Data security transmission system based on homomorphic encryption algorithm
Through homomorphic encryption technology, data is kept encrypted in the entire process of transmission, storage and calculation, solving the problem of privacy leakage and data owner loss of control during data encryption transmission, and realizing multi-dimensional protection of data security.
Patent Information
- Application Number
- CN202510501220.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-21
- Publication Date
- 2025-05-23
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the prior art, during the data encryption transmission process, users can obtain original plain text data, resulting in privacy leakage and data owner loss of control, and cannot protect the rights and interests of data owners.
Homomorphic encryption technology is used to encrypt the original data into the initial ciphertext and perform calculations in the ciphertext state to ensure that the data is always in the encryption protection state during the entire process of transmission, storage and calculation. By monitoring the data transmission and reception and encryption processes in real time, potential risk behaviors are identified, and reliable encryption feature verification is carried out, the compliance of key validity period and encryption strength is dynamically evaluated, and the risk of encryption failure is warned in advance.
It effectively avoids the risk of data leakage and theft during transmission, ensures the privacy and rights of data owners, and improves the multi-dimensional protection of data security.
Smart Images

Figure CN120034315A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data encryption transmission, and in particular to a data security transmission system based on a homomorphic encryption algorithm. Background Art
[0002] In the era of digital economy, data has become a core driving force and is widely used in various fields. However, its sharing and circulation face challenges of privacy leakage and ownership. How to achieve efficient use and value mining of data on the basis of ensuring data security, respecting privacy and protecting the rights and interests of data owners has become a key problem in promoting the sustainable and healthy development of the digital economy. Advanced technologies such as homomorphic encryption are urgently needed to provide solutions.
[0003] At present, there are many problems in the encryption transmission process of data. For example, data users can obtain the original plaintext data, which may leak privacy. Regardless of authorized plaintext sharing or encrypted sharing, data users use the original plaintext data for calculation, which causes privacy leakage and loss of control of the data owner. After obtaining the original data, data users may copy or spread it again, causing the data owner to lose control of the data and fail to protect the rights and interests of the data owner.
[0004] In view of the above situation, the encryption scheme based on the SM2 cryptographic algorithm and the more secure data transmission verification method become effective solutions, so that the ciphertext data can be directly calculated without the user accessing the original plaintext data, and decrypted after the calculation is completed, and the same result as the calculation directly using the plaintext data can be obtained. In addition, more scientific and effective data transmission and user behavior risk control management can be combined to avoid brute force cracking of the original data, thereby improving data security in multiple dimensions;
[0005] In view of the above technical problems, this application proposes a solution. Summary of the invention
[0006] In the present invention, the encryption conversion of original data to initial ciphertext is realized through homomorphic encryption technology, and direct calculation in the ciphertext state is supported, ensuring that the data is always in an encrypted protection state in the entire process of transmission, storage and calculation. Through real-time monitoring of data receiving and sending process and encryption process data, potential risk behaviors such as abnormal key distribution and abnormal distribution frequency of ciphertext calculation results are accurately identified. At the same time, encryption reliability feature verification is performed, and the compliance of key validity period decay and encryption strength changes over time is dynamically evaluated. The risk of encryption failure is warned in advance, and the problem that the original data is easily leaked, stolen and decrypted when used in complex usage scenarios and during transmission, which leads to the leakage of original data and the inability to protect the rights and interests of data owners is solved. A data security transmission system based on homomorphic encryption algorithm is proposed.
[0007] The object of the present invention can be achieved by the following technical solutions:
[0008] A data security transmission system based on a homomorphic encryption algorithm, comprising an encryption control module, a risk verification module, a data transceiver module, and a homomorphic encryption generation module. The homomorphic encryption generation module can process the distribution application of the user's public and private key pairs, and distribute the private key. The homomorphic encryption generation module encrypts the original data according to the public key to obtain an initial ciphertext, and uploads the initial ciphertext to the network platform. Then, it calculates the initial ciphertext according to the user's usage request to obtain a ciphertext calculation result, and finally distributes the ciphertext calculation result to the user. The user decrypts it with the private key to obtain the data result after operation.
[0009] The data transceiver module is used to count the public and private key distribution process, the user's usage request, and the ciphertext calculation result distribution process to obtain a data transceiver process, and send the data transceiver process to the risk verification module.
