Mixed data asset protection method based on attribute encryption and homomorphic encryption
By combining attribute encryption and homomorphic encryption technology in the data asset protection system, a two-layer encryption architecture is realized, which solves the shortcomings of traditional data encryption and decryption technology in permission management, computing power and operation record transparency, and realizes flexible permission management, efficient calculation of encrypted data and operation record transparency.
Patent Information
- Application Number
- CN202510050203.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-13
- Publication Date
- 2025-05-13
AI Technical Summary
When traditional data encryption and decryption technology copes with complex and changing data security needs, there are problems such as insufficient static key management, lack of encrypted data computing capabilities, and opaque permission management and operation recording, which is difficult to meet the current high requirements for data security and privacy.
A hybrid data asset protection system based on attribute encryption and homomorphic encryption is adopted to achieve security protection and efficient computing of data through a two-layer encryption architecture. Specifically, it includes data encryption module, attribute management module, security calculation module and data decryption module, which supports flexible permission management, encrypted data calculation and transparency of operation records.
It realizes flexible permission management and dynamic adjustment, supports efficient calculation of encrypted data, provides transparency and traceability of operation records, effectively solves the shortcomings of traditional encryption and decryption technology, and improves data security and privacy.
Smart Images

Figure CN119989379A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data security protection, and discloses a hybrid data asset protection system and method based on attribute encryption and homomorphic encryption. Background Art
[0002] With the in-depth development of the information age, data has become a key asset in various fields such as business operations, scientific research, and national governance. The value and importance of data have become increasingly prominent, and its security and privacy protection issues have also become the focus of attention from all walks of life. However, traditional data encryption and decryption technologies have revealed many deficiencies and defects in responding to the current complex and changing data security needs.
[0003] First, traditional encryption and decryption technologies mostly use static key mechanisms. Once generated, such keys are fixed and often need to be shared by multiple users or systems during use. This static and shared key management method is easy to be leaked or misused. Once the key is illegally obtained, the security of encrypted data will be seriously threatened. At the same time, static keys are difficult to meet the complex and ever-changing permission management requirements. In scenarios where data access rights need to be frequently adjusted or fine-grained, the limitations of static keys are particularly obvious, posing a great threat to data security.
[0004] Secondly, traditional encryption and decryption technologies lack the ability to directly compute encrypted data. When it is necessary to process, analyze or mine encrypted data, it must first be decrypted into plaintext before the corresponding computing operations can be performed. This "decrypt first, then compute" model not only increases the risk of data leakage, because the decrypted plaintext data may be intercepted or abused during transmission and processing; it also reduces the efficiency and flexibility of data processing, because the decryption and encryption process itself consumes a certain amount of computing resources and time.
[0005] Finally, in the scenario of multi-party collaboration, the permission management and operation records of traditional encryption and decryption technologies are often opaque. In the process of data sharing, exchange or processing, it is difficult to effectively track and audit information such as data users, operation processes, and permission changes. This opacity not only poses a great challenge to data security management, but may also lead to problems such as data leakage, abuse or infringement. At the same time, the lack of effective operation records and audit mechanisms also makes it difficult to trace responsibility and locate the source of data security problems when they occur.
[0006] In summary, the existing traditional data encryption and decryption technology has many defects and deficiencies, and it is difficult to meet the current high requirements for data security and privacy. Therefore, it is particularly important and urgent to develop a more flexible, efficient and secure data encryption and decryption technology. Summary of the invention
[0007] In view of the shortcomings of the prior art, the present invention proposes a hybrid data asset protection method based on attribute encryption and homomorphic encryption, which realizes data security protection and efficient computing through a double-layer encryption architecture.
[0008] The present invention includes the following technical solutions:
[0009] A hybrid data asset protection system based on attribute encryption and homomorphic encryption, including the following modules:
[0010] Data encryption module: used to perform two-layer encryption on data assets, including access control encryption based on attribute encryption and secure computing encryption based on homomorphic encryption;
[0011] Attribute management module: used to define user attribute sets and dynamically adjust access rights based on user attributes;
[0012] Secure computing module: used to directly perform computing operations when data is in a homomorphic encryption state;
[0013] Data decryption module: used to complete double-layer decryption by reconstructing the key to obtain plaintext data after the user meets the access rights.
