Multi-link data security verification method based on homomorphic encryption and asymmetric encryption

By adopting a multi-link data security verification method of homomorphic encryption and asymmetric encryption in multi-party communication scenarios, the problem of leaking sensitive information during data transmission is solved, and the secure and efficient transmission and verification of data is achieved.

CN120034390AActive Publication Date: 2025-05-23BEIJING INST OF COMP TECH & APPL
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510253281.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-05
Publication Date
2025-05-23
Estimated Expiration
2045-03-05

AI Technical Summary

Technical Problem

In multi-party communication scenarios, how to achieve effective trust and verification between the data generation end, multiple processing ends and data receiving ends, ensure that the data does not leak sensitive information during transmission, and ensure that the final receiver can receive data accurately and completely.

Method used

A multi-link data security verification method based on homomorphic encryption and asymmetric encryption is adopted. The data to be sent is homomorphic encryption through the data generation end, a dynamic binding key is generated, and data verification and calculation are carried out in each verification step to ensure that the data is processed in the ciphertext state and avoid plaintext data leakage.

Benefits of technology

It realizes the protection of data privacy in multi-party communication scenarios, ensures that data is not leaked during transmission, and the ultimate receiver can accurately decrypt the received data, improving the security and efficiency of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034390A_ABST
    Figure CN120034390A_ABST
Patent Text Reader

Abstract

The invention relates to a multi-link data security verification method based on homomorphic encryption and asymmetric encryption, and belongs to the technical field of information security in the communication field. According to the method, the security and privacy of data transmission among the data generation end, the plurality of processing ends and the data receiving end are ensured through a verification mechanism in combination with the plurality of processing ends. According to the method, homomorphic encryption and asymmetric encryption technologies are combined, and safe and efficient data transmission and verification are realized while data privacy is ensured through a multi-layer verification and calculation mechanism. According to the method, data privacy and transmission security are ensured through secure transmission links among a data generation end, a plurality of processing ends and a data receiving end, and security and credibility during information verification and data transmission in a multi-party communication scene are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of information technology in the field of communications, and specifically relates to a multi-link data security verification method based on homomorphic encryption and asymmetric encryption. Background Art

[0002] In modern communication systems, security, privacy, and authenticity assurance during data transmission are crucial. Especially in multi-party communication scenarios, how to achieve effective trust and verification between the data generation end, multiple processing ends, and data receiving ends is an important issue in communication security.

[0003] Although traditional encryption technology can ensure the confidentiality of data, when it comes to scenarios where data verification is performed in multiple links, how to ensure that sensitive information will not be leaked during the processing of each processing end and how to ensure that the final receiving end can receive the data accurately and completely becomes an urgent problem to be solved.

[0004] For example, in some communication scenarios where data needs to be verified by multiple processing ends, and one of the processing ends can send the information to the data receiving end only after verification and processing, how to ensure that each processing end can only perform verification and processing operations but cannot obtain the data content, while ensuring that the final receiving end can correctly decrypt and receive the data, is an important technical challenge in the field of information security.

[0005] As a new type of encryption method, homomorphic encryption technology has the characteristic of performing calculations in a ciphertext state. Unlike traditional encryption algorithms, homomorphic encryption allows operations such as addition and multiplication to be performed on encrypted data without first decrypting the data. This means that the processing end can still perform effective operations on encrypted data even if it cannot obtain the plaintext data, which can ensure the security of calculation and processing while protecting data privacy.

[0006] The emergence of homomorphic encryption has greatly enhanced the protection of data privacy, especially in cloud computing and distributed computing scenarios, where the contradiction between data privacy and computing efficiency has been well balanced. For scenarios that require verification and processing in multiple links, homomorphic encryption provides a security technology solution that can both protect data privacy and achieve necessary data processing and verification. It allows all parties to calculate and process data without leaking the plaintext of the data, and the final recipient can restore the original data through the corresponding decryption operation.

[0007] However, the application of existing homomorphic encryption technology in multi-party verification and data transmission still faces certain technical challenges. For example, how to verify and perform calculations layer by layer in multiple verification links and maintain data privacy, how to effectively avoid data leakage in the middle links during the homomorphic encryption process, and at the same time ensure that the final decrypted data is accurate, are all problems that need to be solved. Summary of the invention

[0008] 1. Technical issues to be resolved

[0009] The technical problem to be solved by the present invention is: to design a data security verification method to achieve safe and efficient data transmission and verification while ensuring data privacy.

