Multi-layer encryption system for electronic bidding document

By introducing multi-layer encryption modules and abnormal analysis technology into the electronic bid encryption system, the problem of difficulty in detecting early decryption and traceability of leaked keys in the existing technology is solved, and higher bid fairness and anti-leakage capability of the encryption system are achieved.

CN120200747AActive Publication Date: 2025-06-24GUANGDONG ZHILIAN IND TECHNOLOGY CO LTD

Patent Information

Application Number
CN202510391368.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-31
Publication Date
2025-06-24
Estimated Expiration
2045-03-31

AI Technical Summary

Technical Problem

The existing electronic bid encryption methods are difficult to detect early decryption and cannot effectively trace the leaked keys, making it difficult for bidders to determine whether there is malicious competition among competitors.

Method used

The electronic bid multi-layer encryption system is adopted to detect the abnormal behavior of the bidder and the possibility of early decryption through quotation abnormality analysis and bidding strategy change detection. Use the key segmentation module, the false quotation generation and binding module, the advance decryption verification module, the leakage traceability module and the sequential decryption module to generate surface bids and false quotations, and conduct correlation analysis to identify the leaked key combination.

Benefits of technology

Effectively detect and prevent early decryption behavior, identify potential malicious collusion, improve the fairness of the bidding process, and track the source of leakage through traceability modules to enhance the anti-leakage capability of the encryption system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200747A_ABST
    Figure CN120200747A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-layer encryption system for an electronic bidding document, particularly relates to the technical field of bidding document encryption, and is used for solving the problems that advanced decryption of an encrypted bidding document is difficult to detect, and a leakage path is difficult to efficiently trace to the source. Comprising a secret key segmentation module, a false quotation generation and binding module, an advanced decryption verification module, a leakage traceability module and a sequential decryption module, a real electronic bidding document is encrypted to generate an encrypted bidding document, a main secret key is segmented by adopting a threshold encryption scheme, a Hash function and random disturbance are combined, a surface bidding document is generated according to the real electronic bidding document, and the surface bidding document is encrypted. The method comprises the following steps: calculating a false quotation of a surface bidding document according to different sub-key combinations used for advanced decryption, generating a sub-key combination-false quotation mapping, carrying out matching evaluation on whether the false quotation of the surface bidding document is decrypted in advance by combining abnormal quotation detection and quotation mode robustness, determining a suspicious key combination used for advanced decryption, and judging whether the false quotation of the surface bidding document is decrypted in advance. And the encrypted bidding document is decrypted in a time window allowed by bid opening.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of tender encryption, and more specifically, the present invention is an electronic tender multi-layer encryption system. Background Art

[0002] Existing electronic bidding platforms generally require the bidders to encrypt and transmit the electronic tenders and store the encrypted electronic tenders. The greatest risk of leakage of electronic tenders lies in the leakage of the private key kept within the bidding team. Using multi-party key splitting to decompose the private key into multiple parts can effectively increase the difficulty of the key being completely stolen. However, the decryption scheme based on threshold setting does not necessarily require the eavesdropper to obtain all the split keys. Only obtaining a part of the keys that meet the threshold setting can decrypt the electronic tender. Before the bid opening, the electronic tender may be prematurely decrypted due to the leakage of the bidder's private key. Premature decryption generally leaves traces, but the traces of premature decryption are not completely impossible to be erased. As a result, after the bid opening, the bidder may be targeted by other competing parties, but it is difficult to determine whether other bidders are engaging in malicious competition based on the known quotes of the bidder.

[0003] In traditional electronic tender encryption methods, once the tender is encrypted, the system mainly relies on methods such as threshold encryption, digital signature, and time lock to ensure the security of the tender. However, traditional methods are difficult to detect premature decryption behavior, cannot effectively trace the leaked key, and are even more difficult to trace which of the multiple sub-keys that have been decomposed is the specific leaked key.

[0004] To solve the above defects, a technical solution is now proposed. Summary of the Invention

[0005] To overcome the above defects of the prior art, an embodiment of the present invention provides an electronic tender multi-layer encryption system. Through abnormal quotation analysis, it detects whether the bidder's quotation deviates from the historical bidding distribution. Through the detection of changes in bidding strategies, it analyzes whether the bidder has a sudden change in bidding strategies. It can not only discover the abnormal bidding behavior of the bidder, but also judge the possibility of premature decryption, breaking through the limitation that traditional encryption methods cannot detect leaks. Through correlation analysis, it calculates the correlation between the bidder's quotation and each false quotation. By matching the leaked false quotations, it reversely deduces the combination of leaked keys. It can not only discover premature decryption behavior, but also identify whether there is malicious bid rigging among bidders, thereby improving the fairness of bidding.