[0010] The encryption control module controls the user's public key, private key, and the original data encryption process to obtain encryption process data, and sends the encryption process data to the risk verification module.
[0011] The risk verification module performs risk control on the data transceiver process and the encryption process data, verifies abnormal behaviors in the data transceiver process, generates a risk control warning. The risk verification module can also verify the reliability of the encryption process data, generate an encryption reliability feature based on time, and make a judgment according to the encryption reliability feature to obtain an encryption failure risk.
[0012] It further includes a cloud warning module, which can respond to the risk control warning and the encryption failure risk to generate a warning reminder.
[0013] As a preferred embodiment of the present invention, the homomorphic encryption generation module includes a key application distribution unit, an original encryption unit, and a user calculation and usage unit. The key application distribution unit is used to generate a public key and a private key, and send the private key to the user.
[0014] The original encryption unit is used to perform homomorphic encryption on the original data.
[0015] The user calculation and usage unit is used to receive the user's data usage request, directly calculate the initial ciphertext according to the user's data usage request, and send the data result after calculation through the data transceiver module.
[0016] As a preferred implementation of the present invention, when the data transceiver module performs statistics on the private key distribution process and the ciphertext calculation result distribution process, it obtains network parameters of the private key distribution path and the ciphertext calculation result distribution path, and monitors the real-time fluctuation of the network parameters, and uses the real-time fluctuation of the network as an abnormal point;
[0017] When the data transceiver module performs statistics on the user usage requests, the density of the user usage requests is calculated and used as the statistical result.
[0018] As a preferred implementation of the present invention, the method for the data transceiver module to obtain the user usage request density is:
[0019] Taking the time when the user's request is received as the starting point, a set time length is selected, and the number of all user requests within the set time length is counted, and the ratio of the number of user requests and the time length is calculated as the density sample value;
[0020] The data transceiver module obtains multiple density sample values by selecting different starting points and changing multiple groups of time lengths, and selects the highest group of density sample values as the user usage request density.
[0021] As a preferred embodiment of the present invention, the encryption management and control module records the time point when the user's public key, private key and original data are encrypted as the start time, and calculates the time elapsed from the start time to the current time in real time to obtain the applied time, and records the ratio of the applied time to the number of encryption layers and the character length of the public-private key pair as encryption process data.
[0022] As a preferred implementation of the present invention, the method for the risk verification module to generate a risk management warning is:
[0023] The risk verification module counts the number of abnormal points and compares the abnormal points with a set threshold. If the abnormal points are greater than the set threshold, it is determined that there is a risk in the transmission process. The risk verification module calculates the proportion of the transmission process with risks in the total transmission process. If the proportion is greater than the set standard, a transmission risk alarm is generated;
[0024] The risk verification module compares the user's usage request density with the set density, and generates a high-frequency request alarm according to the comparison result;
[0025] The risk verification module uses transmission risk warnings and high-frequency request warnings as risk management warnings.
[0026] As a preferred embodiment of the present invention, the method for the risk verification module to generate an encrypted reliable feature is:
[0027] The risk verification module performs multi-level threshold judgment based on the encryption process data, and generates an encryption reliability feature based on the level threshold of the encryption process data. The larger the encryption process data, the smaller the encryption reliability feature.
[0028] As a preferred implementation of the present invention, the encryption method performed by the original encryption unit is:
[0029] Step 1: User A generates a random number r and calculates C1=[r]G to obtain a point C1 on the elliptic curve, where G is the base point in the SM2 cryptographic algorithm and [] is the elliptic curve multiplication operation;
[0030] Step 2: Calculate C2=[r]PK+[m]G to get another point C2 on the elliptic curve, where PK is the public key of user A and m is the data to be encrypted;
[0031] Step 3: Get the encrypted ciphertext (C1, C2).
[0032] As a preferred embodiment of the present invention, the method for the user computing unit to perform ciphertext calculation and decryption is:
[0033] S1: Add or subtract the two ciphertext data C1 and C2 respectively to obtain the ciphertext after addition or subtraction;
[0034] S2: Multiply the two ciphertext data C1 and C2 by the plaintext n respectively to obtain the ciphertext after scalar multiplication;
[0035] S3: Calculate the point P=[m]G=C2-[SK]C1 on the elliptic curve, where SK is the user's private key and m is the plaintext result after calculation.