[0014] Furthermore, in the above-mentioned hybrid data asset protection system based on attribute encryption and homomorphic encryption, the data encryption module selects different attribute encryption strategies for data of different sensitivities through predefined encryption strategies.
[0015] Furthermore, in the above-mentioned hybrid data asset protection system based on attribute encryption and homomorphic encryption, the attribute management module can dynamically update the user's attribute set and adjust access rights in real time.
[0016] Furthermore, in the above-mentioned hybrid data asset protection system based on attribute encryption and homomorphic encryption, the security computing module supports basic operations such as addition and multiplication as well as complex statistical analysis.
[0017] Furthermore, in the above-mentioned hybrid data asset protection system based on attribute encryption and homomorphic encryption, the data decryption module embeds a dynamic watermark during the decryption process to record data user information.
[0018] The present invention discloses a hybrid data asset protection method based on attribute encryption and homomorphic encryption, which is used in the above-mentioned hybrid data asset protection system based on attribute encryption and homomorphic encryption. The method comprises the following steps:
[0019] a. Data encryption steps: Perform two-layer encryption on data assets. The first layer uses attribute-based access control encryption, and different attribute encryption strategies are selected according to the sensitivity of the data. The second layer uses secure computing encryption based on homomorphic encryption to support direct computing on encrypted data.
[0020] b. Attribute management step: define user attribute sets and dynamically adjust their access rights to data assets based on changes in user attributes;
[0021] c. Secure computing step: When the data is in a homomorphic encrypted state, basic operations such as addition and multiplication as well as complex statistical analysis are directly performed without decrypting the data first;
[0022] d. Data decryption step: Under the condition that the user meets the access rights, the encrypted data is double-decrypted by reconstructing the key to obtain the plaintext data, and a dynamic watermark is embedded in the decryption process to record the information of the data user.
[0023] Furthermore, the above-mentioned hybrid data asset protection method based on attribute encryption and homomorphic encryption records encryption strategies, decryption operation logs and permission adjustment history through blockchain.
[0024] The present invention also discloses a storage module for a hybrid data asset protection system based on attribute encryption and homomorphic encryption, which is characterized by:
[0025] The storage module includes a high-security storage medium for storing data assets that have undergone two layers of encryption. The first layer of encryption uses attribute-based access control encryption, and different attribute encryption schemes are selected according to the sensitivity of the data and the predefined encryption strategy. The second layer of encryption uses secure computing encryption based on homomorphic encryption to support direct computing operations on encrypted data.
[0026] The storage module is also configured with a dedicated storage area for storing user attribute sets, encryption policy details, decryption operation logs, permission adjustment history, and any metadata related to data encryption and decryption;
[0027] The storage module supports efficient data retrieval and access control mechanisms to ensure that only authorized users can access stored data;
[0028] During the data decryption process, the storage module is integrated with a dynamic watermark embedding function to record the information of data users for auditing and tracking purposes.
[0029] The present invention also discloses a computing unit for a hybrid data asset protection system based on attribute encryption and homomorphic encryption.
[0030] The computing unit includes high-performance encryption and decryption circuits for performing attribute-based access control encryption and homomorphic encryption-based secure computation encryption;
[0031] The computing unit is equipped with special operation logic, which supports the direct execution of basic operations such as addition and multiplication, as well as complex statistical analysis and other computing operations when the data is in a homomorphic encryption state, without the need to decrypt the data first, thus ensuring the security and privacy of the data;
[0032] The computing unit is tightly integrated with the attribute management module, and can adjust the access rights to data assets in real time according to the changes in user attributes, ensuring the accuracy and flexibility of access control;
[0033] The computing unit also supports efficient algorithm optimization and hardware acceleration technology to improve the performance of encryption, decryption and computing operations.
[0034] The present invention also discloses a server configured with a hybrid data asset protection system based on attribute encryption and homomorphic encryption.
