Method and apparatus for determining data packet transmission object
By obtaining the target request and extracting the target signature in the privacy computing system, and using the data authentication system to trace the sender of the data packet, the problem of not being able to determine the sender of the data packet in privacy computing is solved, and the accurate location of the sender and the tracing of data tampering are realized.
Patent Information
- Application Number
- CN202310652335.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-02
- Publication Date
- 2025-12-09
- Estimated Expiration
- 2043-06-02
AI Technical Summary
Existing technologies cannot effectively determine the recipient of data packets, especially in privacy computing scenarios where there is a risk of data tampering, and it is impossible to trace the data owner who committed the data tampering.
By obtaining the target request and extracting the target signature from the data packet, the target signature is assigned to the object using the data authentication system. Based on the correspondence between the signature and the object, the object that actually sent the data packet is traced back to ensure that the identity of the object that sent the data packet is determined.
It enables the determination of the recipient of data packets in privacy computing scenarios, solves the problem of tracing data tampering behavior, and ensures that the recipient of data packets is accurately located.
Smart Images

Figure CN116668127B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of communication, in particular to a method and device for determining a data packet sending object. BACKGROUND
[0002] The privacy computing technology is used for the scene that needs multiple data owners to perform collaborative calculation in the case of mutual distrust. The privacy computing technology adopts operations such as description, measurement, evaluation and fusion of involved privacy information, hides the original data state of the data from the data user through symbolic and formulaic methods, realizes "available but invisible" of the data used by the data user, and thus protects the privacy information. In actual use, there is a risk that the data owner mixes false data or tampers with the data provided by the data owner. However, due to the "data available but invisible" feature of the privacy computing technology, the data user cannot trace back to the data owner who tampers with the data.
[0003] In view of the problem that the sending object of the data packet cannot be determined in the related art, no effective solution has been proposed so far. SUMMARY
[0004] The main purpose of the present application is to provide a method and device for determining a data packet sending object, so as to solve the problem that the sending object of the data packet cannot be determined in the related art.
[0005] In order to achieve the above-mentioned purpose, according to one aspect of the present application, a method for determining a data packet sending object is provided, which is applied to a data authentication system. The method comprises: obtaining a target request sent by a first object, wherein the target request is used to request to determine an object that sends a first data packet to a privacy calculation module of the first object, the first data packet carries target business data required by the first object for business handling, the privacy calculation module is used to obtain reference business data by hiding a data original state of the target business data from the first object, the first object is used to perform business handling by using the reference business data, and the target request is generated in a case that a handling result of the business handling of the first object indicates that the target business data is abnormal business data; extracting a target signature from the first data packet, wherein the target signature is allocated by the data authentication system for an object that sends the first data packet to the privacy calculation module, and the target signature is used to represent an object identity of the object that sends the first data packet to the privacy calculation module; obtaining a second object corresponding to the target signature from signatures and objects having a corresponding relationship, wherein the second object is an object that sends the first data packet to the privacy calculation module; and sending the second object to the first object.
[0006] Optionally, the obtaining the second object corresponding to the target signature from the objects and the signatures having the corresponding relationship comprises: determining the second object corresponding to the target encryption key from the encryption keys and the objects having the corresponding relationship, wherein the target signature comprises the target encryption key, the second object is used to sign a second data packet by using the target encryption key to obtain the first data packet, and the second data packet is a data packet obtained by encrypting the target service data by using a reference encryption key corresponding to the first object by the second object.
[0007] Optionally, the extracting the target signature from the first data packet comprises: obtaining a target key identifier carried by the first data packet; and determining a target encryption key corresponding to the target key identifier from the key identifiers and the encryption keys having the corresponding relationship, wherein the target signature comprises the target encryption key, the second object is used to sign a second data packet by using the target encryption key to obtain the first data packet, and the second data packet is a data packet obtained by encrypting the target service data by using a reference encryption key corresponding to the first object by the second object.
[0008] Optionally, after the obtaining the second object corresponding to the target signature from the objects and the signatures having the corresponding relationship, the method further comprises: sending a target data obtaining request to the second object, wherein the target data obtaining request is used to request obtaining a third data packet generated by the second object, the third data packet is a data packet generated by the second object in response to a service data obtaining request of the first object, and the service data obtaining request is used to request obtaining the target service data; matching candidate service data carried in the third data packet with the target service data carried in the first data packet; and determining that the second object performs a data tampering operation on the target service data carried in the first data packet in a case where the candidate service data and the target service data do not match.
[0009] Optionally, the matching the candidate service data carried in the third data packet with the target service data carried in the first data packet comprises: obtaining a first data digest value of the first data packet and a second data digest value of the third data packet, wherein the first data digest value is used to represent data content of the target service data carried in the first data packet, and the second data digest value is used to represent data content of the candidate service data carried in the third data packet; matching the first data digest value with the second data digest value; and determining that the candidate service data and the target service data do not match in a case where the first data digest value and the second data digest value do not match.
[0010] According to another aspect of the present application, a method for determining a data packet sending object is provided, and is applied to a first object. The method comprises: obtaining reference service data generated by a privacy calculation module of the first object, wherein the privacy calculation module is configured to receive a first data packet carrying target service data, and obtain the reference service data by hiding a data original state of the target service data from the first object; performing service processing using the reference service data; in a case where a processing result of the service processing indicates that the target service data is abnormal service data, generating a target request, wherein the target request is used to request to determine an object that sends the first data packet to the privacy calculation module; sending the target request to a data authentication system, wherein the data authentication system is configured to respond to the target request, extract a target signature from the first data packet, obtain a second object corresponding to the target signature from a signature and an object having a corresponding relationship, and send the second object to the first object, the target signature being allocated by the data authentication system to an object corresponding to sending the first data packet to the privacy calculation module, and the target signature being used to represent an object identity of an object that sends the first data packet to the privacy calculation module; and receiving the second object returned by the data authentication system.
[0011] Optionally, before the obtaining the reference service data generated by the privacy calculation module of the first object, the method further comprises: obtaining a target key identifier carried by the first data packet; obtaining a target decryption key corresponding to the target key identifier and generated by the data authentication system; decrypting target signature information carried in the first data packet using the target decryption key to obtain a candidate encryption key, wherein the target signature information is obtained by encrypting the candidate encryption key using a target encryption key, and the target signature includes the target encryption key; and in a case where the candidate encryption key matches a reference encryption key, performing data conversion processing on the target service data to obtain the reference service data, wherein the data conversion processing is used to hide a data original state of the target service data from the first object, and the reference encryption key is a key allocated by the first object to the second object for encrypting the target service data.
[0012] Optionally, before the obtaining the target key identifier carried by the first data packet, the method further comprises: calculating a third data digest value of the target service data; matching the third data digest value with a first data digest value, wherein the first data digest value is used to represent a data content of the target service data carried in the first data packet; and in a case where the third data digest value matches the first data digest value, obtaining the target key identifier carried by the first data packet.
[0013] According to another aspect of the present application, a method for determining a data packet sending object is provided, which is applied to a second object. The method comprises: obtaining a target signature assigned by a data authentication system, wherein the target signature is used to represent an object identity of the second object; signing target business data using the target signature to obtain a first data packet; and sending the first data packet to a privacy calculation module of a first object, wherein the privacy calculation module is used to hide a data original state of the target business data from the first object to obtain reference business data, the first object is used to conduct a business using the reference business data, and in a case where a business handling result of the business handling indicates that the target business data is abnormal business data, a target request is generated and sent to the data authentication system, the target request is used to determine an object sending the first data packet to the privacy calculation module, and the data authentication system is used to respond to the target request, extract a target signature from the first data packet, obtain a second object corresponding to the target signature from a signature and an object having a corresponding relationship, and send the second object to the first object.
[0014] Optionally, the signing of the target business data using the target signature to obtain the first data packet comprises: encrypting the target business data using a reference encryption key corresponding to the first object to obtain a second data packet; encrypting the reference encryption key using a target encryption key to obtain target signature information; and generating the first data packet carrying the second data packet and the target signature information.
[0015] In order to achieve the above object, according to another aspect of the present application, a data packet sending object determination apparatus is provided, which is applied to a data authentication system. The apparatus comprises: a first obtaining module, configured to obtain a target request sent by a first object, wherein the target request is used to request to determine an object that sends a first data packet to a privacy calculation module of the first object, the first data packet carries target business data required by the first object for business handling, the privacy calculation module is used to obtain reference business data by hiding a data original state of the target business data from the first object, the first object is used to perform business handling by using the reference business data, and the target request is generated in a case that a handling result of the business handling of the first object indicates that the target business data is abnormal business data; an extracting module, configured to extract a target signature from the first data packet, wherein the target signature is allocated by the data authentication system to an object corresponding to the first data packet for sending the first data packet to the privacy calculation module, and the target signature is used to represent an object identity of the object for sending the first data packet to the privacy calculation module; a second obtaining module, configured to obtain a second object corresponding to the target signature from signatures and objects having a corresponding relationship, wherein the second object is an object that sends the first data packet to the privacy calculation module; and a first sending module, configured to send the second object to the first object.
