A method and system for preserving encryption and decryption of financial privacy data
Through the Feistel network structure and the conformal encryption method of dynamic key generation, the security and format compatibility issues in financial data encryption are solved, and the protection of financial data with the same encrypted output and plaintext length is achieved.
Patent Information
- Application Number
- CN202510578187.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-07
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2045-05-07
AI Technical Summary
Existing conformal encryption algorithms in the financial field are unable to adaptively generate encryption strategies based on contextual information such as user identity and behavioral characteristics, resulting in insufficient security consistency and difficulty in balancing ciphertext format compliance and encryption strength. In addition, traditional key generation mechanisms cannot support dynamic adjustment or multi-layer control, are easily tampered with, and are difficult to detect.
The Feistel network structure is adopted, and the base information in the character encoding method is used for encryption. A dynamic key is generated by a distortion factor. The data is divided into two parts for round function encryption. Exchange and addition operations are performed in each round of iteration. A check code is added to ensure that the encrypted output is consistent with the plaintext length. Dynamic replacement boxes and context perturbation mechanisms are introduced to improve security.
It ensures the security and system compatibility of financial data during transmission, storage and processing, enhances anti-attack capabilities, ensures the consistency of encrypted ciphertext and plaintext formats, and prevents format mismatch and context leakage.
Smart Images

Figure CN120086897B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of privacy data encryption and decryption, and in particular to a method and system for preserving encryption and decryption of financial privacy data. Background Art
[0002] With the rapid development of information technology, an increasing amount of sensitive information (such as personal identity information, bank card numbers, and transaction records) is being transmitted and stored over the internet. The financial industry, in particular, processes a large amount of highly sensitive data involving customer privacy, banking transactions, and other sensitive data. Therefore, protecting this sensitive information from leakage and misuse has become a critical issue that needs to be addressed. Encryption technology is widely used in data protection to ensure the security of information during transmission or storage. However, while traditional encryption technologies can effectively prevent data theft or tampering, they often cause the encrypted data to change in format, which in turn affects its processing and use. This is particularly true in the financial industry, where systems often need to preserve certain characteristics of the original data, such as length, type, and other formatting features.
[0003] Against this backdrop, conformal encryption technology emerged. Conformal encryption is a specialized encryption method whose core goal is to preserve the format characteristics of the original data during encryption, ensuring that the encrypted ciphertext and plaintext share certain structural and property characteristics. Specifically, conformal encryption requires that the format of the plaintext (such as length, character type, and numeric range) be preserved to the greatest extent possible in the encrypted data. In some cases, the format of the ciphertext and plaintext is completely identical.
[0004] Taking financial privacy data as an example, sensitive information such as bank card numbers often have specific format requirements. For example, bank card numbers are usually 19 digits long. Using conformal encryption technology, the encrypted bank card number still meets the 19-digit requirement, thus maintaining the format and validity of the original data during encryption.
[0005] However, the existing conformal encryption algorithms in the financial field are unable to adaptively generate encryption strategies based on contextual information such as user identity and behavioral characteristics, resulting in inconsistent security and difficulty in balancing ciphertext format compliance and encryption strength, affecting system docking and availability. In addition, traditional key generation mechanisms cannot support dynamic adjustment or multi-layer control key derivation, resulting in concentrated risks. Most encryption schemes do not consider the integrity verification mechanism after encryption, making them easy to tamper with without being detected. Summary of the Invention
[0006] The present invention provides a conformal encryption and decryption method for financial privacy data, wherein the conformal encryption and decryption method adopts a Feistel network structure and utilizes the base information in the character encoding method to enable the financial privacy data to be calculated in a fixed domain. The length of the data before and after encoding is consistent and the data is divided into two parts for round function encryption. In the round function encryption process, each round of iteration is only an operation such as exchange and addition, which does not change the data length. Therefore, the total length of the encrypted output is exactly the same as the plaintext, and the fixed domain of the financial privacy data is not changed. The conformal encryption and decryption of the financial data is achieved, and the Feistel network structure covers distortion factor generation and key derivation, data encoding and grouping, improved round function encryption and ciphertext checksum generation, significantly improving the security and system compatibility of financial data during transmission, storage and processing, as well as the anti-attack capability of financial privacy data.
[0007] To achieve the above objectives, the present invention provides a method for preserving encryption and decryption of financial privacy data, comprising the following steps:
[0008] S1: Extract user information associated with financial privacy data, generate a distortion factor, and use the distortion factor to perform dynamic key derivation to obtain a dynamic encryption key;
[0009] S2: Obtain financial privacy data, perform character encoding and data grouping on the financial privacy data using a dynamic encryption key, and obtain the encoding and grouping results of the financial privacy data;
[0010] S3: Using an improved round encryption method to perform multiple rounds of encryption on the encoded grouping results of the financial privacy data to generate the encrypted ciphertext of the financial privacy data;
[0011] S4: Add a check code to the encrypted ciphertext to generate an encrypted ciphertext with the check code as the conformal encrypted ciphertext of the financial privacy data, and perform verification and decryption on the conformal encrypted ciphertext.
[0012] As a further improvement method of the present invention:
[0013] Optionally, extracting user information associated with the financial privacy data to generate a distortion factor includes:
[0014] The user information user includes user ID and registration time;
[0015] The generation formula of the distortion factor is:
[0016] ;
[0017] in, Indicates splicing processing, represents the distortion factor, is the current millimeter-level timestamp, which is 13 bits long. Indicates a 16-bit system random number. Indicates that hash operation is performed using the hash function SHA-256. Indicates the first E bits to be extracted, where E represents the preset warp factor length.
