Client information confidentiality management method and system based on encryption algorithm
Through the customer information confidentiality management system based on encryption algorithm, the hardware security module and dynamic parameter adjustment optimization are used to solve the problems of key management and data differentiated processing, and efficient and secure customer information management is achieved to adapt to data confidentiality and analysis in complex business scenarios.
Patent Information
- Application Number
- CN202510349402.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-24
- Publication Date
- 2025-07-08
AI Technical Summary
The existing technology lacks hardware security modules in customer information management, which cannot effectively protect key leakage, and the encryption strategy cannot take into account the differentiated data needs, making it difficult to take into account both security and performance, and there are duplicate calculations and security vulnerabilities in cross-module data processing.
The customer information confidentiality management system based on encryption algorithm is adopted, including data encryption and decryption module, key management module, encrypted data analysis module, algorithm processing unit and comprehensive linkage optimization module. The hardware security module is used to provide high-strength key protection, and differentiated analysis and linkage optimization are achieved through block encryption, hash checks and dynamic parameter adjustment optimization.
It realizes data processing in an encrypted state, reduces the risk of key leakage, improves data security and processing efficiency, supports the linkage and optimization of multi-source data, avoids repeated calculations and security vulnerabilities, and adapts to data confidentiality and analysis in complex business scenarios.
Smart Images

Figure CN120277715A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information confidentiality management, and specifically to a method and system for customer information confidentiality management based on encryption algorithms. Background Art
[0002] In modern information society, the volume of enterprise collection and processing of customer information is increasing continuously, which includes various sensitive information such as personal identity information, transaction flow data, and behavior analysis indicators. Since most enterprises need to deeply analyze and mine these data to gain competitive advantages or meet regulatory compliance requirements, higher challenges are posed to data security and privacy protection. On the one hand, current personal information protection regulations (such as GDPR, CCPA, etc.) require enterprises to take strict security measures during the collection, storage, and use processes, including but not limited to encryption, desensitization, hierarchical authorization, etc.; on the other hand, traditional information security measures (such as simple database encryption or access control) are difficult to fully resist multiple risks such as hacker attacks, internal malicious theft, and data transmission interception.
[0003] In the existing industry practices, customer information is usually centralized in one or more database systems, and the "unified encryption + restricted access" mode is used to ensure data security. However, such methods often have the following deficiencies: First, the key management lacks a hardware security module (HSM) or multi-layer protection, resulting in ineffective protection when the key is stolen or leaked; second, when facing various types of data (such as sensitive transaction data and business indicator data), a "one-size-fits-all" encryption strategy is adopted, failing to take into account the differentiated data requirements, making it difficult to balance security and performance; third, there is a lack of a sustainable dynamic regulation and collaborative optimization mechanism, and the system is mostly statically configured, making it difficult to adapt to different business scenarios or changing security level requirements, and thus unable to achieve efficient and flexible data analysis in practical applications.
[0004] In addition, when an enterprise needs to deeply analyze customer information (including data mining, indicator calculation, cross-departmental data sharing, etc.), most existing systems can only centrally process the plaintext data after decryption. This approach increases the risk of data exposure on the one hand, and on the other hand, cross-module or cross-departmental data requires multiple decryption and re-encryption operations, which also causes repeated calculations and performance bottlenecks. Especially in cloud environments or distributed architectures, the distribution and synchronization of data are more complex, and once the management is not in place, security vulnerabilities and compliance risks are likely to occur. Summary of the Invention
[0005] The purpose of the present invention is to provide a method and system for customer information confidentiality management based on encryption algorithms to solve the technical problems raised in the above background art.
[0006] Based on the above ideas, the present invention provides the following technical solutions: A customer information confidentiality management system based on an encryption algorithm, characterized in that the system runs on a hardware environment composed of a server cluster, a hardware security module, and network communication devices, and the system includes: A data encryption / decryption module, a key management module, an encrypted data analysis module, an algorithm processing unit, a comprehensive linkage optimization module, and a system monitoring and dynamic parameter adjustment module; The data encryption / decryption module communicates with the hardware security module and is used for encrypting and storing and decrypting different types of customer data, and outputting encrypted ciphertext data or decrypted plaintext data; The key management module interacts bidirectionally with the data encryption / decryption module, manages and distributes the public key, private key, and symmetric key required by the system, and securely transmits the key information to the hardware security module; The encrypted data analysis module is connected to the data encryption / decryption module and the key management module, and is used for preprocessing, feature extraction, and index calculation of encrypted or ciphertext-form customer data, and transmitting the results to the algorithm processing unit; The algorithm processing unit includes a first encryption preprocessing algorithm processor for preprocessing and analyzing the first type of data to be processed, and interacts with the encrypted data analysis module; A second encryption analysis algorithm processor for calculating specific indexes of the second type of data to be processed, and interacts with the encrypted data analysis module; The first type of data to be processed is sensitive financial transaction flow data, and the second type of data to be processed is statistical business index data; The algorithm processing unit sends the output obtained by processing through the first encryption preprocessing algorithm processor and the second encryption analysis algorithm processor to the comprehensive linkage optimization module; The comprehensive linkage optimization module interacts bidirectionally with the algorithm processing unit, performs linkage optimization on the output of the algorithm processing unit through a third encryption optimization algorithm processor, and outputs the final comprehensive analysis result; The system monitoring and dynamic parameter adjustment module interacts with all modules of the system, and dynamically adjusts algorithm parameters and key configurations based on the system state and customer data changes monitored in real time to optimize the system operation efficiency and analysis accuracy.
[0007] By deploying multiple core functional modules on the server cluster, hardware security module, and network communication devices, a full-process closed-loop management from key distribution to data encryption and decryption, and then to business analysis and optimization is achieved. First, the present invention utilizes the high-strength key protection and hardware acceleration provided by the hardware security module (HSM) to execute key management and core encryption and decryption operations of sensitive data in a secure environment as much as possible, reducing the risk of key leakage and data tampering from the source. Second, the relationship between the data encryption and decryption module, key management module, encrypted data analysis module, algorithm processing unit, comprehensive linkage optimization module, and system monitoring and dynamic parameter adjustment module is clearly defined in the system structure, and through clear data flow docking, the division of responsibilities of each module in the processing process and the orderliness of information transmission are ensured. Through this architecture, large-scale and diverse data can be encrypted first after entering the system, then differentially analyzed according to different sensitivity levels, and finally the comprehensive result can be obtained through linkage optimization, providing an efficient, reliable, and scalable data confidentiality and analysis solution for enterprises in complex scenarios.
