Order processing method of e-commerce system under global quantum secure network
By utilizing XOR encryption and key management within a quantum-secure network, the privacy of order information in e-commerce systems is protected, solving the problem of order information leakage and improving the security of e-commerce systems.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- MATRICTIME DIGITAL TECH CO LTD
- Filing Date
- 2023-06-13
- Publication Date
- 2026-04-14
AI Technical Summary
Order information in e-commerce systems is easily leaked. Existing digital signature technology based on public-key cryptography faces security threats in the era of quantum computing and cannot effectively protect user privacy.
In a fully quantum-secure network, the order processing takes place between the client and the server in a secure zone. Through XOR encryption and key management in the quantum-secure network, information is kept confidential in the non-secure zone, and data is transmitted via a one-way transfer interface.
It ensures the privacy of order information, guaranteeing that it is only visible to users and merchants, preventing information leakage, and improving the security of the e-commerce system.
Smart Images

Figure CN116633657B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of quantum information security, specifically to an order processing method for an e-commerce system under a global quantum-secure network. Background Technology
[0002] Today, the internet has become an important channel for people to shop and businesses to sell goods, and there are numerous websites that provide online sales services. The emergence of e-commerce has transformed traditional lifestyles, facilitating shopping, sales, settlements, and economic transactions between business people, greatly accelerating and enriching our access to various products and services.
[0003] Due to the openness of the internet, orders in e-commerce systems are easily leaked. In addition to product information, orders also include users' personal information such as phone numbers and addresses. Therefore, leaked orders could potentially lead to the leakage of user privacy.
[0004] Patent application number 201610275264.7 proposes using QR codes to replace traditional text orders. The QR code contains personal delivery information encrypted using a digital envelope, an order number encrypted using the consumer's public key, and a digital signature from the logistics company. The digital signature technology in this patent is based on a public-private key cryptography system, which faces serious security threats in today's world of rapidly advancing computing power and algorithms, especially quantum computing.
[0005] Therefore, it is necessary to propose a more secure order processing method suitable for e-commerce systems to ensure user information security throughout the entire e-commerce process. Summary of the Invention
[0006] Purpose of the invention: To solve the problem of order information leakage in e-commerce systems, this invention provides an order processing method for e-commerce systems under a fully quantum-secure network. By generating orders in a secure area and having the client and server secure areas interact with each other, the order processing process is elevated to a quantum-secure level.
[0007] Technical Solution: This invention provides an order processing method for an e-commerce system under a fully quantum-secure network. The method involves a client and a server. The client receives instructions from consumers, including a first unsecured area C1 and a first secure area C2, which communicate via a first interface. The server receives instructions from merchants, including a second unsecured area S1 and a second secure area S2, which communicate via a second interface. The method includes the following steps:
[0008] Step 1: The server receives instructions from the merchant to publish multiple products in the second non-secure zone S1 on the server, and the multiple products are displayed in the first non-secure zone C1 on the client.
[0009] Step 2: The client's first secret zone C2 generates a confirmation information doc1 based on the product information selected by the consumer and the consumer's identity information;
[0010] Step 3: The first secret zone C2 uses XOR encryption. The first encryption key a is used to encrypt the message doc1 to be confirmed, resulting in the encrypted message to be confirmed. The encrypted confirmation information doc1' is then sent to the server's second secure zone S2 via a quantum-safe network.
[0011] Step 4: The second secret zone S2 of the server receives the encrypted information to be confirmed, doc1', and decrypts the encrypted information to be confirmed, doc1', using the first decryption key a' corresponding to the first encryption key a in the first secret zone C2, to obtain the information to be confirmed, doc1; the second secret zone S2 generates an order based on the information to be confirmed, doc1.
[0012] As an improvement of the present invention, the first interface can only realize the one-way data transfer function from the first non-secret area C1 to the first secret area C2; the second interface can only realize the one-way data transfer function from the second non-secret area S1 to the second secret area S2.