[0018] Optionally, performing dynamic key derivation using the distortion factor to obtain a dynamic encryption key includes:
[0019] Generate an encryption master key using the distortion factor and the encryption system master key , and use the key derivation parameters to encrypt the master key Perform dynamic key derivation to generate multiple rounds of dynamic encryption keys. Specifically, the formula for dynamic key derivation is:
[0020] ;
[0021] ;
[0022] in, represents the dynamic encryption key for round r, , R represents the round of encryption, Represents the dynamic encryption key for round r The local round key at the nth position, , N represents the preset dynamic encryption key length, Represents the key derivation function The key derivation function The calculation result is the hash value;
[0023] Indicates extracting the nth bit of the hash value;
[0024] represents the distortion factor;
[0025] The encryption master key The generation formula is:
[0026] ;
[0027] in, Indicates the encryption system master key.
[0028] Optionally, character encoding and data grouping processing are performed on the financial privacy data in combination with the dynamic encryption key, including:
[0029] Perform digital index coding on each financial privacy category data to obtain the index coding sequence corresponding to the financial privacy category data;
[0030] The index coding sequence corresponding to each financial privacy category data is grouped and divided into two groups of sequences, namely the index coding left sequence and the index coding right sequence;
[0031] The index coding left sequence and index coding right sequence corresponding to all financial privacy category data are used as the financial privacy data coding grouping result.
[0032] Specifically, the radix information of each financial privacy category data is set, where the radix information of the bank card number, mobile phone number, and ID card number is 10, and the radix information of the tax number is 36. The bank card number, mobile phone number, and ID card number are composed of numbers, and the tax number is composed of numbers and uppercase letters. An index code mapping table for 0-9 numbers and an index code mapping table for 0-0, AZ are respectively constructed, where the digital index range of the index code mapping table for 0-9 numbers is 0-9, and the digital index range of the index code mapping table for 0-0+AZ is 0-35;
[0033] Map the numbers in the bank card number, mobile phone number, and ID card number according to the index coding mapping table of 0-9 numbers, convert the numbers into digital indexes, map the numbers in the tax number and the index coding mapping table of uppercase letters 0-9+AZ, convert the numbers and uppercase letters into digital indexes, and take each digital index as 1 bit to obtain the index coding sequence corresponding to the financial privacy category data. The index coding sequence is composed of the digital indexes of the numbers and uppercase letters in the financial privacy category data, and the number of digital indexes in the index coding sequence is consistent with the data length of the financial privacy category data. As a conformal encryption method of the present invention, an index coding mapping table is used to map financial privacy category data of different formats into digital indexes, where the financial privacy category data includes data with only numeric characters and data with numeric characters and uppercase letters. The numbers 0-9 will be mapped to 9 numeric indexes of 0-9, and 0-9+AZ will be mapped to 36 numeric indexes of 0-35. This ensures that the subsequent encryption process is calculated in a fixed domain, the length of the data before and after encoding is consistent, and the data format before and after encoding remains unchanged. For example, financial privacy category data in any format of XXXX-XX-XXXX will still have the format of YYYY-YY-YYYY after encoding, where Y is the numeric index of X.
[0034] The index code mapping table is a fixed domain.
[0035] Optionally, the index coding sequence is divided into two groups of sequences, namely the index coding left sequence and the index coding right sequence, including:
[0036] Extract the index code sequence and calculate the perturbation factor of each sequence value in the index code sequence; specifically, the index code sequence is represented as:
[0037] ;
[0038] Where H represents the index encoding sequence, Represents the index encoding sequence H sequence values, represents the i-th sequence value in the index encoding sequence H, , Indicates the number of sequence values in the index encoding sequence H;
[0039] The sequence value The disturbance factor is:
[0040] ;
[0041] in, Represents a sequence value The disturbance factor, Indicates the control index parameter, Distortion factor The Bit, Indicates the Round dynamic encryption key The local round key indexed at position i;
[0042] Indicates taking the lowest integer value;
[0043] Specifically, using the hash value The method of using the lowest-order integer value as the perturbation factor of the sequence value ensures the determinism of the perturbation factor, thereby ensuring the stability of the subsequent index coding left sequence and index coding right sequence. The lowest-order integer value can be processed using bit operations or modulo operations, without the need for random number generation operations. The randomness of the random number extraction method is stronger, but the stability of the index coding left sequence and index coding right sequence cannot be guaranteed, which will destroy the data structure of financial privacy data during the encryption and decryption process.
[0044] As an embodiment of the present invention, the bitwise operation processing method for obtaining the lowest integer value is as follows: setting the lowest bit count, generating a mask with all low count bits being 1, retaining the lowest count bits of the hash value according to the location operation, setting the remaining bits to 0, and converting the lowest count bits to an integer;
[0045] The sequence value whose perturbation factor is higher than the preset perturbation threshold is added to the index left coding sequence, and the sequence value whose perturbation factor is not higher than the preset perturbation threshold is added to the index right coding sequence, and the index coding sequence is divided into an index coding left sequence and an index coding right sequence.
[0046] Specifically, the present invention proposes an encryption perturbation mechanism based on dynamic grouping of perturbation weights to optimize data grouping and perturbation propagation paths. This mechanism, for the first time, introduces a perturbation factor as a perturbation intensity assessment metric, thereby constructing high-perturbation sequences (index-encoded left sequences) and low-perturbation sequences (index-encoded right sequences). The high-perturbation group controls the left half of the initial encryption structure, while the low-perturbation group controls the right half. This corresponds to the control of the round function structure during the round encryption process, allowing the perturbation to continue to diffuse in subsequent rounds. This significantly enhances the nonlinear perturbation and diffusion properties of the encryption path, improving the round encryption structure's resistance to differential analysis.
