Unstructured Personal Data Protection Method for the Omnichannel In-Store Pickup Service in the Apparel Industry

By SM3 encryption and symmetric encryption of unstructured personal data, and CP-ABE encryption of symmetric keys, combined with preset access policies and hash values, the problems of management complexity and communication costs in the existing technology are solved, and efficient, secure and reliable data protection is achieved.

CN118972094BActive Publication Date: 2025-06-24GUANGZHOU REGENTSOFT TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202410941276.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-15
Publication Date
2025-06-24
Estimated Expiration
2044-07-15

AI Technical Summary

Technical Problem

Existing methods for protection of unstructured personal data have problems such as management complexity, increasing management efforts and communication costs, and affecting communication effectiveness.

Method used

Unstructured personal data is processed using SM3 encryption and symmetric encryption, and the data ciphertext, its symmetric key and hash value are obtained, and the symmetric key is CP-ABE encryption is performed to generate the key ciphertext. Identity authorization is performed based on the preset access policy, the original data is obtained decrypted and the hash comparison is determined whether the data has been tampered with.

Benefits of technology

Through CP-ABE encryption, flexible access policies are realized, management complexity is reduced, decryption efficiency and data integrity are improved, management work and communication costs are reduced, and data security and reliability are ensured.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118972094B_ABST
    Figure CN118972094B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for protecting unstructured personal data in the full-channel self-pickup service of the clothing industry, including: performing SM3 encryption and symmetric encryption on the unstructured personal data to obtain the data ciphertext, its symmetric key, and the first hash value; performing CP-ABE encryption on the symmetric key to generate the key ciphertext; obtaining the access request of the data requester, and performing identity authorization on the data requester based on a preset access policy; decrypting the key ciphertext according to the authorization result to obtain the symmetric key, and decrypting the data ciphertext with the symmetric key to obtain the original data; performing SM3 encryption on the original data to obtain the second hash value, and comparing the first hash value and the second hash value to determine whether the unstructured personal data has been tampered with. There is no need to set a private key for each user, which greatly improves the management efficiency and the timeliness of users decrypting data. At the same time, it is also possible to determine whether the data has been tampered with according to the comparison of the hash values before and after the data, and verify the integrity and reliability of the data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data management, and particularly to a method for protecting unstructured personal data in the full-channel self-pickup business of the clothing industry. Background Art

[0002] At present, with the rapid development of Internet technology, the e-commerce industry has flourished, and more and more clothing enterprises have actively promoted digital transformation. However, along with the convenience of digitization, a series of problems and challenges have also emerged. As one of the industries that are vulnerable to data leakage incidents all year round, clothing enterprises have unstructured business secrets such as design drawings and production plans within their internal systems, which are often stolen and leaked by malicious individuals due to poor protection. Problems such as original designs being launched on the market by competitors in advance and production plans being blocked caused by this situation have brought immeasurable economic losses to enterprises. Therefore, how to protect the internal data of clothing enterprises and establish a comprehensive data anti-leakage solution has become an urgent problem that needs to be solved by current clothing enterprises.

[0003] Most of the existing methods for protecting unstructured personal data are to use a public key cryptosystem to encrypt unstructured data, that is, generate a corresponding public key for each user to encrypt the data, and each user then uses their own private key to decrypt the received file. It has the following problems: It is necessary to maintain and manage the public key of each user and ensure that the correct public key is used to encrypt the file. This may increase the complexity of management, especially in the case of a large number of users or frequent updates of user public keys. Secondly, if the public key of a user needs to be updated or a new user joins, the sender needs to update and re-encrypt the file in a timely manner, which may bring additional management work and communication costs. Finally, if any error occurs during the encryption process or the private key of a certain recipient is lost, the file cannot be decrypted, thus affecting the effectiveness of communication. Summary of the Invention

[0004] In view of the problems shown above, the present invention provides a method for protecting unstructured personal data in the full-channel self-pickup business of the clothing industry to solve the problems of increasing management complexity, bringing additional management work and communication costs, and affecting communication effectiveness mentioned in the background art.

[0005] A method for protecting unstructured personal data in the full-channel self-pickup business of the clothing industry includes the following steps:

[0006] Perform SM3 encryption and symmetric encryption on the unstructured personal data to obtain the data ciphertext, its symmetric key, and the first hash value, and perform CP-ABE encryption on the symmetric key to generate the key ciphertext;

[0007] Obtain the access request of the data requester, and perform identity authorization on the data requester based on a preset access policy;

[0008] Decrypt the ciphertext of the secret key according to the authorization result to obtain the symmetric key, and use the symmetric key to decrypt the data ciphertext to obtain the original data;

[0009] Perform SM3 encryption on the original data to obtain the second hash value, and compare the first hash value and the second hash value to determine whether the unstructured personal data has been tampered with.