[0010] (II) Technical solution

[0011] In order to solve the above technical problems, the present invention provides a multi-link data security verification method based on homomorphic encryption and asymmetric encryption, comprising the following steps:

[0012] 1. The data generation end encrypts the verification information and the data to be sent

[0013] Step 1: Generate a dynamic binding key

[0014] 11) The data generation end first generates the original data Data to be sent. After preprocessing, these data are ready to be sent to the subsequent verification link. The original data is not encrypted; the data generation end also obtains the public key PK of the data receiver receiver ;

[0015] 12) Dynamic Key Derivation

[0016] Calculate the hash value of the data recipient's public key: H PK =SHA3 512 (PK receiver );

[0017] Generate initial homomorphic parameter n temp (Paillier secure prime product), encrypted as: C n =RSA-OAEP(PK receiver ,n temp );

[0018] Generate the final homomorphic modulus as a dynamic key:

[0019] Step 2: Homomorphically encrypt the original data to be sent

[0020] 21) Use the dynamic modulus n to perform Paillier homomorphic encryption on Data and obtain the homomorphic ciphertext: C data=Enc Paillier (Data) = g Data ·r n mod n 2 ; g is a generator, providing homomorphic structure; r is a random number, providing randomness;

[0021] 22) Salt value generation:

[0022] For H PK and n temp Perform ECDSA signing and extract the first 128 bits as the salt value:

[0023]

[0024] 23) Data processing end verification information preparation

[0025] Use the corresponding data processing end public key to encrypt a piece of verification data as data processing end verification information to identify which data processing end should process the data;

[0026] Step 3: Prepare and encrypt verification information

[0027] The data generation end is ready to send the following data to the data processing end: dynamic homomorphic ciphertext, encrypted initial modulus, hash value of the data receiver's public key, signature salt value Salt, data processing end verification information, etc., to confirm the legitimacy of the data generation end in the subsequent verification link;

[0028] Step 4: Send encrypted data and verification information

[0029] The data generation end sends the encrypted homomorphic encrypted data and verification information to the first verification link;

[0030] 2. Data processing end performs data verification and processing

[0031] Step 5: Receive encrypted data and parse verification information

[0032] After receiving the encrypted data, each verification link first decrypts the verification information and parses out the relevant verification data;

[0033] Step 6: Verify the legitimacy of the data

[0034] Use the public key of the data generator to verify whether the Salt comes from a legitimate signature:

[0035]

[0036] Verify whether the data generating end is the authorized party and check whether the data has been tampered with or forged; if the verification fails, forward it to other data processing ends and return to step 5; only if the verification passes will the verification link continue to process the data;

[0037] Step 7: Calculate and process the ciphertext

[0038] After the verification is passed, the verification link will check the encrypted data C data Perform necessary calculation operations; all operations are performed in ciphertext state;

[0039] Step 8: Forward the processed ciphertext

[0040] The verified and calculated ciphertext will be forwarded to the data receiving end. During this process, the verification link can only operate on the ciphertext and cannot access the plaintext of the ciphertext;

[0041] 3. Data receiving end decrypts ciphertext

[0042] Step 9: Receive ciphertext

[0043] The data receiving end receives the homomorphically encrypted ciphertext from the verification link. Since the data receiving end is the final recipient, it has the right to decrypt the ciphertext;

[0044] Step 10: Decrypt the ciphertext using the private key

[0045] 101) Restore the initial modulus:

[0046] Decrypt C using the private key n Get n temp ′:

[0047] n temp ′=RSA-OAEP-Decrypt(SK receiver ,C n )

[0048] 102) Reconstructing the homomorphic modulus:

[0049] Compute the homomorphic modulus:

[0050]

[0051] H PK ′ is the public key hash value calculated by the data receiving end;

[0052] 103) Prime number verification:

[0053] Verify whether n′ is a legal Paillier modulus. If n′=p×q and p≡q≡3mod4, it is considered legal.