[0016] According to another aspect of the present application, a data packet sending object determination apparatus is provided, which is applied to a first object. The apparatus comprises: a third obtaining module, configured to obtain reference business data generated by a privacy calculation module of the first object, wherein the privacy calculation module is used to receive a first data packet carrying target business data, and obtain the reference business data by hiding a data original state of the target business data from the first object; a processing module, configured to perform business handling by using the reference business data; a generating module, configured to generate a target request in a case that a handling result of the business handling indicates that the target business data is abnormal business data, wherein the target request is used to request to determine an object that sends the first data packet to the privacy calculation module; a third sending module, configured to send the target request to a data authentication system, wherein the data authentication system is used to respond to the target request, extract a target signature from the first data packet, obtain a second object corresponding to the target signature from signatures and objects having a corresponding relationship, and send the second object to the first object, the target signature is allocated by the data authentication system to an object corresponding to the first data packet for sending the first data packet to the privacy calculation module, and the target signature is used to represent an object identity of the object for sending the first data packet to the privacy calculation module; and a receiving module, configured to receive the second object returned by the data authentication system.
[0017] According to another aspect of the present application, a data packet sending object determination apparatus is provided, which is applied to a second object. The apparatus comprises: a seventh obtaining module configured to obtain a target signature assigned by a data authentication system, wherein the target signature is used to represent an object identity of the second object; a signature module configured to sign target service data using the target signature to obtain a first data packet; and a fourth sending module configured to send the first data packet to a privacy calculation module of a first object, wherein the privacy calculation module is configured to hide a data original state of the target service data from the first object to obtain reference service data, the first object is configured to use the reference service data to handle a service, and in a case where a handling result of the service indicates that the target service data is abnormal service data, the first object is configured to generate a target request and send the target request to the data authentication system, the target request is used to determine an object that sends the first data packet to the privacy calculation module, and the data authentication system is configured to respond to the target request, extract a target signature from the first data packet, obtain a second object corresponding to the target signature from a signature and an object having a corresponding relationship, and send the second object to the first object.
[0018] By the present application, the following steps are adopted: obtaining a target request sent by a first object, wherein the target request is used to request to determine an object that sends a first data packet to a privacy calculation module of the first object, the first data packet carries target business data required by the first object for business handling, the privacy calculation module is used to obtain reference business data by hiding the data original state of the target business data from the first object, the first object is used to use the reference business data for business handling, and the target request is generated in a case where a handling result of the business handling of the first object indicates that the target business data is abnormal business data; extracting a target signature from the first data packet, wherein the target signature is allocated by the data authentication system to an object corresponding to the first data packet sent to the privacy calculation module, and the target signature is used to represent the object identity of the object that sends the first data packet to the privacy calculation module; obtaining a second object corresponding to the target signature from signatures and objects having a corresponding relationship, wherein the second object is an object that sends the first data packet to the privacy calculation module; and sending the second object to the first object, allocating a corresponding target signature to an object by the data authentication system, representing the object identity of the object by the signature, and carrying the target signature by the object each time the object sends a first data packet to the privacy calculation module of the first object, so as to obtain the target request sent by the first object for requesting to determine the object that sends the first data packet to the privacy calculation module of the first object by the data authentication system, extract the target signature from the first data packet, and then obtain the second object corresponding to the target signature from the signatures and objects having the corresponding relationship, so as to realize tracing the second object that sends the first data packet to the privacy calculation module according to the target signature carried in the first data packet, and solve the problem that the sending object of the data packet cannot be determined in the related art. Therefore, the effect of determining the sending object of the data packet is achieved. BRIEF DESCRIPTION OF DRAWINGS
[0019] The accompanying drawings, which form a part of the present application, are intended to provide further understanding of the present application, and the illustrative embodiments of the present application and their description serve the purpose of explaining the present application. The accompanying drawings should not be construed as an inappropriate limitation on the present application.
[0020] Figure 1 is a flow of a method for determining a data packet sending object according to an embodiment of the present application Figure One ;
[0021] Figure 2 is a schematic diagram of an optional secure multi-party computation scenario according to an embodiment of the present application
[0022] Figure 3 is a flow of a method for determining a data packet sending object according to an embodiment of the present application Figure Two;
[0023] Figure 4 is a flow of a method for determining a data packet sending object according to an embodiment of the present application Figure Three ;
[0024] Figure 5 is an optional interaction schematic diagram according to an embodiment of the present application
[0025] Figure 6 is a schematic diagram of a device for determining a data packet sending object according to an embodiment of the present application Figure One ;
[0026] Figure 7 is a schematic diagram of a device for determining a data packet sending object according to an embodiment of the present application Figure Two ;
[0027] Figure 8 is a schematic diagram of a device for determining a data packet sending object according to an embodiment of the present application Figure Three ;
[0028] Figure 9 is an optional electronic device schematic diagram according to an embodiment of the present application DETAILED DESCRIPTION
[0029] It should be noted that the embodiments and features of the present application can be combined with each other in the case of no conflict. The technical solutions in the embodiments of the present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0030] In order to enable persons skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by persons skilled in the art without creative labor should belong to the protection scope of the present application.
[0031] It should be noted that the terms "first", "second" and the like in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or a chronological sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device including a series of steps or units does not necessarily limit to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0032] The application will be described in the following with reference to the preferred embodiments of the application, Figure 1 A flow of a method for determining a data packet sending object is provided according to an embodiment of the application Figure One and applied to a data authentication system, as shown in the figure, the method comprises the following steps: Figure 1
[0033] In step S101, a target request sent by a first object is acquired, wherein the target request is used to request to determine an object that sends a first data packet to a privacy calculation module of the first object, the first data packet carries target business data required by the first object for business handling, the privacy calculation module is used to obtain reference business data by hiding a data original state of the target business data of the first object, the first object is used to perform business handling by using the reference business data, and the target request is generated in a case where a handling result of the business handling of the first object indicates that the target business data is abnormal business data;
[0034] In step S102, a target signature is extracted from the first data packet, wherein the target signature is allocated by the data authentication system to an object that sends the first data packet to the privacy calculation module, and the target signature is used to represent an object identity of the object that sends the first data packet to the privacy calculation module;
[0035] In step S103, a second object corresponding to the target signature is acquired from signatures and objects having a corresponding relationship, wherein the second object is an object that sends the first data packet to the privacy calculation module;
[0036] In step S104, the second object is sent to the first object.
[0037] Optionally, in the method for determining a data packet sending object provided in the embodiment of the application, a corresponding target signature is allocated to an object by a data authentication system, the object identity of the object is represented by the signature, the object carries the target signature every time the object sends a first data packet to a privacy calculation module of a first object, and then after the data authentication system acquires a target request sent by the first object and used to request to determine an object that sends a first data packet to a privacy calculation module of the first object, the target signature is extracted from the first data packet, and then a second object corresponding to the target signature is acquired from signatures and objects having a corresponding relationship, so as to realize tracing the second object that sends the first data packet to the privacy calculation module according to the target signature carried in the first data packet, and solve the problem that the sending object of the data packet cannot be determined in the related art. Furthermore, the effect of determining the sending object of the data packet is achieved.
[0038] In step S101, the first object can be an account registered on the data authentication system, or can also be a data sending system or a data sending device associated with the data authentication system, and the present scheme does not limit this.
[0039] Optionally, in the embodiment, the second object can be an account registered on the data authentication system, or can also be a data processing system or a data processing device associated with the data authentication system, and the present scheme does not limit this.
[0040] Optionally, in the embodiment, the privacy computing module can be a module configured on the first object, or can also be a module having a binding relationship with the first object. For example, when the first object is a data processing system, the privacy computing module can be a module configured on the data processing system, or can also be a module having a binding relationship with the data processing system. When the first object requests the target business data from the second object, the second object sends the target business data to the privacy computing module of the first object, thereby realizing the function of hiding the original state of the target business data from the first object.
[0041] Optionally, in the embodiment, the privacy computing module can, but is not limited to, realize the hiding of the original state of the target business data of the first object by using the operations of describing, measuring, evaluating and fusing the involved private information, and realizing the original state of the target business data of the first object by using the symbolic and formulaic method.
[0042] Optionally, in the embodiment, the business handling of the first object using the reference business data can include, but is not limited to, model training, data operation, data analysis, etc., and the present scheme does not limit this.
[0043] Optionally, in the embodiment, the first object determining that the target business data is abnormal business data can also be obtained by data analysis on the first data packet. For example, the first data packet carries a data digest value of the target business data. The first object calculates the data digest value of the target business data, matches it with the data digest value carried in the first data packet, and determines that the target business data is abnormal business data when the matching result of the two data digest values is inconsistent. Alternatively, the first data packet carries a second data packet and a data digest value of the second data packet. The second data packet is obtained by encrypting the target business data using the encryption key corresponding to the first object. The first object calculates the data digest value of the second data packet, matches it with the data digest value carried in the first data packet, and determines that the target business data is abnormal business data when the matching result is inconsistent.
