A password leakage detection method and system based on fully homomorphic encryption

By fully homomorphic encryption of the real password on the user side and homomorphic matching calculations are performed using the leaked database on the server side, the leakage problem during password detection in the existing technology is solved, and a safe and efficient password leakage detection is achieved.

CN119675985BActive Publication Date: 2025-05-13BEIJING YINSUAN TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510174935.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-18
Publication Date
2025-05-13
Estimated Expiration
2045-02-18

AI Technical Summary

Technical Problem

When detecting the leakage of user passwords, the prior art can easily lead to the leakage of user real passwords, and the traditional hash function encryption method is easily reversely solved, which poses a security risk.

Method used

Using a method based on full homomorphic encryption, the user side conducts full homomorphic encryption of the real password, generates ciphertext data, and performs homomorphic matching calculations through the leaked database on the server side to determine whether the password has been leaked.

Benefits of technology

Without revealing the user's real password, it is effectively detected whether it has been leaked, avoiding the problem of password leakage during the detection stage and improving detection efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119675985B_ABST
    Figure CN119675985B_ABST
Patent Text Reader

Abstract

The present invention provides a password leakage detection method and system based on fully homomorphic encryption, including: obtaining and storing the disclosed user names in external networks and databases, and the suspected password data corresponding to the user names, to obtain a leakage database; obtaining the ciphertext data sent by the user end, the ciphertext data including the user name of the user, and the encrypted data after the user performs fully homomorphic encryption on the real password; screening and obtaining a number of corresponding suspected password data in the leakage database according to the user name in the ciphertext data; using the suspected password data as an index, performing homomorphic matching calculations with the encrypted data respectively, and then performing integrated calculations to obtain the ciphertext matching results, and sending them to the user end, so that the user end performs fully homomorphic decryption on the ciphertext matching results, and judging whether the real password is leaked according to the decryption results. The present invention can effectively check whether the real password is leaked without leaking the real password of the user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of crop disease prevention and control, and relates to a password leakage detection method and system based on fully homomorphic encryption. Background Art

[0002] In today's digital age, the security and privacy protection of user passwords have become key issues. Traditional password management systems have significant privacy risks and security risks.

[0003] Some service providers may directly store user passwords in plain text. Once the database is compromised, the attacker can directly obtain the passwords of all users. This not only leads to direct data leakage, but may also cause a chain reaction because the user reuses the same password in multiple services. It is more common to use hash functions (such as MD5, SHA-256) to store passwords in a one-way encrypted manner. However, even hash values ​​can be reversed through rainbow table attacks or brute force cracking. When users want to detect whether their passwords have been leaked, they usually need to provide the password or its hash value to the server. This method not only increases the risk of password interception or abuse, but may also lead to the exposure of users' sensitive information.

[0004] As society attaches more importance to data protection, enterprises and organizations must protect user data more strictly, especially personally identifiable information. This requires enterprises to take appropriate technical and organizational measures to ensure the security of personal information and give users more control over their data.

[0005] Therefore, how to provide a password leakage detection method and system based on fully homomorphic encryption that can effectively detect password leakage without infringing user privacy is a problem that technical personnel in this field urgently need to solve. Summary of the invention

[0006] In view of this, the present invention proposes a password leakage detection method and system based on fully homomorphic encryption, which can check whether the user's real passwords are leaked without leaking them.

[0007] In order to achieve the above object, the present invention adopts the following technical solution:

[0008] The present invention discloses a password leakage detection method based on fully homomorphic encryption, comprising the following steps:

[0009] S1: Obtain and store the disclosed user names in the external network and database, as well as the suspected password data corresponding to the user names, to obtain a leaked database;

[0010] S2: Obtain ciphertext data sent by the user, where the ciphertext data includes the user's username and encrypted data obtained by fully homomorphically encrypting the user's real password;

[0011] S3: According to the user name in the ciphertext data, a number of corresponding suspected password data are obtained by screening in the leaked database; using the suspected password data as an index, homomorphic matching calculations are performed with the encrypted data respectively, and then integrated calculations are performed to obtain ciphertext matching results, and the results are sent to the user terminal so that the user terminal can perform fully homomorphic decryption on the ciphertext matching results, and determine whether the real password has been leaked according to the decryption results.

