A blacklist sharing method and device, electronic equipment and storage medium
By exchanging blacklist information through RSA encryption and unintentional transmission protocol, the problem of joint risk control among financial institutions is solved, achieving efficient and secure blacklist sharing and protecting customer privacy.
Patent Information
- Application Number
- CN202411742862.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-29
- Publication Date
- 2025-12-19
- Estimated Expiration
- 2044-11-29
AI Technical Summary
The inability of financial institutions to achieve joint risk control allows illegal and criminal activities to evade anti-money laundering monitoring through cross-bank transactions, and existing list exchange schemes are not conducive to the protection of customer privacy.
Using the RSA encryption algorithm and the stealth transmission protocol, blacklist data is encrypted and key pairs are exchanged. A second organization then uses the key set to decrypt and obtain the real information, without directly exchanging the blacklist.
It enables efficient exchange of blacklist information while protecting customer privacy, requiring only two rounds of information exchange, thus ensuring information security and privacy protection.
Smart Images

Figure CN119675930B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of financial security, more particularly, to a blacklist sharing method and device, electronic equipment and storage medium. BACKGROUND
[0002] With the rapid integration of financial technology, the field of anti-money laundering monitoring also faces greater opportunities and challenges. However, due to the inability of various institutions to implement joint risk control, when illegal criminal activities manipulate fund flow, they often consciously cut off tracking clues through cross-bank transactions, so that transaction information is scattered on the "island" of different obligated institutions. For example, a customer or a transaction may trigger a suspicious transaction in one obligated institution, but may not trigger a suspicious transaction in another institution. This can largely evade effective monitoring and analysis, which is not conducive to the development of anti-money laundering work. List monitoring means is a key technical solution of the existing anti-money laundering monitoring system, which plays a crucial role in anti-money laundering work. However, if the list is directly exchanged, it is not conducive to the protection of customer privacy. SUMMARY
[0003] Therefore, the present application provides a blacklist sharing method and device, electronic equipment and storage medium for exchanging blacklists on the basis of protecting customer privacy.
[0004] In order to achieve the above purpose, the present application provides the following scheme:
[0005] A blacklist sharing method applied to an electronic device, the electronic device including a first institution and a second institution needing to exchange a blacklist, the blacklist sharing method including the steps of:
[0006] controlling the first institution to encrypt blacklist data to obtain an encrypted data set and an RSA key pair, and sending plaintext in the RSA key pair to the second institution;
[0007] controlling the second institution to obtain the data set and a key set based on the plaintext and through an oblivious transfer protocol;
[0008] controlling the second institution to decrypt the data set using the key set to obtain the required real information.
[0009] Optionally, the controlling the first institution to encrypt the blacklist data to obtain the encrypted data set and the RSA key pair, and sending the plaintext in the RSA key pair to the second institution includes the steps of:
[0010] classifying and encrypting the blacklist data to obtain a plurality of data clusters, the data clusters being the data set;
[0011] generating the RSA key pair based on an RSA encryption algorithm, the RSA key pair comprising key parameters and the plaintext;
[0012] sending the plaintext to the second organization.
[0013] Optionally, the control of the second organization to obtain the data set and the key set based on the plaintext and through an oblivious transfer protocol comprises the steps of:
[0014] controlling the second organization to randomly allocate two large prime numbers and to process the two large prime numbers based on an oblivious transfer algorithm, and sending a y value, first data and a P value obtained to the first organization;
[0015] controlling the first organization to perform encryption processing on the first data to generate second data, and sending the second data to the second organization;
[0016] controlling the second organization to perform decryption processing on the second data to obtain third data, and sending the third data to the first organization;
[0017] controlling the first organization to perform decryption processing on the third data to obtain the two large prime numbers, and obtaining the key set based on the two large prime numbers and the y value, and sending the key set and the data set to the second organization.
[0018] Optionally, the control of the second organization to randomly allocate two large prime numbers and to process the two large prime numbers based on an oblivious transfer algorithm, and sending a y value, first data and a P value obtained to the first organization comprises the steps of:
[0019] randomly allocating the two large prime numbers;
[0020] mechanically processing the two large prime numbers through an oblivious transfer algorithm to obtain the y value;
[0021] performing encryption processing on the two large prime numbers through two random numbers to obtain the first data and the P value;
[0022] sending the y value, the first data and the P value to the first organization.