[0008] Preferably, the algorithm processing unit includes a first encryption preprocessing algorithm processor for preprocessing the first type of data to be processed, including deduplication, format normalization, and security marking; The first encryption preprocessing algorithm processor includes an encryption preprocessing algorithm, and the steps of the encryption preprocessing algorithm include: A1. Obtain the symmetric encryption key from the key management module and perform block encryption on the sensitive fields in the data to be processed; A2. Perform hash verification on the encrypted block data and generate a preprocessing verification label; A3. Eliminate duplicate or abnormal data that may pose risks according to the preprocessing verification label; A4. Output the encrypted primary result for subsequent analysis.
[0009] Through a series of preprocessing steps such as deduplication, format normalization, and security marking, abnormal data and duplicate records can be eliminated at the most preliminary stage, thus greatly improving the processing efficiency of the subsequent analysis module. This algorithm first performs block encryption on the data using the symmetric encryption key, and then performs hash verification and label comparison to ensure that the encrypted data is always in a secure state during the processing. At this time, a corresponding hash label will be generated for the encrypted result of each block. If a duplicate or suspicious label is encountered, it will be immediately marked as invalid ⊥ to prevent malicious data or duplicate data from interfering downstream. Through this process-based mechanism of "encrypt first, then verify, then eliminate", the integrity and uniqueness of sensitive data can be effectively guaranteed at the front end, thus providing more accurate and credible input for subsequent business indicator extraction or linkage optimization.
[0010] Preferably, the encryption preprocessing algorithm is specifically implemented using the following formula: Given a dataset D = {d1, d2, …, d n} to be processed and a symmetric key K, perform the following operations on each data block d i : EncBlock i = Enc K (d i ) ; Where, Enc K () represents a function for block encryption using the symmetric key KKK; Perform a hash operation on the encrypted block data EncBlock i to generate a check tag; Tag i = Hash(EncBlock i ) ; Compare Tag i with the existing tags in the system. If the same or abnormal tags are found, perform a rejection mark, otherwise retain and output: ; Where, D = {d1, d2, …, d n} is the first type of dataset to be processed, which is sensitive financial transaction flow data; all the data records to be preprocessed are packed into a set D; d i represents the i-th data or the i-th block; when performing preprocessing operations such as encryption, hashing, and deduplication, each data or each block needs to be processed separately; K is the symmetric encryption key; in the first encryption preprocessing algorithm processor, the key used for block encryption of sensitive data fields is obtained through a secure key management module; Enc K () represents a function for encrypting using the symmetric key K; after encrypting the input data using the symmetric algorithm, the AES ciphertext is output; EncBlock i The result of encrypting the i-th data, denoted as the encrypted data block; it is the input for subsequent hash verification and deduplication judgment; Hash() is a hash function that performs a hash operation on the input to generate a check tag with a fixed length; Tag i is the hash check tag of the encrypted block EncBlock i ; it is used to quickly check for duplicate or abnormal data; An abnormal or duplicate set is a tag record saved internally by the system, used to mark confirmed duplicate or abnormal data. It is a database or hash map. When a new Tag i appears in this set, it indicates that this data block needs special processing or elimination; Result i The final preprocessing result of the i-th data; depending on whether the verification tag is in the abnormal or duplicate set, it decides whether to eliminate or retain and output.
[0011] ⊥ is the symbol for the elimination operation.
[0012] On the one hand, it makes the algorithm process repeatable and verifiable. Those skilled in the art can directly implement the corresponding symmetric encryption and hash operations according to the formula. On the other hand, the determination mechanism that compares tags for each output block in the formula can effectively screen out bad data in combination with the abnormal or duplicate set, enabling the system to implement a risk-dispersion strategy at the earliest stage. In addition, with the help of these specific mathematical descriptions, this algorithm can be seamlessly docked with the hardware security module (HSM), and symmetric encryption and tag generation can be completed in the HSM, greatly improving the overall security and processing efficiency of the system.
[0013] Preferably, the second encryption analysis algorithm processor extracts and calculates specific metrics for the second type of data to be processed, statistical business metric data; including an encryption analysis algorithm for metric calculation and effect value output, and the steps of the encryption analysis algorithm include: B1. Receive the public key PK from the key management module and perform asymmetric encryption on the keyword fields in the second type of data; B2. Based on the encrypted keyword fields, calculate the encrypted metric values related to the business and generate a specific effect value E; B3. Associate the effect value E with the business serial number or unique identifier and output the encryption analysis result for other modules in the system to call.
[0014] First, data isolation for external analysis can be ensured through public key encryption, avoiding the risk of data leakage caused by the key being accessed by multiple parties. Second, the algorithm generates corresponding encrypted fields for each keyword field and then performs homomorphic operations or secure multi-party calculations on them using specific business calculation functions, enabling numerical or logical operations to be completed without restoring the plaintext. Finally, the algorithm outputs a specific effect value E, which can be directly associated with the business serial number or unique identifier, thus enabling fast and implicit association queries in the data statistics or analysis report link. Through this analysis algorithm, enterprises can obtain important statistical information while maintaining high data confidentiality, and can also be applicable to extensions in multiple business scenarios due to the flexibility brought by the modular design.
[0015] Preferably, the encryption analysis algorithm includes the following formula: Given a second type of dataset T = {t1, t2, …, t m} and a public key PK, perform the following encryption on each key field t j : EncField j = Enc PK (t j ) ; Based on EncField j calculate the metrics required for the service: Metric j = CalcMetric(EncField j ) ; Combine all Metrics j to generate a specific effect value E: E = Combine(Metric1, Metric2, ..., Metric m ) ; Finally, bind the output effect value EEE to the corresponding unique identifier to form the encryption analysis result where T = {t1, t2, ..., t m} is the second type of dataset to be processed, which is statistical service metric data; t j is the j-th original data or data block in the second type of dataset; when performing asymmetric encryption and service metric calculation, each (block) of data is processed separately; PK is the public key, which is used to perform asymmetric encryption on the key field in the second encryption analysis algorithm processor; Enc PK () is a function that performs asymmetric encryption using the public key PK and generates ciphertext after encrypting the input data; EncField j is the result of encrypting the key field of the j-th data; CalcMetric() is the service metric calculation, which includes homomorphic operations or other forms of secure multi-party calculation; performs specific analysis logic on the encrypted field and outputs one or more service metric values; Metric j is the service metric value calculated for the encrypted field of the j-th data; Combine() is a function that combines multiple metric values and generates the final effect value by weighted averaging of multiple metrics; E is a specific effect value representing the comprehensive analysis of the second type of data.