[0012] Preferably, the step of the user in S2 performing fully homomorphic encryption on his real password includes:

[0013] Generate encryption keys and decryption keys based on a fully homomorphic encryption algorithm;

[0014] The encryption key is used to perform a fully homomorphic encryption operation on the user's own real password to obtain the encrypted data.

[0015] Preferably, the step of performing a fully homomorphic encryption operation on the user's own real password using an encryption key comprises:

[0016] S21: Encode the real password according to the specified format and then cut it into several sub-segments of fixed length. , , len is the number of sub-segments;

[0017] S22: Use the encryption key to convert the sub-segment Encryption is the encrypted data .

[0018] Preferably, each of the sub-segments The corresponding ciphertext have the same length T, and is in integer format; the ciphertext For the length T The position of is set to value Q, and the rest of the length T is value 0; the expression is as follows:

[0019] Preferably, the step of using the suspected password data as an index, performing homomorphic matching calculations with the encrypted data, and then performing integrated calculations to obtain a ciphertext matching result in S3 includes:

[0020] S31, the suspected password data obtained by screening is encoded according to a specified format and then cut to obtain several sub-segments of fixed length , the encoding operation and the cutting operation are performed according to the encoding operation steps and the cutting operation steps of the user terminal;

[0021] S32, the sub-segment of the suspected password data Get the encrypted data as an index At length T The value of the position is the set value Q or 0; Execute this step one by one on all encrypted data in to obtain len values, and perform a fully homomorphically encrypted ciphertext multiplication operation on the len values;

[0022] S33, executing S32 one by one on the plurality of suspected password data corresponding to the same user name, obtaining a plurality of ciphertext multiplication results, and performing a ciphertext addition operation on the plurality of ciphertext multiplication results under fully homomorphic encryption;

[0023] S34. Send the ciphertext addition result obtained in S33 to the user end.

[0024] Preferably, the step in which the user terminal determines whether its real password has been leaked according to the decryption result in S3 includes: determining whether the decryption result is 0, if so, the real password has not been leaked; if not, the real password has been leaked.

[0025] Preferably, it also includes: the user terminal performs fully homomorphic decryption on the ciphertext matching result, and determines whether its real password is leaked according to the decryption result, and displays the determination result on the user terminal.

[0026] The present invention also discloses a password leakage detection system according to the password leakage detection method based on fully homomorphic encryption, comprising: a user end and a server end, wherein the user end and the server end are connected via a network, wherein:

[0027] The user terminal comprises:

[0028] The encryption and decryption module is used to perform fully homomorphic encryption on the user's real password to obtain encrypted data, and to perform fully homomorphic decryption on the ciphertext matching result to obtain the decrypted result;

[0029] The server side includes:

[0030] An initialization module is used to obtain and store the user names that have been disclosed in the external network and database, and the suspected password data corresponding to the user names, and obtain a leaked database;

[0031] A data preprocessing module, used for screening the leaked database according to the user name in the ciphertext data to obtain a number of corresponding suspected password data;

[0032] The homomorphic calculation module is used to use the suspected password data as an index, perform homomorphic matching calculations with the encrypted data respectively, and then perform integrated calculations to obtain a ciphertext matching result.

[0033] Preferably, the user terminal further includes a front-end display module for displaying a judgment result of whether the real password has been leaked according to the decryption result.

[0034] Preferably, the user end and the server end both further include a communication module for executing the sending and receiving operations of the user end ciphertext data and the server end ciphertext matching results.

