Account qualification authentication method and device, equipment, storage medium and product
Patent Information
- Application Number
- CN202211101123.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-09
- Publication Date
- 2026-09-11
- Estimated Expiration
- 2042-09-09
AI Technical Summary
[0004]然而,上述方式仍然难以快速获取到跨境用户可靠的资质认证结果,存在跨境用户资质认证效率低下的问题
Smart Images

Figure CN115619519B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and in particular to an account authentication method, apparatus, computer equipment, storage medium, and computer program product. Background Technology
[0002] With the development of computer technology, cross-border business is increasing. Some overseas users often need to obtain qualifications before conducting cross-border business within China.
[0003] In related technologies, when determining the qualifications of cross-border users, their qualifications can be determined based on the relevant information of the cross-border users within the country, or the cross-border users can also provide relevant evidence of cross-border qualification mutual recognition to assist in the qualification certification process.
[0004] However, the above methods are still insufficient to quickly obtain reliable qualification certification results for cross-border users, resulting in low efficiency in cross-border user qualification certification. Summary of the Invention
[0005] Therefore, it is necessary to provide an account authentication method, apparatus, computer equipment, computer-readable storage medium, and computer program product to address the aforementioned technical problems.
[0006] Firstly, this application provides an account authentication method, the method comprising:
[0007] The system receives a request from an overseas institution to a domestic institution to obtain qualification information carrying an encrypted account identifier; the qualification information request is generated by the overseas institution after receiving the qualification authentication request for the target account from the domestic institution, and the encrypted account identifier is obtained by encrypting the account identifier of the target account;
[0008] In response to the qualification information acquisition request, the asset information of multiple candidate accounts of the domestic institution is obtained, and multiple computing nodes participating in multi-party secure computation are triggered to determine the target asset information associated with the encrypted account identifier from the asset information of the multiple candidate accounts.
[0009] Based on the target asset information, determine the encryption qualification information of the account corresponding to the encrypted account identifier;
[0010] The encrypted qualification information is returned to the overseas institution to trigger the overseas institution to obtain the qualification verification result of the target account overseas based on the encrypted qualification information.
[0011] In one embodiment, the step of obtaining asset information of multiple candidate accounts of the domestic institution in response to the qualification information acquisition request includes:
[0012] In response to the qualification information acquisition request, the original asset information of multiple candidate accounts of the domestic institution is obtained, and the multiple original asset information is segmented to obtain the asset information of multiple candidate accounts after segmentation.
[0013] The asset information after being fragmented from the multiple candidate accounts is encrypted to obtain multiple encrypted asset information fragments;
[0014] The multiple computing nodes that trigger participation in multi-party secure computation determine the target asset information associated with the encrypted account identifier from the asset information of the multiple candidate accounts, including:
[0015] The multiple encrypted asset information fragments are distributed to multiple computing nodes participating in multi-party secure computation, and the multiple computing nodes determine the target asset information associated with the encrypted account identifier from the multiple encrypted asset information fragments.
[0016] In one embodiment, each computing node obtains a portion of the encrypted asset information fragments from the plurality of encrypted asset information fragments. The step of the plurality of computing nodes determining the target asset information associated with the encrypted account identifier from the plurality of encrypted asset information fragments includes:
[0017] For each computing node, the computing node matches the encrypted account identifier with the partial encrypted asset information fragments obtained by the computing node to obtain the target encrypted asset information fragment that matches the encrypted account identifier;
[0018] Based on the target encrypted asset information fragments matched by each of the multiple computing nodes, the target asset information associated with the encrypted account identifier is determined.
[0019] In one embodiment, the step of distributing the plurality of encrypted asset information fragments to multiple computing nodes participating in multi-party secure computation includes:
[0020] Identify the multiple computing nodes participating in secure multi-party computation;
[0021] The multiple encrypted asset information fragments are divided into multiple fragment sets according to a preset secret sharing algorithm; each fragment set includes a portion of the multiple encrypted asset information fragments.
[0022] The multiple shard sets are sent to the multiple computing nodes respectively.
[0023] In one embodiment, determining the encryption qualification information of the account corresponding to the encrypted account identifier based on the target asset information includes:
[0024] Based on the target asset information, determine the initial qualification information of the account corresponding to the encrypted account identifier;
[0025] Obtain reference qualification information from the domestic institution for the account corresponding to the encrypted account identifier;
[0026] Based on the initial qualification information and the reference qualification information, the encrypted qualification information of the account corresponding to the encrypted account identifier is determined.
[0027] In one embodiment, determining the encrypted qualification information of the account corresponding to the encrypted account identifier based on the initial qualification information and the reference qualification information includes:
[0028] If the qualification level corresponding to the initial qualification information is greater than or equal to the qualification level corresponding to the reference qualification information, then based on the qualification level corresponding to the initial qualification information, the encrypted qualification information of the account corresponding to the encrypted account identifier is obtained.
[0029] If the qualification level corresponding to the initial qualification information is lower than the qualification level corresponding to the reference qualification information, then the qualification level corresponding to the initial qualification information is adjusted based on the qualification level corresponding to the reference qualification information, and the encrypted qualification information of the account corresponding to the encrypted account identifier is obtained based on the adjusted qualification level.
[0030] Secondly, this application also provides an account qualification authentication method, the method comprising:
[0031] In response to a qualification authentication request sent from a target account of an overseas institution to a domestic institution, the account identifier of the target account is obtained and encrypted to obtain an encrypted account identifier;
[0032] Send a qualification information acquisition request carrying the encrypted account identifier to the overseas institution; the qualification information acquisition request is used to trigger the overseas institution to acquire asset information of multiple candidate accounts, and multiple computing nodes participating in multi-party secure computation determine the target asset information associated with the encrypted account identifier from the asset information of the multiple candidate accounts, and determine the encrypted qualification information of the account corresponding to the encrypted account identifier based on the target asset information;
[0033] Receive encrypted qualification information returned by the overseas institution, and obtain the qualification certification result of the target account within the territory based on the encrypted qualification information.
[0034] Thirdly, this application also provides an account authentication device, the device comprising:
[0035] The qualification information acquisition request receiving module is used to receive qualification information acquisition requests sent by overseas institutions to domestic institutions, which carry encrypted account identifiers; the qualification information acquisition request is generated by the overseas institution after receiving the qualification authentication request of the target account of the domestic institution, and the encrypted account identifier is obtained by encrypting the account identifier of the target account;
[0036] The multi-party secure computation module is used to respond to the qualification information acquisition request, acquire the asset information of multiple candidate accounts of the domestic institution, and trigger multiple computing nodes participating in the multi-party secure computation to determine the target asset information associated with the encrypted account identifier from the asset information of the multiple candidate accounts.
[0037] The encrypted qualification information acquisition module is used to determine the encrypted qualification information of the account corresponding to the encrypted account identifier based on the target asset information;
[0038] The encrypted qualification information sending module is used to return the encrypted qualification information to the overseas institution, so as to trigger the overseas institution to obtain the qualification authentication result of the target account overseas based on the encrypted qualification information.