[0047] Optionally, an improved round encryption method is used to perform multiple rounds of encryption on the encoded grouping result of the financial privacy data, including:
[0048] The financial privacy data coding grouping result is composed of index coding results of different financial privacy category data, wherein the index coding result of the financial privacy category data includes the index coding left sequence and the index coding right sequence corresponding to the financial privacy category data;
[0049] splicing the left sequence of index codes and the right sequence of index codes corresponding to the financial privacy category data to obtain a splicing result of the financial privacy category data;
[0050] Perform R rounds of encryption on the concatenated result of the financial privacy category data, wherein each round of encryption encrypts the left data block to be encrypted and the right data block to be encrypted respectively, to obtain an encrypted left data block and an encrypted right data block in each round of encryption;
[0051] splicing the encrypted left data block and the encrypted right data block encrypted in the Rth round to obtain the privacy category encrypted ciphertext of the financial privacy category data;
[0052] The privacy category encrypted ciphertexts of all financial privacy category data are concatenated to obtain the encrypted ciphertexts of the financial privacy data.
[0053] Specifically, the round encryption process of the rth round encryption is:
[0054] Combined with user ID Generate the dynamic replacement box for round r:
[0055] ;
[0056] in, Indicates the dynamic replacement box in round r, represents the distortion factor, represents a pseudo-random permutation operation based on the seed order, Indicates seed order, using seed order Perform a reversible random permutation on the input value x and use the random permutation result as a dynamic replacement box. , Indicates user ID;
[0057] Get the right data block to be encrypted in the rth round of encryption process and the dynamic encryption key for round r , combined with the dynamic replacement box of the rth round, use the round function to encrypt the right data block And the left data block to be encrypted To encrypt:
[0058] ;
[0059] );
[0060] ;
[0061] in, Indicates the left data block to be encrypted The encryption result of Placed on the right, it realizes multi-round obfuscation encryption of the encrypted data block, that is, the encrypted right data block of the rth round encryption, Represents the left data block to be encrypted in the rth round of encryption process, represents the round function, Represents the exclusive OR operator; The number of digits and Consistent, if The number of digits is higher than , then Truncate, otherwise Fill with 0, ) and Consistent, if ) has more digits than , then ) is truncated, otherwise ) to fill with 0;
[0062] The right data block to be encrypted The encryption result is , and Place it on the left for the next round of encryption;
[0063] described For modular addition, the length of the modular addition result is the same as The purpose of this is to ensure that the encrypted data remains within the base information of the original input data. The base information is also a fixed domain for financial privacy data. If the addition operation is used directly without the modulo operation, the value may exceed the range of the original data, resulting in overflow and failure to preserve the data shape during the encryption and decryption process.
[0064] Each round of the round function encryption process only performs operations such as swapping and addition, which does not change the data length. Therefore, the total length of the encrypted output is exactly the same as the plaintext, making the encrypted ciphertext consistent with the length of the financial privacy data, thus achieving shape-preserving encryption and decryption of financial data.
[0065] Similarly, in the round function encryption process, no hash operation is involved for the encrypted data block, and only exchange operation, modular addition operation and exclusive OR operation are involved, so that the encrypted ciphertext remains in a fixed domain and within the range of base information, that is, the result of the encrypted ciphertext remains within the range of digital index, that is, within the range of 0-35;
[0066] Optionally, a check code is added to the encrypted ciphertext to generate the encrypted ciphertext with the check code as the conformal encrypted ciphertext of the financial privacy data, including:
[0067] Generate a 2-digit additional check code for the encrypted ciphertext, and add the 2-digit additional check code to the end of the encrypted ciphertext as the conformal encrypted ciphertext of the financial privacy data. Specifically, the generation formula of the 2-digit additional check code is:
[0068] ;
[0069] in, Indicates encrypted ciphertext, Represents the 2-bit additional check code of the encrypted ciphertext m, represents the cth bit of the encrypted ciphertext m, , Sum represents the number of bits of the encrypted ciphertext m, and 36 represents the maximum base information of the financial privacy category data. As a conformal encryption and decryption method of the present invention, the maximum base information of the financial privacy category data is 36, and the fixed domain of the financial privacy data, that is, the base information, is not changed during the encryption process. Therefore, the encrypted ciphertext result is still within the range of the digital index, that is, the range of 0-35. The fixed domain range is still 36, so In base 36 representation that's 2 bits.
[0070] Optionally, verify and decrypt the conformal encrypted ciphertext, including:
[0071] Recover the distortion factor based on user information and time backtracking, and reconstruct the dynamic encryption key;
[0072] Extract the last two digits of the conformal encrypted ciphertext and restore them using the inverse generation formula of the additional check code. If the restored result is consistent with the encrypted ciphertext, the verification passes. The encrypted ciphertext is the conformal encrypted ciphertext with the last two digits removed.
[0073] If the verification passes, the encrypted ciphertext in the conformal encryption ciphertext is extracted and split into privacy category encrypted ciphertexts of different financial privacy category data. The privacy category encrypted ciphertext is backtracked using the improved round encryption method in reverse order to obtain the index encoding result of the financial privacy category data, and the financial privacy data encoding grouping result is formed. The financial privacy data encoding grouping result is subjected to inverse data grouping processing and inverse character encoding processing in combination with the dynamic encryption key and the distortion factor to obtain the financial privacy data.
