Data encryption supervision method and device in data flow

CN116827642BActive Publication Date: 2026-09-18HANGZHOU NUOWEI INFORMATION TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310797740.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-30
Publication Date
2026-09-18
Estimated Expiration
2043-06-30

AI Technical Summary

Technical Problem

但是采用这种方案,无法监管了解详细的计算过程,例如无法确定数据提供方数据加密并传输的时间、无法确定计算方何时解密数据并进行计算、也无法确定数据计算方何时计算得到计算结果并进行加密,也无法保证监管方不会使用其中的密钥对存储的密文计算结果进行解密,进而泄露计算结果

Benefits of technology

[0079]In summary, embodiments of the present invention provide a data encryption supervision method and apparatus for data circulation. The method includes: a supervision service issuing an encrypted computing task to a first data computing party; receiving a first key request from the first data computing party, and sending a computing task decryption key to the first data computing party according to the first key request, so that the first data computing party uses the computing task decryption key to decrypt the encrypted computing task, and performs calculations based on the decrypted computing task to obtain a calculation result; receiving a second key request from the first data computing party, and sending a calculation result encryption key to the first data computing party according to the second key request, so that the first data computing party uses the calculation result encryption key to encrypt the calculation result, and sends the encrypted calculation result to a result requesting party; receiving a third key request from the result requesting party, and sending a calculation result decryption key to the result requesting party according to the third key request, so that the result requesting party uses the calculation result decryption key to decrypt the calculation result received from the first data computing party. The technical solution provided by this invention manages the key transmission process, thereby achieving key supervision at each stage of data provision, transmission, and computation. In this process, data encryption, data decryption, intermediate data encryption, intermediate data decryption, computation result encryption, and computation result decryption all require the exchange of keys through the supervisory service provider. Thus, the supervisory service provider can supervise the entire computation process and computation time, improving the security of multi-participant data computation and transmission processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116827642B_ABST
    Figure CN116827642B_ABST
Patent Text Reader

Abstract

The embodiment of the present application relates to a kind of data encryption supervision method and device in data flow, the method comprises: the first data computing party is issued to the supervisory service direction encrypted computing task;Receive the first key request of first data computing party, according to the first key request, send computing task decryption key to first data computing party;Receive the second key request of first data computing party, according to the second key request, send computing result encryption key to first data computing party;Receive the third key request of result demand party, according to the third key request, send computing result decryption key to result demand party.The technical scheme provided by the embodiment of the present application, by the management of key transmission process, the key supervision is realized in each link of data providing, transmission and computing, improves the security of multi-participant data computing and transmission process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of privacy computing technology, and in particular to a data encryption and monitoring method and apparatus for data circulation. Background Technology

[0002] Distributed computing involved in data circulation poses a risk of privacy leaks. In existing distributed computing regulatory scenarios, a regulator is typically appointed to authenticate all participants and send them keys and other information. Each participant uses the key to encrypt and decrypt the data, perform calculations, and transmit the data. However, this approach lacks oversight of the detailed computation process. For example, it's impossible to determine when the data provider encrypts and transmits the data, when the computer decrypts the data and performs calculations, when the computer obtains the result and encrypts it, or whether the regulator will use the key to decrypt the stored encrypted results, thus leaking the computation outcome. Summary of the Invention

[0003] Based on the above-mentioned situation of the prior art, the purpose of this invention is to provide a data encryption supervision method and apparatus in data circulation, which improves the security of multi-participant data calculation and transmission processes by managing the key transmission process.

[0004] To achieve the above objectives, according to one aspect of the present invention, a data encryption supervision method is provided, applied to a supervision service provider, the method comprising:

[0005] The encrypted computation task is sent to the first data computation party;

[0006] Receive a first key request from the first data computing party. The first key request is sent by the first data computing party after confirming that the computing task has been transmitted.

[0007] According to the first key request, a computing task decryption key is sent to the first data computing party so that the first data computing party can use the computing task decryption key to decrypt the encrypted computing task and perform calculations based on the decrypted computing task to obtain the calculation result.

[0008] The system receives a second key request from the first data computing party, sends a calculation result encryption key to the first data computing party according to the second key request, so that the first data computing party can use the calculation result encryption key to encrypt the calculation result, and send the encrypted calculation result to the receiving result request party.

[0009] The receiving party requests a third key.

[0010] According to the third key request, a calculation result decryption key is sent to the result requester so that the result requester can use the calculation result decryption key to decrypt the calculation result received from the first data calculation party.

[0011] Furthermore, the method also includes:

[0012] Receive a fourth key request from the data provider, send a data encryption key to the data provider according to the fourth key request, so that the data provider can use the data encryption key to encrypt the data, and send the encrypted data and the fifth data volume information to the first data calculation party;

[0013] The system receives a fifth key request from the first data computing party, which is sent by the first data computing party after confirming that the data transmission is complete based on the fifth data volume information.

[0014] According to the fifth key request, a data decryption key is sent to the first data computing party so that the first data computing party can use the data decryption key to decrypt the data received from the data provider to obtain intermediate data for calculation. The intermediate data is then used to perform calculations in a trusted execution environment or a trusted virtual machine to obtain the calculation result.

[0015] Furthermore, the method also includes:

[0016] Receive a sixth key request from the first data computing party, and send an intermediate data encryption key to the first data computing party according to the sixth key request, so that the first data computing party can encrypt the intermediate data using the intermediate data encryption key, and then transmit the encrypted intermediate data and the seventh data volume information to at least one second data computing party.

[0017] Receive at least one seventh key request from a second data computing party, the seventh key request being sent by the second data computing party after confirming the completion of intermediate data transmission based on the seventh data volume information;

[0018] The seventh key request sends an intermediate data decryption key to at least one second data computation party, so that the at least one second data computation party can use the intermediate data decryption key to decrypt the intermediate data in a trusted execution environment or a trusted virtual machine, and use the decrypted intermediate data to perform joint computation.

[0019] Furthermore, the method also includes:

[0020] Record the first sending time information of sending the computation task decryption key, the second sending time information of sending the computation result encryption key, the third sending time information of sending the computation result decryption key, the fourth sending time information of sending the data encryption key, the fifth sending time information of sending the data decryption key, the sixth sending time information of sending the intermediate data encryption key, and the seventh sending time information of sending the intermediate data decryption key.

[0021] Store the first, second, third, fourth, fifth, sixth, and seventh transmission time information into the information storage space;

[0022] Data security analysis is performed based on the information stored in the information storage space.

[0023] Furthermore, the information storage space includes a blockchain.

[0024] Furthermore, the method also includes:

[0025] Receive a key fragmentation request from the first data computation party, and generate a first computation result key fragment based on the key fragmentation request;

[0026] The first calculation result key fragment is sent to the first data computing party so that the first data computing party can use the first algorithm to process the first calculation result key fragment and the second calculation result key fragment to generate a calculation result encryption key. The second calculation result key fragment is generated locally by the first data computing party and sent to the result requester.

[0027] Receive encrypted calculation results, wherein the encrypted calculation results are generated by the first data calculation party locally by encrypting the calculation results using a calculation result encryption key;

[0028] According to the third key request, the encrypted calculation result and the first calculation result key fragment are sent to the result requester so that the result requester can use the first calculation result key fragment and the second calculation result key fragment to generate a calculation result decryption key to decrypt the encrypted calculation result.