[0044] In the embodiment provided in step S102, the object sending the data packet is configured to perform a signature operation on the target service data using the target signature, so that the first data packet carries the target signature. The signature operation can include, but is not limited to, setting a data watermark, performing encryption processing using the target signature, merging the target signature and the target service data, etc. For example, setting a data watermark can include, but is not limited to, setting a watermark value of the data watermark as the target signature on the target service data, or setting a watermark value of the data watermark as the target signature on the encrypted data packet carrying the target service data. Performing encryption processing using the target signature on the target service data can include, but is not limited to, encrypting the target service data using the target signature, encrypting the encrypted data packet (for example, the second data packet obtained by encrypting the target service data using the reference encryption key corresponding to the first object) carrying the target service data using the target signature, or encrypting the encryption key (for example, the reference encryption key corresponding to the first object, which is used to encrypt the target service data) used to encrypt the target service data using the target signature.
[0045] Optionally, in the embodiment, when the object signs the target service data by merging the target signature and the target service data, the target signature is extracted by searching for the signature value corresponding to the target signature from the data carried by the first data packet; when the object signs the target service data by setting a data watermark, the target signature is extracted by extracting the watermark value from the first data packet; and when the object signs the target data by performing encryption processing using the target signature, the encryption key corresponding to the decryption key can be obtained to decrypt the data packet encrypted using the target signature, so that the encryption key corresponding to the decryption key is determined as the target signature, or the target key identifier corresponding to the target signature can be extracted from the first data packet, and then the target signature corresponding to the target key identifier is determined from the key identifier and the signature having a corresponding relationship.
[0046] As an optional embodiment, the second object corresponding to the target signature is obtained from the signature and the object having a corresponding relationship, and the second object is configured to perform a signature operation on the second data packet using the target encryption key to obtain the first data packet.
[0047] The second object corresponding to the target encryption key is determined from the encryption key and the object having a corresponding relationship, wherein the target signature includes the target encryption key, and the second object is configured to perform a signature operation on the second data packet using the target encryption key to obtain the first data packet, and the second data packet is obtained by encrypting the target service data using the reference encryption key corresponding to the first object.
[0048] Optionally, in the embodiment, the data authentication system assigns a corresponding encryption key to each object sending the data packet as the target signature, which can be but is not limited to a public key and a private key generated by an asymmetric key algorithm. For example, the public key is sent to the second object as the target encryption key, which is used by the second object to encrypt the target business data to realize the signature of the target business data. Meanwhile, the data authentication system displays the private key as the target decryption key corresponding to the target encryption key through the second object's external trusted channel (the second object's official website, the data authentication system, official email, etc.). Alternatively, the private key can also be sent to the second object as the target encryption key, which is used by the second object to encrypt the target business data to realize the signature of the target business data. Meanwhile, the data authentication system displays the public key as the target decryption key corresponding to the target encryption key through the second object's external trusted channel (the second object's official website, the data authentication system, official email, etc.).
[0049] Optionally, in the embodiment, the reference encryption key can be an encryption key pre-assigned by the first object to the object sending the data packet. Different data sending objects are assigned different reference encryption keys, which are used by the data sender to encrypt the target business data to obtain the second data packet, thereby avoiding tampering during data transmission. Meanwhile, the first object stores a reference decryption key corresponding to the reference encryption key, which is used by the first object to decrypt the second data packet. The first object can generate a public key and a private key by an asymmetric algorithm, and use the public key as the reference encryption key and the private key as the reference decryption key.
[0050] As an optional embodiment, the extracting the target signature from the first data packet comprises:
[0051] Obtaining the target key identifier carried by the first data packet;
[0052] Determining the target encryption key corresponding to the target key identifier from the key identifiers and the encryption keys having a corresponding relationship, wherein the target signature comprises the target encryption key, and the second object uses the target encryption key to sign the second data packet to obtain the first data packet. The second data packet is a data packet obtained by encrypting the target business data using the reference encryption key corresponding to the first object.
[0053] Optionally, in the embodiment, the target key identifier can be set on the first data packet by means of first data packet watermarking.
[0054] Optionally, in the embodiment, the target key identifier is used to indicate information of a target encryption key used by the target object for sending the first data packet.
[0055] As an optional embodiment, after the second object corresponding to the target signature is obtained from the signatures and objects having the corresponding relationship, the method further comprises:
[0056] sending a target data obtaining request to the second object, wherein the target data obtaining request is used to request obtaining a third data packet generated by the second object, the third data packet being a data packet generated by the second object in response to a service data obtaining request of the first object, and the service data obtaining request being used to request obtaining the target service data;
[0057] matching the candidate service data carried in the third data packet with the target service data carried in the first data packet;
[0058] in a case where the candidate service data and the target service data do not match, determining that the second object has performed a data tampering operation on the target service data carried in the first data packet.
[0059] Optionally, in the embodiment, the matching of the candidate service data and the target service data can be, but is not limited to, a manner of matching data values of the candidate service data and data values of the target service data, or can also be a manner of matching a candidate data digest value and a target data digest value, wherein the candidate data digest value is used to guarantee data content of the candidate service data carried in the third data packet, and the target data digest value is used to represent data content of the target service data carried in the first data packet.
[0060] As an optional embodiment, the matching of the candidate service data carried in the third data packet with the target service data carried in the first data packet comprises:
[0061] obtaining a first data digest value of the first data packet and a second data digest value of the third data packet, wherein the first data digest value is used to represent data content of the target service data carried in the first data packet, and the second data digest value is used to represent data content of the candidate service data carried in the third data packet;
[0062] matching the first data digest value with the second data digest value;
[0063] in a case where the first data digest value and the second data digest value do not match, determining that the candidate service data and the target service data do not match.
[0064] Optionally, in the embodiment, the first data digest value can be calculated based on the target service data, or can be calculated based on the second data packet (a data packet obtained by encrypting the target service data by using a reference encryption key corresponding to the first object), or can be calculated based on the first data packet, and the scheme is not limited in this regard.
[0065] Optionally, the method for determining a data packet sending object provided in the embodiments of the present application can be applied in, but is not limited to, a privacy calculation scene of multi-source data fusion, such as secure multi-party computation and federated learning. The secure multi-party computation is a privacy protection distributed calculation technology in the field of cryptography. The secure multi-party computation can enable multiple parties to participate in collaborative calculation without knowing the content of each other, and finally produce valuable analysis content. The federated learning is also known as federated machine learning or joint learning. Compared with the traditional machine learning using a centralized method, the federated learning realizes learning and training of multiple parties in combination by circulation and processing of intermediate encrypted data without exporting the local original data. It generally uses distributed data to perform localized model training, and through certain security design and privacy algorithm, the obtained model result is aggregated to a trusted central node through a secure and reliable transmission channel, and then the final training model is obtained after secondary training. Due to the guarantee of the cryptographic algorithm, the central node cannot see the original data, but can only obtain the model result, thereby effectively ensuring the privacy of the process. The implementation of the federated learning is mainly "model-oriented", and its core concept is "data does not move and model moves". The secure multi-party computation is "data-oriented", and its core concept is "data is available but invisible".
[0066] Figure 2 is an optional secure multi-party computation scene schematic diagram according to the embodiments of the present application, as shown in Figure 2 a plurality of objects sending data packets to the first object determine the data to be transmitted, and then determine the data encryption method combined by multiple encryption algorithms, and then perform ciphertext calculation on the data sent to the first object through the encryption method, and perform differential noise, so as to encrypt and transmit the data to be transmitted to the first object to the first object.
[0067] The above two privacy computing scenarios are implemented based on homomorphic encryption, differential privacy and oblivious transfer three "black box method" cryptographic algorithms, and the data user cannot see the specific data provided by the data provider. Due to the risk of mixing false data, the corresponding technologies and computing models of the two privacy computing scenarios are often used in honest and semi-honest environments (the data provider itself has a certain credibility, and it is assumed that they will not make malicious behaviors of mixing false data). For malicious environments, it is not possible to support or develop technologies and products that can support malicious scenarios. Such technologies and products usually need to perform additional computing power, thereby reducing the execution efficiency.
[0068] Figure 3 A method for determining a data packet sending object is provided according to an embodiment of the application Figure Two , applied to a first object, as Figure 3 shown, the method comprises the following steps:
[0069] Step S301, obtaining reference business data generated by a privacy computing module of the first object, wherein the privacy computing module is used to receive a first data packet carrying target business data, and obtain the reference business data by hiding the data original state of the target business data from the first object;
[0070] Step S302, using the reference business data to handle business;
[0071] Step S303, in the case that the handling result of the business handling indicates that the target business data is abnormal business data, generating a target request, wherein the target request is used to request to determine an object that has sent the first data packet to the privacy computing module;
[0072] Step S304, sending the target request to a data authentication system, wherein the data authentication system is used to respond to the target request, extract a target signature from the first data packet, obtain a second object corresponding to the target signature from a signature and an object having a corresponding relationship, and send the second object to the first object. The target signature is allocated by the data authentication system for an object corresponding to the first data packet sent to the privacy computing module, and the target signature is used to represent the object identity of the object sending the first data packet to the privacy computing module;
[0073] Step S305, receiving the second object returned by the data authentication system.