[0074] In order to solve the above problem, the present invention further provides an electronic device, comprising:
[0075] a memory storing at least one instruction;
[0076] Communication interfaces to enable electronic equipment to communicate; and
[0077] The processor executes the instructions stored in the memory to implement the above-mentioned method for preserving encryption and decryption of financial privacy data.
[0078] In order to solve the above problems, the present invention also provides a computer-readable storage medium, which stores at least one instruction, and the at least one instruction is executed by a processor in an electronic device to implement the above-mentioned method for preserving encryption and decryption of financial privacy data.
[0079] Compared with the existing technology, the present invention proposes a method for preserving the encryption and decryption of financial privacy data, which has the following advantages:
[0080] First, this application proposes a conformal encryption and decryption method. The conformal encryption and decryption method uses a Feistel network structure. During the key generation process, user information is introduced as context information. This context information is used to generate a distortion factor, which is used to perturb the encryption system master key. The perturbation result is used as the key derivation result. During the key derivation process, a standard KDF function is used for entropy diffusion and secure stretching, effectively defending against brute force cracking and intermediate state attacks. In addition, the addition of the distortion factor significantly enhances the key's irreproducibility. Even if an attacker intercepts all communication flows, it is difficult to restore the generation process. The method has extremely high unpredictability and resistance to differential analysis, thereby significantly improving the security, adaptability, and anti-replay capabilities of the conformal encryption structure in the financial privacy data protection scenario. During the data encryption process, the base information in the character encoding method is used to enable the financial privacy data to be calculated in a fixed domain. The length of the data before and after encoding is consistent, and the data is divided into two parts for round function encryption. In the round function encryption process, each iteration is only a swap and addition operation, which does not change the data length and the fixed domain. Therefore, the total length and fixed domain of the encrypted output are exactly the same as the plaintext, achieving conformal encryption and decryption of financial data.
[0081] The round function encryption mechanism proposed in this application utilizes a multi-round Feistel network structure and introduces dynamic substitution boxes and context perturbation mechanisms, significantly enhancing the conformal encryption capabilities of financial privacy data. This addresses technical challenges faced by traditional encryption algorithms for structured data, such as format mismatch, context leakage, and insufficient anti-analysis capabilities. First, by employing a dynamic round function structure, the encryption path is personalized for each round. Unlike traditional static substitution boxes and fixed round function structures, this application generates dynamic substitution boxes for substitution mappings in real time based on contextual information such as the user ID and distortion factor associated with the financial privacy data. This ensures that each set of data corresponds to a unique dynamic substitution box. This mechanism effectively prevents attackers from inferring the dynamic substitution box mapping relationship through fixed encryption paths or known plaintext and ciphertext pairs. Furthermore, a pseudo-random permutation mechanism based on a SHA-256 hash seed is introduced to dynamically perturb the position of the output results of each round, forming a high-entropy diffusion path for the data. Through two mechanisms, user information and system status are deeply integrated, making the ciphertext distribution highly nonlinear, thereby improving the unpredictability of encrypted data. The pseudo-random permutation mechanism is reversible, which can ensure the accurate restoration of the decryption process and resist the risk of ciphertext collision caused by input similarity. BRIEF DESCRIPTION OF THE DRAWINGS
[0082] Figure 1 A flowchart of a method for preserving encryption and decryption of financial privacy data provided by one embodiment of the present invention;
[0083] Figure 2A data flow diagram showing conformal encryption of financial privacy data provided by an embodiment of the present invention;
[0084] Figure 3 This is a functional module diagram of a financial privacy data conformal encryption and decryption system provided by one embodiment of the present invention;
[0085] Figure 3 Middle: 100 financial privacy data shape-preserving encryption and decryption system, 101 encryption parameter generation module, 102 financial privacy data encryption and decryption module, 103 data acquisition device;
[0086] The purpose, features and advantages of the present invention will be further described with reference to the accompanying drawings and in conjunction with the embodiments. DETAILED DESCRIPTION
[0087] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0088] The present invention provides a method for preserving the shape of financial data encryption and decryption. The method can be performed by at least one of a server, a terminal, or other electronic device capable of executing the method provided by the present invention. In other words, the method can be executed by software or hardware installed on a terminal or server device, where the software can be a blockchain platform. The server can include, but is not limited to, a single server, a server cluster, a cloud server, or a cloud server cluster.
[0089] Reference Figure 1 and Figure 2 , embodiment 1 of the present invention is:
[0090] S1: Extract user information associated with financial privacy data, generate a distortion factor, use the distortion factor to perform dynamic key derivation, and obtain a dynamic encryption key.
[0091] Extracting user information associated with the financial privacy data and generating a distortion factor includes:
[0092] The user information user includes user ID and registration time;
[0093] The generation formula of the distortion factor is:
[0094] ;
[0095] in, Indicates splicing processing, represents the distortion factor, is the current millimeter-level timestamp, which is 13 bits long. Indicates a 16-bit system random number. Indicates that hash operation is performed using the hash function SHA-256. Indicates the first E bits to be extracted, where E represents the preset warp factor length.
