E-commerce order data storage method
Through the combination of network security detection model and attribute-based encryption algorithm, the storage process of e-commerce order data is identified and controlled, which solves the problems of low efficiency and poor security of e-commerce order data storage, and realizes efficient and secure data storage and query.
Patent Information
- Application Number
- CN202510409093.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-02
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2045-04-02
AI Technical Summary
In the prior art, e-commerce order data storage has problems such as low storage efficiency, poor data security and slow query speed, which is difficult to meet the efficient, safe and fast needs of modern e-commerce business.
The pre-set network security detection model is used to identify real-time network traffic characteristics, obtain the network security status in the data storage process, and terminate the stored process when the network security status is unsafe. The data is encrypted using attribute-based encryption algorithm, and the user's private key is fragmented and isolated and stored.
Improve the security and loss resistance of data storage, ensure the security and reliability of data storage procedures, and improve data storage efficiency and query speed.
Smart Images

Figure CN120301631A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data processing, and particularly relates to a method for storing e-commerce order data. Background Art
[0002] E-commerce order data is the core information in the process of e-commerce transactions, covering multi-dimensional data such as user purchase behavior, commodity information, transaction amount, delivery address, etc. With the booming development of the e-commerce industry, the order data volume has increased sharply, becoming an important basis for enterprises to analyze market trends, optimize operation strategies, and improve customer experience. Order data usually includes fields such as order number, user ID, commodity ID, quantity, price, payment method, order time, delivery time, and receipt time, and has characteristics such as being structured, having strong real-time performance, and high value density. Effectively storing and managing e-commerce order data is of great significance for ensuring data security, improving data processing efficiency, and supporting business decisions. With the rapid development of the Internet, the e-commerce industry has become increasingly prosperous, and the order data volume has grown explosively. Traditional methods for storing order data often have problems such as low storage efficiency, poor data security, and slow query speed, and are difficult to meet the high-efficiency, secure, and fast requirements of modern e-commerce operations. Summary of the Invention
[0003] The present invention provides a method for storing e-commerce order data to solve the problem of relatively low security performance in storing e-commerce order data in the prior art.
[0004] A method for storing e-commerce order data includes: Obtaining the e-commerce order data to be stored, the unique identity identification code corresponding to the e-commerce order data to be stored, the user attributes corresponding to the e-commerce order data to be stored, and the real-time network traffic characteristics during the data storage process; Using a pre-set network security detection model to identify the real-time network traffic characteristics and obtaining the network security status during the data storage process; wherein, the network security status includes network security or network insecurity; When the network security status is network insecurity, the data storage process of this e-commerce order data is terminated, network security is controlled, and an abnormal message is fed back to the data storage user; When the network security status is network security, based on the user attributes corresponding to the e-commerce order data to be stored, using an attribute-based encryption algorithm to encrypt the e-commerce order data to be stored, and obtaining the encrypted e-commerce order data to be stored and the user private key; After associating the encrypted e-commerce order data to be stored and the unique identity identification code corresponding to the e-commerce order data to be stored, transmitting them to any one of the servers in the data storage server cluster for storage; Fragment the user's private key to obtain multiple private key fragments, and separately transmit the multiple private key fragments to different servers in the data storage server cluster for storage, thus completing the storage process of e-commerce order data.
[0005] Further, use a pre-set network security detection model to identify real-time network traffic characteristics, and obtain the network security status during the data storage process, including: Construct the real-time network traffic characteristics into a data vector or a data matrix to obtain the data to be identified; Use the data to be identified as the input of the pre-set network security detection model, obtain the output of the pre-set network security detection model, and use the state category with the highest probability in the output as the network security status during the data storage process.
[0006] Further, the pre-set network security detection model is set as: a convolutional neural network or a recurrent neural network.
[0007] Further, the method for pre-setting the network security detection model includes: After optimizing the hyperparameters of the network security detection model using an intelligent optimization algorithm, determine the final hyperparameters of the network security detection model, and deploy the network security detection model according to the final hyperparameters of the network security detection model, thus completing the pre-setting of the network security detection model.