[0010] Preferably, before performing SM3 encryption and symmetric encryption on the unstructured personal data to obtain the data ciphertext, its symmetric key, and the first hash value, and performing CP-ABE encryption on the symmetric key to generate the ciphertext of the secret key, it further includes:

[0011] Define an encryption function and execute the initialization algorithm to generate a 128-byte block;

[0012] Save the first 32 bytes in the 128-byte block as the system master key, and save the last 96 bytes in the 128-byte block as the system public key.

[0013] Preferably, the performing SM3 encryption and symmetric encryption on the unstructured personal data to obtain the data ciphertext, its symmetric key, and the first hash value, and performing CP-ABE encryption on the symmetric key to generate the ciphertext of the secret key includes:

[0014] Determine the first data type of the unstructured personal data, select a chunking method according to the first data type, and divide the unstructured personal data into multiple chunks through the chunking method;

[0015] Perform SM3 encryption on each chunk, and obtain the first hash value according to the first encryption result;

[0016] Select a symmetric encryption algorithm according to the first data type of the unstructured personal data, and perform symmetric encryption on the unstructured personal data through the symmetric encryption algorithm;

[0017] Obtain the data ciphertext according to the second encryption result, define the identity attribute set of the CP-ABE encryption system and initialize the CP-ABE encryption system, and perform CP-ABE encryption on the symmetric key by using the CP-ABE encryption system to generate the ciphertext of the secret key.

[0018] Preferably, the obtaining the access request of the data requester, and performing identity authorization on the data requester based on a preset access policy includes:

[0019] Obtain the access request of the data requester through the blockchain network, and obtain the identity information of the data requester according to the access request;

[0020] Review the identity information, determine the abnormal information items based on the review results, and determine the eligibility of the data requester's identity authentication according to the abnormal information items;

[0021] If the verification is qualified, obtain the current identity attributes of the data requester according to the identity information;

[0022] Based on the preset access policy, determine the conditional identity attributes that meet the data access permissions, and authorize the identity of the data requester according to the conditional identity attributes and the current identity attributes.

[0023] Preferably, the step of determining the conditional identity attributes that meet the data access permissions based on the preset access policy and authorizing the identity of the data requester according to the conditional identity attributes and the current identity attributes includes:

[0024] Based on the preset access policy, determine the identity attribute data set, and determine multiple conditional identity attributes that meet the data access permissions according to the identity attribute data set;

[0025] Match the current identity attributes with the multiple conditional identity attributes to obtain a matching result, and determine whether there is a matching item according to the matching result;

[0026] If so, determine that the data requester has the data access permission, authorize the identity of the data requester and distribute the identity private key and the system public key to it;

[0027] If not, determine that the data requester does not have the data access permission, and send a reminder that the identity authorization condition is not met to the data requester.

[0028] Preferably, before decrypting the key ciphertext according to the authorization result to obtain the symmetric key and using the symmetric key to decrypt the data ciphertext to obtain the original data, it further includes:

[0029] Upload the data ciphertext to the cloud storage server, and obtain the data ciphertext address according to the storage path;

[0030] Construct a data element table according to the data ciphertext address, the key ciphertext, and the first hash value and upload it to the blockchain network;

[0031] Respond to the access request of the data requester, retrieve the data element table and feedback it to the terminal where the data requester is located.

[0032] Preferably, decrypting the key ciphertext according to the authorization result to obtain the symmetric key and using the symmetric key to decrypt the data ciphertext to obtain the original data includes:

[0033] Obtain the identity private key and the system public key of the data requester according to the authorization result, and decrypt the key ciphertext with the identity private key and the system public key to obtain the symmetric key;

[0034] Obtain the ciphertext address through the data element table, access the cloud storage server based on the ciphertext address, and receive the data ciphertext sent by the cloud storage server;

[0035] Decrypt the data ciphertext with the symmetric key to obtain the original data.

[0036] Preferably, the decrypting the data ciphertext with the symmetric key to obtain the original data includes:

[0037] Create a random initial vector and expand the random initial vector to obtain an expansion factor, iterate the expansion factor with the data ciphertext, and obtain the generated ciphertext according to the iteration result;

[0038] Determine whether the generated ciphertext meets the expected output. If so, obtain a copy of the original data according to the generated ciphertext. If not, recreate the initial vector and perform repeated iteration until the generated ciphertext meets the expected output;

[0039] Decrypt the original data copy with the symmetric key to obtain the original data.

[0040] Preferably, the encrypting the original data with SM3 to obtain a second hash value, and comparing the first hash value and the second hash value to determine whether the unstructured personal data has been tampered with includes:

[0041] Determine the second data type of the original data, select a chunking method according to the second data type, and divide the original data into multiple chunks through the chunking method;

[0042] Encrypt each chunk with SM3, and obtain the second hash value according to the third encryption result;

[0043] Determine whether the first hash value is the same as the second hash value. If so, determine that the unstructured personal data has not been tampered with. If not, determine that the unstructured personal data has been tampered with.

