Data query method, risk control method, device, equipment and medium
By decomposing the digital identifier of the target query object into sub-digit identifiers and performing hidden query processing, the problem of information leakage during data query is solved, and the security and correctness of data query is achieved.
Patent Information
- Application Number
- CN202211050268.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-30
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2042-08-30
AI Technical Summary
When conducting data queries between different subjects, directly querying the identification information of the query object poses a risk of information leakage, affecting the query object and the subject participating in the data query.
The data query method based on hidden query is adopted. By decomposing the numerical identifiers of the target query object into N subnumerical identifiers, and dividing these subnumerical identifiers into the first and second categories, and using corresponding algorithms for calculations to obtain encrypted key values, thereby realizing hidden query.
It effectively protects the data security during the data query process, prevents information leakage, and ensures the correctness and security of query results.
Smart Images

Figure CN115422582B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of information security, and more particularly to a data query method and a risk control method based on stealth query, as well as corresponding devices, equipment, media, and program products. Background Art
[0002] When performing data queries between different entities, if the query is directly made through the identification information of the query object, there is a risk of information leakage of the query object, which may have some adverse effects on the query object and each entity participating in the data query. For example, when a financial institution queries the resource consumption level of its corporate customers during business operations through a public utility, in order to evaluate whether there are any abnormalities in the business conditions of the corporate customers, if the market learns that the corporate customers are being queried, it may cause adverse business speculations about the corporate customers in the market and may also reduce the business reputation of the financial institution. Therefore, it is crucial to ensure both the correct validity of the final query result and the data security during the query process when performing data queries between different entities. Summary of the Invention
[0003] In view of the above problems, the present disclosure provides a data query method and a risk control method based on stealth query, as well as corresponding devices, equipment, media, and program products.
[0004] In the first aspect of the embodiments of the present disclosure, a data query method based on stealth query is provided, which is applied to a data server. The data query method includes first receiving a query request, where the query request includes a first sub - digital identifier and classification information of the first sub - digital identifier; wherein, the first sub - digital identifier is any one of N sub - digital identifiers obtained by decomposing the digital identifier of a target query object based on a first algorithm rule, where N is an odd number greater than or equal to 3; the N sub - digital identifiers are divided into a first category and a second category, where the first category includes [(N - 1) / 2]+1 sub - digital identifiers, and the second category includes (N - 1) / 2 sub - digital identifiers; the classification information of the first sub - digital identifier is used to indicate whether the first sub - digital identifier belongs to the first category or the second category; the first algorithm rule has the commutative law and the associative law. Then, by querying the records of S objects, the calculation result group corresponding to the first sub - digital identifier is obtained according to the following processing method; wherein, the records of the S objects include the digital identifiers and key values of the S objects, S is an integer greater than 1, and the S objects include the target query object. The processing method includes: performing an operation on the digital identifier of each of the S objects by using the first sub - digital identifier based on the algorithm rule corresponding to the classification information of the first sub - digital identifier, to obtain S intermediate identifiers; wherein, the algorithm rule corresponding to the first category is the inverse operation of the first algorithm rule, and the algorithm rule corresponding to the second category is the first algorithm rule; and using each intermediate identifier as an encryption parameter and the key value of the object participating in the calculation of this intermediate identifier among the S objects as an encryption object, to obtain an encrypted key value corresponding to each intermediate identifier through homomorphic encryption; wherein, representing the S intermediate identifiers and the encrypted key value corresponding to each intermediate identifier in the form of key - value pairs, to obtain the calculation result group corresponding to the first sub - digital identifier. Finally, the calculation result group corresponding to the first sub - digital identifier is fed back to the data query end that issues the query request; wherein, after obtaining the N calculation result groups corresponding to the N sub - digital identifiers one by one, the data query end inversely solves the key value corresponding to the target query object based on the N calculation result groups.
[0005] According to an embodiment of the present disclosure, the first algorithm rule includes an addition operation.
[0006] According to an embodiment of the present disclosure, the homomorphic encryption includes: a power operation with the encryption object as the exponent and the encryption parameter as the base.
[0007] In a second aspect of the embodiments of the present disclosure, a data query method based on stealth query is provided, which is applied to a data query end. The data query method includes: first, obtaining a digital identifier of a target query object; then decomposing the digital identifier of the target query object based on a first algorithm to obtain N sub-digital identifiers, where N is an odd number greater than or equal to 3; next, dividing the N sub-digital identifiers into a first category and a second category, where the first category includes [(N - 1) / 2] + 1 sub-digital identifiers and the second category includes (N - 1) / 2 sub-digital identifiers; then sending the N sub-digital identifiers and the classification information of each sub-digital identifier to a data server to request the data server to perform data query according to the data query method provided in the first aspect of the embodiments of the present disclosure; then receiving N calculation result groups returned by the data server that correspond one-to-one to the N sub-digital identifiers; and finally, inversely solving the key value corresponding to the target query object based on the N calculation result groups.
[0008] According to the embodiments of the present disclosure, inversely solving the key value corresponding to the target query object based on the N calculation result groups includes: performing the following calculation in a trial-and-error manner: each time, selecting an intermediate identifier from each of the N calculation result groups, and then performing an operation on the selected N intermediate identifiers according to the first algorithm to obtain a calculation result; stopping the trial-and-error when the calculation result is a predetermined value, and selecting the N intermediate identifiers when the calculation result is the predetermined value as N target intermediate identifiers, where the predetermined value is a value determined by canceling each other out between the first algorithm and its inverse operation; and decrypting the key value of the target query object based on the encrypted key values corresponding to the N target intermediate identifiers.
[0009] According to the embodiments of the present disclosure, the first algorithm is addition, and the predetermined value is zero.
[0010] According to the embodiments of the present disclosure, decrypting the key value of the target query object based on the encrypted key values corresponding to the N target intermediate identifiers includes: when the homomorphic encryption is a power operation with the encrypted object as the exponent and the encryption parameter as the base, solving the logarithm with the product of the encrypted key values corresponding to the N target intermediate identifiers as the true number and the product of the N target intermediate identifiers as the base to obtain the key value of the target query object.
[0011] In the third aspect of the embodiments of the present disclosure, a risk control method based on stealth query is provided, which is applied to a first business entity. The risk control method includes: First, obtain the digital identifiers of M customers of the first business entity, where M is an integer greater than or equal to 1, and the M customers include a target customer; then, decompose the digital identifier of each customer based on a first algorithm to obtain N sub-digital identifiers corresponding to each customer, where a total of M*N sub-digital identifiers are obtained corresponding to the M customers; where N is an odd number greater than or equal to 3; then, divide the N sub-digital identifiers corresponding to each customer into a first category and a second category, where for each customer, the first category includes [(N - 1) / 2]+1 sub-digital identifiers, and the second category includes (N - 1) / 2 sub-digital identifiers; next, send the M*N sub-digital identifiers and the classification information of each sub-digital identifier to each of the R second business entities, so as to request each of the second business entities to perform data query according to the data query method provided in the first aspect of the embodiments of the present disclosure, where R is an integer greater than or equal to 1; then, receive the M*N calculation result groups corresponding one-to-one to the M*N sub-digital identifiers returned by the second business entity; then, select N calculation result groups corresponding to the N sub-digital identifiers of the target customer from the M*N calculation result groups; where the selected N calculation result groups are used as N target calculation result groups; after that, based on the N target calculation result groups, reverse-decode the key value of the target customer recorded in the second business entity; finally, evaluate the business risk of the target customer based on the key values of the target customer recorded in the R second business entities.
[0012] According to the embodiments of the present disclosure, the reverse-decoding the key value of the target customer recorded in the second business entity based on the N target calculation result groups includes: performing the following calculations in a trial-and-error manner: each time, select an intermediate identifier from each of the N target calculation result groups, and then perform an operation on the selected N intermediate identifiers according to the first algorithm to obtain a calculation result; stop the trial-and-error when the calculation result is a predetermined value, and select the N intermediate identifiers when the calculation result is a fixed value as N target intermediate identifiers, and the predetermined value is a value determined by the cancellation of the first algorithm and its inverse operation; and decrypt the key value of the target customer based on the encryption key values corresponding to the N target intermediate identifiers.
[0013] According to the embodiments of the present disclosure, the first algorithm is addition, and the predetermined value is zero.
[0014] According to an embodiment of the present disclosure, decrypting the key value of the target customer based on the encrypted key values corresponding to the N target intermediate identifiers includes: when the homomorphic encryption is a power operation with the encryption object as the exponent and the encryption parameter as the base, solving the logarithm with the product of the encrypted key values corresponding to the N target intermediate identifiers as the true number and the product of the N target intermediate identifiers as the base to obtain the key value of the target customer.
[0015] According to an embodiment of the present disclosure, sending the M*N sub-digital identifiers and the classification information of each sub-digital identifier to each of the R second business entities includes sending in any of the following ways: sending the M*N sub-digital identifiers in batches according to the classification information, where the classification information of each sub-digital identifier is determined according to the sending batch; marking the classification information of each sub-digital identifier and sending the M*N sub-digital identifiers after shuffling the order; or arranging the M*N sub-digital identifiers in a specific order and identifying the classification information of each sub-digital identifier through the position information of each sub-digital identifier.
[0016] According to an embodiment of the present disclosure, when R is greater than 1, evaluating the business risk of the target customer based on the key values of the target customer recorded in the R second business entities includes: performing weighted processing on the key values of the target customer recorded in the R second business entities to obtain a comprehensive score of the target customer.
[0017] According to an embodiment of the present disclosure, the first business entity includes a financial institution, and at least one of the R second business entities includes an electric power enterprise, a water supply enterprise, a heat supply enterprise, or a gas enterprise.
[0018] In a fourth aspect of the embodiments of the present disclosure, a data query device based on stealth query is provided, which is disposed on a data server. The data query device includes a first receiving module, a first query module, and a first returning module. The first receiving module is configured to receive a query request, where the query request includes a first sub-digital identifier and classification information of the first sub-digital identifier; wherein, the first sub-digital identifier is any one of N sub-digital identifiers obtained by decomposing a digital identifier of a target query object based on a first algorithm rule, where N is an odd number greater than or equal to 3; the N sub-digital identifiers are divided into a first category and a second category, where the first category includes [(N - 1) / 2] + 1 sub-digital identifiers, and the second category includes (N - 1) / 2 sub-digital identifiers; the classification information of the first sub-digital identifier is used to indicate whether the first sub-digital identifier belongs to the first category or the second category; the first algorithm rule has a commutative law and an associative law. The first query module is configured to obtain a calculation result group corresponding to the first sub-digital identifier by querying records of S objects according to the following processing method; wherein, the records of the S objects include digital identifiers and key values of the S objects, S is an integer greater than 1, and the S objects include the target query object. The first query module specifically includes a first query operation sub-module and a first query encryption sub-module. The first query operation sub-module is configured to perform an operation on the digital identifier of each of the S objects by using the first sub-digital identifier based on an algorithm rule corresponding to the classification information of the first sub-digital identifier to obtain S intermediate identifiers; wherein, the algorithm rule corresponding to the first category is the inverse operation of the first algorithm rule, and the algorithm rule corresponding to the second category is the first algorithm rule. The first query encryption sub-module is configured to use each intermediate identifier as an encryption parameter and the key values of the objects participating in the calculation of the intermediate identifier among the S objects as encryption objects to obtain an encrypted key value corresponding to each intermediate identifier through homomorphic encryption; wherein, the S intermediate identifiers and the encrypted key value corresponding to each intermediate identifier are represented in a key-value pair manner to obtain a calculation result group corresponding to the first sub-digital identifier. The first returning module is configured to feedback the calculation result group corresponding to the first sub-digital identifier to a data query end that issues the query request; wherein, after obtaining N calculation result groups corresponding to the N sub-digital identifiers one by one, the data query end inversely solves the key value corresponding to the target query object based on the N calculation result groups.