[0016] First, using the publicly distributable public key PK, any authorized party can encrypt the original fields without exposing the system's private key, reducing the complexity of key management. Second, by using the CalcMetric() function to extract business metrics in the encrypted state, the risk of information leakage caused by the need to decrypt before calculation in conventional analysis is overcome, and the overall data security level is enhanced. Finally, by using the Combine() function to integrate multiple metric values into the effect value E, custom analysis and summarization of multi-source metrics can be achieved through methods such as weighting, normalization, and special function mapping.
[0017] Preferably, the comprehensive linkage optimization module includes a third encryption optimization algorithm processor for integrally linking the encryption preprocessing result output by the first encryption preprocessing algorithm processor and the encryption analysis result output by the second encryption analysis algorithm processor; The comprehensive processing of the foregoing two results is achieved through a progressive optimization algorithm, and the progressive optimization algorithm includes: C1. Receive the output result of the first encryption preprocessing algorithm, and extract the check tag and valid data blocks therein; C2. Receive the output effect value E of the second encryption analysis algorithm; C3. Based on the system parameters provided by the real-time data monitoring module, match and fuse the above results and generate an innovative comprehensive index; C4. Dynamically adjust the calculation weights in the fusion process to optimize the adaptability and effectiveness of the comprehensive result; C5. Output the finally integrally linked and optimized comprehensive result for the system to make further decisions or for display.
[0018] First, through interaction with the system monitoring and dynamic parameter adjustment module, the algorithm can perceive environmental parameters such as network load, data scale, and encryption intensity requirements in real time, so as to adaptively adjust the weights, priorities, and scheduling mechanisms of algorithm fusion. Second, the algorithm allows synchronous or batch processing of data from different sensitivities in the encrypted state, and further outputs comprehensive indexes, providing more comprehensive and real-time business insights for managers or decision-making systems. Third, since it realizes the linkage and unified optimization of multi-source data within the same framework, the algorithm can avoid information fragmentation or duplicate calculations caused by isolated analysis, and can also greatly reduce the redundant operations of decrypting and then encrypting during cross-module transmission, thereby strengthening the security and performance of the system.
[0019] Preferably, the progressive optimization algorithm further includes: Let the output set of the encryption preprocessing algorithm be denoted as R A , the output set of the encryption preprocessing algorithm contains valid data blocks and check tags, and the output effect value of the encryption analysis algorithm is denoted as E B ; Including an integration formula to generate a comprehensive indicator: I syn = α × AggrA(R A ) + β × AggrB(E B ); Perform the optimization function Optimize() on the comprehensive indicator I syn to obtain the final result O final: O final = Optimize(Isyn, P); Record the final result O final along with the system identifier for subsequent decision-making or display; where R A is the output result set of the encryption preprocessing algorithm, containing the valid data chunks and corresponding check tags after encryption and preprocessing, i.e., an ordered set of Result i ; E B is the effectiveness value obtained from the encryption analysis algorithm; α and β are weight parameters, used in the comprehensive linkage optimization to weight or adjust the importance of different results; obtained through the system monitoring and dynamic parameter adjustment module, determining the proportion or weight of the output of the encryption preprocessing algorithm and the output of the encryption analysis algorithm in the calculation of the final comprehensive indicator; AggrA() and AggrB() are functions that aggregate the output of the encryption preprocessing algorithm and the output of the encryption analysis algorithm respectively; AggrA(R A ) performs homomorphic summation processing on the first type of results; AggrB(E B ) performs hierarchical processing on the second type of results; In the homomorphic encryption scenario, homomorphic operations are performed on the chunk data within R A ; In the ordinary scenario, multiple sub-indicators in R A are normalized; I syn is the comprehensive indicator representing the comprehensive evaluation indicator obtained by integrating the outputs of the first encryption preprocessing algorithm and the second encryption analysis algorithm; P is the set of environmental parameters obtained by real-time system monitoring, including data scale, network load, current encryption intensity requirements, time constraints, and CPU usage, for reference by the subsequent optimization function to achieve dynamic tuning; Optimize() is a function that further optimizes the comprehensive indicator; including the parameter adjustment logic of gradient descent; O final is the final output result of the third encryption optimization algorithm, based on Isyn It is obtained after optimization with external environmental parameter P and is used for subsequent system decision-making, display, or further processing by downstream modules.
[0020] First, by setting dynamic weights such as α and β, an adjustable weighted aggregation is performed on the outputs of the first encryption preprocessing algorithm and the second encryption analysis algorithm to achieve the balance and coordination of data from different sources or with different sensitivities. Second, functions such as AggrA() and AggrB() can combine homomorphic operations or other secure computing technologies to aggregate encrypted data without exposing any sensitive fields in plaintext in intermediate steps. Third, the Optimize() function can adaptively switch between gradient descent, genetic algorithms, or other optimization algorithms according to the system environmental parameter P, and then perform iterative upgrades on I syn to generate the final optimized result O with high precision and meeting the requirements of the real-time environment. final . Through this comprehensive and dynamic collaborative mechanism, the present invention achieves a balance between data security and analysis performance, and significantly improves the adaptability to complex business scenarios and decision-making support capabilities. A method for managing the confidentiality of customer information based on an encryption algorithm, including using a system for managing the confidentiality of customer information based on an encryption algorithm.
