Information processing method, device, equipment and medium
Through target public key encryption technology and preset ciphertext matching algorithm, the problem that business outlets find it difficult to identify customers with special business needs is solved, and accurate identification and improvement of business processing efficiency is achieved.
Patent Information
- Application Number
- CN202211059555.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-31
- Publication Date
- 2025-05-02
- Estimated Expiration
- 2042-08-31
AI Technical Summary
It is difficult for related business outlets to accurately identify customers with special business needs, which affects business processing efficiency.
By using the target public key encryption technology, the identity attribute encryption and matching of the first customer is realized, and the identity attribute ciphertext of the first customer and the second customer is matched based on the preset ciphertext matching algorithm, the target query ciphertext is generated and sent to the second server.
Without decrypting the ciphertext of the customer's identity attribute, accurately identifying the matching relationship between the first customer and the second customer improves the timeliness of identifying customers entering the outlet area and improves the efficiency of business processing.
Smart Images

Figure CN115442117B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the fields of information security and data encryption technology, and in particular to an information processing method, device, equipment, medium and program product. Background Art
[0002] With the rapid development of science and technology, enterprises and other related business organizations are increasingly inclined to use computers and other network equipment in their business outlets to handle related business for customers who come to the business outlets. For example, banks and other financial institutions can use computers to build business service systems. Computer equipment in bank outlets can connect to the business service system to handle deposits, withdrawals, loans and other businesses for customers. In particular, the business service system can also be used to quickly handle related business services for customers with special business needs, thereby improving the overall efficiency of customer business handling.
[0003] However, the inventors have discovered that in the related technology, it is difficult for relevant business outlets to accurately identify customers with special business needs. Special business needs may include appointments for large-amount withdrawals, group savings card activation, etc. This will affect the business handling efficiency of the business outlets. Summary of the invention
[0004] In view of the above problems, the present disclosure provides an information processing method, apparatus, device, medium and program product.
[0005] According to a first aspect of the present disclosure, there is provided an information processing method, which is applied to a first server, comprising:
[0006] Encrypting the first identity attribute plaintext of the first customer using the target public key to obtain the first identity attribute ciphertext;
[0007] In response to detecting that the first customer enters a preset outlet area corresponding to the service outlet, matching the second identity attribute ciphertext from the second service end with the first identity attribute ciphertext based on a preset ciphertext matching algorithm to obtain a matching result, wherein the second identity attribute ciphertext is ciphertext data obtained by encrypting the second identity attribute plaintext of the second customer by the second service end using the target public key;
[0008] In the case where the matching result indicates that the first customer matches the second customer, encrypting the target query plaintext corresponding to the first customer using the target public key to obtain a target query ciphertext; and
[0009] Send the target query ciphertext to the second server.
[0010] According to an embodiment of the present disclosure, the above-mentioned preset ciphertext matching algorithm includes a privacy intersection algorithm;
[0011] The second identity attribute ciphertext from the second server is matched with the first identity attribute ciphertext based on a preset ciphertext matching algorithm, and the matching result obtained includes:
[0012] Determine the privacy intersection between the second identity attribute ciphertext and the first identity attribute ciphertext based on the privacy intersection algorithm; and
[0013] When the privacy intersection is not empty, a matching result of the first identity attribute ciphertext and the second identity attribute ciphertext is determined as a first matching result, wherein the first matching result indicates that the first customer matches the second customer.
[0014] According to an embodiment of the present disclosure, before using the target public key to encrypt the target query plaintext corresponding to the second customer to obtain the target query ciphertext, the information processing method further includes:
[0015] Processing the first communication number in the first identity attribute information based on a preset rule to generate a second communication number associated with the first communication number;
[0016] The target query plaintext corresponding to the first customer is encrypted using the target public key to obtain the target query ciphertext including:
[0017] The target public key is used to encrypt the customer identification of the first customer and the second communication number corresponding to the first customer to obtain the target query ciphertext.
[0018] According to an embodiment of the present disclosure, the above information processing method further includes:
[0019] parsing the communication request sent from the second server to obtain the second communication number; and
[0020] According to the association relationship between the second communication number and the first communication number, a communication connection is established between the second service end and the first client corresponding to the first communication number.
[0021] According to an embodiment of the present disclosure, the target query plain text includes the customer identification of the first customer and random characters generated based on random rules;
[0022] The target query plaintext corresponding to the first customer is encrypted using the target public key to obtain the target query ciphertext including:
[0023] The target public key is used to encrypt the concatenation result of the customer identification of the first customer and the random characters to obtain the target query ciphertext.
[0024] According to an embodiment of the present disclosure, the target query plaintext includes the first identity attribute plaintext and the customer evaluation information of the first customer;
[0025] The target query plaintext corresponding to the first customer is encrypted using the target public key to obtain the target query ciphertext including:
[0026] The target public key is used to encrypt the first identity attribute plaintext and the customer evaluation information of the first customer to obtain the target query ciphertext.
[0027] A second aspect of the present disclosure provides an information processing method, which is applied to a second server, comprising:
[0028] Encrypting the second identity attribute plaintext of the second customer using the target public key to obtain the second identity attribute ciphertext;
[0029] Sending the second identity attribute ciphertext to the first server, wherein the first server determines a matching result between the second identity attribute ciphertext and the first identity attribute ciphertext based on a preset ciphertext matching algorithm, and generates a target query ciphertext corresponding to the first customer if the matching result indicates that the first customer matches the second customer; and
[0030] In response to detecting the target query ciphertext from the first server, the target query ciphertext is decrypted using the target private key corresponding to the target public key to obtain the target query plaintext for the second customer.
[0031] According to an embodiment of the present disclosure, the target query plain text includes a second communication number corresponding to the first customer;
[0032] The above information processing method further includes:
[0033] generating a communication request for establishing a communication connection with the first client according to the second communication number; and
[0034] Send the communication request to the first server.
[0035] According to an embodiment of the present disclosure, the above information processing method further includes:
[0036] Send the target public key to the first server.
[0037] According to an embodiment of the present disclosure, the above information processing method further includes:
[0038] Obtaining authorization from the second customer for entering the second identity attribute in plain text; and
[0039] After obtaining the above authorization, enter the above second identity attribute in plain text.
[0040] A third aspect of the present disclosure provides an information processing device, applied to a first server, comprising:
[0041] A first encryption module, used to encrypt a first identity attribute plaintext of a first customer using a target public key to obtain a first identity attribute ciphertext;
[0042] a ciphertext matching module, configured to, in response to detecting that the first customer enters a preset outlet area corresponding to the service outlet, match the second identity attribute ciphertext from the second service end with the first identity attribute ciphertext based on a preset ciphertext matching algorithm to obtain a matching result, wherein the second identity attribute ciphertext is ciphertext data obtained by encrypting the second identity attribute plaintext of the second customer by the second service end using the target public key;
[0043] a second encryption module, configured to, when the matching result indicates that the first customer matches the second customer, encrypt the target query plaintext corresponding to the first customer using the target public key to obtain a target query ciphertext; and
[0044] The first sending module is used to send the target query ciphertext to the second server.