[0029] Furthermore, the method also includes:

[0030] Receive a key fragmentation request from the data provider, and generate a first data key fragment based on the key fragmentation request;

[0031] The first data key fragment is sent to the data provider so that the data provider can use the first algorithm to process the first data key fragment and the second data key fragment to generate a data encryption key. The second data key fragment is generated locally by the data provider.

[0032] The first data key fragment is sent to the first data computing party in accordance with the fifth key request, so that the first data computing party can generate a data decryption key based on the first data key fragment.

[0033] Furthermore, the first data calculation party confirms that the calculation task has been transmitted based on the first data volume information sent by the regulatory service provider; the result request party confirms that the calculation result has been transmitted based on the third data volume information sent by the regulatory service provider.

[0034] The first data volume information indicates the data size of the computation task; the third data volume information indicates the data size of the computation result; the fifth data volume information indicates the data size of the data; and the seventh data volume information indicates the data size of the intermediate data.

[0035] According to a second aspect of the present invention, a data encryption monitoring method is provided, applied to at least one data computation party, the method comprising:

[0036] Receive encrypted computing tasks and initial data volume information sent by the regulatory service provider;

[0037] After confirming the completion of the computing task transmission based on the first data volume information, a first key request is sent to the regulatory service provider based on the computing task to obtain the computing task decryption key from the regulatory service provider, and the encrypted computing task is decrypted using the computing task decryption key.

[0038] In a trusted execution environment or trusted virtual machine, the computation results are obtained by performing computations based on the decrypted computation task.

[0039] Send a second key request to the regulatory service provider to obtain the encryption key for the calculation result. Use the encryption key to encrypt the calculation result and send the encrypted calculation result to the receiving party.

[0040] Furthermore, the method also includes:

[0041] A sixth key request is sent to the regulatory service provider to obtain the intermediate data encryption key from the regulatory service provider. After encrypting the intermediate data with the intermediate data encryption key, the encrypted intermediate data and the seventh data volume information are transmitted to at least one other data computing party so that at least one other data computing party can decrypt the intermediate data and perform joint calculations.

[0042] In a trusted execution environment or trusted virtual machine, joint computation is performed with at least one other data computation party to obtain the computation result.

[0043] Furthermore, the method also includes:

[0044] According to the computing task, a data request is sent to the data provider to obtain encrypted data, fifth data volume information and second data key fragments for computing from the data provider;

[0045] After confirming the completion of data transmission based on the fifth data volume information, a fifth key request is sent to the regulatory service provider to obtain the first data key fragment. The second algorithm is then used to process the first data key fragment and the second data key fragment to generate a data decryption key.

[0046] The encrypted data received from the data provider is decrypted using this data decryption key to obtain intermediate data for computation.

[0047] The intermediate data is used to perform calculations in a trusted execution environment or a trusted virtual machine to obtain the calculation results.

[0048] Furthermore, the method also includes:

[0049] According to the computing task, a data request is sent to the data provider to obtain the first temporary public key from the data provider;

[0050] Generate a second temporary public-private key pair and a second symmetric key, wherein the second temporary public-private key pair includes a second temporary public key and a second temporary private key;

[0051] Send a second temporary public key to the data provider and receive a first temporary public key sent by the data provider;

[0052] Send a fifth key request to the regulatory service provider to obtain the encrypted data, the encrypted first symmetric key, and the encrypted first temporary private key from the regulatory service provider;

[0053] The system receives encrypted data, an encrypted first symmetric key, and an encrypted first temporary private key from the regulatory service provider. It then decrypts the encrypted first temporary private key using a second temporary private key to obtain the first temporary private key. Finally, it decrypts the encrypted first symmetric key using the first temporary private key to obtain the first symmetric key. Finally, it decrypts the encrypted data using the first symmetric key to obtain the data used for computation.

[0054] According to a third aspect of the present invention, a data encryption supervision method is provided, applied to a data provider, the method comprising:

[0055] Receive a data request from the first data computing party, and send a fourth key request to the regulatory service party based on the data request in order to obtain the data encryption key from the regulatory service party;

[0056] The data is encrypted using the data encryption key, and the encrypted data is sent to the first data calculation party.

[0057] Furthermore, the method also includes:

[0058] The system receives a data request from a first data computing party, generates a second data key fragment based on the data request, and sends a key fragment request to a regulatory service party so that the regulatory service party generates a first data key fragment based on the key fragment request.

[0059] The system receives a first data key fragment sent by the regulatory service provider, processes the first data key fragment and the second data key fragment using a first algorithm, and generates a data encryption key.

[0060] The data is encrypted using the data encryption key, and the encrypted data and the second data key fragment are sent to the first data computing party.

[0061] Furthermore, the method also includes:

[0062] Receive a data request from a first data computing party, and generate a first temporary public-private key pair and a first symmetric key based on the data request. The first temporary public-private key pair includes a first temporary public key and a first temporary private key.

[0063] Send a first temporary public key to the first data computation party, and receive a second temporary public key sent by the first data computation party;

[0064] The data is encrypted using the first symmetric key to obtain encrypted data; the first symmetric key is encrypted using the first temporary public key to generate an encrypted first symmetric key; the first temporary private key is encrypted using the second temporary public key to generate an encrypted first temporary private key.

[0065] The encrypted data, the first encrypted symmetric key, and the first encrypted temporary private key are sent to the regulatory service provider.

[0066] According to a fourth aspect of the present invention, a data encryption monitoring device is provided, applied to a monitoring service provider, the device comprising:

[0067] The task distribution module is used to distribute encrypted computing tasks to the first data computing party.

[0068] The computation task decryption key module is used to receive a first key request from the first data computation party, and send a computation task decryption key to the first data computation party according to the first key request, so that the first data computation party can use the computation task decryption key to decrypt the encrypted computation task, and perform computation based on the decrypted computation task to obtain the computation result.

[0069] The calculation result encryption module is used to receive a second key request from the first data calculation party, send a calculation result encryption key to the first data calculation party according to the second key request, so that the first data calculation party can use the calculation result encryption key to encrypt the calculation result, and send the encrypted calculation result to the result receiving party.

[0070] The calculation result decryption module is used to receive a third key request from the result requester, and send a calculation result decryption key to the result requester according to the third key request, so that the result requester can use the calculation result decryption key to decrypt the calculation result received from the first data calculation party.

[0071] According to a fifth aspect of the present invention, a data encryption monitoring device is provided, applied to at least one data computing party, the device comprising:

[0072] The computation task receiving module is used to receive encrypted computation tasks sent by the regulatory service provider.

[0073] The computing task encryption module is used to send a first key request to the regulatory service provider based on the computing task in order to obtain the computing task decryption key from the regulatory service provider, and to decrypt the encrypted computing task using the computing task decryption key;

[0074] The computation module is used to perform calculations based on the decrypted computation task and obtain the calculation results in a trusted execution environment or a trusted virtual machine.

[0075] The settlement result encryption module is used to send a second key request to the regulatory service provider to obtain the calculation result encryption key from the regulatory service provider, encrypt the calculation result using the calculation result encryption key, and send the encrypted calculation result to the receiving result requester.

[0076] According to a sixth aspect of the present invention, a data encryption monitoring device is provided, applied to a data provider, the device comprising:

[0077] The data providing module is used to receive a data request from the first data computing party and send a fourth key request to the regulatory service party based on the data request in order to obtain the data encryption key from the regulatory service party.

[0078] The data encryption module is used to encrypt the data using the data encryption key and send the encrypted data to the first data computing party.