[0013] As an improvement of the present invention, in step Step 2, the specific process by which the first secret area C2 of the client generates the confirmation information doc1 based on the product information selected by the consumer and the consumer's identity information includes:
[0014] The client receives an instruction from the consumer to select one or more products from the plurality of products, and transmits the product information selected by the consumer and the consumer's identity information unidirectionally from the first non-secure zone C1 to the first secure zone C2 through the first interface. The first secure zone C2 generates a confirmation information doc1 based on the received product information and consumer identity information. The product information selected by the consumer includes the product's model, style, quantity, name of the merchant to which the product belongs, and the merchant's payment information. The consumer's identity information includes the consumer's account, contact information, and delivery address.
[0015] As an improvement of the present invention, in step Step 2, the specific process by which the first secret area C2 of the client generates the confirmation information doc1 based on the product information selected by the consumer and the consumer's identity information includes:
[0016] The client generates sub-public information in the first unsecured area C1 and sub-private information in the first secure area C2. Then, the client's first unsecured area C1 transmits the sub-public information to the first secure area C2 through the first interface. The first secure area C2 receives the sub-public information and integrates it with the sub-private information stored in itself to form complete information to be confirmed, doc1. The sub-public information includes the product's model, style, quantity, and the name of the merchant to which the product belongs. The sub-private information includes the consumer's account, contact information, address, and the merchant's payment information.
[0017] As an improvement of the present invention, in step 4, the method of generating the order includes:
[0018] Step (1): The second secret zone S2 generates an order to be confirmed, doc2, based on the information to be confirmed, doc1;
[0019] Step (2): The second secret zone S2 uses XOR encryption to encrypt the order to be confirmed, doc2, using the second encryption key b, to obtain the encrypted order to be confirmed. And send the encrypted order to be confirmed, doc2', to the first secure zone C2;
[0020] Step (3): The first secret zone C2 receives the encrypted order to be confirmed doc2', and performs a decryption operation using the second decryption key b' corresponding to the second encryption key b, to obtain the order to be confirmed doc2; the consumer performs a confirmation operation on the decrypted order to be confirmed doc2 in the first secret zone S2;
[0021] Step (4): After the consumer confirms, the first secret zone C2 encrypts the confirmation information and sends it to the second secret zone S2;
[0022] Step (5): The second secret zone S2 generates a confirmed order based on the received confirmation information and the unconfirmed order doc2, and generates an order number for the confirmed order to complete the order processing process.
[0023] As an improvement of the present invention, in step (1), the specific process of the second secret area S2 generating the order to be confirmed doc2 based on the information to be confirmed doc1 is as follows:
[0024] The second secret zone S2 verifies the information to be confirmed after decryption:
[0025] When the information to be confirmed passes the verification, the second secret zone S2 generates the order to be confirmed, doc2.
[0026] When the information to be confirmed fails the verification, the second secret zone S2 returns the information to be confirmed to the first secret zone C2. The first secret zone C2 receives the consumer's instruction to modify the information to be confirmed in order to generate new information to be confirmed. Based on the new information to be confirmed, steps step3 and step (1) are re-executed until the new information to be confirmed passes the verification. The second secret zone S2 then generates the order to be confirmed, doc2.