[0006] To achieve the above object, the present invention provides the following technical solution: including a key splitting module, a false quotation generation and binding module, a premature decryption verification module, a leakage traceability module, and an order decryption module;

[0007] The key splitting module is used to encrypt the real electronic tender document to generate an encrypted tender document, split the master key using a threshold encryption scheme, and transmit the several sub-keys generated by the splitting to several members in the tender team for storage;

[0008] The false quotation generation and binding module is used to combine a hash function and random perturbation, generate a surface tender document according to the real electronic tender document, calculate the false quotation of the surface tender document according to different sub-key combinations used for early decryption, and generate a sub-key combination - false quotation mapping;

[0009] The early decryption verification module is used to detect abnormal quotations according to the historical quotation data of the bidders collected, calculate the robustness of the quotation pattern of the bidders through time series analysis, and conduct a matching evaluation on whether the false quotation of the surface tender document is decrypted in advance by combining abnormal quotation detection and quotation pattern robustness. If it is judged that the encrypted tender document is decrypted in advance, leakage tracing is carried out. If it is judged that the encrypted tender document is not decrypted in advance, opening and decryption are carried out;

[0010] The leakage tracing module is used to determine the suspicious key combination used during early decryption according to the matching evaluation result, issue an alarm, and verify the members who save any sub-key in the suspicious key combination;

[0011] The sequential decryption module is used to, within the time window allowed for opening the tender, take any sub-key as the activation key input, generate the input order of subsequent sub-keys according to the input time of the activation key, and decrypt the encrypted tender document according to the sub-key input order.

[0012] In a preferred embodiment, the method for splitting the master key using a threshold encryption scheme is as follows:

[0013] Encrypt the real electronic tender document to generate an encrypted tender document. The master key of the encrypted tender document is K. Split the master key K using a threshold encryption scheme. The threshold encryption scheme is (k, n), where n is the total number of sub-keys into which the master key K is split, and k is the minimum number of sub-keys required to reconstruct the master key K. Any k sub-keys can restore the master key K.

[0014] In a preferred embodiment, the method for generating a surface tender document according to the real electronic tender document is as follows:

[0015] Define the real electronic tender document as Pt, and the real quotation in the real electronic tender document is Qt. Then the generation method of the surface tender document is Pf = Mask(Pt, Qf). In the formula, the surface tender document is Pf, the false quotation is Qf, Mask() is a masking transformation, and the expression formula of the masking transformation is In the formula, H() is a hash function, is the bitwise exclusive OR operation, and || is used to connect multiple inputs into a hash input. Salt is a random salt value.

[0016] In a preferred embodiment, the logic for obtaining false quotes in the surface tender is as follows:

[0017] Calculate the hash value for each sub-key combination Ki that meets the threshold requirements. The calculation expression is Hi = H(Ki), where Hi is the hash value of the sub-key combination Ki, and H(Ki) is the unique identifier for performing the hash calculation on the sub-key combination Ki;

[0018] Calculate the basic perturbation value Bpv for each sub-key combination Ki that meets the threshold requirements using the hash value Hi. The calculation expression is Bpv = rand(Hi) mod R, where rand(Hi) is a random number generated based on Hi, R is the perturbation range, mod is the modulo value, and mod R is used to constrain the perturbation result within the range [0, R - 1];

[0019] Then the calculation expression for the false quote is Qf = Qt + Bpv.

[0020] In a preferred embodiment, the method for detecting abnormal quotes based on the historical quote data of bidders collected is as follows:

[0021] Set a time window for a tender round, collect the historical quote data of bidders within the time window of the tender round, and calculate the mean and standard deviation of the historical quote data to generate a normal quote distribution. The normal quote distribution is N(μ, σ), where μ is the mean of the historical quote data, and the calculation expression is In the formula, X e is the bid price in the e-th round of bidding, N is the number of historical bidding rounds, and σ is the standard deviation of the historical quote data. The calculation expression is

[0022] Set the abnormal threshold as Exth, and calculate the Z-score of the bidder's quote data in this round as where X is the bidder's quote data in this round. If the Z-score is greater than or equal to the abnormal threshold Exth, record that the bidder's quote in this round is abnormal and mark the electronic tender as a 1A signal. If the Z-score is less than the abnormal threshold Exth, record that the bidder's quote in this round is normal and mark the electronic tender as a 1B signal.

[0023] In a preferred embodiment, the method for calculating the quote pattern robustness of bidders through time series analysis is as follows:

[0024] Construct a time series based on the historical quote data of bidders as Sc = {B t-v}, where B t-v is the quote data in the previous v rounds before this round. Then calculate the quote pattern robustness of the bidder as B tThis is the quotation data for this round;

[0025] Set the strategy change threshold as Pcth. If |Gc| is greater than or equal to the strategy change threshold Pcth, record that the bidder's strategy is abnormal in this round and mark the electronic tender as 0A signal. If |Gc| is less than the strategy change threshold Pcth, record that the bidder's strategy is normal in this round and mark the electronic tender as 0B signal.

