Data sharing accurate authorization method, system and terminal

By using homomorphic encryption algorithms and result verification mechanisms in data sharing authorization, the problems of low data processing efficiency and insufficient authorization accuracy in the existing technology are solved, and efficient and secure data sharing authorization are achieved.

CN120068034AInactive Publication Date: 2025-05-30ZHILIN TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510103853.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-23
Publication Date
2025-05-30
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing data sharing authorization method requires frequent decryption and encrypted data when processing computing tasks, which reduces data processing efficiency and lacks a result verification mechanism, which cannot guarantee the accuracy of data sharing.

Method used

The original data of participants is encrypted using homomorphic encryption algorithm, and the calculation is performed in the encrypted state to ensure that only participants with corresponding authorization can decrypt the calculation results, and analyze whether the calculation task is carried out according to the authorization rules through the result verification mechanism.

Benefits of technology

It improves data processing efficiency, ensures the security of data during transmission and processing, and improves the accuracy of authorization through the result verification mechanism.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068034A_ABST
    Figure CN120068034A_ABST
Patent Text Reader

Abstract

The invention discloses a data sharing accurate authorization method, system and terminal, and relates to the technical field of data sharing, original data of participants are encrypted by using a homomorphic encryption algorithm, all participants are ensured to obtain necessary keys to perform encryption and decryption operations under the framework of homomorphic encryption, a multi-party computing protocol is used, and the data sharing accuracy is improved. And enabling the participant to carry out calculation in an encryption state, decrypting a calculation result by using a homomorphic decryption method to obtain a final plaintext result, carrying out result verification, analyzing whether calculation of a calculation task is carried out according to an authorization rule or not, and generating a corresponding decision suggestion according to an analysis result. According to the authorization method, in the data transmission process, encryption is carried out based on the homomorphic encryption algorithm, calculation is allowed to be executed in the encryption state, data decryption is not needed, the data processing efficiency is improved, after the result is obtained, whether the result is carried out according to the authorization rule or not is analyzed, and the authorization accuracy is further improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data sharing, and particularly to a method, system and terminal for precise authorization of data sharing. Background Art

[0002] Precise authorization of data sharing is a management method that ensures data is accessed and used reasonably and securely through a refined authorization mechanism during the process of data exchange and sharing. This method aims to balance the need for data sharing with data privacy and security, ensuring that the flow of data does not violate relevant laws, regulations, policies or internal organizational regulations. Existing authorization methods usually calculate and allocate authorization for computing tasks based on pre-set authorization rules. However, in order to avoid data leakage during the authorization process, participants choose to encrypt computing tasks, but this requires the recipient to decrypt each computing task, reducing the data processing efficiency. Moreover, after obtaining the results, existing authorization methods do not perform result verification processing, unable to guarantee the precision of data sharing. Summary of the Invention

[0003] The purpose of the present invention is to provide a method, system and terminal for precise authorization of data sharing to solve the deficiencies in the background art.

[0004] To achieve the above purpose, the present invention provides the following technical solution: A method for precise authorization of data sharing, the authorization method comprising the following steps:

[0005] Encrypt the original data of the participating parties using a homomorphic encryption algorithm. Homomorphic encryption allows computations to be performed in the encrypted state without decrypting the data;

[0006] Under the framework of homomorphic encryption, ensure that all participating parties obtain the necessary keys for encryption and decryption operations;

[0007] When entrusting computing tasks to one or more participating parties, determine which participating parties have the right to access which computing tasks based on authorization rules, and use a multi-party computing protocol to enable the participating parties to perform computations in the encrypted state;

[0008] Decrypt the result of the computation using a homomorphic decryption method to obtain the final plaintext result, and record audit information;

[0009] Verify the result, analyze whether the computation of the computing task is carried out according to the authorization rules, and generate corresponding decision-making suggestions based on the analysis result. After the computation is completed, clean up the intermediate results and decryption keys.

[0010] Preferably, verifying the result and analyzing whether the computation of the computing task is carried out according to the authorization rules comprises the following steps:

[0011] Obtain the permission matching index, decryption frequency, and identity verification error rate of the calculation result;

[0012] Comprehensively calculate the permission matching index, decryption frequency, and identity verification error rate to obtain the authorization coefficient. The expression is:

[0013]

[0014] In the formula, SQX is the authorization coefficient, piz, jmp, and sfz are the permission matching index, decryption frequency, and identity verification error rate respectively, n is the number of subtasks in the calculation task, and piz i represents the permission matching index of the i-th subtask, and jmp i represents the decryption frequency of the i-th subtask, and sfz i represents the identity verification error rate of the i-th subtask. a1, a2, and a3 are the proportionality coefficients of the identity verification error rate, decryption frequency, and identity verification error rate respectively, and a1, a2, and a3 are all greater than 0;

[0015] After obtaining the authorization coefficient, compare the authorization coefficient with the preset authorization threshold. If the authorization coefficient is greater than or equal to the authorization threshold, analyze that the calculation of the calculation task is carried out according to the authorization rules. If the authorization coefficient is less than the authorization threshold, analyze that the calculation of the calculation task is not carried out according to the authorization rules.