[0019] In the fifth aspect of the embodiments of the present disclosure, a data query device based on stealth query is provided, which is arranged at the data query end. The data query device includes: a second acquisition module, a second decomposition module, a second classification module, a second request sending module, a second result receiving module, and a second data inverse resolution module. The second acquisition module is used to acquire the digital identifier of the target query object. The second decomposition module is used to decompose the digital identifier of the target query object based on the first algorithm rule to obtain N sub-digital identifiers, where N is an odd number greater than or equal to 3. The second classification module is used to divide the N sub-digital identifiers into a first category and a second category, where the first category includes [(N - 1) / 2] + 1 sub-digital identifiers, and the second category includes (N - 1) / 2 sub-digital identifiers. The second request sending module is used to send the N sub-digital identifiers and the classification information of each sub-digital identifier to the data server to request the data server to perform data query by using the data query device described in the fourth aspect above provided therein. The second result receiving module is used to receive N calculation result groups returned by the data server that correspond one-to-one to the N sub-digital identifiers. The second data inverse resolution module is used to inverse-resolve the key value corresponding to the target query object based on the N calculation result groups.
[0020] According to the embodiments of the present disclosure, the second data inverse resolution module is specifically used for: performing the following calculation in a trial calculation manner, each time selecting an intermediate identifier from each of the N calculation result groups, and then performing an operation on the selected N intermediate identifiers according to the first algorithm rule to obtain a calculation result; then stopping the trial calculation when the calculation result is a predetermined value, and selecting the N intermediate identifiers when the calculation result is the predetermined value as N target intermediate identifiers, where the predetermined value is a value determined by the cancellation of the first algorithm rule and its inverse operation; decrypting the key value of the target query object based on the encrypted key values corresponding to the N target intermediate identifiers.
[0021] According to the embodiments of the present disclosure, the first algorithm rule is addition, and the predetermined value is zero.
[0022] According to the embodiments of the present disclosure, the second data inverse resolution module is further used for: when the homomorphic encryption is a power operation with the encrypted object as the exponent and the encrypted parameter as the base, solving the logarithm with the product of the encrypted key values corresponding to the N target intermediate identifiers as the true number and the product of the N target intermediate identifiers as the base to obtain the key value of the target query object.
[0023] In a sixth aspect of the embodiments of the present disclosure, a risk control device based on stealth query is provided, which is disposed in a first business entity. The risk control device includes: a third acquisition module, a third decomposition module, a third classification module, a third sending module, a third result receiving module, a third selection module, a third data inverse solution module, and a third evaluation module. The third acquisition module is configured to acquire digital identifiers of M customers of the first business entity, where M is an integer greater than or equal to 1, and the M customers include target customers. The third decomposition module is configured to decompose the digital identifier of each customer based on a first algorithm to obtain N sub-digital identifiers corresponding to each customer; where, corresponding to the M customers, a total of M * N sub-digital identifiers are obtained; where N is an odd number greater than or equal to 3. The third classification module is configured to divide the N sub-digital identifiers corresponding to each customer into a first category and a second category; where, for each customer, the first category includes [(N - 1) / 2] + 1 sub-digital identifiers, and the second category includes (N - 1) / 2 sub-digital identifiers. The third sending module is configured to send the M * N sub-digital identifiers and the classification information of each sub-digital identifier to each of the R second business entities, where R is an integer greater than or equal to 1. The third result receiving module is configured to receive M * N calculation result groups corresponding one-to-one to the M * N sub-digital identifiers returned by each of the second business entities after performing data queries using the data query device described in the fourth aspect above provided therein. The third selection module is configured to select N calculation result groups corresponding to the N sub-digital identifiers of the target customer from the M * N calculation result groups; where, the selected N calculation result groups are used as N target calculation result groups. The third data inverse solution module is configured to inverse-solve the key value of the target customer recorded in the second business entity based on the N target calculation result groups. The third evaluation module is configured to evaluate the business risk of the target customer based on the key values of the target customer recorded in the R second business entities.
[0024] According to an embodiment of the present disclosure, the third sending module is further configured to send the M * N sub-digital identifiers and the classification information of each sub-digital identifier in any one of the following ways: sending the M * N sub-digital identifiers in batches according to the classification information, where the classification information of each sub-digital identifier is determined according to the sending batch; marking the classification information of each sub-digital identifier and sending the M * N sub-digital identifiers after scrambling the order; or arranging the M * N sub-digital identifiers in a specific order and identifying the classification information of each sub-digital identifier through the position information of each sub-digital identifier.
[0025] According to an embodiment of the present disclosure, when R is greater than 1, the third evaluation module is further configured to perform weighted processing on the key values of the target customer recorded in the R second business entities to obtain a comprehensive score of the target customer.
[0026] In a seventh aspect of the embodiments of the present disclosure, an electronic device is provided. The electronic device includes one or more processors and a memory. The memory is used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute: the data query method described in the first aspect above, or the data query method described in the second aspect above, or the risk control method described in the third aspect above.
[0027] In an eighth aspect of the embodiments of the present disclosure, a computer-readable storage medium is further provided, on which executable instructions are stored, and when the instructions are executed by a processor, the processor is caused to execute: the data query method described in the first aspect above, or the data query method described in the second aspect above, or the risk control method described in the third aspect above.
[0028] In a ninth aspect of the embodiments of the present disclosure, a computer program product is further provided, including a computer program, and when the computer program is executed by a processor, it implements: the data query method described in the first aspect above, or the data query method described in the second aspect above, or the risk control method described in the third aspect above.
[0029] The above one or more embodiments have the following advantages or beneficial effects: The data query end decomposes the data identifier of the object to be queried into a series of sub-identifiers and then provides them for query. Matching calculations are performed based on the received sub-data identifiers, and a corresponding calculation result set is returned. In this way, except for the final query user at the data query end, almost no link in the entire data query process and data transmission link can know which object's data is being queried. Even if the transmitted data is leaked during network transmission, it is difficult to know the specific object being queried. In this way, the data security during the data query process is improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] Through the following description of the embodiments of the present disclosure with reference to the drawings, the above content and other objects, features, and advantages of the present disclosure will become clearer. In the drawings:
[0031] Figure 1 Schematically shows an application scenario diagram of a data query method, device, equipment, medium, and program product according to an embodiment of the present disclosure;
[0032] Figure 2 Schematically shows a schematic diagram of decomposing sub-digital identifiers from the digital identifier of a target object according to an embodiment of the present disclosure;
[0033] Figure 3 Schematically shows a schematic diagram of S objects according to an embodiment of the present disclosure;
[0034] Figure 4 Schematically shows a flowchart of a data query method applied to a data server according to an embodiment of the present disclosure;
[0035] Figure 5 Schematically shows a schematic diagram of a data query method applied to a data query end according to an embodiment of the present disclosure;
[0036] Figure 6 Schematically shows a flowchart of the data query end reverse-solving the data of the target query object according to an embodiment of the present disclosure;
[0037] Figure 7 Schematically shows the system architecture of a risk control method according to an embodiment of the present disclosure;
[0038] Figure 8 Schematically shows a flowchart of a risk control method according to an embodiment of the present disclosure;
[0039] Figure 9 Schematically shows a schematic diagram of a first business entity decomposing a sub-digital identifier from the digital identifiers of multiple customers in a risk control method according to an embodiment of the present disclosure;
[0040] Figure 10 Schematically shows the interaction between a financial institution and an electric power enterprise in a risk control method according to an embodiment of the present disclosure;
[0041] Figure 11 Schematically shows the interaction between a financial institution and a water enterprise in a risk control method according to an embodiment of the present disclosure;
[0042] Figure 12 Schematically shows the interaction between a financial institution and a gas enterprise in a risk control method according to an embodiment of the present disclosure;
[0043] Figure 13 Schematically shows the interaction between a financial institution and a heating enterprise in a risk control method according to an embodiment of the present disclosure;
[0044] Figure 14 Schematically shows a block diagram of a data query device provided in a data server according to an embodiment of the present disclosure;
[0045] Figure 15 Schematically shows a block diagram of a data query device provided in a data query end according to an embodiment of the present disclosure;
[0046] Figure 16 Schematically shows a block diagram of a risk control device based on concealed query according to an embodiment of the present disclosure; and
[0047] Figure 17A block diagram of an electronic device suitable for a data query method or a risk control method based on stealth query according to an embodiment of the present disclosure is schematically shown. Detailed implementation manners
[0048] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the following detailed description, for the sake of explanation, numerous specific details are set forth in order to provide a comprehensive understanding of the embodiments of the present disclosure. However, it is obvious that one or more embodiments can be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessarily confusing the concepts of the present disclosure.
[0049] The terms used herein are merely for describing specific embodiments and are not intended to limit the present disclosure. The terms "including", "comprising", etc. used herein indicate the presence of the described features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0050] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification, and should not be interpreted in an idealized or overly rigid manner.
[0051] In the case of using expressions such as "at least one of A, B, and C, etc.", generally, it should be interpreted according to the meaning commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include, but is not limited to, a system having only A, only B, only C, having A and B, having A and C, having B and C, and / or having A, B, and C, etc.). The terms "first" and "second" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly indicating the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more features.
[0052] Embodiments of the present disclosure provide a data query method and apparatus based on stealth query, a risk control method and apparatus based on the stealth query, and an electronic device, a medium, and a program product for implementing the methods of the various embodiments of the present disclosure. Among them, stealth query, also known as trace - hiding query or private information query, refers to the data query end hiding the keyword or identification information (for example, ID information) of the object to be queried, and the data service end feeding back the matching query results according to the information provided by the data query end but being unable to know which specific query object it corresponds to.
[0053] Specifically, in the data query method based on stealth query according to the embodiments of the present disclosure, the data query end decomposes the digital identifier of the target query object into N sub-digital identifiers, and then provides these N sub-digital identifiers to the data server at one time or one by one. The data server, according to the received sub-digital identifiers, obtains a calculation result group corresponding to each sub-digital identifier through matching calculation from the records of S stored objects, and returns it to the data query end. After the data query end receives the calculation result groups corresponding to all N sub-digital identifiers decomposed from the digital identifier of the target query object, it can reverse-decompose the key value of the target query object stored in the data server. In this article, the "key value" refers to the value of an object on a certain field or attribute (such as power consumption, credit score, etc.).
[0054] Figure 1 FIG. schematically shows an application scenario diagram of a data query method, apparatus, device, medium, and program product according to an embodiment of the present disclosure. It should be noted that Figure 1 The shown is only an example of a system architecture to which the embodiments of the present disclosure can be applied, to help those skilled in the art understand the technical content of the present disclosure, but it does not mean that the embodiments of the present disclosure cannot be used in other devices, systems, environments, or scenarios.
[0055] As Figure 1 shown, the application scenario 100 according to this embodiment may include a data query end 110, a data server 120, and a network 130. The network 130 is a medium for providing a communication link between the data query ends 110 and 120. The network 130 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.
[0056] The data query end 110 has a terminal device 112 that can display query results, and a server 111 with data processing capabilities. The user can use the terminal device 112 to send instructions to the server 111, such as specifying the target query object and its query content (that is, which field or attribute key value to query). The server 111 can decompose the digital identifier of the target query object into sub-digital identifiers, and then send a query request to the data server 120 through the network 130. And after the server 111 receives the query result feedback from the data server 120 through the network 130, it processes the query result, reverse-decomposes the key value of the target query object, and then displays it to the user in the terminal device 112.
[0057] The data server 120 includes a database 121 with data storage capabilities and a database server 122 with computing capabilities. After receiving a query request from the data query end 110 through the network 130, the database server 122 can first preliminarily locate the query data range (e.g., S objects) from the database 121, and then obtain the calculation result group corresponding to each sub - digital identifier through the matching operation between the sub - digital identifier in the query request and the digital identifiers of the S objects. Then, the calculation result group is returned to the data query end 110 through the network 130.
[0058] In the embodiments of the present disclosure, to achieve the concealed query of the data server 120 and the correct inverse solution of the data query end 110, it is required that the algorithms used in the concealed query in the data server 120 and the algorithms used in the data query end 110 to inverse - solve the key values of the target query objects have a corresponding relationship. Specifically, in the data query method of the embodiments of the present disclosure, it is mainly manifested in the following aspects.