[0035] It can be seen from the above technical solution that, compared with the prior art, the beneficial effects of the present invention include:

[0036] (1) After the server completes the match, the result is still in ciphertext, so the server does not know whether there is any leakage in this detection, further avoiding the problem of password leakage during the detection phase.

[0037] (2) The password data on the user side is decomposed into multiple characters and encrypted to ensure that the server cannot obtain the specific information of the current password to be detected when matching the password, thus avoiding the leakage of user privacy.

[0038] (3) User name screening on the server side can reduce a lot of unnecessary data comparisons, greatly improving detection efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art are briefly introduced below. Obviously, the drawings in the following description are only embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on the provided drawings without creative work.

[0040] Figure 1 A flowchart of a password leakage detection method based on fully homomorphic encryption provided by an embodiment of the present invention;

[0041] Figure 2 A flowchart of obtaining a ciphertext matching result provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0042] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0043] A first aspect of an embodiment of the present invention provides a password leakage detection method based on fully homomorphic encryption, comprising the following steps:

[0044] S1: Obtain and store the disclosed user names in the external network and database, as well as the suspected password data corresponding to the user names, to obtain the leaked database;

[0045] S2: Obtain the ciphertext data sent by the user, which includes the user's username and the encrypted data after the user performs fully homomorphic encryption on his real password;

[0046] S3: According to the user name in the ciphertext data, several corresponding suspected password data are screened in the leaked database; using the suspected password data as an index, homomorphic matching calculations are performed with the encrypted data respectively, and then integrated calculations are performed to obtain the ciphertext matching results, and sent to the user end so that the user end can perform fully homomorphic decryption on the ciphertext matching results, and determine whether the real password has been leaked based on the decryption results.

[0047] In one embodiment, the specific execution steps of S1 include:

[0048] The system administrator logs in to the server and enters the leaked password data into the system and saves it in the database in the form of The key-value pairs are saved in the form of integers to be called when querying. The max here represents the maximum value of the data entered into the system. The password data here can be obtained from the disclosed public social engineering database.

[0049] In one embodiment, the step of fully homomorphic encryption of the real password by the user in S2 includes:

[0050] Generate encryption keys and decryption keys based on a fully homomorphic encryption algorithm;

[0051] The encryption key is used to perform a fully homomorphic encryption operation on the user's real password to obtain the encrypted data.

[0052] In this embodiment, the steps of performing a fully homomorphic encryption operation on the user's own real password using an encryption key include:

[0053] S21: Encode the real password according to the specified format and cut it into several sub-segments of fixed length , , len is the number of sub-segments; for example, 78464465440 is cut into {7,84,64,46,54,40} according to two digits, len=6.

[0054] S22: Use the encryption key to Encryption to encrypt data For {7,84,64,46,54,40}, the first sub-segment is 7, and the segmentation is based on two digits, indicating that the value range is [0,99]. Then the encryption key is used to obtain , and Indicates the ciphertext obtained by encrypting messages 0 and 1 using the key. Similar encryption .

[0055] In this embodiment, each sub-segment The corresponding ciphertext have the same length T, and Integer format; ciphertext For the length T The position of is set to value Q, and the rest of the length T is value 0; the expression is as follows:

[0056] .

[0057] In this embodiment, the steps of using the suspected password data as an index in S3, performing homomorphic matching calculations with the encrypted data, and then performing integrated calculations to obtain the ciphertext matching results include:

[0058] S31, the server first matches the username username in the packaged ciphertext data with the username in the leaked database, filters out the suspected password data with the same username and saves it as the data to be executed for ciphertext matching. For example, assuming that the username of the first k data in the system is the same as username, then Note that the usernames of the k pieces of data here are exactly the same, but the corresponding suspected password data may not be consistent with the real password; the suspected password data obtained by screening is encoded according to the specified format and then cut to obtain several sub-segments of fixed length , the encoding operation and the cutting operation are performed according to the encoding operation steps and the cutting operation steps of the user end;

[0059] It should be noted that It is not necessary to filter out only one piece of suspected password data , it is possible to obtain multiple suspected password data from one platform or multiple platforms.