[0016] Preferably, encrypt the original data of the participating parties using the homomorphic encryption algorithm. Homomorphic encryption allows calculations to be performed in the encrypted state without decrypting the data, including the following steps:

[0017] Generate the necessary keys for the homomorphic encryption algorithm, including the public key and the private key. The public key is used to encrypt the data, and the private key is used to decrypt the calculation result. Encode the original data of the participating parties, use the public key of the homomorphic encryption algorithm to encrypt the encoded data, transmit the encrypted data to other participating parties or store it. In the encrypted state, perform homomorphic calculations on the encrypted data. After completing the homomorphic calculations, use the public key of the homomorphic encryption algorithm to encrypt the calculation result, and use the private key of the homomorphic encryption algorithm to decrypt the calculation result to obtain the final plaintext result.

[0018] Preferably, in the framework of homomorphic encryption, ensuring that all participating parties obtain the necessary keys for encryption and decryption operations includes the following steps:

[0019] The public key and private key required for the homomorphic encryption algorithm are generated by a trusted key manager. The key manager distributes the generated public key of the homomorphic encryption algorithm to all participating parties. According to the negotiated process, the generated private key of the homomorphic encryption algorithm is distributed to the participating parties. The participating parties initiate the key negotiation process to ensure that each participating party obtains the private key for decryption and performing calculations. During the key negotiation process, the participating parties need to authenticate their identities to ensure that only legitimate participating parties obtain the private key. The participating parties initiate the key negotiation protocol, negotiate to obtain the public keys of the other parties and the information for generating the session key through a secure communication channel. Use the obtained public keys of the other parties and the local private key to generate the session key for symmetric encryption. Distribute the generated session key to other participating parties through a secure communication channel to ensure that all participating parties use homomorphic encryption in the calculation. Use the negotiated session key in the calculation to perform homomorphic encryption calculations.

[0020] Preferably, when delegating a computing task to one or more participating parties, determine which participating parties have the right to access which computing tasks based on the authorization rules, including the following steps:

[0021] Define the computing tasks to be executed, including data, algorithms, and computing objectives. Define access conditions, usage conditions, and time limits. Establish an access permission list listing the scope of permissions of each participating party, including the types of computing tasks to be executed and the scope of specific data. Before delegating the task, verify the identity of the participating parties. According to the authorization rules, delegate the computing task to the participating parties with corresponding permissions. The entrusted participating parties use the data and algorithms required for the delegated task to execute the computing task. After completing the computing task, the delegating party receives the computing result from the participating party.

[0022] Preferably, use a multi-party computing protocol to enable the participating parties to perform calculations in an encrypted state, including the following steps:

[0023] The participating parties jointly generate the keys for the MPC protocol, including shared secrets or generating key pairs for homomorphic encryption. The participating parties encrypt their respective inputs, use the homomorphic encryption algorithm to encrypt the input data. If the protocol requires, conduct key negotiation to ensure that each participating party obtains the keys for protocol execution. Decompose the overall computing task into subtasks processed by each participating party. The participating parties execute their respective subtasks according to the provisions of the MPC protocol, perform calculations using the encrypted inputs. Each participating party merges their encrypted intermediate results through the protocol to obtain the final encrypted result of the calculation.

[0024] Preferably, decrypt the result of the calculation using the homomorphic decryption method to obtain the final plaintext result, including the following steps:

[0025] Determine which parties are entitled to the homomorphic decryption key in the protocol to ensure that only the parties with corresponding authorization can decrypt the calculation results. During the generation process of the homomorphic decryption key, perform authorization verification on the parties to ensure that only the parties with corresponding authorization can obtain the homomorphic decryption key. The parties with corresponding authorization use the homomorphic decryption key to decrypt the encrypted calculation results, and the decrypted results will be the calculation results in plaintext form.

[0026] A precise authorization system for data sharing, including a homomorphic encryption module, a key negotiation module, a task authorization module, an encrypted calculation module, a result decryption module, a result verification module, and a data cleaning module;

[0027] Homomorphic encryption module: Encrypt the original data of the parties using the homomorphic encryption algorithm. Homomorphic encryption allows calculations to be performed in the encrypted state without decrypting the data;

[0028] Key negotiation module: Under the framework of homomorphic encryption, ensure that all parties obtain the necessary keys for encryption and decryption operations;

[0029] Task authorization module: When delegating a computing task to one or more parties, determine which parties are entitled to access which computing tasks based on the authorization rules;

[0030] Encrypted calculation module: Use the multi-party calculation protocol to enable the parties to perform calculations in the encrypted state;

[0031] Result decryption module: Decrypt the calculation results using the homomorphic decryption method to obtain the final plaintext results and record audit information:

[0032] Result verification module: Verify the results, analyze whether the calculation of the computing task is carried out according to the authorization rules, and generate corresponding decision suggestions based on the analysis results;

[0033] Data cleaning module: After the calculation is completed, clean up the intermediate results and the decryption key.

