Privacy protection encryption method and system based on attribute recognition

CN117749366BActive Publication Date: 2026-08-18LINGSHU TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311744205.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-18
Publication Date
2026-08-18
Estimated Expiration
2043-12-18

AI Technical Summary

Technical Problem

[0004]本发明的目的是提供基于属性识别的隐私保护加密方法及系统,用以解决现有在基于属性识别对用户隐私数据进行加密保护过程中,无法基于用户特征对用户的传输数据进行针对性地、有区别地加密处理,导致用户隐私数据加密保护控制效果不佳的问题

Benefits of technology

[0014]1. By establishing a communication connection with the user and reading the user's unique ID; based on the unique ID, calling the account database to extract the user's cloud security features; reading the user's information to be transmitted and parsing and segmenting the information to be transmitted to generate data segmentation results with attribute identifiers; reconstructing the security level of the corresponding data segmentation results using the cloud security features and attribute identifiers, and generating level clustering constraints based on the security level reconstruction results; using the security level reconstruction results as the first clustering constraint and the attribute identifiers as the second clustering constraint, performing chain clustering of the data segmentation results; generating N encrypted chains based on the chain clustering results, and performing sequential interactive encryption of the N encrypted chains, and simultaneously generating a privacy protection key to complete the encryption protection of the information to be transmitted. By combining the user account database and cloud security features to identify the attributes of each segment of the user's information to be transmitted, thereby forming a corresponding security level reconstruction, and further using the security level reconstruction and attribute identifiers as constraints to cluster the information to be transmitted to generate N encrypted chains, and generating corresponding privacy protection keys for data privacy protection, the goal of formulating a targeted protection scheme for the user's information to be transmitted is achieved, thereby improving the quality of encryption protection of user privacy data and thus improving the technical effect of improving user data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117749366B_ABST
    Figure CN117749366B_ABST
Patent Text Reader

Abstract

The application discloses a privacy protection encryption method and system based on attribute identification, and relates to the technical field of privacy protection. The method comprises the following steps: establishing a communication connection with a user, extracting the cloud security features of the user based on a unique ID; reading the information to be transmitted, and analyzing and segmenting to generate a data segmentation result with attribute identification; reconstructing the security level of the corresponding data segmentation result to generate a level clustering constraint; performing chain clustering of the data segmentation result; generating N encryption chains and sequentially interacting with encryption to synchronously generate a privacy protection key, thereby completing the encryption protection of the information to be transmitted. The method solves the problem that, in the process of encrypting and protecting user privacy data based on attribute identification, the transmission data of the user cannot be processed by targeted and differentiated encryption based on user features, resulting in poor control effect of user privacy data encryption protection. The method improves the quality of user privacy data encryption protection and the security of user data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of privacy protection technology, and in particular to a privacy protection encryption method and system based on attribute recognition. Background Technology

[0002] With the rapid development of internet technology, massive amounts of data are transmitted and stored over networks. To protect data privacy and security, various encryption technologies have emerged. Traditional encryption methods typically employ symmetric or asymmetric encryption techniques, such as DES, AES, and RSA, which suffer from encryption complexity and key management difficulties. Attribute-based privacy-preserving encryption methods, by utilizing attribute information within the data to encrypt and decrypt it, effectively reduce the challenges of key management and algorithm complexity, thus possessing significant research value and application potential.

[0003] However, existing methods for encrypting and protecting user privacy data based on attribute recognition cannot perform targeted and differentiated encryption processing of user-transmitted data based on user characteristics, resulting in poor encryption and protection control of user privacy data. Summary of the Invention

[0004] The purpose of this invention is to provide a privacy protection encryption method and system based on attribute recognition, in order to solve the problem that existing methods for encrypting and protecting user privacy data based on attribute recognition cannot perform targeted and differentiated encryption processing of user transmission data based on user characteristics, resulting in poor encryption and protection control of user privacy data.

[0005] In view of the above problems, the present invention provides a privacy-preserving encryption method and system based on attribute recognition.