[0074] Optionally, in the method for determining a data packet sending object provided in the embodiments of the present application, the data authentication system is used to assign a corresponding target signature to the object, the object identity of the object is represented by the signature, and the object carries the target signature each time the object sends a first data packet to the privacy calculation module of the first object. Then, after the data authentication system obtains a target request sent by the first object for requesting to determine the object that sends the first data packet to the privacy calculation module of the first object, the target signature is extracted from the first data packet, and then the second object corresponding to the target signature is obtained from the signatures and objects having a corresponding relationship, so as to realize tracing the second object that sends the first data packet to the privacy calculation module according to the target signature carried in the first data packet, and solve the problem that the sending object of the data packet cannot be determined in the related art. Therefore, the effect of determining the sending object of the data packet is achieved.
[0075] In the embodiments provided in the above step S301, the privacy calculation module can be a module configured on the first object, or can also be a module having a binding relationship with the first object. For example, in the case where the first object is a data processing system, the privacy calculation module can be a module configured on the data processing system, or can also be a module having a binding relationship with the data processing system. When the first object requests target business data from the second object, the second object is instructed to send the target business data to the privacy calculation module of the first object, so as to realize the function of hiding the original state of the target business data from the first object.
[0076] Optionally, in the present embodiment, the privacy calculation module can, but is not limited to, hide the data original state of the target business data from the first object by using operations such as description, measurement, evaluation and fusion of the involved private information, and realize the invisibility of the first object to the target business data by using symbolization and formulaization.
[0077] In the embodiments provided in the above step S302, the business handling can include, but is not limited to, model training, data operation, data analysis, data cleaning and the like, which are not limited by the present solution.
[0078] In the embodiments provided in the above step S303, the target request can, but is not limited to, carry the first data packet carried by the privacy calculation module, or carry the target signature and the target business data obtained by the privacy calculation module by analyzing the data packet.
[0079] As an optional embodiment, before the reference business data generated by the privacy calculation module of the first object is obtained, the method further includes:
[0080] Obtaining the target key identifier carried by the first data packet;
[0081] obtain a target decryption key corresponding to the target key identifier generated by the data authentication system;
[0082] decrypt target signature information carried in the first data packet using the target decryption key to obtain a candidate encryption key, wherein the target signature information is obtained by encrypting the candidate encryption key using a target encryption key, and the target signature includes the target encryption key;
[0083] in the case where the candidate encryption key and the reference encryption key match, perform data conversion processing on the target service data to obtain the reference service data, wherein the data conversion processing is used to hide the data original state of the target service data from the first object, and the reference encryption key is a key allocated by the first object to the second object for encrypting the target service data.
[0084] Optionally, in the embodiment, the first object can request the target decryption key from the data authentication system by sending a decryption key obtaining request carrying the target key identifier to the data authentication system, but is not limited thereto.
[0085] Optionally, in the embodiment, the first object can generate a public key and a private key by using an asymmetric algorithm, use the public key as the reference encryption key, use the private key as the reference decryption key, and send the reference encryption key to the object that sends the data packet to indicate that the data packet sending object uses the reference encryption key for encryption transmission, and uses the reference decryption key to decrypt the received data packet encrypted by the reference encryption key.
[0086] Optionally, in the embodiment, when the candidate encryption key and the reference encryption key match, it can be considered that the data is not tampered with in the data transmission process.
[0087] Optionally, in the embodiment, the data conversion processing can be achieved by directly converting the second data packet (the data packet obtained by encrypting the target data using the reference encryption key by the data sending object), so that the target service data carried in the second data packet is converted into the reference service data, or the reference decryption key corresponding to the reference encryption key can also be used to decrypt the second data packet, so as to obtain the target service data, and then convert the target service data into the reference service data, which is not limited by the present scheme.
[0088] As an optional embodiment, before the obtaining of the target key identifier carried in the first data packet, the method further comprises:
[0089] calculating a third data digest value of the target service data;
[0090] matching the third data digest value with a first data digest value, wherein the first data digest value is used to represent data content of the target service data carried in the first data packet;
[0091] in a case where the third data digest value matches the first data digest value, obtaining a target key identifier carried in the first data packet.
[0092] Optionally, in the embodiment, the third data digest value can be obtained by performing data digest value calculation on the target service data, or can be obtained by performing data digest value calculation on a second data packet (a data packet obtained by encrypting the target service data by using a reference encryption key corresponding to the first object by the object sending the data packet), or can be obtained by performing data digest value calculation on the first data packet, and the present scheme does not limit this.
[0093] Figure 4 A method for determining a data packet sending object is provided according to an embodiment of the present application Figure Three , and is applied to a second object, as shown in Figure 4 , the method comprises the following steps:
[0094] Step S401, obtaining a target signature distributed by a data authentication system, wherein the target signature is used to represent an object identity of the second object;
[0095] Step S402, signing target service data by using the target signature to obtain a first data packet;
[0096] Step S403, sending the first data packet to a privacy calculation module of a first object, wherein the privacy calculation module is used to hide a data original state of the target service data from the first object to obtain reference service data, the first object is used to perform service handling by using the reference service data, and in a case where a handling result of the service handling indicates that the target service data is abnormal service data, a target request is generated and sent to the data authentication system, the target request is used to determine an object sending the first data packet to the privacy calculation module, and the data authentication system is used to respond to the target request, extract a target signature from the first data packet, obtain the second object corresponding to the target signature from a signature and an object having a corresponding relationship, and send the second object to the first object.
[0097] Optionally, in the method for determining a data packet sending object provided in the embodiments of the present application, the data authentication system assigns a corresponding target signature to the object, the object identity of the object is represented by the signature, and the object carries the target signature each time the object sends a first data packet to the privacy calculation module of the first object. Then, after the data authentication system obtains a target request sent by the first object for requesting to determine the object that sends the first data packet to the privacy calculation module of the first object, the target signature is extracted from the first data packet, and then the second object corresponding to the target signature is obtained from the signatures and objects having a corresponding relationship, so as to trace the second object that sends the first data packet to the privacy calculation module according to the target signature carried in the first data packet, thereby solving the problem that the sending object of the data packet cannot be determined in the related art. Therefore, the effect of determining the sending object of the data packet is achieved.
[0098] In the embodiments provided in the above step S402, the second object signs the target business data by performing a signature operation on the target business data using the target signature. The signature operation can include, but is not limited to, setting a data watermark, encrypting the target business data using the target signature, merging the target signature and the target business data, and the like. For example, setting a data watermark can be, but is not limited to, setting a data watermark with a watermark value being the target signature to the target business data, or setting a data watermark with a watermark value being the target signature to an encrypted data packet carrying the target business data. Encrypting the target business data using the target signature can be, but is not limited to, encrypting the target business data using the target signature, encrypting an encrypted data packet (for example, a second data packet obtained by encrypting the target business data using a reference encryption key corresponding to the first object) carrying the target business data using the target signature, or encrypting an encryption key (for example, a reference encryption key corresponding to the first object, which is used to encrypt the target business data) used to encrypt the target business data using the target signature.
[0099] As an optional embodiment, the signing the target business data using the target signature to obtain a first data packet comprises:
[0100] encrypting the target business data using a reference encryption key corresponding to the first object to obtain a second data packet;
[0101] encrypting the reference encryption key using a target encryption key to obtain target signature information;
[0102] generating the first data packet carrying the second data packet and the target signature information.
[0103] Optionally, in the embodiment, before sending the first data packet to the privacy computing module, the second object can, but is not limited to, calculating a data digest value for representing the data content of the target business data (such as calculating a data digest value for the first data packet, calculating a data digest value for the second data packet, etc.), and setting the data digest value as a watermark of the first data packet, for the first object to determine whether the target business data in the first data packet is tampered with according to the data digest value after receiving the first data packet.
[0104] Optionally, in the embodiment, before sending the first data packet to the privacy computing module, the second object can, but is not limited to, setting a target key identifier representing the target encryption key as a watermark of the first data packet, for indicating the first object to obtain a target decryption key corresponding to the target encryption key for decryption according to the target key identifier after receiving the first data packet.
[0105] In the embodiment of the present application, a data authentication system is set, the data authentication system allocates a corresponding target signature to each object sending data to the first object, the object sending data signs the data by using the target signature, and then can trace the sending object of the data packet according to the target signature after receiving the target request of the first object, Figure 5 is an optional interaction schematic diagram according to the embodiment of the present application, as Figure 5 shown, the data provider (i.e. the second object) applies for a special digital certificate to the third party trusted agency (i.e. the data authentication system), the private key (i.e. the target encryption key) of the digital certificate is saved by the data provider for encryption and digital signature, and the public key (i.e. the target decryption key) of the digital certificate is displayed with the digital certificate through the external trusted channel (the official website of the provider, the official website of the third party trusted agency, the official email provider, etc.) of the data provider.