[0008] Further, when the network security status is network insecurity, terminate the data storage process of this e-commerce order data, conduct network security control, and feedback abnormal information to the data storage user, including: When the network security status is network insecurity, terminate the data storage process of this e-commerce order data; Restrict the access of the data storage user to achieve network security control, and at the same time generate abnormal information prohibiting access to the data storage user.
[0009] Further, fragmenting the user's private key to obtain multiple private key fragments includes: Construct a known K-order polynomial with a constant term; where the constant term in the known K-order polynomial is set as the user's private key; when the user's private key is not a decimal number, first convert the private key to a decimal number; a known K-order polynomial means that the coefficients of each order are known; Randomly generate 2K independent variables, and input the independent variables into the known K-order polynomial to obtain the dependent variables output by the known K-order polynomial, and obtain the dependent variable corresponding to each independent variable; Form a private key fragment by combining any dependent variable with the dependent variable corresponding to the independent variable. After traversing all the dependent variables, obtain multiple private key fragments.
[0010] Further, it also includes: When a data storage user accesses the stored e-commerce data, different servers use the public key publicly announced by the data storage user to encrypt the private key fragments, and then transmit the encrypted private key fragments to the data storage user, so that the data storage user can restore the user private key based on the encrypted private key fragments, realizing the storage security control of e-commerce data.
[0011] Further, after different servers use the public key publicly announced by the data storage user to encrypt the private key fragments and transmit the encrypted private key fragments to the data storage user, it includes: Query the public key corresponding to the data storage user; Based on the unique identity identification code corresponding to the data storage user, query the server storing the corresponding private key fragments to obtain the first target server; Randomly determine more than K servers from the first target server to obtain multiple second target servers; Transmit the unique identity identification code corresponding to the data storage user, the public key corresponding to the data storage user, and the private key fragment transmission instruction to the second target server According to the unique identity identification code corresponding to the data storage user, query the private key fragments corresponding to the data storage user through the second target server to obtain the private key fragments to be sent; After using the public key corresponding to the data storage user to encrypt the private key fragments to be sent through the second target server, obtain the encrypted private key fragments; According to the unique identity identification code corresponding to the data storage user, query the data receiving address corresponding to the data storage user through the second target server, and transmit the encrypted private key fragments to the data storage user according to the data receiving address; Among them, the association relationship between the unique identity identification code corresponding to the data storage user and the corresponding data receiving address is pre-stored data or obtained during the data storage user's access to data.
[0012] Further, the data storage user restores the user private key based on the encrypted private key fragments, including: The data storage user constructs an unknown K-order polynomial with a constant term; where the unknown K-order polynomial means that the coefficients of each order are unknown; Use the dependent variable and independent variable in the private key fragments to decrypt the unknown K-order polynomial to obtain a known K-order polynomial, and take the constant term of the known K-order polynomial as the user private key.
[0013] Further, it also includes: When a data storage user accesses the stored e-commerce data, the target server storing the e-commerce data is queried according to the unique identity identification code corresponding to the e-commerce order data to be stored, and the target server is scheduled to transmit the encrypted e-commerce order data to be stored to the data storage user, so that the data storage user can use the user private key and the encrypted e-commerce order data to be stored, and complete data decryption by using the attribute-based encryption algorithm to achieve the storage access control of the e-commerce data.
[0014] An e-commerce order data storage method provided by the present invention can initially ensure the security during the data storage process by using a pre-set network security detection model to identify real-time network traffic characteristics, obtaining the network security status during the data storage process, and controlling the data storage process according to the network security status. Then, the attribute-based encryption algorithm is used to encrypt the e-commerce order data to be stored, further enhancing the data security, enabling only the data storage users related to the data to access the data. Then, the user private key is fragmented and the private key fragments are stored in isolation, greatly enhancing the data security and anti-loss property, and ensuring the storage security of the e-commerce order data. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] The accompanying drawings herein are incorporated into the specification and constitute a part of the specification, showing embodiments consistent with the present invention and used together with the specification to explain the principles of the present invention.