[0045] A fourth aspect of the present disclosure provides an information processing device, applied to a second server, comprising:
[0046] A third encryption module is used to encrypt the second identity attribute plaintext of the second customer by using the target public key to obtain the second identity attribute ciphertext;
[0047] a second sending module, configured to send the second identity attribute ciphertext to the first server, wherein the first server determines a matching result between the second identity attribute ciphertext and the first identity attribute ciphertext based on a preset ciphertext matching algorithm, and generates a target query ciphertext corresponding to the first customer when the matching result indicates that the first customer matches the second customer; and
[0048] The decryption module is used to, in response to detecting the target query ciphertext from the first server, decrypt the target query ciphertext using the target private key corresponding to the target public key to obtain the target query plaintext for the second customer.
[0049] The fifth aspect of the present disclosure provides an electronic device, comprising: one or more processors; a memory for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors execute the above-mentioned information processing method.
[0050] The sixth aspect of the present disclosure also provides a computer-readable storage medium having executable instructions stored thereon, which, when executed by a processor, causes the processor to execute the above-mentioned information processing method.
[0051] The seventh aspect of the present disclosure also provides a computer program product, including a computer program, which implements the above-mentioned information processing method when executed by a processor. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] The above contents and other objects, features and advantages of the present disclosure will become more apparent through the following description of the embodiments of the present disclosure with reference to the accompanying drawings, in which:
[0053] Figure 1 The application scenario diagram of the information processing method and device according to the embodiment of the present disclosure is schematically shown;
[0054] Figure 2 A flowchart schematically shows an information processing method applied to a first server according to an embodiment of the present disclosure;
[0055] Figure 3 A flowchart schematically shows a method of matching a second identity attribute ciphertext from a second server with a first identity attribute ciphertext based on a preset ciphertext matching algorithm to obtain a matching result according to an embodiment of the present disclosure;
[0056] Figure 4 A flowchart schematically shows an information processing method applied to a second server according to an embodiment of the present disclosure;
[0057] Figure 5 The application scenario diagram of the information processing method according to the embodiment of the present disclosure is schematically shown;
[0058] Figure 6 A diagram schematically shows an application scenario of an information processing method according to another embodiment of the present disclosure;
[0059] Figure 7 A diagram schematically shows an application scenario of an information processing method according to another embodiment of the present disclosure;
[0060] Figure 8 The structure block diagram of the information processing device according to the embodiment of the present disclosure is schematically shown;
[0061] Fig. 9 A block diagram schematically shows a structure of an information processing device according to another embodiment of the present disclosure; and
[0062] Fig.10 A block diagram of an electronic device suitable for implementing an information processing method according to an embodiment of the present disclosure is schematically shown. DETAILED DESCRIPTION
[0063] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the present disclosure. In the following detailed description, for ease of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure. However, it is apparent that one or more embodiments may also be implemented without these specific details. In addition, in the following description, descriptions of known structures and technologies are omitted to avoid unnecessary confusion of the concepts of the present disclosure.
[0064] The terms used herein are only for describing specific embodiments and are not intended to limit the present disclosure. The terms "comprise", "include", etc. used herein indicate the existence of the features, steps, operations and / or components, but do not exclude the existence or addition of one or more other features, steps, operations or components.
[0065] All terms (including technical and scientific terms) used herein have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification, and should not be interpreted in an idealized or overly rigid manner.
[0066] When using expressions such as "at least one of A, B, and C, etc.", they should generally be interpreted according to the meaning of the expression commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include but is not limited to a system having A alone, B alone, C alone, A and B, A and C, B and C, and / or A, B, C, etc.).
[0067] In the technical solution of the present disclosure, the collection, storage, use, processing, transmission, provision, disclosure and application of user personal information involved comply with the provisions of relevant laws and regulations, take necessary confidentiality measures, and do not violate public order and good morals.
[0068] In the technical solution of the present disclosure, the user's authorization or consent is obtained before obtaining or collecting the user's personal information.
[0069] An embodiment of the present disclosure provides an information processing method, which is applied to a first server, including: encrypting a first identity attribute plaintext of a first customer using a target public key to obtain a first identity attribute ciphertext; in response to detecting that the first customer enters a preset outlet area corresponding to a service outlet, matching a second identity attribute ciphertext from a second server with the first identity attribute ciphertext based on a preset ciphertext matching algorithm to obtain a matching result, wherein the second identity attribute ciphertext is ciphertext data obtained after the second server encrypts the second identity attribute plaintext of the second customer using the target public key; when the matching result indicates that the first customer matches the second customer, encrypting a target query plaintext corresponding to the first customer using the target public key to obtain a target query ciphertext; and sending the target query ciphertext to the second server.
[0070] An embodiment of the present disclosure also provides an information processing method, which is applied to a second server, including: encrypting a second identity attribute plaintext of a second client using a target public key to obtain a second identity attribute ciphertext; sending the second identity attribute ciphertext to a first server, wherein the first server determines a matching result between the second identity attribute ciphertext and the first identity attribute ciphertext based on a preset ciphertext matching algorithm, and generates a target query ciphertext corresponding to the first client when the matching result indicates that the first client matches the second client; and in response to detecting the target query ciphertext from the first server, decrypting the target query ciphertext using a target private key corresponding to the target public key to obtain a target query plaintext for the second client.
[0071] According to an embodiment of the present disclosure, after detecting that the first customer has entered the branch area, the second identity attribute ciphertext is matched with the first identity attribute ciphertext based on a preset ciphertext matching algorithm. It is possible to determine that the first customer matches the second customer specified by the second server without decrypting the customer's identity attribute ciphertext, and obtain the target query ciphertext using the target public key encryption, so that the second server can promptly know that the first customer has entered the branch area based on the target query ciphertext, thereby ensuring the security of the customer's identity information while at least partially improving the timeliness of identifying the first customer entering the branch area, and then promptly taking business preparation measures based on the relevant business needs of the first customer to improve the branch's business handling efficiency for the first customer, thereby achieving the improvement of the overall business handling efficiency of the branch.
[0072] Figure 1 The application scenario diagram of the information processing method and device according to the embodiments of the present disclosure is schematically shown.
[0073] like Figure 1As shown, the application scenario 100 according to this embodiment may include terminal devices 101, 102, 103, a network 104, a first service end 121a, 121b, a second server 122, a preset network area 120, and a customer 110 holding a mobile phone. The network 104 is used to provide a medium for a communication link between the terminal devices 101, 102, 103 and the second server 122. The network 104 may include various connection types, such as wired, wireless communication links or optical fiber cables, etc.
[0074] The user can use the terminal devices 101, 102, 103 to interact with the second server 122 through the network 104 to receive or send messages, etc. Various communication client applications can be installed on the terminal devices 101, 102, 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (only as examples).
[0075] The terminal devices 101 , 102 , and 103 may be various electronic devices having a display screen and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers, and desktop computers.