[0035] The server comprises a storage module as claimed in claim 8 and a computing unit as claimed in claim 9, which work together to provide comprehensive data asset protection;
[0036] The server is also equipped with a powerful attribute management module, which is used to define and manage user attribute sets and dynamically adjust access permissions based on user attributes to ensure that only qualified users can access data;
[0037] The server is further configured with a data decryption module, which is used to complete double-layer decryption by reconstructing the key to obtain plaintext data after the user meets the access rights, and embed a dynamic watermark in the decryption process to record the information of the data user and conduct auditing;
[0038] The server also supports blockchain technology to record encryption policies, decryption operation logs, permission adjustment history, and any key information related to data encryption and decryption to enhance the security, traceability, and immutability of the system.
[0039] The server is also equipped with a comprehensive security management mechanism and monitoring system to monitor the system's operating status in real time, detect potential security threats and respond promptly to ensure the security and availability of data assets.
[0040] Compared with the prior art, the present invention has the following beneficial effects:
[0041] This invention combines advanced technologies such as attribute encryption and homomorphic encryption to build a hybrid data asset protection system, which effectively solves the problems existing in traditional encryption and decryption technologies and brings the following significant beneficial effects:
[0042] 1. Flexible permission management and dynamic adjustment are realized:
[0043] The present invention adopts attribute-based access control encryption technology, defines user attribute sets, and dynamically adjusts the access rights to data assets according to the changes in user attributes. This flexible rights management mechanism not only meets the complex and changeable rights management needs, but also implements fine-grained access control to ensure the security and privacy of data. At the same time, the system supports dynamic updates of user attribute sets, so that rights management can more timely and accurately reflect the actual needs and role changes of users.
[0044] 2. Support efficient calculation of encrypted data to avoid plaintext leakage:
[0045] The present invention introduces homomorphic encryption technology, so that when the data is in an encrypted state, basic operations such as addition and multiplication, as well as complex statistical analysis and other computing operations can still be directly performed. This efficient computing capability of encrypted data not only avoids the risk of plaintext data leakage, but also improves the efficiency and flexibility of data processing. Users can perform calculations without decrypting encrypted data into plaintext, thereby effectively protecting the privacy and security of data.
[0046] 3. Provide transparency and traceability of operation records:
[0047] The present invention records encryption strategies, decryption operation logs, permission adjustment history, and any key information related to data encryption and decryption by integrating blockchain technology. These records are tamper-proof and traceable, so that information such as data users, operation processes, and permission changes can be effectively tracked and audited. This transparency and traceability not only enhances the security of the system, but also facilitates tracing responsibilities and locating the source of problems when data security issues occur, providing a strong guarantee for data security management.
[0048] In summary, the present invention effectively solves the problems existing in traditional encryption and decryption technologies by realizing flexible permission management, supporting efficient calculation of encrypted data, and providing transparency and traceability of operation records, and provides a more comprehensive, flexible and secure solution for the protection of data assets. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] Figure 1 Schematic diagram of the structure of a hybrid data asset protection system based on attribute encryption and homomorphic encryption;
[0050] Figure 2 Schematic diagram of the steps of a hybrid data asset protection method based on attribute encryption and homomorphic encryption;
[0051] Figure 3 Schematic diagram of the server structure configured with a hybrid data asset protection system based on attribute encryption and homomorphic encryption. DETAILED DESCRIPTION
[0052] The technical solutions in the embodiments of the present invention are described clearly and completely below. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0053] Embodiment 1:
[0054] A hybrid data asset protection system based on attribute encryption and homomorphic encryption
[0055] This embodiment proposes a hybrid data asset protection system based on attribute encryption and homomorphic encryption. The system uses a two-layer encryption mechanism to achieve flexible access control and support efficient calculation of encrypted data, while ensuring the transparency and traceability of operation records.
[0056] Detailed description of embodiments
[0057] 1. System architecture
[0058] like Figure 1 As shown, the system of the present invention includes a data encryption module, an attribute management module, a security calculation module and a data decryption module.
[0059] 2. Data encryption module
[0060] (1) Encryption policy definition:
[0061] For highly sensitive data, attribute-based access control encryption (ABE) is used. The attribute set A is defined as {attribute 1, attribute 2, ..., attribute n}. The access control policy P is a Boolean expression defined based on the attribute set A and is used to determine which users can decrypt the data.
[0062] For data that requires computing operations, a layer of homomorphic encryption (HE) is superimposed on the basis of ABE encryption to support computing in an encrypted state.