[0044] Preferably, it further includes:

[0045] Obtain multiple operation behavior parameters of the data requester for the unstructured data and the operation frequency of each operation behavior parameter;

[0046] Determine the abnormal operation behavior parameters according to the operation frequency and issue a warning reminder based on the abnormal operation behavior parameters;

[0047] Determine the operation type of each operation behavior parameter, and generate an operation record of the data requester for the unstructured data according to the multiple operation behavior parameters;

[0048] Generate an operation log of the data requester according to the operation record and the operation type and upload the operation log to the cloud storage server.

[0049] Other features and advantages of the present invention will be set forth in the following description, and in part will be obvious from the description, or may be learned by practice of the present invention. The objectives and other advantages of the present invention may be realized and attained by the structure particularly pointed out in the written description and the drawings.

[0050] The technical solution of the present invention will be further described in detail below with reference to the drawings and embodiments. Description of the Drawings

[0051] The drawings are used to provide a further understanding of the present invention, and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention, and do not constitute a limitation to the present invention.

[0052] Figure 1 It is a flowchart of a method for protecting unstructured personal data in the full-channel self-pickup service of the clothing industry provided by the present invention;

[0053] Figure 2 It is another flowchart of a method for protecting unstructured personal data in the full-channel self-pickup service of the clothing industry provided by the present invention;

[0054] Figure 3 It is yet another flowchart of a method for protecting unstructured personal data in the full-channel self-pickup service of the clothing industry provided by the present invention;

[0055] Figure 4 It is a screenshot of an embodiment of a method for protecting unstructured personal data in the full-channel self-pickup service of the clothing industry provided according to the present invention. Detailed Embodiments

[0056] Exemplary embodiments will be described in detail herein, and examples thereof are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present disclosure. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present disclosure as detailed in the appended claims.

[0057] At present, with the rapid development of Internet technology, the e-commerce industry has emerged vigorously, and more and more clothing enterprises have started to actively promote digital transformation. However, along with the convenience of digitalization, a series of problems and challenges have also arisen. As one of the industries that are vulnerable to data leakage incidents all year round, clothing enterprises have unstructured business secrets such as design drawings and production plans within their internal systems, which are often stolen and leaked by malicious individuals due to poor protection. Problems such as the premature launch of original designs by competitors and the obstruction of production plans caused by this situation have brought immeasurable economic losses to enterprises. Therefore, how to protect the internal data of clothing enterprises and establish a comprehensive data leakage prevention plan has become an urgent problem that needs to be solved by current clothing enterprises.

[0058] Most of the existing protection methods for unstructured personal data are to use the public key cryptosystem to encrypt unstructured data, that is, generate a corresponding public key for each user to encrypt the data, and each user then uses their own private key to decrypt the received file. It has the following problems: It is necessary to maintain and manage the public key of each user and ensure that the correct public key is used to encrypt the file. This may increase the complexity of management, especially when the number of users is large or the public keys of users are frequently updated. Secondly, if the public key of a user needs to be updated or a new user joins, the sender needs to update and re-encrypt the file in a timely manner, which may bring additional management work and communication costs. Finally, if any error occurs during the encryption process or the private key of a certain recipient is lost, the file cannot be decrypted, thus affecting the effectiveness of communication. To solve the above problems, this embodiment discloses a protection method for unstructured personal data based on CP-ABE encryption.

[0059] A protection method for unstructured personal data in the omni-channel self-pickup business of the clothing industry, as Figure 1 shown, includes the following steps:

[0060] Step S101: Perform SM3 encryption and symmetric encryption on the unstructured personal data to obtain the data ciphertext, its symmetric key, and the first hash value, and perform CP-ABE encryption on the symmetric key to generate the key ciphertext;

[0061] Step S102: Obtain the access request of the data requester, and perform identity authorization on the data requester based on the preset access policy;

[0062] Step S103: Decrypt the key ciphertext according to the authorization result to obtain the symmetric key, and use the symmetric key to decrypt the data ciphertext to obtain the original data;

[0063] Step S104: Perform SM3 encryption on the original data to obtain the second hash value, and compare the first hash value and the second hash value to determine whether the unstructured personal data has been tampered with.

[0064] In this embodiment, performing CP-ABE encryption on the symmetric key means that only one encryption of the file is required and the identity attributes of the decryption personnel are set, so that the corresponding personnel can have the access and call rights to the data. For example, if it is desired that only department leaders or team leaders can decrypt the file, then the attributes of the file can be defined as {role: department leader OR role: team leader}. This means that as long as the user has one of the two attributes of "department leader" or "team leader", the file can be decrypted.

[0065] The working principle of the above technical solution is as follows: performing SM3 encryption and symmetric encryption on unstructured personal data to obtain the data ciphertext, its symmetric key, and the first hash value; performing CP-ABE encryption on the symmetric key to generate the key ciphertext; obtaining the access request of the data request personnel, and performing identity authorization on the data request personnel based on a preset access policy; decrypting the key ciphertext according to the authorization result to obtain the symmetric key, using the symmetric key to decrypt the data ciphertext to obtain the original data; performing SM3 encryption on the original data to obtain the second hash value, and comparing the first hash value and the second hash value to determine whether the unstructured personal data has been tampered with.