[0106] The data user (i.e., the first object) generates an asymmetric key pair (i.e., a reference encryption key and a reference decryption key) after obtaining the data use authorization of the data provider, saves the private key (i.e., the reference decryption key) by itself, and provides the public key (i.e., the reference encryption key) to the data provider, requiring the data provider to encrypt the provided source data or predicted data (i.e., target business data) by using the reference encryption key to obtain a second data packet, and then sign the reference encryption key by using the target encryption key, calculate the data digest value of the source data or predicted data and sign it in the form of data watermark to follow the source data or predicted data ciphertext (i.e., the first data packet) to provide to the data user. The data user obtains the signature certificate from the external trusted channel of the data provider. The data user decrypts the public key of the asymmetric key pair of the data provider by using the public key (i.e., the target decryption key) of the signature certificate, and confirms that the source data is provided by the data provider after verifying that the public key is the public key corresponding to the asymmetric key pair generated by itself. The data user can decrypt the data source or predicted data by using the private key for fusion calculation or directly use the ciphertext for fusion calculation. When the data "poisoning" phenomenon occurs in the fusion calculation or the fusion calculation result is inaccurate, the data user can start the accountability process, invite the trusted third party that issues the certificate for the data provider to check whether there is data mixing false data. The third-party trusted institution extracts the ciphertext of the source data, decrypts the ciphertext by the data user, the data provider extracts the data source signature and digest value in the plaintext data, and the third-party trusted institution can determine the data source by verifying the data signature and determine whether the data provider has the data mixing false data behavior by comparing the digest value of the data provided by the data provider.
[0107] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described herein can be executed in an order different from that shown herein.
[0108] The embodiment of the present application also provides a data packet sending object determination device. It should be noted that the data packet sending object determination device of the embodiment of the present application can be used to execute the data packet sending object determination method provided by the embodiment of the present application. The data packet sending object determination device provided by the embodiment of the present application is introduced as follows.
[0109] Figure 6 is a schematic diagram of the data packet sending object determination device according to the embodiment of the present application Figure One . As Figure 6As shown, the apparatus comprises: a first obtaining module 61, configured to obtain a target request sent by a first object, wherein the target request is used to request to determine an object that sends a first data packet to a privacy calculation module of the first object, the first data packet carries target business data required by the first object for business handling, the privacy calculation module is used to obtain reference business data by hiding a data original state of the target business data for the first object, the first object is used to use the reference business data for business handling, and the target request is generated in a case where a handling result of the business handling of the first object indicates that the target business data is abnormal business data; an extracting module 62, configured to extract a target signature from the first data packet, wherein the target signature is allocated by the data authentication system for an object corresponding to the first data packet sent to the privacy calculation module, and the target signature is used to represent an object identity of the object that sends the first data packet to the privacy calculation module; a second obtaining module 63, configured to obtain a second object corresponding to the target signature from signatures and objects having a corresponding relationship, wherein the second object is an object that sends the first data packet to the privacy calculation module; and a first sending module 64, configured to send the second object to the first object.
[0110] The data packet sending object determination apparatus provided by the embodiment of the present application allocates a corresponding target signature for an object by a data authentication system, represents an object identity of the object by the signature, carries the target signature every time the object sends a first data packet to a privacy calculation module of a first object, and then obtains a target request sent by the first object for requesting to determine an object that sends the first data packet to the privacy calculation module of the first object after the data authentication system obtains the target request, extracts a target signature from the first data packet, and then obtains a second object corresponding to the target signature from signatures and objects having a corresponding relationship, so as to realize tracing the second object that sends the first data packet to the privacy calculation module according to the target signature carried in the first data packet, and solve the problem that the sending object of the data packet cannot be determined in the related art. The effect of determining the sending object of the data packet is achieved.
[0111] Optionally, the second obtaining module comprises: a first determining unit, configured to determine the second object corresponding to a target encryption key from encryption keys and objects having a corresponding relationship, wherein the target signature comprises the target encryption key, and the second object is used to sign a second data packet by using the target encryption key to obtain the first data packet, and the second data packet is obtained by encrypting the target business data by using a reference encryption key corresponding to the first object by the second object.
[0112] Optionally, the extracting module comprises: a first obtaining unit, configured to obtain a target key identifier carried by the first data packet; and a second determining unit, configured to determine a target encryption key corresponding to the target key identifier from the key identifiers and the encryption keys having the corresponding relationship, wherein the target signature comprises the target encryption key, and the second object is configured to use the target encryption key to sign a second data packet to obtain the first data packet, the second data packet being a data packet obtained by encrypting the target service data by the second object using a reference encryption key corresponding to the first object.
[0113] Optionally, the apparatus further comprises: a second sending module, configured to send a target data obtaining request to the second object after obtaining the second object corresponding to the target signature from the signatures and the objects having the corresponding relationship, wherein the target data obtaining request is configured to request to obtain a third data packet generated by the second object, the third data packet being a data packet generated by the second object in response to a service data obtaining request of the first object, and the service data obtaining request is configured to request to obtain the target service data; a first matching module, configured to match candidate service data carried in the third data packet with the target service data carried in the first data packet; and a determining module, configured to determine that the second object has performed a data tampering operation on the target service data carried in the first data packet in a case where the candidate service data and the target service data do not match.
[0114] Optionally, the first matching module comprises: a second obtaining unit, configured to obtain a first data digest value of the first data packet and a second data digest value of the third data packet, wherein the first data digest value is configured to represent data content of the target service data carried in the first data packet, and the second data digest value is configured to represent data content of the candidate service data carried in the third data packet; a matching unit, configured to match the first data digest value with the second data digest value; and a third determining unit, configured to determine that the candidate service data and the target service data do not match in a case where the first data digest value and the second data digest value do not match.
[0115] Figure 7 is a schematic diagram of a data packet sending object determination apparatus according to an embodiment of the present application Figure Two application is applied to a first object. As Figure 7As shown, the apparatus comprises: a third acquisition module 71, configured to acquire reference service data generated by a privacy computing module of the first object, wherein the privacy computing module is configured to receive a first data packet carrying target service data, and obtain the reference service data by hiding data original state of the target service data from the first object; a processing module 72, configured to use the reference service data to handle a service; a generation module 73, configured to generate a target request in a case where a handling result of the service handling indicates that the target service data is abnormal service data, wherein the target request is used to request to determine an object that sent the first data packet to the privacy computing module; a third sending module 74, configured to send the target request to a data authentication system, wherein the data authentication system is configured to respond to the target request, extract a target signature from the first data packet, acquire a second object corresponding to the target signature from a signature and an object having a corresponding relationship, and send the second object to the first object, the target signature being allocated by the data authentication system to an object corresponding to sending the first data packet to the privacy computing module, and the target signature being used to represent object identity of the object that sends the first data packet to the privacy computing module; and a receiving module 75, configured to receive the second object returned by the data authentication system.
[0116] The data packet sending object determination apparatus provided by the embodiment of the present application allocates a corresponding target signature to an object by using a data authentication system, represents object identity of the object by using the signature, and carries the target signature every time the object sends a first data packet to a privacy computing module of a first object, so as to acquire a target request for requesting to determine an object that sends a first data packet to the privacy computing module of the first object from the first object by using the data authentication system, extract a target signature from the first data packet, and acquire a second object corresponding to the target signature from a signature and an object having a corresponding relationship, so as to trace the second object that sends the first data packet to the privacy computing module according to the target signature carried in the first data packet, and solve the problem that the sending object of the data packet cannot be determined in the related art. The effect of determining the sending object of the data packet is achieved.
[0117] Optionally, the apparatus further comprises: a fourth obtaining module, configured to obtain a target key identifier carried by the first data packet before the reference service data generated by the privacy calculation module of the first object is obtained; a fifth obtaining module, configured to obtain a target decryption key corresponding to the target key identifier generated by the data authentication system; a decryption module, configured to decrypt target signature information carried in the first data packet by using the target decryption key to obtain a candidate encryption key, wherein the target signature information is obtained by encrypting the candidate encryption key by using a target encryption key, and the target signature includes the target encryption key; a conversion module, configured to perform data conversion processing on the target service data to obtain the reference service data in a case where the candidate encryption key matches a reference encryption key, wherein the data conversion processing is used to hide the data original state of the target service data from the first object, and the reference encryption key is a key allocated by the first object to the second object for encrypting the target service data.
[0118] Optionally, the apparatus further comprises: a calculation module, configured to calculate a third data digest value of the target service data before the target key identifier carried by the first data packet is obtained; a second matching module, configured to match the third data digest value with a first data digest value, wherein the first data digest value is used to represent the data content of the target service data carried in the first data packet; and a sixth obtaining module, configured to obtain the target key identifier carried by the first data packet in a case where the third data digest value matches the first data digest value.