[0063] (2) Encryption algorithm:
[0064] ABE encryption:
[0065] Select a bilinear pair e:G0×G1→G T , where G0, G1, G T is a group of order large prime number p.
[0066] Select generator g∈G0 and random elements h1,h2,...,h n∈G1, corresponding to each attribute in the attribute set A.
[0067] For data D, choose a random key s∈Z p , and calculate the ciphertext components:
[0068] C0=e(g,g) s
[0069] For each attribute i, if the attribute appears in the access control policy P, then calculate C i =h i s ;
[0070] The access control policy P is encoded as an access tree T, where each non-leaf node is a threshold (such as an AND gate or an OR gate) and each leaf node corresponds to an attribute.
[0071] The final ciphertext is C ABE =(C0,{C i}i∈A T ), where A T is the set of attributes that appear in the access tree T.
[0072] HE Encryption:
[0073] Use a homomorphic encryption scheme (such as Paillier or Gentry's FHE scheme) to encrypt the ABE-encrypted ciphertext CABE again.
[0074] Assume that the Paillier scheme is used, select two large prime numbers p and q, satisfying q|(p-1), and calculate n=pq.
[0075] Pick a random integer Make g n modn 2 =1+n (g is an n-order element of n^2).
[0076] The public key is (n,g) and the private key is λ=\lcm(p-1,q-1) (i.e. the least common multiple of p-1 and q-1).
[0077] C ABE Encrypt and get C = Enc HE (C ABE ,(n,g)).
[0078] 3. Attribute management module
[0079] (1) User attribute set definition:
[0080] The attribute set of user U is defined as attr ={attribute a1, attribute a2, ..., attribute am}, where m≤n.
[0081] (2) Dynamic adjustment of access rights:
[0082] When the attribute set U of user U attr When the access control policy P is satisfied (i.e., it can match the access tree T), the user obtains access rights.
[0083] The attribute management module supports dynamic updating of user attribute sets and real-time adjustment of access rights.
[0084] 4. Secure computing module
[0085] (1) Computational operation support:
[0086] The secure computing module supports direct execution of basic operations such as addition and multiplication as well as complex statistical analysis when the data is in a homomorphic encryption state.
[0087] (2) Calculation algorithm:
[0088] Addition operation:
[0089] Given two homomorphically encrypted ciphertexts C1=Enc HE (D1,(n,g)) and C2=Enc HE (D2,(n,g)), where D1 and D2 are plain text.
[0090] The ciphertext result of the addition operation is C add =C1·C 2mod n 2 =Enc HE (D1+D2,(n,g)).
[0091] Multiplication operation:
[0092] The multiplication operation is relatively complex because the homomorphic property needs to be preserved. In the Paillier scheme, the multiplication operation involves an additional exponential operation.
[0093] C mul =Enc HE (D1·D2,(n,g))=(C1 α ·gD 1 · β modn 2 ), where α and β are intermediate values obtained through the decryption process and are related to D1 and the private key λ.
[0094] In practical applications, multiplication operations are usually implemented efficiently through pre-computation or optimized algorithms.
[0095] Complex statistical analysis:
[0096] By combining basic operations (addition and multiplication), complex statistical analysis operations such as mean, variance, etc. can be achieved.
[0097] 5. Data decryption module
[0098] (1) Decryption process:
[0099] When the user U meets the access rights, the attribute management module generates a decryption key Kdec, which is related to the user's attribute set Uattr and the access control policy P, and uses Kdec to decrypt the ciphertext CABE of the ABE encryption layer. This usually involves traversing the access tree T and matching attributes.
[0100] If CABE is decrypted directly, an intermediate result D′ is obtained (which may be a partial decryption result or some representation of the original data).
[0101] Then, the homomorphically encrypted private key λ is used to decrypt D′ (or directly C if D′ is structurally identical to C) to obtain the final plaintext D.
[0102] (2) Dynamic watermark embedding:
[0103] During the decryption process, the data decryption module embeds a dynamic watermark W to record the data user information. The watermark W can be bound to the user U's identity information, access time, etc.
[0104] The decrypted plaintext D is attached with a watermark W, forming the final output D w .