[0036] Compared with the prior art, the present invention has the following beneficial effects:
[0037] 1. The present invention uses homomorphic encryption technology to realize the encryption conversion of original data to initial ciphertext, and supports direct calculation in the ciphertext state, ensuring that the data is always in an encrypted protection state in the entire process of transmission, storage and calculation. Compared with the traditional method of decryption followed by calculation and processing, it effectively avoids the risk of data exposure in the intermediate links, especially during the transmission process of the network platform. Even if the ciphertext is intercepted, the original data cannot be obtained by reverse decryption. Combined with the dynamic distribution mechanism of public and private keys and private key control, the access permission management of user-side data is further strengthened to avoid the possibility of obtaining original data by means of private keys or data hijacking during data use.
[0038] 2. In the present invention, through real-time monitoring of the data receiving and sending process and the encryption process data, it is possible to accurately identify potential risk behaviors such as abnormal key distribution and abnormal distribution frequency of ciphertext calculation results, avoid obtaining original data by obtaining a large amount of initial ciphertext, reverse decrypting the ciphertext after calculation, etc., and verify the encryption reliability characteristics based on time, dynamically evaluate the compliance of the key validity period decay and the encryption strength change over time, and give early warning of the risk of encryption failure. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] In order to facilitate understanding by those skilled in the art, the present invention is further described below with reference to the accompanying drawings.
[0040] Figure 1 is a system block diagram of the present invention;
[0041] Figure 2 It is a system flow chart of the present invention. DETAILED DESCRIPTION
[0042] The technical solution of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0043] Embodiment 1:
[0044] See also Figure 1 - Figure 2 As shown, a data security transmission system based on a homomorphic encryption algorithm includes a homomorphic encryption generation module, which includes a key application distribution unit, an original encryption unit and a user calculation and use unit. The homomorphic encryption generation module can process the distribution application of the user's public and private key pairs and distribute the private key. The homomorphic encryption generation module encrypts the original data according to the public key to obtain the initial ciphertext, and uploads the initial ciphertext to the network platform. Then, the initial ciphertext is calculated according to the user's use request to obtain the ciphertext calculation result, and finally the ciphertext calculation result is distributed to the user, and the user decrypts it through the private key to obtain the data result after the operation;
[0045] The key application distribution unit is used to generate public keys and private keys, and send the private key to the user;
[0046] The original encryption unit is used to homomorphically encrypt the original data;
[0047] The encryption method of the original encryption unit is:
[0048] Step 1: User A generates a random number r and calculates C1=[r]G to obtain a point C1 on the elliptic curve, where G is the base point in the SM2 cryptographic algorithm and [] is the elliptic curve multiplication operation;
[0049] Step 2: Calculate C2=[r]PK+[m]G to get another point C2 on the elliptic curve, where PK is the public key of user A and m is the data to be encrypted;
[0050] Step 3: Get the encrypted ciphertext (C1, C2);
[0051] The user calculation and use unit is used to receive the user's data use request, directly calculate the initial ciphertext according to the user's data use request, and pass the calculated data result through the data transceiver module;
[0052] The method for the user computing unit to perform ciphertext calculation and decryption is as follows:
[0053] S1: Add or subtract the two ciphertext data C1 and C2 respectively to obtain the ciphertext after addition or subtraction: new_cipher=(cipher1.C1±cipher2.C1, cipher1.C2±cipher2.C2);
[0054] S2: Multiply the two ciphertext data C1 and C2 by the plaintext n respectively to get the ciphertext after scalar multiplication:
[0055] new_cipher=([n]cipher1.C1,[n]cipher1.C2);
[0056] S3: Calculate the point P=[m]G=C2-[SK]C1 on the elliptic curve, where SK is the user's private key and m is the plaintext result after calculation;
[0057] At the same time, since there is no mathematical method to calculate m from P, the exhaustive method is used to calculate, and the big step-small step algorithm combined with the cache technology is used to improve the calculation speed. Assume that the value range of m is [-(2 31 -1), 2 31 -1], the cache size is 2 16 , then the maximum time complexity of the algorithm is 2 15 If the cache size is increased, the time complexity can be further reduced. For example, if the cache size is increased to 2 18 , the time complexity is reduced to 8192.