[0016] Figure 1 It is a flowchart of an e-commerce order data storage method provided by an embodiment of the present invention.
[0017] Through the above accompanying drawings, specific embodiments of the present invention have been shown, and there will be more detailed descriptions hereinafter. These drawings and written descriptions are not intended to limit the scope of the inventive concept in any way, but to illustrate the concept of the present invention to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0018] Here, the exemplary embodiments will be described in detail, and the examples are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present invention. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present invention as detailed in the appended claims.
[0019] The embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
[0020] As Figure 1 shown, an embodiment of the present invention provides an e-commerce order data storage method, including: S1. Obtain the e-commerce order data to be stored, the unique identity identification code corresponding to the e-commerce order data to be stored, the user attributes corresponding to the e-commerce order data to be stored, and the real-time network traffic characteristics during the data storage process; The e-commerce order data to be stored can be the data transmitted by users or the data of the e-commerce platform, which is the data to be stored in the embodiments of the present invention. The unique identity identification code corresponding to the e-commerce order data to be stored can be used to store and search for the data of the data storage user, which can effectively improve the data storage efficiency. The user attributes corresponding to the e-commerce order data to be stored are mainly used for attribute-based encryption, so that only users with the user attributes specified by the access policy can access and decrypt the data, which fundamentally improves the data security. The real-time network traffic characteristics during the data storage process are used to identify the network security status, so as to identify the security during the data storage process and access process, which can effectively ensure the data security.
[0021] S2. Use a pre-set network security detection model to identify the real-time network traffic characteristics and obtain the network security status during the data storage process; wherein, the network security status includes network security or network insecurity; The pre-set network security detection model can be a deep learning model trained through a historical data set. Such a deep learning model usually has the ability to identify network traffic characteristics. By using the pre-set network security detection model to identify the real-time network traffic characteristics, the network security during the data storage process or data access process can be effectively identified, which effectively improves the data storage security.
[0022] S3. When the network security status is network insecurity, terminate the data storage process of this e-commerce order data, control the network security, and feedback the abnormal information to the data storage user; When the network security status is network insecurity, it indicates that the current data storage user may be attacking the data storage server cluster, and the data storage security is threatened. Therefore, the network security can be controlled to ensure the security of the data storage server cluster.
[0023] S4. When the network security status is network security, use the attribute-based encryption algorithm to encrypt the e-commerce order data to be stored based on the user attributes corresponding to the e-commerce order data to be stored, and obtain the encrypted e-commerce order data to be stored and the user private key; When the network security status is network security, it indicates that the current data access process is normal. When the account password of the data storage user matches correctly, data storage or data access can be performed for the user. Encrypting the e-commerce order data to be stored using the attribute-based encryption algorithm can greatly enhance data security.
[0024] S5. After associating the encrypted e-commerce order data to be stored and the unique identity identification code corresponding to the e-commerce order data to be stored, transmit them to any one of the servers in the data storage server cluster for storage; Optionally, the associated data can also be mirror-stored on different servers in the data storage server cluster, so as to achieve multi-backup storage and improve the anti-loss performance of the data.
[0025] S6. Fragment the user private key to obtain multiple private key fragments, and transmit the multiple private key fragments to different servers in the data storage server cluster for storage respectively, thus completing the storage process of the e-commerce order data.
[0026] Fragment the user private key to obtain multiple private key fragments, and transmit the multiple private key fragments to different servers in the data storage server cluster for storage respectively, so that even if an illegal data acquirer obtains some private key fragments, decryption cannot be achieved, further enhancing data security.
[0027] An e-commerce order data storage method provided by the present invention can initially ensure the security in the data storage process by using a pre-set network security detection model to identify real-time network traffic characteristics, obtaining the network security status in the data storage process, and controlling the data storage process according to the network security status. Then, the e-commerce order data to be stored is encrypted using the attribute-based encryption algorithm, further enhancing data security, enabling only the data storage user related to the data to access the data. Then, the user private key is fragmented and the private key fragments are stored in isolation, greatly enhancing data security and anti-loss performance, and ensuring the storage security of the e-commerce order data.