[0021] Compared with the prior art, the beneficial effects of the present invention are as follows: By performing block encryption and preprocessing on sensitive financial transaction flow data, the dual goals of security and efficiency are prominently achieved. First, the data is encrypted with a symmetric key when entering the system, avoiding the risks of theft or tampering that may occur during network transmission or hard disk storage. Then, the algorithm uses hash verification to generate tags to quickly eliminate duplicate or suspicious data, thereby effectively reducing the interference factors and computational burden of subsequent analysis. At the same time, the combination of block encryption and hash verification enables each piece of data to be independently verified and processed, and can be immediately marked as ⊥ when an anomaly is detected without affecting the normal operation of the overall data stream. This mode improves the preprocessing efficiency while ensuring the minimum exposure of sensitive data, laying a solid foundation for the subsequent analysis and optimization links of the system. In addition, the specific formula of the algorithm clearly defines the execution methods of the EncK() encryption function and the Hash() verification function, making it easy for relevant technical personnel to verify and reuse when implementing or integrating. With the help of this algorithm, users can ensure the authenticity and uniqueness of the data in the early stage, greatly reducing the subsequent operation and maintenance risks and ensuring the stability of the system performance.
[0022] For statistical business metric data, an asymmetric encryption and homomorphic or secure multi-party computing design concept is adopted, achieving the goal of extracting and calculating metrics for keyword fields under the condition of "no plaintext" or "minimum plaintext". Its primary advantage is that since the public key is used to encrypt the data, the business side can publicly and flexibly encrypt the data without having to handle sensitive private keys or symmetric keys, greatly reducing the key management difficulty and potential security risks. Next, the CalcMetric() function set in the algorithm allows for j performing various secure computing operations, including homomorphic summation, aggregation, or statistical analysis, etc., ensuring that important business metrics can be refined even in the ciphertext state. Finally, through the Combine() function, the individual metric values are integrated into a specific effect value E, which can be directly associated with the business serial number or unique identifier for output, enabling enterprises to quickly call this effect value in a wider range of analysis scenarios without secondary decryption or data backtracking. This algorithm not only ensures the confidentiality of sensitive data but also meets the computing requirements for multi-dimensional metrics such as business operations, production capacity assessment, and customer behavior analysis, thus forming an accurate and secure analysis toolchain based on ciphertext within the enterprise.
[0023] Dynamically match and weight assign the block-encrypted data and hash tags output by the first encryption preprocessing algorithm processor, and the effect value obtained by the second encryption analysis algorithm processor to form an innovative comprehensive metric I syn 。By introducing adjustable parameters α and β into the formula, the system monitoring and dynamic tuning module can automatically adjust the weights according to real-time business traffic, data scale, network load, and even the requirements of different security policies, thereby achieving multi-source linkage and adaptive fusion of the encrypted data. In addition, the Optimize() function can further syn iterate on I through gradient update or other advanced optimization means to generate the final optimized comprehensive output O final 。This linkage and optimization process not only greatly improves the data utilization rate during cross-module collaboration but also avoids the extra overhead and security risks caused by decryption-re-encryption in a decentralized encryption environment. Finally, on the premise of ensuring customer information security and compliance, it provides an enterprise with a closed-loop optimization process that is multi-scenario-oriented, cross-multi-model, and dynamically adaptable, significantly improving the analysis depth and decision-making accuracy of the system. Brief Description of the Drawings
[0024] Figure 1 It is a schematic diagram of the module relationship of a customer information confidentiality management method and system based on an encryption algorithm according to the present invention. Detailed Embodiments
[0025] A customer information confidentiality management system based on encryption algorithms, characterized in that the system runs on a hardware environment composed of a server cluster, a hardware security module, and network communication devices, and the system includes: A data encryption and decryption module, a key management module, an encrypted data analysis module, an algorithm processing unit, a comprehensive linkage optimization module, and a system monitoring and dynamic parameter adjustment module; The data encryption and decryption module communicates with the hardware security module and is used for encrypting and storing and decrypting different types of customer data, and outputting encrypted ciphertext data or decrypted plaintext data; The key management module interacts bidirectionally with the data encryption and decryption module, manages and distributes the public key, private key, and symmetric key required by the system, and securely transmits the key information to the hardware security module; The encrypted data analysis module is connected to the data encryption and decryption module and the key management module, and is used for preprocessing, feature extraction, and index calculation of encrypted or ciphertext-form customer data, and transmitting the results to the algorithm processing unit; The algorithm processing unit includes a first encryption preprocessing algorithm processor for preprocessing and analyzing the first type of data to be processed, and interacts with the encrypted data analysis module; A second encryption analysis algorithm processor for calculating specific indicators of the second type of data to be processed, and interacts with the encrypted data analysis module; The first type of data to be processed is sensitive financial transaction flow data, and the second type of data to be processed is statistical business indicator data; The algorithm processing unit sends the output obtained through the processing of the first encryption preprocessing algorithm processor and the second encryption analysis algorithm processor to the comprehensive linkage optimization module; The comprehensive linkage optimization module interacts bidirectionally with the algorithm processing unit, performs linkage optimization on the output of the algorithm processing unit through a third encryption optimization algorithm processor, and outputs the final comprehensive analysis result; The system monitoring and dynamic parameter adjustment module interacts with all modules of the system, and dynamically adjusts algorithm parameters and key configurations based on the system status and customer data changes monitored in real time to optimize the system operation efficiency and analysis accuracy.
[0026] By deploying multiple core functional modules on server clusters, hardware security modules and network communication equipment, a closed-loop management of the entire process from key distribution to data encryption and decryption to business analysis and optimization is achieved. First, the present invention utilizes the high-intensity key protection and hardware acceleration provided by the hardware security module (HSM) to perform the key management and the core encryption and decryption operations of sensitive data in a secure environment as much as possible, thereby reducing the risk of key leakage and data tampering from the source. Secondly, the system structure clearly divides the relationship between the data encryption and decryption module, the key management module, the encrypted data analysis module, the algorithm processing unit, the comprehensive linkage optimization module and the system monitoring and dynamic parameter adjustment module, and through clear data flow docking, the division of responsibilities of each module in the processing flow and the orderliness of information transmission are guaranteed. Through this architecture, large-scale and diversified data can be encrypted after entering the system, and then differentiated analysis can be achieved according to different sensitivity levels. Finally, a comprehensive result is obtained through linkage optimization, which provides enterprises with efficient, reliable and scalable data confidentiality and analysis solutions in complex scenarios.