[0027] As an improvement of the present invention, in step 4, the method of generating the order includes:
[0028] Step (1): The second secret zone S2 on the server uses the first decryption key a' to decrypt the encrypted message doc1' to obtain the message doc1:
[0029] Step (1)-1: The client's first secret zone C2 generates a first order to be confirmed, doc3, based on the information to be confirmed, doc1;
[0030] Step (1)-2: The second secret zone S2 on the server generates a second order to be confirmed, doc4, based on the information to be confirmed, doc1;
[0031] Step (2): The first secret zone C2 and the second secret zone S2 share a key and use the same hash algorithm to generate the same hash function H. p,s The first secret zone C2 uses the hash function H. p,s Calculate the first hash value of the first pending order doc3: hash1 = H p,s (doc3), the second secret zone S2 uses the hash function H. p,s Calculate the second hash value of the second pending order doc4: hash2 = H p,s (doc4);
[0032] Step (3): The first secret zone C2 is XORed with the third encryption key c obtained from the key pool or locally to encrypt the first hash value hash1, resulting in the encrypted hash value. And send it to the second secret zone S2;
[0033] Step (4): The second secret zone S2 decrypts the received encrypted first hash value hash1' to obtain the first hash value hash1; the decrypted first hash value hash1 is compared with the second hash value hash2 calculated in step (2):
[0034] If the comparison results are consistent, the second secret zone S2 generates a confirmation order based on the second unconfirmed order doc4;
[0035] If the comparison results are inconsistent, the first secret zone C2 receives the consumer's instruction to modify the information to be confirmed and generates new information to be confirmed. Based on the new information to be confirmed, it returns to the execution steps (1)-(4) until the first hash value is consistent with the second hash value. Thus, the second secret zone S2 generates a confirmed order based on the second order to be confirmed, doc4.
[0036] As an improvement of the present invention, the information to be confirmed, doc1, also includes an information number.
[0037] As an improvement of the present invention, in step 3, the first encryption key a is obtained in advance from the key pool in the quantum secure network and stored in the first secret zone C2, and the second secret zone S2 stores the first decryption key a' that is paired with the key in the first secret zone C2.
[0038] As an improvement of the present invention, in step 3, if the first secret zone C2 and the second secret zone S2 do not have keys stored in advance, after the first secret zone C2 generates the confirmation information doc1, the first secret zone C2 sends a key request information to the key pool in the quantum security network. The key pool responds to the key request information and sends the paired first encryption key a and first decryption key a' to the first secret zone C2 and the second secret zone S2 respectively.
[0039] The beneficial effects of this invention are as follows: This invention proposes an order processing method for an e-commerce system under a global quantum secure network. Orders are transmitted between secure zones and will not be disclosed in unsecured zones. This ensures that the information in a user's order is only visible to the user and the merchant, thus guaranteeing the privacy of the order information. Attached Figure Description
[0040] Figure 1 This is a schematic diagram of an e-commerce system under a global quantum-secure network according to the present invention;
[0041] Figure 2 This is a flowchart illustrating an order processing method for an e-commerce system under a global quantum-secure network, according to the present invention.
[0042] Figure 3 This is a flowchart illustrating another order processing method for an e-commerce system under a global quantum-secure network according to the present invention.
[0043] Figure 4 This is a schematic diagram of another e-commerce system under a global quantum-secure network according to the present invention. Detailed Implementation
[0044] The present invention will be further described below with reference to the accompanying drawings and embodiments.
[0045] In e-commerce systems, consumers obtain detailed product information, such as product images, manufacturer information, and model details, through their own client applications. Merchants, on the other hand, publish detailed product information through their own server applications, allowing consumers to search for the products online.
[0046] Because consumers have privacy requirements for their orders—that is, the order should only be visible to the consumer and the merchant, and not to other consumers or merchants in the network—the privacy of consumer orders needs to be ensured by operating within a fully quantum-secure network. This fully quantum-secure network can provide services such as CA authentication capabilities, keys required for communication, and hash calculations for both the client and server.
[0047] Example 1:
[0048] like Figure 1 As shown, in a fully quantum-secure network, both the client and server have registered their identities within the network, with authentication services provided by quantum CA devices. Authenticated clients and servers can then prove their legitimacy and proceed with order processing.
[0049] The client can include a first unsecured zone C1 and a first secure zone C2. The first unsecured zone C1 can be deployed in an internet environment, and operations within it can be performed in an unencrypted environment, such as searching for products or browsing product information. The first secure zone C2 must be deployed in a quantum-secure network, and all operations within it are quantum-encrypted to ensure data privacy. The first unsecured zone C1 and the first secure zone C2 communicate via a first interface, which only allows for one-way data transfer from the first unsecured zone C1 to the first secure zone C2.