[0039] Fourthly, this application also provides an account authentication device, the device comprising:
[0040] The account encryption module is used to respond to the qualification authentication request sent by the target account of the overseas institution to the domestic institution, obtain the account identifier of the target account, and encrypt the account identifier to obtain the encrypted account identifier;
[0041] The qualification information acquisition request sending module is used to send a qualification information acquisition request carrying the encrypted account identifier to the overseas institution; the qualification information acquisition request is used to trigger the overseas institution to acquire asset information of multiple candidate accounts, and multiple computing nodes participating in multi-party secure computation determine the target asset information associated with the encrypted account identifier from the asset information of the multiple candidate accounts, and determine the encrypted qualification information of the account corresponding to the encrypted account identifier based on the target asset information;
[0042] The qualification certification result acquisition module is used to receive encrypted qualification information returned by the overseas institution and obtain the qualification certification result of the target account within the territory based on the encrypted qualification information.
[0043] Fifthly, this application also provides a computer device. The computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the steps of any of the aforementioned account authentication methods.
[0044] Sixthly, this application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, which, when executed by a processor, implements the steps of any of the above-described account authentication methods.
[0045] Seventhly, this application also provides a computer program product. The computer program product includes a computer program that, when executed by a processor, implements the steps of any of the aforementioned account authentication methods.
[0046] The aforementioned qualification authentication methods, devices, computer equipment, storage media, and computer program products allow domestic institutions to receive qualification information acquisition requests carrying encrypted account identifiers sent by overseas institutions to domestic institutions. These qualification information acquisition requests are generated by the overseas institution after receiving a qualification authentication request for a target account from the domestic institution. The encrypted account identifier is obtained by encrypting the target account's account identifier. In response to the qualification information acquisition request, the domestic institution can acquire asset information from multiple candidate accounts and trigger multiple computing nodes participating in multi-party secure computation to determine the target asset information associated with the encrypted account identifier from the asset information of the multiple candidate accounts. Based on the target asset information, the encrypted qualification information of the account corresponding to the encrypted account identifier is determined, and the encrypted qualification information is returned to the overseas institution, thereby triggering the overseas institution to obtain the qualification authentication result of the target account overseas based on the encrypted qualification information. In this proposed solution, when a target account of a domestic institution applies for qualification certification to an overseas institution, the overseas institution can conduct the qualification certification based on the target account's relevant asset information within the domestic institution. Furthermore, by encrypting the target account's identity information during the certification process and then matching the asset information using multi-party secure computation technology, the data security of the target account both domestically and overseas during the qualification certification process can be guaranteed. This approach not only allows for the rapid acquisition of qualification certification results but also prevents the leakage of account information, effectively improving the efficiency of qualification certification. Attached Figure Description
[0047] Figure 1 This is a diagram illustrating the application environment of an account authentication method in one embodiment.
[0048] Figure 2 This is a flowchart illustrating an account qualification authentication method in one embodiment;
[0049] Figure 3 This is a flowchart illustrating one step in obtaining encrypted qualification information in one embodiment;
[0050] Figure 4 This is a flowchart illustrating an account qualification authentication method in another embodiment;
[0051] Figure 5This is an application environment diagram of an account qualification authentication method in another embodiment;
[0052] Figure 6 This is a flowchart illustrating the processing steps of a task authentication and scheduling device in one embodiment;
[0053] Figure 7 This is a flowchart illustrating the processing steps of a data acquisition device in one embodiment;
[0054] Figure 8 This is a flowchart illustrating the processing steps of a data security computing device in one embodiment;
[0055] Figure 9 This is a structural block diagram of an account authentication device in one embodiment;
[0056] Figure 10 This is a structural block diagram of another account authentication device in one embodiment;
[0057] Figure 11 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation
[0058] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0059] It should be noted that the account authentication methods, devices, computer equipment, storage media, and computer program products provided in this application can be applied to the field of information security technology, as well as other related fields.
[0060] The account authentication method provided in this application embodiment can be applied to, for example... Figure 1 In the application environment shown, there may be two types of organizations, which can be referred to as the first organization and the second organization for easy distinction. The first organization and the second organization are located in different customs territories or national borders. Users can apply for a corresponding account with the first organization and apply for corresponding qualification certification from the second organization for that account. This qualification certification can represent the qualification status of the account in the customs territory or national border where the second organization is located.
[0061] The first and second entities may deploy terminals or servers and utilize them for network communication. Each entity may have its own data storage system, which may store account-related information. The terminals may be, but are not limited to, various personal computers, laptops, smartphones, and tablets; the servers may be independent servers or server clusters composed of multiple servers.
[0062] In one embodiment, such as Figure 2 As shown, an account qualification authentication method is provided, which is applied to... Figure 1 Taking the first institution as an example, the explanation includes the following steps:
[0063] S201, receiving a request from an overseas institution to a domestic institution for access to qualification information carrying an encrypted account identifier.
[0064] Specifically, domestic and foreign institutions can be relative. If the first institution is a domestic institution, the second institution can be understood as a foreign institution, and vice versa. In this embodiment, the first institution can be understood as a domestic institution, and the second institution as a foreign institution. The qualification information acquisition request is generated by the foreign institution after receiving a qualification authentication request from the target account of the domestic institution. The encrypted account identifier is obtained by encrypting the target account's account identifier. The target account can be a domestic institution account applying for qualification authentication from a foreign institution and obtaining qualification information from that foreign institution; the target account can also be referred to as a cross-border account.
[0065] In practical applications, users can apply for corresponding accounts with domestic institutions. For example, for the customs territory or national border where the first institution is located, the user can apply for an account using a domestic identity identifier. Then, the user can use this account to apply for overseas qualification certification from overseas institutions and send a qualification certification request to the overseas institution. For example, the user can send a qualification certification request to an overseas institution using an account carrying a domestic identity identifier. The overseas institution can identify that the qualification certification request comes from an account of an institution in another customs territory or national border by reading the identity identifier in the qualification certification request.
[0066] After receiving a qualification authentication request from a target account, an overseas institution can obtain the account identifier of the target account. In some embodiments, the target account can add its corresponding account identifier to the qualification authentication request. For example, the account identifier, which includes the user name, user ID document type, and user ID document number, can be added to the qualification authentication request and sent. In this way, the overseas institution can read the account identifier of the target account from the received qualification authentication request.
[0067] After obtaining the account identifier of the target account, the overseas institution can encrypt the account identifier to obtain the encrypted account identifier corresponding to the target account. After generating a qualification information acquisition request carrying the encrypted account identifier, the institution can send the qualification information acquisition request to the corresponding domestic institution. Specifically, in related technologies, when an institution needs to authenticate the qualifications of accounts from different customs territories or national borders, although it can analyze information such as the asset quality, work, and life trajectory of the user associated with the account within the current institution's territory, there are situations where the assessable information is limited or the information acquisition efficiency is low, affecting the efficiency of qualification authentication. In this embodiment, the overseas institution can send a qualification information acquisition request to the domestic institution where the target account is located, triggering the domestic institution to provide relevant qualification information more quickly and efficiently based on various information about the target account within the territory.
[0068] Furthermore, when overseas institutions request queries from domestic institutions, they provide an encrypted account identifier for the target account. This encrypted account identifier is different from the target account's account identifier. Without providing relevant decryption information, the target account's account identifier cannot be deciphered from the encrypted account identifier. This enables secure calculations for obtaining qualification information and prevents domestic institutions from identifying which account is currently seeking the relevant qualification information.
[0069] S202, in response to the qualification information acquisition request, obtains asset information of multiple candidate accounts of domestic institutions, and triggers multiple computing nodes participating in multi-party secure computation to determine the target asset information associated with the encrypted account identifier from the asset information of multiple candidate accounts.