[0058] Embodiment 2:
[0059] See also Figure 1 - Figure 2As shown, it also includes an encryption control module, a risk verification module, a data transceiver module and a cloud early warning module;
[0060] The data sending and receiving module is used to collect statistics on the public and private key distribution process, user usage requests, and the ciphertext calculation result distribution process, obtain the data sending and receiving process, and send the data sending and receiving process to the risk verification module;
[0061] When the data transceiver module collects statistics on the private key distribution process and the ciphertext calculation result distribution process, it obtains the network parameters of the private key distribution path and the ciphertext calculation result distribution path, monitors the real-time fluctuation of the network parameters, and uses the real-time fluctuation of the network as an abnormal point;
[0062] When the data transceiver module counts the user's usage requests, it calculates the user's usage request density and uses it as the statistical result;
[0063] The method for the data transceiver module to obtain the user usage request density is:
[0064] Taking the time when the user's request is received as the starting point, a set time length is selected, and the number of all user requests within the set time length is counted, and the ratio of the number of user requests and the time length is calculated as the density sample value;
[0065] The data transceiver module obtains multiple density sample values by selecting different starting points and changing multiple groups of time lengths, and selects the highest group of density sample values as the user usage request density.
[0066] The encryption control module controls the encryption process of the user's public key, private key and original data. The encryption control module records the time point when the user's public key, private key and original data are encrypted as the start time, and calculates the time from the start time to the current time in real time to obtain the applied time, and records the ratio of the applied time to the number of encryption layers and the character length of the public and private key pair as the encryption process data, and sends the encryption process data to the risk verification module;
[0067] The risk verification module performs risk control on the data sending and receiving process and the encryption process data. The method for the risk verification module to generate risk control warning is:
[0068] The risk verification module counts the number of abnormal points and compares the abnormal points with the set threshold. If the abnormal points are greater than the set threshold, it is determined that there is a risk in the transmission process. The risk verification module calculates the proportion of risky transmission processes in the total transmission process. If the proportion is greater than the set standard, a transmission risk alarm is generated;
[0069] The risk verification module compares the user's usage request density with the set density and generates a high-frequency request alarm based on the comparison results;
[0070] The risk verification module uses transmission risk alarms and high-frequency request alarms as risk management warnings;
[0071] The risk verification module can also verify the reliability of the encryption process data, generate time-based encryption reliability features, and make judgments based on the encryption reliability features to obtain the encryption failure risk. The method for the risk verification module to generate encryption reliability features is:
[0072] The risk verification module performs multi-level threshold judgment based on the encryption process data, and generates encryption reliability features according to the level threshold of the encryption process data. The larger the encryption process data, the smaller the encryption reliability feature.
[0073] The cloud-based early warning module can respond to risk management warnings and encryption failure risks. When a risk management warning occurs, it will issue an early warning reminder to the management party and display the encryption reliability features to remind the management party to update the public and private key pairs, encryption layers and encryption random numbers to ensure encryption reliability.
[0074] The preferred embodiments of the present invention disclosed above are only used to help explain the present invention. The preferred embodiments do not describe all the details in detail, nor do they limit the invention to only specific implementation methods. Obviously, many modifications and changes can be made according to the content of this specification. This specification selects and specifically describes these embodiments in order to better explain the principles and practical applications of the present invention, so that those skilled in the art can understand and use the present invention well. The present invention is limited only by the claims and their full scope and equivalents.
Claims
1. A data security transmission system based on homomorphic encryption algorithm, characterized in that: It includes an encryption control module, a risk verification module, a data transceiver module and a homomorphic encryption generation module. The homomorphic encryption generation module can process the distribution application of the user's public and private key pairs and distribute the private key. The homomorphic encryption generation module encrypts the original data according to the public key to obtain the initial ciphertext, and uploads the initial ciphertext to the network platform. Then, the initial ciphertext is calculated according to the user's use request to obtain the ciphertext calculation result. Finally, the ciphertext calculation result is distributed to the user, and the user decrypts it with the private key to obtain the data result after the calculation; The data transceiving module is used to collect statistics on the public and private key distribution process, user usage requests, and ciphertext calculation result distribution process, obtain the data transceiving process, and send the data transceiving process to the risk verification module; The encryption control module controls the user's public key, private key and the original data encryption process, obtains the encryption process data, and sends the encryption process data to the risk verification module; The risk verification module performs risk control on the data sending and receiving process and the encryption process data, verifies abnormal behavior in the data sending and receiving process, and generates risk control warnings. The risk verification module can also verify the reliability of the encryption process data, generate encryption reliability features based on time, and make judgments based on the encryption reliability features to obtain encryption failure risks; It also includes a cloud-based early warning module, which can respond to risk management and control warnings and encryption failure risks and generate early warning reminders.