[0096] Using the distortion factor to perform dynamic key derivation to obtain a dynamic encryption key includes:
[0097] Generate an encryption master key using the distortion factor and the encryption system master key , and use the key derivation parameters to encrypt the master key Perform dynamic key derivation to generate multiple rounds of dynamic encryption keys. Specifically, the formula for dynamic key derivation is:
[0098] ;
[0099] ;
[0100] in, represents the dynamic encryption key for round r, , R represents the round of encryption, Represents the dynamic encryption key for round r The local round key at the nth position, , N represents the preset dynamic encryption key length, Represents the key derivation function The key derivation function The calculation result is the hash value;
[0101] Indicates extracting the nth bit of the hash value;
[0102] represents the distortion factor;
[0103] The encryption master key The generation formula is:
[0104] ;
[0105] in, Indicates the encryption system master key.
[0106] S2: Obtain financial privacy data, perform character encoding and data grouping on the financial privacy data using a dynamic encryption key, and obtain the encoding and grouping results of the financial privacy data.
[0107] Combining the dynamic encryption key to character encode the financial privacy data and perform data grouping processing, including:
[0108] Perform digital index coding on each financial privacy category data to obtain the index coding sequence corresponding to the financial privacy category data;
[0109] The index coding sequence corresponding to each financial privacy category data is grouped and divided into two groups of sequences, namely the index coding left sequence and the index coding right sequence;
[0110] The index coding left sequence and index coding right sequence corresponding to all financial privacy category data are used as the financial privacy data coding grouping result.
[0111] Specifically, the radix information of each financial privacy category data is set, where the radix information of the bank card number, mobile phone number, and ID card number is 10, and the radix information of the tax number is 36. The bank card number, mobile phone number, and ID card number are composed of numbers, and the tax number is composed of numbers and uppercase letters. An index code mapping table for 0-9 numbers and an index code mapping table for 0-0, AZ are respectively constructed, where the digital index range of the index code mapping table for 0-9 numbers is 0-9, and the digital index range of the index code mapping table for 0-0+AZ is 0-35;
[0112] Map the numbers in the bank card number, mobile phone number, and ID card number according to the index coding mapping table of 0-9 numbers, convert the numbers into digital indexes, map the numbers in the tax number and the index coding mapping table of uppercase letters 0-9+AZ, convert the numbers and uppercase letters into digital indexes, and take each digital index as 1 bit to obtain the index coding sequence corresponding to the financial privacy category data. The index coding sequence is composed of the digital indexes of the numbers and uppercase letters in the financial privacy category data, and the number of digital indexes in the index coding sequence is consistent with the data length of the financial privacy category data. As a conformal encryption method of the present invention, an index coding mapping table is used to map financial privacy category data of different formats into digital indexes, where the financial privacy category data includes data with only numeric characters and data with numeric characters and uppercase letters. The numbers 0-9 will be mapped to 9 numeric indexes of 0-9, and 0-9+AZ will be mapped to 36 numeric indexes of 0-35. This ensures that the subsequent encryption process is calculated in a fixed domain, the length of the data before and after encoding is consistent, and the data format before and after encoding remains unchanged. For example, financial privacy category data in any format of XXXX-XX-XXXX will still have the format of YYYY-YY-YYYY after encoding, where Y is the numeric index of X.
[0113] The index code mapping table is a fixed domain.
[0114] The index coding sequence is divided into two groups of sequences, namely the index coding left sequence and the index coding right sequence, including:
[0115] Extract the index code sequence and calculate the perturbation factor of each sequence value in the index code sequence; specifically, the index code sequence is represented as:
[0116] ;
[0117] Among them, H represents the index encoding sequence, Represents the index encoding sequence H sequence values, represents the i-th sequence value in the index encoding sequence H, , Indicates the number of sequence values in the index encoding sequence H;
[0118] The sequence value The disturbance factor is:
[0119] ;
[0120] in, Represents a sequence value The disturbance factor, Indicates the control index parameter, Distortion factor The Bit, Indicates the Round dynamic encryption key The local round key indexed at position i;
[0121] Indicates taking the lowest integer value;
[0122] Specifically, using the hash value The method of using the lowest-order integer value as the perturbation factor of the sequence value ensures the determinism of the perturbation factor, thereby ensuring the stability of the subsequent index coding left sequence and index coding right sequence. The lowest-order integer value can be processed using bit operations or modulo operations, without the need for random number generation operations. The randomness of the random number extraction method is stronger, but the stability of the index coding left sequence and index coding right sequence cannot be guaranteed, which will destroy the data structure of financial privacy data during the encryption and decryption process.
[0123] As an embodiment of the present invention, the bitwise operation processing method for obtaining the lowest integer value is as follows: setting the lowest bit count, generating a mask with all low count bits being 1, retaining the lowest count bits of the hash value according to the location operation, setting the remaining bits to 0, and converting the lowest count bits to an integer;
[0124] The sequence value whose perturbation factor is higher than the preset perturbation threshold is added to the index left coding sequence, and the sequence value whose perturbation factor is not higher than the preset perturbation threshold is added to the index right coding sequence, and the index coding sequence is divided into an index coding left sequence and an index coding right sequence.
[0125] Specifically, the present invention proposes an encryption perturbation mechanism based on dynamic grouping of perturbation weights to optimize data grouping and perturbation propagation paths. This mechanism, for the first time, introduces a perturbation factor as a perturbation intensity assessment metric, thereby constructing high-perturbation sequences (index-encoded left sequences) and low-perturbation sequences (index-encoded right sequences). The high-perturbation group controls the left half of the initial encryption structure, while the low-perturbation group controls the right half. This corresponds to the control of the round function structure during the round encryption process, allowing the perturbation to continue to diffuse in subsequent rounds. This significantly enhances the nonlinear perturbation and diffusion properties of the encryption path, improving the round encryption structure's resistance to differential analysis.