[0050] Similarly, the server can also include a second unencrypted zone S1 and a second encrypted zone S2. The second unencrypted zone S1 can be deployed in an internet environment to perform operations that do not require encryption, such as merchants publishing product information. The second encrypted zone S2 must be deployed in a quantum-secure network, and all operations within it are quantum-encrypted to ensure data privacy. The second unencrypted zone S1 and the second encrypted zone S2 communicate via a second interface, which only allows for one-way data transfer between the second unencrypted zone S1 and the second encrypted zone S2.
[0051] This invention uses the example of a consumer placing a privacy-preserving order to illustrate an order processing method for an e-commerce system under a fully quantum-secure network. Figure 2 As shown, the method may include the following steps:
[0052] Step 1: The server receives instructions from the merchant to publish multiple products in the second unsecured zone S1 on the server. These multiple products can be displayed in the first unsecured zone C1 on the client for consumers to browse and select.
[0053] Since the purpose of merchants publishing products is to allow a wide range of consumers to obtain product information, the product display here does not need to be encrypted. The interaction between the first unencrypted zone C1 and the second unencrypted zone S1 can be carried out freely on the Internet.
[0054] Step 2: The client's first secret zone C2 generates confirmation information based on the product information selected by the consumer and the consumer's identity information.
[0055] In some embodiments, the client receives an instruction from a consumer to select one or more products from a plurality of products, and transmits the selected product information and the consumer's identity information unidirectionally from the first non-secured area C1 to the first secure area C2 through a first interface. The selected product information may include the product's model, style, quantity, the name of the seller, and the seller's payment information. The consumer's identity information may include the consumer's account, contact information, and shipping address. The first secure area C2 generates confirmation information based on the received information.
[0056] In other embodiments, the client can generate sub-public information in the first unsecured area C1 and sub-private information in the first secure area C2. The sub-public information includes public product information such as the product model, style, quantity, and merchant name, while the sub-private information includes consumer privacy information such as the consumer's account, contact information, and address, and merchant privacy information such as the merchant's payment information. Then, the client's first unsecured area C1 transmits the sub-public information to the first secure area C2 through a first interface. The first secure area C2 receives the sub-public information and integrates it with its stored sub-private information to form complete information to be confirmed, denoted as doc1.
[0057] The pending confirmation information doc1 may also include an information number. This information number can be used as an index to subsequently search for the order processing progress.
[0058] Step 3: The first secret zone C2 uses XOR encryption. The first encryption key a is used to encrypt the message doc1 to be confirmed, resulting in the encrypted message to be confirmed. The encrypted confirmation information doc1' is then sent to the server's second secure zone S2 via a quantum-safe network.
[0059] In this process, the first encryption key 'a' used for encryption can be obtained in advance from the key pool in the quantum secure network and stored in the first secret zone C2; correspondingly, the second secret zone S2 stores the first decryption key 'a' that matches the key in the first secret zone C2. Alternatively, neither the first secret zone C2 nor the second secret zone S2 may store keys in advance. After the first secret zone C2 generates the confirmation information doc1, it sends a key request to the key pool in the quantum secure network. The key pool responds to the key request by sending the paired first encryption key 'a' and first decryption key 'a' to the first secret zone C2 and the second secret zone S2, respectively, for use in this order processing.
[0060] Step 4: The second secure zone S2 on the server side receives the encrypted confirmation information doc1' and decrypts it using the first decryption key a' corresponding to the first encryption key a in the first secure zone C2, obtaining the confirmation information doc1. The second secure zone S2 then generates an order based on this confirmation information doc1.
[0061] There are two ways to generate an order:
[0062] Method 1:
[0063] Step (1): The second secret zone S2 generates the order to be confirmed doc2 based on the information to be confirmed doc1.
[0064] The second secure area S2 verifies the decrypted information to be confirmed, such as whether the product inventory information meets the product quantity requirements in the information to be confirmed (doc1) and whether the merchant's payment information is correct. When the information to be confirmed passes the verification, the second secure area S2 generates an order to be confirmed (doc2).