[0079] In summary, embodiments of the present invention provide a data encryption supervision method and apparatus for data circulation. The method includes: a supervision service issuing an encrypted computing task to a first data computing party; receiving a first key request from the first data computing party, and sending a computing task decryption key to the first data computing party according to the first key request, so that the first data computing party uses the computing task decryption key to decrypt the encrypted computing task, and performs calculations based on the decrypted computing task to obtain a calculation result; receiving a second key request from the first data computing party, and sending a calculation result encryption key to the first data computing party according to the second key request, so that the first data computing party uses the calculation result encryption key to encrypt the calculation result, and sends the encrypted calculation result to a result requesting party; receiving a third key request from the result requesting party, and sending a calculation result decryption key to the result requesting party according to the third key request, so that the result requesting party uses the calculation result decryption key to decrypt the calculation result received from the first data computing party. The technical solution provided by this invention manages the key transmission process, thereby achieving key supervision at each stage of data provision, transmission, and computation. In this process, data encryption, data decryption, intermediate data encryption, intermediate data decryption, computation result encryption, and computation result decryption all require the exchange of keys through the supervisory service provider. Thus, the supervisory service provider can supervise the entire computation process and computation time, improving the security of multi-participant data computation and transmission processes. Attached Figure Description

[0080] Figure 1 This is a flowchart of a data encryption and monitoring method provided in an embodiment of the present invention;

[0081] Figure 2 This is a flowchart of a data encryption and monitoring method provided in another embodiment of the present invention;

[0082] Figure 3 This is a flowchart of a data encryption and monitoring method provided in another embodiment of the present invention;

[0083] Figure 4 This is a schematic diagram illustrating data interaction between parties in the data encryption and supervision method provided in this embodiment of the invention;

[0084] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation

[0085] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to specific embodiments and the accompanying drawings. It should be understood that these descriptions are merely exemplary and not intended to limit the scope of the invention. Furthermore, descriptions of well-known structures and techniques are omitted in the following description to avoid unnecessarily obscuring the concept of the invention.

[0086] It should be noted that, unless otherwise defined, the technical or scientific terms used in one or more embodiments of the present invention should have the ordinary meaning understood by one of ordinary skill in the art to which this disclosure pertains. The terms "first," "second," and similar terms used in one or more embodiments of the present invention do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Terms such as "comprising" or "including" mean that the element or object preceding the word encompasses the element or object listed following the word and its equivalents, without excluding other elements or objects. Terms such as "connected" or "linked" are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect.

[0087] The technical solution of the present invention will now be described in detail with reference to the accompanying drawings. An embodiment of the present invention provides a data encryption and monitoring method, applied to a monitoring service provider. Figure 1 This is a flowchart of the data encryption and monitoring method of this embodiment of the present invention, as follows: Figure 1 As shown, the method includes the following steps:

[0088] S102. An encrypted computation task is issued to the first data computation party. At the start of the computation, the regulatory service provider issues an encrypted computation task. Upon receiving the task, each data computation party actively requests the regulatory service provider to obtain the task decryption key. This key is then used to decrypt the encrypted computation task, obtaining the plaintext computation task, and computation begins. Before computation begins, the regulatory service provider may pre-confirm the participants in this multi-party computation. These participants may include at least one data provider, a result requester, and at least one data computation party. The data provider provides data for computation based on the content of the computation task; for example, in a financial services scenario, this data provider could be a bank or other provider of financial data. The data computation party provides computing power services based on the content of the computation task. There may be one or more data computation parties, which can perform multi-party joint computation through data interaction. The result requester is, for example, a user who proposes a computation task and expects the corresponding computation result. In this step, the regulatory service provider encrypts, for example, the computation task pre-proposed by the result requester, and saves the computation task decryption key. The encrypted computation task is then issued to the first data computation party executing the computation task. The encryption of computing tasks can employ existing encryption methods, including but not limited to symmetric encryption and asymmetric encryption, without specific limitations.

[0089] S104. Receive the first key request from the first data computing party, and send a computation task decryption key to the first data computing party according to the first key request. This allows the first data computing party to decrypt the encrypted computation task using the computation task decryption key and perform computation based on the decrypted task to obtain the computation result. The first key request is sent by the first data computing party after confirming the completion of the computation task transmission. In this scheme, the monitoring service provider can issue corresponding decryption keys based on the key requests from each party. The key requests from each party are generated after completing the corresponding stage of processing. The process of verifying the completion of the stage processing and generating the key request can be completed in a trusted execution environment, thus reliably confirming that each party has completed the corresponding stage task and recording the corresponding time information. In this step, based on the first key request from the first data computing party, the stored computation task decryption key is sent to the first data computing party through a pre-established connection. While issuing encrypted computation tasks, the monitoring service provider can also send first data volume information to the first data computation provider. This first data volume information indicates the size of the computation task, allowing the first data computation provider to confirm whether the computation task has been completely transmitted. Upon confirming the completion of the computation task, the first data computation provider sends a first key request to the monitoring service provider. This configuration allows the recipient of computation tasks, results, or data to confirm whether the received content has been completely received based on the data volume information, avoiding problems caused by accidental interruptions in the reception process leading to the mistaken belief that reception is complete.

[0090] S106. Receive a second key request from the first data computing party, and send a calculation result encryption key to the first data computing party according to the second key request, so that the first data computing party can use the calculation result encryption key to encrypt the calculation result, and send the encrypted calculation result to the receiving party. In this step, according to the second key request from the first data computing party, a calculation result encryption key for encrypting the calculation result is sent to the first data computing party. This calculation result encryption key can be generated locally by the regulatory service provider, or it can be jointly generated by the regulatory service provider and the first data computing party.

[0091] S108. Receive the third key request from the result requester, and send a calculation result decryption key to the result requester according to the third key request, so that the result requester can use the calculation result decryption key to decrypt the calculation result received from the first data calculation party. The third key request is sent by the result requester after confirming that the calculation result transmission is complete. In this step, a calculation result decryption key for decrypting the calculation result is sent to the result requester according to the third key request. Similar to steps S102 and S104 above, the supervisory service provider can also send third data volume information to the result requester while issuing the encrypted calculation task. The third data volume information indicates the data size of the calculation result, so the result requester can confirm whether the calculation result has been transmitted completely based on the third data volume information, and send a third key request to the supervisory service provider after confirming that the calculation result has been received.

[0092] According to certain optional embodiments, the encryption key and decryption key for the calculation results in steps S106 and S108 above can be generated through the following steps:

[0093] S1062. Receive a key fragmentation request from the first data computing party, and generate a first calculation result key fragment according to the key fragmentation request.

[0094] S1064. The first calculation result key fragment is sent to the first data calculation party so that the first data calculation party uses the first algorithm to process the first calculation result key fragment and the second calculation result key fragment to generate a calculation result encryption key. The second calculation result key fragment is generated locally by the first data calculation party and sent to the result request party.

[0095] S1066. Receive the encrypted calculation result, wherein the encrypted calculation result is generated by the first data calculation party locally by encrypting the settlement result using the calculation result encryption key.

[0096] S1068. Based on the third key request, send the encrypted calculation result and the first calculation result key fragment to the result requester, so that the result requester can use the first calculation result key fragment and the second calculation result key fragment to generate a calculation result decryption key to decrypt the encrypted calculation result.