[0006] In a first aspect, the present invention provides a privacy-preserving encryption method based on attribute recognition. The method is implemented through an attribute-based privacy-preserving encryption system. The method includes: establishing a communication connection with a user and reading the user's unique ID; accessing an account database based on the unique ID to extract the user's cloud security features; reading the user's information to be transmitted and parsing and segmenting the information to be transmitted to generate data segmentation results with attribute identifiers; reconstructing the security level of the corresponding data segmentation results using the cloud security features and attribute identifiers, and generating level clustering constraints based on the security level reconstruction results; performing chain clustering of the data segmentation results using the security level reconstruction results as the first clustering constraint and the attribute identifiers as the second clustering constraint; generating N encryption chains based on the chain clustering results, performing sequential interactive encryption of the N encryption chains, and simultaneously generating a privacy-preserving key to complete the encryption protection of the information to be transmitted.

[0007] Secondly, the present invention also provides a privacy-preserving encryption system based on attribute recognition, used to execute the privacy-preserving encryption method based on attribute recognition as described in the first aspect, wherein the system includes: a unique ID reading module, used to establish a communication connection with the user and read the user's unique ID; a cloud security feature extraction module, used to call an account database based on the unique ID and extract the user's cloud security features from the account database; a parsing and segmentation module, used to read the user's information to be transmitted and to parse and segment the information to be transmitted, generating a data segmentation result with attribute identifiers; a hierarchical clustering constraint generation module, used to reconstruct the security level of the corresponding data segmentation result using the cloud security features and attribute identifiers, and to generate hierarchical clustering constraints based on the security level reconstruction result; a clustering module, used to perform chain clustering of the data segmentation result using the security level reconstruction result as the first clustering constraint and the attribute identifier as the second clustering constraint; and an encryption protection module, used to generate N encryption chains based on the chain clustering result, and to perform sequential interactive encryption of the N encryption chains, and to synchronously generate a privacy protection key to complete the encryption protection of the information to be transmitted.

[0008] Thirdly, this application also provides an electronic device, including:

[0009] At least one processor;

[0010] A memory that is communicatively connected to the at least one processor;

[0011] The memory stores instructions that can be executed by the at least one processor, which, when executed by the at least one processor, enables the at least one processor to perform the method described in any one of the first aspects above.

[0012] Fourthly, a computer-readable storage medium storing a computer program that, when executed, implements the steps of the method described in any one of the first aspects above.

[0013] One or more technical solutions provided in this invention have at least the following technical effects or advantages:

[0014] 1. By establishing a communication connection with the user and reading the user's unique ID; based on the unique ID, calling the account database to extract the user's cloud security features; reading the user's information to be transmitted and parsing and segmenting the information to be transmitted to generate data segmentation results with attribute identifiers; reconstructing the security level of the corresponding data segmentation results using the cloud security features and attribute identifiers, and generating level clustering constraints based on the security level reconstruction results; using the security level reconstruction results as the first clustering constraint and the attribute identifiers as the second clustering constraint, performing chain clustering of the data segmentation results; generating N encrypted chains based on the chain clustering results, and performing sequential interactive encryption of the N encrypted chains, and simultaneously generating a privacy protection key to complete the encryption protection of the information to be transmitted. By combining the user account database and cloud security features to identify the attributes of each segment of the user's information to be transmitted, thereby forming a corresponding security level reconstruction, and further using the security level reconstruction and attribute identifiers as constraints to cluster the information to be transmitted to generate N encrypted chains, and generating corresponding privacy protection keys for data privacy protection, the goal of formulating a targeted protection scheme for the user's information to be transmitted is achieved, thereby improving the quality of encryption protection of user privacy data and thus improving the technical effect of improving user data security.

[0015] 2. The security level of data information is reconstructed by using the user's cloud security features. Because the data is distributed across different servers in the cloud computing environment through virtualization technology, it is not affected by single points of failure. This also ensures the accuracy and effectiveness of the cloud security features and provides a reliable reference and basis for subsequent information encryption protection.

[0016] 3. By calling a hash function with irreversible properties to encrypt each node in the encryption chain sequentially, the encryption quality of the information to be transmitted is improved while simplifying the calculation, effectively protecting the integrity and security of the user's data.