[0105] 6. Specific implementation steps
[0106] (1) Data encryption:
[0107] Select highly sensitive data D = "sensitive information", define attribute set A = {department, position, level}, formulate access control policy P: only users whose department is "R&D department", whose position is "engineer" and whose level is "senior" can access D, use ABE algorithm to encrypt D, and get C ABE The specific process includes selecting a random key s, calculating C0 and C i , and construct the access tree T, and then use the HE algorithm to ABE Encrypt and obtain the final ciphertext C.
[0108] (2) Attribute management:
[0109] User U1's attribute set U 1attr = {Department: R&D, Position: Engineer, Level: Intermediate}. Since U1's level does not meet P, U1 cannot access D. User U2's attribute set U 2attr={Department: R&D, Position: Engineer, Level: Senior}, U2 satisfies P and therefore obtains access rights.
[0110] (3) Secure computing:
[0111] Assume there is another encrypted data D′ = “other sensitive information”, whose ciphertext is C′. Perform an addition operation on C and C′ to get C add =C·C′modn 2 =Add HE (C,C′), C add Still encrypted, but can be stored or transmitted without being decrypted.
[0112] (4) Data decryption:
[0113] U2 requests decryption of C (or C add , if the calculation result needs to be decrypted).
[0114] The attribute management module generates the decryption key K decU2 , which typically involves traversing and matching attributes of the tree T. Using K decU2 For C (or C add ) is decrypted by the ABE encryption layer to obtain the intermediate result D′ (or D add ′). Use the private key λ to add ′) to decrypt and obtain the plaintext D (or D add ), embed the watermark (W_{.
[0115] Example 2
[0116] Based on the system of Example 1, this embodiment discloses an embodiment of a hybrid data asset protection method based on attribute encryption and homomorphic encryption.
[0117] Background setting:
[0118] Suppose we have a financial institution that needs to provide highly secure protection for its customers' data assets (such as transaction records, credit scores, etc.). In order to ensure the confidentiality, integrity, and availability of the data while supporting necessary calculations and analysis on encrypted data, the institution decided to adopt a hybrid data asset protection method based on attribute encryption and homomorphic encryption.
[0119] Implementation steps: Figure 2 As shown:
[0120] 1) Data encryption steps:
[0121] 11) The first layer of encryption (attribute-based access control encryption):
[0122] First, define different attribute encryption strategies for different data assets based on the sensitivity of the data. For example, for highly sensitive customer identity information, the combined attributes of "department + position + years of work experience" may be used as the encryption strategy, and only users who meet these attributes can decrypt.
[0123] The attribute-based encryption (ABE) algorithm is used to perform the first layer of encryption on data assets. During the encryption process, the data access policy is embedded into the ciphertext to ensure that only users who meet the policy can decrypt it.
[0124] 12) Second layer of encryption (secure computing encryption based on homomorphic encryption):
[0125] Based on the first layer of encryption, a second layer of encryption is performed on data assets using a homomorphic encryption algorithm (such as fully homomorphic encryption or partially homomorphic encryption).
[0126] Homomorphic encryption allows basic operations such as addition and multiplication to be performed directly on encrypted data without first decrypting the data. This is very important for financial institutions because they need to perform statistical analysis and risk assessment on transaction data while protecting customer privacy.
[0127] 2) Attribute management steps:
[0128] Define user attribute sets, including department, position, years of experience, security level, etc.
[0129] Dynamically adjust access rights to data assets based on changes in user attributes. For example, when an employee is transferred from the finance department to the risk management department, their access rights will be adjusted accordingly to ensure that they can only access data assets related to the new department.
[0130] 3) Safety calculation steps:
[0131] When the data is in a homomorphic encryption state, basic operations such as addition and multiplication can be performed directly. For example, the encrypted transaction amount can be aggregated or the encrypted credit score can be averaged.
[0132] Supports computational operations such as complex statistical analysis. For example, you can use homomorphic encryption algorithms to perform regression analysis or cluster analysis on encrypted transaction data to discover potential financial risks or market trends.
[0133] 4) Data decryption steps:
[0134] When a user needs to access encrypted data, first verify whether they meet the access permission requirements. If the user meets the attribute requirements in the access policy, then the decryption operation is allowed.
[0135] The encrypted data is decrypted in two layers by reconstructing the key. First, the decryption key of homomorphic encryption is used to decrypt the second layer of encryption, and then the decryption key of attribute-based encryption is used to decrypt the first layer of encryption, and finally the plaintext data is obtained.