[0097] The generation of the encryption key and decryption key for the computation result can be achieved by the data computation party generating a second fragment of the computation result key, requesting the regulatory service party to generate a first fragment of the computation result key and sending it to the data computation party. Then, a first algorithm is used to process the first and second fragments of the computation result key, for example, performing a SHA256 calculation on both fragments to generate the encryption key. This encryption key is then used to encrypt the computation result. The data computation party then returns the encrypted computation result to the regulatory service party, and sends the second fragment of the computation result key to the result requester. This method prevents the regulatory service party from decrypting the computation result without authorization. When obtaining the computation result, the second computation result key fragment can be obtained from the data computation provider, and the encrypted computation result and the first computation result key fragment can be obtained from the regulatory service provider. Then, the first and second computation result key fragments can be processed using a second algorithm. For example, a SHA256 calculation can be performed on the first and second computation result key fragments to generate a computation result decryption key. This computation result decryption key can be used to decrypt the computation result to obtain the decrypted computation result.

[0098] According to certain optional embodiments, the method further includes the step of:

[0099] S110. Receive the fourth key request from the data provider, and send a data encryption key to the data provider according to the fourth key request, so that the data provider can use the data encryption key to encrypt the data, and send the encrypted data and the fifth data volume information to the first data computing party. In this step, a data encryption key for encrypting the data is sent to the data provider according to the fourth key request. This data encryption key can be generated locally by the regulatory service provider, or it can be jointly generated by the regulatory service provider and the data provider.

[0100] S112. Receive a fifth key request from the first data computing party, and send a data decryption key to the first data computing party according to the fifth key request, so that the first data computing party can use the data decryption key to decrypt the data received from the data provider to obtain intermediate data for computation. The fifth key request is sent by the first data computing party after confirming the completion of data transmission based on the fifth data volume information, which indicates the size of the transmitted data, allowing the first data computing party to confirm whether data transmission is complete. In this step, a data decryption key for decrypting the data is sent to the first data computing party according to the fifth key request.

[0101] According to certain optional embodiments, the data encryption key and data decryption key in steps S110 and S112 above can be generated by the following steps:

[0102] S1102. Receive a key fragmentation request from the data provider and generate a first data key fragment based on the key fragmentation request.

[0103] S1104. The first data key fragment is sent to the data provider so that the data provider can use the first algorithm to process the first data key fragment and the second data key fragment to generate a data encryption key. The second data key fragment is generated locally by the data provider.

[0104] S1106. Send a first data key fragment to the first data computing party according to the fifth key request, so that the first data computing party can generate a data decryption key according to the first data key fragment.

[0105] During the computation process, depending on the content of the computation task, the data provider can request the regulatory service provider to generate a first data key fragment before sending the data. Simultaneously, the data provider generates a second data key fragment locally. A first algorithm is used to process both the first and second data key fragments; for example, a SHA256 calculation can be performed on both fragments to generate a data encryption key. This encryption key is then used to encrypt the data before sending the encrypted data along with the second data key fragment to the data computation provider. When decrypting the data, the data computation provider first requests the first data key fragment from the regulatory service provider. A second algorithm is then used to process both fragments; for example, a SHA256 calculation can be performed on both fragments to generate a data decryption key. This decryption key is then used to decrypt the data before computation. Throughout the entire computation process, the same encryption and decryption keys can be used, or different encryption and decryption keys can be used.

[0106] According to some optional embodiments, when multiple data computing parties are required for computation, one data computing party receives the data for computation, transforms or performs computations on the data to obtain intermediate data, and then sends the intermediate data to the other data computing parties for joint computation. During the joint computation process, the transmission of intermediate data between the various data computing parties also needs to be encrypted and decrypted, and the encryption and decryption keys are obtained by initiating a key request to the regulatory service provider. The method further includes the following steps:

[0107] S114. Receive the sixth key request from the first data computing party, and send an intermediate data encryption key to the first data computing party according to the sixth key request, so that the first data computing party can encrypt the intermediate data using the intermediate data encryption key and then transmit the encrypted intermediate data and the seventh data quantity information to at least one second data computing party.

[0108] S116. Receive a seventh key request from at least one second data computing party, and send an intermediate data decryption key to at least one second data computing party according to the seventh key request, so that at least one second data computing party can use the intermediate data decryption key to decrypt the intermediate data. The seventh key request is sent by the second data computing party after confirming the completion of intermediate data transmission based on seventh data volume information, which indicates the size of the intermediate data.

[0109] According to certain optional embodiments, the method further includes the step of:

[0110] S118. Record the first sending time information of sending the computation task decryption key, the second sending time information of sending the computation result encryption key, the third sending time information of sending the computation result decryption key, the fourth sending time information of sending the data encryption key, the fifth sending time information of sending the data decryption key, the sixth sending time information of sending the intermediate data encryption key, and the seventh sending time information of sending the intermediate data decryption key.

[0111] S120. Store the first, second, third, fourth, fifth, sixth, and seventh transmission time information into an information storage space, such as a blockchain.

[0112] S122. Perform data security analysis based on the information stored in the information storage space. By storing the above-mentioned interaction process and the time information of each time node in the blockchain, the entire process of data interaction and computation can be monitored, traced, and information leakage can be prevented, greatly improving the security of data computation involving multiple parties.

[0113] According to certain optional embodiments, the method further includes the step of:

[0114] S124. Receive encrypted data, an encrypted first symmetric key, and an encrypted first temporary private key sent by the data provider.

[0115] S126. Receive the fifth key request from the first data computing party, and send encrypted data, an encrypted first symmetric key, and an encrypted first temporary private key to the first data computing party according to the fifth key request.

[0116] Embodiments of the present invention also provide a data encryption monitoring method, applied to at least one data computation party. Figure 2 This is a flowchart of the data encryption monitoring method of this embodiment of the present invention, as follows: Figure 2 As shown, the method includes the following steps:

[0117] S202. Receive the encrypted computation task and first data volume information sent by the regulatory service provider. The data computation provider performs data computation based on the content of the computation task, and the first data volume information is used to indicate the size of the transmitted computation task data.

[0118] S204. After confirming the completion of the computation task transmission based on the first data volume information, a first key request is sent to the regulatory service provider based on the computation task to obtain the computation task decryption key from the regulatory service provider, and the encrypted computation task is decrypted using the computation task decryption key.

[0119] S206. In a trusted execution environment (TEE) or trusted virtual machine, the calculation result is obtained by performing calculations based on the decrypted calculation task. In this step, the calculation of the data can be completed by a single data calculation party or by multiple data calculation parties through joint calculation. In various embodiments of the present invention, the data calculation parties all adopt a trusted execution environment (TEE technology) or a trusted virtual machine (such as Intel SGX) to ensure that the calculation process cannot be compromised by hackers and that the data will not be leaked.

[0120] S208. Send a second key request to the regulatory service provider to obtain the encryption key for the calculation result. Use this encryption key to encrypt the calculation result and send the encrypted result to the receiving party. In this step, the encryption key for the calculation result can be generated through the following steps:

[0121] S2082. Send a key fragmentation request to the regulatory service provider so that the regulatory service provider can generate a first calculation result encryption key fragment based on the key fragmentation request.

[0122] S2084. Generate the second calculation result encryption key fragment.

[0123] S2086. The first algorithm is used to process the first calculation result key fragment and the second calculation result key fragment to generate the calculation result encryption key.

[0124] S2088. The calculation result is encrypted using the encryption key of the calculation result, and the encrypted calculation result is sent to the regulatory service provider. The second calculation result encryption key is fragmented and sent to the result requester.