[0023] A blacklist sharing device applied to an electronic device, the electronic device comprising a first organization and a second organization which need to exchange a blacklist, the blacklist sharing device comprising:
[0024] a first control module configured to control the first organization to perform encryption processing on blacklist data to obtain an encrypted data set and an RSA key pair, and to send a plaintext in the RSA key pair to the second organization;
[0025] a second control module configured to control the second mechanism to obtain the data set and the key set based on the plaintext and through an oblivious transfer protocol;
[0026] a shared execution module configured to control the second mechanism to decrypt the data set by using the key set, to obtain the required real information.
[0027] Optionally, the first control module comprises:
[0028] a first encryption unit configured to classify and encrypt the blacklist data, to obtain a plurality of data clusters, the data clusters being the data set;
[0029] a second encryption unit configured to generate the RSA key pair based on an RSA encryption algorithm, the RSA key pair comprising a key parameter and the plaintext;
[0030] a sending execution unit configured to send the plaintext to the second mechanism.
[0031] Optionally, the second control module comprises:
[0032] a first control unit configured to control the second mechanism to randomly allocate two large prime numbers, and to cause the two large prime numbers to be processed based on an oblivious transfer algorithm, to send a y value, first data and a P value obtained to the first mechanism;
[0033] a second control unit configured to control the first mechanism to encrypt the first data, to generate second data, and to send the second data to the second mechanism;
[0034] a third control unit configured to control the second mechanism to decrypt the second data, to obtain third data, and to send the third data to the first mechanism;
[0035] a fourth control unit configured to control the first mechanism to decrypt the third data, to obtain the two large prime numbers, and to obtain the key set based on the two large prime numbers and the y value, and to send the key set and the data set to the second mechanism.
[0036] Optionally, the first control unit is configured to perform the following steps:
[0037] randomly allocating the two large prime numbers;
[0038] mechanically processing the two large prime numbers through an oblivious transfer algorithm, to obtain the y value;
[0039] The two large prime numbers are encrypted by two random numbers to obtain the first data and the P value;
[0040] The y value, the first data and the P value are sent to the first institution.
[0041] An electronic device, comprising at least one processor and a memory connected to the processor, wherein:
[0042] The memory is used to store a computer program or treatment;
[0043] The processor is used to execute the computer program or instruction, so that the electronic device realizes the black list sharing method as described above.
[0044] A computer readable storage medium applied to an electronic device, the storage medium carrying one or more computer programs, the one or more computer programs being executable by the electronic device, so that the electronic device realizes the black list sharing method as described above.
[0045] From the above technical solution, the present application discloses a black list sharing method, device, electronic device and storage medium, the method and device are applied to electronic equipment, electronic equipment includes the first institution and the second institution which need to exchange the list, the black list sharing method is specifically to control the first institution to encrypt the black list data, obtain the encrypted data set and RSA key pair, and send the plaintext in the RSA key pair to the second institution; control the second institution to obtain the data set and the key set based on the plaintext and through the oblivious transfer protocol; control the second institution to decrypt the data set by using the key set, obtain the required real information. The present application does not give the second institution the black list in the process of obtaining the real information, but obtains the required real information through information exchange, which objectively plays a role in protecting customer privacy.
[0046] From the efficiency analysis point of view, the present application only needs two rounds of information interaction, which are the first institution sending y value and the second institution sending information set to the first institution. The main information processing process is concentrated in the calculation process of and Combined with the system server performance of the financial institution, it can be considered that the server can complete the calculation and processing in a short time;
[0047] From the security analysis point of view, the alpha and beta used by the first organization are randomly selected, and the RSA algorithm is used for key encryption in the transmission process, and meanwhile, no other information is sent to the second organization in the whole process, so that zero degree disclosure of the query information is realized. In addition, since the first organization can only decrypt the required information item, even if the first organization sends the elephant related data in the whole process, the second organization can only obtain the related data required by itself, and cannot decrypt other data. BRIEF DESCRIPTION OF DRAWINGS
[0048] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or prior art description will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor on the basis of these drawings.
[0049] Figure 1 A flow chart of a blacklist exchange method according to an embodiment of the present application;
[0050] Figure 2 A block diagram of a blacklist exchange device according to an embodiment of the present application;
[0051] Figure 3 A working flow chart of a blacklist sharing device according to an embodiment of the present application;
[0052] Figure 4 A block diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0053] The technical solutions in the embodiments of the present application will be described clearly and completely in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the present application.