[0119] Figure 8 is a schematic diagram of a data packet sending object determination apparatus according to an embodiment of the present application Figure Three application to a second object. As Figure 8As shown, the apparatus comprises: a seventh acquisition module 81 configured to acquire a target signature assigned by a data authentication system, wherein the target signature is used to represent an object identity of the second object; a signature module 82 configured to sign target service data using the target signature to obtain a first data packet; and a fourth sending module 83 configured to send the first data packet to a privacy calculation module of a first object, wherein the privacy calculation module is configured to hide a data original state of the target service data from the first object to obtain reference service data, the first object is configured to use the reference service data to handle a service, and generate a target request and send the target request to the data authentication system in a case where a handling result of the service handling indicates that the target service data is abnormal service data, the target request is used to determine an object that sends the first data packet to the privacy calculation module, and the data authentication system is configured to respond to the target request, extract a target signature from the first data packet, acquire a second object corresponding to the target signature from a signature and an object having a corresponding relationship, and send the second object to the first object.
[0120] The data packet sending object determination apparatus provided by the embodiments of the present application can assign a corresponding target signature to an object by using a data authentication system, the object identity of the object is represented by the signature, the object carries the target signature every time the object sends a first data packet to a privacy calculation module of a first object, and then, after the data authentication system acquires a target request sent by the first object and used to request to determine an object that sends the first data packet to the privacy calculation module of the first object, the target signature is extracted from the first data packet, and then a second object corresponding to the target signature is acquired from a signature and an object having a corresponding relationship, so as to realize tracing the second object that sends the first data packet to the privacy calculation module according to the target signature carried in the first data packet, and solve the problem that the sending object of the data packet cannot be determined in the related art. Therefore, the effect of determining the sending object of the data packet is achieved.
[0121] Optionally, the signature module comprises: a first encryption unit configured to encrypt the target service data using a reference encryption key corresponding to the first object to obtain a second data packet; a second encryption unit configured to encrypt the reference encryption key using a target encryption key to obtain target signature information; and a generation unit configured to generate the first data packet carrying the second data packet and the target signature information.
[0122] The data packet sending object determination apparatus provided by the embodiment of the present application allocates a corresponding target signature to the object through a data authentication system, the signature represents the object identity of the object, and the object carries the target signature each time when sending a first data packet to the privacy calculation module of the first object. Then, after the data authentication system obtains a target request sent by the first object for requesting to determine the object sending the first data packet to the privacy calculation module of the first object, the target signature is extracted from the first data packet, and then the second object corresponding to the target signature is obtained from the signature and the object having the corresponding relationship, so as to realize the tracing of the second object sending the first data packet to the privacy calculation module according to the target signature carried in the first data packet, and solve the problem that the sending object of the data packet cannot be determined in the related art. Therefore, the effect of determining the sending object of the sending data packet is achieved.
[0123] The data packet sending object determination apparatus includes a processor and a memory, the above modules, units and the like are stored in the memory as program units, and the corresponding functions are realized by the processor executing the above program units stored in the memory.
[0124] The processor includes a core, and the core calls the corresponding program units in the memory. The core can be one or more, and the core parameters are adjusted to realize the determination of the sending object of the sending data packet.
[0125] The memory can include a non-permanent memory in a computer readable medium, a random access memory (RAM) and / or a non-volatile memory such as a read-only memory (ROM) or a flash memory (flash RAM), and the memory includes at least one memory chip.
[0126] The embodiment of the present application provides a computer readable storage medium, which stores a program, and the program is executed by a processor to realize the data packet sending object determination method.
[0127] The embodiment of the present application provides a processor, which is used to run a program, and the program is executed to realize the data packet sending object determination method.
[0128] Figure 9 An optional electronic device schematic diagram according to the embodiment of the present application is as shown in Figure 9As shown, the embodiment of the present application provides an electronic device, the device comprising a processor, a memory, and a program stored on the memory and executable on the processor, and the processor implements the following steps when executing the program: obtaining a target request sent by a first object, wherein the target request is used to request to determine an object that sends a first data packet to a privacy calculation module of the first object, the first data packet carries target business data required by the first object for business handling, the privacy calculation module is used to obtain reference business data by hiding a data original state of the target business data for the first object, the first object is used to use the reference business data for business handling, and the target request is generated in a case where a handling result of the business handling of the first object indicates that the target business data is abnormal business data; extracting a target signature from the first data packet, wherein the target signature is allocated by a data authentication system for an object corresponding to the first data packet for sending the first data packet to the privacy calculation module, and the target signature is used to represent an object identity of the object for sending the first data packet to the privacy calculation module; obtaining a second object corresponding to the target signature from signatures and objects having a corresponding relationship, wherein the second object is an object that sends the first data packet to the privacy calculation module; and sending the second object to the first object.
[0129] Optionally, the obtaining the second object corresponding to the target signature from the signatures and the objects having the corresponding relationship comprises: determining the second object corresponding to a target encryption key from encryption keys and objects having a corresponding relationship, wherein the target signature comprises the target encryption key, and the second object is used to sign a second data packet using the target encryption key to obtain the first data packet, and the second data packet is obtained by encrypting the target business data using a reference encryption key corresponding to the first object.
[0130] Optionally, the extracting the target signature from the first data packet comprises: obtaining a target key identifier carried by the first data packet; and determining a target encryption key corresponding to the target key identifier from key identifiers and encryption keys having a corresponding relationship, wherein the target signature comprises the target encryption key, the second object is used to sign a second data packet using the target encryption key to obtain the first data packet, and the second data packet is a data packet obtained by encrypting the target business data using a reference encryption key corresponding to the first object.
[0131] Optionally, after the second object corresponding to the target signature is obtained from the signatures and objects having a corresponding relationship, the method further comprises: sending a target data acquisition request to the second object, wherein the target data acquisition request is used to request to acquire a third data packet generated by the second object, the third data packet is a data packet generated by the second object in response to a service data acquisition request of the first object, and the service data acquisition request is used to request to acquire the target service data; matching candidate service data carried in the third data packet with the target service data carried in the first data packet; and in the case that the candidate service data and the target service data are inconsistent, determining that the second object has performed a data tampering operation on the target service data carried in the first data packet.
[0132] Optionally, the matching of the candidate service data carried in the third data packet with the target service data carried in the first data packet comprises: obtaining a first data digest value of the first data packet and a second data digest value of the third data packet, wherein the first data digest value is used to represent the data content of the target service data carried in the first data packet, and the second data digest value is used to represent the data content of the candidate service data carried in the third data packet; matching the first data digest value with the second data digest value; and in the case that the first data digest value and the second data digest value are inconsistent, determining that the candidate service data and the target service data are inconsistent.
[0133] The processor implements the following steps when executing the program: obtaining reference service data generated by a privacy calculation module of the first object, wherein the privacy calculation module is used to receive a first data packet carrying target service data, and obtain the reference service data by hiding the data original state of the target service data from the first object; performing service handling using the reference service data; in the case that the handling result of the service handling indicates that the target service data is abnormal service data, generating a target request, wherein the target request is used to request to determine an object that has sent the first data packet to the privacy calculation module; sending the target request to a data authentication system, wherein the data authentication system is used to respond to the target request, extract a target signature from the first data packet, obtain a second object corresponding to the target signature from signatures and objects having a corresponding relationship, and send the second object to the first object, the target signature is allocated by the data authentication system for an object that has sent the first data packet to the privacy calculation module, and the target signature is used to represent the object identity of the object that has sent the first data packet to the privacy calculation module; and receiving the second object returned by the data authentication system.
[0134] Optionally, before the obtaining the reference service data generated by the privacy computing module of the first object, the method further comprises: obtaining a target key identifier carried by the first data packet; obtaining a target decryption key corresponding to the target key identifier generated by the data authentication system; decrypting target signature information carried in the first data packet using the target decryption key to obtain a candidate encryption key, wherein the target signature information is obtained by encrypting the candidate encryption key using a target encryption key, and the target signature includes the target encryption key; in the case that the candidate encryption key and a reference encryption key match, performing data conversion processing on the target service data to obtain the reference service data, wherein the data conversion processing is used to hide the data original state of the target service data from the first object, and the reference encryption key is a key allocated by the first object to the second object for encrypting the target service data.
[0135] Optionally, before the obtaining the target key identifier carried by the first data packet, the method further comprises: calculating a third data digest value of the target service data; matching the third data digest value with a first data digest value, wherein the first data digest value is used to represent the data content of the target service data carried in the first data packet; in the case that the third data digest value and the first data digest value match, obtaining the target key identifier carried by the first data packet.
[0136] The processor implements the following steps when executing the program: obtaining a target signature allocated by a data authentication system, wherein the target signature is used to represent the object identity of the second object; signing target service data using the target signature to obtain a first data packet; sending the first data packet to a privacy computing module of a first object, wherein the privacy computing module is used to hide the data original state of the target service data from the first object to obtain reference service data, the first object is used to perform service handling using the reference service data, and in the case that the handling result of the service handling indicates that the target service data is abnormal service data, a target request is generated and sent to the data authentication system, the target request is used to determine the object that sends the first data packet to the privacy computing module, and the data authentication system is used to respond to the target request, extract a target signature from the first data packet, obtain a second object corresponding to the target signature from the signatures and objects having a corresponding relationship, and send the second object to the first object.