[0026] In a preferred embodiment, the logic for performing a matching evaluation on whether the false quotation in the surface tender is decrypted in advance by combining abnormal quotation detection and quotation mode robustness is as follows:

[0027] If the electronic tender is marked as 1A signal and 0A signal, update the electronic tender signal to 00 signal. The bidder's quotation is abnormal and the quotation strategy mutates. Perform a correlation analysis between the bidder's quotation and each false quotation to determine the leaked false quotation;

[0028] If the electronic tender is marked as 1A signal and 0B signal, update the electronic tender signal to 10 signal. The bidder's quotation is abnormal and the quotation strategy is stable. Do not perform a correlation analysis between the bidder's quotation and each false quotation;

[0029] If the electronic tender is marked as 1B signal and 0A signal, update the electronic tender signal to 01 signal. The bidder's quotation is normal and the quotation strategy mutates. Do not perform a correlation analysis between the bidder's quotation and each false quotation;

[0030] If the electronic tender is marked as 1B signal and 0B signal, update the electronic tender signal to 11 signal. The bidder's quotation is normal and the quotation strategy is stable. Do not perform a correlation analysis between the bidder's quotation and each false quotation.

[0031] In a preferred embodiment, the method for performing a correlation analysis between the bidder's quotation and each false quotation to determine the leaked false quotation is as follows:

[0032] Calculate the correlation between the bidder's quotation and each false quotation through the Pearson correlation coefficient. The calculation expression is In the formula, r is the correlation between the bidder's quotation and each false quotation, is the covariance between the bidder's quotation and each false quotation. The calculation expression is M is the total number of historical tender quotation data, is the jth bidder's quotation, is the false quotation generated by the sub-key combination Ki in the jth bid, σB comp is the standard deviation of the bidder's quotation. The calculation expression is Among them, is the mean value of the historical bidder quotes, and the calculation expression is is the standard deviation of the false quotes, and the calculation expression is is the mean value of the false quotes, and the calculation expression is

[0033] Set the relevant threshold as Rth. When the calculated Pearson correlation coefficient r is greater than or equal to the relevant threshold Rth, mark the false quote as a relevant quote and record that there is a leakage risk for this false quote. When the calculated Pearson correlation coefficient r is less than the relevant threshold Rth, mark the false quote as an irrelevant quote and record that there is no leakage risk for this false quote.

[0034] In a preferred embodiment, if there is a false quote with a leakage risk, determine the sub-key combination corresponding to the false quote through the sub-key combination - false quote mapping, mark the sub-key combination as a suspicious key combination, and warn the administrator of the multi-layer encryption system of the electronic tender to verify the holders of the sub-keys in the suspicious key combination;

[0035] If there is no false quote with a leakage risk, within the time window allowed for the opening of bids, input any one sub-key as the activation key, generate the input order of the subsequent sub-keys according to the input time of the activation key, and decrypt the encrypted tender according to the input order of the sub-keys.

[0036] In a preferred embodiment, record the input timestamp after the activation key is input to ensure that the decryption order is generated based on the dynamic timestamp. Use the hash function to calculate the input order of the subsequent sub-keys. The calculation expression is Seed = H(T0, Kinit) mod n, where Kinit is the activation key, T0 is the input timestamp of the activation key, H() is the hash function, n is the total number of sub-keys, mod is the modulo value, mod n ensures that the generated index is within the key range, Seed is the seed value used to generate the key input order, and the input order of the subsequent sub-keys is P = Permute({1, 2,..., n}, Seed), where Permute() is the random permutation function. Input the remaining k - 1 sub-keys in sequence according to the input order P of the subsequent sub-keys to decrypt the encrypted tender;

[0037] If the input order of the sub-keys is correct and the sub-key combination meets the requirements of the threshold scheme, the real electronic tender can be decrypted;

[0038] If the input order of the sub-keys is incorrect, the surface tender can be decrypted and the real electronic tender cannot be obtained.

[0039] In the above technical solution, the technical effects and advantages provided by the present invention are:

[0040] By generating a surface bidding document, an early decryptor cannot obtain the true bid price but only a false bid price, thus preventing the bid price of the electronic bidding document from being exploited by competitors. Even if the electronic bidding document is stolen during storage or transmission, they can only see the surface bidding document, which does not affect the decryption process of the final true bidding document. Generating the surface bidding document based on the true bidding document effectively improves the anti-disclosure ability of the electronic bidding document. Even if the encrypted part is cracked, there is still additional disguise protection to effectively prevent competitors from adjusting the bid price in advance through illegal means.