[0017] 4. By selecting the appropriate distributed storage device to transmit and store the information based on the security level of the information to be transmitted and the real-time application status of the distributed storage device, the differentiated management goal of data with different security levels is achieved, thereby improving the scientificity and efficiency of data encryption management and providing a basic technical effect for subsequent data retrieval.

[0018] The above description is merely an overview of the technical solution of the present invention. To better understand the technical means of the present invention and to facilitate its implementation according to the description, and to make the above and other objects, features, and advantages of the present invention more apparent, specific embodiments of the present invention are described below. It should be understood that the content described in this section is not intended to identify key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily apparent from the following description. Attached Figure Description

[0019] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are merely exemplary. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0020] Figure 1 This is a flowchart illustrating the privacy-preserving encryption method based on attribute recognition according to the present invention.

[0021] Figure 2 This is a schematic diagram illustrating the distributed transmission and storage of encryption results in the privacy-preserving encryption method based on attribute recognition of the present invention.

[0022] Figure 3 This is a schematic diagram of the privacy protection encryption system based on attribute recognition according to the present invention.

[0023] Explanation of reference numerals in the attached figures:

[0024] Unique ID reading module 11, cloud security feature extraction module 12, parsing and segmentation module 13, hierarchical clustering constraint generation module 14, clustering module 15, encryption protection module 16. Detailed Implementation

[0025] This invention provides a privacy-preserving encryption method and system based on attribute recognition. It solves the problem that existing methods for encrypting user privacy data based on attribute recognition cannot perform targeted and differentiated encryption processing based on user characteristics, resulting in poor encryption control of user privacy data. This invention achieves the goal of developing targeted protection schemes for user-transmitted information, thereby improving the quality of user privacy data encryption and ultimately enhancing user data security.

[0026] The technical solutions of the present invention will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. It should be understood that the present invention is not limited to the exemplary embodiments described herein. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention. It should also be noted that, for ease of description, only the parts related to the present invention are shown in the accompanying drawings, not all of them.

[0027] Example 1

[0028] Please see the appendix Figure 1 This invention provides a privacy-preserving encryption method based on attribute recognition, wherein the method is applied to a privacy-preserving encryption system based on attribute recognition, and the method specifically includes the following steps:

[0029] Establish a communication connection with the user and read the user's unique ID;

[0030] The user's cloud security features are extracted from the account database based on the unique ID.

[0031] Read the user's information to be transmitted, and parse and segment the information to be transmitted to generate a data segmentation result with attribute identifiers;

[0032] The security level of the corresponding data segmentation results is reconstructed based on the cloud security features and attribute identifiers, and level clustering constraints are generated based on the security level reconstruction results;

[0033] Using the security level reconstruction result as the first clustering constraint and the attribute identifier as the second clustering constraint, chain clustering of the data segmentation result is performed;

[0034] N encrypted chains are generated based on the chain clustering results, and sequential interactive encryption of the N encrypted chains is performed. A privacy protection key is generated simultaneously to complete the encryption protection of the information to be transmitted.

[0035] Specifically, the attribute-based privacy protection encryption method is applied to an attribute-based privacy protection encryption system, which can combine user account databases and cloud security features to formulate targeted protection schemes for users' information to be transmitted.

[0036] First, a communication connection is established between the user and the attribute-based privacy-preserving encryption system to obtain the user's unique ID. This unique ID serves as the sole credential for the user's network account in all transactions, including data transmission and reception. Then, based on this unique ID, the user's unique account database can be accessed, and further, the user's cloud security features can be extracted from this database. The account database refers to a database containing logs and other relevant data records of all data sent and received by the user through the account under this unique ID in the network environment. The cloud security features are the historical data encryption and distribution characteristics corresponding to the user's account. Since these features reside in a cloud computing environment, their information is distributed across different servers using virtualization technology, thus avoiding the impact of single points of failure. This ensures the accuracy and effectiveness of the cloud security features extracted by the attribute-based privacy-preserving encryption system and provides a reliable reference and basis for subsequent information encryption and protection.

