree based on the bank account ciphertexts, and send the transaction tree to the control device; The control device is configured to:
2. The system of claim 1, wherein, determine the starting bank account information in the user query instruction upon receiving the user query instruction, send a transaction query request comprising the starting bank account information to a bank to which the starting bank account information belongs, or obtain leaf nodes in a transaction tree returned by any bank server upon receiving the transaction tree, send a transaction query request comprising the leaf nodes to each bank server, each node in the transaction tree being a bank account ciphertext, and each leaf node being a bank account ciphertext without a child node; Each bank server is configured to, upon receiving the transaction query request comprising the starting bank account information, determine the initial bank account information comprised in the transaction query request as the target bank account information; or, upon receiving the transaction query request comprising the leaf nodes, obtain the leaf nodes comprised in the transaction query request, decrypt the leaf nodes, and determine a decrypted leaf node as the target bank account information. Each bank server is configured to:
3. The system of claim 1, wherein, perform a search based on a target bank account in the target bank account information and transaction information, to obtain an associated bank account and a corresponding transaction timestamp of the associated bank account, the associated bank account being a bank account that directly or indirectly receives funds from the target bank account information; generate transaction information of the associated bank account based on the transaction timestamp corresponding to the associated bank account. Based on the obtained associated bank account and its corresponding transaction information, retrieval is performed until a retrieval stop condition is reached.
4. The system of claim 3, wherein, Each bank server is configured to cyclically perform the following steps until the retrieval stop condition is reached: Based on the obtained associated bank account and its corresponding transaction information, retrieval is performed; If it is determined that the retrieval result is empty, it is determined that the retrieval stop condition is reached; Otherwise, the next associated bank account information is obtained, which includes the next associated bank account and its corresponding transaction information.
5. The system of any one of claims 1-4, wherein, The associated bank account information includes an associated bank account, and the target bank account information includes a target bank account. Each bank server is configured to: From the associated bank accounts, filter out the associated bank accounts whose banks are the same as the bank to which the target bank account belongs; Use the symmetric key corresponding to the bank to which the target bank account belongs to encrypt the target bank account and the filtered associated bank accounts, respectively, to obtain the corresponding bank account ciphertext; Use the public key corresponding to the bank to which the unfiltered associated bank account belongs to encrypt the unfiltered associated bank account to obtain the corresponding bank account ciphertext.
6. The system of claim 5, wherein, Each bank server is configured to: Use the symmetric key corresponding to the bank to which the target bank account belongs to encrypt the target bank account to obtain an initial bank account ciphertext; If it is determined that the target bank account information is obtained based on the leaf node in the transaction query request, then based on the initial bank account ciphertext and the leaf node corresponding to the target bank account information, the bank account ciphertext of the target bank account is obtained.
7. The system of claim 5, wherein, The control device is configured to: For two target transaction trees, if it is determined that there are matching bank account ciphertexts in the two target transaction trees, then based on the matching bank account ciphertexts, the two target transaction trees are spliced. The target transaction tree is any one of the transaction trees and the spliced transaction trees.
8. The system of claim 7, wherein, The control device is further configured to: If it is determined that the root node in one of the target transaction trees contains a target leaf node in another target transaction tree, it is determined that the target leaf node and the root node match; the target leaf node is any leaf node in the one target transaction tree; Splice the target leaf node and the root node.
9. The system of any one of claims 1-4, wherein, The control device is further configured to: Analyze each bank account ciphertext in the fund transfer tree to determine an abnormal bank account ciphertext; Send the abnormal bank account ciphertext to each bank server, so that each bank server decrypts the abnormal bank account ciphertext using a local symmetric key; Receive the abnormal bank account returned by each bank server based on the abnormal bank account ciphertext.
10. A transaction data processing method characterized by, A control device applied to a transaction data processing system, the transaction data processing system further includes a plurality of bank servers, and the method includes: Sending a transaction query request to each bank server; the transaction query request includes the starting bank account information or the leaf node in the transaction tree returned by each bank server; receive transaction trees returned by each bank server based on the transaction query request; the transaction trees contain a plurality of bank account number ciphertexts obtained by encrypting a plurality of bank account numbers using encryption keys corresponding to banks to which the bank account numbers belong, and used to represent transactions between the plurality of bank account numbers; each bank server uses symmetric encryption for bank account numbers of the bank server and uses a public key in asymmetric encryption for cross-bank account numbers; splice the transaction trees returned by each bank server to generate a fund transfer tree; the fund transfer tree contains a plurality of bank account number ciphertexts obtained by encrypting a plurality of bank account numbers, and used to represent transactions between the plurality of bank account numbers; the transaction trees are spliced by performing an exclusive or operation on a target leaf node of a target transaction tree and a root node of another target transaction tree to obtain a splicing node, or are spliced based on matching bank account number ciphertexts in the two target transaction trees.
11. The method of claim 10, wherein, The sending of the transaction query request to each bank server includes: Upon determining that the user query instruction is received, obtaining starting bank account information in the user query instruction, and sending a transaction query request containing the starting bank account information to a bank to which the starting bank account information belongs; Alternatively, upon determining that a transaction tree returned by any bank server is received, obtaining a leaf node in the transaction tree, and sending a transaction query request containing the leaf node to each bank server, each node in the transaction tree being a bank account number ciphertext, and the leaf node being a bank account number ciphertext without a child node.