[0136] Dynamic watermarks are embedded in the decryption process to record the information of data users (such as user ID, decryption time, etc.), which helps to track data access and usage and prevent data leakage or abuse.
[0137] Implementation effect:
[0138] By adopting this hybrid data asset protection method based on attribute encryption and homomorphic encryption, financial institutions can effectively protect the confidentiality and integrity of customer data while supporting necessary calculations and analysis on encrypted data. This method not only improves data security, but also enhances data availability and flexibility, providing strong support for financial institutions' business operations and risk management.
[0139] Example 3
[0140] A specific embodiment of a server configured with a hybrid data asset protection system based on attribute encryption and homomorphic encryption.
[0141] As the value of data assets becomes increasingly prominent, a large enterprise decided to deploy an advanced hybrid data asset protection system to ensure the security and privacy of its sensitive data. The system combines attribute-based access control encryption and homomorphic encryption-based secure computing encryption technology to provide a comprehensive data protection solution. The following is a specific server implementation of the system.
[0142] Server configuration, such as Figure 3 As shown:
[0143] S1 storage module:
[0144] S11 high-security storage media: The server is equipped with a high-performance SSD (solid-state drive) as a storage medium, using hardware-level encryption technology to ensure that the stored data assets are protected at the physical level. All data is processed through two layers of encryption: the first layer is attribute-based access control encryption, which selects the appropriate attribute encryption scheme based on the sensitivity of the data and the predefined encryption strategy; the second layer is secure computing encryption based on homomorphic encryption, which supports direct computing on encrypted data.
[0145] S12 Dedicated Storage Area: A dedicated storage area is set up in the server to store user attribute sets, encryption policy details, decryption operation logs, permission adjustment history, and any metadata related to data encryption and decryption. This data is stored in encrypted form to ensure that only authorized personnel can access it.
[0146] S13 Efficient data retrieval and access control mechanism: The storage module integrates an efficient data retrieval engine and access control mechanism to ensure that only authorized users can retrieve and access stored data according to predefined access policies.
[0147] S14 dynamic watermark embedding function: During the data decryption process, the storage module is integrated with a dynamic watermark embedding function to record the data user's information, such as user ID, decryption time, etc., for auditing and tracking.
[0148] S2 Compute Unit:
[0149] S21 high-performance encryption and decryption circuits: The server is equipped with dedicated encryption and decryption circuits that use hardware acceleration technology to improve the performance of encryption, decryption, and computing operations. These circuits support attribute-based access control encryption and secure computing encryption based on homomorphic encryption.
[0150] S22 Specialized Operation Logic: The computing unit is equipped with specialized operation logic, which supports the direct execution of basic operations such as addition and multiplication, as well as complex statistical analysis and other computing operations when the data is in a homomorphic encryption state, without the need to decrypt the data first, thus ensuring the security and privacy of the data.
[0151] S23 is tightly integrated with the attribute management module: The computing unit is tightly integrated with the attribute management module, and can adjust the access rights to data assets in real time according to the changes in user attributes, ensuring the accuracy and flexibility of access control.
[0152] S3 attribute management module:
[0153] S31 Define and manage user attribute sets: The server is equipped with a powerful attribute management module for defining and managing user attribute sets, including department, position, security level, etc.
[0154] S32 Dynamically adjust access rights: The attribute management module dynamically adjusts access rights based on user attributes to ensure that only qualified users can access data. When user attributes change, such as job promotion or department transfer, the attribute management module automatically updates their access rights.
[0155] S4 data decryption module:
[0156] S41 double-layer decryption: The server is equipped with a data decryption module, which is used to complete double-layer decryption by reconstructing the key to obtain plaintext data after the user meets the access rights. The decryption process uses hardware acceleration technology to improve decryption efficiency.
[0157] S42 Dynamic watermark embedding: During the decryption process, the data decryption module will embed a dynamic watermark to record the information of the data user for auditing and tracking purposes.
[0158] S5 Blockchain Technology:
[0159] S51 records key information: The server supports blockchain technology to record encryption strategies, decryption operation logs, permission adjustment history, and any key information related to data encryption and decryption. This information is stored in the form of blockchain to ensure data integrity, traceability, and immutability.