[0028] In the embodiment of the present invention, using a pre-set network security detection model to identify real-time network traffic characteristics and obtain the network security status in the data storage process includes: Construct the real-time network traffic characteristics into a data vector or a data matrix to obtain the data to be identified; for example, assuming that the pre-set network security detection model is set as a convolutional neural network, then the real-time network traffic characteristics should be constructed into a data matrix, and the construction can refer to the existing methods.
[0029] Use the data to be recognized as the input of a pre-set network security detection model, obtain the output of the pre-set network security detection model, and use the state category with the highest probability in the output as the network security state during the data storage process.
[0030] In the embodiments of the present invention, the pre-set network security detection model is set as: a convolutional neural network or a recurrent neural network. However, it should be noted that the above two neural networks are only preferred ways in the embodiments of the present invention, and other neural networks can also be used as the network security detection model to achieve network security detection.
[0031] In the embodiments of the present invention, the method for pre-setting the network security detection model includes: After optimizing the hyperparameters of the network security detection model using an intelligent optimization algorithm, determine the final hyperparameters of the network security detection model, and deploy the network security detection model according to the final hyperparameters of the network security detection model to complete the pre-setting of the network security detection model.
[0032] Optionally, the embodiments of the present invention provide an intelligent optimization algorithm to improve the accuracy of network security detection, which may include: Randomly initialize the hyperparameters of the network security detection model (such as randomly initialize between the upper and lower limits of the hyperparameters), and encode the initialized hyperparameters into vectors to obtain parameter vectors, and repeat to obtain multiple different parameter vectors; Use an existing training data set (such as the KDD99 data set) to obtain the loss function value (such as the root mean square loss function value) corresponding to each parameter vector; According to the loss function values corresponding to all parameter vectors, determine the parameter vector with the largest loss function value as the optimal parameter vector; Based on the optimal parameter vector, use an adaptive learning mechanism to perform social learning on each parameter vector to obtain the parameter vector after social learning; For the parameter vector after social learning, use a local adjustment mechanism to perform local position adjustment on the parameter vector to obtain the parameter vector after local position adjustment; For the parameter vector after local position adjustment, use a global adjustment mechanism to perform global position adjustment on the parameter vector to obtain the parameter vector after global position adjustment; Repeat the execution of the adaptive learning mechanism, the local adjustment mechanism, and the global adjustment mechanism until the maximum number of training times is reached. According to the parameter vector after global position adjustment in the last training process, re-determine the optimal parameter vector, and use the hyperparameters in the optimal parameter vector as the final hyperparameters to complete the training.
[0033] Optionally, based on the optimal parameter vector, an adaptive learning mechanism is used to perform social learning on each parameter vector to obtain the parameter vector after social learning, which may include:
[0034]
[0035] Wherein, represents the adaptive inertia weight, represents pi, t represents the current number of training times, T represents the preset maximum number of training times, represents the t th parameter vector in the i th training process, i = 1, 2, …, I, I represents the total number of parameter vectors, represents the first constant factor, represents the first learning parameter, represents the optimal parameter vector, represents the second constant factor, represents the second learning parameter, represents the optimal parameter vector in the (t - 1)th training process, that is, the optimal parameter vector in the previous training process, represents the third learning parameter, represents the parameter vector after social learning .
[0036] The adaptive learning mechanism provided by the embodiments of the present invention can make the algorithm have a larger weight in the early stage of iteration, enable the parameter vector to widely search in the search space, which is beneficial to improving the global search performance of the algorithm. Then, by searching for the optimal positions in different training processes, it can effectively achieve the search in the optimal direction, with a certain degree of volatility, and can avoid falling into the local optimum prematurely to a certain extent.