[0041] By generating a sub-key combination - false bid price mapping, different sub-key combinations decrypt different bid prices in advance. Even if a thief obtains some keys, they cannot accurately infer the true bid price. Each false bid price is uniquely bound to a key combination. By observing the changes in the bid price of the bidder, it is possible to evaluate whether sub-key leakage has occurred and trace the specific source of the leakage. The false bid price is not fixed but is generated based on a hash function and random perturbation, effectively blocking the way of reverse reasoning for the true bid price. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings described below are only some embodiments recorded in the present invention. For those of ordinary skill in the art, other drawings can also be obtained based on these drawings.

[0043] Figure 1 It is a system module diagram of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0045] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0046] Embodiment 1: Please refer to Figure 1 As shown, the present invention is a multi-layer encryption system for electronic bidding documents, including a key splitting module, a false bid price generation and binding module, an early decryption verification module, a leakage tracing module, and an ordered decryption module;

[0047] The key splitting module is used to encrypt the real electronic bidding document to generate an encrypted bidding document, split the master key using a threshold encryption scheme, and separately transmit the several sub-keys generated by the split to several members in the bidding team for storage;

[0048] The false quotation generation and binding module is used to combine a hash function with random perturbation to generate a surface tender document according to the real electronic tender document, calculate the false quotation of the surface tender document according to different sub-key combinations used for early decryption, and generate a sub-key combination - false quotation mapping;

[0049] The early decryption verification module is used to detect abnormal quotations based on the historical quotation data of the bidders collected, calculate the robustness of the bidders' quotation patterns through time series analysis, and conduct a matching evaluation on whether the false quotation of the surface tender document is prematurely decrypted by combining abnormal quotation detection and quotation pattern robustness. If it is judged that the encrypted tender document is prematurely decrypted, leakage tracing is carried out. If it is judged that the encrypted tender document is not prematurely decrypted, opening and decryption are carried out;

[0050] The leakage tracing module is used to determine the suspicious key combination used during early decryption according to the matching evaluation result, issue an alarm, and verify the members who save any sub-key in the suspicious key combination;

[0051] The sequential decryption module is used to, within the time window allowed for opening the tender, take any one sub-key as the activation key input, generate the input order of the subsequent sub-keys according to the input time of the activation key, and decrypt the encrypted tender document according to the sub-key input order.

[0052] After encrypting the real electronic tender document, an encrypted tender document is generated. The main key of the encrypted tender document is K. The threshold encryption scheme is used to split the main key K. The threshold encryption scheme is (k,n), where n is the total number of sub-keys into which the main key K is split, and k is the minimum number of sub-keys required to reconstruct the main key K. Any k sub-keys can restore the main key K. The split sub-keys are separately saved by the members of the tender team, and each sub-key is held by a unique member.

[0053] The tender document derivation module is used to fabricate false information. The method for generating a surface tender document according to the real electronic tender document is as follows:

[0054] Define the real electronic tender document as Pt, and the real quotation Qt is included in the real electronic tender document. Then the generation method of the surface tender document is Pf = Mask(Pt, Qf). In the formula, the surface tender document is Pf, the false quotation is Qf, Mask() is the masking transformation, and the expression formula of the masking transformation is In the formula, H() is the hash function, is the bitwise exclusive OR operation, and || is used to connect multiple inputs into a hash input. Salt is the random salt value;

[0055] It should be noted that the surface tender document modifies the quotation field, but keeps the format, terms, and technical parameters of the real tender document unchanged. A slight perturbation is introduced in the non-quotation field to prevent inferring the real tender document through text comparison, that is, the surface tender document has the same format as the real tender document but different quotations.

[0056] The logic for obtaining false quotes in the surface tender document is as follows:

[0057] Calculate the hash value for each sub-key combination Ki that meets the threshold requirements. The calculation expression is Hi = H(Ki), where Hi is the hash value of the sub-key combination Ki, and H(Ki) is the unique identifier for performing a hash calculation on the sub-key combination Ki;

[0058] Calculate the basic perturbation value Bpv for each sub-key combination Ki that meets the threshold requirements using the hash value Hi. The calculation expression is Bpv = rand(Hi) mod R, where rand(Hi) is a random number generated based on Hi, R is the perturbation range, mod is the modulo value, and mod R is used to constrain the perturbation result within the range [0, R - 1];

[0059] Then the calculation expression for the false quote is Qf = Qt + Bpv;

[0060] It should be noted that the false quote obtained based on the hash function and the random perturbation term is an irreversible hash mapping, ensuring that the false quotes obtained from different sub-key combinations during pre-decryption are different. The secure hash function ensures that the quote corresponding to each key combination is unique. The modulo value controls the amplitude of the quote change, and the random perturbation term is used to prevent attackers from reverse-inferring the key through the hash. The specific settings of the hash coefficient and the perturbation range are set by professionals in this field themselves.