[0027] Specifically, the algorithm processing unit includes a first encryption preprocessing algorithm processor, which is used to preprocess the first type of data to be processed, including deduplication, format normalization and security marking; The first encryption preprocessing algorithm processor includes an encryption preprocessing algorithm, and the steps of the encryption preprocessing algorithm include: A1. Obtain the symmetric encryption key from the key management module and perform block encryption on the sensitive fields in the data to be processed; A2. Perform hash verification on the encrypted block data and generate a pre-processing verification tag; A3. Eliminate duplicate or abnormal data that may pose a risk based on preprocessing verification labels; A4. Output the encrypted primary results for subsequent analysis.
[0028] Through a series of preprocessing steps such as deduplication, format normalization, and security marking, abnormal data and duplicate records can be eliminated at the very beginning, thereby greatly improving the processing efficiency of subsequent analysis modules. The algorithm first uses a symmetric encryption key to encrypt the data in blocks, and then performs hash verification and label comparison to ensure that the encrypted data is always in a safe state during the processing process. At this time, a corresponding hash label will be generated for the encryption result of each block. If a duplicate or suspicious label is encountered, it will be immediately marked as invalid⊥ to prevent malicious data or duplicate data from interfering downstream. Through this process-based "encryption first, verification, and elimination" mechanism, the integrity and uniqueness of sensitive data can be effectively guaranteed at the front end, thereby providing more accurate and reliable input for subsequent business indicator extraction or linkage optimization.
[0029] Specifically, the encryption preprocessing algorithm is specifically implemented using the following formula: Given a dataset D = {d1, d2, …, d n} to be processed and a symmetric key K, perform the following operations on each data block d i : EncBlock i = Enc K (d i ) ; Where Enc K () represents a function for block encryption using the symmetric key KKK; Perform a hash operation on the encrypted block data EncBlock i to generate a check tag; Tag i = Hash(EncBlock i ) ; Compare Tag i with the existing tags in the system. If the same or abnormal tags are found, mark them for deletion; otherwise, retain and output: ; Where D = {d1, d2, …, d n} is the first type of dataset to be processed, which is sensitive financial transaction flow data; all the data records that need to be preprocessed are packed into a set D; d i represents the i-th data or the i-th block; when performing preprocessing operations such as encryption, hashing, and duplicate removal, each data or each block needs to be processed separately; K is the symmetric encryption key; in the first encryption preprocessing algorithm processor, the key used for block encryption of sensitive data fields is obtained through a secure key management module; Enc K () represents a function for encryption using the symmetric key K; after encrypting the input data using the symmetric algorithm, the AES ciphertext is output; EncBlock i The result of encrypting the i-th data, denoted as the encrypted data block; it is the input for subsequent hash verification and duplicate removal judgment; Hash() is a hash function that performs a hash operation on the input to generate a check tag of a fixed length; Tag i is the hash check tag of the encrypted block EncBlock i ; it is used to quickly check for duplicate or abnormal data; The abnormal or duplicate set is a tag record stored in the system, which is used to mark confirmed duplicate or abnormal data. It is a database or hash map. i Appearing in this collection means that the data block needs special processing or elimination; Result i The final preprocessing result for the i-th data; decide whether to remove or retain and output it based on whether the verification label is in the abnormal or duplicate set.
[0030] ⊥ is the symbol for the elimination operation.
[0031] On the one hand, it makes the algorithm process repeatable and verifiable, and technicians in this field can directly implement the corresponding symmetric encryption and hash operations based on the formula; on the other hand, the judgment mechanism for label comparison of each output block in the formula can effectively filter out bad data in combination with abnormal or repeated sets, so that the system can implement the risk diversification strategy at the earliest stage. In addition, with the help of these specific mathematical descriptions, this algorithm can be seamlessly connected with the hardware security module (HSM), and symmetric encryption and label generation can be completed in the HSM, greatly improving the overall security and processing efficiency of the system.
[0032] When used specifically: When the system receives sensitive financial transaction flow data, it first calculates the Tag based on Hash() i , if the tag already exists in the exception or duplicate set, then Result i =⊥, which means that the transaction flow will be marked as suspected duplication or abnormal, and will be directly discarded or manually reviewed later. Block encryption ensures security. All retained transaction data enters the subsequent process in the form of block encryption to ensure that sensitive information is not stored or transmitted in plain text. After algorithm preprocessing, the system will generate a set of valid blocks (that is, EncBlock i ), and the corresponding tag information Tag i , this part of the encryption results will enter the downstream link for further analysis or integration.
[0033] EncBlock i The encrypted transaction flow data required for subsequent analysis provides clean and secure input for the next step of data analysis and comprehensive linkage.
[0034] Tags i It can be verified again in subsequent steps, or provide traceability clues for auditing and tracking abnormal transactions.
[0035] ⊥ serves as an identifier for invalid data, helping the system to filter out abnormal or duplicate data in the early stages, thereby improving overall computing efficiency and reducing security risks.
[0036] Specifically, the second encryption analysis algorithm processor extracts and calculates specific metrics from the second type of data to be processed, i.e., statistical business metric data, including an encryption analysis algorithm for metric calculation and effect value output. The steps of the encryption analysis algorithm are as follows: B1. Receive the public key PK from the key management module and perform asymmetric encryption on the keyword fields in the second type of data; B2. Based on the encrypted keyword fields, calculate the encrypted metric values related to the business and generate a specific effect value E; B3. Associate the effect value E with the business serial number or unique identifier and output the encryption analysis result for other modules in the system to call.
[0037] First, public key encryption can ensure data isolation for external analysis, avoiding the risk of data leakage caused by multi-party access to the key. Second, the algorithm generates corresponding encrypted fields for each keyword field and then performs homomorphic operations or secure multi-party calculations on them using specific business calculation functions, enabling numerical or logical operations without restoring the plaintext. Finally, the algorithm outputs a specific effect value E, which can be directly associated with the business serial number or unique identifier, thus enabling fast and implicit association queries in the data statistics or analysis report stage. Through this analysis algorithm, enterprises can obtain important statistical information while maintaining high data confidentiality and can also be applicable to the expansion in multiple business scenarios due to the flexibility brought by modular design.
