A multi-party risk label encryption joint query method and system
Through the multi-party risk tag encryption joint query method, the additive homomorphic encryption algorithm and Diffie-Hellman key negotiation are used to solve the problems of high computing complexity, insufficient security and flexibility in the existing technology, and efficient and secure risk tag encryption joint query is achieved.
Patent Information
- Application Number
- CN202510258978.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-06
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-03-06
AI Technical Summary
The existing technology has high computational complexity in large-scale graph data scenarios, resulting in performance bottlenecks, and pseudonymization technology cannot resist re-identification attacks. The graph query task relies on the reference n-order neighborhood of the demand side to merge the data provider, resulting in data redundancy and storage pressure, and insufficient flexibility.
The multi-party risk tag encryption joint search method is used to negotiate a session key through the Diffie-Hellman algorithm. The result party generates a data request. The data party uses the addition homomorphic encryption algorithm to encrypt the number of tag touches. The agency performs ciphertext aggregation. The result party uses the session private key to decrypt and conducts statistical analysis.
Improve computing efficiency, enhance data privacy and security, improve the flexibility and efficiency of multi-party cooperation, reduce data redundancy and storage pressure, and avoid re-identification attacks.
Smart Images

Figure CN119743260B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of privacy computing technology, and in particular relates to a multi-party risk label encryption joint query method and system. Background Art
[0002] In recent years, the data of a single institution has become difficult to prevent and control increasingly complex fraud risks. Therefore, it has become an inevitable trend to establish a cross-industry and cross-institutional joint anti-fraud model based on privacy computing. It will also help banks to more comprehensively portray the portraits of fraud subjects and more accurately identify fraudulent behaviors and activities.
[0003] Through privacy computing technology, it is possible to achieve the secure integration of multiple data including label data among the public security, banks, and operators, create a variety of anti-fraud models, including risk label joint investigation and analysis models, and improve the identification rate of risky personnel.
[0004] The Chinese invention patent application with publication number CN115033599A discloses a graph query method, system and related devices based on multi-party security. The method includes: extracting vertex IDs from their respective local graph data by each of multiple participants to obtain multiple vertex IDs, each vertex ID corresponds to a user; using the privacy set intersection technology by multiple participants to determine the intersection users between multiple vertex IDs to obtain the target intersection user; extracting the n-order neighborhood of the target intersection user by each of at least one data provider, and pseudonymizing the n-order neighborhood to obtain their respective reference n-order neighborhoods, and saving the dictionary corresponding to their respective pseudonyms and original IDs; and performing the graph query task by the demander based on the local graph data of the demander and the reference n-order neighborhood of at least one data provider to obtain the target query result.
[0005] This scheme involves the intersection of privacy sets and the extraction of n-order neighbors. These operations have high computational complexity in large-scale graph data scenarios, especially when there are a large number of participants or the scale of graph data is large, which may lead to performance bottlenecks. At the same time, pseudonymization technology is used to hide the original ID, but pseudonymization itself cannot resist re-identification attacks. Moreover, the graph query task relies on the demander to merge the reference n-order neighbors of all data providers into the graph database. This approach may lead to data redundancy and storage pressure when there are a large number of data providers, and lacks flexibility. Summary of the invention
[0006] The present invention provides a multi-party risk label encryption joint query method and system, aiming to solve the problems of low computational efficiency, insufficient security and flexibility in the prior art.
[0007] In order to solve the above technical problems, the present invention proposes a multi-party risk label encryption joint query method, which includes the following steps:
[0008] The result party and the agency conduct a session key negotiation based on the Diffie-Hellman algorithm to generate a session public key and a session private key. The session public key is broadcast to all data parties, and the session private key is owned only by the result party.
[0009] The result party generates data requests based on analysis requirements and requests data from all data parties;
[0010] The data party aligns all tags through broadcasting, counts the number of touches of each tag, encrypts the statistical value of the number of touches based on a session public key using an encryption algorithm with additive homomorphic properties, and then sends it to the agency;
[0011] The agency aggregates the encrypted data received and returns the aggregated data to the result party;
[0012] The result party uses a one-time session private key to decrypt the aggregated data to obtain the intermediate data, searches for the label data corresponding to the intermediate data through a predefined mapping table, and performs statistical analysis based on the label data.