[0037] Optionally, for the parameter vector after social learning, a local adjustment mechanism is used to perform local position adjustment on the parameter vector to obtain the parameter vector after local position adjustment as:
[0038] Wherein, represents the mth parameter vector after social learning in the tth training process, represents the parameter vector after local position adjustment , represents the worst parameter vector (i.e., the parameter vector with the largest loss function value), represents the optimal parameter vector, represents the first learning rate, and is a random number uniformly distributed between [0, 1]; represents the second learning rate, and is a random number uniformly distributed between [0, 1]; represents an adjustment factor randomly selected from (0, 1).
[0039] The local adjustment mechanism provided by the embodiments of the present invention searches the local area based on the worst position and the optimal position, so that more local unfamiliar areas can be searched, and the ability of the algorithm to escape from the local optimal solution can be improved to a certain extent.
[0040] Optionally, for the parameter vector after local position adjustment, a global adjustment mechanism is used to perform global position adjustment on the parameter vector, and the parameter vector after global position adjustment is obtained as:
[0041]
[0042] where represents the j th parameter vector after local position adjustment, j = 1, 2,..., I, represents the first random parameter vector corresponding to the parameter vector ; represents the second random evolution parameter vector corresponding to the parameter vector ; represents the parameter vector after global position adjustment , represents the first random number between (0, 1), represents the second random number between (0, 1), represents the third random number between (0, 1), represents the fourth random number between (0, 1), represents the fifth random number between (0, 1), represents the global search coefficient, represents the natural constant, T represents the maximum number of training times, represents pi.
[0043] The global adjustment mechanism provided by the present invention has a slow decline in the global search coefficient, which can enable the algorithm to have a large global jump ability in the early and middle stages, thereby effectively avoiding the algorithm from falling into the local optimum, thus improving the global search ability of the algorithm. In the later stage of the algorithm, the global search coefficient will decrease sharply, which can effectively ensure the convergence ability of the algorithm.
[0044] The intelligent optimization algorithm provided by the embodiments of the present invention can enable the trained neural network to better learn the data relationships in the dataset, so as to better identify network security and ensure the storage security of e-commerce order data.
[0045] In the embodiments of the present invention, when the network security status is network insecure, the data storage process of the current e-commerce order data is terminated, and network security is controlled, and abnormal information is fed back to the data storage user, including: When the network security status is network insecure, the data storage process of the current e-commerce order data is terminated; Restrict the access of the data storage user (such as prohibiting the user's access within a certain period of time or blocking the user) to control network security, and at the same time generate abnormal information of prohibited access to the data storage user.
[0046] In the embodiments of the present invention, the user private key is fragmented to obtain a plurality of private key fragments, including: Construct a known K-order polynomial with a constant term; wherein, the constant term in the known K-order polynomial is set as the user private key; when the user private key is not a decimal number, the private key is first converted to a decimal number so as to be applicable to various encryption systems; a known K-order polynomial means that the coefficients of each order are known; Randomly generate 2K independent variables, and input the independent variables into the known K-order polynomial to obtain the dependent variables output by the known K-order polynomial, and obtain the dependent variables corresponding to each independent variable; Form a private key fragment by combining any one of the dependent variables with the dependent variables corresponding to the independent variables. After traversing all the dependent variables, a plurality of private key fragments are obtained.
[0047] In the embodiments of the present invention, it further includes: When the data storage user accesses the stored e-commerce data, different servers encrypt the private key fragments with the public key announced by the data storage user and then transmit the encrypted private key fragments to the data storage user, so that the data storage user can restore the user private key according to the encrypted private key fragments to achieve the storage security control of e-commerce data.