[0054] Figure 1 A flow chart of a blacklist exchange method according to an embodiment of the present application.
[0055] As Figure 1As shown, the blacklist exchange method provided by the embodiment is applied to an electronic device. The electronic device includes a first mechanism and a second mechanism. The first mechanism can be described as a receiving mechanism that stores blacklist data. The second mechanism can be described as a sending mechanism for proving to the first mechanism whether there is a list overlap. The electronic device can be understood as a computer, a server, and a cloud platform that have data calculation and data processing capabilities. The blacklist exchange method includes the following steps.
[0056] S1, control the first mechanism to perform encryption processing on the blacklist data to obtain an encrypted data set and an RSA key pair, and send plaintext in the RSA key pair to the second mechanism.
[0057] The specific process is as follows:
[0058] The blacklist data is classified and encrypted to obtain a plurality of data clusters, and each data cluster is a data set.
[0059] An RSA key pair is generated based on an RSA encryption algorithm. The RSA key pair includes a key parameter and plaintext.
[0060] The plaintext is sent to the second mechanism.
[0061] The specific calculation process of the RSA encryption algorithm is as follows:
[0062] (1) The server of the server generates an RSA key pair, and the key pair includes (N, e, d). N is plaintext, and the plaintext N is sent to the terminal of the client, that is, N is public, and the key parameters e and d are secret and not public.
[0063] (2) The terminal generates two random numbers R n1 and R n2 , and both random numbers are secret and not public. The root key of the terminal is R k , and R k is required to be less than N. The terminal performs calculation and encryption, that is, R k ∧R n1 mod N=R k1 , (R k +R k ∧(R n1 *R n2 ))mod N=P, and the terminal transmits R k1 and P to the server.
[0064] (3) The server receives the encrypted data and performs encryption again to obtain R k1 ^e mod N=R k2 , and transmits R k2 to the terminal.
[0065] (4) The terminal decrypts the re-encrypted data of the server: R k2 ∧R n2 mod N = R k3 , and sends R k3 to the server;
[0066] (5) The server decrypts R k3 to R k3 ^d mod N = R k4 , (P-R k4 ) mod N = R k0 , at this time R k0 is the root key R k .
[0067] S2, controls the second mechanism to obtain a data set and a key set based on plaintext and through an oblivious transfer protocol.
[0068] The specific process is as follows:
[0069] First, when the second mechanism performs data query, the controller randomly allocates two large prime numbers a and b, calculates the two large prime numbers according to the oblivious transfer algorithm to obtain a value y, and encrypts a and b through two random numbers to generate first data R k1 , P, sends the value y, R k1 , and P to the first receiving mechanism.
[0070] The first mechanism controls the encryption of the first data R k1 to generate second data R k2 , and transmits the second data R k2 to the second sending mechanism.
[0071] The second mechanism controls the decryption of the second data R k2 to generate third data R k3 , and transmits the third data R k3 to the first receiving mechanism.
[0072] The first mechanism controls the decryption of the third data R k3 to obtain a and b, and on the basis of receiving the value y, returns the prepared encrypted data cluster, i.e., the data set, and the calculated key set to the second mechanism.
[0073] The specific content of the oblivious transfer algorithm in the present application is as follows:
[0074] Suppose q and p are two large prime numbers (2q+1), G is a q-order group, a and b are generators of the group G, and Z q represents the smallest residual set of q. Among them, a, b, and G are published to the sending mechanism. The working mode of the algorithm can be represented as follows:
[0075] Assume M = {m1, m2, ... m} n} is the result set of the query by the sending organization, and the sending organization wants to obtain a specific piece of data m from this set. a (1≤a≤n). Therefore, this mechanism generates a condition that satisfies r∈Z. q Generate a random number and calculate y = α. r β a mod p, and then send y to the receiving agency.
[0076] The receiving mechanism first applies K = {k1, k2, ... k} to each element in M. n Encrypt and generate the encrypted set. After receiving the y-value from the sending organization, the receiving organization... as well as The calculation yields ST = {(s1, t1), (s2, t2), ..., (s...} n , t n ))}, where h i ∈Z q , 1≤i≤n. And return EM and ST to the sending agency simultaneously.