[0060] S32, the sub-segment of suspected password data Get encrypted data as index At length T The value of the position is the set value Q or 0; Execute this step one by one on all encrypted data in , obtain len values, and perform a fully homomorphic encrypted ciphertext multiplication operation on the len values;

[0061] S33, executing S32 one by one for a number of suspected password data corresponding to the same user name, obtaining a number of ciphertext multiplication results, and performing a ciphertext addition operation on the number of ciphertext multiplication results under fully homomorphic encryption;

[0062] S34. Send the ciphertext addition result obtained in S33 to the user end.

[0063] In one embodiment, the step in S3 where the user terminal determines whether its real password has been leaked according to the decryption result includes: determining whether the decryption result is 0, if so, the real password has not been leaked; if not, the real password has been leaked.

[0064] In this embodiment, when the suspected password data corresponding to the same user name in the leaked database is unique, the set value Q can be <1> , only the values ​​extracted from the current index are <1> When the ciphertext is multiplied by <1> In this case, the plaintext value sent to the user end for decryption is 1. Since the suspected password data is unique, there will be at most one result among the multiplication results of several ciphertexts. <1> , which is the result of a successful match. Therefore, in the process of calculating the ciphertext addition by multiplying the results of several ciphertexts in S33, there is at most one ciphertext <1> and at least n-1 ciphertexts remain <0> The final ciphertext addition result is either <0> Either <1> After the user end fully homomorphic decryption, the received result can be <1> , judging that the real password has been leaked.

[0065] In one embodiment, it also includes: the user terminal performs fully homomorphic decryption on the ciphertext matching result, and determines whether the real password is leaked according to the decryption result, and displays the determination result on the user terminal.

[0066] The second aspect of the embodiment of the present invention further provides a password leakage detection system according to the first aspect of the embodiment, comprising: a user end and a server end, the user end and the server end are connected via a network, wherein:

[0067] The user end includes:

[0068] The encryption and decryption module is used to perform fully homomorphic encryption on the user's real password to obtain encrypted data, and to perform fully homomorphic decryption on the ciphertext matching result to obtain the decrypted result;

[0069] The server side includes:

[0070] An initialization module is used to obtain and store the user names that have been disclosed in the external network and database, as well as the suspected password data corresponding to the user names, to obtain a leaked database;

[0071] A data preprocessing module is used to filter out a number of corresponding suspected password data in the leaked database according to the user name in the ciphertext data;

[0072] The homomorphic computing module is used to use the suspected password data as an index, perform homomorphic matching calculations with the encrypted data, and then perform integrated calculations to obtain the ciphertext matching results.

[0073] In one embodiment, the user terminal also includes a front-end display module for displaying the judgment result of whether the real password has been leaked according to the decryption result, so as to facilitate user visualization.

[0074] In one embodiment, both the user end and the server end further include a communication module for executing the sending and receiving operations of the user end ciphertext data and the server end ciphertext matching results.

[0075] The password leakage detection method and system based on fully homomorphic encryption provided by the present invention are introduced in detail above. In this embodiment, specific examples are applied to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea; at the same time, for general technical personnel in this field, according to the idea of ​​the present invention, there will be changes in the specific implementation method and application scope. In summary, the content of this specification should not be understood as a limitation on the present invention.

[0076] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined in the present embodiments may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown in the present embodiment, but will conform to the widest range consistent with the principles and novel features disclosed in the present embodiment.