[0061] Specifically, if the threshold encryption scheme divides the main key of the encrypted tender document, divides the main key K into (3, 5), the total number of sub-keys is 5, and the minimum number of sub-key copies required to reconstruct the main key K is 3, then the sub-key combination - false quote mapping is as follows:

[0062] Sub - key combination (Ki) Hash value Hi Base perturbation value Bpv False offer Qf {k1,k2,k3} H1 +2.3% 1.023 million {k1,k3,k5} H2 -1.8% 982,000 {k3,k4,k5} H3 +0.5% 1.005 million … … … …

[0063] Table 1 Sub-key combination - false quote mapping

[0064] Since the electronic bidding system usually only allows the upload of one bid document, it is not possible to directly submit a fake bid and retain the real bid. The surface bid is a masking transformation based on the real bid, which looks no different from an ordinary bid externally, but the core quotation is false. Before the bid opening, the early decryptor cannot obtain the real quotation and can only obtain the false quotation, thus preventing the quotation of the electronic bid from being exploited by competitors. When stealing the electronic bid during storage or transmission, only the surface bid can be seen, which does not affect the final decryption process of the real bid. Generating the surface bid based on the real bid effectively improves the anti-disclosure ability of the electronic bid. Even if the encrypted part is cracked, there is still additional disguise protection, effectively preventing competitors from adjusting the quotation in advance through illegal means. Different sub-key combinations decrypt different quotations in advance. Even if the thief obtains some keys, it is impossible to accurately infer the real quotation. Each false quotation is uniquely bound to the key combination. Whether sub-key leakage has occurred can be evaluated through the change in the bidder's quotation, and the specific leakage source can be traced. The false quotation is not fixed but generated based on the hash function and random perturbation, effectively blocking the way of reverse reasoning of the real quotation.

[0065] The early decryption verification module is used to detect abnormal quotations according to the historical quotation data of the bidders collected, calculate the robustness of the bidders' quotation patterns through time series analysis, and conduct a matching evaluation on whether the false quotation of the surface bid is prematurely decrypted by combining abnormal quotation detection and quotation pattern robustness. If it is judged that the encrypted bid has been prematurely decrypted, leakage tracing is carried out. If it is judged that the encrypted bid has not been prematurely decrypted, bid opening decryption is carried out;

[0066] The method for detecting abnormal quotations according to the historical quotation data of the bidders collected is as follows:

[0067] Set a time window for a bidding round, collect the historical quotation data of the bidders within the time window of the bidding round, and calculate the mean and standard deviation of the historical quotation data to generate a normal quotation distribution. The normal quotation distribution is N(μ,σ), where μ is the mean of the historical quotation data, and the calculation expression is In the formula, X e is the e-th round of bidding quotation, N is the number of historical quotation rounds, and σ is the standard deviation of the historical quotation data. The calculation expression is

[0068] Set the abnormal threshold as Exth, and calculate the Z-score of the bidders' quotation data in this round as where X is the bidders' quotation data in this round. If the Z-score is greater than or equal to the abnormal threshold Exth, record that the bidders' quotation in this round is abnormal and mark the electronic bid as a 1A signal. If the Z-score is less than the abnormal threshold Exth, record that the bidders' quotation in this round is normal and mark the electronic bid as a 1B signal.

[0069] The method for calculating the robustness of the bidder's quotation pattern through time series analysis is as follows:

[0070] Construct a time series Sc = {B t-v} based on the historical quotation data of the bidder. B t-v is the quotation data of the previous v rounds before this round. Then, calculate the robustness of the bidder's quotation pattern as B t is the quotation data of this round;

[0071] Set the strategy change threshold as Pcth. If |Gc| is greater than or equal to the strategy change threshold Pcth, record that the bidder's strategy is abnormal in this round and mark the electronic tender as 0A signal. If |Gc| is less than the strategy change threshold Pcth, record that the bidder's strategy is normal in this round and mark the electronic tender as 0B signal.

[0072] The logic for matching and evaluating whether the false quotation in the surface tender is decrypted in advance by combining abnormal quotation detection and quotation pattern robustness is as follows:

[0073] If the electronic tender is marked as 1A signal and 0A signal, update the electronic tender signal to 00 signal. The bidder's quotation is abnormal and the quotation strategy mutates. Conduct a correlation analysis between the bidder's quotation and each false quotation to determine the leaked false quotation;

[0074] If the electronic tender is marked as 1A signal and 0B signal, update the electronic tender signal to 10 signal. The bidder's quotation is abnormal and the quotation strategy is stable. Do not conduct a correlation analysis between the bidder's quotation and each false quotation;

[0075] If the electronic tender is marked as 1B signal and 0A signal, update the electronic tender signal to 01 signal. The bidder's quotation is normal and the quotation strategy mutates. Do not conduct a correlation analysis between the bidder's quotation and each false quotation;

[0076] If the electronic tender is marked as 1B signal and 0B signal, update the electronic tender signal to 11 signal. The bidder's quotation is normal and the quotation strategy is stable. Do not conduct a correlation analysis between the bidder's quotation and each false quotation.