[0048] In the embodiments of the present invention, different servers encrypt the private key fragments with the public key announced by the data storage user and then transmit the encrypted private key fragments to the data storage user, including: Query the public key corresponding to the data storage user; Based on the unique identity identifier code of the data storage user, query the server storing the corresponding private key fragments to obtain the first target server; Randomly determine more than K servers from the first target server to obtain multiple second target servers; Transmit the unique identity identification code corresponding to the data storage user, the public key corresponding to the data storage user, and the private key fragment transmission instruction to the second target server According to the unique identity identification code corresponding to the data storage user, query the private key fragment corresponding to the data storage user through the second target server to obtain the private key fragment to be sent; After encrypting the private key fragment to be sent by using the public key corresponding to the data storage user through the second target server, obtain the encrypted private key fragment; According to the unique identity identification code corresponding to the data storage user, query the data receiving address corresponding to the data storage user through the second target server, and transmit the encrypted private key fragment to the data storage user according to the data receiving address; Among them, the association relationship between the unique identity identification code corresponding to the data storage user and the corresponding data receiving address is pre-stored data or obtained during the process of the data storage user accessing data.
[0049] In the embodiment of the present invention, the data storage user restores the user private key according to the encrypted private key fragment, including: The data storage user constructs an unknown K-order polynomial with an attached constant term; where the unknown K-order polynomial means that the coefficients of each order are unknown; Use the dependent variable and independent variable in the private key fragment to decrypt the unknown K-order polynomial to obtain a known K-order polynomial, and take the constant term of the known K-order polynomial as the user private key.
[0050] The user private key fragmentation process provided by the embodiment of the present invention can effectively avoid data being unable to be decrypted or decrypted by illegal persons due to the loss of the user private key, and greatly increases the storage security of e-commerce order data.
[0051] In the embodiment of the present invention, it further includes: When the data storage user accesses the stored e-commerce data, query the target server storing the e-commerce data according to the unique identity identification code corresponding to the e-commerce order data to be stored, and schedule the target server to transmit the encrypted e-commerce order data to be stored to the data storage user, so that the data storage user completes data decryption according to the user private key and the encrypted e-commerce order data to be stored, and realizes the storage access control of e-commerce data.
[0052] Other embodiments of the present invention will be readily apparent to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. The present invention is intended to cover any variations, uses, or adaptations of the invention following the general principles of the invention and including known common knowledge or conventional technical means in the technical field not disclosed by the present invention. It should be understood that the present invention is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present invention is only limited by the appended claims.
Claims
1. A method for storing e-commerce order data, characterized in that, Including: Obtain the e-commerce order data to be stored, the unique identity identification code corresponding to the e-commerce order data to be stored, the user attributes corresponding to the e-commerce order data to be stored, and the real-time network traffic characteristics during the data storage process; Use a pre-set network security detection model to identify the real-time network traffic characteristics, and obtain the network security status during the data storage process; wherein, the network security status includes network security or network insecurity; When the network security status is network insecurity, terminate the data storage process of this e-commerce order data, control network security, and feedback abnormal information to the data storage user; When the network security status is network security, based on the user attributes corresponding to the e-commerce order data to be stored, use the attribute-based encryption algorithm to encrypt the e-commerce order data to be stored, and obtain the encrypted e-commerce order data to be stored and the user private key; After associating the encrypted e-commerce order data to be stored and the unique identity identification code corresponding to the e-commerce order data to be stored, transmit them to any server in the data storage server cluster for storage; Fragment the user private key to obtain multiple private key fragments, and transmit the multiple private key fragments to different servers in the data storage server cluster for storage respectively, completing the data storage process of the e-commerce order data.
2. The e-commerce order data storage method according to claim 1, wherein Use a pre-set network security detection model to identify the real-time network traffic characteristics, and obtain the network security status during the data storage process, including: Construct the real-time network traffic characteristics into a data vector or a data matrix to obtain the data to be identified; Use the data to be identified as the input of the pre-set network security detection model, obtain the output of the pre-set network security detection model, and use the state category with the highest probability in the output as the network security status during the data storage process.
3. The e-commerce order data storage method according to claim 2, wherein The pre-set network security detection model is set as: a convolutional neural network or a recurrent neural network.
4. The e-commerce order data storage method according to claim 3, wherein The pre-set method of the network security detection model includes: After using an intelligent optimization algorithm to optimize the hyperparameters of the network security detection model, determine the final hyperparameters of the network security detection model, and deploy the network security detection model according to the final hyperparameters of the network security detection model, completing the pre-setting of the network security detection model.