[0070] Upon receiving a request to obtain qualification information, if the domestic institution cannot determine the corresponding target account based on the encrypted account identifier in the qualification information request due to the lack of relevant decryption information, that is, the domestic institution cannot determine which account the current qualification information request is for, the domestic institution can obtain multiple accounts as candidate accounts. For example, it can be all existing accounts in the system, or multiple accounts with relevant permissions granted.
[0071] After obtaining multiple candidate accounts, asset information of multiple candidate accounts can be obtained. Asset information can be information representing part or all of the assets of the candidate account. For example, asset information can include at least one of the following: asset rating results of domestic institutions for the account, average turnover of the account, asset size, deposits, and wealth management products within a preset period.
[0072] Then, the domestic institution can identify multiple computing nodes participating in the multi-party secure computation and trigger these nodes to determine the target asset information associated with the encrypted account identifier from the asset information of multiple candidate accounts. Multi-party secure computation, also known as secure multi-party computation, primarily addresses the problem of how to securely compute an agreed-upon function in the absence of a trusted third party.
[0073] In this embodiment, the asset information associated with the encrypted account identifier can be determined from the asset information of multiple candidate accounts and used as the function solution target. Multiple computing nodes can determine the target asset information associated with the encrypted account identifier from the asset information of multiple candidate accounts based on existing multi-party secure computation algorithms.
[0074] S203, Determine the encryption qualification information of the account corresponding to the encryption account identifier based on the target asset information.
[0075] Among them, encrypted qualification information refers to qualification information in an encrypted state, and the entire calculation and analysis process of encrypted qualification information can be carried out in an encrypted state.
[0076] After obtaining the target asset information associated with the encrypted account identifier, the domestic institution can determine the asset status corresponding to the target asset information. Based on this asset status, it can then obtain the qualification information of the account corresponding to the encrypted account identifier in an encrypted state, thus obtaining encrypted qualification information. In other words, although the domestic institution may not know the target account indicated by the encrypted account identifier, it can determine that the encrypted account identifier is associated with an account. Through the target asset information of that account within the domestic territory, the domestic institution can assess the encrypted qualification information of the account corresponding to the encrypted account identifier.
[0077] S204 returns encrypted qualification information to overseas institutions to trigger them to obtain the qualification verification results of the target account overseas based on the encrypted qualification information.
[0078] After obtaining the encrypted qualification information, the domestic institution can use the encrypted qualification information as the response data for the qualification information acquisition request and return it to the overseas institution. The overseas institution can then use the encrypted qualification information to determine the qualification certification result of the target account overseas based on the received encrypted qualification information.
[0079] Specifically, after receiving encrypted qualification information, overseas institutions can decrypt it to obtain decrypted qualification information. This decrypted qualification information can serve as the qualification authentication result of the overseas institution (i.e., the second institution) for the target account, and the result can be displayed to the user corresponding to the target account. Relevant staff can also provide corresponding services based on the qualification authentication result.
[0080] In this embodiment, a domestic institution can receive a qualification information acquisition request carrying an encrypted account identifier sent by an overseas institution. This qualification information acquisition request is generated by the overseas institution after receiving a qualification authentication request for a target account from the domestic institution. The encrypted account identifier is obtained by encrypting the target account's account identifier. In response to the qualification information acquisition request, the domestic institution can obtain asset information of multiple candidate accounts and trigger multiple computing nodes participating in multi-party secure computation to determine the target asset information associated with the encrypted account identifier from the asset information of multiple candidate accounts. Based on the target asset information, the encrypted qualification information of the account corresponding to the encrypted account identifier is determined and returned to the overseas institution, thereby triggering the overseas institution to obtain the qualification authentication result of the target account overseas based on the encrypted qualification information. In this application scheme, when a target account of a domestic institution applies for qualification authentication from an overseas institution, the overseas institution can conduct qualification authentication based on the target account's relevant asset information in the domestic institution. Furthermore, by encrypting the target account's identity information during the authentication process and then matching asset information through multi-party secure computation technology, the data security of the target account both overseas and domestically can be guaranteed during the qualification authentication process. This approach avoids account information leakage while quickly obtaining qualification authentication results, effectively improving the efficiency of qualification authentication.
[0081] In one embodiment, S202, in response to a qualification information acquisition request, obtains asset information from multiple candidate accounts of a domestic institution, which may include the following steps:
[0082] In response to the request for qualification information, the system obtains the original asset information of multiple candidate accounts of domestic institutions, and performs fragmentation processing on the multiple original asset information to obtain fragmented asset information of multiple candidate accounts; the fragmented asset information of multiple candidate accounts is then encrypted to obtain multiple encrypted asset information fragments.
[0083] In practical implementation, in response to a request for qualification information, a domestic institution can obtain multiple candidate accounts and determine the original asset information for each candidate account. This original asset information can be pre-stored in a data storage system and can encompass all assets of the corresponding account. After obtaining multiple sets of original asset information, these sets can be fragmented to obtain fragmented asset information for each candidate account. Each candidate account can have multiple fragmented asset information sets; individual or partially fragmented asset information cannot derive the original asset information.
[0084] After obtaining the asset information after sharding multiple candidate accounts, each shard of asset information can be further encrypted to obtain multiple encrypted asset information shards. In other words, in this embodiment, the original asset information of multiple candidate accounts can be sharded and securely encrypted. Each encrypted asset information shard obtained after processing is invisible and cannot be reasoned about. The purpose is to make the asset information of multiple candidate accounts available but invisible (that is, asset information matching can be performed in an encrypted state, but the plaintext displayed is the encrypted result), ensuring that the data cannot be intercepted and decrypted by any party.
[0085] Accordingly, S202 triggers multiple computing nodes participating in multi-party secure computation to determine the target asset information associated with the encrypted account identifier from the asset information of multiple candidate accounts, which may include:
[0086] Multiple encrypted asset information fragments are distributed to multiple computing nodes participating in multi-party secure computation. These computing nodes then determine the target asset information associated with the encrypted account identifier from the multiple encrypted asset information fragments.
[0087] After obtaining multiple fragments of encrypted asset information, these fragments can be distributed to multiple computing nodes participating in multi-party secure computation. These nodes then determine the target asset information associated with the encrypted account identifier from these fragments. During the process of each computing node matching the encrypted asset information fragment associated with the encrypted account identifier, the multiple encrypted asset information fragments remain encrypted throughout the process, and matching is performed based on multi-party secure computation algorithms while still in this encrypted state.
[0088] In this embodiment, by sharding and encrypting the original asset information of multiple candidate accounts, and then distributing it to multiple computing nodes participating in multi-party secure computation for matching, it is possible to ensure that the target asset information associated with the encrypted account identifier is matched even when the asset information of all candidate accounts is in an encrypted state, thus balancing data security and rapid acquisition of the target account's asset information.
[0089] In one embodiment, each computing node obtains a portion of the encrypted asset information fragments from multiple encrypted asset information fragments; that is, a single computing node does not obtain all encrypted asset information fragments. Accordingly, the step of determining the target asset information associated with the encrypted account identifier from the multiple encrypted asset information fragments by multiple computing nodes may include the following steps:
[0090] For each computing node, the computing node matches the encrypted account identifier with the partial encrypted asset information fragments obtained by the computing node to obtain the target encrypted asset information fragments that match the encrypted account identifier; based on the target encrypted asset information fragments matched by multiple computing nodes, the target asset information associated with the encrypted account identifier is determined.