[0076] The second server 122 may be a server that provides various services, such as a background management server (only as an example) that provides support for websites browsed by users using the terminal devices 101, 102, and 103. The background management server may analyze and process the received data such as user requests, and feed back the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal device.
[0077] The first service end 121a, 121b may include a first server 121a and a signal detection device 121b. The signal detection device 121b may be a device for detecting the location signal of the mobile phone held by the client 110, such as a location signal detection device such as LBS (Location Based Service) in the related art. The first server 121a may be a server that provides various services, and the first server 121a and the second server 122 may communicate via a wired communication link and / or a wireless communication link.
[0078] It should be noted that the information processing method provided in the embodiment of the present disclosure and applied to the first server can generally be executed by the first server 121a. Accordingly, the information processing device provided in the embodiment of the present disclosure and applied to the first server can generally be set in the first server 121a. The information processing method provided in the embodiment of the present disclosure and applied to the second server can generally be executed by the second server 122. Accordingly, the information processing device provided in the embodiment of the present disclosure and applied to the second server can generally be set in the second server 122. Alternatively, the information processing method provided in the embodiment of the present disclosure and applied to the second server can also be executed by the terminal devices 101, 102, 103, and accordingly, the information processing device provided in the embodiment of the present disclosure and applied to the second server can also be set in the terminal devices 101, 102, 103.
[0079] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is only for illustration. Any number of terminal devices, networks and servers may be provided according to implementation requirements.
[0080] The following will be based on Figure 1 The scene described by Figure 2 to Figure 7 The information processing method of the disclosed embodiment is described in detail.
[0081] Figure 2 The flowchart of the information processing method applied to the first server according to the embodiment of the present disclosure is schematically shown.
[0082] like Figure 2 As shown, the information processing method of this embodiment can be applied to the first server, including operations S210 to S240.
[0083] In operation S210, the first identity attribute plaintext of the first customer is encrypted using the target public key to obtain the first identity attribute ciphertext.
[0084] According to the embodiments of the present disclosure, the target public key can be sent from the second server to the first server, or sent to the first server by a relevant trusted authority. The embodiments of the present disclosure do not limit the generation method and source of the target public key, as long as the first server and the second server have the same target public key for encryption.
[0085] According to an embodiment of the present disclosure, the first identity attribute plain text may include relevant identity attribute information of the first customer that the first server has the authority to query and call, and the first identity attribute plain text may include information used to characterize the uniqueness of the identity of the first customer, such as the first customer's name, contact information, address, etc.
[0086] In operation S220, in response to detecting that the first customer enters a preset outlet area corresponding to a service outlet, a second identity attribute ciphertext from a second server is matched with the first identity attribute ciphertext based on a preset ciphertext matching algorithm to obtain a matching result, wherein the second identity attribute ciphertext is ciphertext data obtained after the second server encrypts the second customer's second identity attribute plaintext using the target public key.
[0087] According to the embodiments of the present disclosure, the preset network point area may be a geographical area corresponding to the geographical location of the preset network point, and the preset network point area may be, for example, an area with the preset network point as the center and a radius of 3 kilometers. It should be understood that the embodiments of the present disclosure do not limit the specific setting range and setting method of the preset network point area, and those skilled in the art may design it according to actual needs.
[0088] According to the embodiments of the present disclosure, the preset ciphertext matching algorithm may include a data matching method in the related art. For example, when both the first identity attribute ciphertext and the second identity attribute ciphertext are long character segments, the first identity attribute ciphertext and the second identity attribute ciphertext may be matched based on the character segments of the first identity attribute ciphertext and the second identity attribute ciphertext to obtain a matching result. However, it is not limited to this. The first identity attribute ciphertext and the second identity attribute ciphertext may also be matched based on a privacy intersection algorithm in the related art, that is, on the premise that the first server and the second server pre-agree on a privacy intersection protocol, the first identity attribute ciphertext and the second identity attribute ciphertext may be matched based on a privacy intersection algorithm to obtain a matching result.
[0089] In operation S230, when the matching result indicates that the first customer matches the second customer, the target query plaintext corresponding to the first customer is encrypted using the target public key to obtain the target query ciphertext.
[0090] In operation S240, the target query ciphertext is sent to the second server.
[0091] According to an embodiment of the present disclosure, the target query plain text may include query data related to the business needs of the first customer, such as the name of the first customer, the time of entering the preset branch area, and the like.
[0092] It should be noted that relevant technical personnel can design the specific data type of the target query plaintext according to actual needs, and the embodiments of the present disclosure do not limit the specific type of the target query plaintext.
[0093] It should be understood that the second server can use the target private key corresponding to the target public key to decrypt the target query ciphertext, thereby obtaining the target query plaintext. The first server does not obtain the right to use the target private key, or does not store the target private key. Therefore, the first server can only perform the plaintext encryption process and cannot obtain the second identity attribute plaintext corresponding to the second identity attribute ciphertext.
[0094] According to an embodiment of the present disclosure, the matching situation between the first customer and the second customer can be determined by the matching result of the first identity attribute ciphertext and the second identity attribute ciphertext, so that the second customer set by the second server can be determined as the first customer entering the preset branch area, which can help the second server to timely and accurately identify that the first customer will enter the business branch corresponding to the preset branch area in a short time, and then target the query ciphertext to prompt the business branch corresponding to the second server to take relevant business measures to improve the business service efficiency for the first customer.
[0095] According to an embodiment of the present disclosure, the first service end may include an organization or institution with authority or qualification to obtain the real-time location of the client, such as a communication operator, etc. The second service end may be an organization or institution that provides business services to the client, such as a bank, a securities trading center, a government affairs processing center, etc.
[0096] According to the embodiments of the present disclosure, in the related technologies, the business service provider usually does not have the authority or qualifications to collect the real-time location of the user in real time. The business service provider can transmit encrypted text with the communication operator that has the authority to collect the customer's location by adopting the information processing method provided in the above embodiments. This can promptly notify the business service outlet that the first customer has entered the preset outlet area without leaking the customer's privacy information. That is, it can be predicted that the first customer can enter the outlet in a short time, thereby improving the customer's business handling efficiency.
[0097] According to an embodiment of the present disclosure, after detecting that the first customer has entered the branch area, the second identity attribute ciphertext is matched with the first identity attribute ciphertext based on a preset ciphertext matching algorithm. It is possible to determine that the first customer matches the second customer specified by the second server without decrypting the customer's identity attribute ciphertext, and obtain the target query ciphertext using the target public key encryption, so that the second server can promptly know that the first customer has entered the branch area based on the target query ciphertext, thereby ensuring the security of the customer's identity information while at least partially improving the timeliness of identifying the first customer entering the branch area, and then promptly taking business preparation measures based on the relevant business needs of the first customer to improve the branch's business handling efficiency for the first customer, thereby achieving the improvement of the overall business handling efficiency of the branch.