[0066] The beneficial effects of the above technical solution are as follows: By performing CP-ABE encryption on the file, flexible access policies can be allowed. By defining an attribute set to determine which users can decrypt the data, users can access the data after successful identity attribute verification without setting a private key for each user, greatly improving the management efficiency and the timeliness of user data decryption. At the same time, it is also possible to determine whether the data has been tampered with according to the comparison of the hash values before and after the data, verify the integrity and reliability of the data, improve the user experience, and solve the problems of increasing management complexity, bringing additional management work and communication costs, and affecting the effectiveness of communication mentioned in the prior art.

[0067] In this embodiment, before performing SM3 encryption and symmetric encryption on unstructured personal data to obtain the data ciphertext, its symmetric key, and the first hash value, and performing CP-ABE encryption on the symmetric key to generate the key ciphertext, it further includes:

[0068] Obtaining the data type and data feature vector of each piece of unstructured personal data;

[0069] Determining the data source according to the data type and data feature vector, and determining the data object dimension based on the data source;

[0070] Determining the data quality and data privacy according to the data object dimension, and dividing the unstructured personal data into lightweight data and heavyweight data according to the data quality and data privacy;

[0071] Determine the first data mixing characteristic of the first partition of unstructured personal data for heavyweight data and the second data mixing characteristic of the second partition of unstructured personal data for lightweight data respectively;

[0072] Conduct qualitative measurement on each first partition of unstructured personal data and second partition of unstructured personal data according to the first data mixing characteristic and the second data mixing characteristic;

[0073] Determine the modal definition for each first partition of unstructured personal data and second partition of unstructured personal data according to the measurement results;

[0074] Obtain unimodal unstructured personal data and bimodal unstructured personal data according to the modal definition, and configure the display characteristics and text characteristics according to the data content of the unimodal unstructured personal data;

[0075] Determine the hidden data segment and the displayable data segment according to the data identifiers of each word in the data content of the bimodal unstructured personal data;

[0076] Configure the primary display characteristics and text characteristics of the bimodal unstructured personal data based on the displayable data segment;

[0077] Configure the advanced display characteristics and text characteristics of the bimodal unstructured personal data based on the hidden data segment;

[0078] Set the mapping rules between the advanced display characteristics and text characteristics and the primary display characteristics and text characteristics of the bimodal unstructured personal data.

[0079] In this embodiment, the data source is represented as the data origin of unstructured personal data. For example, the data source of the ID number is ID card image acquisition;

[0080] In this embodiment, the data object dimension is represented as the dimension to which the data source belongs. For example, height dimension data, weight dimension data, identity dimension data, etc.;

[0081] In this embodiment, lightweight data is represented as personal data with relatively low privacy, and heavyweight data is represented as personal data with relatively high privacy;

[0082] In this embodiment, the data mixing characteristic is represented as the combined characteristic of the mixing of multiple data types contained in each unstructured personal data;

[0083] In this embodiment, the qualitative measurement is represented as a measurement method of scoring the respective partition data in lightweight data and heavyweight data according to a measurement standard;

[0084] In this embodiment, the modal definition is expressed as defining the display modality of unstructured personal data, which is divided into single-modal and dual-modal. Among them, the single-modal displays all data, and the dual-modal only displays partial data in the basic form and all data in the advanced state.

[0085] In this embodiment, the data identifier is used to determine the data type and unit of each type of data.

[0086] In this embodiment, the hidden data segment and the displayable data segment are an integral data segment. Only partial data is displayed in the initial display mode, and all data is displayed only in the advanced display mode. For example, only the first six digits and the last four digits of the ID number are displayed, and the middle part is hidden. For female personnel data such as bust size 34C, the 3 is displayed and the 4C is hidden.

[0087] The beneficial effects of the above technical solution are as follows: By qualitatively analyzing unstructured personal data to determine heavyweight data and then setting its multi-modal display and text features, the privacy of users can be effectively protected. Focused protection is provided for data with high privacy, avoiding data leakage and resulting in customer information and property losses, and improving security and practicality.

[0088] In one embodiment, before performing SM3 encryption and symmetric encryption on unstructured personal data, obtaining the data ciphertext, its symmetric key, and the first hash value, and performing CP-ABE encryption on the symmetric key to generate the key ciphertext, it further includes:

[0089] Define an encryption function and execute an initialization algorithm to generate a 128-byte block.

[0090] Save the first 32 bytes in the 128-byte block as the system master key, and save the last 96 bytes in the 128-byte block as the system public key.

[0091] In one embodiment, as Figure 2 shown, the performing SM3 encryption and symmetric encryption on unstructured personal data, obtaining the data ciphertext, its symmetric key, and the first hash value, and performing CP-ABE encryption on the symmetric key to generate the key ciphertext includes:

[0092] Step S201: Determine the first data type of the unstructured personal data, select a chunking method according to the first data type, and divide the unstructured personal data into multiple chunks through the chunking method.