[0065] When the confirmation information fails verification, the second secret zone S2 returns the confirmation information to the first secret zone C2. The first secret zone C2 can receive instructions from the consumer to modify the confirmation information to generate new confirmation information. Based on the new confirmation information, step 3 and step (1) are re-executed until the new confirmation information passes verification, and the second secret zone S2 generates the confirmation order doc2.
[0066] Step (2): The second secret zone S2 uses XOR encryption to encrypt the order to be confirmed, doc2, using the second encryption key b, to obtain the encrypted order to be confirmed. The encrypted order doc2' is then sent to the first encrypted zone C2.
[0067] Step (3): The first secure zone C2 receives the encrypted order to be confirmed doc2', and decrypts it using the second decryption key b' corresponding to the second encryption key b, to obtain the order to be confirmed doc2. The consumer performs a confirmation operation on the decrypted order to be confirmed doc2 in the first secure zone S2, including confirming the product model, style, quantity, consumer account, contact information, delivery address, etc. in the order to be confirmed doc2.
[0068] Step (4): After the consumer confirms, the first secure zone C2 encrypts the confirmation information and sends it to the second secure zone S2. This confirmation information can be a confirmation command generated after the consumer clicks "confirm" on the client.
[0069] Step (5): The second secret zone S2 generates a confirmed order order based on the received confirmation information and the order to be confirmed doc2, and generates an order number for the confirmed order order.
[0070] This completes the entire order processing process, and the confirmed order is the final order required.
[0071] Method 2:
[0072] like Figure 3 As shown, orders are generated using the following method.
[0073] Step (1): The server's second encrypted zone S2 uses the first decryption key a' to decrypt the encrypted message doc1' to obtain the message doc1. At this time, the message doc1 is present in both the client's first encrypted zone C2 and the server's second encrypted zone S2.
[0074] Step (1)-1: The client's first secret zone C2 generates the first order to be confirmed, doc3, based on the information to be confirmed, doc1;
[0075] Step (1)-2: The second secret zone S2 on the server generates the second order to be confirmed doc4 based on the information to be confirmed doc1.
[0076] Step (2): The first secret zone C2 and the second secret zone S2 share a key and generate a hash function using the same hash algorithm. The hash algorithm can be uniformly provided by the hash calculation service module in the quantum-safe network. For example, the hash algorithm could be a hash function H generated using an irreducible polynomial and input random numbers. p,s That is, the hash function in both the first secret zone C2 and the second secret zone S2 is H. p,s The first secret zone C2 uses the hash function to calculate the first hash value of the first pending order doc3, hash1 = H. p,s(doc3), the second secret zone S2 uses the hash function to calculate the second hash value of the second order to be confirmed (doc4): hash2 = H p,s (doc4)
[0077] Step (3): The first secret zone C2 is XORed with the third encryption key c obtained from the key pool or locally to encrypt the first hash value hash1, resulting in the encrypted hash value. And send it to the second secret zone S2.
[0078] Step (4): The second secret zone S2 decrypts the received encrypted first hash value hash1' to obtain the first hash value hash1. The decrypted first hash value hash1 is compared with the second hash value hash2 calculated in step (2). If the comparison results are consistent, it means that the second unconfirmed order doc4 generated by the server is consistent with the order that the consumer on the client side wants to receive. Therefore, the second secret zone S2 generates a confirmed order based on the second unconfirmed order doc4.
[0079] If the comparison results are inconsistent, it means that the order to be confirmed generated by the server is inconsistent with the order that the consumer on the client side expects. The first secret zone C2 needs to receive the consumer's instruction to modify the information to be confirmed and generate new information to be confirmed. Based on the new information to be confirmed, return to the execution steps (1)-(4) until the first hash value and the second hash value are consistent.
[0080] Example 2:
[0081] like Figure 4 As shown, the client can include only the first encrypted zone C2, and the server can include only the second encrypted zone S2. Thus, from the initial server publishing and displaying product information to the client, the server's second encrypted zone S2 needs to encrypt the displayed product information using a key, and the client's first encrypted zone C2 needs to decrypt the encrypted product information using a decryption key. The subsequent order processing method is consistent with the methods in Examples 1 and 2, and will not be repeated here. It is understandable that this deployment method will consume a large number of keys.