[0098] It should be noted that the first customer (second customer) can sign a relevant service agreement with the first server and the second server in advance, so that the first server and the second server can implement the above information processing method according to the customer's authorization and relevant laws or regulations.
[0099] According to an embodiment of the present disclosure, the preset ciphertext matching algorithm includes a privacy intersection algorithm.
[0100] Figure 3 The flowchart schematically shows a method of matching a second identity attribute ciphertext from a second server with a first identity attribute ciphertext based on a preset ciphertext matching algorithm to obtain a matching result according to an embodiment of the present disclosure.
[0101] like Figure 3 As shown, operation S220, matching the second identity attribute ciphertext from the second server with the first identity attribute ciphertext based on a preset ciphertext matching algorithm, and obtaining the matching result may include operations S310 to S320.
[0102] In operation S310 , a privacy intersection between the second identity attribute ciphertext and the first identity attribute ciphertext is determined based on a privacy intersection algorithm.
[0103] In operation S320 , when the privacy intersection is not empty, a matching result of the first identity attribute ciphertext and the second identity attribute ciphertext is determined as a first matching result, wherein the first matching result indicates that the first customer matches the second customer.
[0104] According to an embodiment of the present disclosure, the privacy intersection algorithm may be an algorithm determined based on a private set intersection (PSI) protocol, and the private set intersection protocol may include: "privacy comparison", "oblivious transfer", and the like.
[0105] According to an embodiment of the present disclosure, when the privacy intersection is not empty, that is, when there is a privacy transaction between the first identity attribute ciphertext and the second identity attribute ciphertext, it can be determined that the first customer matches the second customer, and thus it can be determined that the first customer entering the preset branch area can be the second customer preset by the second server.
[0106] According to the embodiments of the present disclosure, by using a privacy intersection algorithm to determine whether the first customer and the second customer are matched, it can be ensured that the second identity attribute plaintext stored on the second server is not leaked to the first server, and even if the first server is difficult to be maliciously obtained by other servers to obtain the first identity attribute ciphertext and the second identity attribute ciphertext, the ciphertext cannot be decrypted to obtain the plaintext, thereby ensuring the security of the customer's identity information while accurately and promptly notifying the second server that the first customer has entered the preset branch area.
[0107] According to an embodiment of the present disclosure, the target query plain text includes a customer identifier of the first customer and random characters generated based on a random rule.
[0108] Encrypting the target query plaintext corresponding to the first customer using the target public key to obtain the target query ciphertext may include the following operations:
[0109] The target public key is used to encrypt the concatenation result of the customer identification of the first customer and the random characters to obtain the target query ciphertext.
[0110] According to the embodiments of the present disclosure, by concatenating the customer identifier with random characters, the complexity and randomness of the target query plaintext can be reduced. Even if the target query ciphertext is maliciously intercepted, it is difficult to crack the plaintext information of the customer identifier, thereby improving the security of the customer's identity information during transmission.
[0111] According to an embodiment of the present disclosure, in the case where the second customers include multiple customers, based on the information processing method provided by the above embodiment, after the first server determines that the matching result of the first identity attribute ciphertext and the second identity attribute ciphertext is the first matching result, it can only determine that the first customer matches the target second customer among the multiple second customers, thereby avoiding the first server from obtaining relevant information of other second customers except the target second customer, thereby further ensuring that the second identity attribute plaintext of each of the multiple second customers will not be obtained by the first server, thereby improving the information security of the customers.
[0112] According to an embodiment of the present disclosure, the target query plaintext includes the first identity attribute plaintext and the customer evaluation information of the first customer;
[0113] Encrypting the target query plaintext corresponding to the first customer using the target public key to obtain the target query ciphertext may include the following operations:
[0114] The target public key is used to encrypt the first identity attribute plaintext and the customer evaluation information of the first customer to obtain the target query ciphertext.
[0115] According to an embodiment of the present disclosure, customer evaluation information may include evaluation information generated based on the payment behavior, payment habits, etc. of the first customer that the first server has the authority to obtain. In the case where the first identity attribute plaintext includes multiple items, the second server may query the identity attribute plaintext of the second customer that matches the first customer entering the preset network point area through the privacy set intersection algorithm provided in the above embodiment, thereby helping the second server to adjust the business service process for the first customer entering the preset network point area in a timely manner based on the customer evaluation information of the first customer entering the preset network point area and the first identity attribute plaintext.
[0116] According to an embodiment of the present disclosure, in operation S230, before encrypting the target query plaintext corresponding to the second customer using the target public key to obtain the target query ciphertext, the information processing method may further include the following operations:
[0117] The first communication number in the first identity attribute information is processed based on a preset rule to generate a second communication number associated with the first communication number.
[0118] In operation S230, encrypting the target query plaintext corresponding to the first customer using the target public key to obtain the target query ciphertext may include the following operations:
[0119] The target public key is used to encrypt the customer identification of the first customer and the second communication number corresponding to the first customer to obtain the target query ciphertext.
[0120] According to an embodiment of the present disclosure, the first communication number may be a contact number commonly used by the first customer entering the preset network area, and the second communication number may be a temporary communication number associated with the first communication number.
[0121] According to the embodiments of the present disclosure, the first communication number can be processed based on a random rule to generate a second communication number, or the first communication number can be processed based on a preset number character conversion rule to obtain a corresponding second communication number. The embodiments of the present disclosure do not limit the specific method of processing the first communication number, and those skilled in the art can design it according to actual needs, as long as the first communication number can be associated with the second communication number.
[0122] According to an embodiment of the present disclosure, by sending a target query ciphertext containing a second communication number to a second server, the first customer's commonly used contact information (i.e., the first communication number) will not be leaked to the second server, and even if the target query ciphertext is maliciously intercepted, the first customer's first communication number will not be leaked, thereby ensuring the information security of the customer's communication contact information.
[0123] According to an embodiment of the present disclosure, the information processing method may further include the following operations:
[0124] Parse the communication request sent from the second server to obtain a second communication number; and establish a communication connection between the second server and the first client corresponding to the first communication number based on the association between the second communication number and the first communication number.
[0125] According to an embodiment of the present disclosure, the communication request from the second server can be sent to the first server in any form. For example, the telephone dialing device of the second server can send a communication request to the first server by dialing the second communication number, or can also send a communication request to the first server by sending a request packet.
[0126] It should be noted that the first server needs to establish a communication connection between the second server and the first customer based on the second communication number received from the second server, so as to prevent other users or organizations that have not established relevant agreements with the first server from obtaining the contact information of the first customer, prevent the first customer from being harassed by irrelevant users or organizations, and protect the privacy and security of the first customer.
[0127] Figure 4 The flowchart schematically shows an information processing method applied to a second server according to an embodiment of the present disclosure.
[0128] like Figure 4 As shown, the information processing method of this embodiment can be applied to the second server, and the information processing method includes operations S410 to S430.
[0129] In operation S410, the second identity attribute plaintext of the second customer is encrypted using the target public key to obtain the second identity attribute ciphertext.