[0077] The sending agency uses k a =[t a / (s a ) r The k required to calculate mod p a And use the key to decrypt and obtain the requested data m. a Its decryption formula is
[0078] S3. The second control unit uses the key set to decrypt the data set and obtain the required real information.
[0079] That is, after the second institution receives the returned information, it controls the second institution to use the aforementioned key set and data set to perform decryption processing to obtain the required real information.
[0080] From the above technical solution can be seen, the embodiment provides a kind of black list sharing method, the method is applied to electronic equipment, electronic equipment includes the first mechanism and second mechanism needing to exchange list, the black list sharing method specifically is control first mechanism carries out encryption processing to black list data, obtains the data set and RSA key pair after encryption, and clear text in RSA key pair is sent to second mechanism;Control second mechanism obtains data set and key set based on clear text and by means of casual transmission protocol;Control second mechanism uses key set to decrypt data set, obtains the real information required.This scheme does not hand over black list to second mechanism in the process of obtaining real information, but obtains the real information required by information exchange, which objectively plays the role of protecting customer privacy.
[0081] From the efficiency analysis point of view, the scheme only needs to pass through two rounds of information interaction, which are the first mechanism sending y value and the second mechanism sending information set to the first mechanism.The main information processing process is concentrated in the calculation process of And Combined with the system server performance deployed by financial institutions, it can be considered that the server can complete the calculation processing in a short time;
[0082] From the security analysis point of view, the first mechanism uses α, β randomly, and RSA algorithm is used for key encryption in the transmission process, and at the same time, any other information is not sent to the second mechanism in the whole process, realizing zero degree disclosure of query information.In addition, since the first mechanism can only decrypt the information items required, even if the first mechanism sends elephant related data in the whole process, the second mechanism can only obtain the related data required by itself, and cannot decrypt other data.
[0083] The flowcharts and block diagrams in the drawings illustrate the possible implementation architecture, function and operation of the system, method and computer program product according to various embodiments of the present disclosure.In this regard, each block in the flowchart or block diagram can represent a module, program segment or part of code containing one or more executable instructions for implementing the specified logic function.It should also be noted that in some alternative implementations, the functions marked in the block can also occur in different order from that marked in the drawing.For example, two blocks indicated in succession can actually be executed substantially in parallel, and sometimes they can be executed in reverse order, depending on the function involved.It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be realized by a special hardware-based system for executing the specified function or operation, or can be realized by a combination of special hardware and computer instructions.
[0084] Although the operations are depicted in a particular, sequential order, this should not be understood as requiring or
[0085] It is to be understood that the various steps described in the method embodiments of the present disclosure can be performed in a different order and / or in parallel. Additionally, the method embodiments can include additional steps and / or omit performing the steps shown. The scope of the present disclosure is not limited in this regard.
[0086] Computer program code for carrying out operations of the present disclosure can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).
[0087] Figure 2 A block diagram of a blacklist exchange device according to an embodiment of the present disclosure.
[0088] As Figure 2 shown, the blacklist exchange device according to the present embodiment is applied to an electronic device. The electronic device according to the present disclosure can be a computer, a server or a cloud platform having data computing and data processing capabilities. The electronic device according to the present disclosure includes a first mechanism and a second mechanism. The first mechanism can be described as a receiving mechanism that stores blacklist data. The second mechanism can be described as a sending mechanism that is used to verify whether there is a list overlap with the first mechanism. The blacklist exchange device according to the present embodiment includes a first control module 10, a second control module 20 and a shared execution module 30.
[0089] The first control module is used to control the first mechanism to perform encryption processing on the blacklist data, to obtain an encrypted data set and an RSA key pair, and to send the plaintext in the RSA key pair to the second mechanism. The module includes a first encryption unit, a second encryption unit and a sending execution unit.
[0090] The first encryption unit is used to classify and encrypt the blacklist data to obtain a plurality of data clusters. Each data cluster is a data set.
[0091] The second encryption unit is configured to generate an RSA key pair based on an RSA encryption algorithm, the RSA key pair comprising key parameters and plaintext;
[0092] The sending execution unit is configured to send the plaintext to the second organization.
[0093] The second control module is configured to control the second organization to obtain a data set and a key set based on the plaintext and through an oblivious transfer protocol. The module comprises a first control unit, a second control unit, a third control unit and a fourth control unit.