[0091] Specifically, after each computing node obtains a fragment of encrypted asset information, it can match the encrypted account identifier with the encrypted asset information fragment obtained by that computing node while the encrypted asset information fragment is in an encrypted state, to obtain the target encrypted asset information fragment associated with the encrypted account identifier. After each computing node obtains its own encrypted asset information fragment associated with the encrypted account identifier, the matching results of multiple computing nodes can be combined, that is, based on the target encrypted asset information fragments matched by multiple computing nodes, to determine the target asset information associated with the encrypted account identifier. Moreover, when multiple computing nodes perform collaborative computation to determine the target asset information, the entire computation process can be in an encrypted state, that is, each target encrypted asset information fragment and the target asset information can always be in a ciphertext state and have not been decrypted.
[0092] In some examples, each computing node can initiate a data computing contract task during the process of determining the target encrypted asset information fragment. It can use the hidden query technique in multi-party secure computation to perform collision matching between the encrypted account identifier (also known as the target account identity information ciphertext) and the encrypted asset information fragments of multiple candidate accounts (also known as the domestic institution candidate account identity information set ciphertext), and obtain the target encrypted asset information fragment based on the collision matching result.
[0093] In this embodiment, multiple computing nodes can match the corresponding target encrypted asset information fragments respectively, and then through data security collaborative computing, the matching results of multiple computing nodes are combined to obtain the final target asset information. This reduces the risk of asset information in plaintext state being restored by a single computing node and improves data security in the domestic and foreign qualification certification process.
[0094] In one embodiment, distributing multiple pieces of encrypted asset information to multiple computing nodes participating in multi-party secure computation may include the following steps:
[0095] Identify multiple computing nodes participating in multi-party secure computation; divide multiple encrypted asset information fragments into multiple fragment sets according to a preset secret sharing algorithm; and send the multiple fragment sets to the multiple computing nodes respectively.
[0096] Each shard set includes portions of multiple crypto asset information shards.
[0097] In practical applications, domestic institutions can identify multiple computing nodes participating in multi-party secure computation. In one example, computing nodes may include local nodes deployed in domestic institutions (i.e., the first institution), local nodes in overseas institutions (i.e., the second institution), and data center nodes overseas.
[0098] Furthermore, domestic institutions can divide multiple encrypted asset information into multiple fragment sets according to a preset secret sharing algorithm. The secret sharing algorithm is one of the basic algorithms for multi-party secure computation. The technical concept of the secret sharing algorithm is to split secret information in a suitable way, and each fragment is managed or processed by different participants. A single participant cannot recover the secret information; only by the cooperation of several participants can the secret information be recovered.
[0099] In this step, domestic institutions can use a secret-sharing algorithm based on multi-party secure computation technology to divide the currently acquired multiple encrypted asset information fragments into multiple fragment sets. Each fragment set can contain only a portion of the multiple encrypted asset information fragments, and the same encrypted asset information fragment can appear in only one fragment set to avoid duplicate matching. The number of fragment sets can be the same as the number of computation nodes. For example, if three computation nodes are determined, three fragment sets can be set. Furthermore, within the same fragment set, all encrypted asset information fragments from the same candidate account are not included, thereby preventing the situation where the same computation node obtains and decrypts all encrypted asset information from the same candidate account.
[0100] After obtaining multiple shard sets, these shard sets can be sent to multiple compute nodes, and each compute node can obtain one shard set.
[0101] In this embodiment, multiple encrypted asset information fragments can be divided into multiple fragment sets according to a preset secret sharing algorithm, and the multiple fragment sets can be sent to multiple computing nodes respectively. This avoids sending all encrypted asset information fragments to the same computing node, reduces the risk of encrypted asset information fragments being cracked, and increases the security of the data processing process.
[0102] In one embodiment, such as Figure 3 As shown, S203 determines the encryption qualification information of the account corresponding to the encryption account identifier based on the target asset information, which may include the following steps:
[0103] S301, determine the initial qualification information of the account corresponding to the encrypted account identifier based on the target asset information.
[0104] After obtaining the target asset information, since the target asset information can reflect the asset status of the account corresponding to the encrypted account identifier, the domestic institution can assess the creditworthiness of the account corresponding to the encrypted account identifier based on the target asset information, and obtain the initial creditworthiness information of the account corresponding to the encrypted account identifier based on the assessment results. The initial creditworthiness information can be obtained through an assessment method provided by an overseas institution, or it can be determined solely based on asset information stored by the domestic institution.
[0105] For example, domestic institutions can perform encrypted statistics on target asset information associated with encrypted account identifiers. When performing encrypted statistics, they can determine the assessment result of the account corresponding to the encrypted account identifier based on the asset size and / or the average transaction value over a preset time period in the target asset information. For example, they can determine the range to which the asset size and / or the average transaction value over a preset time period belong, determine the preset score for that range, and obtain the assessment result and the corresponding initial qualification information based on the score.
[0106] S302, Obtain reference qualification information from domestic institutions for accounts corresponding to encrypted account identifiers.
[0107] Furthermore, domestic institutions can also obtain reference qualification information associated with the accounts corresponding to the encrypted account identifiers in advance. This reference qualification information can be determined by the staff of the domestic institution based on various information about the accounts corresponding to the encrypted account identifiers. The basis for determining the reference qualification information can be not only the asset information associated with the account in the data storage system, but also other information not stored in the data storage system. For example, it can be the information obtained by staff based on the content of the conversation between the staff and the user.
[0108] In one embodiment, reference qualification information can be used as one of the asset information of candidate accounts and determined by the computing nodes participating in multi-party secure computation. In other words, during the multi-party secure computation process, in addition to matching the asset size, transaction information, and other content of the account corresponding to the encrypted account identifier, reference qualification information corresponding to the encrypted account identifier can also be matched.
[0109] S303, based on initial qualification information and reference qualification information, determine the encrypted qualification information of the account corresponding to the encrypted account identifier.
[0110] After obtaining the initial qualification information and reference qualification information, the qualification information of the account corresponding to the encrypted account identifier can be determined by combining the initial qualification information obtained from the current assessment and the pre-stored reference qualification information. This qualification information can be qualification information in an encrypted state, thus obtaining the encrypted qualification information.
[0111] In this embodiment, multiple qualification information, including initial qualification information and reference qualification information, can be combined to determine the encrypted qualification information of the account corresponding to the encrypted account identifier, effectively improving the reliability and accuracy of the finally obtained encrypted qualification information.
[0112] In one embodiment, S303 determines the encrypted qualification information of the account corresponding to the encrypted account identifier based on the initial qualification information and the reference qualification information, which may include the following steps:
[0113] If the qualification level corresponding to the initial qualification information is greater than or equal to the qualification level corresponding to the reference qualification information, then the encrypted qualification information of the account corresponding to the encrypted account identifier is obtained based on the qualification level corresponding to the initial qualification information; if the qualification level corresponding to the initial qualification information is less than the qualification level corresponding to the reference qualification information, then the qualification level corresponding to the initial qualification information is adjusted based on the qualification level corresponding to the reference qualification information, and the encrypted qualification information of the account corresponding to the encrypted account identifier is obtained based on the adjusted qualification level.