[0059] First, in the embodiments of the present disclosure, the data query end 110 decomposes the digital identifier of the target query object into N sub - digital identifiers based on the first operation rule, where N is an odd number greater than or equal to 3.
[0060] Second, in the embodiments of the present disclosure, when the data query end 110 sends the sub - digital identifier to the data server 120, it will also send the classification information of the sub - digital identifier. Among them, when the data query end 110 decomposes into N sub - digital identifiers, the N sub - digital identifiers will be divided into two categories: the first category and the second category. Among them, the first category includes [(N - 1) / 2]+1 sub - digital identifiers, and the second category includes (N - 1) / 2 sub - digital identifiers. The number of sub - digital identifiers in the first category is exactly 1 more than the number of sub - digital identifiers in the second category.
[0061] The role of this classification information is that when the data server 120 performs the matching operation, the sub - digital identifiers in the first category perform the inverse operation of the first operation rule on the digital identifiers of the S objects respectively to obtain the corresponding intermediate identifiers, while the sub - digital identifiers in the second category perform the operation based on the first operation rule on the digital identifiers of the S objects respectively to obtain the corresponding intermediate identifiers. In the embodiments of the present disclosure, the intermediate identifier corresponding to each sub - digital identifier will be used as a component of the calculation result group of the sub - digital identifier and returned to the data query end 110.
[0062] Again, in the embodiments of the present disclosure, the first algorithm has the commutative law and the associative law. This means that after obtaining the calculation result groups of each sub-digital identifier returned by the data query end 110, when the intermediate identifiers corresponding to different sub-digital identifiers are recombined according to the first operation rule, there will be a mutual cancellation effect between the first operation rule and its inverse operation. Thus, when the data query end 110 performs inverse solution, this mutual cancellation effect can be utilized to inversely solve the correct result from the calculation result groups of all N sub-digital identifiers corresponding to the target query object.
[0063] Here, taking the first operation rule as addition and N as 3 as an example, in combination with Figure 1 , Figure 2 and Figure 3 as examples, the conceptual principle of the embodiments of the present disclosure is exemplarily described.
[0064] Among them, Figure 2 schematically shows a schematic diagram of decomposing a digital identifier A1 of a target object into three sub-digital identifiers A11, A12, and A13 according to the embodiments of the present disclosure. Figure 3 schematically shows a schematic diagram of S objects in the embodiments of the present disclosure, where Figure 3 specifically exemplifies four objects.
[0065] Specifically, referring to Figure 2 , when A1 represents the digital identifier of the target query object (for example, the ID of an enterprise), A1 can be decomposed into {A11, A12, A13}. Since the first operation rule is addition, correspondingly A1 = A11 + A12 + A13.
[0066] In the embodiments of the present disclosure, when the data query end 110 sends the sub-digital identifier to the data service end 120, the classification information of the sub-digital identifier will be sent simultaneously. This classification information can be provided by tagging the sub-digital identifier or by sending the N sub-digital identifiers in a specific order. For example, Figure 2 in it, classification can be performed according to the second subscript of {A11, A12, A13}, where those with an odd second subscript belong to the first category and those with an even second subscript belong to the second category. The role of this classification information is to select whether to perform the first operation rule operation or the inverse operation of the first operation rule on the digital identifiers of the S objects for the sub-digital identifier during the matching operation of the data service end 120.
[0067] Referring to Figure 3, assume that the digital identifiers of S objects in the data server 120 are {B1, B2, B3, B4}. Among them, in the data server 120, information can be stored in the form of digital identifiers of objects and key-value pairs [KEY, VALUE], such as {[B1, v1], [B2, v2], [B3, v3], [B4, v4]}.
[0068] Combined with Figure 2 and Figure 3 , when the data server 120 receives any one of the sub-digital identifiers in {A11, A12, A13}, corresponding calculations can be performed on each digital identifier in {B1, B2, B3, B4} according to the classification information of the sub-digital identifier. Among them, analogy division can be performed according to the second subscript. Among them, the second subscript being odd is divided into the first category, and the second subscript being even is divided into the second category. Thus, the second subscripts of A11 and A13 are odd, so subtraction is applicable, and the second subscript of A12 is even, so addition is applicable. For example:
[0069] Calculation method of A11 and B1: D111 = A11 - B1
[0070] Calculation method of A12 and B1: D121 = A12 + B1
[0071] Calculation method of A13 and B1: D131 = A13 - B1
[0072] Among them, D111, D121, and D131 are the intermediate identifiers corresponding to A11, A12, and A13 respectively.
[0073] After performing calculations on B2, B3, and B4 respectively in a manner similar to that of {A11, A12, A13} and B1, the corresponding intermediate identifiers D112, D122, D132, D113, D123, D133, D114, D124, and D134 can be obtained.
[0074] Meanwhile, in the embodiments of the present disclosure, after the data server 120 obtains each intermediate identifier, it can also use the intermediate identifier as an encryption parameter to perform homomorphic encryption on the key values of the objects participating in the calculation of the intermediate identifier among the S objects. For example, v1 in [B1, v1] can be encrypted using D111, D121, and D131. For example, through power operation encryption, the encrypted key values are obtained:
[0075] C111 = D111 v1 ,
[0076] C121 = D121 v1 ,
[0077] C131 = D131 v1 .
[0078] Similarly, after encrypting the key values of the three objects {[B2, v2], [B3, v3], [B4, v4]}, {C112, C122, C132, C113, C123, C133, C114, C124, C134} can be obtained.
[0079] Each intermediate identifier and the encrypted key value corresponding to this intermediate identifier can be represented in the form of key-value pairs, such as:
[0080] {[D111, C111], [D121, C121], [D131, C131],
[0081] [D112, C112], [D122, C122], [D132, C132],
[0082] [D113, C113], [D123, C123], [D133, C133],
[0083] [D114, C114], [D124, C124], [D134, C134]}.
[0084] Among them, the part of A11 participating in the calculation constitutes the calculation result group [D, C] of A11 11 :
[0085] [D, C] 11 = {[D111, C111], [D112, C112], [D113, C113], [D114, C114]}.
[0086] The part of A12 participating in the calculation constitutes the calculation result group [D, C] of A12 12 :
[0087] [D, C] 12 = {[D121, C121], [D122, C122], [D123, C123], [D124, C124]}.
[0088] The part of A13 participating in the calculation constitutes the calculation result group [D, C] of A13 13 :
[0089] [D, C] 13 = {[D131, C131], [D132, C132], [D133, C133], [D124, C124]}.
[0090] The data query end 110 will use the calculation result groups [D, C] 11 , [D, C] 12 and [D, C] 13, as the calculation result groups for A11, A12, and A13 respectively, are fed back to the data query end 110. Thus, the process of the data server 120's oblivious query for {A11, A12, A13} comes to an end.
[0091] Next, after the data query end 110 obtains the respective calculation result groups of A11, A12, and A13 [D, C] 11 、[D, C] 12 and [D, C] 13 , it reverse-solves the key value of A1 by finding the calculation result where D11i + D12i + D13i is 0.
[0092] Because:
[0093] D11i + D12i + D13i
[0094] =(A11 - Bi)+(A12 + Bi)+(A13 - Bi)
[0095] =A11 + A12 + A13 - Bi
[0096] =A1 - Bi
[0097] When D11i + D12i + D13i is 0, it indicates that Bi = A1.
[0098] When A1 = Bi, by calculating the encrypted key values C11i, C12i, C13i corresponding to D11i, D12i, D13i when the calculation result is 0, vi can be obtained. The calculation method is:
[0099] C11i * C12i * C13i = D11i vi *D12i vi *D13i vi =(D11i * D12i * D13i) vi
[0100] Thus, vi = log (D11i*D12i*D13i) (C11i * C12i * C13i)
[0101] In this way, the data query end 110 reverse-solves the key value vi of the target query object A1 (i.e., Bi).
[0102] It can be seen that when the data query end 110 reverse-solves the key value of the target query object, it is considered that the three data D11i, D12i, D13i are obtained through "subtraction", "addition", and "subtraction" operations respectively, and the subtraction is exactly one more time than the addition, while A1 = A11 + A12 + A13 is an addition operation. Thus, the mutual cancellation effect of addition and subtraction can be used to find D11i + D12i + D13i = 0.
[0103] It can be seen that during the process of inverse-solving the result at the data query end 110, the following is fully utilized: N is odd, such that the number of sub-digital identifiers in the first category is exactly 1 more than the number of sub-digital identifiers in the second category, ensuring that during the calculation of the three numbers D11i, D12i, and D13i, subtraction is exactly one more time than addition; at the same time, addition has the commutative law and the associative law. After the superposition of the positive and inverse operations cancels each other out, it is inevitable that D11i + D12i + D13i = A1 - Bi.
[0104] Then, after locating D11i, D12i, and D13i when D11i + D12i + D13i = 0, vi can be decrypted according to the decryption algorithm corresponding to the homomorphic encryption algorithm.
[0105] Combined with Figure 1 It can be seen that for the data query method of the embodiment of the present disclosure, except for the end user of the data query end 110, almost no one in the entire data query process and any link in the data transmission link can know which specific object's data is being queried. Even if the transmitted data is leaked during the network transmission process, or the query request information is leaked at the data server 120, it is almost impossible to know the specific object being queried. Moreover, when the data query end 110 sends a query request to the data server 120, some confusion or obfuscation measures can also be taken, such as scrambling the sub-digital identifiers of multiple objects in random order or sending them one by one or in batches, etc., to further enhance the data security during the data query process.
[0106] It should be noted that the data query method and device determined by the embodiment of the present disclosure can be used in the financial field and can also be used in any field other than the financial field. The present disclosure does not limit the application field.
[0107] It should be understood that Figure 1 the numbers of the terminal devices, networks, and servers in
[0108] are merely illustrative. According to the implementation requirements, there can be any number of terminal devices, networks, and servers. Figure 1 The following will be based on Figure 2 the scenarios described in Figure 3 and Figures 4 to 6 the examples in
[0109] Figure 4 A flowchart of the data query method applied to the data server 120 according to the embodiment of the present disclosure is schematically shown.
[0110] As Figure 4 shown, the data query method according to this embodiment may include operation S410 to operation S440.
[0111] First, in operation S410, a query request is received. The query request includes a first sub - digital identifier and classification information of the first sub - digital identifier.
[0112] The first sub - digital identifier is any one of N sub - digital identifiers obtained by decomposing the digital identifier of the target query object based on a first algorithm rule, where N is an odd number greater than or equal to 3.
[0113] The digital identifier of the target query object is decomposed into N sub - digital identifiers based on the first algorithm rule, which means that after combining the N sub - digital identifiers based on the first algorithm rule, the digital identifier of the target query object can be directly or indirectly obtained. For example, in the previous example, A1 = A11+A12+A13, that is, the three sub - digital identifiers directly obtain A1 based on addition combination. And for an example of indirectly obtaining the digital identifier of the target query object by combining N sub - digital identifiers based on the first algorithm rule, reference can be made to the analysis and introduction of lgA1 = A11+A12+A13 in the following text.
[0114] The classification information of the first sub - digital identifier is used to indicate whether the first sub - digital identifier belongs to the first category or the second category. Among them, the N sub - digital identifiers decomposed from the digital identifier of the target query object are divided into the first category and the second category. Among them, the first category includes [(N - 1) / 2]+1 sub - digital identifiers, and the second category includes (N - 1) / 2 sub - digital identifiers. In the previous example, A11, A12, and A13 are divided according to whether the second subscript is odd or even. Of course, in practical applications, the classification information of each sub - digital identifier can be determined by means of the label information in the received first sub - digital identifier, or the position information of each sub - digital identifier in the sequence composed of the received multiple sub - digital identifiers, or the batch information of the received sub - digital identifiers when receiving sub - digital identifiers in batches, etc.