[0034] A terminal includes a precise authorization system for data sharing.

[0035] In the above technical solution, the technical effects and advantages provided by the present invention:

[0036] The present invention encrypts the original data of the participating parties using a homomorphic encryption algorithm. Under the framework of homomorphic encryption, it ensures that all participating parties obtain the necessary keys for encryption and decryption operations. When entrusting a computing task to one or more participating parties, it determines which participating parties are authorized to access which computing tasks based on authorization rules. Using a multi-party computing protocol, it enables the participating parties to perform calculations in an encrypted state, decrypts the calculation results using a homomorphic decryption method to obtain the final plaintext result, verifies the result, analyzes whether the calculation of the computing task is carried out according to the authorization rules, and generates corresponding decision-making suggestions based on the analysis results. This authorization method encrypts based on the homomorphic encryption algorithm during the data transmission process, allows calculations to be performed in an encrypted state without decrypting the data, improves data processing efficiency, and further improves the accuracy of authorization by analyzing whether the results are in accordance with the authorization rules after the results are obtained. Brief Description of the Drawings

[0037] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments recorded in the present invention. For those of ordinary skill in the art, other drawings can also be obtained based on these drawings.

[0038] Figure 1 It is a flowchart of the method of the present invention. Detailed Embodiments

[0039] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0040] Embodiment 1: Please refer to Figure 1 As shown, a method for precise authorization of data sharing in this embodiment, the authorization method includes the following steps:

[0041] Encrypt the original data of the participating parties using a homomorphic encryption algorithm. Homomorphic encryption allows computations to be performed in the encrypted state without decrypting the data. Under the framework of homomorphic encryption, ensure that all participating parties obtain the necessary keys for encryption and decryption operations, which is achieved through the process of negotiating keys. Ensure that each participating party correctly uses homomorphic encryption in the computation. When delegating a computing task to one or more participating parties, determine which participating parties have the right to access which computing tasks based on authorization rules. Use a multi-party computation protocol to enable participating parties to perform computations in the encrypted state. The MPC protocol allows participating parties to perform computations without sharing the original data and finally obtain an encrypted result. Decrypt the result of the computation using a homomorphic decryption method to obtain the final plaintext result. This ensures that the data remains encrypted during the computation process, and only the participating parties with corresponding authorization can decrypt and obtain the final result. Record audit information for tracking and verifying the history of the computation. Conduct result verification to analyze whether the computation of the computing task is carried out according to the authorization rules. Generate corresponding decision-making suggestions based on the analysis results. After the computation ends, clean up the intermediate results and decryption keys to ensure that no sensitive information is left behind.

[0042] In this application, the original data of the participating parties is encrypted using a homomorphic encryption algorithm. Under the framework of homomorphic encryption, ensure that all participating parties obtain the necessary keys for encryption and decryption operations. When delegating a computing task to one or more participating parties, determine which participating parties have the right to access which computing tasks based on authorization rules. Use a multi-party computation protocol to enable participating parties to perform computations in the encrypted state. Decrypt the result of the computation using a homomorphic decryption method to obtain the final plaintext result. Conduct result verification to analyze whether the computation of the computing task is carried out according to the authorization rules. Generate corresponding decision-making suggestions based on the analysis results. This authorization method encrypts the data during transmission based on the homomorphic encryption algorithm, allows computations to be performed in the encrypted state without decrypting the data, improves data processing efficiency, and after the result is obtained, analyzes whether the result is in accordance with the authorization rules to further improve the accuracy of authorization.

[0043] Embodiment 2: Encrypt the original data of the participating parties using a homomorphic encryption algorithm. Homomorphic encryption allows computations to be performed in the encrypted state without decrypting the data, and includes the following steps:

[0044] Select a homomorphic encryption algorithm: Select an appropriate homomorphic encryption algorithm according to the requirements and performance requirements of the application. Common homomorphic encryption algorithms include partial homomorphic encryption (Paillier encryption system), fully homomorphic encryption (such as FHE - Fully Homomorphic Encryption), etc.

[0045] Key generation: Generate the necessary keys for the homomorphic encryption algorithm, including a public key and a private key. The public key is used to encrypt the data, and the private key is used to decrypt the computation result.

[0046] Data Encoding: Appropriately encode the original data of the participating parties so that homomorphic calculations can be performed in an encrypted state. Encoding usually involves mapping the data to the element space of the homomorphic encryption system.

[0047] Data Encryption: Use the public key of the homomorphic encryption algorithm to encrypt the encoded data. In this way, the encrypted data can be transmitted or stored without exposing the original data.