12. The method of claim 10 or 11, wherein, The splicing of the transaction trees returned by each bank server to generate the fund transfer tree includes: Upon determining that a root node in a target transaction tree among the transaction trees contains a target leaf node in another target transaction tree, determining that the target leaf node and the root node match; the target transaction tree is any one of the transaction trees and the spliced transaction trees, and the target leaf node is any leaf node in the target transaction tree; splicing the target leaf node and the root node.
13. The method of claim 10 or 11, wherein, The method is further used for: analyzing each bank account number ciphertext in the fund transfer tree to determine an abnormal bank account number ciphertext; sending the abnormal bank account number ciphertext to each bank server, so that each bank server decrypts the abnormal bank account number ciphertext using a local symmetric key; receiving an abnormal bank account number returned by each bank server based on the abnormal bank account number ciphertext.
14. A transaction data processing method characterized by, Any bank server applied to a transaction data processing system, the transaction data processing system further containing a control device, the method including: Upon determining that a transaction query request is received, determining target bank account information to be queried based on the transaction query request; the transaction query request contains starting bank account information or a leaf node in a transaction tree returned by each bank server; querying associated bank account information of the target bank account information based on the target bank account information; The target bank account information and the associated bank account information are respectively encrypted by using the encryption key corresponding to the bank to which the bank account information belongs, and a plurality of bank account ciphertexts are obtained; any bank server uses symmetric encryption for the bank account of the bank and uses the public key in asymmetric encryption for the cross-bank account to perform encryption; A transaction tree is generated based on the bank account ciphertexts; The transaction tree is sent to the control device, so that the control device splices the transaction trees returned by the bank servers to generate a fund transfer tree, and the transaction tree and the fund transfer tree both contain a plurality of bank account ciphertexts obtained by encrypting the bank account information of a plurality of bank accounts and are both used to represent the transactions between the plurality of bank accounts; the transaction tree is obtained by splicing a splicing node obtained by performing XOR operation on a target leaf node of one target transaction tree and a root node of another target transaction tree, or is obtained by splicing based on the matching bank account ciphertexts in the two target transaction trees.
15. The method of claim 14, wherein, When it is determined that the transaction query request is received, the target bank account information to be queried is determined based on the transaction query request, including: When it is determined that the transaction query request containing the initial bank account information is received, the initial bank account information contained in the transaction query request is determined as the target bank account information; Or, when it is determined that the transaction query request containing the leaf node is received, the leaf node contained in the transaction query request is obtained, the leaf node is decrypted, and the decrypted leaf node is determined as the target bank account information.
16. The method of claim 14, wherein, The associated bank account information of the target bank account information is queried based on the target bank account information, including: The associated bank account and the corresponding transaction timestamp are obtained by searching based on the target bank account in the target bank account information and the transaction information, and the associated bank account is a bank account that directly or indirectly obtains the transferred fund from the target bank account information; The transaction information of the associated bank account is generated based on the transaction timestamp corresponding to the associated bank account; The associated bank account and the corresponding transaction information are searched based on the obtained associated bank account and the corresponding transaction information until a search stop condition is reached.
17. The method of claim 16, wherein, The associated bank account and the corresponding transaction information are searched based on the obtained associated bank account and the corresponding transaction information until a search stop condition is reached, including: The following steps are repeatedly executed until the search stop condition is reached: The associated bank account and the corresponding transaction information are searched based on the obtained associated bank account and the corresponding transaction information; If it is determined that the search result is empty, it is determined that the search stop condition is reached; Otherwise, the next associated bank account information is obtained, and the next associated bank account information contains the next associated bank account and the corresponding transaction information.
18. The method of any one of claims 14-17, wherein, The associated bank account information contains the associated bank account, the target bank account information contains the target bank account, and the target bank account information and the associated bank account information are respectively encrypted by using the encryption key corresponding to the bank to which the bank account information belongs, and a plurality of bank account ciphertexts are obtained, including: From the associated bank accounts, filter out the associated bank accounts whose banks are the same as the bank to which the target bank account belongs; Use the symmetric key corresponding to the bank to which the target bank account belongs to encrypt the target bank account and the filtered associated bank account, and obtain the corresponding bank account ciphertext; Use the public key corresponding to the bank to which the unfiltered associated bank account belongs to encrypt the unfiltered associated bank account, and obtain the corresponding bank account ciphertext.
19. The method of claim 18, wherein, The step of using the symmetric key corresponding to the bank to which the target bank account belongs to encrypt the target bank account information to obtain the corresponding bank account ciphertext comprises: If it is determined that the target bank account information is obtained based on the leaf node in the transaction query request, then use the symmetric key corresponding to the bank to which the target bank account belongs to encrypt the target bank account to obtain the initial bank account ciphertext; Based on the initial bank account ciphertext and the leaf node corresponding to the target bank account information, obtain the bank account ciphertext of the target bank account.
20. An electronic device, comprising: The computer program is executed by the processor to run the method of any one of claims 10-13 or 14-19.
21. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to run the method of any one of claims 10-13 or 14-19.
Citation Information
Patent Citations
Fund tracking method, device and equipment
CN110659973A
Data processing method and device of transfer platform based on block chain network
CN110992028A
Characteristic fund flow analysis method and system of digital currency, and electronic equipment
CN113449150A