[0038] Specifically, the encryption analysis algorithm includes the following formula: Given the second type of data set T = {t1, t2,..., t m} and the public key PK, perform the following encryption on each keyword field t j : EncField j = Enc PK (t j ) Based on EncField j calculate the metrics required by the business: Metric j = CalcMetric(EncField j ) Combine all Metric j to generate a specific effect value E: E = Combine(Metric1, Metric2,..., Metric m ) Finally, bind the output effect value EEE with the corresponding unique identifier to form the encryption analysis result Among them, T = {t1, t2,..., t m} is the second type of dataset to be processed, which is statistical business metric data; t j is the j-th original data or data block in the second type of dataset; when performing asymmetric encryption and business metric calculation, each (block) of data is processed separately; PK is the public key, which is used to perform asymmetric encryption on the key fields in the second encryption analysis algorithm processor; Enc PK () is a function that performs asymmetric encryption using the public key PK, and generates ciphertext after encrypting the input data; EncField j is the result of encrypting the key field of the j-th data; CalcMetric() is the business metric calculation, which includes homomorphic operations or other forms of secure multi-party calculation; it executes specific analysis logic on the encrypted fields and outputs one or more business metric values; Metric j is the business metric value calculated from the encrypted field of the j-th data; Combine() is a function that combines multiple metric values, which weights and averages multiple metrics to generate the final effect value; E is a specific effect value, which represents the comprehensive analysis of the second type of data.
[0039] First, using the publicly distributable public key PK, any authorized party can encrypt the original fields without exposing the private key of the system, reducing the complexity of key management. Second, by using the CalcMetric() function to extract business metrics in the encrypted state, it overcomes the information leakage risk brought by the need to decrypt first and then calculate in conventional analysis, and improves the overall data security level. Finally, by using the Combine() function to integrate multiple metric values into the effect value E, it can achieve custom analysis and summary of multi-source metrics through methods such as weighting, normalization, and special function mapping.
[0040] When specifically used: Since in most business statistics, it is necessary to statistically analyze information such as user behavior, operation efficiency, and marketing activities. However, if such data is shared with other parties or retrieved across departments, if it is stored or transmitted in plaintext, it will be easily stolen. In this embodiment, EncPK() is used to encrypt the key fields, and it can only be decrypted when the backend or the authorized party holds the corresponding private key, greatly reducing the risk of data leakage.
[0041] CalcMetric() can perform numerical operations, statistical aggregations, etc. on encrypted fields using homomorphic encryption or secure multi-party computing technologies as needed, without prior decryption. This enables enterprises to obtain necessary indicator outputs while maintaining privacy.
[0042] Combine() synthesizes several indicator values into an effect value E that can be directly used for business reports, process decisions, or risk assessments. For example, "business health score" can be obtained for further decision-making.
[0043] EncField j Remain encrypted throughout the sharing process within the system or across departments, meeting compliance and security requirements.
[0044] Metric j Individual indicators obtained through secure operations can be called or parameter-adjusted as needed to enable the system to flexibly analyze different dimensions.
[0045] E is the most important aggregated indicator, directly used as the basis for macro decision-making by management, the numerical value of the core report, or the trigger condition for automated processes (e.g., triggering a risk control warning when E exceeds the threshold).
[0046] Specifically, the comprehensive linkage optimization module includes a third encryption optimization algorithm processor for integrally linking the encrypted preprocessing result output by the first encryption preprocessing algorithm processor and the encrypted analysis result output by the second encryption analysis algorithm processor; The comprehensive processing of the above two results is achieved through a progressive optimization algorithm, and the progressive optimization algorithm includes: C1. Receive the output result of the first encryption preprocessing algorithm, and extract the verification label and valid data chunks therein; C2. Receive the output effect value E of the second encryption analysis algorithm; C3. Based on the system parameters provided by the real-time data monitoring module, match and fuse the above results and generate an innovative comprehensive indicator; C4. Dynamically adjust the calculation weights during the fusion process to optimize the adaptability and effectiveness of the comprehensive result; C5. Output the finally integrally optimized comprehensive result for the system to make further decisions or for display.
[0047] First, through interaction with the system monitoring and dynamic parameter tuning module, the algorithm can perceive environmental parameters such as network load, data scale, and encryption intensity requirements in real time, thereby adaptively adjusting the weights, priorities, and scheduling mechanisms of algorithm fusion. Second, the algorithm allows for synchronous or batch processing of data from different sensitivities in the encrypted state and further outputs comprehensive metrics, providing more comprehensive and real-time business insights for managers or decision-making systems. Third, since it realizes the linkage and unified optimization of multi-source data within the same framework, the algorithm can avoid information fragmentation or duplicate calculations caused by isolated analysis, and can also significantly reduce redundant operations of decrypting and then re-encrypting during cross-module transmission, thereby enhancing the security and performance of the system.
[0048] Specifically, the progressive optimization algorithm further includes: Let the output set of the encryption preprocessing algorithm be denoted as R A , the output set of the encryption preprocessing algorithm contains valid data blocks and check tags, and the output effect value of the encryption analysis algorithm is denoted as E B ; Including an integration formula to generate comprehensive metrics: I syn =α×AggrA(R A )+β×AggrB(E B ); Further perform the optimization function Optimize() on the comprehensive metric I syn to obtain the final result O final: O final =Optimize(Isyn,P); Record the final result O final along with the system identifier for subsequent decision-making or display; where R A is the output result set of the encryption preprocessing algorithm, containing the valid data blocks and corresponding check tags after encryption and preprocessing, that is, an ordered set of Result i ; E B is the effect value obtained by the encryption analysis algorithm; α and β are weight parameters, used in the comprehensive linkage optimization to weight or adjust the importance of different results; obtained through the system monitoring and dynamic parameter tuning module, determining the proportion or weight of the output of the encryption preprocessing algorithm and the output of the encryption analysis algorithm in the calculation of the final comprehensive metric; AggrA() and AggrB() are functions that aggregate the output of the encryption preprocessing algorithm and the output of the encryption analysis algorithm respectively; AggrA(R A)Perform homomorphic summation processing on the first type of results; AggrB(E B )Perform hierarchical processing on the second type of results; In the homomorphic encryption scenario, perform homomorphic operations on the chunked data within R A ; In the ordinary scenario, normalize the multiple sub-indices in R A ; I syn is the comprehensive index, representing the comprehensive evaluation index obtained by integrating the outputs of the first encryption preprocessing algorithm and the second encryption analysis algorithm; P is the set of environmental parameters obtained by the system's real-time monitoring, including data scale, network load, current encryption strength requirements, time constraints, and CPU usage, for reference by subsequent optimization functions to achieve dynamic tuning; Optimize() is a function for further optimizing the comprehensive index; it contains the parameter tuning logic of gradient descent; O final is the final output result of the third encryption optimization algorithm, obtained by optimizing based on I syn and the external environmental parameter P, and is used for subsequent system decision-making, display, or further processing by downstream modules.