[0048] Transmission or Storage of Encrypted Data: Transmit the encrypted data to other participating parties or store it in a suitable location for subsequent calculations.

[0049] Perform Homomorphic Calculations: Perform homomorphic calculations on the encrypted data in an encrypted state. This includes basic arithmetic operations such as addition and multiplication, depending on the selected homomorphic encryption scheme.

[0050] Encryption of Calculation Results: After completing the homomorphic calculations, use the public key of the homomorphic encryption algorithm to encrypt the calculation results. This ensures that the calculation results remain encrypted during transmission or storage.

[0051] Decryption of Calculation Results: If necessary, use the private key of the homomorphic encryption algorithm to decrypt the calculation results to obtain the final plaintext results. This step is optional, depending on the requirements of the application.

[0052] In the framework of homomorphic encryption, ensure that all participating parties obtain the necessary keys for encryption and decryption operations through the process of negotiating keys, and ensure that each participating party correctly uses homomorphic encryption in the calculations, including the following steps:

[0053] Key Generation: A trusted entity (e.g., a trusted third party or the initiator of the protocol) generates the public and private keys required for the homomorphic encryption algorithm. This entity is usually referred to as the key manager.

[0054] Public Key Distribution: The key manager distributes the generated public key of the homomorphic encryption algorithm to all participating parties. This is transmitted through a secure communication channel to prevent malicious attackers from eavesdropping or tampering with the key.

[0055] Private Key Distribution: The key manager distributes the generated private key of the homomorphic encryption algorithm to the participating parties according to the negotiated process. This involves negotiation protocols, key exchange and other mechanisms.

[0056] Key Negotiation Process Initiation: The participating parties initiate the key negotiation process to ensure that each participating party correctly obtains the private key for decryption and performing calculations.

[0057] Authentication: During the key negotiation process, the participating parties need to authenticate their identities to ensure that only legitimate parties obtain the private key. This is achieved through means such as digital signatures and certificates.

[0058] Key negotiation: The participating parties initiate a key negotiation protocol, negotiate to obtain the public keys of each other and the information for generating the session key through a secure communication channel.

[0059] Session key generation: The participating parties use the public keys of each other obtained through negotiation and their local private keys to generate a session key for symmetric encryption. This session key will be used for encryption and decryption operations in the homomorphic encryption calculation.

[0060] Session key distribution: The participating parties distribute the generated session key to other participating parties through a secure communication channel to ensure that all participating parties correctly use homomorphic encryption in the calculation.

[0061] Homomorphic encryption calculation: The participating parties use the negotiated session key in the calculation to perform homomorphic encryption calculations to ensure that the data in the calculation process remains encrypted.

[0062] When delegating a computing task to one or more participating parties, determine which participating parties have the right to access which computing tasks based on the authorization rules, including the following steps:

[0063] Define the computing task: Clearly define the computing task to be executed, including the required data, algorithms, and specific computing objectives. Ensure that the purpose and scope of the computing task comply with the authorization rules.

[0064] Formulate authorization rules: Based on the authorization rules, clarify which participating parties have the right to access specific types of computing tasks. This includes defining access conditions, usage conditions, time limits, etc., to ensure that the access and use of computing tasks are restricted and compliant.

[0065] Access permission list: Establish an access permission list that lists the scope of permissions for each participating party, including the types of computing tasks to be executed, the scope of specific data, etc. This helps to clarify the permissions of each participating party before executing the delegated task.

[0066] Authentication: Before delegating the task, ensure that the identities of the participating parties are authenticated to prevent unauthorized parties from participating in the computing task. This is achieved through means such as digital signatures and identity certificates for authentication.

[0067] Computing task delegation: According to the authorization rules, delegate the computing task to the participating parties with the corresponding permissions. This involves processes such as negotiating the session key and formulating a task execution plan.

[0068] Task Execution: The entrusted participating party uses the data and algorithms required for the entrusted task to execute the computing task. Ensure that the authorization rules are observed during the calculation process and do not exceed the authorized scope of authority.

[0069] Result Return: After completing the computing task, the entrusting party needs to receive the calculation result from the participating party. This requires an encrypted and secure communication mechanism to ensure the secure transmission of the result.

[0070] Auditing and Monitoring: Audit the execution of the computing task to ensure that the participating party complies with the authorization rules during the execution process. This includes recording information such as the execution status of the task, access time, and data used for subsequent auditing and monitoring.

[0071] Using a multi-party computation protocol, the participating parties perform calculations in an encrypted state. The MPC protocol allows the participating parties to perform calculations without sharing the original data and finally obtain encrypted results, including the following steps:

[0072] Select the MPC Protocol: Select an MPC protocol suitable for the requirements, which is one of the Secure Multi-Party Computation (SMPC) protocols. This includes protocols based on secret sharing, such as Shamir's Secret Sharing, or more complex protocols based on homomorphic encryption, such as protocols based on Paillier encryption or FHE.