[0114] In practice, qualification information can include the account's qualification level. After obtaining the initial qualification information and the reference qualification information, the qualification level corresponding to the initial qualification information and the qualification level corresponding to the reference qualification information can be obtained and compared.
[0115] If the qualification level corresponding to the initial qualification information is greater than or equal to the qualification level of the reference qualification information, the qualification level corresponding to the initial qualification information can be used as the encrypted qualification information of the account corresponding to the encrypted account identifier. If the qualification level corresponding to the initial qualification information is less than the qualification level of the reference qualification information, the difference between the qualification level corresponding to the initial qualification information and the qualification level of the reference qualification information can be determined. For example, if the qualification level corresponding to the initial qualification information is L1 and the qualification level of the reference qualification information is L, the difference between the two can be obtained based on L-L1, and the adjustment range parameter K can be obtained. The adjustment range parameter K can be a percentage parameter. Then, the adjustment range can be obtained based on the product of the adjustment range parameter and the difference. The qualification level corresponding to the initial qualification level is adjusted using this adjustment range, and the qualification level obtained after adjustment is used as the encrypted qualification information of the account corresponding to the encrypted account identifier. For example, "L1+[(L-L1)*K]" can be determined as the encrypted qualification information.
[0116] In this embodiment, by adjusting the qualification level corresponding to the initial qualification information based on the qualification level corresponding to the reference qualification information, and obtaining the encrypted qualification information of the account corresponding to the encrypted account identifier based on the adjusted qualification level, the comprehensiveness of the qualification level certification result can be improved by further combining the reference qualification information when the account qualification level is low.
[0117] In one embodiment, such as Figure 4As shown, another method for account qualification verification is provided, which can be applied to... Figure 1 Taking the second institution as an example, the explanation includes the following steps:
[0118] S401, in response to a qualification authentication request sent by a target account of an overseas institution to a domestic institution, obtains the account identifier of the target account and encrypts the account identifier to obtain an encrypted account identifier.
[0119] Specifically, domestic and foreign institutions can be relative. If the first institution is a domestic institution, the second institution can be understood as a foreign institution, and vice versa. In this embodiment, the second institution can be understood as a domestic institution, and the first institution as a foreign institution.
[0120] The qualification information acquisition request is generated by the domestic institution after receiving a qualification authentication request from a target account of an overseas institution. The encrypted account identifier is obtained by encrypting the target account's account identifier. The target account can be the account of an overseas institution applying for qualification authentication from a domestic institution and obtaining qualification information from the domestic institution; the target account can also be referred to as a cross-border account.
[0121] In practical applications, users can apply for corresponding accounts at overseas institutions. For example, for the customs territory or national border where the first institution is located, the user can apply for an account using an identity document from that customs territory or national border. Then, the user can use this account to apply for overseas qualification certification from a domestic institution and send a qualification certification request to the domestic institution (i.e., the second institution). For example, the user can send a qualification certification request to a domestic institution using an account carrying an overseas identity document. The domestic institution can identify that the qualification certification request comes from an account of an institution in another customs territory or national border by reading the identity document in the qualification certification request.
[0122] After a domestic institution receives a qualification authentication request from a target account, it can obtain the account identifier of the target account. In some embodiments, the target account can add its corresponding account identifier to the qualification authentication request. For example, the account identifier, which includes the user name, user ID document type, and user ID document number, can be added to the qualification authentication request and sent. Then, the domestic institution can read the account identifier of the target account from the received qualification authentication request.
[0123] After obtaining the account identifier of the target account, the domestic institution can encrypt the account identifier to obtain the encrypted account identifier corresponding to the target account.
[0124] S402, send a request to an overseas institution to obtain qualification information carrying an encrypted account identifier; the qualification information acquisition request is used to trigger the overseas institution to obtain asset information of multiple candidate accounts, and multiple computing nodes participating in multi-party secure computation determine the target asset information associated with the encrypted account identifier from the asset information of multiple candidate accounts, and determine the encrypted qualification information of the account corresponding to the encrypted account identifier based on the target asset information.
[0125] After obtaining the encrypted account identifier, the domestic institution can generate a qualification information retrieval request carrying the encrypted account identifier and send the request to the corresponding overseas institution. Specifically, when requesting a query from the overseas institution, the domestic institution provides an encrypted account identifier of the target account. This encrypted account identifier is different from the target account's original account identifier. Without the relevant decryption information, it is impossible to decipher and recover the target account's original account identifier from the encrypted account identifier. In other words, when the overseas institution receives the qualification information retrieval request, it cannot directly determine the corresponding target account based on the encrypted account identifier. This enables secure computation for qualification information retrieval, preventing the overseas institution from identifying which account is currently seeking the relevant qualification information.
[0126] Upon receiving a request to obtain qualification information, if the overseas institution lacks the relevant decryption information, it cannot determine the corresponding target account based on the encrypted account identifier in the qualification information request. In other words, the overseas institution cannot determine which account the current qualification information request is targeting. Therefore, the overseas institution can obtain multiple accounts as candidate accounts. These could be all existing accounts in the system, or multiple accounts with the relevant permissions granted. After obtaining multiple candidate accounts, the asset information of these candidate accounts can be obtained to determine the multiple computing nodes participating in multi-party secure computation. These computing nodes can then be triggered to determine the target asset information associated with the encrypted account identifier from the asset information of the multiple candidate accounts.
[0127] After obtaining the target asset information associated with the encrypted account identifier, the overseas institution can determine the asset status corresponding to the target asset information. Based on this asset status, it can then obtain the qualification information of the account corresponding to the encrypted account identifier in an encrypted state, thus obtaining encrypted qualification information. In other words, although the overseas institution may not know the target account indicated by the encrypted account identifier, it can determine that the encrypted account identifier is associated with an account. Through the target asset information of that account located overseas, the overseas institution can assess the encrypted qualification information of the account corresponding to the encrypted account identifier.
[0128] S403 receives encrypted qualification information returned by overseas institutions and obtains the qualification certification results of the target account within the territory based on the encrypted qualification information.
[0129] After obtaining encrypted qualification information, the overseas institution can return this information as response data to the domestic institution in response to the qualification information retrieval request. Upon receiving the encrypted qualification information from the overseas institution, the domestic institution can decrypt it and determine the corresponding qualification information of the target account based on the decryption result. Based on this qualification information, the domestic institution can obtain the target account's qualification authentication result within China; for example, the decrypted qualification information can be directly used as the target account's qualification authentication result within China.
[0130] In this embodiment, in response to a qualification authentication request sent by a target account of an overseas institution to the domestic institution, the domestic institution can obtain the account identifier of the target account, encrypt the account identifier to obtain an encrypted account identifier, and then send a qualification information acquisition request carrying the encrypted account identifier to the overseas institution. This request triggers the overseas institution to obtain asset information of multiple candidate accounts. Multiple computing nodes participating in multi-party secure computation determine the target asset information associated with the encrypted account identifier from the asset information of the multiple candidate accounts. Based on the target asset information, the encrypted qualification information of the account corresponding to the encrypted account identifier is determined. Then, the domestic institution can receive the encrypted qualification information returned by the overseas institution and obtain the qualification authentication result of the target account within the domestic territory based on the encrypted qualification information. In this application scheme, when the target account of an overseas institution applies for qualification authentication to the domestic institution, the domestic institution can conduct qualification authentication based on the relevant asset information of the target account in the overseas institution. Furthermore, by encrypting the identity information of the target account during the authentication process and then matching the asset information through multi-party secure computation technology, the data security of the target account both overseas and domestically can be guaranteed during the qualification authentication process. This approach avoids account information leakage while quickly obtaining qualification authentication results, effectively improving the efficiency of qualification authentication.