[0137] Optionally, the signing the target service data using the target signature comprises: encrypting the target service data using a reference encryption key corresponding to the first object to obtain a second data package; encrypting the reference encryption key using a target encryption key to obtain target signature information; and generating the first data package carrying the second data package and the target signature information.
[0138] The device herein can be a server, a PC, a PAD, a mobile phone, etc.
[0139] The application further provides a computer program product adapted to execute the program of the following method steps when executed on a data processing device: obtaining a target request sent by a first object, wherein the target request is used to request to determine an object that sends a first data package to a privacy calculation module of the first object, the first data package carrying target service data required by the first object for service handling, the privacy calculation module being used to obtain reference service data by hiding a data original state of the target service data from the first object, the first object being used to handle service using the reference service data, the target request being generated in a case where a handling result of the service handling of the first object indicates that the target service data is abnormal service data; extracting a target signature from the first data package, wherein the target signature is allocated by the data authentication system to an object corresponding to the first data package sent to the privacy calculation module, and the target signature is used to represent an object identity of the object that sends the first data package to the privacy calculation module; obtaining a second object corresponding to the target signature from signatures and objects having a corresponding relationship, wherein the second object is the object that sends the first data package to the privacy calculation module; and sending the second object to the first object.
[0140] Optionally, the obtaining the second object corresponding to the target signature from the signatures and the objects having the corresponding relationship comprises: determining the second object corresponding to a target encryption key from encryption keys and objects having a corresponding relationship, wherein the target signature comprises the target encryption key, and the second object is used to sign a second data package using the target encryption key to obtain the first data package, the second data package being obtained by encrypting the target service data using a reference encryption key corresponding to the first object.
[0141] Optionally, the extracting the target signature from the first data packet comprises: obtaining a target key identifier carried by the first data packet; determining a target encryption key corresponding to the target key identifier from encryption keys and key identifiers having a corresponding relationship, wherein the target signature comprises the target encryption key, and the second object is configured to use the target encryption key to sign a second data packet to obtain the first data packet, the second data packet being a data packet obtained by encrypting the target service data by the second object using a reference encryption key corresponding to the first object.
[0142] Optionally, after the second object corresponding to the target signature is obtained from the signatures and objects having the corresponding relationship, the method further comprises: sending a target data acquisition request to the second object, wherein the target data acquisition request is used to request to acquire a third data packet generated by the second object, the third data packet being a data packet generated by the second object in response to a service data acquisition request of the first object, and the service data acquisition request is used to request to acquire the target service data; matching candidate service data carried in the third data packet with the target service data carried in the first data packet; and in a case where the candidate service data and the target service data do not match, determining that the second object has performed a data tampering operation on the target service data carried in the first data packet.
[0143] Optionally, the matching the candidate service data carried in the third data packet with the target service data carried in the first data packet comprises: obtaining a first data digest value of the first data packet and a second data digest value of the third data packet, wherein the first data digest value is used to represent data content of the target service data carried in the first data packet, and the second data digest value is used to represent data content of the candidate service data carried in the third data packet; matching the first data digest value with the second data digest value; and in a case where the first data digest value and the second data digest value do not match, determining that the candidate service data and the target service data do not match.
[0144] When executed on a data processing device, the program is adapted to perform the following method steps: obtaining reference service data generated by a privacy computing module of the first object, wherein the privacy computing module is configured to receive a first data packet carrying target service data, and obtain the reference service data by hiding a data original state of the target service data from the first object; performing service handling using the reference service data; in a case where a handling result of the service handling indicates that the target service data is abnormal service data, generating a target request, wherein the target request is used to request to determine an object that sent the first data packet to the privacy computing module; sending the target request to a data authentication system, wherein the data authentication system is configured to extract a target signature from the first data packet in response to the target request, obtain a second object corresponding to the target signature from a signature and an object having a corresponding relationship, and send the second object to the first object, the target signature being allocated by the data authentication system to the object corresponding to sending the first data packet to the privacy computing module, and the target signature being used to represent an object identity of the object that sent the first data packet to the privacy computing module; and receiving the second object returned by the data authentication system.
[0145] Optionally, before the obtaining the reference service data generated by the privacy computing module of the first object, the method further comprises: obtaining a target key identifier carried by the first data packet; obtaining a target decryption key corresponding to the target key identifier and generated by the data authentication system; decrypting target signature information carried in the first data packet using the target decryption key to obtain a candidate encryption key, wherein the target signature information is obtained by encrypting the candidate encryption key using a target encryption key, and the target signature includes the target encryption key; in a case where the candidate encryption key matches a reference encryption key, performing data conversion processing on the target service data to obtain the reference service data, wherein the data conversion processing is used to hide a data original state of the target service data from the first object, and the reference encryption key is a key allocated by the first object to the second object for encrypting the target service data.
[0146] Optionally, before the obtaining the target key identifier carried by the first data packet, the method further comprises: calculating a third data digest value of the target service data; matching the third data digest value with a first data digest value, wherein the first data digest value is used to represent a data content of the target service data carried in the first data packet; and in a case where the third data digest value matches the first data digest value, obtaining the target key identifier carried by the first data packet.
[0147] When executed on a data processing device, the program is adapted to perform the following method steps: obtaining a target signature assigned by a data authentication system, wherein the target signature is used to represent an object identity of a second object; signing target service data using the target signature to obtain a first data packet; sending the first data packet to a privacy calculation module of a first object, wherein the privacy calculation module is used to hide a data original state of the target service data from the first object to obtain reference service data, the first object is used to conduct a service using the reference service data, and in a case where a handling result of the service indicates that the target service data is abnormal service data, a target request is generated and sent to the data authentication system, the target request is used to determine an object that sends the first data packet to the privacy calculation module, and the data authentication system is used to respond to the target request, extract a target signature from the first data packet, and obtain a second object corresponding to the target signature from a signature and an object having a corresponding relationship, and send the second object to the first object.
[0148] Optionally, the signing of the target service data using the target signature to obtain a first data packet comprises: encrypting the target service data using a reference encryption key corresponding to the first object to obtain a second data packet; encrypting the reference encryption key using a target encryption key to obtain target signature information; and generating the first data packet carrying the second data packet and the target signature information.
[0149] Those skilled in the art should understand that embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0150] The present application is described with reference to the flowcharts and / or block diagrams according to the methods, devices (systems), and computer program products of the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to produce a machine, so that the instructions executed by the computer or other programmable data processing devices produce a device that implements the flowcharts and / or block diagrams. Figure One one flow or multiple flows and / or blocks Figure Onean apparatus to perform one or more of the functions specified in a block or blocks.
[0151] These computer program instructions can also be stored in a computer- readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the flow Figure One one or more of the flows or flow blocks and / or blocks Figure One an apparatus to perform one or more of the functions specified in a block or blocks.
[0152] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the flow Figure One one or more of the flows or flow blocks and / or blocks Figure One an apparatus to perform one or more of the functions specified in a block or blocks.
[0153] In one typical configuration, the computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.
[0154] The memory can include non-persistent memory and / or volatile memory, such as random access memory (RAM) about which the processor can execute instructions. The memory can also include non-volatile memory, such as read only memory (ROM), electrically programmable read only memory (EPROM), electrically erasable programmable read only memory (EEPROM), programmable read only memory (PROM), erasable programmable read only memory (EPROM), flash memory, or a combination of non-volatile memories in different types. The memory can also include a storage device, such as a hard disk drive or a solid state drive. The memory can include a combination of memory devices in different technologies. The memory is an example of a computer readable storage medium.
[0155] Computer readable media includes permanent and non-permanent, removable and non-removable media implemented in any method or technology for storage of information such as computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read only memory (ROM), electrically programmable read only memory (EEPROM), flash memory or other memory technologies, compact disc read only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission medium that can be used to store information accessible to a computing device. According to the definition herein, computer readable media does not include transitory media, such as modulated data signals and carrier waves.
[0156] It is also to be noted that the terms "comprising", "including", and any other variation thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can also include other elements not expressly listed or inherent to such process, method, article, or apparatus. An element proceeded by "comprises a... " does not, without more constraints, exclude the existence of additional identical elements in the process, method, article, or apparatus that comprises the element.
[0157] Those skilled in the art will appreciate that embodiments of the present application can be devised for a method, a system, or a computer program product. Accordingly, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Furthermore, the present application can take the form of a computer program product on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage devices, etc.) embodying computer-readable program code.
[0158] The embodiments of the present application are only illustrative and are not intended to limit the present application. Various modifications and changes can be made by those skilled in the art without departing from the spirit and scope of the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the scope of the claims of the present application.