[0073] Key Generation: The participating parties jointly generate the keys used for the MPC protocol, which includes sharing secrets or generating key pairs for homomorphic encryption.

[0074] Input Encryption: The participating parties encrypt their respective inputs to ensure that the input data remains encrypted during the calculation process. This involves using homomorphic encryption algorithms to encrypt the input data.

[0075] Key Agreement: If the protocol requires, perform key agreement to ensure that each participating party can correctly obtain the required keys for the execution of the protocol.

[0076] Computing Task Decomposition: Decompose the overall computing task into subtasks processed by each participating party. This is carried out in the manner specified by the protocol to ensure that each participating party only processes a part of the calculation without knowing the inputs of other participating parties.

[0077] Computing Task Execution: The participating parties execute their respective subtasks according to the provisions of the MPC protocol and perform calculations using the encrypted inputs. During the calculation process, each participating party can only see the encrypted intermediate results and cannot know the inputs of other participating parties.

[0078] Merge Encrypted Intermediate Results: Each participating party merges their respective encrypted intermediate results through the protocol to obtain the final encrypted result of the computation. This involves merging homomorphically encrypted or secret-shared information distributed among different participating parties.

[0079] Output Decryption: If needed, use the corresponding decryption key to decrypt the final encrypted result of the computation to obtain the plaintext result.

[0080] Decrypt the result of the computation using the homomorphic decryption method to obtain the final plaintext result. This ensures that the data during the computation process remains encrypted, and only the participating parties with the corresponding authorization can decrypt and obtain the final result, including the following steps:

[0081] Homomorphic Decryption Key Generation: Determine which participating parties are entitled to obtain the homomorphic decryption key in the protocol. This is specified during the negotiation process to ensure that only the participating parties with the corresponding authorization can decrypt the computation result.

[0082] Authorization Verification: During the process of homomorphic decryption key generation, it is necessary to verify the authorization of the participating parties to ensure that only the participating parties with the corresponding authorization can obtain the homomorphic decryption key. This involves the authentication mechanism in the protocol.

[0083] Homomorphic Decryption: The participating parties with the corresponding authorization use the homomorphic decryption key to decrypt the encrypted result of the computation. The homomorphic decryption process ensures that the computation result remains encrypted while being decrypted.

[0084] Obtain Plaintext Result: The decrypted result will be the computation result in plaintext form. This is the statistical indicator, aggregation result, or other legitimate output of the computation, depending on the goal of the protocol.

[0085] Result Usage: According to the provisions of the protocol, the obtained plaintext result needs to be used for specific purposes after the computation ends. This includes further analysis, report generation, etc.

[0086] Result Transmission: If the plaintext result needs to be transmitted to other participating parties or systems, ensure that the transmission process is secure to prevent unauthorized access or data leakage.

[0087] Audit and Monitoring: Audit and monitor the process of homomorphic decryption to ensure that the decryption operation is carried out according to the authorization rules, and record the audit information for tracing and verifying the history of the computation.

[0088] Cleanup: After the entire process ends, clean up information such as decryption keys and intermediate results to ensure that no potential risks or sensitive information are left.

[0089] Record audit information for tracing and verifying the history of the computation, including the following steps:

[0090] Logging: During the entire calculation process, record key events and operations. This includes the authentication of participating parties, key negotiation, delegated calculation tasks, intermediate steps during the calculation, etc. The log should contain sufficient information for subsequent auditing.

[0091] Timestamp: Timestamp each recorded event and operation to ensure accurate tracking of the chronological order of events. This helps to reconstruct the timeline of the calculation during auditing.

[0092] Participant identity information: Record the identity information of participating parties, including the unique identifiers of the participating parties, authentication certificates, etc. This helps to track the operations of specific participating parties.

[0093] Calculation task description: Record the description of the delegated calculation task, including information such as the type of task, the data involved, and the calculation objective. This helps to understand the context of the calculation.

[0094] Key negotiation record: If there is a key negotiation process, record the details of the key negotiation, including which participating parties negotiated the key, the time of negotiation, etc.

[0095] Calculation process record: Record the intermediate steps of the calculation, including the calculation tasks performed by each participating party, intermediate values of the calculation results, etc. This helps auditors to understand the execution process of the calculation.

[0096] Access permission record: If there is control of access permissions, record the access permissions of each participating party to data or calculation tasks to ensure that the authorized scope is not exceeded during the calculation process.

[0097] Exception event record: Record any exception events or errors, including abnormal behaviors during the calculation process, authentication failures, illegal access attempts, etc. This helps to detect potential security threats.

[0098] Auditor identity information: Record the identity information of the auditor who performs the audit, as well as the time range of the audit. This helps to ensure the legitimacy of the auditor.

[0099] Result record: Record the final result of the calculation task, including the final encrypted result and the decrypted plaintext result. This ensures that the final output of the calculation is audited.