[0160] S6 safety management mechanism and monitoring system:
[0161] S61 Real-time monitoring: The server is equipped with a complete security management mechanism and monitoring system to monitor the system's operating status in real time, detect potential security threats and respond promptly.
[0162] S62 Security Threat Response: When the monitoring system detects potential security threats, such as unauthorized access attempts or signs of data leakage, a security alert will be triggered immediately and corresponding security measures will be taken, such as isolating the infected system part, notifying the security team, etc.
[0163] Implementation effect:
[0164] By deploying this server equipped with a hybrid data asset protection system based on attribute encryption and homomorphic encryption, the enterprise can effectively protect the security and privacy of its sensitive data assets. The system provides a comprehensive data protection solution, including efficient data retrieval and access control mechanisms, dynamic watermark embedding functions, blockchain technology to record key information, and a complete security management mechanism and monitoring system. These functions jointly ensure the security and availability of data assets, providing strong support for the business development of the enterprise.
[0165] The advantages and improvements of the above embodiments are summarized as follows:
[0166] 1Enhanced Data Security:
[0167] By combining attribute-based access control encryption (ABE) and homomorphic encryption (HE), multi-layer protection of data is achieved. ABE ensures that only users who meet specific attributes can access the data, while HE allows computation on encrypted data without decryption, thus maintaining the confidentiality of the data.
[0168] The dynamic watermark embedding function records the information of data users during the decryption process, which helps to track the access and use of data and further prevent data leakage or abuse.
[0169] 2Flexible access control:
[0170] The attribute management module supports the definition and management of user attribute sets, and dynamically adjusts access rights according to changes in user attributes. This ensures the accuracy and flexibility of access control and adapts to the needs of corporate organizational structure and personnel changes.
[0171] 3. Efficient data calculation and analysis:
[0172] The secure computing module supports performing basic operations and complex statistical analysis directly on encrypted data without decrypting the data first. This greatly improves the efficiency of data processing while maintaining the confidentiality of the data.
[0173] Specialized encryption and decryption circuits and hardware acceleration technology improve the performance of encryption, decryption and computing operations to meet the needs of large-scale data processing.
[0174] 4 Comprehensive data protection solutions:
[0175] The server configuration includes high-security storage media, dedicated storage areas, efficient data retrieval and access control mechanisms, etc., providing a comprehensive data protection solution.
[0176] Blockchain technology is used to record key information, ensuring the integrity, traceability and non-tamperability of data.
[0177] 5. Perfect safety management mechanism and monitoring system:
[0178] The server is equipped with a complete security management mechanism and monitoring system, which can monitor the system's operating status in real time, detect potential security threats and respond promptly.
[0179] When a security threat is detected, the system can immediately trigger a security alert and take corresponding security measures to ensure the security of data assets.
[0180] In summary, the above embodiments provide a comprehensive, flexible and efficient data asset protection solution by combining a variety of advanced encryption technologies and security management mechanisms. These solutions not only improve the security of data, but also enhance the availability and flexibility of data, providing strong support for the business development of enterprises.
[0181] The above are limited to several preferred embodiments of the present invention, and the description is relatively specific and detailed, but it cannot be understood as limiting the scope of the present invention. It should be pointed out that for ordinary technicians in this field, several modifications and improvements can be made without departing from the concept of the present invention, which all belong to the protection scope of the present invention.
Claims
1. A hybrid data asset protection system based on attribute encryption and homomorphic encryption, characterized in that: Includes the following modules: Data encryption module: used to perform two-layer encryption on data assets, including access control encryption based on attribute encryption and secure computing encryption based on homomorphic encryption; Attribute management module: used to define user attribute sets and dynamically adjust access rights based on user attributes; Secure computing module: used to directly perform computing operations when data is in a homomorphic encryption state; Data decryption module: used to complete double-layer decryption by reconstructing the key to obtain plaintext data after the user meets the access rights.
2. A hybrid data asset protection system based on attribute encryption and homomorphic encryption according to claim 1, characterized in that: The data encryption module selects different attribute encryption strategies for data of different sensitivities through predefined encryption strategies.