[0131] To enable those skilled in the art to better understand the above steps, the following example illustrates the embodiments of this application, but it should be understood that the embodiments of this application are not limited thereto.
[0132] like Figure 5 As shown, the second institution may be equipped with an authentication task scheduling device and an authentication result acquisition device, and the first institution may also be equipped with a data acquisition device and a data security computing device. The first institution and the second institution belong to two different national borders or customs territories. For ease of distinction, the national border or customs territory where the first institution is located is referred to as the overseas territory, and the national border or customs territory where the second institution is located is referred to as the domestic territory.
[0133] In practice, cross-border customers can pre-open relevant accounts in their country of origin, i.e., the country or customs territory where the first institution is located. For example, they can open an account with the first institution. When cross-border customers conduct business with the second institution, they can first send a qualification verification request carrying the account identifier to the second institution for qualification verification, so that the second institution can provide corresponding services based on the qualification verification results.
[0134] Upon receiving a qualification verification request, the second institution can encrypt the account identifier to obtain an encrypted account identifier. Then, by requesting qualification information carrying the encrypted account identifier, the first institution can be triggered to provide relevant qualification information for the cross-border client.
[0135] In practice, when a second organization initiates cross-border qualification certification, such as Figure 6 As shown, the operation parameters of the authentication task can be obtained, and corresponding data services can be run according to the operation parameters of the authentication task. In some embodiments, the task authentication device deployed by the second institution can receive the qualification authentication request of the target account, obtain the account identifier of the target account from the qualification authentication request, and obtain the encrypted account identifier after encrypting and transforming the target account. The encrypted account identifier is then input into a pre-created authentication task, and the authentication task is started. This authentication task triggers the overseas institution to obtain relevant qualification information. In practical applications, before starting the authentication task, the relevant operation parameters of the authentication task can be obtained. These operation parameters may include the connection parameters of the first institution, the data service definition of the first institution, the connection parameters of the second institution, the data service definition of the second institution, and the task definition of the authentication task. Furthermore, when starting the authentication task, data services can be run according to the relevant operation parameters. Specifically, this may include running the data service of the second institution according to the connection parameters and the data service definition of the second institution, obtaining the account identifier of the target account (such as user identity information) through this data service. At the same time, data services provided by the first institution can also be run according to the connection parameters and the data service definition of the first institution, sending qualification information acquisition requests through this service, triggering the first institution to obtain relevant qualification information.
[0136] Accordingly, after receiving the second institution's request for access to qualification information, the first institution, as follows: Figure 7 As shown, asset information of multiple accounts (i.e., candidate accounts) in the first institution can be obtained through a data acquisition device, and data security processing can be performed on the asset information of multiple accounts to obtain encrypted asset information fragments of multiple accounts. These encrypted asset information fragments can then be input into a data security computing device. After receiving the multiple encrypted asset information fragments, the data security computing device can process them as follows: Figure 8As shown, multiple encrypted asset information fragments are first input into multiple computing nodes participating in multi-party secure computation. Each computing node only obtains a portion of the encrypted asset information fragments. Then, multiple computing nodes can be triggered to execute a multi-party data security computation contract, performing data security collaborative computation according to the contract rules to match the target encrypted asset information fragment associated with the encrypted account identifier. The final result, i.e., the target asset information associated with the account corresponding to the encrypted account identifier, can then be obtained from the target encrypted asset information fragments matched by multiple computing nodes. After obtaining the target asset information, the data security computation device can determine the encrypted qualification information corresponding to the target asset information and send it to the authentication result acquisition device of a second institution. Furthermore, multiple fragments used in the computation process can be deleted, enabling account qualification rating calculations to be completed without the account information leaving the country.
[0137] After receiving the encrypted qualification information, the authentication result acquisition device can decrypt it and obtain the qualification authentication result of the cross-border customer based on the decryption result.
[0138] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0139] Based on the same inventive concept, this application also provides an account authentication device for implementing the account authentication method described above. The solution provided by this device is similar to the solution described in the above method; therefore, the specific limitations in one or more account authentication device embodiments provided below can be found in the limitations of the account authentication method described above, and will not be repeated here.
[0140] In one embodiment, such as Figure 9 As shown, an account authentication device is provided, comprising:
[0141] The qualification information acquisition request receiving module 901 is used to receive a qualification information acquisition request sent by an overseas institution to a domestic institution, which carries an encrypted account identifier; the qualification information acquisition request is generated by the overseas institution after receiving the qualification authentication request of the target account of the domestic institution, and the encrypted account identifier is obtained by encrypting the account identifier of the target account;
[0142] The multi-party secure computation module 902 is used to respond to the qualification information acquisition request, acquire the asset information of multiple candidate accounts of the domestic institution, and trigger multiple computing nodes participating in the multi-party secure computation to determine the target asset information associated with the encrypted account identifier from the asset information of the multiple candidate accounts.
[0143] The encryption qualification information acquisition module 903 is used to determine the encryption qualification information of the account corresponding to the encryption account identifier based on the target asset information;
[0144] The encrypted qualification information sending module 904 is used to return the encrypted qualification information to the overseas institution, so as to trigger the overseas institution to obtain the qualification authentication result of the target account overseas based on the encrypted qualification information.
[0145] In one embodiment, the multi-party secure computation module 902 includes:
[0146] The information sharding submodule is used to respond to the qualification information acquisition request, acquire the original asset information of multiple candidate accounts of the domestic institution, and shard the multiple original asset information to obtain the asset information of multiple candidate accounts after sharding.
[0147] The encryption submodule is used to encrypt the asset information after the multiple candidate accounts are fragmented, so as to obtain multiple encrypted asset information fragments;
[0148] The sharding and distribution submodule is used to shard the multiple encrypted asset information to multiple computing nodes participating in multi-party secure computation, and the multiple computing nodes determine the target asset information associated with the encrypted account identifier from the multiple encrypted asset information shards.
[0149] In one embodiment, each computing node obtains a portion of the encrypted asset information fragments from the plurality of encrypted asset information fragments, and the fragment distribution submodule is specifically used for:
[0150] For each computing node, the computing node matches the encrypted account identifier with the partial encrypted asset information fragments obtained by the computing node to obtain the target encrypted asset information fragment that matches the encrypted account identifier;
[0151] Based on the target encrypted asset information fragments matched by each of the multiple computing nodes, the target asset information associated with the encrypted account identifier is determined.
[0152] In one embodiment, the sharding distribution submodule is specifically used for:
[0153] Identify the multiple computing nodes participating in secure multi-party computation;
[0154] The multiple encrypted asset information fragments are divided into multiple fragment sets according to a preset secret sharing algorithm; each fragment set includes a portion of the multiple encrypted asset information fragments.
[0155] The multiple shard sets are sent to the multiple computing nodes respectively.