[0100] Secure storage: Securely store the audit logs and related information to prevent unauthorized access or tampering. Secure storage includes means such as using digital signatures and encryption.

[0101] Periodic auditing: Periodically audit the recorded audit information to ensure its integrity and consistency. Periodic auditing helps to discover potential security issues and take timely measures.

[0102] Verify the results, analyze whether the calculation of the computing task is carried out according to the authorization rules, and generate corresponding decision suggestions based on the analysis results, including the following steps:

[0103] Obtain the permission matching index, decryption frequency, and identity verification error rate of the calculation results;

[0104] Comprehensively calculate the permission matching index, decryption frequency, and identity verification error rate to obtain the authorization coefficient. The expression is:

[0105]

[0106] In the formula, SQX is the authorization coefficient, piz, jmp, and sfz are the permission matching index, decryption frequency, and identity verification error rate respectively, n is the number of subtasks in the computing task, piz i represents the permission matching index of the i-th subtask, jmp i represents the decryption frequency of the i-th subtask, sfz i represents the identity verification error rate of the i-th subtask, and a1, a2, and a3 are the proportionality coefficients of the identity verification error rate, decryption frequency, and identity verification error rate respectively, and a1, a2, and a3 are all greater than 0;

[0107] After obtaining the authorization coefficient, compare the authorization coefficient with the preset authorization threshold. If the authorization coefficient is greater than or equal to the authorization threshold, analyze that the calculation of the computing task is carried out according to the authorization rules. If the authorization coefficient is less than the authorization threshold, analyze that the calculation of the computing task is not carried out according to the authorization rules;

[0108] If it is analyzed that the calculation of the computing task is not carried out according to the authorization rules, the corresponding decision suggestions are:

[0109] Abort the computing task: It is recommended to immediately abort the unauthorized computing task to prevent further unauthorized access or data leakage.

[0110] Immediately revoke the access permission: Revoke the access permission of the participating party to stop its participation in the computing task. This can be achieved by immediately retrieving keys, access tokens, etc.

[0111] Start the security emergency procedure: Start the security emergency procedure, including isolating the affected system, notifying the relevant security team, and quickly responding to unauthorized behavior.

[0112] Start the investigation procedure: Start the investigation procedure to determine how the unauthorized computing occurred and find out the reasons for this problem. This may require in-depth analysis of logs and audit information.

[0113] Fix the vulnerabilities or weaknesses: According to the investigation results, fix the vulnerabilities or weaknesses in the system to prevent future unauthorized access.

[0114] Update authorization rules: If necessary, update the authorization rules to better reflect business requirements and security policies. Ensure that the update of authorization rules is the result of comprehensive consideration of business changes and security requirements.

[0115] Notify relevant parties: Notify relevant parties, including system administrators, business owners, etc., inform them of the unauthorized execution of computing tasks, and provide corresponding suggestions and measures.

[0116] Strengthen monitoring and auditing: Strengthen the monitoring and auditing mechanisms of the system to detect unauthorized behaviors more timely and ensure that there is sufficient information for investigation.

[0117] Training and awareness improvement: Train the involved parties to improve their understanding and compliance awareness of authorization rules. Ensure that all involved parties clearly understand the importance of authorization rules.

[0118] Legal compliance: Depending on the specific situation, it may be necessary to consider legal compliance issues, including whether to report to relevant regulatory agencies and whether legal liabilities will be involved.

[0119] After the calculation is completed, clean up the intermediate results and decryption keys to ensure that no sensitive information is left, including the following steps:

[0120] Clean up intermediate results: Delete or destroy the intermediate results generated during the calculation process. This includes temporary files, cached data, etc. generated during the execution of the entrusted computing task. Ensure that these intermediate results do not remain in the system.

[0121] Clean up decryption keys: When the calculation result has been obtained and decryption is no longer required, clean up the decryption keys. This prevents unauthorized visitors from obtaining the decryption keys in the system and ensures that the calculation result is decrypted only under authorization.

[0122] Secure Erasure: For sensitive information stored on disks or other storage media, use secure erasure methods to ensure that the data is completely overwritten and cannot be recovered. This helps prevent data from being maliciously exploited.

[0123] Clean up memory: Clean up the memory used during the calculation process to ensure that sensitive information generated during the calculation process does not remain in the memory. This includes cleaning up temporary variables, buffers, etc.

[0124] Clean up keys: If temporary keys are used during the calculation process, ensure that these keys are cleaned up after the calculation is completed. This helps reduce the potential risk of key leakage.

[0125] Audit Log Retention: Retain backups of audit logs for future auditing and monitoring. Although the main data has been cleared, the retention of audit logs provides traceability and verification of the computing history.

[0126] Regular Clearing: Set up a regular clearing strategy to ensure that a large amount of unnecessary data or information does not accumulate in the system. This helps maintain the cleanliness and security of the system.