Claims

1. A password leakage detection method based on fully homomorphic encryption, characterized in that: The steps include: S1: Obtain and store the disclosed user names in the external network and database, as well as the suspected password data corresponding to the user names, to obtain a leaked database; S2: Obtain ciphertext data sent by the user, the ciphertext data including the user's username and the encrypted data obtained by performing fully homomorphic encryption on the user's real password; including: Generate encryption keys and decryption keys based on a fully homomorphic encryption algorithm; The real password is encoded according to the specified format and then cut into pieces to obtain several fixed-length sub-segments {p1, p2, ..., p t ,...,p len }, t∈len, len is the number of sub-segments; S22: Use the encryption key to encrypt the sub-segments {p1, p2, ..., p len } Encrypted to the encrypted data S3: Filtering a number of corresponding suspected password data in the leaked database according to the user name in the ciphertext data; using the suspected password data as an index, performing homomorphic matching calculations with the encrypted data respectively, and then performing integration calculations to obtain ciphertext matching results, and sending them to the user end, so that the user end performs fully homomorphic decryption on the ciphertext matching results, and determines whether its real password has been leaked according to the decryption results; including: S31, the suspected password data obtained by screening is encoded according to a specified format and then cut to obtain a number of fixed-length sub-segments p′ t , the encoding operation and the cutting operation are performed according to the encoding operation steps and the cutting operation steps of the user terminal; S32, the sub-segment p' of the suspected password data t Get the encrypted data as an index At length T corresponding to p′ t The value of the position is the set value Q or 0; Execute this step one by one on all encrypted data in to obtain len values, and perform a fully homomorphically encrypted ciphertext multiplication operation on the len values; S33, executing S32 one by one for the plurality of suspected password data corresponding to the same user name, obtaining a plurality of ciphertext multiplication results, and performing a ciphertext addition operation under fully homomorphic encryption on the plurality of ciphertext multiplication results; S34. Send the ciphertext addition result obtained in S33 to the user end.

2. According to claim 1, the password leakage detection method based on fully homomorphic encryption is characterized in that: Each of the sub-segments p t The corresponding ciphertext The length T is the same, and p t is in integer format; the ciphertext For the length T corresponding to p t The position of is set to value Q, and the rest of the length T is value 0; the expression is as follows:

3. The password leakage detection method based on fully homomorphic encryption according to claim 1 is characterized in that: The step in S3 where the user terminal determines whether its real password has been leaked according to the decryption result includes: determining whether the decryption result is 0, if so, the real password has not been leaked; if not, the real password has been leaked.

4. The password leakage detection method based on fully homomorphic encryption according to claim 1 is characterized in that: Also includes: The user terminal performs fully homomorphic decryption on the ciphertext matching result, and determines whether the real password has been leaked according to the decryption result, and displays the determination result on the user terminal.

5. A password leakage detection system according to the password leakage detection method based on fully homomorphic encryption according to any one of claims 1 to 4, characterized in that: include: A user end and a server end, wherein the user end and the server end are connected via a network, wherein: The user terminal comprises: The encryption and decryption module is used to perform fully homomorphic encryption on the user's real password to obtain encrypted data, and to perform fully homomorphic decryption on the ciphertext matching result to obtain the decrypted result; The server side includes: An initialization module is used to obtain and store the user names that have been disclosed in the external network and database, and the suspected password data corresponding to the user names, and obtain a leaked database; A data preprocessing module, used for screening the leaked database according to the user name in the ciphertext data to obtain a number of corresponding suspected password data; The homomorphic calculation module is used to use the suspected password data as an index, perform homomorphic matching calculations with the encrypted data respectively, and then perform integrated calculations to obtain a ciphertext matching result.

6. The password leakage detection system according to claim 5, characterized in that: The user terminal also includes a front-end display module, which is used to display the judgment result of whether the real password is leaked according to the decryption result.

7. The password leakage detection system according to claim 5, characterized in that: The user end and the server end both further include a communication module for executing the sending and receiving operations of the user end ciphertext data and the server end ciphertext matching results.

Citation Information

Patent Citations

  • Method and system for realizing fingerprint matching by using ciphertext

    CN105391554A

  • Ciphertext feature matching method and system based on fully homomorphic encryption and composite polynomial

    CN118381598A