Claims
1. A method for order processing in an e-commerce system under a global quantum-safe network, characterized in that, The method involves a client and a server, wherein the client receives instructions from a consumer, including a first unsecured zone C1 and a first secure zone C2, which communicate via a first interface; the server receives instructions from a merchant, including a second unsecured zone S1 and a second secure zone S2, which communicate via a second interface; the method includes the following steps: Step 1: The server receives instructions from the merchant to publish multiple products in the second non-secure zone S1 on the server, and the multiple products are displayed in the first non-secure zone C1 on the client. Step 2: The client's first secret zone C2 generates a confirmation information doc1 based on the product information selected by the consumer and the consumer's identity information; Step 3: The first secret zone C2 uses XOR encryption to perform encryption on the information to be confirmed, doc1, using the first encryption key a, to obtain the encrypted information to be confirmed, doc1' = doc1 ⊕ a, and then sends the encrypted information to be confirmed, doc1', to the second secret zone S2 of the server through the quantum-safe network. Step 4: The second secret zone S2 of the server receives the encrypted information to be confirmed, doc1', and decrypts the encrypted information to be confirmed, doc1', using the first decryption key a' corresponding to the first encryption key a in the first secret zone C2, to obtain the information to be confirmed, doc1; the second secret zone S2 generates an order based on the information to be confirmed, doc1.
2. The order processing method for an e-commerce system under a global quantum-secure network according to claim 1, characterized in that, The first interface can only realize the one-way data transfer function from the first non-secret area C1 to the first secret area C2; the second interface can only realize the one-way data transfer function from the second non-secret area S1 to the second secret area S2.
3. The order processing method for an e-commerce system under a global quantum-secure network according to claim 2, characterized in that, In Step 2, the specific process by which the client's first secure area C2 generates the confirmation information doc1 based on the product information selected by the consumer and the consumer's identity information includes: The client receives an instruction from the consumer to select one or more products from the plurality of products, and transmits the product information selected by the consumer and the consumer's identity information unidirectionally from the first non-secure zone C1 to the first secure zone C2 through the first interface. The first secure zone C2 generates a confirmation information doc1 based on the received product information and consumer identity information. The product information selected by the consumer includes the product's model, style, quantity, name of the merchant to which the product belongs, and the merchant's payment information. The consumer's identity information includes the consumer's account, contact information, and delivery address.
4. The order processing method for an e-commerce system under a global quantum-secure network according to claim 2, characterized in that, In Step 2, the specific process by which the client's first secure area C2 generates the confirmation information doc1 based on the product information selected by the consumer and the consumer's identity information includes: The client generates sub-public information in the first unsecured area C1 and sub-private information in the first secure area C2. Then, the client's first unsecured area C1 transmits the sub-public information to the first secure area C2 through the first interface. The first secure area C2 receives the sub-public information and integrates it with the sub-private information stored in itself to form complete information to be confirmed, doc1. The sub-public information includes the product's model, style, quantity, and the name of the merchant to which the product belongs. The sub-private information includes the consumer's account, contact information, address, and the merchant's payment information.
5. The order processing method for an e-commerce system under a global quantum-secure network according to claim 3 or 4, characterized in that, In step 4, the method of generating an order includes: Step (1): The second secret zone S2 generates an order to be confirmed, doc2, based on the information to be confirmed, doc1; Step (2): The second secret zone S2 uses XOR encryption to encrypt the order to be confirmed doc2 using the second encryption key b, so as to obtain the encrypted order to be confirmed doc2' = doc2 ⊕ b, and sends the encrypted order to be confirmed doc2' to the first secret zone C2; Step (3): The first secret zone C2 receives the encrypted order to be confirmed doc2', and performs a decryption operation using the second decryption key b' corresponding to the second encryption key b, to obtain the order to be confirmed doc2; the consumer performs a confirmation operation on the decrypted order to be confirmed doc2 in the first secret zone S2; Step (4): After the consumer confirms, the first secret zone C2 encrypts the confirmation information and sends it to the second secret zone S2; Step (5): The second secret zone S2 generates a confirmed order based on the received confirmation information and the unconfirmed order doc2, and generates an order number for the confirmed order to complete the order processing process.