[0037] Next, the information the user intends to transmit, i.e., the information to be transmitted, is obtained. This information is then parsed and segmented to obtain corresponding data segmentation results, where each data point in the segmentation results possesses a corresponding data attribute identifier. Then, based on the cloud security characteristics of the user's historical transmission data extracted earlier, combined with the attribute identifiers of the segmented data to be transmitted, the security level of the data segmentation results is assessed and analyzed, resulting in the security level reconstruction result. This security level reconstruction result is then used as a level clustering constraint, providing a basis for subsequent clustering of the transmitted information to different security levels, and laying the foundation for clustering and distributed encryption protection of the information to be transmitted.

[0038] Next, using the security level reconstruction result as the first clustering constraint and the attribute identifier as the second clustering constraint, chain clustering is performed on the data segmentation results of the information to be transmitted. Chain clustering refers to treating each segmented information segment in the aforementioned data segmentation result as a single-point cluster, and then calculating the similarity between each pair of single-point clusters. The greater the similarity, the closer the two single-point clusters are, and correspondingly, the shorter the chain between the two single-point clusters. Through this scheme, a chain is added between single-point clusters each time, with the shortest chain added first, and these chains combine the points into clusters. Since the information to be transmitted by the client at one time has limitations such as length and target object, using chain clustering to cluster the data segmentation results is reliable and effective.

[0039] Finally, based on the chain clustering results, N encrypted chains of the data to be transmitted are generated, and these N encrypted chains are sequentially and interactively encrypted. Correspondingly, a privacy protection key is generated synchronously, and the encryption protection of the information to be transmitted is completed based on the privacy protection key. By combining the user account database and cloud security features to identify the attributes of each segment of the user's information to be transmitted, a corresponding security level reconstruction is formed. Furthermore, the security level reconstruction and attribute identifiers are used as constraints to cluster the information to be transmitted, generating N encrypted chains, and correspondingly generating a privacy protection key for data privacy protection. This achieves the goal of developing a targeted protection scheme for the user's information to be transmitted, and achieves the technical effect of improving the quality of encryption protection of user privacy data, thereby improving the security of user data.

[0040] Furthermore, the present invention also includes the following steps:

[0041] During the encryption process, the privacy protection key is used to call the hash function to perform encryption calculations on the data of the first node of the encryption chain, generating the first encrypted ciphertext.

[0042] The first encrypted ciphertext and the privacy protection key are sent synchronously to the second node, and the first encrypted ciphertext and the data of the second node are used as encrypted data to perform encryption calculations and generate the second encrypted ciphertext.

[0043] The encryption process is completed sequentially for N encryption chains to achieve encryption protection of the information to be transmitted.

[0044] Specifically, based on the privacy protection key synchronously generated during the sequential interactive encryption of the N encryption chains, a hash function is invoked to perform encryption calculations on the data of the first node on the encryption chain, thus obtaining the first encrypted ciphertext of the first node. The hash function can perform irreversible one-way encryption processing on data of different lengths on the node, thereby effectively improving the quality of information encryption protection for the user. Next, the first encrypted ciphertext and the privacy protection key are synchronously sent to the second node on the encryption chain, and the data of the first encrypted ciphertext and the second node are used as encryption data to perform encryption calculations on the second node, correspondingly generating the second encrypted ciphertext. This process continues iteratively, sequentially completing the encryption processing of all nodes on the N encryption chains, ultimately completing the encryption protection of the information to be transmitted.

[0045] By calling a hash function with irreversible properties to encrypt each node in the encryption chain sequentially, the encryption protection quality of the information to be transmitted is improved, effectively protecting the user's data security.

[0046] Further details are attached. Figure 2 As shown, the present invention further includes the following steps:

[0047] The overall information security level of the information to be transmitted is calculated based on the security level reconstruction results.

[0048] Real-time status matching is performed based on the calculation results of the comprehensive information security level and the idle status of the distributed storage devices;

[0049] Distributed transmission and storage of encrypted results based on real-time status matching results.

[0050] Specifically, after reconstructing the security level of the corresponding data segmentation results based on the user's cloud security characteristics and the attribute identifier of the information to be transmitted, the information security level of the information to be transmitted is obtained by comprehensive analysis based on the security level of each segmented data segment in the security level reconstruction result. This results in the calculation of the information security level. Then, the information security level calculation result is matched with the idle state of the distributed storage device in real time, and the encrypted result is transmitted and stored in a distributed manner according to the real-time state matching result.