[0115] Then, in operation S420, for the digital identifier of each of the S objects, an operation is performed based on the algorithm rule corresponding to the classification information of the first sub - digital identifier using the first sub - digital identifier, and S intermediate identifiers are obtained. Among them, the algorithm rule corresponding to the first category is the inverse operation of the first algorithm rule, and the algorithm rule corresponding to the second category is the first algorithm rule.
[0116] The S objects can be at least a part of the data objects stored in the database 122 of the data server 120. Among them, the S objects include the target query object, and S is an integer greater than 1. The records of the S objects stored in the database 122 include the digital identifiers and key values of the S objects.
[0117] In practical applications, when the data query end 110 sends a query request to the data service end 120, it can simultaneously provide the data service end 120 with information for limiting query conditions, so that the data service end 120 can determine the S objects according to the query condition information. For example, when the target query object is a certain enterprise, the data query end 110 can inform the data service end 120 of the industry where the target query object is located, or the data query end 110 can request information about enterprises whose establishment years are within a certain time range, etc.
[0118] After operation S420, the first sub - digital identifier can obtain S intermediate identifiers. Among them, when calculating the S intermediate identifiers, according to the classification information of the first sub - digital identifier, it is determined whether to apply the first operation rule or the inverse operation of the first operation rule.
[0119] In the example above, the first operation rule is addition. The second subscripts of A11 and A13 are odd numbers and are classified into the first category, so subtraction is applicable. The second subscript of A12 is an even number and is classified into the second category, so addition is applicable. When the first sub - digital identifier is A11, after operation S420, the three intermediate identifiers corresponding to A11 are: D111 = A11 - B1, D112 = A11 - B2, D113 = A11 - B3.
[0120] Next, in operation S430, using each intermediate identifier as the encryption parameter and the key values of the objects in the S objects that participate in the calculation of this intermediate identifier as the encryption objects, through homomorphic encryption, the encrypted key values corresponding to each intermediate identifier are obtained. Encrypting the key values before transmission can reduce the risk of data leakage during network transmission.
[0121] For example, when the first operation rule is addition and A1 = A11 + A12 + A13, as in the example above, through power operation, the encrypted key value C11i = D11i can be obtained for each intermediate identifier. v1 。
[0122] It should be noted that encrypting through power operation in operation S430 is only one embodiment of homomorphic encryption. In actual operation, other algorithms can also be used for encryption. For example, in one embodiment, when the first operation rule is addition and A1 = A11 + A12 + A13, the encrypted key value of each intermediate identifier can also be obtained through multiplication operation, that is, C11i = D11i * v1. In this way, the process of calculating vi using the encrypted key values C11i, C12i, C13i corresponding to D11i, D12i, D13i when the calculation result of D11i + D12i + D13i is 0 can be as follows:
[0123]
[0124] It can be seen that the homomorphic encryption algorithm in operation S430 can have various forms and various deformations. Examples are not given one by one here.
[0125] In the embodiments of the present disclosure, S intermediate identifiers of the first sub-digital identifier can be obtained through operation S420, and S encryption key values corresponding one-to-one to the S intermediate identifiers can be obtained through operation S430. The S intermediate identifiers and their corresponding S encryption key values can be represented in the form of key-value pairs, and the calculation result group corresponding to the first sub-digital identifier can be obtained. For example, the calculation result groups corresponding to A11, A12, and A13 can be respectively marked as [D, C] 11 , [D, C] 12 and [D, C] 13 .
[0126] Then in operation S440, the calculation result group corresponding to the first sub-digital identifier is fed back to the data query end 110 that issues the query request. After the data query end 110 obtains the N calculation result groups corresponding one-to-one to the N sub-digital identifiers, the key value corresponding to the target query object can be reverse-solved based on the N calculation result groups.
[0127] Of course, it can be understood that the first operation rule in the embodiments of the present disclosure is not limited to addition.
[0128] In some embodiments, the first operation rule can also be multiplication. For example, A1 = A11 * A12 * A13. Correspondingly, when obtaining S intermediate identifiers in operation S420, division operations can be performed on B1, B2, B3, and B4 respectively using A11 and A13, and multiplication operations can be performed on B1, B2, B3, and B4 respectively using A12, so that the obtained intermediate identifiers are: D11i = A11 / B1, D12i = A12 * B1, D13i = A13 / B1. When homomorphically encrypting to obtain the encryption key value in operation S430, each intermediate identifier can be multiplied by the key value of the object for calculating the intermediate identifier, that is, C11i = vl * D11i, C12i = vl * D11i, C13i = vl * D11i.
[0129] In this way, when the data query end 110 reverse-solves A1, a set of solutions where D11i * D12i * D13i = 1 can be found, because D11i * D12i * D13i
[0130] = A11 / Bi * A12 * Bi * A13 / Bi
[0131] = A11 * A12 * A13 / Bi
[0132] = A1 / Bi
[0133] When D11i * D12i * D13i = 1, it indicates that Bi = A1.
[0134] Meanwhile, when the data query end 110 inverse - solves the key value of A1, it can be done through:
[0135]
[0136] to decrypt and obtain the key value vi of the target query object A1.
[0137] In some other embodiments, the digital identifier of the target query object is decomposed into N sub - digital identifiers based on the first algorithm rule. It is also possible to first perform a function process on the digital identifier of the target query object and then use the first algorithm rule for decomposition. For example, the logarithm of the digital identifier of the target query object can be taken first, and then the logarithm - taken digital identifier of the target query object is decomposed into the sum of three sub - digital identifiers. For example, it is denoted as lgA1 = lga11 + lga12 + lga13, where a11, a12, and a13 are actually three factors of A1. After such processing, the three sub - digital identifiers of A1 can be taken as A11 = lga11, A12 = lga12, and A13 = lga13. In this case, the first algorithm rule is addition, and the sub - digital identifiers A11, A12, and A13 of A1 can indirectly obtain A1 through combination by the first algorithm rule, that is, lgA1 = A11 + A12 + A13.
[0138] In operation S420 like this, after the data server 120 receives any one of the three sub - digital identifiers A11, A12, and A13, in one embodiment, the logarithm of the digital identifiers of the S objects stored locally can be taken first, and then an operation is performed with the sub - digital identifier based on the first algorithm rule or its inverse operation to obtain an intermediate identifier. For example, take the logarithm of B1, B2, B3, B4 first to get lgB1, 1gB2, 1gB3, lgB4, and then when calculating the intermediate identifier, it can be obtained that, for example, D11i = A11 - 1gBi, D12i = A12 + lgBi, D13i = A13 - lgBi. Correspondingly, in operation S430, the encrypted key value can be obtained through power operation, that is, C11i = D11i v1 , C12i = D12i v1 , C13i = D13i v1 .
[0139] In this way, when the data query end 110 inverse - solves A1, a group of intermediate identifiers with D11i + D12i + D13i = 0 can be found. This is because in this case, D11i + D12i + D13i = A11 - lgBi + A12 + lgBi + A13 - lgBi = lg(A1 / Bi). Meanwhile, when the data query end 110 inverse - solves the key value of A1, it can be done through:
[0140] C11i * C12i * C13i = D11i vi * D12i vi * D13i vi = (D11i * D12i * D13i) vi
[0141] Thus, vi = log (D11i*D12i*D13i) (C11i * C12i * C13i)
[0142] As can be seen from the above example, there can be various specific implementation methods for decomposing the digital identifier of the target query object into N sub-digital identifiers based on the first arithmetic rule. Among them, for different decomposition methods, the operation methods of changing the intermediate identifier and the homomorphic encryption algorithm in operations S420 and S430 can achieve the hidden query. For various deformation forms, the present disclosure will not give examples one by one.
[0143] As can be seen from the above introduction, when the data query method of the embodiment of the present disclosure is applied to the data server 120, the received query request does not explicitly contain the information of the target query object, and the calculation result group returned to the data query end 110 does not contain the information pointing to a certain object either. Thus, it is difficult for the data server 120 to locate the target query object being queried. In particular, assuming that the data query end 110 decomposes the digital identifier of the target query object into multiple sub-digital identifiers and sends them over at different time periods, and the time intervals between them are relatively long or other data query contents are inserted during the intervals, it is even more difficult for the data server 120 to deduce the query purpose of the data query end 110.
[0144] Figure 5 Schematically shows a schematic diagram of the data query method applied to the data query end 110 according to an embodiment of the present disclosure. Among them, since there is an interaction relationship between the data query end 110 and the data server 120 during the data query process, thus Figure 5 The part related to the interaction in the schematic method, and Figure 4 The method shown has a certain corresponding relationship.
[0145] As Figure 5 shown, the data query method according to this embodiment may include operations S510 to S560.
[0146] In operation S510, obtain the digital identifier of the target query object. For example, it can be specified or filtered by the user's operation in the terminal device 112 for the target query object.
[0147] In operation S520, decompose the digital identifier of the target query object based on the first algorithm to obtain N sub-digital identifiers, where N is an odd number greater than or equal to 3.
[0148] In operation S530, divide the N sub-digital identifiers into a first category and a second category, where the first category includes [(N - 1) / 2] + 1 sub-digital identifiers, and the second category includes (N - 1) / 2 sub-digital identifiers.
[0149] In operation S540, send the N sub-digital identifiers and the classification information of each sub-digital identifier to the data server 120 to request the data server 120 to perform a data query.
[0150] In the embodiment of the present disclosure, the decomposition process of the sub-digital identifiers in operation S520, the category division process in operation S530, and the implementation process of sending the sub-digital identifiers and their classification information to the data server 120 in operation S540 can refer to the relevant introductions in the previous operations S410 and Figures 1 to 3 are not elaborated here.
[0151] After the data query end 110 sends the sub-digital identifiers and their classification information to the data server 120, data query can be performed according to the method described above Figure 4 to obtain a calculation result group corresponding to each sub-digital identifier, and send the calculation result group corresponding to each sub-digital identifier to the data query end 110.
[0152] In operation S550, receive N calculation result groups returned by the data server 120 and corresponding one-to-one to the N sub-digital identifiers.
[0153] In operation S560, reverse-solve the key value corresponding to the target query object based on the N calculation result groups. The principle of reverse-solving has been introduced in detail above and is not elaborated here. The following refers to Figure 6 to give an exemplary introduction to a feasible implementation process of reverse-solving.
[0154] Figure 6 Schematically shows a flowchart of the data query end 110 reverse-solving the data of the target query object according to the embodiment of the present disclosure.
[0155] As Figure 6 shown, according to this embodiment, operation S560 may include operations S601 to S603.
[0156] In operation S601, perform the following calculation in a trial calculation manner: each time, select an intermediate identifier from each of the N calculation result groups, and then perform an operation on the selected N intermediate identifiers according to the first algorithm to obtain a calculation result. For example, each time from [D, C] 11 、[D, C]12 and [D, C] 13 Among the three groups of arrays, each time a middle identifier is selected respectively, so that three middle identifiers are selected each time, and then the three middle identifiers selected according to the first operation rule are calculated.
[0157] In operation S602, when the calculation result is a predetermined value, the trial calculation is stopped, and N middle identifiers when the calculation result is the predetermined value are selected as N target middle identifiers.
[0158] The predetermined value used to judge the stop of the trial calculation is a value determined by the cancellation of the first operation rule and its inverse operation. In one embodiment, when the first operation rule is addition, the predetermined value is zero. For example, in the previous example, when A1 = A11 + A12 + A13, or lgA1 = A11 + A12 + A13, the corresponding judgment condition can be D11i + D12i + D13i = 0. In another embodiment, when the first operation rule is multiplication, the predetermined value can be 1. For example, in the previous example, A1 = A11 * A12 * A13, and the corresponding judgment condition is D11i * D12i * D13i = 1.
[0159] In operation S603, based on the encryption key values corresponding to the N target middle identifiers, the key value of the target query object is decrypted.