[0156] In one embodiment, the encryption qualification information acquisition module 903 includes:
[0157] The initial qualification information acquisition submodule is used to determine the initial qualification information of the account corresponding to the encrypted account identifier based on the target asset information;
[0158] The reference qualification information acquisition submodule is used to acquire the reference qualification information of the domestic institution for the account corresponding to the encrypted account identifier;
[0159] The encrypted qualification information determination submodule is used to determine the encrypted qualification information of the account corresponding to the encrypted account identifier based on the initial qualification information and the reference qualification information.
[0160] In one embodiment, the encryption qualification information determination submodule is specifically used for:
[0161] If the qualification level corresponding to the initial qualification information is greater than or equal to the qualification level corresponding to the reference qualification information, then based on the qualification level corresponding to the initial qualification information, the encrypted qualification information of the account corresponding to the encrypted account identifier is obtained.
[0162] If the qualification level corresponding to the initial qualification information is lower than the qualification level corresponding to the reference qualification information, then the qualification level corresponding to the initial qualification information is adjusted based on the qualification level corresponding to the reference qualification information, and the encrypted qualification information of the account corresponding to the encrypted account identifier is obtained based on the adjusted qualification level.
[0163] In one embodiment, such as Figure 10 As shown, another account authentication device is provided, including:
[0164] The account encryption module 1001 is used to respond to the qualification authentication request sent by the target account of the overseas institution to the domestic institution, obtain the account identifier of the target account, and encrypt the account identifier to obtain the encrypted account identifier;
[0165] The qualification information acquisition request sending module 1002 is used to send a qualification information acquisition request carrying the encrypted account identifier to the overseas institution; the qualification information acquisition request is used to trigger the overseas institution to acquire asset information of multiple candidate accounts, and multiple computing nodes participating in multi-party secure computation determine the target asset information associated with the encrypted account identifier from the asset information of the multiple candidate accounts, and determine the encrypted qualification information of the account corresponding to the encrypted account identifier based on the target asset information;
[0166] The qualification certification result acquisition module 1003 is used to receive encrypted qualification information returned by the overseas institution and obtain the qualification certification result of the target account within the territory based on the encrypted qualification information.
[0167] Each module in the aforementioned account authentication device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the corresponding operations of each module.
[0168] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 11 As shown, the computer device includes a processor, memory, and a network interface connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. The database stores account data. The network interface communicates with external terminals via a network connection. When executed by the processor, the computer program implements an account authentication method.
[0169] Those skilled in the art will understand that Figure 11 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0170] In one embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:
[0171] The system receives a request from an overseas institution to a domestic institution to obtain qualification information carrying an encrypted account identifier; the qualification information request is generated by the overseas institution after receiving the qualification authentication request for the target account from the domestic institution, and the encrypted account identifier is obtained by encrypting the account identifier of the target account;
[0172] In response to the qualification information acquisition request, the asset information of multiple candidate accounts of the domestic institution is obtained, and multiple computing nodes participating in multi-party secure computation are triggered to determine the target asset information associated with the encrypted account identifier from the asset information of the multiple candidate accounts.
[0173] Based on the target asset information, determine the encryption qualification information of the account corresponding to the encrypted account identifier;
[0174] The encrypted qualification information is returned to the overseas institution to trigger the overseas institution to obtain the qualification verification result of the target account overseas based on the encrypted qualification information.
[0175] In one embodiment, the processor also performs the steps described in the other embodiments when executing the computer program.
[0176] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, the computer program performing the following steps when executed by a processor:
[0177] The system receives a request from an overseas institution to a domestic institution to obtain qualification information carrying an encrypted account identifier; the qualification information request is generated by the overseas institution after receiving the qualification authentication request for the target account from the domestic institution, and the encrypted account identifier is obtained by encrypting the account identifier of the target account;
[0178] In response to the qualification information acquisition request, the asset information of multiple candidate accounts of the domestic institution is obtained, and multiple computing nodes participating in multi-party secure computation are triggered to determine the target asset information associated with the encrypted account identifier from the asset information of the multiple candidate accounts.
[0179] Based on the target asset information, determine the encryption qualification information of the account corresponding to the encrypted account identifier;
[0180] The encrypted qualification information is returned to the overseas institution to trigger the overseas institution to obtain the qualification verification result of the target account overseas based on the encrypted qualification information.
[0181] In one embodiment, the computer program, when executed by a processor, also implements the steps described in the other embodiments above.
[0182] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, performs the following steps:
[0183] The system receives a request from an overseas institution to a domestic institution to obtain qualification information carrying an encrypted account identifier; the qualification information request is generated by the overseas institution after receiving the qualification authentication request for the target account from the domestic institution, and the encrypted account identifier is obtained by encrypting the account identifier of the target account;
[0184] In response to the qualification information acquisition request, the asset information of multiple candidate accounts of the domestic institution is obtained, and multiple computing nodes participating in multi-party secure computation are triggered to determine the target asset information associated with the encrypted account identifier from the asset information of the multiple candidate accounts.
[0185] Based on the target asset information, determine the encryption qualification information of the account corresponding to the encrypted account identifier;
[0186] The encrypted qualification information is returned to the overseas institution to trigger the overseas institution to obtain the qualification verification result of the target account overseas based on the encrypted qualification information.
[0187] In one embodiment, the computer program, when executed by a processor, also implements the steps described in the other embodiments above.
[0188] In one embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:
[0189] In response to a qualification authentication request sent from a target account of an overseas institution to a domestic institution, the account identifier of the target account is obtained and encrypted to obtain an encrypted account identifier;
[0190] Send a qualification information acquisition request carrying the encrypted account identifier to the overseas institution; the qualification information acquisition request is used to trigger the overseas institution to acquire asset information of multiple candidate accounts, and multiple computing nodes participating in multi-party secure computation determine the target asset information associated with the encrypted account identifier from the asset information of the multiple candidate accounts, and determine the encrypted qualification information of the account corresponding to the encrypted account identifier based on the target asset information;
[0191] Receive encrypted qualification information returned by the overseas institution, and obtain the qualification certification result of the target account within the territory based on the encrypted qualification information.
[0192] In one embodiment, the processor also performs the steps described in the other embodiments when executing the computer program.
[0193] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, the computer program performing the following steps when executed by a processor:
[0194] In response to a qualification authentication request sent from a target account of an overseas institution to a domestic institution, the account identifier of the target account is obtained and encrypted to obtain an encrypted account identifier;
[0195] Send a qualification information acquisition request carrying the encrypted account identifier to the overseas institution; the qualification information acquisition request is used to trigger the overseas institution to acquire asset information of multiple candidate accounts, and multiple computing nodes participating in multi-party secure computation determine the target asset information associated with the encrypted account identifier from the asset information of the multiple candidate accounts, and determine the encrypted qualification information of the account corresponding to the encrypted account identifier based on the target asset information;
[0196] Receive encrypted qualification information returned by the overseas institution, and obtain the qualification certification result of the target account within the territory based on the encrypted qualification information.
[0197] In one embodiment, the computer program, when executed by a processor, also implements the steps described in the other embodiments above.
[0198] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, performs the following steps:
[0199] In response to a qualification authentication request sent from a target account of an overseas institution to a domestic institution, the account identifier of the target account is obtained and encrypted to obtain an encrypted account identifier;
[0200] Send a qualification information acquisition request carrying the encrypted account identifier to the overseas institution; the qualification information acquisition request is used to trigger the overseas institution to acquire asset information of multiple candidate accounts, and multiple computing nodes participating in multi-party secure computation determine the target asset information associated with the encrypted account identifier from the asset information of the multiple candidate accounts, and determine the encrypted qualification information of the account corresponding to the encrypted account identifier based on the target asset information;
[0201] Receive encrypted qualification information returned by the overseas institution, and obtain the qualification certification result of the target account within the territory based on the encrypted qualification information.