[0126] S3: Use the improved round encryption method to perform multiple rounds of encryption on the encoded grouping results of the financial privacy data to generate the encrypted ciphertext of the financial privacy data.
[0127] The improved round encryption method is used to perform multiple rounds of encryption on the encoded grouping result of the financial privacy data, including:
[0128] The financial privacy data coding grouping result is composed of index coding results of different financial privacy category data, wherein the index coding result of the financial privacy category data includes the index coding left sequence and the index coding right sequence corresponding to the financial privacy category data;
[0129] splicing the left sequence of index codes and the right sequence of index codes corresponding to the financial privacy category data to obtain a splicing result of the financial privacy category data;
[0130] Perform R rounds of encryption on the concatenated result of the financial privacy category data, wherein each round of encryption encrypts the left data block to be encrypted and the right data block to be encrypted respectively, to obtain an encrypted left data block and an encrypted right data block in each round of encryption;
[0131] splicing the encrypted left data block and the encrypted right data block encrypted in the Rth round to obtain the privacy category encrypted ciphertext of the financial privacy category data;
[0132] The privacy category encrypted ciphertexts of all financial privacy category data are concatenated to obtain the encrypted ciphertexts of the financial privacy data.
[0133] Specifically, the round encryption process of the rth round encryption is:
[0134] Combined with user ID Generate the dynamic replacement box for round r:
[0135] ;
[0136] in, Indicates the dynamic replacement box in round r, represents the distortion factor, represents a pseudo-random permutation operation based on the seed order, Indicates seed order, using seed order Perform a reversible random permutation on the input value x and use the random permutation result as a dynamic replacement box. , Indicates user ID;
[0137] Get the right data block to be encrypted in the rth round of encryption process and the dynamic encryption key for round r , combined with the dynamic replacement box of the rth round, use the round function to encrypt the right data block And the left data block to be encrypted To encrypt:
[0138] ;
[0139] ;
[0140] ;
[0141] in, Indicates the left data block to be encrypted The encryption result of Placed on the right, it realizes multi-round obfuscation encryption of the encrypted data block, that is, the encrypted right data block of the rth round encryption, Represents the left data block to be encrypted in the rth round of encryption process, represents the round function, Represents the exclusive OR operator; The number of digits and Consistent, if The number of digits is higher than , then Truncate, otherwise Fill with 0, ) and Consistent, if ) has more digits than , then ) is truncated, otherwise ) to fill with 0;
[0142] The right data block to be encrypted The encryption result is , and Place it on the left for the next round of encryption;
[0143] described For modular addition, the length of the modular addition result is the same as The purpose of this is to ensure that the encrypted data remains within the base information of the original input data. The base information is also a fixed domain for financial privacy data. If the addition operation is used directly without the modulo operation, the value may exceed the range of the original data, resulting in overflow and failure to preserve the data shape during the encryption and decryption process.
[0144] Each round of the round function encryption process only performs operations such as swapping and addition, which does not change the data length. Therefore, the total length of the encrypted output is exactly the same as the plaintext, making the encrypted ciphertext consistent with the length of the financial privacy data, thus achieving shape-preserving encryption and decryption of financial data.
[0145] Similarly, in the round function encryption process, no hash operation is involved on the encrypted data block, and only exchange operation, modular addition operation and XOR operation are involved, so that the encrypted ciphertext is still in a fixed domain and the range of the base information, that is, the result of the encrypted ciphertext is still in the range of the digital index, that is, in the range of 0-35.
[0146] The improved round encryption method described in this application breaks the limitations of traditional fixed structures between data security and adaptability, and realizes customized and conformal encryption processing of structured financial data through dynamic mapping and context perturbation. It not only ensures the controllable structure and stable length of the ciphertext, but also greatly improves the anti-attack capability, providing a feasible path and technical support for building a high-strength, format-preserving data encryption system.
[0147] As an embodiment of the present invention, if the target data contains a check digit at the end (such as an ID card or bank card number), this application provides two processing methods: retaining the check digit without performing round encryption to ensure that the format is retained as it is; recalculating the check digit after round encryption and updating it to the end of the ciphertext to ensure consistency and security; this method can be flexibly configured according to the actual application scenario.
[0148] S4: Add a check code to the encrypted ciphertext to generate an encrypted ciphertext with the check code as the conformal encrypted ciphertext of the financial privacy data, and perform verification and decryption on the conformal encrypted ciphertext.
[0149] Adding a check code to the encrypted ciphertext to generate an encrypted ciphertext with the check code as the conformal encryption ciphertext of the financial privacy data, including:
[0150] Generate a 2-digit additional check code for the encrypted ciphertext, and add the 2-digit additional check code to the end of the encrypted ciphertext as the conformal encrypted ciphertext of the financial privacy data. Specifically, the generation formula of the 2-digit additional check code is:
[0151] ;
[0152] in, Indicates encrypted ciphertext, Represents the 2-bit additional check code of the encrypted ciphertext m, represents the cth bit of the encrypted ciphertext m, , Sum represents the number of bits of the encrypted ciphertext m, and 36 represents the maximum base information of the financial privacy category data. As a conformal encryption and decryption method of the present invention, the maximum base information of the financial privacy category data is 36, and the fixed domain of the financial privacy data, that is, the base information, is not changed during the encryption process. Therefore, the encrypted ciphertext result is still within the range of the digital index, that is, the range of 0-35. The fixed domain range is still 36, so In base 36 representation that's 2 bits.