[0051] By selecting the appropriate distributed storage device to transmit and store the information based on its security level and the real-time application of the distributed storage device, the goal of differentiated management of data with different security levels is achieved. This improves the scientificity and efficiency of data encryption management and provides a foundational technical effect for subsequent data retrieval.

[0052] Furthermore, the present invention includes the following steps:

[0053] The data volume is evaluated based on the data segmentation results, and the preset number of segments is configured according to the data volume evaluation results;

[0054] Data evaluation within the data segmentation results is performed using the first clustering constraint and the second clustering constraint, and a constraint limit space is established.

[0055] The preset number of segments and the constraint limit space are input into the clustering configuration network to generate clustering configuration results, wherein the clustering configuration results include cluster center distribution results and clustering search step size;

[0056] Chain clustering of the data segmentation results is performed based on the clustering configuration results.

[0057] Furthermore, the present invention includes the following steps:

[0058] Based on the cluster center distribution results, perform adjacent data matching within the corresponding data segmentation results;

[0059] Generate and determine cluster centers for adjacent matching results;

[0060] If the generation decision passes, then cluster search is performed based on the cluster search step size, and a gradient movement decision of the cluster center is executed after each search is completed.

[0061] Based on the gradient movement results of the cluster centers, the next round of search constraints is performed until all data segmentation results are clustered, generating N encrypted chains.

[0062] Furthermore, the present invention includes the following steps:

[0063] Privacy data is located based on the attribute identifiers of the data segmentation results;

[0064] Before performing sequential interactive encryption of N encryption chains, the data undergoes adaptive security level pre-encryption processing based on the privacy data location results;

[0065] The results of the adaptive security level pre-encryption process are then subjected to sequential interactive encryption.

[0066] Specifically, after segmenting the information to be transmitted, the data volume of the segmented results is statistically evaluated to obtain a data volume evaluation result. Based on this evaluation result, a preset number of segments is determined to ensure an appropriate number of segments for the information to be transmitted. This approach improves system responsiveness and data encryption efficiency while ensuring data security, and also facilitates subsequent clustering and encryption protection. Then, the first and second clustering constraints are used to evaluate each data segment within the segmented results, and a corresponding constraint limit space is established. Next, the preset number of segments and the constraint limit space are input into a clustering configuration network to generate a clustering configuration result. This result includes the cluster center distribution and the clustering search step size. Finally, chain clustering of the data segmentation results is performed using the clustering configuration result. Developing the clustering configuration result, including the cluster center distribution and the clustering search step size, based on the actual characteristics of the information to be transmitted is crucial for the clustering speed and accuracy of subsequent chain clustering.

[0067] Furthermore, when performing chain clustering of the data segmentation results using the clustering configuration results, firstly, data adjacency matching within the corresponding data segmentation results is performed based on the cluster center distribution results. Then, a cluster center generation determination is made based on the adjacency matching results. If the generation determination passes, a cluster search is performed based on the clustering search step size, and a gradient movement determination of the cluster centers is performed after each search. Next, the next round of search constraints is performed based on the gradient movement results of the cluster centers until the clustering of all data segmentation results is completed, i.e., N encrypted chains are generated. If the generation determination fails, data adjacency matching within the corresponding data segmentation results is performed again based on the cluster center distribution results.

[0068] Finally, based on the attribute identifiers of the data segmentation results, the privacy data in the information to be transmitted is located. Before performing sequential interactive encryption of N encryption chains, adaptive security level pre-encryption processing is performed on the privacy data location results. That is, according to the security level of the privacy data, a corresponding location encryption method is selected to perform a preliminary encryption process on the location result of the privacy data. Then, the adaptive security level pre-encryption processing result is subjected to sequential interactive encryption processing. By performing adaptive security level pre-encryption processing on the privacy data location results, the leakage of privacy data location can be avoided, achieving the goal of high-quality encryption protection of privacy information.

[0069] Furthermore, the present invention also includes the following steps:

[0070] Establish a trust verification mechanism for extracting information to be transmitted, wherein the trust verification mechanism includes time-series verification of the extracting entity and input verification of the extracting key;

[0071] Supervision is performed based on the extracted trust verification.