[0130] In operation S420, the second identity attribute ciphertext is sent to the first server, wherein the first server determines a matching result between the second identity attribute ciphertext and the first identity attribute ciphertext based on a preset ciphertext matching algorithm, and generates a target query ciphertext corresponding to the first customer when the matching result indicates that the first customer matches the second customer.
[0131] In operation S430, in response to detecting the target query ciphertext from the first server, the target query ciphertext is decrypted using a target private key corresponding to the target public key to obtain a target query plaintext for the second client.
[0132] According to an embodiment of the present disclosure, the information processing method may further include the following operations:
[0133] Obtaining authorization from the second customer for entering the second identity attribute plain text; and entering the second identity attribute plain text after obtaining the authorization.
[0134] According to an embodiment of the present disclosure, the information processing method may further include the following operations:
[0135] Send the target public key to the first server.
[0136] According to an embodiment of the present disclosure, the target query plaintext includes a second communication number corresponding to the first customer.
[0137] The information processing method may further include the following operations:
[0138] A communication request for establishing a communication connection with the first client is generated according to the second communication number; and the communication request is sent to the first server.
[0139] Figure 5 The application scenario diagram of the information processing method according to the embodiment of the present disclosure is schematically shown.
[0140] like Figure 5As shown, the application scenario may include a preset network area 500, and the area and location of the preset network area can be determined according to the geographical location of the business network of the network customer service module 510 (i.e., the second service end) and the operator customer service module 520 (i.e., the first service end).
[0141] The network point VIP module 510 may include a customer information submodule 511, a VIP information submodule 512, and a receiving notification submodule 513. The operator VIP module 520 may include a VIP information storage submodule 521, a VIP location submodule 522, and a VIP information processing submodule 523.
[0142] It should be noted that the VIP may be the abbreviation of an important customer, and the important customer may be the second customer set by the second server and / or the first customer set by the first client.
[0143] The customer information submodule 511 of the branch VIP module 510 needs to seek the consent of important customers and sign a letter of authorization. The plain text of the important customer's VIP information (and the plain text of the second identity attribute), such as name, ID number, contact number, etc., is sent to the VIP information submodule 512.
[0144] The VIP information submodule 512 generates a public-private key pair, namely a target public key and a target private key. The target public key is sent to the VIP information storage submodule 521, the VIP positioning submodule 522 and the VIP information processing submodule 523, and the VIP information plaintext is encrypted with the target public key to encrypt the VIP information ciphertext (i.e., the second identity attribute ciphertext).
[0145] The VIP information ciphertext is sent to the VIP information storage submodule 521. The VIP information storage submodule 521 stores the target public key and the VIP information ciphertext.
[0146] The VIP positioning submodule 522 of the operator's VIP module 520, by deploying devices with positioning functions such as LBS base station positioning functions, can access the operator's positioning function device through the mobile phone of the visiting customer 530 (i.e., the first customer) in the preset branch area 500 corresponding to the business branch, thereby detecting that the visiting customer 530 enters the preset branch area 500.
[0147] When a visiting customer enters the network, the VIP location submodule 522 encrypts the visiting customer's contact number (ie, the first identity attribute plain text) into visitor information ciphertext (and the first identity attribute ciphertext), and sends it to the VIP information processing submodule 523 .
[0148] The VIP information processing submodule 523 determines whether the visitor information ciphertext and the contact number corresponding to the VIP information ciphertext match through the privacy set intersection algorithm, and assembles the first matching result representing the match and the customer identifier of the first customer with random characters to obtain the target query plaintext, encrypts the assembled target query plaintext into the target query ciphertext with the target public key, and sends it to the notification receiving submodule 513.
[0149] The receiving notification submodule 513 obtains the target private key from the VIP information submodule 512, and uses the target private key to decrypt the target query ciphertext, obtains the target query plaintext assembled with the first matching result, the customer identification of the first customer and the random number, removes the random number, retains the first matching result and the customer identification of the first customer, and then notifies the relevant business personnel of the business outlet to execute relevant business processes for the first customer 530 entering the preset outlet area 500.
[0150] It should be noted that the operator VIP module 520 is a device system provided by the relevant communication operator, which can be deployed in the business outlets of the financial institution and is physically isolated from the operator's core system to avoid the plaintext leakage of the second identity attribute stored in the operator VIP module 520. In this way, the customer information in the financial institution will be transmitted to the operator VIP module 520. Although the communication operator provides technical support for location detection, the customer information and other data of the financial institution will not be retained outside the area of the financial institution to meet the provisions on data storage in relevant laws and regulations.
[0151] Figure 6 An application scenario diagram of an information processing method according to another embodiment of the present disclosure is schematically shown.
[0152] like Figure 6 As shown, the application scenario may include an institutional customer verification module 610 (second service end) and an operator customer verification module 620 (first service end).
[0153] The customer information analysis submodule 621 of the operator customer verification module 620 forms the customer's three-factor information (i.e., the first identity attribute in plain text) based on the customer's real-name authentication information, including name, ID number, and contact number. Based on the customer's call information, the customer's frequently used contacts are analyzed to form the customer's frequently used contact information. The customer's frequently used address is analyzed based on the broadband application information or the long-term address of the mobile phone information at night. Based on whether the customer is on the operator's blacklist, whether the customer is involved in fraud, etc., analyze whether the customer is on the customer blacklist. Analyze the customer's rating information (i.e., the customer evaluation information of the first customer) based on the customer's consumption at the operator.
[0154] When a customer conducts business at a financial institution, he / she registers the three elements of information, namely name, ID number and contact number. The customer information such as common contacts and common addresses can be determined as the second identity attribute in plain text. The financial institution asks the customer for consent and signs a letter of authorization to initiate customer information verification.
[0155] The verification initiation submodule 611 generates a public-private key pair, a target public key and a target private key, and the target public key is sent to the verification calculation submodule 622, and the target private key is stored in the verification initiation submodule 611. The verification initiation submodule 611 encrypts the customer's name, ID number, contact number, and common contact and common address information (second identity attribute plain text) with the target public key, respectively, into a second identity attribute ciphertext, and sends the second identity attribute ciphertext to the verification calculation submodule 622. The verification calculation submodule 622 receives the second identity attribute ciphertext.
[0156] After detecting that the customer has entered the preset branch area, the operator customer verification module 620 can obtain the first identity attribute plaintext consisting of the customer's name, ID number, contact number, common contacts, common addresses, etc. from the customer information analysis sub-module 621, and can also obtain customer evaluation information such as whether the customer is on the blacklist and customer rating, and use the target public key to encrypt the first identity attribute plaintext and customer evaluation information respectively into the first identity attribute ciphertext.
[0157] The verification calculation submodule 622 performs a privacy query based on the privacy set intersection algorithm, compares the matching results of the second identity attribute ciphertext and the first identity attribute ciphertext, and when the matching result is the first matching result, uses the target public key to encrypt the customer evaluation information and the first identity attribute plaintext into a verification result ciphertext (i.e., the target query ciphertext), and sends the target query ciphertext to the verification result submodule 612.