[0013] Preferably, the method for negotiating a session key is specifically as follows:
[0014] The result party holds long-term public keys A and B, and the corresponding private keys a and b, satisfying , , where g is the generator of the finite discrete logarithm multiplicative group;
[0015] The result party generates a temporary session identifier, records the initiation timestamp as the current system time, and sends it to the agency for a session key negotiation;
[0016] The agency generates the random factor r and the random commitment , and return R to the result party, and calculate the session public key once:
[0017]
[0018] In the formula, Y is a session public key, H() represents a hash function, SID is a temporary session identifier, T is a timestamp, It is a string concatenation operation. After the calculation is completed, the agency broadcasts the one-time session public key to all data parties.
[0019] As a result, the session private key is calculated once:
[0020]
[0021] The result party retains a session private key, a session public key and a session private key to meet .
[0022] Preferably, the content of the data request includes a request task identifier, a request timestamp, a list of tags to be counted, a user range, and data format requirements.
[0023] Preferably, after receiving the data request, the data party uses empty tags to fill in the missing values in the data, and after the statistics are completed, each party will count the number of times their own tags are touched.
[0024] Preferably, the method of encrypting the statistical value of the number of touches based on a session public key using an encryption algorithm with additive homomorphic properties is:
[0025]
[0026] In the formula, Indicates that the specified user is in the data side The The encrypted ciphertext of the tags is represents the encryption function, Indicates that the specified user is in the data side The The plaintext of the tag, Y is the public key of a session, A random factor generated for the encryption algorithm. g is a generator of the finite discrete logarithm multiplicative group.
[0027] Preferably, the method of ciphertext aggregation is:
[0028]
[0029] In the formula, Represents the aggregate value of the ciphertext labels of all data parties, Indicates that the specified user is in the data side The The encrypted ciphertext of the tags is represents the encryption function, Indicates that the specified user is in the data side The The plaintext of the tag, Y is the public key of a session, is the sum of random factors, is the sum of the label values, N is the number of data cubes, and g is the generator of the finite discrete logarithm multiplicative group.
[0030] Preferably, the result party uses a one-time session private key to decrypt the aggregated data, specifically:
[0031]
[0032] In the formula, To decrypt the intermediate data, is the sum of random factors, is the sum of the tag values, g is the generator of the finite discrete logarithm multiplicative group, Y is the public key of a session, and y is the private key of a session.
[0033] Preferably, the predefined mapping table construction method is: the result side has a generator g of a finite discrete logarithm multiplication group, a large prime number p and a plaintext value range, and is calculated by modular operation ,Will As the key value of the mapping table, M is used as the value of the mapping table to construct the mapping table.
[0034] Preferably, the agency performs a consistency check on the ciphertext submitted by the data party before performing ciphertext aggregation.
[0035] Accordingly, the present invention also proposes a multi-party risk label encryption joint query system, which is used to implement the above method, including:
[0036] The result party is used to generate a data request, negotiate a session key with the agency, obtain a session public key and a session private key, and perform statistical analysis on the decrypted data;
[0037] The agency is used to receive the encrypted data submitted by the data party, perform ciphertext aggregation, and return the aggregated ciphertext data to the result party, while performing ciphertext consistency verification to ensure data accuracy;
[0038] The data party is used to align the tag data, count the number of tag touches, and encrypt the statistical value of the number of touches based on a session public key and send it to the agency;
[0039] Encryption calculation, which is used to encrypt statistical data based on the additive homomorphic encryption algorithm, and to find the corresponding label data based on the predefined mapping table after the result is decrypted;
[0040] The storage module is used to store encrypted data, intermediate calculation results and predefined mapping tables to support data processing and analysis.
[0041] Compared with the prior art, the present invention has the following technical effects:
[0042] 1. In the encrypted joint query method proposed in the present invention, all data exchange and calculation operations are protected by the additive homomorphic encryption algorithm. Additive homomorphic encryption ensures that data can be added without decryption, and there is no need to disclose the original data of any single data party. Therefore, in the entire process, neither the data party nor the agency can know the specific data of other data parties, which guarantees data privacy and security to the greatest extent.