[0153] Verify and decrypt conformal encrypted ciphertext, including:
[0154] Recover the distortion factor based on user information and time backtracking, and reconstruct the dynamic encryption key;
[0155] Extract the last two digits of the conformal encrypted ciphertext and restore them using the inverse generation formula of the additional check code. If the restored result is consistent with the encrypted ciphertext, the verification passes. The encrypted ciphertext is the conformal encrypted ciphertext with the last two digits removed.
[0156] If the verification passes, the encrypted ciphertext in the conformal encrypted ciphertext is extracted and split into privacy-category encrypted ciphertexts for different financial privacy category data. The privacy-category encrypted ciphertexts are backtracked using a reverse-order improved round encryption method to obtain index encoding results for the financial privacy category data, which are then used to form a financial privacy data encoding grouping result. The financial privacy data encoding grouping result is then subjected to inverse data grouping and inverse character encoding processing using a dynamic encryption key and a distortion factor to obtain the financial privacy data. As one embodiment of the present invention, the inverse data grouping and inverse character encoding processing are performed in reverse order of the character encoding and data grouping processing.
[0157] like Figure 2 As shown in the figure, in the key derivation process, complex distortion factors and user information are used to dynamically generate keys to avoid key leakage. In the encryption process of financial privacy data, multiple rounds of obfuscated encryption are performed on the financial privacy data through encoding processing and round function encryption processing. The fixed domain and data format of the financial privacy data are not changed during the encryption process, thereby realizing conformal encryption of the financial privacy data.
[0158] Example 2:
[0159] This solution conducts comparative experiments on the aforementioned financial privacy data conformal encryption and decryption method, the AES encryption and decryption method, and the standard conformal encryption FF3-1 method. It also uses 50,000 data samples obtained from real financial transactions, including sensitive information such as ID card numbers and bank card numbers.
[0160] The comparative experimental results are shown in Table 1:
[0161] Table 1
[0162] ;
[0163] As shown in Table 1, the conformal encryption and decryption method for financial privacy data described in the present invention generates a disturbance factor and a dynamic key on the basis of maintaining the data format during the encryption process, realizes user-level ciphertext differentiation, and effectively prevents repeated encryption and leakage of the same data. Due to context disturbance and support for dynamic keys, the ciphertext output has nonlinearity and uncertainty, and the resistance to differential attacks is better.
[0164] Example 3:
[0165] like Figure 3 , which is a functional module diagram of a financial privacy data conformal-preserving encryption and decryption system 100 provided in one embodiment of the present invention, which can implement a financial privacy data conformal-preserving encryption and decryption method in Example 1.
[0166] Depending on the functionality implemented, the financial privacy data conformal encryption and decryption system 100 may include an encryption parameter generation module 101, a financial privacy data encryption and decryption module 102, and a data acquisition device 103. A module, also referred to as a unit, is a series of computer program segments that can be executed by an electronic device processor and perform a fixed function.
[0167] The encryption parameter generation module 101 is used to extract user information associated with financial privacy data, generate a distortion factor, and use the distortion factor to perform dynamic key derivation to obtain a dynamic encryption key;
[0168] The financial privacy data encryption and decryption module 102 is used to obtain financial privacy data, perform character encoding and data grouping on the financial privacy data using a dynamic encryption key to obtain a financial privacy data encoding and grouping result, perform multiple rounds of encryption on the financial privacy data encoding and grouping result using an improved round encryption method to generate encrypted ciphertext of the financial privacy data, append a check code to the encrypted ciphertext to generate an encrypted ciphertext with the check code as the conformal encrypted ciphertext of the financial privacy data, and perform verification and decryption on the conformal encrypted ciphertext;
[0169] The data collection device 103 is used to collect financial privacy data to be encrypted.
[0170] In detail, the modules in the financial privacy data conformal encryption and decryption system 100 in the embodiment of the present invention adopt the same Figure 1 The technical means are the same as the financial privacy data shape-preserving encryption and decryption method described in, and can produce the same technical effects, so I will not go into details here.
[0171] It should be understood that the embodiment is for illustration only and the scope of the patent application is not limited to this structure.
[0172] It should be noted that the serial numbers of the above-mentioned embodiments of the present invention are for descriptive purposes only and do not represent the advantages or disadvantages of the embodiments. In addition, the terms "including", "comprising" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, device, article or method comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, device, article or method. In the absence of further restrictions, an element defined by the sentence "including a ..." does not exclude the presence of other identical elements in the process, device, article or method comprising the element.
[0173] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better embodiment. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in each embodiment of the present invention.
[0174] The above are only preferred embodiments of the present invention and are not intended to limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made using the contents of the present invention description and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.
Claims
1. A method for preserving encryption and decryption of financial privacy data, characterized in that: The method comprises: S1: Extract user information associated with financial privacy data, generate a distortion factor, and use the distortion factor to perform dynamic key derivation to obtain a dynamic encryption key; The extracting user information associated with the financial privacy data and generating a distortion factor includes: The user information user includes user ID and registration time; The generation formula of the distortion factor is: ; in, Indicates splicing processing, represents the distortion factor, is the current millimeter-level timestamp, which is 13 bits long. Indicates a 16-bit system random number. Indicates that hash operation is performed using the hash function SHA-256. Indicates the first E bits to be extracted, where E represents the preset warp factor length; The step of using the distortion factor to derive a dynamic key to obtain a dynamic encryption key includes: Generate an encryption master key using the distortion factor and user ID , and use the key derivation parameters to encrypt the master key Perform dynamic key derivation to generate multiple rounds of dynamic encryption keys; S2: Acquire financial privacy data, divide the financial privacy data into financial privacy category data under multiple financial privacy categories, perform character encoding and data grouping processing on the financial privacy data using a dynamic encryption key, and obtain a financial privacy data encoding and grouping result; S3: Perform multiple rounds of encryption on the encoded grouping results of the financial privacy data using an improved round encryption method to generate encrypted ciphertext of the financial privacy data, wherein the improved round encryption method uses a distortion factor and a dynamic encryption key as main encryption parameters; S4: Add a check code to the encrypted ciphertext to generate an encrypted ciphertext with the check code as the conformal encrypted ciphertext of the financial privacy data, and verify and decrypt the conformal encrypted ciphertext to achieve conformal encryption and decryption of the financial privacy data.