[0125] According to certain optional embodiments, the method further includes the step of:

[0126] S210. Send a data request to the data provider according to the computing task to obtain encrypted data and fifth data volume information for computing from the data provider; the fifth data volume information is used to indicate the data size of the transmitted data.

[0127] S212. After confirming the completion of data transmission based on the fifth data volume information, a fifth key request is sent to the regulatory service provider to obtain the data decryption key. The data decryption key is then used to decrypt the encrypted data received from the data provider to obtain intermediate data for computation.

[0128] S214. In a trusted execution environment or trusted virtual machine, the intermediate data is used to perform calculations to obtain the calculation result. This embodiment is applicable to situations where data calculation can be performed using only one data calculation method. In this case, the decrypted intermediate data can be used for data calculation by that data calculation method, and the calculation result can be obtained by using the intermediate data for calculation.

[0129] In step S212 above, the data decryption key can be obtained through the following steps:

[0130] S2122. Send a data request to the data provider according to the computing task to obtain encrypted data and second data key fragments for computing from the data provider.

[0131] S2124. Send a fifth key request to the regulatory service provider to obtain the first data key fragment from the regulatory service provider, and use the second algorithm to process the first data key fragment and the second data key fragment to generate a data decryption key.

[0132] S2126. Use the data decryption key to decrypt the encrypted data received from the data provider to obtain intermediate data for calculation.

[0133] In step S212 above, according to certain optional embodiments, the data decryption key can also be obtained through the following steps:

[0134] S2132. Send a data request to the data provider according to the computing task to obtain the first temporary public key from the data provider.

[0135] S2134. Generate a second temporary public-private key pair and a second symmetric key, wherein the second temporary public-private key pair includes a second temporary public key and a second temporary private key.

[0136] S2136. Send the second temporary public key to the data provider and receive the first temporary public key sent by the data provider.

[0137] S2138. Send a fifth key request to the regulatory service provider to obtain encrypted data, an encrypted first symmetric key, and an encrypted first temporary private key from the regulatory service provider.

[0138] S2140. Receive encrypted data, an encrypted first symmetric key, and an encrypted first temporary private key sent by the regulatory service provider; decrypt the encrypted first temporary private key using a second temporary private key to obtain the first temporary private key; decrypt the encrypted first symmetric key using the first temporary private key to obtain the first symmetric key; and decrypt the encrypted data using the first symmetric key to obtain the data used for computation.

[0139] In this embodiment, for example, proxy re-encryption technology can be used to generate the data decryption key. The data provider generates a first temporary public-private key pair key_pairA = (pubA, privA), and the data computer generates a second temporary public-private key pair key_pairB = (pubB, privB). The data provider and the data computer each exchange public keys through the established connection (i.e., the data provider sends its first temporary public key pubA to the data computer, and the data computer sends its second temporary public key pubB to the data provider). The data provider generates a first symmetric key `aes_k` locally and uses it to encrypt the data `data_key`, resulting in encrypted data `encrypted_data_key = AES_enc(data_key)`. The data provider then uses a first temporary public key `pubA` to encrypt the first symmetric key `aes_key`, generating an encrypted first symmetric key `encrypted_aes_k`. The data provider uses a second temporary public key `pubB` to encrypt its own first temporary private key `priA`, generating an encrypted first temporary private key `priBA`. The data provider sends the encrypted first symmetric key `encrypted_aes_key`, the encrypted data `encrypted_data_key`, and the encrypted first temporary private key `priBA` to the regulatory service provider. The data provider then requests the encrypted first symmetric key `encrypted_aes_key`, the encrypted data `encrypted_data_key`, and the encrypted first temporary private key `priBA` from the regulatory service provider, and decrypts the encrypted first temporary private key `priBA` using its own second temporary private key `priB` to obtain the first temporary private key `priA`. The first symmetric key encrypted_aes_key is obtained by decrypting the first symmetric key encrypted_aes_key using the first temporary private key priA. Finally, the first symmetric key aes_key is used to decrypt the encrypted data encrypted_data_key to obtain the decrypted data data_key. The decrypted data data_key is then used for calculation.

[0140] The data computation providers request the log interface of the monitoring service provider from within the trusted execution environment to report their computation progress. This process can be performed in a non-blocking manner (they can proceed to the next computation without waiting for a response from the central monitoring service, thus improving computation speed). After analyzing the logs, the monitoring service provider can proactively send control signals to the data computation providers (to control task pause / continue / stop). Because each data computation provider operates within the trusted execution environment, it can respond to the control signals from the monitoring service provider as expected.

[0141] According to certain optional embodiments, when multiple data computing parties are required to jointly complete a computation, one data computing party, after receiving the data for computation, transforms or performs computations to obtain intermediate data, and then sends the intermediate data to the other data computing parties for joint computation. During the joint computation process, the transmission of intermediate data between the various data computing parties also needs to be encrypted and decrypted, and the encryption and decryption keys are obtained through key requests initiated from the regulatory service provider. The method further includes the following steps:

[0142] S216. Send a sixth key request to the regulatory service provider to obtain the intermediate data encryption key from the regulatory service provider. After encrypting the intermediate data using the intermediate data encryption key, transmit the encrypted intermediate data and the seventh data volume information to at least one other data computing party, so that at least one other data computing party can decrypt the intermediate data and perform joint computation. The seventh data volume information is used to indicate the size of the transmitted intermediate data.

[0143] S218. In a trusted execution environment or a trusted virtual machine, perform joint computation with at least one other data computation party to obtain the computation result.

[0144] S220. After confirming the completion of intermediate data transmission based on the seventh data volume information, send a seventh key request to the regulatory service provider to obtain the intermediate data decryption key from the regulatory service provider.

[0145] S222. In a trusted execution environment or a trusted virtual machine, the intermediate data decryption key is used to decrypt the encrypted intermediate data received from other data computation parties, and the decrypted intermediate data is used for joint computation.

[0146] When multiple data computing parties perform joint calculations, there may be multiple intermediate data interactions. Each transmission of intermediate data needs to be encrypted and decrypted by the regulatory service provider. After multiple interactions among the data computing parties, the calculation result is obtained. The first data computing party (i.e., the data computing party that initiated the calculation) can request the result encryption key from the regulatory service provider. The regulatory service provider will issue the calculation result encryption key and record the time. After encrypting the calculation result, the data computing party will send the encrypted calculation result to the result requesting party or the regulatory service provider.

[0147] Embodiments of the present invention also provide a data encryption and monitoring method, applied to data providers. Figure 3 This is a flowchart of the data encryption monitoring method of this embodiment of the present invention, as follows: Figure 3 As shown, the method includes the following steps:

[0148] S302. Receive the data request from the first data computing party, and send a fourth key request to the regulatory service party according to the data request in order to obtain the data encryption key from the regulatory service party.

[0149] S304. Encrypt the data using the data encryption key and send the encrypted data to the first data calculation party.

[0150] In step S302 above, the data encryption key can be generated using the following method:

[0151] S3022. Receive a data request from the first data computing party, generate a second data key fragment based on the data request, and send a key fragment request to the regulatory service party so that the regulatory service party generates a first data key fragment based on the key fragment request.

[0152] S3024. Receive the first data key fragment sent by the regulatory service provider, and process the first data key fragment and the second data key fragment using the first algorithm to generate a data encryption key.

[0153] S3026. Encrypt the data using the data encryption key, and send the encrypted data and the second data key fragment to the first data computing party.