[0160] The algorithm adopted in the decryption process corresponds to the homomorphic encryption algorithm of the data server 120 in operation S430. For example, when the first operation rule is addition and the data server 120 obtains the encryption key value through power operation (that is, taking the key value as the encryption object as the exponent and the middle identifier as the encryption parameter as the base), in operation S603, the logarithm with the product of the encryption key values corresponding to the N target middle identifiers as the true number and the product of the N target middle identifiers as the base can be solved (for example, vi = log (D11i*D12i*D13i) (C11i * C12i * C13i)) to decrypt and obtain the key value of the target query object. Another example is that when the first operation rule is multiplication and the data server 120 obtains the encryption key value by multiplying the middle identifier and the corresponding key value, in operation S603, the multiplication of the encryption key values corresponding to the N target middle identifiers can be performed and then the Nth root can be taken to decrypt and obtain the key value of the target query object. Specific examples of decryption can refer to the previous examples and will not be listed here.
[0161] It can be seen that according to the embodiments of the present disclosure, the data query end 110 can hide the information of the target query object to be queried by the data query end 110 by decomposing the digital identifier of the target query object into sub-digital identifiers and sending the sub-data identifiers to the data server 120 for query.
[0162] Moreover, in the network link between the data server 120 and the data query end 110, even if one or more of the sub - digital identifiers are leaked, or the data in the calculation result set returned to the data query end 110 is leaked, it is difficult for the outside world to reverse - infer the target query object based on this leaked information. And since the key values in the calculation result set are encrypted key values, even if they are intercepted or leaked during network transmission, no real information of any query object can be leaked. Compared with the traditional encryption - transmission method between the data server 120 and the data query end 110, it can better conceal the information of the queried object.
[0163] According to the data query method based on hidden query of the embodiments of the present disclosure, when the data query end 110 is an organization such as an enterprise, and the data server 120 is a public utility such as an electricity, heat, water, or gas data provider, or a credit rating agency, or a data think tank in various industries, etc., it can be used for the daily business risk control of enterprises. For example, a financial institution queries the electricity, heat, water, or gas data of a customer to evaluate the business status of its enterprise customers and conduct marketing risk control. Or, an enterprise can query the credit certification information, credit rating information, etc. of its customers or potential customers from a third - party certification agency to better evaluate the true status of its customers or potential customers, etc. Moreover, applying the data query method of the embodiments of the present disclosure will not disclose the query purpose of the querier, nor will it disclose the information of the queried object. While meeting the needs of enterprises and organizations such as marketing risk control, it can also avoid the adverse effects caused by data leakage to all parties.
[0164] In view of this, the embodiments of the present disclosure also provide a risk control method based on hidden query. The following will be combined with Figures 7 to 13 , taking a financial institution as the data query end 110 as an example, to exemplarily illustrate this risk control method. It should be noted that the data query method and device determined by the embodiments of the present disclosure can be used in the financial field, and can also be used in any field other than the financial field. The present disclosure does not limit the application field.
[0165] Figure 7 Schematically shows the system architecture of the risk control method according to an embodiment of the present disclosure.
[0166] Reference Figure 7, the business situation of an enterprise can be reflected by its electricity, water, gas, and heat consumption. The marketing risk control business of financial institutions for corporate customers needs to evaluate the business situation of the enterprise in the form of corporate customer scores. Among them, financial institutions can evaluate the business situation of an enterprise from its electricity, water, gas, and heat consumption. In the prior art, when financial institutions obtain the electricity, water, gas, and heat consumption of an enterprise from power enterprises, water supply enterprises, gas enterprises, and heat enterprises, they either directly obtain the data of corporate customers from the corresponding public utilities such as power, water, gas, and heat, or establish a connection with a communication operator through traditional cryptographic techniques to encrypt and transmit the data of corporate customers. However, directly transmitting the data of corporate customers not only poses a significant risk of data leakage in the data transmission link, but also the staff of public utilities may know which corporate customer is being queried, which may also have an adverse impact on financial institutions, corporate customers, and public utilities. Through traditional cryptographic techniques, it is mainly possible to effectively reduce the risk of leakage during data transmission, but the staff of public utilities also have the opportunity to know which corporate customer is being queried. Different from the prior art, the method of the embodiment of the present disclosure can use a financial institution as the data query end 110 and any one of power enterprises, water supply enterprises, gas enterprises, or heat enterprises as the data service end 120. Through the method of concealed query, it helps financial institutions achieve the purpose of risk control, while greatly reducing the possibility that the information of the queried corporate customer is known to the outside world.
[0167] Figure 8 Schematically shows a flowchart of a risk control method according to an embodiment of the present disclosure.
[0168] As Figure 8 shown, the risk control method according to this embodiment may include operation S810 to operation S880.
[0169] In operation S810, obtain the digital identifiers of M customers of the first business entity, where M is an integer greater than or equal to 1, and the M customers include the target customer. In Figure 7 the architecture, the first business entity is the financial institution.
[0170] In operation S820, decompose the digital identifier of each customer based on the first algorithm to obtain N sub-digital identifiers corresponding to each customer; among them, a total of M * N sub-digital identifiers are obtained corresponding to the M customers, where N is an odd number greater than or equal to 3;
[0171] Figure 9 Schematically shows a schematic diagram of the first business entity decomposing sub-digital identifiers from the digital identifiers of multiple customers in the risk control method according to an embodiment of the present disclosure.
[0172] For example, a financial institution can combine the digital identifier A1 of the enterprise to be queried (i.e., the target customer) with the digital identifiers A2 and A3 of multiple enterprises randomly selected from enterprise information to form an enterprise identifier group {A1, A2, A3}. The identifiers of the multiple randomly selected enterprises are used to obfuscate the query purpose and hide the digital identifier A1 of the target enterprise.
[0173] N sub-digital identifiers can be decomposed from the digital identifier of each enterprise in the enterprise identifier group {A1, A2, A3}. As Figure 9 shown, A1 is decomposed into {A11, A12, A13}, A2 is decomposed into {A21, A22, A23}, and A3 is decomposed into {A31, A32, A33}. The process of decomposing sub-digital identifiers in operation S820 can refer to the relevant introductions in the previous operations S520 and S410.
[0174] In operation S830, the N sub-digital identifiers corresponding to each customer are divided into a first category and a second category. Among them, for each customer, the first category includes [(N - 1) / 2] + 1 sub-digital identifiers, and the second category includes (N - 1) / 2 sub-digital identifiers. Specifically, it can refer to the relevant introductions in the previous operations S530 and S410.
[0175] In operation S840, the M * N sub-digital identifiers and the classification information of each sub-digital identifier are sent to each of the R second business entities to request each second business entity to perform data queries, where R is an integer greater than or equal to 1. In Figure 7 the architecture, the second business entity can be any one of an electric power enterprise, a water supply enterprise, a gas enterprise, and a heat supply enterprise. The R second business entities can be one or more or all of an electric power enterprise, a water supply enterprise, a gas enterprise, and a heat supply enterprise, which are set according to the analysis needs of the financial institution.
[0176] When sending M*N sub-digital identifiers and the classification information of each sub-digital identifier to the second business entity, it can be achieved in various ways; in one embodiment, the M*N sub-digital identifiers can be sent in batches according to the classification information, where the classification information of each sub-digital identifier is determined according to the sending batch. For example, each batch sends sub-digital identifiers belonging to the same category, and the order of the sub-digital identifiers can be disrupted within each batch, and there can be a long time interval between different batches, etc., increasing the difficulty for the outside world to reverse-infer the information of the query object after intercepting the transmitted data; in another embodiment, the classification information of each sub-digital identifier can be marked, and the M*N sub-digital identifiers are sent after being disrupted in order; in still other embodiments, the M*N sub-digital identifiers can be arranged in a specific order, and the classification information of each sub-digital identifier is identified through the position information of each sub-digital identifier; for example, the M*N sub-digital identifiers can be arranged in one or more sequences, and those with odd position information in each sequence are determined as the first category, and those with even position information are determined as the second category, where the order within each category can be disrupted at will for sending. According to the embodiments of the present disclosure, operation S840 can, through the setting of the sending method, on the one hand, achieve the transmission of the classification information of each sub-digital identifier, and on the other hand, can also hide the information of the further target query object.
[0177] In this embodiment, the second business entity acts as the data server 120 and can execute the data query method applied to the data server 120 described above, perform data query according to the received sub-digital identifiers and the classification information of each sub-digital identifier, obtain the calculation result group of each sub-digital identifier and return it to the data query end 110.
[0178] In operation S850, receive the M*N calculation result groups returned by the second business entity that correspond one-to-one to the M*N sub-digital identifiers.
[0179] In operation S860, select N calculation result groups corresponding to the N sub-digital identifiers of the target customer from the M*N calculation result groups. Among them, the selected N calculation result groups are used as the N target calculation result groups. For example, in combination with Figure 9 and Figure 3 's example, select the calculation result groups [D, C] 11 , [D, C] 12 and [D, C] 13 corresponding to A11, A12, and A13 from the 3*3 calculation result groups.
[0180] In operation S870, based on the N target calculation result groups, reverse-solve the key value of the target customer recorded in the second business entity. The principle of the reverse-solving process refers to the introduction above, and one implementation manner of the reverse-solving process can refer to Figure 6 's related introduction.
[0181] In operation S880, based on the key values of the target customers recorded in the R second business entities, the business risks of the target customers are evaluated.
[0182] For example, when R = 1 and the second business entity is an electric power enterprise, the business risks of the target customers can be evaluated according to the power consumption data of the target customers (for example, power consumption scores). For example, the power consumption data of the target customers is compared with the power consumption data of the same industry, or the power consumption data of the target customers is compared with the power consumption data in the same period in the past, to determine whether there are any abnormal operations of the target customers.
[0183] For another example, when R is greater than 1, the key values of the target customers recorded in the R second business entities can be weighted to obtain the comprehensive score of the target customers.
[0184] Figures 10 to 13 Schematically show the internal structures and interaction processes between financial institutions and electric power enterprises, water supply enterprises, gas enterprises, and heating enterprises in the risk control method.
[0185] Specifically, Figure 10 Schematically shows the interaction schematic between a financial institution and an electric power enterprise in the risk control method according to an embodiment of the present disclosure.
[0186] As Figure 10 shown, an enterprise information analysis module 001 is provided in the financial institution, and the enterprise information analysis module 001 may include an enterprise preprocessing sub-module 101, an enterprise information separation sub-module 102, a result processing sub-module 103, and a result summary sub-module 104.
[0187] An electric power enterprise verification module 002 may be provided in the electric power enterprise. The electric power enterprise verification module 002 may include an electric power enterprise information analysis sub-module 201 and an electric power verification calculation sub-module 202.
[0188] The enterprise preprocessing sub-module 101 may combine the digital identifier of the enterprise to be queried with the digital identifiers of multiple enterprises randomly selected from the enterprise information into an enterprise identifier group, such as Figure 9 shown {A1, A2, A3}.
[0189] The enterprise information separation sub-module 102 decomposes the digital identifier of each enterprise in the enterprise identifier group into N sub-digital identifiers to form an enterprise sub-digital identifier group {A11, A12, A13, A21, A22, A23, A31, A32, A33}, where it may be in a determined order, or when sending to the power company, the data is divided into two categories. The first category is the sub-digital identifiers with an odd second subscript, and the second category is the sub-digital identifiers with an even second subscript.), and sent to the power verification calculation sub-module 202 of the power company,
[0190] In the power enterprise information analysis sub-module 201 of the power company, information is stored in the form of [KEY, VALUE] of the enterprise's digital identifier and the enterprise's power score. For example, in combination with Figure 3 {[B1, v1], [B2, v2], [B3, v3], [B4, v4]}. The power score value of the enterprise can be the statistical data of the enterprise's electricity consumption, or the power company's evaluation score of the enterprise's electricity consumption level, etc.
[0191] The power verification calculation sub-module 202 receives the enterprise sub-digital identifier group, and performs a hidden query calculation on each sub-digital identifier and each item {B1, B2, B3, B4} of the enterprise's digital identifier score list. For specific reference, see the detailed introduction of the hidden query process in Figure 4 previously.