[0043] 2. The encrypted joint query method proposed in this invention allows multiple data parties to jointly participate in the encrypted calculation and analysis of risk labels while maintaining data privacy. Multiple data parties can generate requests and collaborate to provide label data according to needs, which maximizes the flexibility and efficiency of cooperation among all parties.
[0044] 3. In the encrypted joint query method proposed in the present invention, the result party generates data requests according to the needs, including the list of labels to be counted, the user range and the data format requirements, which is highly customizable and applicable to various analysis scenarios. This enables the method to respond flexibly to different risk label analysis tasks and meet the needs of various application scenarios.
[0045] 4. The encrypted joint query method proposed in the present invention uses the characteristics of additive homomorphic encryption to enable the agency to directly calculate the ciphertext without decrypting it first, which greatly improves the efficiency of data processing and calculation. In addition, through the predefined mapping table, the decryption operation becomes more efficient, avoiding the process of calculating each label one by one, thereby saving computing resources and time.
[0046] 5. The encryption joint query method proposed in the present invention ensures the security of each data transmission through the negotiation of a one-time session key. Each session key is temporarily generated and is not associated with the previous session key, avoiding the security vulnerabilities that may be caused by long-term public keys. This session key mechanism enhances the security of the system and prevents the leakage of session keys. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] Figure 1 It is a flow chart of the encrypted joint query method of the present invention. DETAILED DESCRIPTION
[0048] In order to make the objectives, technical solutions and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in combination with specific embodiments of the present application and with reference to the accompanying drawings.
[0049] Embodiment 1
[0050] This embodiment is a multi-party risk tag encryption joint query method. Figure 1 As shown, the steps include steps one to five:
[0051] Step 1: The result party and the agency conduct a session key negotiation based on the Diffie-Hellman algorithm to generate a session public key and a session private key. The session public key is broadcast to all data parties, and the session private key is only owned by the result party.
[0052] The method for negotiating a session key is specifically as follows:
[0053] The result party holds long-term public keys A and B, and the corresponding private keys a and b, satisfying , , where g is the generator of the finite discrete logarithm multiplicative group;
[0054] The result party generates a temporary session identifier, records the initiation timestamp as the current system time, and sends it to the agency for a session key negotiation;
[0055] The agency generates the random factor r and the random commitment , and return R to the result party, and calculate the session public key once:
[0056]
[0057] In the formula, Y is a session public key, H() represents a hash function, SID is a temporary session identifier, T is a timestamp, It is a string concatenation operation; after the agency completes the calculation, it broadcasts the one-time session public key to all data parties.
[0058] As a result, the session private key is calculated once:
[0059]
[0060] The result is that the party retains the session private key once. During the Diffie-Hellman-based session key negotiation process, there is Therefore, the negotiated session public key and session private key satisfy .
[0061] Through the negotiation of a one-time session key, the present application scheme ensures the security of each data transmission. Each session key is generated temporarily and is not associated with the previous session key, avoiding the security vulnerabilities that may be caused by long-term public keys. This session key mechanism enhances the security of the system and prevents the leakage of session keys.
[0062] Step 2: The result party generates a data request based on the analysis requirements and requests data from all data parties.
[0063] The content of the data request includes a request task identifier, a request timestamp, a list of tags to be counted, a user range, and data format requirements.
[0064] The result party first generates a unique task ID based on the current analysis task to identify the task of the current data request. The task ID ensures that each task can be clearly distinguished in the case of multiple tasks.
[0065] The result party generates a request timestamp to record the exact time when the current request is initiated. The timestamp is used to identify the timeliness of the request and prevent the data request from expiring or becoming invalid.
[0066] The result party lists the tags that need to be counted according to the analysis requirements. These tags may be some user behavior tags, risk tags or other relevant data indicators; the tag list is the core of the data request and determines what data the data party needs to prepare for statistics.
[0067] The result party specifies the user range involved in the data request, which is usually a condition or screening standard that defines which users' data needs to be included in this request. For example, it can be user data for a specific time period, or user data under certain specific conditions (such as users in a certain region or category), or a specific data tag for a specific user.