[0077] The method for conducting a correlation analysis between the bidder's quotation and each false quotation to determine the leaked false quotation is as follows:

[0078] Calculate the correlation between the bidder's quotation and each false quotation through the Pearson correlation coefficient. The calculation expression is In the formula, r is the correlation between the bidder's quotation and each false quotation, is the covariance between the bidder's quotation and each false quotation. The calculation expression is M is the total number of historical bid price data, is the j-th bidder's quotation, is the false quotation generated by the sub-key combination Ki in the j-th bid, σB comp is the standard deviation of the bidder's quotation, and the calculation expression is where, is the mean value of the historical bidder's quotation, and the calculation expression is is the standard deviation of the false quotation, and the calculation expression is is the mean value of the false quotation, and the calculation expression is

[0079] Set the relevant threshold as Rth. When the calculated Pearson correlation coefficient r is greater than or equal to the relevant threshold Rth, mark the false quotation as a relevant quotation and record that there is a leakage risk for this false quotation. When the calculated Pearson correlation coefficient r is less than the relevant threshold Rth, mark the false quotation as an irrelevant quotation and record that there is no leakage risk for this false quotation.

[0080] If there is a false quotation with a leakage risk, determine the sub-key combination corresponding to this false quotation through the sub-key combination - false quotation mapping, mark this sub-key combination as a suspicious key combination, and warn the administrator of the multi-layer encryption system of the electronic tender to verify the holders of the sub-keys in the suspicious key combination;

[0081] If there is no false quotation with a leakage risk, within the time window allowed for bid opening, input any one sub-key as the activation key, generate the input order of the subsequent sub-keys according to the input time of the activation key, and decrypt the encrypted tender according to the input order of the sub-keys.

[0082] After the activation key is input, record the input timestamp to ensure that the decryption order is generated based on the dynamic timestamp. Use the hash function to calculate the input order of the subsequent sub-keys. The calculation expression is Seed = H(T0, Kinit) mod n, where Kinit is the activation key, T0 is the input timestamp of the activation key, H() is the hash function, n is the total number of sub-keys, mod is the modulo value, mod n ensures that the generated index is within the key range, Seed is the seed value used to generate the key input order, and the input order of the subsequent sub-keys is P = Permute({1, 2,..., n}, Seed), where Permute() is the random permutation function. Input the remaining k - 1 sub-keys in sequence according to the input order P of the subsequent sub-keys to decrypt the encrypted tender;

[0083] If the input order of the sub-keys is correct and the combination of sub-keys meets the requirements of the threshold scheme, the real electronic tender document can be decrypted.

[0084] If the input order of the sub-keys is incorrect, the surface tender document can be decrypted and the real electronic tender document cannot be obtained.

[0085] Permute() is used to rearrange the order of the sub-keys according to Seed to ensure that the input order of the sub-keys is unpredictable.

[0086] Traditional methods usually require that enough sub-keys be collected to decrypt. Therefore, as long as some sub-keys are leaked, the attacker can decrypt in advance and obtain the content of the real electronic tender document. Even if threshold encryption is adopted, once the threshold requirement is met, the decryption process is still fixed. The attacker can use the pre-obtained sub-keys for offline decryption. However, for the encryption method provided in this application, obtaining only enough sub-keys is not sufficient for decryption. It must be input in the correct time window according to the dynamically generated key input order to successfully decrypt. Even if some sub-keys are leaked, it is difficult to obtain the correct key input order before the tender opening time, so it is impossible to decrypt in advance. Traditional methods usually rely on static keys, that is, the keys themselves are fixed and do not change with time. Once the key is leaked, it can be decrypted at any time without being restricted by the tender opening time limit. In this application, by activating the key input time and calculating the sub-key order, the decryption order changes dynamically. Traditional encryption methods generally cannot detect sub-key leakage because the attacker can decrypt the data secretly without leaving a trace. Even if there is a risk of early decryption, it is impossible to trace back the specific leaked sub-keys because the functions of all sub-keys are equivalent. This application adopts the design of combining the surface tender document with the associated key combination. Each sub-key combination corresponds to a different false quotation. Early decryption can only obtain false quotations. After the tender opening, by analyzing the tender quotations of other bidders, the leaked sub-key combination can be effectively traced back to lock the potential leakage path.

[0087] The above formulas are all dimensionless and take their numerical values for calculation. The formula is obtained by collecting a large amount of data and performing software simulation to get a formula closest to the real situation. The preset parameters in the formula are set by those skilled in the art according to the actual situation.

[0088] Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working process of the above-described system can refer to the corresponding process in the foregoing method embodiment and will not be elaborated here.

[0089] As described above, it is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims described above.