2. According to claim 1, the data security transmission system based on the homomorphic encryption algorithm is characterized in that: The homomorphic encryption generation module includes a key application distribution unit, an original encryption unit and a user computing and using unit, wherein the key application distribution unit is used to generate a public key and a private key, and send the private key to the user; The original encryption unit is used to perform homomorphic encryption on the original data; The user calculation and use unit is used to receive a user's data use request, directly calculate the initial ciphertext according to the user's data use request, and pass the calculated data result through the data transceiver module.
3. The data security transmission system based on homomorphic encryption algorithm according to claim 1 is characterized in that: When the data transceiver module performs statistics on the private key distribution process and the ciphertext calculation result distribution process, it obtains network parameters of the private key distribution path and the ciphertext calculation result distribution path, monitors the real-time fluctuation of the network parameters, and uses the real-time fluctuation of the network as an abnormal point; When the data transceiver module performs statistics on the user usage requests, the density of the user usage requests is calculated and used as the statistical result.
4. The data security transmission system based on homomorphic encryption algorithm according to claim 3 is characterized in that: The method for the data transceiver module to obtain the user usage request density is: Taking the time when the user's request is received as the starting point, a set time length is selected, and the number of all user requests within the set time length is counted, and the ratio of the number of user requests and the time length is calculated as the density sample value; The data transceiver module obtains multiple density sample values by selecting different starting points and changing multiple groups of time lengths, and selects the highest group of density sample values as the user usage request density.
5. The data security transmission system based on homomorphic encryption algorithm according to claim 1 is characterized in that: The encryption management and control module records the time point when the user's public key, private key and original data are encrypted as the start time, and calculates the time elapsed from the start time to the current time in real time to obtain the applied time, and records the ratio of the applied time to the number of encryption layers and the character length of the public-private key pair as the encryption process data.
6. The data security transmission system based on homomorphic encryption algorithm according to claim 1 is characterized in that: The method for the risk verification module to generate risk management warning is: The risk verification module counts the number of abnormal points and compares the abnormal points with a set threshold. If the abnormal points are greater than the set threshold, it is determined that there is a risk in the transmission process. The risk verification module calculates the proportion of the transmission process with risks in the total transmission process. If the proportion is greater than the set standard, a transmission risk alarm is generated; The risk verification module compares the user's usage request density with the set density, and generates a high-frequency request alarm according to the comparison result; The risk verification module uses transmission risk warnings and high-frequency request warnings as risk management warnings.
7. The data security transmission system based on homomorphic encryption algorithm according to claim 1 is characterized in that: The method for the risk verification module to generate encrypted reliable features is: The risk verification module performs multi-level threshold judgment based on the encryption process data, and generates an encryption reliability feature based on the level threshold of the encryption process data. The larger the encryption process data, the smaller the encryption reliability feature.
8. The data security transmission system based on homomorphic encryption algorithm according to claim 2 is characterized in that: The encryption method of the original encryption unit is: Step 1: User A generates a random number r and calculates C1=[r]G to obtain a point C1 on the elliptic curve, where G is the base point in the SM2 cryptographic algorithm and [] is the elliptic curve multiplication operation; Step 2: Calculate C2=[r]PK+[m]G to get another point C2 on the elliptic curve, where PK is the public key of user A and m is the data to be encrypted; Step 3: Get the encrypted ciphertext (C1, C2).
9. The data security transmission system based on homomorphic encryption algorithm according to claim 2 is characterized in that: The method for the user computing unit to perform ciphertext calculation and decryption is: S1: Add or subtract the two ciphertext data C1 and C2 respectively to obtain the ciphertext after addition or subtraction; S2: Multiply the two ciphertext data C1 and C2 by the plaintext n respectively to obtain the ciphertext after scalar multiplication; S3: Calculate the point P=[m]G=C2-[SK]C1 on the elliptic curve, where SK is the user's private key and m is the plaintext result after calculation.
Citation Information
Patent Citations
Data homomorphic encryption method and device
CN117318918A
Data protection communication method, system and equipment based on semi-homomorphic encryption and medium
CN118381639A
Data security risk assessment early warning system
CN119128899A
Internet-based data transmission encryption security protection system
CN119128947A
Method and system for digital privacy management
US20170272472A1