[0068] Data format requirements are used to inform data parties of the data format requirements that need to be met when preparing data. The result party will clearly specify the format of the returned data in the data request, such as JSON, CSV, XML, etc., to ensure that all data parties provide data in a unified format for subsequent processing and analysis.
[0069] Step 3: The data party aligns all tags through broadcasting, counts the number of touches of each tag, uses an encryption algorithm with additive homomorphic properties to encrypt the statistical value of the number of touches based on a session public key, and then sends it to the agency.
[0070] After receiving the data request, the data party uses empty tags to fill the missing values in the data. After the statistics are completed, each party will count the number of times their own tags are touched.
[0071] After receiving the data request, the data provider first checks whether there are missing values in its data. In most practical scenarios, user data may be incomplete, and data items of certain labels may be missing. To ensure the completeness of statistics, the data provider will use empty labels (usually a default value of 0) to fill these missing values. The filling process ensures the consistency of the data and avoids incorrect statistics caused by missing values.
[0072] After filling the missing values, the data cube will count the number of touches for each user under the specified tag. A touch refers to the number of times the tag appears in the user's data or the number of related behaviors. This statistical value is usually an integer, indicating the activity level of the tag on the specified user. For example, if the tag represents "login behavior", the number of touches may represent the number of times the user logs in.
[0073] After counting the number of touches of each user on the tag, the data party needs to encrypt the statistical values of these touches. In order to ensure the privacy protection of the data and subsequent aggregate analysis, an encryption algorithm with additive homomorphic properties is used. This embodiment uses an improved algorithm based on the Elgamal encryption algorithm to encrypt the statistical values of the number of touches. Additive homomorphic encryption allows the encrypted data to be directly added without decrypting the data first. Specifically, the method of encrypting the statistical value of the number of touches based on a session public key using an encryption algorithm with additive homomorphic properties is as follows:
[0074]
[0075] In the formula, Indicates that the specified user is in the data side The The encrypted ciphertext of the tags is represents the encryption function, Indicates that the specified user is in the data side The The plain text of a tag is usually the number of times the tag has been touched. Y is the session public key generated through negotiation in step 1. A random factor generated for the encryption algorithm. g is a generator of the finite discrete logarithm multiplicative group.
[0076] After the encryption operation is completed, the data party packages all the encrypted ciphertexts and sends them to the agency. Since the encrypted data is encrypted based on a one-time session public key, these ciphertexts can only be decrypted by the corresponding private key, ensuring the security of the data. In the encrypted data, the agency cannot directly decrypt and view the statistical values of the number of plaintext touches. The agency only receives and processes the encrypted data, so it does not expose any original user data or statistical details.
[0077] Step 4: The agency aggregates the encrypted data received and returns the aggregated data to the result party. Due to the characteristics of additive homomorphic encryption, the agency can directly perform addition operations on these ciphertexts without decrypting them first. Additive homomorphic encryption ensures that the agency can obtain appropriate results without leaking the specific information of any individual data party.
[0078] The agency first receives encrypted data from each data party. These encrypted data represent the encrypted results of each data party according to the number of tag touches. The agency's task is to perform ciphertext aggregation on the encrypted data sent by all data parties, that is, to perform addition operations on the encrypted touch count statistics. Under the framework of additive homomorphic encryption, the agency can directly perform addition operations on the encrypted data without decryption.
[0079] Additive homomorphic encryption allows ciphertext to be added according to the corresponding rules without decrypting it first. For example, for the ciphertext of two data parties and , respectively, by plain text and The encryption is as follows:
[0080]
[0081]
[0082] and The random factors generated by the encryption algorithm for the two data parties can be directly calculated by the agency:
[0083]
[0084] Therefore, the agency needs to perform the same homomorphic addition operation on the encrypted data of all data parties until the sum of the number of tag touches is obtained and all In this step, the final aggregate ciphertext will be:
[0085]
[0086] In the formula, Represents the aggregated value of the ciphertext labels of all data parties. This is the final ciphertext result after aggregation. Indicates that the specified user is in the data side The The encrypted ciphertext of the tags is represents the encryption function, Indicates that the specified user is in the data side The The plaintext of the tag, Y is the public key of a session, The sum of random factors provided by all data parties, It is the sum of the statistical values of the number of tag touches provided by all data parties, N is the number of data parties, and g is the generator of the finite discrete logarithm multiplication group. That is, the ciphertext tag values provided by all data parties corresponding to a certain tag of the user are aggregated homomorphically.