[0093] Step S202: Perform SM3 encryption on each chunk, and obtain the first hash value according to the first encryption result.

[0094] Step S203: Select a symmetric encryption algorithm according to the first data type of the unstructured personal data, and perform symmetric encryption on the unstructured personal data through the symmetric encryption algorithm.

[0095] Step S204: Obtain the data ciphertext according to the second encryption result, define the identity attribute set of the CP-ABE encryption system and initialize the CP-ABE encryption system, and use the CP-ABE encryption system to perform CP-ABE encryption on the symmetric key to generate the key ciphertext.

[0096] In this embodiment, for text data, it can be divided into blocks every 32 characters or every line; for other types of data, it can be divided into blocks according to its size.

[0097] In this embodiment, the symmetric encryption algorithms include but are not limited to AES, DES, and RC2.

[0098] The beneficial effects of the above technical solution are as follows: perform SM3 encryption and symmetric encryption on unstructured personal data, obtain the data ciphertext, its symmetric key, and the first hash value, perform CP-ABE encryption on the symmetric key to generate the key ciphertext, which not only ensures the security and reliability of the data, but also ensures the integrity of the data, and different encryption algorithms and key management methods can be flexibly selected according to the actual situation, improving the effect of data protection.

[0099] In one embodiment, as Figure 3 shown, obtaining the access request of the data request person and performing identity authorization on the data request person based on a preset access policy includes:

[0100] Step S301: Obtain the access request of the data request person through the blockchain network, and obtain the identity information of the data request person according to the access request;

[0101] Step S302: Examine the identity information, determine the abnormal information items according to the examination results, and determine the identity verification eligibility of the data request person according to the abnormal information items;

[0102] Step S303: If the verification is qualified, obtain the current identity attributes of the data request person according to the identity information;

[0103] Step S304: Determine the conditional identity attributes that meet the data access permissions based on the preset access policy, and perform identity authorization on the data request person according to the conditional identity attributes and the current identity attributes.

[0104] In this embodiment, the abnormal information items refer to the information items that do not match the actual situation of the data request person, such as position, age, name, etc.;

[0105] The beneficial effects of the above technical solution are as follows: By reviewing the identity information of data requesters, determining abnormal information items, judging the eligibility of the requesters' identity verification, and obtaining the current identity attributes, determining the conditional identity attributes that meet the data access permissions based on the preset access policy, and performing identity authorization, it is possible to more accurately judge whether a user has the right to access specific data, thereby effectively preventing illegal users from obtaining sensitive information, reducing security risks, and improving data security.

[0106] In one embodiment, determining the conditional identity attributes that meet the data access permissions based on the preset access policy and performing identity authorization on the data requesters according to the conditional identity attributes and the current identity attributes includes:

[0107] Determining the identity attribute data set based on the preset access policy and determining multiple conditional identity attributes that meet the data access permissions according to the identity attribute data set;

[0108] Matching the current identity attributes with the multiple conditional identity attributes, obtaining the matching result, and determining whether there is a matching item according to the matching result;

[0109] If so, determining that the data requester has the data access permission, performing identity authorization on the data requester and distributing the identity private key and the system public key to him;

[0110] If not, determining that the data requester does not have the data access permission and sending a reminder that the identity authorization condition is not met to the data requester.

[0111] The beneficial effects of the above technical solution are as follows: Determining multiple conditional identity attributes that meet the data access permissions according to the identity attribute data set, matching them with the current identity attributes, and determining whether the data requester has the access permission according to the matching result can prevent unauthorized access and ensure data security.

[0112] In one embodiment, before decrypting the key ciphertext according to the authorization result to obtain the symmetric key and using the symmetric key to decrypt the data ciphertext to obtain the original data, it further includes:

[0113] Uploading the data ciphertext to the cloud storage server and obtaining the data ciphertext address according to the storage path;

[0114] Constructing a data element table according to the data ciphertext address, the key ciphertext, and the first hash value and uploading it to the blockchain network;

[0115] Responding to the access request of the data requester, retrieving the data element table and feeding it back to the terminal where the data requester is located.

[0116] The beneficial effects of the above technical solution are as follows: By constructing a data element table based on the data ciphertext address, the key ciphertext, and the first hash value and uploading it to the blockchain network, information such as the source, destination, and status of data elements can be easily traced and queried, which helps to improve the data management efficiency. At the same time, according to the access request of the data requester, the data element table is retrieved and fed back to the terminal where the requester is located. The data can be directly fed back to the terminal where the data requester is located, avoiding the loss or damage of data in the intermediate links and improving the data query efficiency.