[0049] First, by setting dynamic weights such as αβ, perform adjustable weighted aggregation on the outputs of the first encryption preprocessing algorithm and the second encryption analysis algorithm to achieve the balance and coordination of data from different sources or with different sensitivities. Second, functions such as AggrA() and AggrB() can combine homomorphic operations or other secure computing technologies to aggregate encrypted data without exposing any sensitive fields in the intermediate steps. Third, the Optimize() function can adaptively switch between gradient descent, genetic algorithms, or other optimization algorithms according to the system environmental parameter P, and then perform iterative upgrades on I syn to generate the final optimized result O final with high precision and meeting the requirements of the real-time environment. Through this comprehensive and dynamic coordination mechanism, the present invention achieves a balance between data security and analysis performance, and significantly improves the adaptability and decision support ability for complex business scenarios.
[0050] Specifically, when used: O final is both the result of comprehensive calculation and can also be the direct trigger basis for downstream modules or system administrators to perform actions. For example: risk warning, if O final shows a high risk, the system will automatically alarm the risk control department and can temporarily increase the encryption strength.
[0051] If O finalIt indicates that the network resources are abundant, and the system can increase the number of algorithm iteration rounds to further improve the analysis accuracy; otherwise, the operation can be simplified to maintain the real-time processing ability.
[0052] The management layer can rely on O final to learn about the comprehensive performance of the current customer transaction activity and business health, and deploy marketing activities or resource investments accordingly.
[0053] A method for managing the confidentiality of customer information based on an encryption algorithm, including using a system for managing the confidentiality of customer information based on an encryption algorithm.
Claims
1. A customer information confidentiality management system based on an encryption algorithm, characterized in that, The system runs on a hardware environment consisting of a server cluster, a hardware security module, and a network communication device, and includes: Data encryption and decryption module, key management module, encrypted data analysis module, algorithm processing unit, comprehensive linkage optimization module and system monitoring and dynamic parameter adjustment module; The data encryption and decryption module communicates with the hardware security module to encrypt, store and decrypt different types of customer data, and output encrypted ciphertext data or decrypted plaintext data; The key management module interacts bidirectionally with the data encryption and decryption module to manage and distribute the public key, private key and symmetric key required by the system, and securely transmits the key information to the hardware security module; The encrypted data analysis module is connected to the data encryption and decryption module and the key management module, and is used to pre-process, extract features, and calculate indicators for the encrypted or ciphertext customer data, and transmit the results to the algorithm processing unit; The algorithm processing unit includes a first encryption preprocessing algorithm processor for preprocessing and analyzing the first type of data to be processed, and performs data interaction with the encryption data analysis module; A second encryption analysis algorithm processor for calculating specific indicators on the second type of data to be processed, and for performing data interaction with the encryption data analysis module; The first type of data to be processed is sensitive financial transaction flow data, and the second type of data to be processed is statistical business indicator data; The algorithm processing unit sends the output obtained by processing by the first encryption preprocessing algorithm processor and the second encryption analysis algorithm processor to the comprehensive linkage optimization module; The comprehensive linkage optimization module interacts bidirectionally with the algorithm processing unit, performs linkage optimization on the output of the algorithm processing unit through the third encryption optimization algorithm processor, and outputs the final comprehensive analysis result; The system monitoring and dynamic parameter adjustment module exchanges information with all modules of the system, and dynamically adjusts algorithm parameters and key configuration based on real-time monitored system status and customer data changes to optimize system operation efficiency and analysis accuracy.
2. The customer information confidentiality management system based on an encryption algorithm according to claim 1, characterized in that, The algorithm processing unit includes a first encryption preprocessing algorithm processor, which is used to preprocess the first type of data to be processed, including deduplication, format normalization and security marking; The first encryption preprocessing algorithm processor includes an encryption preprocessing algorithm, and the steps of the encryption preprocessing algorithm include: A1. Obtain the symmetric encryption key from the key management module and perform block encryption on the sensitive fields in the data to be processed; A2. Perform hash verification on the encrypted block data and generate a pre-processing verification tag; A3. Eliminate duplicate or abnormal data that may pose a risk based on preprocessing verification labels; A4. Output the encrypted primary results for subsequent analysis.
3. A customer information confidentiality management system based on an encryption algorithm according to claim 2, characterized in that, The encryption preprocessing algorithm is specifically implemented using the following formula: Given the dataset D = {d1, d2, …, d n} and the symmetric key K, for each data block d i perform the following operations: EncBlock i =Enc K (d i ) ; Among them, Enc K () represents a function for block encryption using the symmetric key KKK; Perform a hashing operation on the encrypted block data EncBlock i to generate a check tag; Tag i =Hash(EncBlock i ); Compare the Tag i with the existing tags in the system. If the same or abnormal tags are found, mark them for deletion; otherwise, retain and output them: ; Among them, D = {d1, d2, …, d n} is the first type of data set to be processed, which is sensitive financial transaction flow data; all the data records that need to be preprocessed are packaged into a set D; d i represents the i-th data or the i-th block; when performing preprocessing operations such as encryption, hashing, and deduplication, each data or each block needs to be processed separately; K is a symmetric encryption key; in the first encryption preprocessing algorithm processor, the key used for block encryption of sensitive data fields is obtained through a secure key management module; Enc K () represents a function that encrypts using the symmetric key K; after encrypting the input data using the symmetric algorithm, it outputs the AES encrypted ciphertext; EncBlock i The result of encrypting the i-th piece of data, denoted as the encrypted data block; it is the input for subsequent hash verification and deduplication judgment. Hash() is a hash function that performs a hash operation on the input and generates a checksum tag of a fixed length; Tag i Is the hash check tag for the encrypted block EncBlock i Used to quickly check for duplicate or abnormal data; The exception or duplicate set is a tag record saved within the system, used to mark confirmed duplicate or abnormal data. It is a database or hash map. When a new Tag i appears in this set, it indicates that this data block needs special processing or elimination; Result i The final preprocessing result of the i-th data; depending on whether the verification label is in the abnormal or duplicate set, decide whether to eliminate or retain and output it. ⊥ is the symbol for the elimination operation.