[0158] The verification result submodule 612 obtains the target private key from the verification initiation submodule 611, decrypts the target query ciphertext, obtains the three-factor information of name, ID number, and contact number, as well as the results of whether the common contacts and common addresses are consistent, as well as customer evaluation information such as whether they are on the blacklist, customer ratings, etc., to prompt the staff of the business outlets to execute relevant business processes.
[0159] Figure 7 An application scenario diagram of an information processing method according to yet another embodiment of the present disclosure is schematically shown.
[0160] like Figure 7 As shown, the application scenario may include an institutional customer loss repair module 710 (and a second server) and an operator customer time limit repair module 720 (ie, a first server).
[0161] The institutional customer lost connection repair module 710 may include a lost connection repair initiating submodule 711 and a lost connection repair processing submodule 712. The operator customer time limit repair module 720 may include a customer information submodule 721, a repair calculation submodule 722 and a transfer processing submodule 723.
[0162] The lost connection repair initiating submodule 711 of the institutional customer lost connection repair module 710 can determine that the customer is a long-term lost connection customer according to the business needs, such as the customer cannot be contacted for many times. The lost connection repair initiating submodule 711 generates a public-private key pair, a target public key and a target private key, and the target public key can be sent to the repair calculation submodule 722.
[0163] The name, ID number and other identity information (i.e., the second identity attribute plain text) of the long-lost customer (i.e., the second customer) is encrypted into the second identity attribute ciphertext using the target public key, and the second identity attribute ciphertext is sent to the repair calculation submodule 722.
[0164] The repair calculation submodule 722 receives the second identity attribute ciphertext, and encrypts the first identity attribute plaintext into the first identity attribute ciphertext using the target public key according to the first identity attribute plaintext stored in the customer information submodule 721. It should be understood that the first identity attribute plaintext may include multiple.
[0165] When the operator customer time limit repair module 720 detects that the customer 730 enters the preset branch area 700, the repair calculation submodule 722 can use the privacy set intersection algorithm to determine the matching result of the second identity attribute ciphertext and the first identity attribute ciphertext, and determine the target first identity attribute ciphertext that matches the second identity attribute ciphertext, so that a privacy query can be performed on the target first identity attribute ciphertext based on the privacy set intersection algorithm. The obtained target first identity attribute ciphertext can determine that the customer 730 is the long-term lost contact customer (i.e., the second customer) that the institutional customer loss repair module 710 needs to determine.
[0166] Furthermore, the repair calculation submodule 722 can obtain the common contact number (i.e., the first communication number) of the customer 730 from the customer information submodule 721, and convert the first communication number of the customer 730 into a temporary communication number (i.e., the second communication number). Then, the repair calculation submodule 722 can send the second communication number to the lost connection repair processing submodule 712.
[0167] After the lost connection repair processing submodule 712 receives the second communication number, the relevant staff of the organization can send a communication request to the transfer submodule 723 by dialing the second communication number. The transfer processing submodule 723 establishes a communication connection between the organization customer lost connection repair module 710 and the customer 730 through the communication request containing the second communication number, that is, realizes a conversation with the customer 730, thereby establishing a communication channel between the shear wall organization and the customer 730.
[0168] Based on the above information processing method, the present disclosure also provides an information processing device. Figure 8 The device is described in detail.
[0169] Figure 8 The structure block diagram of the information processing device according to the embodiment of the present disclosure is schematically shown.
[0170] like Figure 8 As shown, the information processing device 800 of this embodiment can be applied to a first server, and the information processing device 800 includes a first encryption module 810, a ciphertext matching module 820, a second encryption module 830 and a first sending module 840.
[0171] The first encryption module 810 is used to encrypt the first identity attribute plaintext of the first customer by using the target public key to obtain the first identity attribute ciphertext.
[0172] The ciphertext matching module 820 is used to match the second identity attribute ciphertext from the second server with the first identity attribute ciphertext based on a preset ciphertext matching algorithm in response to detecting that the first customer enters a preset branch area corresponding to the service branch, to obtain a matching result, wherein the second identity attribute ciphertext is the ciphertext data obtained after the second server encrypts the second identity attribute plaintext of the second customer using the target public key.
[0173] The second encryption module 830 is used to encrypt the target query plaintext corresponding to the first customer using the target public key to obtain the target query ciphertext when the matching result indicates that the first customer matches the second customer.
[0174] The first sending module 840 is used to send the target query ciphertext to the second server.
[0175] According to an embodiment of the present disclosure, the preset ciphertext matching algorithm includes a privacy intersection algorithm.
[0176] The ciphertext matching module includes: a first ciphertext determining unit and a first determining unit.
[0177] The first ciphertext determination unit is used to determine a privacy intersection between the second identity attribute ciphertext and the first identity attribute ciphertext based on a privacy intersection algorithm.
[0178] The first determination unit is used to determine, when the privacy intersection is not empty, a matching result of the first identity attribute ciphertext and the second identity attribute ciphertext as a first matching result, wherein the first matching result indicates that the first customer matches the second customer.
[0179] According to an embodiment of the present disclosure, the information processing device further includes: a communication number generating module.
[0180] The communication number generation module is used to process the first communication number in the first identity attribute information based on a preset rule to generate a second communication number associated with the first communication number.
[0181] Wherein, the second encryption module includes: a first encryption unit.
[0182] The first encryption unit is used to encrypt the customer identification of the first customer and the second communication number corresponding to the first customer by using the target public key to obtain the target query ciphertext.
[0183] According to an embodiment of the present disclosure, the information processing device further includes: a parsing module and a communication connection establishing module.
[0184] The parsing module is used to parse the communication request sent from the second server to obtain the second communication number.
[0185] The communication connection establishing module is used to establish a communication connection between the second service end and the first client corresponding to the first communication number according to the association relationship between the second communication number and the first communication number.
[0186] According to an embodiment of the present disclosure, the target query plain text includes a customer identifier of the first customer and random characters generated based on a random rule.
[0187] The second encryption module includes a second encryption unit.
[0188] The second encryption unit is used to encrypt the concatenation result of the customer identification of the first customer and the random characters by using the target public key to obtain the target query ciphertext.
[0189] According to an embodiment of the present disclosure, the target query plaintext includes the first identity attribute plaintext and customer evaluation information of the first customer.
[0190] The second encryption module includes a third encryption unit.
[0191] The third encryption unit is used to encrypt the first identity attribute plaintext and the customer evaluation information of the first customer by using the target public key to obtain the target query ciphertext.
[0192] Fig. 9 The structure block diagram of an information processing device according to another embodiment of the present disclosure is schematically shown.
[0193] like Fig. 9 As shown, the information processing device 900 of this embodiment can be applied to the second server, and the information processing device 900 includes a third encryption module 910, a second sending module 920 and a decryption module 930.
[0194] The third encryption module 910 is used to encrypt the second identity attribute plaintext of the second customer by using the target public key to obtain the second identity attribute ciphertext.