[0054] 104) Layered decryption and auditing

[0055] Decrypt the homomorphic ciphertext and get:

[0056]

[0057] Where λ = lcm(p-1,q-1), L is the core function of the Paillier decryption algorithm, C result The ciphertext received by the data receiving end.

[0058] The present invention also provides a system for implementing the method.

[0059] The invention also provides a communication system implemented based on the method.

[0060] The invention also provides an application of the method in the field of information security.

[0061] (III) Beneficial effects

[0062] Compared with the prior art, the present invention has the following beneficial effects:

[0063] Privacy protection: Through homomorphic encryption technology, the ciphertext transmitted from the data generation end to the verification link can be encrypted during the transmission process to ensure data privacy; each verification link is only responsible for data verification and performs calculations on encrypted data without leaking data content. In contrast, ordinary encryption mainly focuses on the storage and transmission security of data. When processing data, the data needs to be decrypted first. This results in the data being in plaintext during the data processing stage, which poses a risk of privacy leakage.

[0064] Key protection: Homomorphic encryption keys are dynamically derived from the recipient's public key hash and temporary parameters. They do not rely on static storage, and attackers cannot obtain global keys by invading a single node.

[0065] Multi-layer verification mechanism: Introduce multiple verification links as intermediaries for data verification. Each verification link can only perform verification and calculation operations. While ensuring data privacy, the model can be processed differently according to business needs, thereby improving the scalability of the system.

[0066] Efficiency: Homomorphic encryption technology can perform various operations such as addition and multiplication on ciphertext. The data processing module can perform statistical operations such as summation and averaging directly on the ciphertext without decrypting the data, providing a more flexible and efficient data processing method. For ordinary encrypted data, if you want to perform calculations, you must first decrypt it. This makes the data calculation process limited by the decryption link. Moreover, each calculation requires the tedious steps of decryption-calculation-re-encryption. BRIEF DESCRIPTION OF THE DRAWINGS

[0067] Figure 1 The figure is a flow chart of the method of the present invention. DETAILED DESCRIPTION

[0068] In order to make the purpose, content and advantages of the present invention more clear, the specific implementation methods of the present invention are further described in detail below in conjunction with the drawings and examples.

[0069] The present invention provides a communication security verification method and system based on asymmetric encryption and homomorphic encryption, which combines multiple processing terminals and ensures the security and privacy of data when it is transmitted between a data generation terminal, multiple processing terminals and a data receiving terminal through a verification mechanism. The present invention combines homomorphic encryption and asymmetric encryption technology, and through multi-layer verification and computing mechanisms, achieves safe and efficient data transmission and verification while ensuring data privacy. The method ensures data privacy and transmission security through a secure transmission link between a data generation terminal, multiple processing terminals and a data receiving terminal, and ensures the security and credibility of information verification and data transmission in a multi-party communication scenario. The method can not only ensure the encrypted transmission of information, but also realize secure verification and decryption across multiple verification links, and is widely applicable to multiple fields such as data transmission, information verification and privacy protection.

[0070] The method comprises the following steps:

[0071] 1. The data generation end encrypts the verification information and the data to be sent

[0072] Step 1: Generate a dynamic binding key

[0073] 11) The data generation end first generates the original data Data to be sent. After preprocessing, these data are ready to be sent to the subsequent verification link. The original data can be any type of information, and these data are not encrypted. The data generation end also obtains the public key PK of the data receiver receiver .

[0074] 12) Dynamic Key Derivation:

[0075] Calculate the hash value of the data recipient's public key: H PK =SHA3 512 (PK receiver );

[0076] Generate initial homomorphic parameters (modulus) n temp (Paillier secure prime product), encrypted as: C n =RSA-OAEP(PK receiver ,n temp );

[0077] Generate the final homomorphic modulus as a dynamic key:

[0078] Step 2: Homomorphically encrypt the original data to be sent

[0079] 21) Use the dynamic modulus n to perform Paillier homomorphic encryption on Data and obtain the homomorphic ciphertext: C data =Enc Paillier (data) = g Data ·r n mod n 2 ; g and r are parameters in the homomorphic encryption algorithm, g is the generator, providing the homomorphic structure; r is a random number, providing randomness;

[0080] 22) Salt value generation:

[0081] For H PK and n temp Perform ECDSA signing and extract the first 128 bits as the salt value:

[0082]

[0083] 23) Data processing end verification information preparation

[0084] A piece of verification data is encrypted using the corresponding data processing end public key as data processing end verification information to identify which data processing end should process the data.