[0117] In one embodiment, decrypting the key ciphertext according to the authorization result to obtain a symmetric key, and decrypting the data ciphertext with the symmetric key to obtain the original data, including:

[0118] Obtaining the identity private key and the system public key of the data requester according to the authorization result, and decrypting the key ciphertext with the identity private key and the system public key to obtain a symmetric key;

[0119] Obtaining the ciphertext address through the data element table, accessing the cloud storage server based on the ciphertext address, and receiving the data ciphertext sent by the cloud storage server;

[0120] Decrypting the data ciphertext with the symmetric key to obtain the original data.

[0121] The beneficial effects of the above technical solution are as follows: Decrypting the key ciphertext with the identity private key and the system public key to obtain a symmetric key. Since the symmetric key is uniquely determined and cannot be cracked, the confidentiality, integrity, and availability of information can be guaranteed. At the same time, accessing the cloud storage server through the ciphertext address obtained from the data element, receiving the data ciphertext, and decrypting it with the symmetric key ensure the security of data transmission and improve the decryption efficiency.

[0122] In one embodiment, decrypting the data ciphertext with the symmetric key to obtain the original data, including:

[0123] Creating a random initial vector and expanding the random initial vector to obtain an expansion factor, iterating the expansion factor with the data ciphertext, and obtaining the generated ciphertext according to the iteration result;

[0124] Determining whether the generated ciphertext meets the expected output. If so, obtaining a copy of the original data according to the generated ciphertext. If not, re-creating the initial vector and repeating the iteration until the generated ciphertext meets the expected output;

[0125] Decrypting the original data copy with the symmetric key to obtain the original data.

[0126] In this embodiment, iteration is expressed as a data processing technology for changing the data attributes of the data ciphertext;

[0127] In this embodiment, the expected output is expressed as whether the format or attribute of the generated ciphertext conforms to the preset output format and data attributes.

[0128] The beneficial effects of the above technical solution are as follows: By decrypting the original data copy with a symmetric key to obtain the original data, the readability of the data can be guaranteed, and it can be ensured that the data has not been tampered with or damaged during transmission and storage. At the same time, the original data copy can be decrypted quickly to ensure the efficiency of the decryption process.

[0129] In one embodiment, the SM3 encryption of the original data to obtain the second hash value, and comparing the first hash value and the second hash value to determine whether the unstructured personal data has been tampered with includes:

[0130] Determine the second data type of the original data, select a chunking method according to the second data type, and divide the original data into multiple chunks by the chunking method;

[0131] Perform SM3 encryption on each chunk, and obtain the second hash value according to the third encryption result;

[0132] Determine whether the first hash value is the same as the second hash value. If so, determine that the unstructured personal data has not been tampered with. If not, determine that the unstructured personal data has been tampered with.

[0133] The beneficial effects of the above technical solution are as follows: Select a chunking method according to the second data type, chunk the original data, encrypt each chunk, obtain the second hash value, compare it with the first hash value, and determine whether the unstructured personal data has been tampered with, which can effectively prevent unauthorized access and modification. At the same time, it can accurately judge whether the data has changed and discover problems in a timely manner.

[0134] In one embodiment, it further includes:

[0135] Obtain multiple operation behavior parameters of the data requester for the unstructured data and the operation frequency of each operation behavior parameter;

[0136] Determine the abnormal operation behavior parameters based on the operation frequency and issue a warning reminder based on the abnormal operation behavior parameters;

[0137] Determine the operation type of each operation behavior parameter, and generate an operation record of the data requester for the unstructured data according to the multiple operation behavior parameters;

[0138] Generate an operation log of the data requester according to the operation record and the operation type and upload the operation log to the cloud storage server.

[0139] The beneficial effects of the above technical solution are as follows: Determine abnormal operation behaviors based on the operation behavior parameters and operation frequencies of data requesters, and issue early warning reminders, which can timely detect existing security risks, thereby reducing potential hazards or losses. At the same time, it can also improve users' awareness and vigilance, and better protect data and privacy. Further, generate operation logs for data requesters according to operation records and operation types, so that all operations can be traced, and avoid the situation where data is lost and the source cannot be found.

[0140] In one embodiment, as Figure 4 shown, it includes:

[0141] 1. The trusted authorization center executes the initialization algorithm to generate the system master key and the system public key.

[0142] 2. The data requester submits relevant attributes to the trusted authorization center for identity authorization.

[0143] 3. The trusted authorization center authorizes the data requester. The trusted authorization center will review the data requester to ensure that its identity is true and valid. After identity verification, calculate the private key for the data requester according to its attributes, and distribute the system public key and the data requester's private key to it.

[0144] 4. The data sender submits relevant attributes to the trusted authorization center for identity authorization.

[0145] 5. The trusted authorization center authorizes the data sender. The trusted authorization center will review the data sender to ensure that its identity is true and valid. After identity verification, calculate the private key for the data sender according to its attributes, and distribute the system public key and the data sender's private key to it.

[0146] 6. The trusted authorization center adds the data sender and data requester nodes with approved identity authorizations to the blockchain network, registers their identity information in the blockchain. The data sender information is the account address SenderAddress, and the data requester information is the account address RequesterAddress and its attributes.