[0154] In step S302 above, according to certain optional embodiments, the data encryption key can be generated using the following method:

[0155] S3032. Receive a data request from the first data computing party, and generate a first temporary public-private key pair and a first symmetric key according to the data request. The first temporary public-private key pair includes a first temporary public key and a first temporary private key.

[0156] S3034. Send the first temporary public key to the first data computing party and receive the second temporary public key sent by the first data computing party.

[0157] S3036. Encrypt the data using the first symmetric key to obtain encrypted data; encrypt the first symmetric key using the first temporary public key to generate an encrypted first symmetric key; encrypt the first temporary private key using the second temporary public key to generate an encrypted first temporary private key.

[0158] S3038. Send the encrypted data, the encrypted first symmetric key, and the encrypted first temporary private key to the regulatory service provider.

[0159] The steps for generating the data encryption key in the above embodiments have been described in the foregoing embodiments of the present invention, and will be omitted here for repetition.

[0160] An embodiment of the present invention also provides a data encryption monitoring device, applied to a monitoring service provider, the monitoring device comprising:

[0161] The task distribution module is used to distribute encrypted computing tasks to the first data computing party.

[0162] The computation task decryption key module is used to receive a first key request from the first data computation party, and send a computation task decryption key to the first data computation party according to the first key request, so that the first data computation party can use the computation task decryption key to decrypt the encrypted computation task, and perform computation based on the decrypted computation task to obtain the computation result.

[0163] The calculation result encryption module is used to receive a second key request from the first data calculation party, send a calculation result encryption key to the first data calculation party according to the second key request, so that the first data calculation party can use the calculation result encryption key to encrypt the calculation result, and send the encrypted calculation result to the result receiving party.

[0164] The calculation result decryption module is used to receive a third key request from the result requester, and send a calculation result decryption key to the result requester according to the third key request, so that the result requester can use the calculation result decryption key to decrypt the calculation result received from the first data calculation party.

[0165] An embodiment of the present invention also provides a data encryption monitoring device, applied to at least one data computing party, the monitoring device comprising:

[0166] The computation task receiving module is used to receive encrypted computation tasks sent by the regulatory service provider.

[0167] The computing task encryption module is used to send a first key request to the regulatory service provider based on the computing task in order to obtain the computing task decryption key from the regulatory service provider, and to decrypt the encrypted computing task using the computing task decryption key;

[0168] The computation module is used to perform calculations based on the decrypted computation task and obtain the calculation results in a trusted execution environment or a trusted virtual machine.

[0169] The settlement result encryption module is used to send a second key request to the regulatory service provider to obtain the calculation result encryption key from the regulatory service provider, encrypt the calculation result using the calculation result encryption key, and send the encrypted calculation result to the receiving result requester.

[0170] An embodiment of the present invention also provides a data encryption monitoring device, applied to a data provider, the monitoring device comprising:

[0171] The data providing module is used to receive a data request from the first data computing party and send a fourth key request to the regulatory service party based on the data request in order to obtain the data encryption key from the regulatory service party.

[0172] The data encryption module is used to encrypt the data using the data encryption key and send the encrypted data to the first data computing party.

[0173] The specific process by which each module in the data encryption monitoring device provided in the above embodiments of the present invention implements its function is the same as the steps of the data encryption monitoring method provided in the above embodiments of the present invention. Therefore, repeated descriptions will be omitted here.

[0174] Figure 4 The diagram illustrates the data interaction between parties in the data encryption and supervision method provided by an embodiment of the present invention, as shown below. Figure 4 As shown, the interaction process involved in this regulatory approach is as follows:

[0175] S1. The regulatory service provider issues an encrypted computing task to the first data computing provider;

[0176] S2. The data computing party sends a first key request to the regulatory service provider based on the encrypted computing task, in order to request the computing task to decrypt the key;

[0177] S3. The regulatory service provider sends the computing task decryption key to the first data computing party;

[0178] S4. The first data calculation party uses the decryption key of the calculation task to decrypt the encrypted calculation task; S5. The calculation result is obtained by performing calculations based on the decrypted calculation task.

[0179] After the first data calculation party obtains the calculation result, it can also...

[0180] S6. The first data calculation party sends a second key request to the regulatory service provider to request the encryption key for the calculation result;

[0181] S7. The regulatory service provider sends the encryption key for the calculation result to the first data calculation provider in accordance with the second key request;

[0182] S8. The first data calculation party uses the encryption key of the calculation result to encrypt the calculation result;

[0183] S9. The first data calculation party sends the encrypted calculation result to the receiving result request party.

[0184] S10. The result requester sends a third key request to the regulatory service provider to request the decryption key for the calculation result;

[0185] S11. The regulatory service provider sends the calculation result decryption key to the result requester based on the third key request.

[0186] S12. The result requester uses the calculation result decryption key to decrypt the calculation result received from the first data calculation party.

[0187] After the first data computing party decrypts the computing task, it is also possible to...

[0188] S13. The first data computing party sends a data request to the data provider to obtain encrypted data for computing from the data provider;

[0189] S14. The data provider sends a fourth key request to the regulatory service provider in accordance with the data request in order to obtain the data encryption key from the regulatory service provider;

[0190] S15. The regulatory service provider sends the data encryption key to the data provider in accordance with the fourth key request;

[0191] S16. The data provider encrypts the data using a data encryption key;

[0192] S17. The data provider sends the encrypted data to the first data calculation party.

[0193] After receiving the encrypted data, the first data computer can also

[0194] S18. The first data computing party sends a fifth key request to the regulatory service provider to obtain the data decryption key from the regulatory service provider;

[0195] S19. The regulatory service provider sends the data decryption key to the first data computing party in accordance with the fifth key request;

[0196] S20. The first data calculation party uses the data decryption key to decrypt the data and obtain intermediate data.

[0197] S21. The first data calculation method uses intermediate data to calculate the result.

[0198] In cases where multiple data computing parties perform joint calculations, it is also possible

[0199] S22. The first data computing party sends a sixth key request to the regulatory service provider to obtain the intermediate data encryption key from the regulatory service provider;

[0200] S23. The regulatory service provider sends the intermediate data encryption key to the first data computing party;

[0201] S24. The first data calculation party uses the intermediate data encryption key to encrypt the intermediate data;

[0202] S25. The first data computing party transmits the encrypted intermediate data to at least one other data computing party;

[0203] S26. At least one other data computing party sends a seventh key request to the regulatory service provider to obtain the intermediate data decryption key from the regulatory service provider;

[0204] S27. The regulatory service provider sends the intermediate data decryption key to at least one other data computing party;

[0205] S28. At least one other data computation party uses the intermediate data decryption key to decrypt the intermediate data;

[0206] S29. The first data calculator and at least one other data calculator jointly perform calculations using the decrypted intermediate data to obtain the calculation result.

[0207] In the above-described interaction process, each encryption and decryption process has been described in the foregoing embodiments, and their repeated descriptions will be omitted here.

[0208] An embodiment of the present invention also provides an electronic device. Figure 5 The diagram shown is a structural schematic of an electronic device provided according to an embodiment of the present invention. Figure 5 As shown, the electronic device 500 includes: one or more processors 501 and a memory 502; and computer program instructions stored in the memory 502, which, when executed by the processor 501, cause the processor 501 to perform the data encryption supervision method as described in any of the above embodiments. The processor 501 may be a central processing unit (CPU) or other form of processing unit with data processing capabilities and / or instruction execution capabilities, and may control other components in the electronic device to perform desired functions.