[0192] Next, the result processing sub-module 103 of the financial institution receives the calculation result group, and extracts [D, C] corresponding to A11, A12, and A13 11 , [D, C] 12 and [D, C] 13 .
[0193] The result processing sub-module 103 of the financial institution extracts the calculation results where D11i + D12i + D13i is a predetermined value from [D, C] 11 , [D, C] 12 and [D, C] 13 returned by the power enterprise.
[0194] The result processing sub-module 103 of the financial institution obtains the corresponding calculation result group: [D11i, C11i], [D12i, C12i], [D13i, C13i], decrypts the power score using C11i, C12i, and C13i through the decryption algorithm, and sends the power score to the result summary sub-module 104.
[0195] Figure 11 Schematically shows the interaction schematic between the financial institution and the water service enterprise in the risk control method according to an embodiment of the present disclosure.
[0196] As Figure 11 shown, a water service enterprise verification module 003 is provided in the water service enterprise. The water service enterprise verification module 003 may include a water service enterprise information analysis sub-module 301 and a water service verification calculation sub-module 302.
[0197] In the water service enterprise information analysis sub-module 301, information is stored in the form of [KEY, VALUE] of the enterprise's digital identifier and the enterprise's water service score.
[0198] The water service verification calculation sub-module 302 receives the enterprise sub-digital identification group sent by the enterprise information separation sub-module 102 in the financial institution, and executes the reference Figure 4 The described hidden query method to obtain the calculation result group corresponding to each sub-digital identification in the enterprise sub-digital identification group, and then send it to the overall result processing sub-module 103 of the financial institution.
[0199] The result processing sub-module 103 of the financial institution reverse-solves the water service score of the queried enterprise A1 from the received calculation result group, and sends the water service score of A1 to the result summary sub-module 104. The water service score value of an enterprise can be the statistical data of the enterprise's water consumption, or the score given by the water service company to the enterprise's water use level, etc.
[0200] Figure 12 Schematically shows the interaction schematic between the financial institution and the gas enterprise in the risk control method according to an embodiment of the present disclosure.
[0201] As Figure 12 shown, a gas enterprise verification module 004 is provided in the gas enterprise. The gas enterprise verification module 004 may include a gas enterprise information analysis sub-module 401 and a gas verification calculation sub-module 402.
[0202] The gas enterprise information analysis sub-module 401 stores information in the form of [KEY, VALUE] of the enterprise's digital identification and the enterprise's gas score.
[0203] The gas verification calculation sub-module 402 receives the enterprise sub-digital identification group sent by the enterprise information separation sub-module 102 in the financial institution, and executes the reference Figure 4 The described hidden query method to obtain the calculation result group corresponding to each sub-digital identification in the enterprise sub-digital identification group, and then send it to the result processing sub-module 103 in the financial institution.
[0204] The result processing sub-module 103 of the financial institution reverse-solves the gas score of the queried enterprise A1 from the received calculation result group, and sends the gas score of A1 to the result summary sub-module 104. The gas score value of an enterprise can be the statistical data of the enterprise's gas consumption, or the score given by the water service company to the enterprise's gas use level, etc.
[0205] Figure 13 Schematically shows the interaction schematic between the financial institution and the heating enterprise in the risk control method according to an embodiment of the present disclosure.
[0206] As Figure 13 shown, a heating enterprise verification module 05 is provided in the heating enterprise. The heating enterprise verification module 005 may include a heating enterprise information analysis sub-module 501 and a heating verification calculation sub-module 502.
[0207] In the thermal enterprise information analysis sub-module 501, information is stored in the form of [KEY, VALUE] of the digital identifier of the enterprise and the enterprise's thermal score.
[0208] The thermal verification calculation sub-module 502 receives the group of enterprise sub-digital identifiers sent by the enterprise information separation sub-module 102 in the financial institution, and executes the Figure 4 described concealed query method, obtains the calculation result group corresponding to each sub-digital identifier in the group of enterprise sub-digital identifiers, and then sends it to the result processing sub-module 103 of the financial institution in total.
[0209] The result processing sub-module 103 of the financial institution reversely solves the thermal score of the queried enterprise A1 from the received calculation result group, and sends the thermal score of A1 to the result summarization sub-module 104. The thermal score value of the enterprise can be the statistical data of the enterprise's thermal consumption, or the score given by the thermal company to the enterprise's thermal consumption level, etc.
[0210] The result summarization sub-module 104 can summarize the electricity score, water score, gas score and thermal score of the queried enterprise A1, and the four scores can be calculated with a certain weight. For example, electricity score: water score: gas score: thermal score = 4:3:2:1, that is, the comprehensive score of the queried enterprise = electricity score * 0.4 + water score * 0.3 + gas score * 0.2 + thermal score * 0.1, and the comprehensive score is used for the marketing risk control business of the financial institution.
[0211] According to the embodiments of the present disclosure, the financial institution can utilize the data such as electricity, water, gas and heat of the queried enterprise from public utility units such as power, water, gas and heat, and summarize and integrate them into an enterprise customer score as the basis for the financial institution to conduct marketing and risk control for the enterprise.
[0212] During the query process, the financial institution can process the digital identifier of the enterprise through the concealed query technology, and query the data such as electricity, water, gas and heat consumption of the queried enterprise from public utility units such as power, water, gas and heat. The concealed query method enables each link and its handlers including the financial institution and public utility units not to know which enterprise is being queried during the query process, and even if the data transmitted during the query process is stolen, it is impossible to know which enterprise is being queried, thereby reducing the risk of leaking the customer information of the financial institution. Thus, the financial institution can obtain public utility units such as power, water, gas and heat for risk control without disclosing the information privacy of its enterprise customers. Moreover, due to enhancing the data privacy and security of the financial institution and public utility units, the willingness of cooperation of public utility units can be improved.
[0213] Figure 14A block diagram of a data query device 1400 provided in a data server 120 according to an embodiment of the present disclosure is schematically shown.
[0214] As Figure 14 shown, the data query device 1400 may include a first receiving module 1410, a first query module 1420, and a first return module 1430.
[0215] The first receiving module 1410 is configured to receive a query request, where the query request includes a first sub - digital identifier and classification information of the first sub - digital identifier; wherein, the first sub - digital identifier is any one of N sub - digital identifiers obtained by decomposing the digital identifier of a target query object based on a first operation rule, where N is an odd number greater than or equal to 3; the N sub - digital identifiers are divided into a first category and a second category, where the first category includes [(N - 1) / 2]+1 sub - digital identifiers, and the second category includes (N - 1) / 2 sub - digital identifiers; the classification information of the first sub - digital identifier is used to indicate whether the first sub - digital identifier belongs to the first category or the second category; the first operation rule has the commutative law and the associative law. In one embodiment, the first receiving module 1410 may be configured to perform the operation S410 described above.
[0216] The first query module 1420 is configured to obtain a calculation result set corresponding to the first sub - digital identifier by querying the records of S objects in the following processing manner; wherein, the records of the S objects include the digital identifiers and key values of the S objects, S is an integer greater than 1, and the S objects include the target query object. In one embodiment, the first query module 1420 may be configured to perform the operation S420 and the operation S430 described above.
[0217] Specifically, the first query module 1420 may be further configured to include a first query operation sub - module 1421 and a first query encryption sub - module 1422.
[0218] The first query operation sub - module 1421 is configured to perform an operation on the digital identifier of each of the S objects by using the first sub - digital identifier based on an operation rule corresponding to the classification information of the first sub - digital identifier to obtain S intermediate identifiers; wherein, the operation rule corresponding to the first category is the inverse operation of the first operation rule, and the operation rule corresponding to the second category is the first operation rule. The first query operation sub - module 1421 may perform the operation S420 described above.
[0219] The first query encryption sub-module 1422 is used to use each intermediate identifier as an encryption parameter, use the key values of the objects participating in the calculation of the intermediate identifier among the S objects as the encryption objects, and obtain the encrypted key values corresponding to each intermediate identifier through homomorphic encryption; wherein, the S intermediate identifiers and the encrypted key values corresponding to each intermediate identifier are represented in the form of key-value pairs to obtain the calculation result group corresponding to the first sub-digital identifier. The first query encryption sub-module 1422 can perform the operation S430 described above.
[0220] The first return module 1430 is used to feedback the calculation result group corresponding to the first sub-digital identifier to the data query end 110 that issues the query request. Among them, after the data query end 110 obtains the N calculation result groups corresponding to the N sub-digital identifiers one by one, it reverse-decodes the key value corresponding to the target query object based on the N calculation result groups. In one embodiment, the first return module 1430 can perform the operation S440 described above.
[0221] This data query device 1400 can execute the Figure 4 data query method described in the reference. The specific content of the operations that each module can perform can refer to the description above, and will not be elaborated here.
[0222] According to an embodiment of the present disclosure, any multiple of the first receiving module 1410, the first query module 1420, and the first return module 1430 can be combined and implemented in one module, or any one of them can be split into multiple modules. Or, at least part of the functions of one or more of these modules can be combined with at least part of the functions of other modules and implemented in one module. According to an embodiment of the present disclosure, at least one of the first receiving module 1410, the first query module 1420, and the first return module 1430 can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on substrate, a system on package, an application specific integrated circuit (ASIC), or can be implemented by any other reasonable way of integrating or packaging circuits, etc., in hardware or firmware, or implemented in any one of the three implementation methods of software, hardware, and firmware, or in any appropriate combination of them. Or, at least one of the first receiving module 1410, the first query module 1420, and the first return module 1430 can be at least partially implemented as a computer program module, and when the computer program module is run, it can execute the corresponding functions.
[0223] Figure 15 A block diagram of a data query device 1500 provided at the data query end 110 according to an embodiment of the present disclosure is schematically shown.
[0224] As Figure 15As shown, the data query device 1500 may include a second acquisition module 1510, a second decomposition module 1520, a second classification module 1530, a second request sending module 1540, a second result receiving module 1550, and a second data inverse solution module 1560.
[0225] The second acquisition module 1510 is used to acquire the digital identifier of the target query object. In one embodiment, the second acquisition module 1510 may be used to perform the operation S510 described above.
[0226] The second decomposition module 1520 is used to decompose the digital identifier of the target query object based on the first algorithm to obtain N sub-digital identifiers, where N is an odd number greater than or equal to 3. In one embodiment, the second decomposition module 1520 may be used to perform the operation S520 described above.
[0227] The second classification module 1530 is used to divide the N sub-digital identifiers into a first category and a second category, where the first category includes [(N - 1) / 2] + 1 sub-digital identifiers, and the second category includes (N - 1) / 2 sub-digital identifiers. In one embodiment, the second classification module 1530 may be used to perform the operation S530 described above.
[0228] The second request sending module 1540 is used to send the N sub-digital identifiers and the classification information of each sub-digital identifier to the data server 120 to request the data server 120 to perform a data query. In one embodiment, the second request sending module 1540 may be used to perform the operation S540 described above.
[0229] The second result receiving module 1550 is used to receive N calculation result groups returned by the data server 120 that correspond one-to-one to the N sub-digital identifiers. In one embodiment, the second result receiving module 1550 may be used to perform the operation S550 described above.
[0230] The second data inverse solution module 1560 is used to inversely solve the key value corresponding to the target query object based on the N calculation result groups. In some embodiments, the second data inverse solution module 1560 may perform the operation 560 described above.
[0231] Specifically, the second data inverse solution module 1560 may be used to: perform the following calculations in a trial-and-error manner, each time selecting an intermediate identifier from each of the N calculation result groups, and then performing an operation on the selected N intermediate identifiers according to the first algorithm to obtain a calculation result; then stop the trial-and-error when the calculation result is a predetermined value, and select the N intermediate identifiers when the calculation result is the predetermined value as the N target intermediate identifiers, and the predetermined value is a value determined by the cancellation of the first algorithm and its inverse operation; decrypt the key value of the target query object based on the encryption key values corresponding to the N target intermediate identifiers.