3. A hybrid data asset protection system based on attribute encryption and homomorphic encryption according to claim 1, characterized in that: The attribute management module can dynamically update the user's attribute set and adjust access rights in real time.
4. A hybrid data asset protection system based on attribute encryption and homomorphic encryption according to claim 1, characterized in that: The secure computing module supports basic operations such as addition and multiplication as well as complex statistical analysis.
5. A hybrid data asset protection system based on attribute encryption and homomorphic encryption according to claim 1, characterized in that: The data decryption module embeds a dynamic watermark during the decryption process to record data user information.
6. A hybrid data asset protection method based on attribute encryption and homomorphic encryption, applied to a hybrid data asset protection system based on attribute encryption and homomorphic encryption as described in any one of claims 1 to 5, characterized in that: The method comprises the following steps: a. Data encryption steps: Perform two-layer encryption on data assets. The first layer uses attribute-based access control encryption, and different attribute encryption strategies are selected according to the sensitivity of the data. The second layer uses secure computing encryption based on homomorphic encryption to support direct computing on encrypted data. b. Attribute management step: define user attribute sets and dynamically adjust their access rights to data assets based on changes in user attributes; c. Secure computing step: When the data is in a homomorphic encrypted state, basic operations such as addition and multiplication as well as complex statistical analysis are directly performed without decrypting the data first; d. Data decryption step: Under the condition that the user meets the access rights, the encrypted data is double-decrypted by reconstructing the key to obtain the plaintext data, and a dynamic watermark is embedded in the decryption process to record the information of the data user.
7. A hybrid data asset protection method based on attribute encryption and homomorphic encryption according to claim 6, characterized in that: The method records encryption strategies, decryption operation logs and permission adjustment history through blockchain.
8. A storage module for a hybrid data asset protection system based on attribute encryption and homomorphic encryption, characterized in that: The storage module includes a high-security storage medium for storing data assets that have been processed with two layers of encryption, wherein the first layer of encryption uses attribute-based access control encryption, and selects different attribute encryption schemes according to the sensitivity of the data and the predefined encryption strategy; The second layer of encryption uses secure computing encryption based on homomorphic encryption to support direct computing operations on encrypted data; The storage module is also configured with a dedicated storage area for storing user attribute sets, encryption policy details, decryption operation logs, permission adjustment history, and any metadata related to data encryption and decryption; The storage module supports efficient data retrieval and access control mechanisms to ensure that only authorized users can access stored data; During the data decryption process, the storage module is integrated with a dynamic watermark embedding function to record the information of data users for auditing and tracking purposes.
9. A computing unit for a hybrid data asset protection system based on attribute encryption and homomorphic encryption, characterized in that: The computing unit includes high-performance encryption and decryption circuits for performing attribute-based access control encryption and homomorphic encryption-based secure computation encryption; The computing unit is equipped with special operation logic, which supports the direct execution of basic operations such as addition and multiplication, as well as complex statistical analysis and other computing operations when the data is in a homomorphic encryption state, without the need to decrypt the data first, thus ensuring the security and privacy of the data; The computing unit is tightly integrated with the attribute management module, and can adjust the access rights to data assets in real time according to the changes in user attributes, ensuring the accuracy and flexibility of access control; The computing unit also supports efficient algorithm optimization and hardware acceleration technology to improve the performance of encryption, decryption and computing operations.
10. A server configured with a hybrid data asset protection system based on attribute encryption and homomorphic encryption, characterized in that: The server comprises a storage module as claimed in claim 8 and a computing unit as claimed in claim 9, which work together to provide comprehensive data asset protection; The server is also equipped with a powerful attribute management module, which is used to define and manage user attribute sets and dynamically adjust access permissions based on user attributes to ensure that only qualified users can access data; The server is further configured with a data decryption module, which is used to complete double-layer decryption by reconstructing the key to obtain plaintext data after the user meets the access rights, and embed a dynamic watermark in the decryption process to record the information of the data user and conduct auditing; The server also supports blockchain technology to record encryption policies, decryption operation logs, permission adjustment history, and any key information related to data encryption and decryption to enhance the security, traceability, and immutability of the system. The server is also equipped with a comprehensive security management mechanism and monitoring system to monitor the system's operating status in real time, detect potential security threats and respond promptly to ensure the security and availability of data assets.