[0085] Step 3: Prepare and encrypt verification information

[0086] The data generation end is ready to send the following data to the data processing end: dynamic homomorphic ciphertext, encrypted initial modulus, hash value of the data recipient's public key, signature salt value Salt, data processing end verification information, etc., to confirm the legitimacy of the data generation end in the subsequent verification link.

[0087] Step 4: Send encrypted data and verification information

[0088] The data generator sends the encrypted homomorphically encrypted data and verification information to the first verification stage. At this stage, the data generator cannot ensure that the data will not be tampered with during transmission, so encryption is used to ensure data privacy, and the identity of the data generator is confirmed through verification information.

[0089] 2. Data processing end performs data verification and processing

[0090] Step 5: Receive encrypted data and parse verification information

[0091] After receiving the encrypted data, each verification link first decrypts the verification information and parses the relevant verification data. Through asymmetric decryption technology, the verification link can verify whether the identity of the data generator is legal and whether the data complies with the predetermined verification rules.

[0092] Step 6: Verify the legitimacy of the data

[0093] Use the public key of the data generator to verify whether the Salt comes from a legitimate signature:

[0094]

[0095] Verify whether the data generation end is the authorized party and check whether the data has been tampered with or forged; if the verification fails, forward it to other data processing ends and return to step five; only if the verification passes will the verification link continue to process the data.

[0096] Step 7: Calculate and process the ciphertext

[0097] After the verification is passed, the verification link will check the encrypted data C data Perform necessary computing operations. These operations include data format conversion, data legitimacy verification, encrypted data aggregation, etc. All operations are performed in ciphertext state to ensure that the privacy of the data will not be leaked.

[0098] Step 8: Forward the processed ciphertext

[0099] The verified and calculated ciphertext will be forwarded to the data receiving end. During this process, the verification link can only operate on the ciphertext and cannot access the plaintext data of the ciphertext, thus effectively protecting the privacy of the data.

[0100] 3. Data receiving end decrypts ciphertext

[0101] Step 9: Receive ciphertext

[0102] The data receiving end receives the homomorphically encrypted ciphertext from the verification link. Since the data receiving end is the final recipient, it has the right to decrypt the ciphertext.

[0103] Step 10: Decrypt the ciphertext using the private key

[0104] 101) Restore the initial modulus:

[0105] Decrypt C using the private key n Get n temp ′:

[0106] n temp ′=RSA-OAEP-Decrypt(SK receiver ,C n )

[0107] 102) Reconstructing the homomorphic modulus:

[0108] Compute the homomorphic modulus:

[0109]

[0110] H PK ′ is the public key hash value calculated by the data receiving end;

[0111] 103) Prime number verification:

[0112] Verify whether n′ is a legal Paillier modulus. It is considered legal if n′=p×q and p≡q≡3mod4.

[0113] 104) Layered decryption and auditing

[0114] Decrypt the homomorphic ciphertext and get:

[0115]

[0116] Where λ = lcm(p-1,q-1), L is the core function of the Paillier decryption algorithm, C result The ciphertext received by the data receiving end.

[0117] Step 11: Further processing and feedback

[0118] The decrypted data will be further processed according to business needs. The data receiving end can perform corresponding operations based on the decryption results and feedback the processing results to the data generating end or verification link as needed.

[0119] The system for implementing the above method includes the following modules:

[0120] Data generation module

[0121] Generate data module: Generate plaintext data to be sent and perform homomorphic encryption on the data.

[0122] Homomorphic encryption module: Use homomorphic encryption technology to encrypt the data to be sent, ensuring that the data can be encrypted during transmission.

[0123] Data sending module: sends the encrypted data and verification information to the first verification link.

[0124] Data processing module

[0125] Processing end receiving module: receives the encrypted data sent by the data generating end.