[0195] The second sending module 920 is used to send the second identity attribute ciphertext to the first server, wherein the first server determines the matching result of the second identity attribute ciphertext and the first identity attribute ciphertext based on a preset ciphertext matching algorithm, and generates a target query ciphertext corresponding to the first customer when the matching result indicates that the first customer matches the second customer.
[0196] The decryption module 930 is used to, in response to detecting the target query ciphertext from the first server, decrypt the target query ciphertext using the target private key corresponding to the target public key to obtain the target query plaintext for the second customer.
[0197] According to an embodiment of the present disclosure, the target query plaintext includes a second communication number corresponding to the first customer.
[0198] The information processing device also includes: a communication request generating module and a communication request sending module.
[0199] The communication request generating module is used to generate a communication request for establishing a communication connection with the first client according to the second communication number.
[0200] The communication request sending module is used to send a communication request to the first service end.
[0201] According to an embodiment of the present disclosure, the information processing device further includes a key sending module.
[0202] The key sending module is used to send the target public key to the first server.
[0203] According to an embodiment of the present disclosure, the information processing device further includes: a first authorization acquisition module and an information entry module.
[0204] The first authorization acquisition module is used to obtain the second customer's authorization for entering the second identity attribute in plain text.
[0205] The information entry module is used to enter the second identity attribute in plain text after authorization.
[0206] According to an embodiment of the present disclosure, any multiple modules of the first encryption module 810, the ciphertext matching module 820, the second encryption module 830, the first sending module 840, the third encryption module 910, the second sending module 920 and the decryption module 930 can be combined in one module for implementation, or any one of the modules can be split into multiple modules. Alternatively, at least part of the functions of one or more of these modules can be combined with at least part of the functions of other modules and implemented in one module. According to an embodiment of the present disclosure, at least one of the first encryption module 810, the ciphertext matching module 820, the second encryption module 830, the first sending module 840, the third encryption module 910, the second sending module 920 and the decryption module 930 can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on a chip, a system on a substrate, a system on a package, an application specific integrated circuit (ASIC), or can be implemented by hardware or firmware such as any other reasonable way of integrating or packaging the circuit, or implemented in any one of the three implementation methods of software, hardware and firmware or in an appropriate combination of any of them. Alternatively, at least one of the first encryption module 810, the ciphertext matching module 820, the second encryption module 830, the first sending module 840, the third encryption module 910, the second sending module 920 and the decryption module 930 can be at least partially implemented as a computer program module, which can perform corresponding functions when the computer program module is executed.
[0207] Fig.10 A block diagram of an electronic device suitable for implementing an information processing method according to an embodiment of the present disclosure is schematically shown.
[0208] like Fig.10 As shown, the electronic device 1000 according to an embodiment of the present disclosure includes a processor 1001, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1002 or a program loaded from a storage part 1008 into a random access memory (RAM) 1003. The processor 1001 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or a related chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 1001 may also include an onboard memory for caching purposes. The processor 1001 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.
[0209] In RAM 1003, various programs and data required for the operation of electronic device 1000 are stored. Processor 1001, ROM 1002 and RAM 1003 are connected to each other via bus 1004. Processor 1001 performs various operations of the method flow according to the embodiment of the present disclosure by executing the program in ROM 1002 and / or RAM 1003. It should be noted that the program can also be stored in one or more memories other than ROM 1002 and RAM 1003. Processor 1001 can also perform various operations of the method flow according to the embodiment of the present disclosure by executing the program stored in the one or more memories.
[0210] According to an embodiment of the present disclosure, the electronic device 1000 may further include an input / output (I / O) interface 1005, which is also connected to the bus 1004. The electronic device 1000 may further include one or more of the following components connected to the I / O interface 1005: an input portion 1006 including a keyboard, a mouse, etc.; an output portion 1007 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage portion 1008 including a hard disk, etc.; and a communication portion 1009 including a network interface card such as a LAN card, a modem, etc. The communication portion 1009 performs communication processing via a network such as the Internet. A drive 1010 is also connected to the I / O interface 1005 as needed. A removable medium 1011, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 1010 as needed, so that a computer program read therefrom is installed into the storage portion 1008 as needed.
[0211] The present disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or may exist independently without being assembled into the device / apparatus / system. The above computer-readable storage medium carries one or more programs, and when the above one or more programs are executed, the method according to the embodiment of the present disclosure is implemented.
[0212] According to an embodiment of the present disclosure, a computer-readable storage medium may be a non-volatile computer-readable storage medium, for example, may include but is not limited to: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program, which may be used by or in combination with an instruction execution system, an apparatus or a device. For example, according to an embodiment of the present disclosure, a computer-readable storage medium may include the ROM 1002 and / or RAM 1003 described above and / or one or more memories other than ROM 1002 and RAM 1003.
[0213] The embodiment of the present disclosure also includes a computer program product, which includes a computer program, and the computer program contains program code for executing the method shown in the flowchart. When the computer program product is run in a computer system, the program code is used to enable the computer system to implement the method provided by the embodiment of the present disclosure.
[0214] The above functions defined in the system / device of the embodiment of the present disclosure are performed when the computer program is executed by the processor 1001. According to the embodiment of the present disclosure, the system, device, module, unit, etc. described above can be implemented by a computer program module.
[0215] In one embodiment, the computer program may rely on tangible storage media such as optical storage devices, magnetic storage devices, etc. In another embodiment, the computer program may also be transmitted and distributed in the form of signals on a network medium, and downloaded and installed through the communication part 1009, and / or installed from the removable medium 1011. The program code contained in the computer program may be transmitted using any appropriate network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.
[0216] In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 1009, and / or installed from the removable medium 1011. When the computer program is executed by the processor 1001, the above functions defined in the system of the embodiment of the present disclosure are performed. According to the embodiment of the present disclosure, the system, device, means, module, unit, etc. described above can be implemented by a computer program module.
[0217] According to an embodiment of the present disclosure, the program code for executing the computer program provided by the embodiment of the present disclosure can be written in any combination of one or more programming languages. Specifically, these computing programs can be implemented using high-level process and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, Java, C++, python, "C" language or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, partially on the remote computing device, or entirely on the remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, using an Internet service provider to connect through the Internet).
[0218] The flow charts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flow chart or block diagram can represent a module, a program segment, or a part of a code, and the above-mentioned module, program segment, or a part of a code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flow chart, and the combination of the boxes in the block diagram or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0219] It will be appreciated by those skilled in the art that the features described in the various embodiments and / or claims of the present disclosure may be combined and / or combined in a variety of ways, even if such combinations and / or combinations are not explicitly described in the present disclosure. In particular, the features described in the various embodiments and / or claims of the present disclosure may be combined and / or combined in a variety of ways without departing from the spirit and teachings of the present disclosure. All of these combinations and / or combinations fall within the scope of the present disclosure.