4. A customer information confidentiality management system based on an encryption algorithm according to claim 3, characterized in that, The second encryption analysis algorithm processor extracts and calculates specific metrics for the second type of data statistical business metric data; it includes an encryption analysis algorithm for metric calculation and effect value output, and the steps of the encryption analysis algorithm are as follows: B1. Receive the public key PK from the key management module and perform asymmetric encryption on the key fields in the second type of data; B2. Based on the encrypted key fields, calculate the encrypted metric values related to the business and generate a specific effect value E; B3. Associate the effect value E with the business serial number or unique identifier and output the encryption analysis result for other modules in the system to call.
5. The customer information confidentiality management system based on an encryption algorithm according to claim 4, characterized in that, The encryption analysis algorithm includes the following formula: Given the second type of dataset \(T = \{t_1, t_2, \ldots, t\) m \} and the public key \(PK\), for each keyword field \(t\) j perform the following encryption: EncField j =Enc PK (t j ); Based on EncField j Calculate the metrics required for the business: Metric j =CalcMetric(EncField j ); Combine all Metrics j After synthesis, generate a specific effect value E: E = Combine(Metric1, Metric2,..., Metric m ); The final output effect value EEE is bound to the corresponding unique identifier to form the encryption analysis result Among them, T = {t1, t2,..., t m} is the second type of data set to be processed, which is statistical business indicator data; t j is the j-th original data or data block in the second type of dataset; when performing asymmetric encryption and business metric calculations, each piece (block) of data is processed separately; PK is the public key, which is used in the second encryption analysis algorithm processor to perform asymmetric encryption on the key fields; Enc PK () is a function for asymmetric encryption using the public key PK, which encrypts the input data to generate ciphertext; EncField j It is the result after encrypting the keyword field of the j-th data CalcMetric() is the business metric calculation, which includes homomorphic operations or other secure multi-party calculation forms; it performs specific analysis logic on the encrypted fields and outputs one or more business metric values; Metric j The service metric value calculated for the encryption field of the j-th data Combine() is a function that combines multiple metric values to generate the final effect value by weighted averaging of multiple metrics; E is a specific effect value representing the comprehensive analysis of the second type of data.
6. The customer information confidentiality management system based on an encryption algorithm according to claim 5, characterized in that, The comprehensive linkage optimization module includes a third encryption optimization algorithm processor, which is used to perform linkage integration on the encryption preprocessing result output by the first encryption preprocessing algorithm processor and the encryption analysis result output by the second encryption analysis algorithm processor; The comprehensive processing of the above two results is realized through a progressive optimization algorithm, and the progressive optimization algorithm includes: C1. Receive the output result of the first encryption preprocessing algorithm and extract the verification label and valid data blocks therein; C2. Receive the output effect value E of the second encryption analysis algorithm; C3. Based on the system parameters provided by the real-time data monitoring module, match and fuse the above results and generate an innovative comprehensive index; C4. Dynamically adjust the calculation weights in the fusion process to optimize the adaptability and effectiveness of the comprehensive result; C5. Output the final comprehensively optimized result after linkage for the system to make further decisions or displays.
7. An encryption algorithm-based customer information confidentiality management system according to claim 6, wherein The progressive optimization algorithm also includes: Let the output set of the encryption preprocessing algorithm be denoted as R A , the output set of the encryption preprocessing algorithm contains valid data blocks and check tags, and the output effect value of the encryption analysis algorithm is denoted as E B ; It includes an integration formula to generate a comprehensive index: I syn = α × AggrA(R A ) + β × AggrB(E B ); For the comprehensive index I syn Further execute the optimization function Optimize() to obtain the final result O final: O final = Optimize(Isyn, P); Record the final result O final along with the system identifier for subsequent decision-making or presentation; Among them, R A is the output result set of the encryption preprocessing algorithm, which contains the valid data blocks and corresponding check tags after encryption and preprocessing, that is, the ordered set of Result i ; E B is the effectiveness value obtained by the encryption analysis algorithm; α and β are weight parameters, which are used in the comprehensive linkage optimization to weight or adjust the importance of different results; they are obtained through the system monitoring and dynamic parameter adjustment module, and determine the proportion or weight of the output of the encryption preprocessing algorithm and the output of the encryption analysis algorithm in the calculation of the final comprehensive index; AggrA() and AggrB() are functions that aggregate the output of the encryption preprocessing algorithm and the output of the encryption analysis algorithm respectively; AggrA(R A ) performs a homomorphic summation process on the first type of results; AggrB(E B ) performs hierarchical processing on the second type of results; In the homomorphic encryption scenario, perform homomorphic operations on the chunked data within R A Normalize multiple sub-indicators in R A under normal scenarios; I syn The comprehensive index represents the comprehensive evaluation index obtained by integrating the outputs of the first encryption preprocessing algorithm and the second encryption analysis algorithm; P is the set of environmental parameters obtained by real-time monitoring of the system, including data scale, network load, current encryption intensity requirements, time constraints, and CPU usage rate, which are for reference by subsequent optimization functions to achieve dynamic tuning; Optimize() is a function that further optimizes the comprehensive index; it includes the parameter adjustment logic of gradient descent; O final It is the final output result of the third encryption optimization algorithm, obtained based on I syn and the optimized external environment parameter P, and is used for subsequent system decisions, displays, or continued processing by downstream modules.
8. A method for confidential management of customer information based on an encryption algorithm, characterized in that, It includes using the customer information confidentiality management system based on the encryption algorithm as described in any one of claims 1-7.
Citation Information
Cited By
Multi-party cooperative computing method and system based on confidential container and additive secret sharing
CN122433107A