Claims

1. The multi-layer encryption system for electronic tender documents is characterized by: It includes key splitting module, false quotation generation and binding module, advance decryption verification module, leakage tracing module and sequential decryption module; The key splitting module is used to encrypt the real electronic bid document to generate an encrypted bid document, split the master key using a threshold encryption scheme, and transmit the resulting subkeys to several members of the bidding team for storage; The false quotation generation and binding module is used to combine the hash function and random perturbation to generate a surface bid based on the real electronic bid, calculate the false quotation of the surface bid based on the different subkey combinations used for pre-decryption, and generate a subkey combination-false quotation mapping; The pre-decryption verification module is used to detect abnormal bids based on the collected historical bid data of bidders, calculate the robustness of bidders' bid patterns through time series analysis, and conduct a matching assessment on whether the false bids in the surface bids have been decrypted in advance by combining abnormal bid detection and the robustness of the bid patterns. If it is determined that the encrypted bids have been decrypted in advance, the leakage is traced; if it is determined that the encrypted bids have not been decrypted in advance, the bid opening decryption is performed; The leakage tracing module is used to determine the suspicious key combination used in advance decryption based on the matching evaluation results, issue an alarm, and verify the member that stores any subkey in the suspicious key combination; The sequential decryption module is used to input any subkey as the activation key within the time window allowed for bid opening, generate the input sequence of subsequent subkeys according to the input time of the activation key, and decrypt the encrypted bid according to the input sequence of the subkeys.

2. The electronic tender document multi-layer encryption system according to claim 1 is characterized in that: The method of splitting the master key using the threshold encryption scheme is: After encrypting the real electronic bid, an encrypted bid is generated. The master key of the encrypted bid is K. The master key K is split using a threshold encryption scheme. The threshold encryption scheme is (k,n), where n is the total number of subkeys into which the master key K is split, and k is the minimum number of subkeys required to reconstruct the master key K. Any k subkeys can restore the master key K.

3. The electronic tender document multi-layer encryption system according to claim 1 is characterized in that: The method of generating a surface tender document based on a real electronic tender document is as follows: Define the real electronic bid as Pt, which contains the real quotation Qt. Then the method for generating the surface bid is Pf = Mask (Pt, Qf), where the surface bid is Pf, the false quotation is Qf, Mask() is the masking transformation, and the expression formula of the masking transformation is Where H() is the hash function, It is a bitwise XOR operation, || is used to concatenate multiple inputs into one hash input, and Salt is a random salt value.

4. The electronic tender document multi-layer encryption system according to claim 3 is characterized in that: The logic for obtaining false quotes from surface-level tenders is as follows: Calculate the hash value for each subkey combination Ki that meets the threshold requirement, and the calculation expression is Hi=H(Ki), where Hi is the hash value of the subkey combination Ki, and H(Ki) is the unique identifier for performing the hash calculation on the subkey combination Ki; For each subkey combination Ki that meets the threshold requirement, the basic perturbation value Bpv is calculated using the hash value Hi. The calculation expression is Bpv = rand(Hi) mod R, where rand(Hi) is a random number generated based on Hi, R is the perturbation range, mod is the modulus value, and mod R is used to constrain the perturbation result within the range of [0, R-1]; The calculation expression for the false quotation is Qf=Qt+Bpv.

5. The electronic tender document multi-layer encryption system according to claim 1 is characterized in that: The method for detecting abnormal bids based on the collected historical bid data of bidders is as follows: Set a bidding round time window, collect the historical bid data of bidders within the bidding round time window, and calculate the mean and standard deviation of the historical bid data to generate a normal bid distribution. The normal bid distribution is N(μ,σ), where μ is the mean of the historical bid data and the calculation expression is: Where, X e is the bid price in the e-th round, N is the number of historical bid rounds, σ is the standard deviation of historical bid data, and the calculation expression is: Set the abnormal threshold as Exth and calculate the Z score of the bidder's bid data in this round as Where X is the bidder's quotation data for this round. If the Z score is greater than or equal to the abnormal threshold Exth, the bidder's quotation for this round is recorded as abnormal, and the electronic bid is marked as a 1A signal. If the Z score is less than the abnormal threshold Exth, the bidder's quotation for this round is recorded as normal, and the electronic bid is marked as a 1B signal.

6. The electronic tender document multi-layer encryption system according to claim 1 is characterized in that: The method for calculating the robustness of the bidding pattern of the bidder through time series analysis is: According to the historical bidding data of the bidders, a time series is constructed as Sc = {B t-v }, B t-v is the bid data of the previous v rounds, then the robustness of the bidder’s bid model is calculated as B t This is the quotation data of this round; Set the strategy change threshold to Pcth. If |Gc| is greater than or equal to the strategy change threshold Pcth, the bidder's strategy for this round is recorded as abnormal, and the electronic bid is marked as a 0A signal. If |Gc| is less than the strategy change threshold Pcth, the bidder's strategy for this round is recorded as normal, and the electronic bid is marked as a 0B signal.