[0232] In some embodiments, the second data inverse solution module 1560 may further be configured to: when the homomorphic encryption is a power operation with the encrypted object as the exponent and the encryption parameter as the base, solve the logarithm with the product of the encrypted key values corresponding to N target intermediate identifiers as the true number and the product of the N target intermediate identifiers as the base, to obtain the key value of the target query object.
[0233] The data query device 1500 may execute the data query method described in the reference Figures 5 to 6 The specific content of the operations that each module can perform can refer to the previous description and will not be elaborated here.
[0234] According to embodiments of the present disclosure, any multiple of the second acquisition module 1510, the second decomposition module 1520, the second classification module 1530, the second request sending module 1540, the second result receiving module 1550, and the second data inverse solution module 1560 may be combined and implemented in one module, or any one of them may be split into multiple modules. Or, at least part of the functions of one or more of these modules may be combined with at least part of the functions of other modules and implemented in one module. According to embodiments of the present disclosure, at least one of the second acquisition module 1510, the second decomposition module 1520, the second classification module 1530, the second request sending module 1540, the second result receiving module 1550, and the second data inverse solution module 1560 may be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on substrate, a system on package, an application specific integrated circuit (ASIC), or any other reasonable manner of integrating or packaging circuits, etc., implemented by hardware or firmware, or implemented in any one of the three implementation manners of software, hardware, and firmware, or in any suitable combination of several of them. Or, at least one of the second acquisition module 1510, the second decomposition module 1520, the second classification module 1530, the second request sending module 1540, the second result receiving module 1550, and the second data inverse solution module 1560 may be at least partially implemented as a computer program module, and when the computer program module is run, it can execute the corresponding functions.
[0235] Figure 16 Schematically shows a block diagram of a risk control device 1600 based on stealth query according to an embodiment of the present disclosure.
[0236] As Figure 16As shown, the risk control device 1600 may include a third acquisition module 1610, a third decomposition module 1620, a third classification module 1630, a third sending module 1640, a third result receiving module 1650, a third selection module 1660, a third data inverse decomposition module 1670, and a third evaluation module 1680.
[0237] The third acquisition module 1610 is configured to acquire digital identifiers of M customers of a first business entity, where M is an integer greater than or equal to 1, and the M customers include target customers. In one embodiment, the third acquisition module 1610 may be configured to perform the operation S810 described above.
[0238] The third decomposition module 1620 is configured to decompose the digital identifier of each customer based on a first algorithm to obtain N sub-digital identifiers corresponding to each customer; where, corresponding to the M customers, a total of M * N sub-digital identifiers are obtained; where N is an odd number greater than or equal to 3. In one embodiment, the third decomposition module 1620 may be configured to perform the operation S820 described above.
[0239] The third classification module 1630 is configured to divide the N sub-digital identifiers corresponding to each customer into a first category and a second category; where, for each customer, the first category includes [(N - 1) / 2] + 1 sub-digital identifiers, and the second category includes (N - 1) / 2 sub-digital identifiers. In one embodiment, the third classification module 1630 may be configured to perform the operation S830 described above.
[0240] The third sending module 1640 is configured to send the M * N sub-digital identifiers and the classification information of each sub-digital identifier to R second business entities, where R is an integer greater than or equal to 1. Each second business entity may serve as a data server and is provided with the data query device 1400 as introduced above. In one embodiment, the third sending module 1640 may be configured to perform the operation S840 described above.
[0241] Specifically, the third sending module 1640 may send the M * N sub-digital identifiers and the classification information of each sub-digital identifier in any of the following ways: sending the M * N sub-digital identifiers in batches according to the classification information, where the classification information of each sub-digital identifier is determined according to the sending batch; marking the classification information of each sub-digital identifier and sending the M * N sub-digital identifiers after scrambling the order; or arranging the M * N sub-digital identifiers in a specific order and identifying the classification information of each sub-digital identifier through the position information of each sub-digital identifier.
[0242] The third result receiving module 1650 is configured to receive M*N calculation result groups corresponding one by one to M*N sub-digital identifiers returned by each second business entity. In one embodiment, the third result receiving module 1650 may perform the operation S850 described above.
[0243] The third selection module 1660 is configured to select N calculation result groups corresponding to the N sub-digital identifiers of the target customer from the M*N calculation result groups; wherein, the selected N calculation result groups are used as N target calculation result groups. In one embodiment, the third selection module 1660 may perform the operation S860 described above.
[0244] The third data inverse solution module 1670 is configured to inverse-solve the key value of the target customer recorded in the second business entity based on the N target calculation result groups. In one embodiment, the third data inverse solution module 1670 may perform the operation S870 described above.
[0245] The third evaluation module 1680 is configured to evaluate the business risk of the target customer based on the key values of the target customer recorded in R of the second business entities. In one embodiment, the third evaluation module 1680 may be used to perform the operation S880 described above. Specifically, when R is greater than 1, the third evaluation module 1680 may be used to perform weighted processing on the key values of the target customer recorded in R of the second business entities to obtain a comprehensive score of the target customer.
[0246] The risk control device 1600 may be disposed in the first business entity, and the first business entity may be, for example, a financial institution 101 serving as a data query end. Thus, in one embodiment, the risk control device 1600 may be used to perform the risk control method described with reference to the foregoing Figures 7 to 13 The specific content may refer to the foregoing introduction and will not be elaborated herein.
[0247] According to an embodiment of the present disclosure, any plurality of modules among the third acquisition module 1610, the third decomposition module 1620, the third classification module 1630, the third sending module 1640, the third result receiving module 1650, the third selection module 1660, the third data inverse resolution module 1670, and the third evaluation module 1680 may be combined and implemented in one module, or any one of them may be split into multiple modules. Alternatively, at least part of the functions of one or more of these modules may be combined with at least part of the functions of other modules and implemented in one module. According to an embodiment of the present disclosure, at least one of the third acquisition module 1610, the third decomposition module 1620, the third classification module 1630, the third sending module 1640, the third result receiving module 1650, the third selection module 1660, the third data inverse resolution module 1670, and the third evaluation module 1680 may be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on a substrate, a system on a package, an application specific integrated circuit (ASIC), or may be implemented by any other reasonable means such as integrating or packaging circuits, etc., in hardware or firmware, or implemented in any one of the three implementation manners of software, hardware, and firmware, or in an appropriate combination of any several of them. Alternatively, at least one of the third acquisition module 1610, the third decomposition module 1620, the third classification module 1630, the third sending module 1640, the third result receiving module 1650, the third selection module 1660, the third data inverse resolution module 1670, and the third evaluation module 1680 may be at least partially implemented as a computer program module, and when the computer program module is run, it can execute corresponding functions.
[0248] Figure 17 FIG. schematically shows a block diagram of an electronic device suitable for a data query method or a risk control method based on a stealth query according to an embodiment of the present disclosure.
[0249] As Figure 17 shown, the electronic device 1700 according to an embodiment of the present disclosure includes a processor 1701, which can perform various appropriate actions and processes according to a program stored in a read only memory (ROM) 1702 or a program loaded from a storage section 1708 into a random access memory (RAM) 1703. The processor 1701 may include, for example, a general microprocessor (such as a CPU), an instruction set processor, and / or a related chipset, and / or a dedicated microprocessor (such as an application specific integrated circuit (ASIC)), etc. The processor 1701 may also include on-board memory for caching purposes. The processor 1701 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.
[0250] In the RAM 1703, various programs and data required for the operation of the electronic device 1700 are stored. The processor 1701, the ROM 1702, and the RAM 1703 are connected to each other via a bus 1704. The processor 1701 performs various operations of the method flow according to the embodiments of the present disclosure by executing programs in the ROM 1702 and / or the RAM 1703. It should be noted that the programs may also be stored in one or more memories other than the ROM 1702 and the RAM 1703. The processor 1701 may also perform various operations of the method flow according to the embodiments of the present disclosure by executing programs stored in the one or more memories.
[0251] According to an embodiment of the present disclosure, the electronic device 1700 may further include an input / output (I / O) interface 1705, and the input / output (I / O) interface 1705 is also connected to the bus 1704. The electronic device 1700 may further include one or more of the following components connected to the I / O interface 1705: an input portion 1706 including a keyboard, a mouse, etc.; an output portion 1707 including, for example, a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage portion 1708 including a hard disk, etc.; and a communication portion 1709 including a network interface card such as a LAN card, a modem, etc. The communication portion 1709 performs communication processing via a network such as the Internet. A drive 1710 is also connected to the I / O interface 1705 as needed. A removable medium 1711, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 1710 as needed so that a computer program read from it can be installed into the storage portion 1708 as needed.
[0252] The present disclosure also provides a computer-readable storage medium, which may be included in the device / device / system described in the above embodiments; or may exist separately without being assembled into the device / device / system. The above computer-readable storage medium carries one or more programs, and when the one or more programs are executed, a data query method or a risk control method according to the embodiments of the present disclosure is implemented.
[0253] According to an embodiment of the present disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, which may include, for example, but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In the present disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present disclosure, the computer-readable storage medium may include the ROM 1702 and / or RAM 1703 described above and / or one or more memories other than ROM 1702 and RAM 1703.
[0254] An embodiment of the present disclosure also includes a computer program product, which includes a computer program that contains program code for executing the method shown in the flowchart. When the computer program product runs in a computer system, the program code is used to enable the computer system to implement the data query method or risk control method provided by the embodiments of the present disclosure.
[0255] When the computer program is executed by the processor 1701, it executes the above functions defined in the system / apparatus of the embodiments of the present disclosure. According to an embodiment of the present disclosure, the above-described systems, apparatuses, modules, units, etc. can be implemented by computer program modules.
[0256] In one embodiment, the computer program may rely on tangible storage media such as optical storage devices and magnetic storage devices. In another embodiment, the computer program may also be transmitted and distributed in the form of a signal on a network medium and downloaded and installed through the communication part 1709, and / or installed from the removable medium 1711. The program code contained in the computer program can be transmitted by any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.
[0257] In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 1709, and / or installed from the removable medium 1711. When the computer program is executed by the processor 1701, it executes the above functions defined in the system of the embodiments of the present disclosure. According to an embodiment of the present disclosure, the above-described systems, devices, apparatuses, modules, units, etc. can be implemented by computer program modules.
[0258] According to embodiments of the present disclosure, program code for executing the computer programs provided by the embodiments of the present disclosure can be written in any combination of one or more programming languages. Specifically, these computing programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, such as Java, C++, Python, the "C" language, or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device can be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, by using an Internet service provider to connect through the Internet).
[0259] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks can occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and combinations of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0260] Those skilled in the art can understand that the features recited in the various embodiments and / or claims of the present disclosure can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly recited in the present disclosure. In particular, without departing from the spirit and teachings of the present disclosure, the features recited in the various embodiments and / or claims of the present disclosure can be combined and / or combined in various ways. All such combinations and / or combinations fall within the scope of the present disclosure.
[0261] The embodiments of the present disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present disclosure. Although the embodiments have been described separately above, this does not mean that the measures in each embodiment cannot be used advantageously in combination. The scope of the present disclosure is defined by the appended claims and their equivalents. Without departing from the scope of the present disclosure, those skilled in the art can make various substitutions and modifications, and all such substitutions and modifications should fall within the scope of the present disclosure.