[0072] Anomalies are reported based on the extracted monitoring results.

[0073] Specifically, after encrypting the information to be transmitted and storing it in a distributed storage device for transmission, an extraction trust verification is established for that information. This extraction trust verification includes timing verification of the extraction subject and input verification of the extraction key. Through these verifications, the system monitors the reception of the information to be transmitted. Specifically, it monitors the extraction of the information based on the extraction trust verification. If either the timing verification of the extraction subject or the input verification of the extraction key is incorrect, the system issues an alarm, reporting an anomaly based on the extraction monitoring results to alert the user of potential information leakage and allow for timely emergency response measures.

[0074] In summary, the attribute-based privacy protection encryption method provided by this invention has the following technical effects:

[0075] 1. By establishing a communication connection with the user and reading the user's unique ID; based on the unique ID, calling the account database to extract the user's cloud security features; reading the user's information to be transmitted and parsing and segmenting the information to be transmitted to generate data segmentation results with attribute identifiers; reconstructing the security level of the corresponding data segmentation results using the cloud security features and attribute identifiers, and generating level clustering constraints based on the security level reconstruction results; using the security level reconstruction results as the first clustering constraint and the attribute identifiers as the second clustering constraint, performing chain clustering of the data segmentation results; generating N encrypted chains based on the chain clustering results, and performing sequential interactive encryption of the N encrypted chains, and simultaneously generating a privacy protection key to complete the encryption protection of the information to be transmitted. By combining the user account database and cloud security features to identify the attributes of each segment of the user's information to be transmitted, thereby forming a corresponding security level reconstruction, and further using the security level reconstruction and attribute identifiers as constraints to cluster the information to be transmitted to generate N encrypted chains, and generating corresponding privacy protection keys for data privacy protection, the goal of formulating a targeted protection scheme for the user's information to be transmitted is achieved, thereby improving the quality of encryption protection of user privacy data and thus improving the technical effect of improving user data security.

[0076] 2. The security level of data information is reconstructed by using the user's cloud security features. Because the data is distributed across different servers in the cloud computing environment through virtualization technology, it is not affected by single points of failure. This also ensures the accuracy and effectiveness of the cloud security features and provides a reliable reference and basis for subsequent information encryption protection.

[0077] 3. By calling a hash function with irreversible properties to encrypt each node in the encryption chain sequentially, the encryption quality of the information to be transmitted is improved while simplifying the calculation, effectively protecting the integrity and security of the user's data.

[0078] 4. By selecting the appropriate distributed storage device to transmit and store the information based on the security level of the information to be transmitted and the real-time application status of the distributed storage device, the differentiated management goal of data with different security levels is achieved, thereby improving the scientificity and efficiency of data encryption management and providing a basic technical effect for subsequent data retrieval.

[0079] Example 2

[0080] Based on the same inventive concept as the attribute-based privacy-preserving encryption method described in the foregoing embodiments, this invention also provides an attribute-based privacy-preserving encryption system. Please refer to the appendix. Figure 3 The system includes:

[0081] Unique ID reading module 11 is used to establish a communication connection with the user and read the user's unique ID;

[0082] The cloud security feature extraction module 12 is used to call the account database based on the unique ID and extract the user's cloud security features from the account database.

[0083] The parsing and segmentation module 13 is used to read the user's information to be transmitted, and to parse and segment the information to be transmitted to generate a data segmentation result with attribute identifiers;

[0084] The hierarchical clustering constraint generation module 14 is used to reconstruct the security level of the corresponding data segmentation results based on the cloud security features and attribute identifiers, and generate hierarchical clustering constraints based on the security level reconstruction results.

[0085] Clustering module 15 is used to perform chain clustering of data segmentation results, using the security level reconstruction result as the first clustering constraint and the attribute identifier as the second clustering constraint.

[0086] The encryption protection module 16 is used to generate N encryption chains based on the chain clustering results, perform sequential interactive encryption of the N encryption chains, and synchronously generate a privacy protection key to complete the encryption protection of the information to be transmitted.