[0209] The memory 502 may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and / or cache memory. Non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage medium, and the processor 501 may execute the program instructions to implement the steps in the data encryption supervision methods of the various embodiments of the present invention described above, and / or other desired functions.

[0210] In some embodiments, the electronic device 500 may further include an input device 503 and an output device 504, these components being connected via a bus system and / or other forms of connection mechanisms. Figure 5 (Not shown in the diagram) Interconnected. For example, when the electronic device is a standalone device, the input device 503 can be a communication network connector for receiving acquired input signals from external mobile devices. Furthermore, the input device 503 may also include, for example, a keyboard, mouse, microphone, etc. The output device 504 can output various information to the outside, and may include, for example, a monitor, speaker, printer, and communication network and its connected remote output devices.

[0211] In addition to the methods and devices described above, embodiments of the present invention may also be computer program products, including computer program instructions, which, when executed by a processor, cause the processor to perform the steps in the data encryption supervision method of any of the above embodiments.

[0212] Computer program products can be written in any combination of one or more programming languages ​​to perform the operations of the embodiments of the present invention. The programming languages ​​include object-oriented programming languages ​​such as Java and C++, as well as conventional procedural programming languages ​​such as C or similar languages. The program code can be executed entirely on the user's computing device, partially on the user's computing device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.

[0213] Furthermore, embodiments of the present invention may also be computer-readable storage media storing computer program instructions that, when executed by a processor, cause the processor to perform the steps in the data encryption monitoring methods of various embodiments of the present invention.

[0214] Computer-readable storage media may take the form of any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may, for example, include, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, or devices, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: electrical connections having one or more wires, portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0215] It should be understood that the processor in the embodiments of the present invention can be a Central Processing Unit (CPU), but it can also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor.

[0216] In summary, the embodiments of the present invention relate to a data encryption supervision method and apparatus in data circulation. The method includes: a supervision service issuing an encrypted computing task to a first data computing party; receiving a first key request from the first data computing party, and sending a computing task decryption key to the first data computing party according to the first key request, so that the first data computing party uses the computing task decryption key to decrypt the encrypted computing task, and performs calculations based on the decrypted computing task to obtain a calculation result; receiving a second key request from the first data computing party, and sending a calculation result encryption key to the first data computing party according to the second key request, so that the first data computing party uses the calculation result encryption key to encrypt the calculation result, and sends the encrypted calculation result to a result requesting party; receiving a third key request from the result requesting party, and sending a calculation result decryption key to the result requesting party according to the third key request, so that the result requesting party uses the calculation result decryption key to decrypt the calculation result received from the first data computing party. The technical solution provided by this invention manages the key transmission process, thereby achieving key supervision at each stage of data provision, transmission, and computation. In this process, data encryption, data decryption, intermediate data encryption, intermediate data decryption, computation result encryption, and computation result decryption all require the exchange of keys through the supervisory service provider. Thus, the supervisory service provider can supervise the entire computation process and computation time, improving the security of multi-participant data computation and transmission processes.

[0217] It should be understood that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of the invention (including the claims) is limited to these examples. Within the framework of this invention, technical features of the above embodiments or different embodiments can also be combined, steps can be implemented in any order, and many other variations exist regarding different aspects of one or more embodiments of the invention as described above, which are not provided in the details for the sake of brevity. The specific embodiments described above are merely illustrative or explanatory of the principles of the invention and do not constitute a limitation thereof. Therefore, any modifications, equivalent substitutions, improvements, etc., made without departing from the spirit and scope of the invention should be included within the protection scope of the invention. Furthermore, the appended claims are intended to cover all variations and modifications falling within the scope and boundaries of the appended claims, or equivalent forms of such scope and boundaries.

Claims

1. A data encryption and monitoring method, characterized in that, Applied to regulatory service providers, the method includes: The encrypted computation task is sent to the first data computation party; Receive the first key request from the first data computing party. The first key request is sent by the first data computing party after confirming that the computing task has been transmitted. According to the first key request, a computing task decryption key is sent to the first data computing party so that the first data computing party can use the computing task decryption key to decrypt the encrypted computing task and perform calculations based on the decrypted computing task to obtain the calculation result. The system receives a second key request from the first data computing party, sends a calculation result encryption key to the first data computing party according to the second key request, so that the first data computing party can use the calculation result encryption key to encrypt the calculation result, and send the encrypted calculation result to the receiving result request party. The system receives a third key request from the result requester and sends a calculation result decryption key to the result requester based on the third key request, so that the result requester can use the calculation result decryption key to decrypt the calculation result received from the first data calculation party. The method further includes: receiving a fourth key request from a data provider, sending a data encryption key to the data provider according to the fourth key request, so that the data provider uses the data encryption key to encrypt the data, and sending the encrypted data and a fifth data volume information to a first data computing party; The system receives a fifth key request from the first data computing party, which is sent by the first data computing party after confirming that the data transmission is complete based on the fifth data volume information. According to the fifth key request, a data decryption key is sent to the first data computing party so that the first data computing party can use the data decryption key to decrypt the data received from the data provider to obtain intermediate data for calculation. The intermediate data is then used to perform calculations in a trusted execution environment or a trusted virtual machine to obtain the calculation result.

2. The method according to claim 1, characterized in that, The method further includes: Receive a sixth key request from the first data computing party, and send an intermediate data encryption key to the first data computing party according to the sixth key request, so that the first data computing party can encrypt the intermediate data using the intermediate data encryption key, and then transmit the encrypted intermediate data and the seventh data volume information to at least one second data computing party. Receive at least one seventh key request from a second data computing party, the seventh key request being sent by the second data computing party after confirming the completion of intermediate data transmission based on the seventh data volume information; The seventh key request sends an intermediate data decryption key to at least one second data computation party, so that the at least one second data computation party can use the intermediate data decryption key to decrypt the intermediate data in a trusted execution environment or a trusted virtual machine, and use the decrypted intermediate data to perform joint computation.

3. The method according to claim 2, characterized in that, The method further includes: Record the first sending time information of sending the computation task decryption key, the second sending time information of sending the computation result encryption key, the third sending time information of sending the computation result decryption key, the fourth sending time information of sending the data encryption key, the fifth sending time information of sending the data decryption key, the sixth sending time information of sending the intermediate data encryption key, and the seventh sending time information of sending the intermediate data decryption key. Store the first, second, third, fourth, fifth, sixth, and seventh transmission time information into the information storage space; Data security analysis is performed based on the information stored in the information storage space.

4. The method according to claim 3, characterized in that, The information storage space includes blockchain.

5. The method according to claim 1, characterized in that, The method further includes: Receive a key fragmentation request from the first data computation party, and generate a first computation result key fragment based on the key fragmentation request; The first calculation result key fragment is sent to the first data computing party so that the first data computing party can use the first algorithm to process the first calculation result key fragment and the second calculation result key fragment to generate a calculation result encryption key. The second calculation result key fragment is generated locally by the first data computing party and sent to the result requester. Receive encrypted calculation results, wherein the encrypted calculation results are generated by the first data calculation party locally by encrypting the calculation results using a calculation result encryption key; According to the third key request, the encrypted calculation result and the first calculation result key fragment are sent to the result requester so that the result requester can use the first calculation result key fragment and the second calculation result key fragment to generate a calculation result decryption key to decrypt the encrypted calculation result.