[0147] 7. The data sender performs SM3 encryption on unstructured data such as files to generate hash value 1.

[0148] 8. The data sender performs symmetric encryption on unstructured data such as files to generate data ciphertext.

[0149] 9. The data sender stores the data ciphertext in the cloud storage server.

[0150] 10. The cloud storage server returns the storage address of the data ciphertext.

[0151] 11. The data sender encrypts the symmetric key using CP-ABE to generate a ciphertext of the key.

[0152] 12. The data sender constructs a data element table with the ciphertext of the key, hash value 1, and ciphertext address and uploads it to the blockchain.

[0153] 13. The data requester sends an access request to the blockchain network.

[0154] 14. The blockchain network returns the data element table.

[0155] 15. The data requester obtains the ciphertext address from the data element table and accesses the cloud storage server.

[0156] 16. The cloud storage server returns the data ciphertext.

[0157] 17. After the attributes of the data requester satisfy the access policy, the symmetric key can be decrypted, and the data ciphertext is decrypted with the symmetric key to obtain the original data.

[0158] 18. The original data is encrypted using SM3 to generate hash value 2, and it is compared whether hash value 1 and hash value 2 are the same.

[0159] Those skilled in the art will readily conceive of other embodiments of the present disclosure after considering the specification and practice disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present disclosure, which follow the general principles of the present disclosure and include common general knowledge or conventional technical means in the technical field not disclosed in the present disclosure. The specification and examples are only illustrative, and the true scope and spirit of the present disclosure are pointed out by the following claims.

[0160] It should be understood that the present disclosure is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present disclosure is only limited by the appended claims.

Claims

1. A method for protecting unstructured personal data in the omni-channel self-pickup business of the clothing industry, characterized in that: The following steps are involved: Perform SM3 encryption and symmetric encryption on unstructured personal data, obtain data ciphertext and its symmetric key and the first hash value, perform CP-ABE encryption on the symmetric key, and generate key ciphertext; Obtain access requests from data requesters and authorize the data requesters based on preset access policies; Decrypt the key ciphertext according to the authorization result to obtain the symmetric key, and use the symmetric key to decrypt the data ciphertext to obtain the original data; Perform SM3 encryption on the original data to obtain a second hash value, and compare the first hash value with the second hash value to determine whether the unstructured personal data has been tampered with; Before performing SM3 encryption and symmetric encryption on the unstructured personal data, obtaining the data ciphertext and its symmetric key and the first hash value, performing CP-ABE encryption on the symmetric key, and generating the key ciphertext, the method further includes: Obtain the data type and data feature vector of each piece of unstructured personal data; Determine the data source based on the data type and data feature vector, and determine the data object dimension based on the data source; Determine data quality and data privacy based on the data object dimension, and classify unstructured personal data into lightweight data and heavyweight data based on data quality and data privacy; respectively determining a first data jumble characteristic of the first partitioned unstructured personal data of the heavyweight data and a second data jumble characteristic of the second partitioned unstructured personal data of the lightweight data; performing qualitative measurement on each of the first partitioned unstructured personal data and the second partitioned unstructured personal data according to the first data confusion characteristic and the second data confusion characteristic; Determine a modality definition for each of the first partitioned unstructured personal data and the second partitioned unstructured personal data according to the measurement result; Obtaining unimodal unstructured personal data and bimodal unstructured personal data according to the modality definition, and configuring display features and text features according to the data content of the unimodal unstructured personal data; determining a hidden data segment and a displayable data segment based on a data identifier of each word in the data content of the bimodal unstructured personal data; Configuring preliminary display features and text features of bimodal unstructured personal data based on displayable data segments; Advanced display features and text features for bimodal unstructured personal data based on hidden data segments; Setting mapping rules between advanced display features and text features and primary display features and text features of bimodal unstructured personal data; Before decrypting the key ciphertext to obtain the symmetric key according to the authorization result and decrypting the data ciphertext using the symmetric key to obtain the original data, the following steps are also included: Upload the data ciphertext to the cloud storage server and obtain the data ciphertext address according to the storage path; Constructing a data element table according to the data ciphertext address, the key ciphertext and the first hash value and uploading it to the blockchain network; Respond to the access request of the data requester, retrieve the data element table and feed it back to the terminal where the data requester is located; Decrypt the key ciphertext according to the authorization result to obtain the symmetric key, and use the symmetric key to decrypt the data ciphertext to obtain the original data, including: Obtain the identity private key and system public key of the data requester according to the authorization result, and use the identity private key and system public key to decrypt the key ciphertext to obtain the symmetric key; Obtain the ciphertext address through the data element table, access the cloud storage server based on the ciphertext address, and receive the data ciphertext sent by the cloud storage server; Decrypt the data ciphertext using the symmetric key to obtain the original data; Decrypting the data ciphertext by using the symmetric key to obtain the original data includes: Create a random initial vector and expand the random initial vector to obtain an expansion factor, iterate the expansion factor and the data ciphertext, and obtain the generated ciphertext according to the iteration result; Determine whether the generated ciphertext meets the expected output. If so, obtain a copy of the original data based on the generated ciphertext. If not, recreate the initial vector and repeat the iteration until the generated ciphertext meets the expected output. The original data copy is decrypted using the symmetric key to obtain the original data.