Claims
1. A data query method based on stealth query, applied to a data server, comprising: Receiving a query request, where the query request includes a first sub - digital identifier and classification information of the first sub - digital identifier; wherein, the first sub - digital identifier is any one of N sub - digital identifiers obtained by decomposing the digital identifier of a target query object based on a first algorithm rule, where N is an odd number greater than or equal to 3; the N sub - digital identifiers are divided into a first category and a second category, where the first category includes [(N - 1) / 2]+1 sub - digital identifiers, and the second category includes (N - 1) / 2 sub - digital identifiers; the classification information of the first sub - digital identifier is used to indicate whether the first sub - digital identifier belongs to the first category or the second category; the first algorithm rule has the commutative law and the associative law; By querying the records of S objects, obtaining a calculation result group corresponding to the first sub - digital identifier according to the following processing method; wherein, the records of the S objects include the digital identifiers and key values of the S objects, S is an integer greater than 1, and the S objects include the target query object; the processing method includes: Performing an operation on the digital identifier of each of the S objects by using the first sub - digital identifier based on an algorithm rule corresponding to the classification information of the first sub - digital identifier, to obtain S intermediate identifiers; wherein, the algorithm rule corresponding to the first category is the inverse operation of the first algorithm rule, and the algorithm rule corresponding to the second category is the first algorithm rule; and Taking each intermediate identifier as an encryption parameter, taking the key value of the object participating in the calculation of this intermediate identifier among the S objects as an encryption object, and obtaining an encrypted key value corresponding to each intermediate identifier through homomorphic encryption; wherein, representing the S intermediate identifiers and the encrypted key value corresponding to each intermediate identifier in the form of a key - value pair, to obtain the calculation result group corresponding to the first sub - digital identifier; Feeding back the calculation result group corresponding to the first sub - digital identifier to the data query end that issues the query request; wherein, after the data query end obtains N calculation result groups corresponding to the N sub - digital identifiers one by one, it inversely solves the key value corresponding to the target query object based on the N calculation result groups.
2. The method according to claim 1, wherein the first algorithm rule includes an addition operation.
3. The method according to claim 2, wherein, the homomorphic encryption includes: A power operation with the encryption object as the exponent and the encryption parameter as the base.
4. A data query method based on stealth query, applied to a data query end, comprising: Obtaining the digital identifier of a target query object; Decomposing the digital identifier of the target query object based on a first algorithm rule to obtain N sub - digital identifiers, where N is an odd number greater than or equal to 3; Dividing the N sub - digital identifiers into a first category and a second category, where the first category includes [(N - 1) / 2]+1 sub - digital identifiers, and the second category includes (N - 1) / 2 sub - digital identifiers; Send the N sub - digital identifiers and the classification information of each sub - digital identifier to the data server to request the data server to perform data query according to the method described in Claim 1; Receive N calculation result groups returned by the data server that correspond one - to - one with the N sub - digital identifiers; and Based on the N calculation result groups, reverse - solve the key value corresponding to the target query object.
5. According to the method described in Claim 4, wherein, The reverse - solving the key value corresponding to the target query object based on the N calculation result groups includes: Performing the following calculations in a trial - calculation manner: Each time, select one intermediate identifier from each of the N calculation result groups, and then perform operations on the selected N intermediate identifiers according to the first operation rule to obtain a calculation result; Stop the trial - calculation when the calculation result is a predetermined value, and select the N intermediate identifiers when the calculation result is the predetermined value as the N target intermediate identifiers; the predetermined value is a value determined by the cancellation of the first operation rule and its inverse operation; and Based on the encrypted key values corresponding to the N target intermediate identifiers, decrypt the key value of the target query object.
6. According to the method described in Claim 5, wherein, The first operation rule is addition, and the predetermined value is zero.
7. According to the method described in Claim 6, wherein, The decrypting the key value of the target query object based on the encrypted key values corresponding to the N target intermediate identifiers includes: When the homomorphic encryption is a power operation with the encrypted object as the exponent and the encrypted parameter as the base, solve the logarithm with the product of the encrypted key values corresponding to the N target intermediate identifiers as the true number and the product of the N target intermediate identifiers as the base to obtain the key value of the target query object.
8. A risk control method based on concealed query, applied to a first business entity, including: Obtain the digital identifiers of M customers of the first business entity, where M is an integer greater than or equal to 1, and the M customers include the target customer; Decompose the digital identifier of each customer based on the first operation rule to obtain N sub - digital identifiers corresponding to each customer; in total, M * N sub - digital identifiers are obtained corresponding to the M customers; where N is an odd number greater than or equal to 3; Divide the N sub - digital identifiers corresponding to each customer into a first category and a second category; for each customer, the first category includes [(N - 1) / 2]+1 sub - digital identifiers, and the second category includes (N - 1) / 2 sub - digital identifiers; Send the M * N sub - digital identifiers and the classification information of each sub - digital identifier to each of the R second business entities, to request each of the second business entities to perform data query according to the method described in Claim 1, where R is an integer greater than or equal to 1; Receive M * N calculation result groups returned by the second business entity that correspond one - to - one with the M * N sub - digital identifiers; Select N calculation result groups corresponding to the N sub - digital identifiers of the target customer from the M * N calculation result groups; wherein, the selected N calculation result groups are used as N target calculation result groups; Based on the N target calculation result groups, reverse - solve the key value of the target customer recorded in the second business entity; and Based on the key values of the target customer recorded in R second business entities, evaluate the business risk of the target customer.
9. The method according to claim 8, wherein, The reverse - solving the key value of the target customer recorded in the second business entity based on the N target calculation result groups includes: Perform the following calculations in a trial - and - error manner: Each time, select an intermediate identifier from each of the N target calculation result groups, and then perform operations on the selected N intermediate identifiers according to the first operation rule to obtain a calculation result; Stop the trial - and - error when the calculation result is a predetermined value, and select the N intermediate identifiers when the calculation result is a fixed value as N target intermediate identifiers; the predetermined value is a value determined by the cancellation of the first operation rule and its inverse operation; Based on the encrypted key values corresponding to the N target intermediate identifiers, decrypt the key value of the target customer.
10. The method according to claim 9, wherein, The first operation rule is addition, and the predetermined value is zero.
11. The method according to claim 10, wherein, The decrypting the key value of the target customer based on the encrypted key values corresponding to the N target intermediate identifiers includes: When the homomorphic encryption is a power operation with the encrypted object as the exponent and the encrypted parameter as the base, solve the logarithm with the product of the encrypted key values corresponding to the N target intermediate identifiers as the true number and the product of the N target intermediate identifiers as the base to obtain the key value of the target customer.
12. The method according to claim 8, wherein, The sending the M * N sub - digital identifiers and the classification information of each sub - digital identifier to each of the R second business entities includes sending in any of the following ways: Send the M * N sub - digital identifiers in batches according to the classification information, wherein the classification information of each sub - digital identifier is determined according to the sending batch; Mark the classification information of each sub - digital identifier and send the M * N sub - digital identifiers after scrambling the order; or Arrange the M * N sub - digital identifiers in a specific order, and identify the classification information of each sub - digital identifier through the position information of each sub - digital identifier.
13. The method according to claim 8, wherein, When R is greater than 1, the evaluating the business risk of the target customer based on the key values of the target customer recorded in R second business entities includes: Perform weighted processing on the key values of the target customer recorded in R second business entities to obtain the comprehensive score of the target customer.
14. The method according to claim 8, wherein, The first business entity includes a financial institution; and The R second business entities include at least one of an electric power enterprise, a water supply enterprise, a heat supply enterprise, or a gas enterprise.
15. A data query device based on stealth query, which is set in a data server, comprising: A first receiving module, configured to receive a query request, where the query request includes a first sub-digital identifier and classification information of the first sub-digital identifier; wherein, the first sub-digital identifier is any one of N sub-digital identifiers obtained by decomposing the digital identifier of a target query object based on a first algorithm, where N is an odd number greater than or equal to 3; the N sub-digital identifiers are divided into a first category and a second category, where the first category includes [(N - 1) / 2] + 1 sub-digital identifiers, and the second category includes (N - 1) / 2 sub-digital identifiers; the classification information of the first sub-digital identifier is used to indicate whether the first sub-digital identifier belongs to the first category or the second category; the first algorithm has the commutative law and the associative law; A first query module, configured to obtain a calculation result group corresponding to the first sub-digital identifier by querying the records of S objects according to the following processing method; wherein, the records of the S objects include the digital identifiers and key values of the S objects, S is an integer greater than 1, and the S objects include the target query object; the first query module specifically includes: A first query operation sub-module, configured to perform an operation on the digital identifier of each of the S objects by using the first sub-digital identifier based on an algorithm corresponding to the classification information of the first sub-digital identifier, to obtain S intermediate identifiers; wherein, the algorithm corresponding to the first category is the inverse operation of the first algorithm, and the algorithm corresponding to the second category is the first algorithm; and A first query encryption sub-module, configured to use each intermediate identifier as an encryption parameter and the key values of the objects participating in the calculation of the intermediate identifier among the S objects as encryption objects, and obtain an encrypted key value corresponding to each intermediate identifier through homomorphic encryption; wherein, representing the S intermediate identifiers and the encrypted key value corresponding to each intermediate identifier in the form of a key-value pair, to obtain the calculation result group corresponding to the first sub-digital identifier; A first return module, configured to feed back the calculation result group corresponding to the first sub-digital identifier to the data query end that issues the query request; wherein, after the data query end obtains N calculation result groups corresponding to the N sub-digital identifiers one by one, it reversely resolves the key value corresponding to the target query object based on the N calculation result groups.
16. A data query device based on stealth query, which is set in a data query end, comprising: A second acquisition module, configured to acquire the digital identifier of a target query object; A second decomposition module, configured to decompose the digital identifier of the target query object based on a first algorithm to obtain N sub-digital identifiers, where N is an odd number greater than or equal to 3; A second classification module, configured to divide the N sub-digital identifiers into a first category and a second category, where the first category includes [(N - 1) / 2] + 1 sub-digital identifiers, and the second category includes (N - 1) / 2 sub-digital identifiers; A second request sending module, configured to send the N sub-digital identifiers and the classification information of each sub-digital identifier to a data server, so as to request the data server to perform data query by using the device described in claim 15 provided therein; A second result receiving module, configured to receive N calculation result groups returned by the data server and corresponding one by one to the N sub-digital identifiers; and A second data reverse resolution module, configured to reverse resolve the key value corresponding to the target query object based on the N calculation result groups.
17. A risk control device based on stealth query, which is disposed in a first business entity Comprising: A third obtaining module, configured to obtain the digital identifiers of M customers of the first business entity, where M is an integer greater than or equal to 1, and the M customers include a target customer; A third decomposition module, configured to decompose the digital identifier of each customer based on a first algorithm to obtain N sub-digital identifiers corresponding to each customer; where, corresponding to the M customers, a total of M*N sub-digital identifiers are obtained; where N is an odd number greater than or equal to 3; A third classification module, configured to divide the N sub-digital identifiers corresponding to each customer into a first category and a second category; where, for each customer, the first category includes [(N-1) / 2]+1 sub-digital identifiers, and the second category includes (N-1) / 2 sub-digital identifiers; A third sending module, configured to send the M*N sub-digital identifiers and the classification information of each sub-digital identifier to each of R second business entities, where R is an integer greater than or equal to 1; A third result receiving module, configured to receive M*N calculation result groups returned by each of the second business entities after performing data query by using the device described in claim 15 provided therein and corresponding one by one to the M*N sub-digital identifiers; A third selection module, configured to select N calculation result groups corresponding to the N sub-digital identifiers of the target customer from the M*N calculation result groups; where, the selected N calculation result groups are used as N target calculation result groups; A third data reverse resolution module, configured to reverse resolve the key value of the target customer recorded in the second business entity based on the N target calculation result groups; A third evaluation module, configured to evaluate the business risk of the target customer based on the key values of the target customer recorded in the R second business entities.
18. An electronic device Comprising: One or more processors; A memory, configured to store one or more programs, where, when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute: the data query method described in any one of claims 1 to 3, or the data query method described in any one of claims 4 to 7, or the risk control method described in any one of claims 8 to 14.
19. A computer-readable storage medium having computer program instructions stored thereon, which when executed by a processor implement: the data query method according to any one of claims 1 to 3, or the data query method according to any one of claims 4 to 7, or the risk control method according to any one of claims 8 to 14.
20. A computer program product comprising computer program instructions, which when executed by a processor implement: the data query method according to any one of claims 1 to 3, or the data query method according to any one of claims 4 to 7, or the risk control method according to any one of claims 8 to 14.
Citation Information
Patent Citations
Data hiding query method and device, storage medium and electronic equipment
CN118586025A