7. The electronic tender document multi-layer encryption system according to claim 6, characterized in that: The logic of combining abnormal quotation detection and quotation pattern robustness to evaluate whether the false quotation of the surface bid is decrypted in advance is as follows: If the electronic bidding document is marked with 1A signal and 0A signal, the electronic bidding document signal is updated to 00 signal. If the bidder's quotation is abnormal and the quotation strategy changes suddenly, the correlation between the bidder's quotation and each false quotation is analyzed to determine the leaked false quotation; If the electronic bidding document is marked as 1A signal and 0B signal, the electronic bidding document signal is updated to 10 signal, the bidder's quotation is abnormal and the quotation strategy is stable, and no correlation analysis is performed between the bidder's quotation and each false quotation; If the electronic bidding document is marked with 1B signal and 0A signal, the electronic bidding document signal is updated to 01 signal, the bidder's quotation is normal and the quotation strategy changes suddenly, and no correlation analysis is performed between the bidder's quotation and each false quotation; If the electronic bidding document is marked as 1B signal and 0B signal, the electronic bidding document signal is updated to 11 signal, the bidder's quotation is normal and the quotation strategy is stable, and no correlation analysis is performed between the bidder's quotation and each false quotation.

8. The electronic tender document multi-layer encryption system according to claim 7, characterized in that: The correlation analysis between the bidder's quotations and each false quotation is performed to determine the leaked false quotation: The correlation between the bidder's bid and each false bid is calculated using the Pearson correlation coefficient. The calculation expression is: In the formula, r is the correlation between the bidder's bid and each false bid, is the covariance between the bidder's bid and each false bid, and the calculation expression is M is the total number of historical bidding price data, is the bid price of the jth bidder, is the false bid generated by the subkey combination Ki in the jth bidding, σB comp is the standard deviation of the bidder's quotation, and the calculation expression is in, is the average of the historical bidders’ quotations, and the calculation expression is: is the standard deviation of false quotes, and the calculation expression is is the mean of false quotes, and the calculation expression is The correlation threshold is set to Rth. When the calculated Pearson correlation coefficient r is greater than or equal to the correlation threshold Rth, the false quotation is marked as a relevant quotation, and it is recorded that the false quotation has a leakage risk. When the calculated Pearson correlation coefficient r is less than the correlation threshold Rth, the false quotation is marked as an irrelevant quotation, and it is recorded that the false quotation has no leakage risk.

9. The electronic tender document multi-layer encryption system according to claim 8, characterized in that: If there is a false quotation with a risk of leakage, the subkey combination corresponding to the false quotation is determined through the subkey combination-false quotation mapping, the subkey combination is marked as a suspicious key combination, and the administrator of the electronic bidding document multi-layer encryption system is warned to verify the holder of the subkey in the suspicious key combination; If there is no false quotation with a risk of leakage, then within the time window allowed for the bid opening, any sub-key can be input as the activation key, and the input order of subsequent sub-keys is generated according to the input time of the activation key, and the encrypted bid is decrypted according to the sub-key input order.

10. The electronic tender document multi-layer encryption system according to claim 9, characterized in that: After the activation key is input, the input timestamp is recorded to ensure that the decryption order is generated based on the dynamic timestamp. The hash function is used to calculate the input order of the subsequent subkeys. The calculation expression is Seed = H (T0, Kinit) mod n, where Kinit is the activation key, T0 is the activation key input timestamp, H () is the hash function, n is the total number of subkeys, mod is the modulus value, mod n ensures that the generated index is within the key range, Seed is the seed value used to generate the key input order, then the input order of the subsequent subkeys is P = Permute ({1, 2, ..., n}, Seed), where Permute () is a random permutation function, and the remaining k-1 subkeys are input in sequence according to the input order P of the subsequent subkeys to decrypt the encrypted bid; If the subkey input sequence is correct and the subkey combination meets the threshold scheme requirements, the real electronic bid document will be decrypted; If the sub-keys are entered in the wrong order, the decrypted document will be the surface tender document, and the real electronic tender document cannot be obtained.

Citation Information

Patent Citations

  • Electronic bid-inviting and bidding system and method based on Shamir threshold

    CN105790940A

  • Electronic bidding method, device and equipment based on block chain, and storage medium

    CN111767582A

  • Collaborative decryption bid opening method for electronic bidding file, storage medium and electronic equipment

    CN116915406A

  • Supplier risk automatic evaluation control method and system in bidding and tendering process

    CN118966763A

  • Data access control system and method thereof

    US6748084B1

Cited By

  • Reversible intelligent mapping method after medical ultrasonic data desensitization

    CN121747852A

  • Reversible intelligent mapping method for desensitized medical ultrasound data

    CN121747852B