[0087] The agency can directly send this encrypted result The result is returned to the party without exposing the original data. It is the final aggregated ciphertext, which contains the encrypted aggregated results of the statistical information of all data parties.
[0088] In some other embodiments of the present invention, the agency performs consistency verification on the ciphertext submitted by the data party before performing ciphertext aggregation.
[0089] Step 5: The result party uses a one-time session private key to decrypt the aggregated data to obtain the intermediate data, searches for the label data corresponding to the intermediate data through a predefined mapping table, and performs statistical analysis based on the label data.
[0090] The result party uses a one-time session private key to decrypt the aggregated data, specifically:
[0091]
[0092] In the formula, To decrypt the intermediate data, is the sum of random factors, is the sum of the tag values, g is the generator of the finite discrete logarithm multiplicative group, Y is the public key of a session, and y is the private key of a session.
[0093] The decryption result is ,because An exponential operation, directly from Obtain This involves calculating discrete logarithms, which are computationally complex in most cases. Therefore, when the plaintext space is not very large, and It is a feasible way to obtain the plaintext result by using the mapping table. Since the number of anti-fraud tag libraries is limited, which means that the plaintext space is not very large, this method is safe and efficient. By looking up the mapping table, the additive aggregation result of the user's tag values in all data cubes is obtained. , that is, the total number of times users touch the tag, and further statistical analysis is performed based on this.
[0094] The predefined mapping table construction method is: the result side has a generator g of a finite discrete logarithm multiplication group, a large prime number p and a plaintext value range, and is calculated by modular operation ,Will As the key value of the mapping table, As the value of the mapping table to build a mapping table, where To decrypt the intermediate data, is the sum of the label values.
[0095] Embodiment 2
[0096] This embodiment is a multi-party risk tag encryption joint query system, which is used to implement the method described in the first embodiment, including:
[0097] The result party is used to generate a data request, negotiate a session key with the agency, obtain a session public key and a session private key, and perform statistical analysis on the decrypted data;
[0098] The agency is used to receive the encrypted data submitted by the data party, perform ciphertext aggregation, and return the aggregated ciphertext data to the result party, while performing ciphertext consistency verification to ensure data accuracy;
[0099] The data party is used to align the tag data, count the number of tag touches, and encrypt the statistical value of the number of touches based on a session public key and send it to the agency;
[0100] Encryption calculation, which is used to encrypt statistical data based on the additive homomorphic encryption algorithm, and to find the corresponding label data based on the predefined mapping table after the result is decrypted;
[0101] The storage module is used to store encrypted data, intermediate calculation results and predefined mapping tables to support data processing and analysis.
[0102] The above is only a preferred embodiment of the present invention. It should be pointed out that a person skilled in the art can make several modifications and improvements without departing from the inventive concept of the present invention, which all belong to the protection scope of the present invention.
Claims
1. A multi-party risk label encryption joint query method, characterized in that: The following steps are involved: The result party and the agency negotiate a session key based on the Diffie-Hellman algorithm to generate a session public key and a session private key. The session public key is broadcast to all data parties, and the session private key is owned only by the result party. The result party generates data requests based on analysis requirements and requests data from all data parties; The data party aligns all tags through broadcasting, counts the number of touches of each tag, encrypts the statistical value of the number of touches based on a session public key using an encryption algorithm with additive homomorphic properties, and then sends it to the agency; The agency aggregates the encrypted data received and returns the aggregated data to the result party; The result party uses a one-time session private key to decrypt the aggregated data to obtain the intermediate data, searches for the label data corresponding to the intermediate data through a predefined mapping table, and performs statistical analysis based on the label data.