2. The unstructured personal data protection method for omni-channel self-pickup business in the clothing industry according to claim 1 is characterized in that: Before performing SM3 encryption and symmetric encryption on the unstructured personal data, obtaining the data ciphertext and its symmetric key and the first hash value, performing CP-ABE encryption on the symmetric key, and generating the key ciphertext, the method further includes: Define the encryption function and execute the initialization algorithm to generate a 128-byte block; The first 32 bytes in the 128-byte block are saved as the system master key, and the last 96 bytes in the 128-byte block are saved as the system public key.

3. The unstructured personal data protection method for omni-channel self-pickup business in the clothing industry according to claim 1 is characterized in that: The step of performing SM3 encryption and symmetric encryption on the unstructured personal data, obtaining the data ciphertext and its symmetric key and the first hash value, performing CP-ABE encryption on the symmetric key, and generating the key ciphertext includes: Determine a first data type of the unstructured personal data, select a block division method according to the first data type, and divide the unstructured personal data into a plurality of blocks by using the block division method; Perform SM3 encryption on each block, and obtain a first hash value according to the first encryption result; Selecting a symmetric encryption algorithm according to the first data type of the unstructured personal data, and symmetrically encrypting the unstructured personal data using the symmetric encryption algorithm; The data ciphertext is obtained according to the second encryption result, the identity attribute set of the CP-ABE encryption system is defined and the CP-ABE encryption system is initialized, and the CP-ABE encryption system is used to perform CP-ABE encryption on the symmetric key to generate the key ciphertext.

4. The unstructured personal data protection method for omni-channel self-pickup business in the clothing industry according to claim 1 is characterized in that: The obtaining of the access request of the data requester and authorizing the identity of the data requester based on the preset access policy includes: Obtain access requests from data requesters through the blockchain network, and obtain identity information of the data requesters based on the access requests; Review the identity information, determine abnormal information items based on the review results, and determine the identity verification eligibility of the data requester based on the abnormal information items; If the verification is qualified, the current identity attributes of the person requesting the data are obtained based on the identity information; Based on the preset access policy, the conditional identity attributes that meet the data access rights are determined, and the identity of the data requester is authorized based on the conditional identity attributes and the current identity attributes.

5. The unstructured personal data protection method for omni-channel self-pickup business in the clothing industry according to claim 4 is characterized in that: The determining of the conditional identity attributes that meet the data access rights based on the preset access policy, and authorizing the data requester according to the conditional identity attributes and the current identity attributes, includes: Determine an identity attribute data set based on a preset access policy, and determine to obtain multiple conditional identity attributes that meet the data access rights based on the identity attribute data set; Match the current identity attribute with multiple conditional identity attributes, obtain a matching result, and determine whether there is a matching item based on the matching result; If yes, determine that the person requesting the data has the data access rights, authorize the person requesting the data and distribute the private key and system public key to the person requesting the data; If not, it is determined that the person requesting the data does not have the data access rights, and a reminder is sent to the person requesting the data that he or she does not meet the identity authorization conditions.

6. The unstructured personal data protection method for omni-channel self-pickup business in the clothing industry according to claim 1 is characterized in that: The performing SM3 encryption on the original data to obtain the second Hash value, and comparing the first Hash value with the second Hash value to determine whether the unstructured personal data has been tampered with, includes: Determine a second data type of the original data, select a block division method according to the second data type, and divide the original data into a plurality of blocks by using the block division method; Perform SM3 encryption on each block, and obtain a second hash value according to the third encryption result; Determine whether the first hash value is the same as the second hash value. If so, determine that the unstructured personal data has not been tampered with. If not, determine that the unstructured personal data has been tampered with.

7. The unstructured personal data protection method for omni-channel self-pickup business in the clothing industry according to claim 1 is characterized in that: Also includes: Obtain multiple operational behavior parameters of the data requester on the unstructured data and the operation frequency of each operational behavior parameter; Determine abnormal operation behavior parameters according to the operation frequency and issue early warning reminders based on the abnormal operation behavior parameters; Determine the operation type of each operation behavior parameter, and generate an operation record of the data requester on the unstructured data based on multiple operation behavior parameters; Generate an operation log for the data requester based on the operation record and operation type and upload the operation log to the cloud storage server.

Citation Information

Patent Citations

  • Attribute-based encryption and block chain combined trusted data access control scheme

    CN112836229A

  • Access control method based on block chain and attribute-based encryption

    CN116112244A

  • Medical data sharing method and device based on block chain, equipment and storage medium

    CN117409914A