[0094] The first control unit is configured to, when the second organization performs a data query, control the controller to randomly assign two large prime numbers α and β, calculate the two large prime numbers according to an oblivious transfer algorithm to obtain a value y, and encrypt the two large prime numbers α and β through two random numbers to generate first data R k1 , P, and send the value y, R k1 , P to the first receiving organization.
[0095] The second control unit is configured to control the first organization to perform encryption processing on the first data R k1 to generate second data R k2 , and transmit the second data R k2 to the second sending organization.
[0096] The third control unit is configured to control the second organization to perform decryption processing on the second data R k2 to generate third data R k3 , and transmit the third data R k3 to the first receiving organization.
[0097] The fourth control unit is configured to control the first organization to perform decryption processing on the third data R k3 to obtain α and β, and return the prepared encrypted data cluster, i.e., the data set, and the calculated key set to the second organization based on the received value y.
[0098] The sharing execution module is configured to control the second organization to perform decryption processing on the data set using the key set to obtain the required real information.
[0099] That is, after the second organization obtains the returned information, the second organization is controlled to perform decryption processing on the key set and the data set to obtain the required real information.
[0100] Specifically, the specific working process of the blacklist sharing device in the application is as shown in Figure 3 , wherein the receiving organization and the first organization of the application are the same technical concept, and the sending organization and the second organization of the application are the same technical concept.
[0101] From the above technical solution can be seen, the embodiment provides a kind of black list sharing device, the device is applied to electronic equipment, electronic equipment includes the first mechanism and the second mechanism needing to exchange list, the black list sharing method is specifically to control the first mechanism to carry out encryption processing to black list data, obtain encrypted data set and RSA key pair, and send plaintext in RSA key pair to the second mechanism;Control the second mechanism obtains data set and key set based on plaintext and by means of casual transmission protocol;Control the second mechanism to utilize key set to carry out decryption to data set, obtain the real information needed.This scheme does not hand over black list to the second mechanism in the process of obtaining real information, but obtains the real information needed by information exchange, which objectively plays the role of protecting customer privacy.
[0102] From the efficiency analysis point of view, the scheme only needs to pass through two rounds of information interaction, which are the first mechanism sending y value and the second mechanism sending information set to the first mechanism.The main information processing process is concentrated in the calculation process of And Combined with the system server performance deployed by financial institutions, it can be considered that the server can complete the calculation processing in a short time;
[0103] From the security analysis point of view, α and β used by the first mechanism are randomly selected, and RSA algorithm is used for key encryption in the transmission process, and at the same time, any other information is not sent to the second mechanism in the whole process, realizing zero degree disclosure of query information.In addition, since the first mechanism can only decrypt the information items needed, even if the first mechanism sends elephant related data in the whole process, the second mechanism can only obtain the related data needed by itself, and cannot decrypt other data.
[0104] The units described in the embodiments of the present disclosure can be implemented in software or hardware. Among them, the name of the unit does not constitute a limitation to the unit itself in some cases, for example, the first acquisition unit can also be described as "a unit for acquiring at least two internet protocol addresses".
[0105] The functions described above in this paper can be executed at least partially by one or more hardware logic components. For example, non-limitingly, exemplary types of hardware logic components that can be used include: field programmable gate array (FPGA), application specific integrated circuit (ASIC), application specific standard product (ASSP), system on chip (SOC), complex programmable logic device (CPLD) and the like.
[0106] Figure 4 A block diagram of an electronic device according to an embodiment of the present application.
[0107] Reference will now be made toFigure 4 FIG. 1 shows a structural diagram of an electronic device suitable for implementing the electronic device in the embodiments of the present disclosure. The terminal device in the embodiments of the present disclosure can include, but is not limited to, a mobile terminal such as a mobile phone, a notebook computer, a digital broadcast receiver, a PDA (Personal Digital Assistant), a PAD (Tablet Personal Computer), a PMP (Portable Multimedia Player), a car terminal (e.g., a car navigation terminal), and the like, and a stationary terminal such as a digital TV, a desktop computer, and the like. The electronic device is merely an example and should not impose any limitation on the functions and use range of the embodiments of the present disclosure.
[0108] The electronic device can include a processing device (e.g., a central processing unit, a graphic processing unit, etc.) 401 that can perform various appropriate actions and processes according to programs stored in a read-only memory (ROM) 402 or programs loaded into a random access memory (RAM) 403 from an input device 406. In the RAM, various programs and data required for the operation of the electronic device are also stored. The processing device, the ROM, and the RAM are connected to each other through a bus 404. An input / output (I / O) interface 405 is also connected to the bus 404.