6. The order processing method for an e-commerce system under a global quantum-secure network according to claim 5, characterized in that, In step (1), the specific process by which the second secret zone S2 generates the order doc2 to be confirmed based on the information doc1 to be confirmed is as follows: The second secret zone S2 verifies the information to be confirmed after decryption: When the information to be confirmed passes the verification, the second secret zone S2 generates the order to be confirmed, doc2. When the information to be confirmed fails the verification, the second secret zone S2 returns the information to be confirmed to the first secret zone C2. The first secret zone C2 receives the consumer's instruction to modify the information to be confirmed in order to generate new information to be confirmed. Based on the new information to be confirmed, steps step3 and step (1) are re-executed until the new information to be confirmed passes the verification. The second secret zone S2 then generates the order to be confirmed, doc2.
7. The order processing method for an e-commerce system under a global quantum-secure network according to claim 3 or 4, characterized in that, In step 4, the method of generating an order includes: Step (1): The second secret zone S2 on the server uses the first decryption key a' to decrypt the encrypted message doc1' to obtain the message doc1: Step (1)-1: The client's first secret zone C2 generates a first order to be confirmed, doc3, based on the information to be confirmed, doc1; Step (1)-2: The second secret zone S2 on the server generates a second order to be confirmed, doc4, based on the information to be confirmed, doc1; Step (2): The first secret zone C2 and the second secret zone S2 share a key and use the same hash algorithm to generate the same hash function H. p,s The first secret zone C2 uses the hash function H. p,s Calculate the first hash value of the first pending order doc3: hash1 = H p,s (doc3), the second secret zone S2 uses the hash function H. p,s Calculate the second hash value of the second pending order doc4: hash2 = H p,s (doc4); Step (3): The first secret zone C2 is XORed with the third encryption key c obtained from the key pool or locally to encrypt the first hash value hash1, resulting in the encrypted hash value hash1' = H. p,s (doc3)⊕c, and send it to the second secret zone S2; Step (4): The second secret zone S2 decrypts the received encrypted first hash value hash1' to obtain the first hash value hash1; the decrypted first hash value hash1 is compared with the second hash value hash2 calculated in step (2): If the comparison results are consistent, the second secret zone S2 generates a confirmation order based on the second unconfirmed order doc4; If the comparison results are inconsistent, the first secret zone C2 receives the consumer's instruction to modify the information to be confirmed and generates new information to be confirmed. Based on the new information to be confirmed, it returns to the execution steps (1)-(4) until the first hash value is consistent with the second hash value. Thus, the second secret zone S2 generates a confirmed order based on the second order to be confirmed, doc4.
8. The order processing method for an e-commerce system under a global quantum-secure network according to claim 1, characterized in that, The information to be confirmed, doc1, also includes an information number.
9. The order processing method for an e-commerce system under a global quantum-secure network according to claim 1, characterized in that, In step 3, the first encryption key a is obtained in advance from the key pool in the quantum secure network and stored in the first secret zone C2. The second secret zone S2 stores the first decryption key a' that is paired with the key in the first secret zone C2.
10. The order processing method for an e-commerce system under a global quantum-secure network according to claim 1, characterized in that, In step 3, if the first secret zone C2 and the second secret zone S2 do not have keys stored in advance, after the first secret zone C2 generates the confirmation information doc1, the first secret zone C2 sends a key request information to the key pool in the quantum security network. The key pool responds to the key request information and sends the paired first encryption key a and first decryption key a' to the first secret zone C2 and the second secret zone S2 respectively.
Citation Information
Patent Citations
Safe order system based on digital certificate
CN105956804A
Quantum communication system and communication method thereof
CN106507344A
Systems and methods for protecting information carried on a data network
US20020004784A1