[0126] Asymmetric decryption module: uses asymmetric encryption technology to decrypt the verification information sent by the data generation end to verify the legitimacy of the data.

[0127] Verification module: performs verification operations based on the decrypted verification information to determine whether the ciphertext is allowed to be forwarded to the next verification link or data receiving end.

[0128] Homomorphic computing module: Perform necessary computing operations on homomorphically encrypted ciphertext and update the ciphertext content. All operations are performed in the ciphertext state to ensure data privacy.

[0129] Data forwarding module: forwards the homomorphically encrypted ciphertext after calculation to the next verification link or data receiving end.

[0130] Data receiving module

[0131] Data receiving module: receives the homomorphic encrypted ciphertext forwarded by the verification link.

[0132] Asymmetric decryption module: Use asymmetric encryption technology to decrypt homomorphic encrypted ciphertext and restore the data originally sent by the data generation end.

[0133] It can be seen that the present invention provides a communication security verification method and system based on a combination of asymmetric encryption and homomorphic encryption, which can effectively protect the privacy, integrity and authenticity of data in multi-party communication scenarios. Through multi-layer verification and encryption mechanisms, an efficient and secure data transmission solution is provided, which is suitable for a wide range of application scenarios.

[0134] This method can be applied to various homomorphic encryption schemes, including:

[0135] 1. Cases with public and private keys (such as homomorphic encryption based on RSA variants)

[0136] The public key is used to encrypt data. Users can use the public key to encrypt plaintext data into ciphertext, just like in ordinary RSA encryption. For example, the data owner (such as an enterprise) can provide the public key to the cloud service provider, and the cloud service provider uses this public key to perform homomorphic computing on the encrypted data sent by the enterprise.

[0137] The private key is used to decrypt the final result. Only the party with the private key (usually the data owner) can decrypt the ciphertext result after homomorphic calculation and obtain meaningful calculation results. This ensures the confidentiality of data and the ownership of calculation results.

[0138] 2. Cases without public and private keys (such as some simple homomorphic encryption schemes)

[0139] Some homomorphic encryption schemes may only be based on symmetric keys, that is, the same key is used for encryption and decryption. In this case, key management is relatively simple, but there may be some restrictions in the application scenario. For example, in multi-party computing scenarios, how to safely share and use this key will be a problem. However, this solution may be more applicable in some specific scenarios with relatively low security requirements and relatively closed computing environments.

[0140] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the technical principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.

Claims

1. A multi-link data security verification method based on homomorphic encryption and asymmetric encryption, characterized in that: The following steps are involved:

1. The data generation end encrypts the verification information and the data to be sent Step 1: Generate a dynamic binding key 11) The data generation end first generates the original data Data to be sent. After preprocessing, these data are ready to be sent to the subsequent verification link. The original data is not encrypted; the data generation end also obtains the public key PK of the data receiver receiver ; 12) Dynamic Key Derivation Calculate the hash value of the data recipient's public key: H PK =SHA3 512 (PK receiver ); Generate initial homomorphic parameter n temp (Paillier secure prime product), encrypted as: C n =RSA-OAEP(PK receiver ,n temp ); Generate the final homomorphic modulus as a dynamic key: Step 2: Homomorphically encrypt the original data to be sent 21) Use the dynamic modulus n to perform Paillier homomorphic encryption on Data and obtain the homomorphic ciphertext: C data =Enc Paillier (Data) = g Data ·r n mod n 2 ; g is a generator, providing a homomorphic structure; r is a random number, providing randomness; 22) Salt value generation: For H PK and n temp Perform ECDSA signing and extract the first 128 bits as the salt value: 23) Data processing end verification information preparation Use the corresponding data processing end public key to encrypt a piece of verification data as data processing end verification information to identify which data processing end should process the data; Step 3: Prepare and encrypt verification information The data generation end is ready to send the following data to the data processing end: dynamic homomorphic ciphertext, encrypted initial modulus, hash value of the data receiver's public key, signature salt value Salt, data processing end verification information, etc., to confirm the legitimacy of the data generation end in the subsequent verification link; Step 4: Send encrypted data and verification information The data generation end sends the encrypted homomorphic encrypted data and verification information to the first verification link; 2. Data processing end performs data verification and processing Step 5: Receive encrypted data and parse verification information After receiving the encrypted data, each verification link first decrypts the verification information and parses out the relevant verification data; Step 6: Verify the legitimacy of the data Use the public key of the data generator to verify whether the Salt comes from a legitimate signature: Verify whether the data generating end is the authorized party and check whether the data has been tampered with or forged; if the verification fails, forward it to other data processing ends and return to step 5; only if the verification passes will the verification link continue to process the data; Step 7: Calculate and process the ciphertext After the verification is passed, the verification link will check the encrypted data C data Perform necessary calculation operations; all operations are performed in ciphertext state; Step 8: Forward the processed ciphertext The verified and calculated ciphertext will be forwarded to the data receiving end. During this process, the verification link can only operate on the ciphertext and cannot access the plaintext of the ciphertext; 3. Data receiving end decrypts ciphertext Step 9: Receive ciphertext The data receiving end receives the homomorphically encrypted ciphertext from the verification link. Since the data receiving end is the final recipient, it has the right to decrypt the ciphertext; Step 10: Decrypt the ciphertext using the private key 101) Restore the initial modulus: Decrypt C using the private key n Get n temp ′: n temp ′=RSA-OAEP-Decrypt(SK receiver ,C n ) 102) Reconstructing the homomorphic modulus: Compute the homomorphic modulus: H PK ′ is the public key hash value calculated by the data receiving end; 103) Prime number verification: Verify whether n′ is a legal Paillier modulus. If n′=p×q and p≡q≡3mod4, it is considered legal. 104) Layered decryption and auditing Decrypt the homomorphic ciphertext and get: Where λ = lcm(p-1,q-1), L is the core function of the Paillier decryption algorithm, C result The ciphertext received by the data receiving end.

2. The method according to claim 1, characterized in that The necessary computing operations in step seven include data format conversion, data legitimacy verification, and encrypted data aggregation.

3. The method according to claim 1, characterized in that The method also includes step eleven: the decrypted data will be further processed according to business needs, the data receiving end will perform corresponding operations based on the decryption result, and feedback the processing result to the data generating end or the verification link as needed.

4. A system for implementing the method as claimed in claim 1, 2 or 3.

5. The system according to claim 4, characterized in that The system includes a data generating end, a data processing module and a data receiving end.

6. The system according to claim 5, characterized in that The data generation end includes: Data generation module: used to generate plaintext data to be sent and perform homomorphic encryption on the data; Homomorphic encryption module: used to encrypt the data to be sent using homomorphic encryption technology to ensure that the data can be encrypted during transmission; Data sending module: used to send the encrypted data and verification information to the first verification link.

7. The system according to claim 5, characterized in that The data processing module includes: Processing end receiving module: receives the encrypted data sent by the data generating end; Asymmetric decryption module: uses asymmetric encryption technology to decrypt the verification information sent by the data generation end to verify the legitimacy of the data; Verification module: performs verification operations based on the decrypted verification information to determine whether to allow the ciphertext to be forwarded to the next verification link or data receiving end; Homomorphic computing module: performs necessary computing operations on homomorphically encrypted ciphertext and updates the ciphertext content. All operations are performed in the ciphertext state; Data forwarding module: forwards the homomorphically encrypted ciphertext after calculation to the next verification link or data receiving end.

8. The system according to claim 5, characterized in that The data receiving end includes: Data receiving module: receiving the homomorphic encrypted ciphertext forwarded by the verification link; Asymmetric decryption module: Use asymmetric encryption technology to decrypt homomorphic encrypted ciphertext and restore the data originally sent by the data generation end.

9. A communication system implemented based on the method as claimed in claim 1, 2 or 3.

10. Application of the method according to claim 1, 2 or 3 in the field of information security.

Citation Information

Patent Citations

  • Data transmission encryption verification method and system

    CN107920050A

  • Privacy and verifiable Internet of Things data aggregation method fusing block chain

    CN116318901A

  • Multi-level privacy protection remote human body scanning method and system

    CN119011237A

  • Block chain and homomorphic encryption-based power data privacy protection method and system

    CN119293845A

  • Block chain transaction privacy protection method and system

    WO2019080933A1