[0127] Comply with Compliance Regulations: Ensure that the clearing operations comply with the corresponding compliance regulations, especially when dealing with sensitive data or data protected by regulations. This helps prevent potential legal liabilities.

[0128] Notify Relevant Parties: After the clearing is completed, if necessary, notify the relevant parties to ensure that they are aware that the computing has ended and no longer have access to the relevant sensitive information.

[0129] Embodiment 3: A data sharing precise authorization system described in this embodiment includes a homomorphic encryption module, a key negotiation module, a task authorization module, an encrypted computing module, a result decryption module, a result verification module, and a data clearing module;

[0130] Homomorphic Encryption Module: Encrypt the original data of the participating parties using a homomorphic encryption algorithm. Homomorphic encryption allows computations to be performed in the encrypted state without decrypting the data;

[0131] Key Negotiation Module: Under the framework of homomorphic encryption, ensure that all participating parties obtain the necessary keys for encryption and decryption operations. This is achieved through the process of negotiating keys to ensure that each participating party correctly uses homomorphic encryption in the computation;

[0132] Task Authorization Module: When delegating a computing task to one or more participating parties, determine which participating parties have the right to access which computing tasks based on the authorization rules;

[0133] Encrypted Computing Module: Use a multi-party computing protocol to enable participating parties to perform computations in the encrypted state. The MPC protocol allows participating parties to perform computations without sharing the original data and finally obtain an encrypted result;

[0134] Result Decryption Module: Decrypt the result of the computation using a homomorphic decryption method to obtain the final plaintext result. This ensures that the data during the computation remains encrypted, and only the participating parties with the corresponding authorization can decrypt and obtain the final result. Record audit information for tracing and verifying the computing history;

[0135] Result Verification Module: Verify the result, analyze whether the computation of the computing task is carried out according to the authorization rules, and generate corresponding decision suggestions based on the analysis results;

[0136] Data cleaning module: After the calculation is completed, clean the intermediate results and decryption keys to ensure that no sensitive information is left behind.

[0137] A terminal includes a data sharing precise authorization system.

[0138] The above formulas are all dimensionless and take their numerical calculations. The formulas are obtained by collecting a large amount of data for software simulation to get a formula that is closest to the actual situation. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.

[0139] In the description of this specification, the descriptions referring to terms such as "one embodiment", "example", "specific example", etc. mean that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described are combined in a suitable manner in any one or more embodiments or examples.

[0140] The preferred embodiments of the present invention disclosed above are only used to help explain the present invention. The preferred embodiments do not elaborate on all the details, nor do they limit the present invention to only the specific embodiments. Obviously, many modifications and variations can be made according to the content of this specification. This specification selects and specifically describes these embodiments to better explain the principles and practical applications of the present invention, so that those skilled in the art in the relevant technical field can well understand and utilize the present invention. The present invention is only limited by the claims and their full scope and equivalents.

Claims

1. A data sharing precise authorization method, characterized by: The authorization method comprises the following steps: Encrypt the original data of the participants using a homomorphic encryption algorithm. Homomorphic encryption allows calculations to be performed in an encrypted state without decrypting the data. In the framework of homomorphic encryption, ensure that all parties have the necessary keys to perform encryption and decryption operations; When entrusting computing tasks to one or more parties, the authorization rules determine which parties have access to which computing tasks, and use multi-party computing protocols to enable the parties to perform computing in an encrypted state; Decrypt the calculated result using the homomorphic decryption method to obtain the final plaintext result and record the audit information; Verify the results, analyze whether the calculation of the computing task is carried out in accordance with the authorization rules, and generate corresponding decision suggestions based on the analysis results. After the calculation is completed, clean up the intermediate results and decryption keys.

2. According to claim 1, a data sharing precise authorization method is characterized by: Verifying the results and analyzing whether the calculation of the computing task is performed in accordance with the authorization rules includes the following steps: Obtain the permission matching index, decryption frequency, and identity verification error rate of the calculation results; The authorization coefficient is obtained by comprehensively calculating the permission matching index, decryption frequency, and identity verification error rate. The expression is: Where SQX is the authorization coefficient, piz, jmp, and sfz are the permission matching index, decryption frequency, and identity verification error rate, respectively, n is the number of subtasks in the calculation task, and piz is the i Indicates the permission matching index of the i-th subtask, jmp i represents the decryption frequency of the i-th subtask, sfz i represents the identity verification error rate of the i-th subtask, a1, a2, a3 are the proportional coefficients of the identity verification error rate, decryption frequency, and identity verification error rate, respectively, and a1, a2, a3 are all greater than 0; After obtaining the authorization coefficient, compare the authorization coefficient with the preset authorization threshold. If the authorization coefficient is greater than or equal to the authorization threshold, the calculation of the analysis and calculation task is performed according to the authorization rules. If the authorization coefficient is less than the authorization threshold, the calculation of the analysis and calculation task is not performed according to the authorization rules.