[0202] In one embodiment, the computer program, when executed by a processor, also implements the steps described in the other embodiments above.
[0203] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.
[0204] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.
[0205] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0206] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. An account qualification authentication method, characterized in that, The method includes: The system receives a request from an overseas institution to a domestic institution to obtain qualification information carrying an encrypted account identifier; the qualification information request is generated by the overseas institution after receiving the qualification authentication request for the target account from the domestic institution, and the encrypted account identifier is obtained by encrypting the account identifier of the target account; In response to the qualification information acquisition request, the system acquires the original asset information of multiple candidate accounts of the domestic institution, and performs fragmentation processing on the multiple original asset information to obtain fragmented asset information of multiple candidate accounts. The fragmented asset information of multiple candidate accounts is then encrypted to obtain multiple encrypted asset information fragments. The multiple encrypted asset information fragments are distributed to multiple computing nodes participating in multi-party secure computation, and the multiple computing nodes determine the target asset information associated with the encrypted account identifier from the multiple encrypted asset information fragments. Based on the target asset information, determine the encryption qualification information of the account corresponding to the encrypted account identifier; The encrypted qualification information is returned to the overseas institution to trigger the overseas institution to obtain the qualification verification result of the target account overseas based on the encrypted qualification information.
2. The method according to claim 1, characterized in that, Each computing node obtains a portion of the encrypted asset information fragments from the plurality of encrypted asset information fragments. The step of the plurality of computing nodes determining the target asset information associated with the encrypted account identifier from the plurality of encrypted asset information fragments includes: For each computing node, the computing node matches the encrypted account identifier with the partial encrypted asset information fragments obtained by the computing node to obtain the target encrypted asset information fragment that matches the encrypted account identifier; Based on the target encrypted asset information fragments matched by each of the multiple computing nodes, the target asset information associated with the encrypted account identifier is determined.
3. The method according to claim 1, characterized in that, The step of distributing the multiple encrypted asset information fragments to multiple computing nodes participating in multi-party secure computation includes: Identify the multiple computing nodes participating in secure multi-party computation; The multiple encrypted asset information fragments are divided into multiple fragment sets according to a preset secret sharing algorithm; each fragment set includes a portion of the multiple encrypted asset information fragments. The multiple shard sets are sent to the multiple computing nodes respectively.
4. The method according to claim 1, characterized in that, The step of determining the encryption qualification information of the account corresponding to the encryption account identifier based on the target asset information includes: Based on the target asset information, determine the initial qualification information of the account corresponding to the encrypted account identifier; Obtain reference qualification information from the domestic institution for the account corresponding to the encrypted account identifier; Based on the initial qualification information and the reference qualification information, the encrypted qualification information of the account corresponding to the encrypted account identifier is determined.
5. The method according to claim 4, characterized in that, The step of determining the encrypted qualification information of the account corresponding to the encrypted account identifier based on the initial qualification information and the reference qualification information includes: If the qualification level corresponding to the initial qualification information is greater than or equal to the qualification level corresponding to the reference qualification information, then based on the qualification level corresponding to the initial qualification information, the encrypted qualification information of the account corresponding to the encrypted account identifier is obtained. If the qualification level corresponding to the initial qualification information is lower than the qualification level corresponding to the reference qualification information, then the qualification level corresponding to the initial qualification information is adjusted based on the qualification level corresponding to the reference qualification information, and the encrypted qualification information of the account corresponding to the encrypted account identifier is obtained based on the adjusted qualification level.
6. An account qualification authentication method, characterized in that, The method includes: In response to a qualification authentication request sent from a target account of an overseas institution to a domestic institution, the account identifier of the target account is obtained and encrypted to obtain an encrypted account identifier; A request to obtain qualification information carrying the encrypted account identifier is sent to the overseas institution. The qualification information acquisition request is used to trigger the overseas institution to obtain the original asset information of multiple candidate accounts, and to perform fragment processing on the multiple original asset information to obtain asset information fragmented from multiple candidate accounts. The asset information fragmented from multiple candidate accounts is encrypted to obtain multiple encrypted asset information fragments. The multiple encrypted asset information fragments are distributed to multiple computing nodes participating in multi-party secure computation. The multiple computing nodes determine the target asset information associated with the encrypted account identifier from the multiple encrypted asset information fragments, and determine the encrypted qualification information of the account corresponding to the encrypted account identifier based on the target asset information. Receive encrypted qualification information returned by the overseas institution, and obtain the qualification certification result of the target account within the territory based on the encrypted qualification information.
7. An account authentication device, characterized in that, The device includes: The qualification information acquisition request receiving module is used to receive qualification information acquisition requests sent by overseas institutions to domestic institutions, which carry encrypted account identifiers; the qualification information acquisition request is generated by the overseas institution after receiving the qualification authentication request of the target account of the domestic institution, and the encrypted account identifier is obtained by encrypting the account identifier of the target account; The multi-party secure computation module is used to respond to the qualification information acquisition request, acquire the original asset information of multiple candidate accounts of the domestic institution, and perform fragmentation processing on the multiple original asset information to obtain fragmented asset information of multiple candidate accounts. The fragmented asset information of multiple candidate accounts is then encrypted to obtain multiple encrypted asset information fragments. The multiple encrypted asset information fragments are distributed to multiple computing nodes participating in the multi-party secure computation, and the multiple computing nodes determine the target asset information associated with the encrypted account identifier from the multiple encrypted asset information fragments. The encrypted qualification information acquisition module is used to determine the encrypted qualification information of the account corresponding to the encrypted account identifier based on the target asset information; The encrypted qualification information sending module is used to return the encrypted qualification information to the overseas institution, so as to trigger the overseas institution to obtain the qualification authentication result of the target account overseas based on the encrypted qualification information.
8. An account authentication device, characterized in that, The device includes: The account encryption module is used to respond to the qualification authentication request sent by the target account of the overseas institution to the domestic institution, obtain the account identifier of the target account, and encrypt the account identifier to obtain the encrypted account identifier; The qualification information acquisition request sending module is used to send a qualification information acquisition request carrying the encrypted account identifier to the overseas institution. The qualification information acquisition request is used to trigger the overseas institution to acquire the original asset information of multiple candidate accounts, and to perform fragment processing on the multiple original asset information to obtain fragmented asset information of multiple candidate accounts. The fragmented asset information of multiple candidate accounts is then encrypted to obtain multiple encrypted asset information fragments. The multiple encrypted asset information fragments are distributed to multiple computing nodes participating in multi-party secure computation. The multiple computing nodes determine the target asset information associated with the encrypted account identifier from the multiple encrypted asset information fragments, and determine the encrypted qualification information of the account corresponding to the encrypted account identifier based on the target asset information. The qualification certification result acquisition module is used to receive encrypted qualification information returned by the overseas institution and obtain the qualification certification result of the target account within the territory based on the encrypted qualification information.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.
11. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Data processing method and system based on core interconnection system, equipment and medium
CN110298648A
Information processing method and device, equipment and storage medium
CN114844694A