[0087] Furthermore, the system also includes an interactive encryption protection module, which is used for:

[0088] During the encryption process, the privacy protection key is used to call the hash function to perform encryption calculations on the data of the first node of the encryption chain, generating the first encrypted ciphertext.

[0089] The first encrypted ciphertext and the privacy protection key are sent synchronously to the second node, and the first encrypted ciphertext and the data of the second node are used as encrypted data to perform encryption calculations and generate the second encrypted ciphertext.

[0090] The encryption process is completed sequentially for N encryption chains to achieve encryption protection of the information to be transmitted.

[0091] Furthermore, the system also includes a distributed transmission and storage module, which is used for:

[0092] The overall information security level of the information to be transmitted is calculated based on the security level reconstruction results.

[0093] Real-time status matching is performed based on the calculation results of the comprehensive information security level and the idle status of the distributed storage devices;

[0094] Distributed transmission and storage of encrypted results based on real-time status matching results.

[0095] Furthermore, the clustering module 15 in the system is also used for:

[0096] The data volume is evaluated based on the data segmentation results, and the preset number of segments is configured according to the data volume evaluation results;

[0097] Data evaluation within the data segmentation results is performed using the first clustering constraint and the second clustering constraint, and a constraint limit space is established.

[0098] The preset number of segments and the constraint limit space are input into the clustering configuration network to generate clustering configuration results, wherein the clustering configuration results include cluster center distribution results and clustering search step size;

[0099] Chain clustering of the data segmentation results is performed based on the clustering configuration results.

[0100] Furthermore, the encryption protection module 16 in the system is also used for:

[0101] Based on the cluster center distribution results, perform adjacent data matching within the corresponding data segmentation results;

[0102] Generate and determine cluster centers for adjacent matching results;

[0103] If the generation decision passes, then cluster search is performed based on the cluster search step size, and a gradient movement decision of the cluster center is executed after each search is completed.

[0104] Based on the gradient movement results of the cluster centers, the next round of search constraints is performed until all data segmentation results are clustered, generating N encrypted chains.

[0105] Furthermore, the encryption protection module 16 in the system is also used for:

[0106] Privacy data is located based on the attribute identifiers of the data segmentation results;

[0107] Before performing sequential interactive encryption of N encryption chains, the data undergoes adaptive security level pre-encryption processing based on the privacy data location results;

[0108] The results of the adaptive security level pre-encryption process are then subjected to sequential interactive encryption.

[0109] Furthermore, the system also includes a monitoring reporting module, which is used for:

[0110] Establish a trust verification mechanism for extracting information to be transmitted, wherein the trust verification mechanism includes time-series verification of the extracting entity and input verification of the extracting key;

[0111] Supervision is performed based on the extracted trust verification.

[0112] Anomalies are reported based on the extracted monitoring results.

[0113] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Figure 1 The attribute-based privacy-preserving encryption method and specific examples in Embodiment 1 are also applicable to the attribute-based privacy-preserving encryption system of this embodiment. Through the foregoing detailed description of the attribute-based privacy-preserving encryption method, those skilled in the art can clearly understand the attribute-based privacy-preserving encryption system of this embodiment; therefore, for the sake of brevity, it will not be described in detail here. As for the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant details can be found in the method section.

[0114] This application also provides an electronic device, including:

[0115] At least one processor;

[0116] A memory that is communicatively connected to the at least one processor;

[0117] The memory stores instructions that can be executed by the at least one processor, which, when executed by the at least one processor, enables the at least one processor to perform the method described in any one of Embodiment 1.

[0118] This application also provides a computer-readable storage medium storing a computer program that, when executed, implements the steps of any of the methods described in Embodiment 1.

[0119] The above description of the disclosed embodiments enables those skilled in the art to make or use the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

[0120] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of this invention and its equivalents, this invention also intends to include these modifications and variations.