2. According to claim 1, a multi-party risk label encryption joint query method is characterized in that: The method for negotiating a session key is specifically as follows: The result party holds long-term public keys A and B, and the corresponding private keys a and b, satisfying , , where g is the generator of the finite discrete logarithm multiplicative group; The result party generates a temporary session identifier, records the initiation timestamp as the current system time, and sends it to the agency for a session key negotiation; The agency generates the random factor r and the random commitment , and return R to the result party, and calculate the session public key once: In the formula, Y is a session public key, H() represents a hash function, SID is a temporary session identifier, T is a timestamp, It is a string concatenation operation. After the calculation is completed, the agency broadcasts the one-time session public key to all data parties. As a result, the session private key is calculated once: The result party retains a session private key, a session public key and a session private key to meet .
3. The method for encrypted joint query of multi-party risk labels according to claim 1 is characterized in that: The content of the data request includes a request task identifier, a request timestamp, a list of tags to be counted, a user range, and data format requirements.
4. The method for encrypted joint query of multi-party risk labels according to claim 1 is characterized in that: After receiving the data request, the data party uses empty tags to fill the missing values in the data. After the statistics are completed, each party will count the number of times their own tags are touched.
5. The method for encrypted joint query of multi-party risk labels according to claim 1 is characterized in that: The method of using an encryption algorithm with additive homomorphic properties to encrypt the statistical value of the number of touches based on a session public key is: In the formula, Indicates that the specified user is in the data side The The encrypted ciphertext of the tags is represents the encryption function, Indicates that the specified user is in the data side The The plaintext of the tag, Y is the public key of a session, A random factor generated for the encryption algorithm. g is a generator of the finite discrete logarithm multiplicative group.
6. The method for encrypted joint query of multi-party risk labels according to claim 1 is characterized in that: The method of ciphertext aggregation is: In the formula, Represents the aggregate value of the ciphertext labels of all data parties, Indicates that the specified user is in the data side The The encrypted ciphertext of the tags is represents the encryption function, Indicates that the specified user is in the data side The The plaintext of the tag, Y is the public key of a session, is the sum of random factors, is the sum of the label values, N is the number of data cubes, and g is the generator of the finite discrete logarithm multiplicative group.
7. The method for encrypted joint query of multi-party risk labels according to claim 1 is characterized in that: The result party uses a one-time session private key to decrypt the aggregated data, specifically: In the formula, To decrypt the intermediate data, is the sum of random factors, is the sum of the tag values, g is the generator of the finite discrete logarithm multiplicative group, Y is the public key of a session, and y is the private key of a session.
8. The method for encrypted joint query of multi-party risk labels according to claim 1 is characterized in that: The predefined mapping table construction method is: the result side has a generator g of a finite discrete logarithm multiplication group, a large prime number p and a plaintext value range, and is calculated by modular operation ,Will As the key value of the mapping table, As the value of the mapping table to build a mapping table, where To decrypt the intermediate data, is the sum of the label values.
9. The method for encrypted joint query of multi-party risk labels according to claim 1 is characterized in that: The agency performs consistency verification on the ciphertext submitted by the data party before performing ciphertext aggregation.
10. A multi-party risk label encryption joint query system, characterized in that: The system is used to implement the method according to any one of claims 1 to 9, comprising: The result party is used to generate a data request, negotiate a session key with the agency, obtain a session public key and a session private key, and perform statistical analysis on the decrypted data; The agency is used to receive the encrypted data submitted by the data party, perform ciphertext aggregation, and return the aggregated ciphertext data to the result party, while performing ciphertext consistency verification to ensure data accuracy; The data party is used to align the tag data, count the number of tag touches, and encrypt the statistical value of the number of touches based on a session public key and send it to the agency; Encryption calculation, which is used to encrypt statistical data based on the additive homomorphic encryption algorithm, and to find the corresponding label data based on the predefined mapping table after the result is decrypted; The storage module is used to store encrypted data, intermediate calculation results and predefined mapping tables to support data processing and analysis.
Citation Information
Patent Citations
Graph query method and system based on multi-party security and related device
CN115033599A
Enterprise cloud ERP system data statistical analysis method and system based on homomorphic encryption
CN113114451A
Signature and authentication method and authentication system of RFID (Radio Frequency Identification Device) group tag
CN118870358A