[0109] Generally, the following devices can be connected to the I / O interface: input devices including, for example, a touch screen, a touch pad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, and the like; output devices 407 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, and the like; storage devices 408 including, for example, a magnetic tape, a hard disk, and the like; and communication devices 409. The communication devices 409 can allow the electronic device to communicate with other devices wirelessly or via wires to exchange data. Although the electronic device having various devices is shown in the figure, it should be understood that all the shown devices are not required to be implemented or provided. More or less devices can be alternatively implemented or provided.
[0110] The present application also provides a computer-readable storage medium embodiment.
[0111] The above computer-readable storage medium is applied to an electronic device and carries one or more computer programs, when the one or more computer programs are executed by the electronic device, the electronic device controls a first mechanism to encrypt blacklist data to obtain an encrypted data set and an RSA key pair, and sends plaintext in the RSA key pair to a second mechanism; controls the second mechanism to obtain the data set and a key set based on the plaintext and through an inadvertent transmission protocol; controls the second mechanism to decrypt the data set using the key set to obtain the required real information. In the process of obtaining the real information, the blacklist is not given to the second mechanism, but the required real information is obtained through information exchange, which objectively plays a role in protecting customer privacy.
[0112] It should be noted that the computer-readable medium in the present disclosure can be a computer-readable signal medium or a computer-readable storage medium or any combination of the two. The computer-readable storage medium may, for example, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or apparatus, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to, an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0113] In the present disclosure, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in connection with an instruction execution system, apparatus or device. In the present disclosure, the computer-readable signal medium can include a data signal that carries computer-readable program code in a baseband or as part of a carrier wave. Such a propagated data signal can take on many forms, including but not limited to electro-magnetic, optical, or any suitable combination thereof. The computer-readable signal medium can also be any computer-readable medium that is not a storage medium and that can communicate, propagate or transport program code for use by or in connection with an instruction execution system, apparatus or device. Program code embodied on a computer-readable medium can be transmitted using any suitable medium, including but not limited to wire, cable, optical fiber, RF, etc., or any suitable combination of the above.
[0114] Each of the embodiments in the present specification is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be mutually referred to.
[0115] Although the preferred embodiments of the embodiments of the present application have been described, those skilled in the art can make further changes and modifications to the embodiments once they know the basic inventive concept. Therefore, the appended claims are intended to include the preferred embodiments and all changes and modifications falling within the scope of the embodiments of the present application.
[0116] Finally, it needs to be pointed out that in this document, relational terms such as first and second and the like can only be used to distinguish one entity or action from another entity or action, without necessarily requiring or implying any such actual relationship or order between such entities or actions. Moreover, the terms "comprises", "comprising", or any other variations thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can include other elements not expressly listed or inherent to such process, method, article, or apparatus. Without more limitations, an element defined by an "comprising" statement serves as a means plus function alternative.
[0117] The above detailed description of the technical solutions provided by the present application has been given, and the principles and implementation manners of the present application are described by applying specific examples in this document. The above description of the examples is only for helping to understand the method of the present application and its core idea; meanwhile, for those skilled in the art, according to the idea of the present application, the specific implementation manners and application ranges will have changes, and the above description of the content of the specification should not be understood as a limitation of the present application.
Claims
1. A blacklist sharing method applied to an electronic device, the electronic device including a first agency and a second agency that need to exchange a blacklist, the method comprising: The blacklist sharing method comprises the steps of: controlling the first mechanism to encrypt the blacklist data to obtain an encrypted data set and an RSA key pair, and sending plaintext in the RSA key pair to the second mechanism; controlling the second mechanism to obtain the data set and the key set based on the plaintext and through an oblivious transfer protocol, specifically, controlling the second mechanism to randomly allocate two large prime numbers, and causing the two large prime numbers to be processed based on an oblivious transfer algorithm, sending a y value, first data and a P value obtained to the first mechanism, controlling the first mechanism to encrypt the first data to generate second data, and sending the second data to the second mechanism, controlling the second mechanism to decrypt the second data to obtain third data, and sending the third data to the first mechanism, controlling the first mechanism to decrypt the third data to obtain the two large prime numbers, and obtaining the key set based on the two large prime numbers and the y value, and sending the key set and the data set to the second mechanism; controlling the second mechanism to decrypt the data set based on the key set to obtain the required real information.