Claims

1. A privacy-preserving encryption method based on attribute recognition, characterized in that, The method includes: Establish a communication connection with the user and read the user's unique ID; The user's cloud security features are extracted from the account database based on the unique ID. Read the user's information to be transmitted, and parse and segment the information to be transmitted to generate a data segmentation result with attribute identifiers; The security level of the corresponding data segmentation results is reconstructed based on the cloud security features and attribute identifiers, and level clustering constraints are generated based on the security level reconstruction results; Using the security level reconstruction result as the first clustering constraint and the attribute identifier as the second clustering constraint, chain clustering of the data segmentation result is performed; N encrypted chains are generated based on the chain clustering results, and sequential interactive encryption of the N encrypted chains is performed. A privacy protection key is generated simultaneously to complete the encryption protection of the information to be transmitted.

2. The method as described in claim 1, characterized in that, The method further includes: During the encryption process, the privacy protection key is used to call the hash function to perform encryption calculations on the data of the first node of the encryption chain, generating the first encrypted ciphertext. The first encrypted ciphertext and the privacy protection key are sent synchronously to the second node, and the first encrypted ciphertext and the data of the second node are used as encrypted data to perform encryption calculations and generate the second encrypted ciphertext. The encryption process is completed sequentially for N encryption chains to achieve encryption protection of the information to be transmitted.

3. The method as described in claim 2, characterized in that, The method further includes: The overall information security level of the information to be transmitted is calculated based on the security level reconstruction results. Real-time status matching is performed based on the calculation results of the comprehensive information security level and the idle status of the distributed storage devices; Distributed transmission and storage of encrypted results based on real-time status matching results.

4. The method as described in claim 1, characterized in that, The method further includes: The data volume is evaluated based on the data segmentation results, and the preset number of segments is configured according to the data volume evaluation results; Data evaluation within the data segmentation results is performed using the first clustering constraint and the second clustering constraint, and a constraint limit space is established. The preset number of segments and the constraint limit space are input into the clustering configuration network to generate clustering configuration results, wherein the clustering configuration results include cluster center distribution results and clustering search step size; Chain clustering of the data segmentation results is performed based on the clustering configuration results.

5. The method as described in claim 4, characterized in that, The method further includes: Based on the cluster center distribution results, perform adjacent data matching within the corresponding data segmentation results; Generate and determine cluster centers for adjacent matching results; If the generation decision passes, then cluster search is performed based on the cluster search step size, and a gradient movement decision of the cluster center is executed after each search is completed. Based on the gradient movement results of the cluster centers, the next round of search constraints is performed until all data segmentation results are clustered, generating N encrypted chains.

6. The method as described in claim 1, characterized in that, The method further includes: Privacy data is located based on the attribute identifiers of the data segmentation results; Before performing sequential interactive encryption of N encryption chains, the data undergoes adaptive security level pre-encryption processing based on the privacy data location results; The results of the adaptive security level pre-encryption process are then subjected to sequential interactive encryption.

7. The method as described in claim 1, characterized in that, The method further includes: Establish a trust verification mechanism for extracting information to be transmitted, wherein the trust verification mechanism includes time-series verification of the extracting entity and input verification of the extracting key; Supervision is performed based on the extracted trust verification. Anomalies are reported based on the extracted monitoring results.

8. A privacy-preserving encryption system based on attribute recognition, characterized in that, The system includes: The unique ID reading module is used to establish a communication connection with the user and read the user's unique ID; The cloud security feature extraction module is used to call the account database based on the unique ID and extract the user's cloud security features from the account database. The parsing and segmentation module is used to read the user's information to be transmitted, and to parse and segment the information to be transmitted to generate data segmentation results with attribute identifiers; The hierarchical clustering constraint generation module is used to reconstruct the security level of the corresponding data segmentation results based on the cloud security features and attribute identifiers, and generate hierarchical clustering constraints based on the security level reconstruction results. The clustering module is used to perform chain clustering of the data segmentation results, with the security level reconstruction result as the first clustering constraint and the attribute identifier as the second clustering constraint. The encryption protection module is used to generate N encryption chains based on the chain clustering results, perform sequential interactive encryption of the N encryption chains, and synchronously generate privacy protection keys to complete the encryption protection of the information to be transmitted.

9. An electronic device, comprising: At least one processor; A memory that is communicatively connected to the at least one processor; The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed, implements the steps of the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Data security storage method based on attribute partition

    CN106156317A

  • Personalized differential privacy protection method and system for vertical segmentation data

    CN113111383A