5. The e-commerce order data storage method according to claim 1, wherein When the network security status is network insecurity, terminate the data storage process of this e-commerce order data, control network security, and feedback abnormal information to the data storage user, including: When the network security status is network insecurity, terminate the data storage process of this e-commerce order data; Restrict the access of the data storage user to control network security, and at the same time generate abnormal information of prohibited access to the data storage user.
6. The e-commerce order data storage method according to claim 1, wherein, Fragment the user private key to obtain multiple private key fragments, including: Construct a known K-order polynomial with a constant term; wherein, the constant term in the known K-order polynomial is set as the user private key; when the user private key is not a decimal number, first convert the private key to a decimal number; a known K-order polynomial means that the coefficients of each order are known; Randomly generate 2K independent variables, input the independent variables into a known K - order polynomial, obtain the dependent variables output by the known K - order polynomial, and get the dependent variables corresponding to each independent variable. Form a private key fragment by combining any one of the dependent variables with the dependent variables corresponding to the independent variables. After traversing all the dependent variables, obtain multiple private key fragments.
7. The e-commerce order data storage method according to claim 1, wherein It also includes: When a data storage user accesses the stored e - commerce data, different servers use the public key announced by the data storage user to encrypt the private key fragments, and then transmit the encrypted private key fragments to the data storage user, so that the data storage user can restore the user private key based on the encrypted private key fragments, realizing the storage security control of e - commerce data.
8. The e-commerce order data storage method according to claim 7, wherein Using the public key announced by the data storage user, different servers encrypt the private key fragments and then transmit the encrypted private key fragments to the data storage user, including: Query the public key corresponding to the data storage user. Based on the unique identity identification code corresponding to the data storage user, query the server storing the corresponding private key fragment to obtain the first target server. Randomly determine more than K servers from the first target server to obtain multiple second target servers. Transmit the unique identity identification code corresponding to the data storage user, the public key corresponding to the data storage user, and the private key fragment transmission instruction to the second target server. According to the unique identity identification code corresponding to the data storage user, query the private key fragment corresponding to the data storage user through the second target server to obtain the private key fragment to be sent. Encrypt the private key fragment to be sent by using the public key corresponding to the data storage user through the second target server to obtain the encrypted private key fragment. According to the unique identity identification code corresponding to the data storage user, query the data receiving address corresponding to the data storage user through the second target server, and transmit the encrypted private key fragment to the data storage user according to the data receiving address. Among them, the association relationship between the unique identity identification code corresponding to the data storage user and the corresponding data receiving address is pre - stored data or obtained during the data storage user's access to data.
9. The e-commerce order data storage method according to claim 8, wherein The data storage user restores the user private key based on the encrypted private key fragment, including: The data storage user constructs an unknown K - order polynomial with a constant term; where the unknown K - order polynomial means that the coefficient of each order is unknown. Use the dependent variables and independent variables in the private key fragment to decrypt the unknown K - order polynomial to obtain a known K - order polynomial, and take the constant term of the known K - order polynomial as the user private key.
10. The e-commerce order data storage method according to claim 1, wherein It also includes: When a data storage user accesses the stored e - commerce data, query the target server storing the e - commerce data according to the unique identity identification code corresponding to the e - commerce order data to be stored, and schedule the target server to transmit the encrypted e - commerce order data to be stored to the data storage user, so that the data storage user can complete data decryption according to the user private key and the encrypted e - commerce order data to be stored, and use the attribute - based encryption algorithm to realize the storage access control of e - commerce data.
Citation Information
Patent Citations
Data management method of transaction platform
CN113111380A
Key management system and method, electronic equipment and computer readable storage medium
CN116264505A
Efficient attribute-based encryption method for proxy re-encryption by using edge controller
CN116318874A
Apparatus for performing on behalf an electronic signature for client terminal and operating method thereof
KR1020170087663A
Method and system for distributed data storage with enhanced security, resilience, and control
WO2020236500A1