2. The blacklist sharing method of claim 1, wherein, The control of the first mechanism to encrypt the blacklist data to obtain an encrypted data set and an RSA key pair, and the sending of plaintext in the RSA key pair to the second mechanism comprises the steps of: classifying and encrypting the blacklist data to obtain a plurality of data clusters, the data clusters being the data set; generating the RSA key pair based on an RSA encryption algorithm, the RSA key pair comprising a key parameter and the plaintext; sending the plaintext to the second mechanism.
3. The blacklist sharing method of claim 1, wherein, The control of the second mechanism to randomly allocate two large prime numbers, and the causing of the two large prime numbers to be processed based on an oblivious transfer algorithm to send a y value, first data and a P value obtained to the first mechanism comprises the steps of: randomly allocating the two large prime numbers; mechanically processing the two large prime numbers through an oblivious transfer algorithm to obtain the y value; encrypting the two large prime numbers through two random numbers to obtain the first data and the P value; sending the y value, the first data and the P value to the first mechanism.
4. A blacklist sharing apparatus applied to an electronic device, the electronic device including a first organization and a second organization which need to exchange a blacklist, characterized by comprising: a blacklist exchange unit configured to exchange the blacklist between the first organization and the second organization; a blacklist management unit configured to manage the blacklist; and a blacklist sharing unit configured to share the blacklist with the second organization. The blacklist sharing device comprises: a first control module configured to control the first mechanism to encrypt the blacklist data to obtain an encrypted data set and an RSA key pair, and send plaintext in the RSA key pair to the second mechanism; A second control module is configured to control the second mechanism to obtain the data set and the key set based on the plaintext and through an oblivious transfer protocol, and specifically includes a first control unit, a second control unit, a third control unit and a fourth control unit, wherein the first control unit is configured to control the second mechanism to randomly allocate two large prime numbers, and to process the two large prime numbers based on an oblivious transfer algorithm, and to send a y value, first data and a P value obtained to the first mechanism, the second control unit is configured to control the first mechanism to perform encryption processing on the first data, to generate second data, and to send the second data to the second mechanism, the third control unit is configured to control the second mechanism to perform decryption processing on the second data, to obtain third data, and to send the third data to the first mechanism, and the fourth control unit is configured to control the first mechanism to perform decryption processing on the third data, to obtain the two large prime numbers, and to obtain the key set based on the two large prime numbers and the y value, and to send the key set and the data set to the second mechanism. A shared execution module is configured to control the second mechanism to decrypt the data set based on the key set, to obtain required real information.
5. The black list sharing apparatus according to claim 4, wherein The first control module includes: A first encryption unit is configured to classify and perform encryption processing on the blacklist data, to obtain a plurality of data clusters, and the data cluster is the data set; A second encryption unit is configured to generate an RSA key pair based on an RSA encryption algorithm, and the RSA key pair includes a key parameter and the plaintext; A sending execution unit is configured to send the plaintext to the second mechanism.
6. The black list sharing apparatus of claim 4, wherein, The first control unit is configured to perform the following steps: Randomly allocate the two large prime numbers; Mechanically process the two large prime numbers through an oblivious transfer algorithm, to obtain the y value; Perform encryption processing on the two large prime numbers through two random numbers, to obtain the first data and the P value; Send the y value, the first data and the P value to the first mechanism.
7. An electronic device, comprising: The electronic device includes at least one processor and a memory connected to the processor, wherein: The memory is used to store a computer program or an instruction; The processor is used to execute the computer program or the instruction, so that the electronic device implements the blacklist sharing method according to any one of claims 1-3.
8. A computer readable storage medium, applied to an electronic device, characterized in that, The storage medium carries one or more computer programs, and the one or more computer programs can be executed by the electronic device, so that the electronic device implements the blacklist sharing method according to any one of claims 1-3. The storage medium carries one or more computer programs, and the one or more computer programs can be executed by the electronic device, so that the electronic device implements the blacklist sharing method according to any one of claims 1-3.
Citation Information
Patent Citations
Safe secret key transmission method based on RSA algorithm
CN104092551A
Blacklist sharing method and system based on casual transmission
CN112989386A