6. The method according to claim 1, characterized in that, The method further includes: Receive a key fragmentation request from the data provider, and generate a first data key fragment based on the key fragmentation request; The first data key fragment is sent to the data provider so that the data provider can use the first algorithm to process the first data key fragment and the second data key fragment to generate a data encryption key. The second data key fragment is generated locally by the data provider. The first data key fragment is sent to the first data computing party in accordance with the fifth key request, so that the first data computing party can generate a data decryption key based on the first data key fragment.

7. The method according to claim 2, characterized in that, The first data calculation party confirms that the calculation task has been transmitted based on the first data volume information sent by the regulatory service provider; the result request party confirms that the calculation result has been transmitted based on the third data volume information sent by the regulatory service provider. The first data volume information indicates the data size of the computation task; the third data volume information indicates the data size of the computation result; the fifth data volume information indicates the data size of the data; and the seventh data volume information indicates the data size of the intermediate data.

8. A data encryption and monitoring method, characterized in that, Applied to at least one data computation method, the method includes: Receive encrypted computing tasks and initial data volume information sent by the regulatory service provider; After confirming the completion of the computing task transmission based on the first data volume information, a first key request is sent to the regulatory service provider based on the computing task to obtain the computing task decryption key from the regulatory service provider, and the encrypted computing task is decrypted using the computing task decryption key. In a trusted execution environment or trusted virtual machine, the computation results are obtained by performing computations based on the decrypted computation task. Send a second key request to the regulatory service provider to obtain the encryption key for the calculation result, encrypt the calculation result using the encryption key, and send the encrypted calculation result to the receiving result requester. According to the computing task, a data request is sent to the data provider to obtain encrypted data, fifth data volume information and second data key fragments for computing from the data provider; After confirming the completion of data transmission based on the fifth data volume information, a fifth key request is sent to the regulatory service provider to obtain the first data key fragment. The second algorithm is then used to process the first data key fragment and the second data key fragment to generate a data decryption key. The encrypted data received from the data provider is decrypted using this data decryption key to obtain intermediate data for computation. The intermediate data is used to perform calculations in a trusted execution environment or a trusted virtual machine to obtain the calculation results.

9. The method according to claim 8, characterized in that, The method further includes: A sixth key request is sent to the regulatory service provider to obtain the intermediate data encryption key from the regulatory service provider. After encrypting the intermediate data with the intermediate data encryption key, the encrypted intermediate data and the seventh data volume information are transmitted to at least one other data computing party so that at least one other data computing party can decrypt the intermediate data and perform joint calculations. In a trusted execution environment or trusted virtual machine, joint computation is performed with at least one other data computation party to obtain the computation result.

10. The method according to claim 8, characterized in that, The method further includes: According to the computing task, a data request is sent to the data provider to obtain the first temporary public key from the data provider; Generate a second temporary public-private key pair and a second symmetric key, wherein the second temporary public-private key pair includes a second temporary public key and a second temporary private key; Send a second temporary public key to the data provider and receive a first temporary public key sent by the data provider; Send a fifth key request to the regulatory service provider to obtain the encrypted data, the encrypted first symmetric key, and the encrypted first temporary private key from the regulatory service provider; The system receives encrypted data, an encrypted first symmetric key, and an encrypted first temporary private key from the regulatory service provider. It then decrypts the encrypted first temporary private key using a second temporary private key to obtain the first temporary private key. Finally, it decrypts the encrypted first symmetric key using the first temporary private key to obtain the first symmetric key. Finally, it decrypts the encrypted data using the first symmetric key to obtain the data used for computation.

11. A data encryption and monitoring method, characterized in that, Applied to data providers, the method includes: Receive a data request from the first data computing party, and send a fourth key request to the regulatory service party based on the data request in order to obtain the data encryption key from the regulatory service party; The data is encrypted using the data encryption key, and the encrypted data is sent to the first data calculation party. The system receives a data request from a first data computing party, generates a second data key fragment based on the data request, and sends a key fragment request to a regulatory service party so that the regulatory service party generates a first data key fragment based on the key fragment request. The system receives a first data key fragment sent by the regulatory service provider, processes the first data key fragment and the second data key fragment using a first algorithm, and generates a data encryption key. The data is encrypted using the data encryption key, and the encrypted data and the second data key fragment are sent to the first data computing party. The regulatory service provider is used to implement the data encryption regulatory method as described in any one of claims 1-7, and the data computing provider is used to implement the data encryption regulatory method as described in any one of claims 8-10.

12. The method according to claim 11, characterized in that, The method further includes: Receive a data request from a first data computing party, and generate a first temporary public-private key pair and a first symmetric key based on the data request. The first temporary public-private key pair includes a first temporary public key and a first temporary private key. Send a first temporary public key to the first data computation party, and receive a second temporary public key sent by the first data computation party; The data is encrypted using the first symmetric key to obtain encrypted data; the first symmetric key is encrypted using the first temporary public key to generate an encrypted first symmetric key; the first temporary private key is encrypted using the second temporary public key to generate an encrypted first temporary private key. The encrypted data, the first encrypted symmetric key, and the first encrypted temporary private key are sent to the regulatory service provider.

13. A data encryption monitoring device, characterized in that, Applied to a regulatory service provider, for implementing the method as described in any one of claims 1-7, the apparatus comprises: The task distribution module is used to distribute encrypted computing tasks to the first data computing party. The computation task decryption key module is used to receive a first key request from the first data computation party, and send a computation task decryption key to the first data computation party according to the first key request, so that the first data computation party can use the computation task decryption key to decrypt the encrypted computation task, and perform computation based on the decrypted computation task to obtain the computation result. The calculation result encryption module is used to receive a second key request from the first data calculation party, send a calculation result encryption key to the first data calculation party according to the second key request, so that the first data calculation party can use the calculation result encryption key to encrypt the calculation result, and send the encrypted calculation result to the result receiving party. The calculation result decryption module is used to receive a third key request from the result requester, and send a calculation result decryption key to the result requester according to the third key request, so that the result requester can use the calculation result decryption key to decrypt the calculation result received from the first data calculation party.

14. A data encryption monitoring device, characterized in that, Applied to at least one data computation unit for implementing the method as described in any one of claims 8-10, the apparatus comprising: The computation task receiving module is used to receive encrypted computation tasks sent by the regulatory service provider. The computing task encryption module is used to send a first key request to the regulatory service provider based on the computing task, so as to obtain the computing task decryption key from the regulatory service provider, and use the computing task decryption key to decrypt the encrypted computing task. The computation module is used to perform calculations based on the decrypted computation task and obtain the calculation results in a trusted execution environment or a trusted virtual machine. The settlement result encryption module is used to send a second key request to the regulatory service provider to obtain the calculation result encryption key from the regulatory service provider, encrypt the calculation result using the calculation result encryption key, and send the encrypted calculation result to the receiving result requester.

15. A data encryption monitoring device, characterized in that, Applied to a data provider for implementing the method as described in claim 11 or 12, the apparatus comprises: The data providing module is used to receive a data request from the first data computing party and send a fourth key request to the regulatory service party based on the data request in order to obtain the data encryption key from the regulatory service party. The data encryption module is used to encrypt the data using the data encryption key and send the encrypted data to the first data computing party.

Citation Information

Patent Citations

  • Private data processing method and system based on data envelope

    CN115643092A

  • Method for processing data in trusted computing platform and management device

    CN115795446A