3. A data sharing precise authorization method according to claim 2, characterized in that: The original data of the participants is encrypted using a homomorphic encryption algorithm. Homomorphic encryption allows calculations to be performed in an encrypted state without decrypting the data. This includes the following steps: Generate necessary keys for the homomorphic encryption algorithm, including public key and private key. The public key is used to encrypt data, and the private key is used to decrypt calculation results. Encode the original data of the participants, encrypt the encoded data using the public key of the homomorphic encryption algorithm, transmit the encrypted data to other participants or store it, perform homomorphic calculation on the encrypted data in the encrypted state, and after completing the homomorphic calculation, encrypt the calculation result using the public key of the homomorphic encryption algorithm, and decrypt the calculation result using the private key of the homomorphic encryption algorithm to obtain the final plaintext result.

4. A data sharing precise authorization method according to claim 3, characterized in that: In the framework of homomorphic encryption, ensuring that all parties have the necessary keys to perform encryption and decryption operations involves the following steps: The public key and private key required for the homomorphic encryption algorithm are generated by a trusted key manager. The key manager distributes the generated public key of the homomorphic encryption algorithm to all participants. According to the negotiation process, the generated private key of the homomorphic encryption algorithm is distributed to the participants. The participants initiate the key negotiation process to ensure that each participant obtains the private key for decryption and calculation. During the key negotiation process, the participants are required to authenticate their identities to ensure that only legitimate participants obtain the private key. The participants initiate a key negotiation protocol and negotiate the other party's public key and information for generating a session key through a secure communication channel. The negotiated public key of the other party and the local private key are used to generate a session key for symmetric encryption. The generated session key is distributed to other participants through a secure communication channel to ensure that all participants use homomorphic encryption in calculations. The negotiated session key is used in calculations to perform homomorphic encryption calculations.

5. According to claim 4, a data sharing accurate authorization method is characterized by: When entrusting computing tasks to one or more participants, determining which participants have access to which computing tasks based on authorization rules includes the following steps: Define the computing tasks to be performed, including data, algorithms and computing targets; define access conditions, usage conditions and time limits; establish an access rights list that specifies the scope of authority of each participant, including the type of computing tasks to be performed and the scope of specific data; verify the identity of the participant before entrusting the task; and entrust the computing task to the participant with corresponding authority according to the authorization rules. The entrusted participant uses the data and algorithms required for the entrusted task to perform the computing task; after completing the computing task, the entrusting party receives the computing result from the participant.

6. A data sharing precise authorization method according to claim 5, characterized in that: Using the multi-party computing protocol, the participants can perform calculations in an encrypted state, including the following steps: The participants jointly generate keys for the MPC protocol, including sharing secrets or generating homomorphic encryption key pairs. The participants encrypt their respective inputs and use homomorphic encryption algorithms to encrypt input data. If the protocol requires, key negotiation is performed to ensure that the keys obtained by each participant are used for the execution of the protocol. The overall computing task is decomposed into subtasks handled by each participant. The participants perform their respective subtasks in accordance with the provisions of the MPC protocol and use encrypted inputs for calculations. Each participant merges their respective encrypted intermediate results through the protocol to obtain the final encrypted result of the calculation.

7. A data sharing precise authorization method according to claim 6, characterized in that: Decrypt the calculated result using the homomorphic decryption method to obtain the final plaintext result, including the following steps: In the protocol, determine which participants have the right to obtain the homomorphic decryption key to ensure that only participants with corresponding authorization can decrypt the calculation results. In the process of generating the homomorphic decryption key, the participants are authorized to verify to ensure that only participants with corresponding authorization can obtain the homomorphic decryption key. The participants with corresponding authorization use the homomorphic decryption key to decrypt the encrypted result of the calculation, and the decrypted result will be the calculation result in plain text.

8. A data sharing precise authorization system, used to implement the authorization method according to any one of claims 1 to 7, characterized in that: It includes homomorphic encryption module, key negotiation module, task authorization module, encryption calculation module, result decryption module, result verification module and data cleaning module; Homomorphic encryption module: encrypts the original data of the participants using a homomorphic encryption algorithm. Homomorphic encryption allows calculations to be performed in an encrypted state without decrypting the data. Key agreement module: Under the framework of homomorphic encryption, ensure that all participants obtain the necessary keys for encryption and decryption operations; Task authorization module: When entrusting computing tasks to one or more parties, it determines which parties have access to which computing tasks based on authorization rules; Encrypted computing module: uses multi-party computing protocols to enable participants to perform calculations in an encrypted state; Result decryption module: decrypt the calculated result using the homomorphic decryption method to obtain the final plaintext result and record the audit information: Result verification module: Verify the results, analyze whether the calculation of the calculation task is performed in accordance with the authorization rules, and generate corresponding decision suggestions based on the analysis results; Data cleaning module: After the calculation is completed, clean up the intermediate results and decryption keys.

9. A terminal, comprising: The data sharing precise authorization system as described in claim 9.