Claims
1. A method of determining a data packet transmission object, characterized by, The application is applied to a data authentication system, comprising: obtaining a target request sent by a first object, wherein the target request is used to request an object sending a first data packet to a privacy calculation module of the first object, the first data packet carries target business data required by the first object for business handling, the privacy calculation module is used to obtain reference business data by hiding the data original state of the target business data from the first object, the first object is used to handle business by using the reference business data, and the target request is generated in a case where the handling result of the first object indicates that the target business data is abnormal business data; extracting a target signature from the first data packet, wherein the target signature is allocated by the data authentication system for an object sending the first data packet to the privacy calculation module, and the target signature is used to represent the object identity of the object sending the first data packet to the privacy calculation module; obtaining a second object corresponding to the target signature from signatures and objects having a corresponding relationship, wherein the second object is an object sending the first data packet to the privacy calculation module; sending the second object to the first object.
2. The method of claim 1, wherein, The method further comprises: determining the second object corresponding to the target encryption key from encryption keys and objects having a corresponding relationship, wherein the target signature comprises the target encryption key, and the second object is used to sign a second data packet by using the target encryption key to obtain the first data packet, and the second data packet is obtained by encrypting the target business data by using a reference encryption key corresponding to the first object.
3. The method of claim 1, wherein, The method further comprises: obtaining a target key identifier carried by the first data packet; determining a target encryption key corresponding to the target key identifier from key identifiers and encryption keys having a corresponding relationship, wherein the target signature comprises the target encryption key, and the second object is used to sign a second data packet by using the target encryption key to obtain the first data packet, and the second data packet is obtained by encrypting the target business data by using a reference encryption key corresponding to the first object.
4. The method of claim 1, wherein, After obtaining the second object corresponding to the target signature from signatures and objects having a corresponding relationship, the method further comprises: sending a target data acquisition request to the second object, wherein the target data acquisition request is used to request to acquire a third data packet generated by the second object, the third data packet is a data packet generated by the second object in response to a business data acquisition request of the first object, and the business data acquisition request is used to request to acquire the target business data; matching candidate business data carried in the third data packet with the target business data carried in the first data packet; In a case where the candidate service data does not match the target service data, it is determined that the second object performs a data tampering operation on the target service data carried in the first data packet.
5. The method of claim 4, wherein, The matching of the candidate service data carried in the third data packet with the target service data carried in the first data packet comprises: obtaining a first data digest value of the first data packet and a second data digest value of the third data packet, wherein the first data digest value is used to represent the data content of the target service data carried in the first data packet, and the second data digest value is used to represent the data content of the candidate service data carried in the third data packet; matching the first data digest value with the second data digest value; in a case where the first data digest value does not match the second data digest value, it is determined that the candidate service data does not match the target service data.
6. A method of determining a data packet transmission object, characterized by, application to a first object, comprising: obtaining reference service data generated by a privacy computing module of the first object, wherein the privacy computing module is configured to receive a first data packet carrying target service data, and obtain the reference service data by hiding a data original state of the target service data from the first object; using the reference service data to handle a service; in a case where a handling result of the service handling indicates that the target service data is abnormal service data, generating a target request, wherein the target request is used to request to determine an object that sends the first data packet to the privacy computing module; sending the target request to a data authentication system, wherein the data authentication system is configured to respond to the target request, extract a target signature from the first data packet, obtain a second object corresponding to the target signature from a signature and an object having a corresponding relationship, and send the second object to the first object, the target signature being allocated by the data authentication system to an object that sends the first data packet to the privacy computing module, and the target signature being used to represent an object identity of an object that sends the first data packet to the privacy computing module; receiving the second object returned by the data authentication system.
7. The method of claim 6, wherein, Before the obtaining of the reference service data generated by the privacy computing module of the first object, the method further comprises: obtaining a target key identifier carried by the first data packet; obtaining a target decryption key corresponding to the target key identifier generated by the data authentication system; decrypting target signature information carried in the first data packet using the target decryption key to obtain a candidate encryption key, wherein the target signature information is encrypted using a target encryption key, and the target signature includes the target encryption key; In a case where the candidate encryption key matches the reference encryption key, performing data conversion processing on the target service data to obtain the reference service data, wherein the data conversion processing is used to hide the data original state of the target service data from the first object, and the reference encryption key is a key allocated by the first object to the second object for encrypting the target service data.
8. The method of claim 7, wherein, Before the target key identifier carried in the first data packet is obtained, the method further comprises: calculating a third data digest value of the target service data; matching the third data digest value with a first data digest value, wherein the first data digest value is used to represent the data content of the target service data carried in the first data packet; in a case where the third data digest value matches the first data digest value, obtaining the target key identifier carried in the first data packet.
9. A method of determining a data packet transmission object, characterized by, Applied to the second object, comprising: obtaining a target signature allocated by a data authentication system, wherein the target signature is used to represent the object identity of the second object; signing target service data using the target signature to obtain a first data packet; sending the first data packet to a privacy calculation module of the first object, wherein the privacy calculation module is used to hide the data original state of the target service data from the first object to obtain reference service data, the first object is used to perform service handling using the reference service data, and in a case where the handling result of the service handling indicates that the target service data is abnormal service data, a target request is generated and sent to the data authentication system, the target request is used to determine the object sending the first data packet to the privacy calculation module, and the data authentication system is used to respond to the target request, extract a target signature from the first data packet, obtain the second object corresponding to the target signature from the signatures and objects having a corresponding relationship, and send the second object to the first object.
10. The method of claim 9, wherein, The target service data is signed using the target signature to obtain a first data packet, comprising: encrypting the target service data using a reference encryption key corresponding to the first object to obtain a second data packet; encrypting the reference encryption key using a target encryption key to obtain target signature information; generating the first data packet carrying the second data packet and the target signature information.
11. An apparatus for determining a data packet transmission object, characterized by comprising: Applied to the data authentication system, comprising: The first obtaining module is configured to obtain a target request sent by a first object, wherein the target request is used to request an object that determines to send a first data packet to a privacy calculation module of the first object, the first data packet carries target business data required by the first object for business handling, the privacy calculation module is used to obtain reference business data by hiding a data original state of the target business data from the first object, the first object is used to perform business handling by using the reference business data, and the target request is generated in a case where a handling result of the business handling of the first object indicates that the target business data is abnormal business data. The extraction module is configured to extract a target signature from the first data packet, wherein the target signature is allocated by a data authentication system for an object that is used to send the first data packet to the privacy calculation module, and the target signature is used to represent an object identity of the object that is used to send the first data packet to the privacy calculation module. The second obtaining module is configured to obtain a second object corresponding to the target signature from signatures and objects having a corresponding relationship, wherein the second object is an object that sends the first data packet to the privacy calculation module. The first sending module is configured to send the second object to the first object.
12. An apparatus for determining a data packet transmission object, characterized by comprising: The application is applied to a first object and includes the following modules. The third obtaining module is configured to obtain reference business data generated by a privacy calculation module of the first object, wherein the privacy calculation module is used to receive a first data packet carrying target business data, and obtain the reference business data by hiding a data original state of the target business data from the first object. The processing module is configured to perform business handling by using the reference business data. The generation module is configured to generate a target request in a case where a handling result of the business handling indicates that the target business data is abnormal business data, wherein the target request is used to request an object that determines to send the first data packet to the privacy calculation module. The third sending module is configured to send the target request to a data authentication system, wherein the data authentication system is used to respond to the target request, extract a target signature from the first data packet, obtain a second object corresponding to the target signature from signatures and objects having a corresponding relationship, and send the second object to the first object, the target signature is allocated by the data authentication system for an object that is used to send the first data packet to the privacy calculation module, and the target signature is used to represent an object identity of the object that is used to send the first data packet to the privacy calculation module. The receiving module is configured to receive the second object returned by the data authentication system.
13. An apparatus for determining a data packet transmission object, characterized by comprising: The application is applied to a second object and includes the following modules. The seventh obtaining module is configured to obtain a target signature allocated by a data authentication system, wherein the target signature is used to represent an object identity of the second object. The signature module is configured to sign target business data by using the target signature to obtain a first data packet. A fourth sending module is configured to send the first data packet to a privacy computing module of a first object, wherein the privacy computing module is configured to hide the data original state of the target business data from the first object to obtain reference business data, the first object is configured to use the reference business data to handle a business, and generate a target request and send the target request to the data authentication system in a case where a handling result of the business handling indicates that the target business data is abnormal business data, the target request is used to determine an object that sends the first data packet to the privacy computing module, and the data authentication system is configured to respond to the target request, extract a target signature from the first data packet, obtain a second object corresponding to the target signature from a signature and an object having a corresponding relationship, and send the second object to the first object.
14. A processor, comprising: The processor is configured to run a program, and the program is configured to perform the method for determining a data packet sending object according to any one of claims 1 to 10 when the program is running.
15. An electronic device, comprising: The apparatus includes one or more processors and memory storing one or more programs, wherein the one or more programs, when executed by the one or more processors, cause the one or more processors to implement the method for determining a data packet sending object according to any one of claims 1 to 10.
Citation Information
Patent Citations
Safety data transferring method and system
CN102196423A
Data processing method and device based on privacy calculation, equipment and storage medium
CN115333775A