2. The method for preserving encryption and decryption of financial privacy data according to claim 1, characterized in that: Combining dynamic encryption keys to perform character encoding and data grouping processing on financial privacy category data, including; Perform digital index coding on each financial privacy category data to obtain the index coding sequence corresponding to the financial privacy category data; The index coding sequence corresponding to each financial privacy category data is grouped and divided into two groups of sequences, namely the index coding left sequence and the index coding right sequence; The index coding left sequence and index coding right sequence corresponding to all financial privacy category data are used as the financial privacy data coding grouping result.
3. The method for preserving encryption and decryption of financial privacy data according to claim 2, characterized in that: The index coding sequence is divided into two groups of sequences, namely the index coding left sequence and the index coding right sequence, including: Extract the index code sequence and calculate the perturbation factor of each sequence value in the index code sequence; The sequence value whose perturbation factor is higher than the preset perturbation threshold is added to the index left coding sequence, and the sequence value whose perturbation factor is not higher than the preset perturbation threshold is added to the index right coding sequence, and the index coding sequence is divided into an index coding left sequence and an index coding right sequence.
4. The method for preserving encryption and decryption of financial privacy data according to claim 1, characterized in that: The improved round encryption method is used to perform multiple rounds of encryption on the encoded grouping result of the financial privacy data, including: The financial privacy data coding grouping result is composed of index coding results of different financial privacy category data, wherein the index coding result of the financial privacy category data includes the index coding left sequence and the index coding right sequence corresponding to the financial privacy category data; splicing the left sequence of index codes and the right sequence of index codes corresponding to the financial privacy category data to obtain a splicing result of the financial privacy category data; Perform R rounds of encryption on the concatenated result of the financial privacy category data, wherein each round of encryption encrypts the left data block to be encrypted and the right data block to be encrypted respectively, to obtain an encrypted left data block and an encrypted right data block in each round of encryption, where R represents the number of rounds of encryption; splicing the encrypted left data block and the encrypted right data block encrypted in the Rth round to obtain the privacy category encrypted ciphertext of the financial privacy category data; The privacy category encrypted ciphertexts of all financial privacy category data are concatenated to serve as the encrypted ciphertext of the financial privacy data.
5. The method for preserving encryption and decryption of financial privacy data according to claim 1, characterized in that: Adding a check code to the encrypted ciphertext to generate an encrypted ciphertext with the check code as the conformal encryption ciphertext of the financial privacy data, including: Generate a 2-digit additional check code for the encrypted ciphertext, and add the 2-digit additional check code to the end of the encrypted ciphertext as the conformal encryption ciphertext of the financial privacy data.
6. The method for preserving encryption and decryption of financial privacy data according to claim 5, characterized in that: Verify and decrypt conformal encrypted ciphertext, including: Recover the distortion factor based on user information and time backtracking, and reconstruct the dynamic encryption key; Extract the last two digits of the conformal encrypted ciphertext and restore them using the inverse generation formula of the additional check code. If the restored result is consistent with the encrypted ciphertext, the verification passes. The encrypted ciphertext is the conformal encrypted ciphertext with the last two digits removed. If the verification passes, the encrypted ciphertext in the conformal encryption ciphertext is extracted and split into privacy category encrypted ciphertexts of different financial privacy category data. The privacy category encrypted ciphertext is backtracked using the improved round encryption method in reverse order to obtain the index encoding result of the financial privacy category data, and the financial privacy data encoding grouping result is formed. The financial privacy data encoding grouping result is subjected to inverse data grouping processing and inverse character encoding processing in combination with the dynamic encryption key and the distortion factor to obtain the financial privacy data.
7. A financial privacy data shape-preserving encryption and decryption system, characterized by: The financial privacy data shape-preserving encryption and decryption system includes a server and a data acquisition device. The server includes an encryption parameter generation module and a financial privacy data encryption and decryption module: The encryption parameter generation module is used to extract user information associated with the financial privacy data, generate a distortion factor, and use the distortion factor to perform dynamic key derivation to obtain a dynamic encryption key; The financial privacy data encryption and decryption module is used to obtain financial privacy data, perform character encoding and data grouping on the financial privacy data using a dynamic encryption key to obtain a financial privacy data encoding and grouping result, perform multiple rounds of encryption on the financial privacy data encoding and grouping result using an improved round encryption method to generate encrypted ciphertext of the financial privacy data, append a check code to the encrypted ciphertext to generate an encrypted ciphertext with the check code as the conformal encrypted ciphertext of the financial privacy data, and perform verification and decryption on the conformal encrypted ciphertext; The data collection device is used to collect financial privacy data to be encrypted; To implement the financial privacy data conformal encryption and decryption method as described in any one of claims 1-6.
Citation Information
Patent Citations
Object identification method and device, electronic equipment and storage medium
CN118797670A
Switching between speech recognition systems
WO2020117505A1