[0220] The embodiments of the present disclosure are described above. However, these embodiments are only for illustrative purposes and are not intended to limit the scope of the present disclosure. Although the embodiments are described above separately, this does not mean that the measures in the various embodiments cannot be used in combination to advantage. The scope of the present disclosure is defined by the attached claims and their equivalents. Without departing from the scope of the present disclosure, those skilled in the art may make a variety of substitutions and modifications, which should all fall within the scope of the present disclosure.
Claims
1. An information processing method, applied to a first server, comprising: Encrypting the first identity attribute plaintext of the first customer using the target public key to obtain the first identity attribute ciphertext; In response to detecting that the first customer enters a preset outlet area corresponding to the service outlet, matching the second identity attribute ciphertext from the second service end with the first identity attribute ciphertext based on a preset ciphertext matching algorithm to obtain a matching result, wherein the second identity attribute ciphertext is ciphertext data obtained after the second service end encrypts the second identity attribute plaintext of the second customer using the target public key; In the case where the matching result indicates that the first customer matches the second customer, encrypting a target query plaintext corresponding to the first customer using the target public key to obtain a target query ciphertext, wherein the target query plaintext is related to a business demand of the first customer for a service outlet corresponding to the preset outlet area, and the second service end is associated with the service outlet; and The target query ciphertext is sent to the second server, and the second server prompts the service outlet to provide business services to the first customer based on the target query ciphertext.
2. The method according to claim 1, wherein: The preset ciphertext matching algorithm includes a privacy intersection algorithm; The second identity attribute ciphertext from the second server is matched with the first identity attribute ciphertext based on a preset ciphertext matching algorithm, and the matching result obtained includes: Determining a privacy intersection between the second identity attribute ciphertext and the first identity attribute ciphertext based on the privacy intersection algorithm; and When the privacy intersection is not empty, a matching result between the first identity attribute ciphertext and the second identity attribute ciphertext is determined to be a first matching result, wherein the first matching result indicates that the first customer matches the second customer.
3. The method according to claim 1, wherein: Before using the target public key to encrypt the target query plaintext corresponding to the first customer to obtain the target query ciphertext, the information processing method further includes: Processing the first communication number in the first identity attribute plaintext based on a preset rule to generate a second communication number associated with the first communication number; The target query plaintext corresponding to the first customer is encrypted using the target public key to obtain the target query ciphertext, which includes: The target public key is used to encrypt the customer identification of the first customer and the second communication number corresponding to the first customer to obtain the target query ciphertext.
4. The method according to claim 3, further comprising: parsing the communication request sent from the second server to obtain the second communication number; as well as According to the association relationship between the second communication number and the first communication number, a communication connection is established between the second service end and the first client corresponding to the first communication number.
5. The method according to claim 1, wherein: The target query plain text includes the customer identification of the first customer and random characters generated based on a random rule; The target query plaintext corresponding to the first customer is encrypted using the target public key to obtain the target query ciphertext including: The target public key is used to encrypt the concatenation result of the customer identification of the first customer and the random characters to obtain the target query ciphertext.
6. The method according to claim 1, wherein: The target query plaintext includes the first identity attribute plaintext and the customer evaluation information of the first customer; The target query plaintext corresponding to the first customer is encrypted using the target public key to obtain the target query ciphertext including: The first identity attribute plaintext and the customer evaluation information of the first customer are encrypted using the target public key to obtain the target query ciphertext.
7. An information processing method, applied to a second server, comprising: Encrypting the second identity attribute plaintext of the second customer using the target public key to obtain the second identity attribute ciphertext; Sending the second identity attribute ciphertext to the first server, wherein the first server determines a matching result between the second identity attribute ciphertext and the first identity attribute ciphertext based on a preset ciphertext matching algorithm, and generates a target query ciphertext corresponding to the first customer when the matching result indicates that the first customer matches the second customer, wherein the target query ciphertext is related to a business demand of the first customer for a service outlet corresponding to a preset outlet area, and the second server is associated with the service outlet; and In response to detecting a target query ciphertext from the first server, the target query ciphertext is decrypted using a target private key corresponding to the target public key to obtain a target query plaintext for the first customer, and the second server prompts the service outlet to provide business services to the first customer based on the target query ciphertext.
8. The method according to claim 7, wherein: The target query plaintext includes a second communication number corresponding to the first customer; The information processing method further includes: generating a communication request for establishing a communication connection with the first client according to the second communication number; as well as Sending the communication request to the first server.
9. The method according to claim 7, further comprising: Send the target public key to the first server.
10. The method according to claim 7, further comprising: Obtaining authorization from the second customer for entering the second identity attribute in plain text; as well as After obtaining the authorization, the second identity attribute is entered in plain text.
11. An information processing device, applied to a first server, comprising: A first encryption module, used to encrypt a first identity attribute plaintext of a first customer using a target public key to obtain a first identity attribute ciphertext; a ciphertext matching module, configured to, in response to detecting that the first customer enters a preset outlet area corresponding to the service outlet, match the second identity attribute ciphertext from the second server with the first identity attribute ciphertext based on a preset ciphertext matching algorithm to obtain a matching result, wherein the second identity attribute ciphertext is ciphertext data obtained after the second server encrypts the second identity attribute plaintext of the second customer using the target public key; a second encryption module, configured to, when the matching result indicates that the first customer matches the second customer, encrypt a target query plaintext corresponding to the first customer using the target public key to obtain a target query ciphertext, wherein the target query plaintext is related to a business demand of the first customer for a service outlet corresponding to the preset outlet area, and the second server is associated with the service outlet; and The first sending module is used to send the target query ciphertext to the second server, and the second server prompts the service outlet to provide business services to the first customer based on the target query ciphertext.
12. An information processing device, applied to a second server, comprising: A third encryption module is used to encrypt the second identity attribute plaintext of the second customer by using the target public key to obtain the second identity attribute ciphertext; a second sending module, configured to send the second identity attribute ciphertext to the first server, wherein the first server determines a matching result between the second identity attribute ciphertext and the first identity attribute ciphertext based on a preset ciphertext matching algorithm, and generates a target query ciphertext corresponding to the first customer when the matching result indicates that the first customer matches the second customer, wherein the target query ciphertext is related to a business demand of the first customer for a service outlet corresponding to a preset outlet area, and the second server is associated with the service outlet; and A decryption module is used to, in response to detecting a target query ciphertext from the first server, decrypt the target query ciphertext using a target private key corresponding to the target public key to obtain a target query plaintext for the first customer, and the second server prompts the service outlet to provide business services to the first customer based on the target query ciphertext.
13. An electronic device comprising: one or more processors; a storage device for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors execute the method according to any one of claims 1 to 10.
14. A computer-readable storage medium having executable instructions stored thereon, which, when executed by a processor, causes the processor to execute the method according to any one of claims 1 to 10.
15. A computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the method according to any one of claims 1 to 10 is implemented.
Citation Information
Patent Citations
Method by utilizing telecommunication network to supply user identity label and user identity authentication to Internet service
CN102437914A
System for performing service by using biometric information, and control method therefor
CN112204549A