E-commerce order data storage method
By combining the network security detection model with the attribute-based encryption algorithm, the storage process of e-commerce order data is identified and controlled, solving the problems of low storage efficiency and poor security of e-commerce order data, and achieving efficient and secure data storage.
Patent Information
- Application Number
- CN202510409093.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-02
- Publication Date
- 2025-09-16
- Estimated Expiration
- 2045-04-02
AI Technical Summary
The existing e-commerce order data storage technology has problems such as low storage efficiency, poor data security, and slow query speed, which makes it difficult to meet the efficiency, security, and speed requirements of modern e-commerce business.
A pre-set network security detection model is used to identify real-time network traffic characteristics, obtain the network security status during data storage, and terminate the storage process when the network security status is unsafe. The attribute-based encryption algorithm is used to encrypt the data, and the user's private key is fragmented and stored in isolation.
It improves the security and loss resistance of data storage, ensures the security and reliability of the data storage process, and improves data storage efficiency and query speed.
Smart Images

Figure CN120301631B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of data processing technology, and in particular relates to a method for storing e-commerce order data. Background Art
[0002] E-commerce order data is core information in e-commerce transactions, encompassing multi-dimensional data such as user purchasing behavior, product information, transaction amounts, and shipping addresses. With the booming e-commerce industry, the volume of order data has grown dramatically, becoming a crucial basis for companies to analyze market trends, optimize operational strategies, and enhance customer experience. Order data typically includes fields such as order number, user ID, product ID, quantity, price, payment method, order time, shipping time, and delivery time. It is structured, highly real-time, and highly valuable. Effective storage and management of e-commerce order data is crucial for ensuring data security, improving data processing efficiency, and supporting business decision-making. With the rapid development of the internet and the growing prosperity of the e-commerce industry, the volume of order data has exploded. Traditional methods for storing order data often suffer from low storage efficiency, poor data security, and slow query speeds, making them unable to meet the efficiency, security, and speed requirements of modern e-commerce operations. Summary of the Invention
[0003] The present invention provides an e-commerce order data storage method to solve the problem of low security performance of e-commerce order data in the prior art.
[0004] An e-commerce order data storage method, comprising:
[0005] Obtaining the e-commerce order data to be stored, the unique identification code corresponding to the e-commerce order data to be stored, the user attributes corresponding to the e-commerce order data to be stored, and the real-time network traffic characteristics during the data storage process;
[0006] Using a pre-set network security detection model to identify real-time network traffic characteristics, and obtain the network security status during data storage; the network security status includes network security or network insecurity;
[0007] When the network security status is unsafe, the data storage process of the e-commerce order data is terminated, the network security is managed and controlled, and abnormal information is fed back to the data storage user;
[0008] When the network security status is network security, the e-commerce order data to be stored is encrypted using an attribute-based encryption algorithm based on the user attributes corresponding to the e-commerce order data to be stored, and the encrypted e-commerce order data to be stored and the user private key are obtained;
[0009] After associating the encrypted e-commerce order data to be stored with the unique identification code corresponding to the e-commerce order data to be stored, the data is transmitted to any server in the data storage server cluster for storage;
[0010] The user private key is fragmented to obtain multiple private key fragments, and the multiple private key fragments are respectively transmitted to different servers in the data storage server cluster for storage, thereby completing the storage process of the e-commerce order data.
[0011] Furthermore, a pre-set network security detection model is used to identify real-time network traffic characteristics and obtain the network security status during data storage, including:
[0012] Construct real-time network traffic features into data vectors or data matrices to obtain the data to be identified;
[0013] The data to be identified is used as the input of a preset network security detection model, the output of the preset network security detection model is obtained, and the state category with the highest probability in the output is used as the network security state during the data storage process.
[0014] Furthermore, the pre-set network security detection model is set to: a convolutional neural network or a recurrent neural network.
[0015] Furthermore, the method for presetting the network security detection model includes:
[0016] After optimizing the hyperparameters of the network security detection model using an intelligent optimization algorithm, the final hyperparameters of the network security detection model are determined, and the network security detection model is deployed according to the final hyperparameters of the network security detection model to complete the pre-setting of the network security detection model.
[0017] Furthermore, when the network security status is unsafe, the data storage process of the e-commerce order data is terminated, network security is managed and controlled, and abnormal information is fed back to the data storage user, including:
[0018] When the network status is unsafe, the data storage process of the e-commerce order data is terminated;
[0019] Limit the access of data storage users to achieve network security management and control, and generate access-prohibited exception information to data storage users.
[0020] Furthermore, the user private key is fragmented to obtain multiple private key fragments, including:
[0021] Construct a known K-order polynomial with a constant term. The constant term in the known K-order polynomial is set to the user's private key. If the user's private key is not a decimal number, first convert the private key to a decimal number. A known K-order polynomial means that the coefficients of each order are known.
[0022] Randomly generate 2K independent variables, input the independent variables into a known K-order polynomial, obtain the dependent variable output by the known K-order polynomial, and obtain the dependent variable corresponding to each independent variable;
[0023] The dependent variables corresponding to any dependent variable and the independent variable are combined into a private key fragment. After traversing all dependent variables, multiple private key fragments are obtained.
[0024] Furthermore, it also includes:
[0025] When a data storage user accesses the stored e-commerce data, different servers use the public key published by the data storage user to encrypt the private key fragments, and then transmit the encrypted private key fragments to the data storage user, so that the data storage user can restore the user's private key based on the encrypted private key fragments, thereby realizing the storage security control of the e-commerce data.
[0026] Furthermore, different servers encrypt the private key fragments using the public key published by the data storage user, and transmit the encrypted private key fragments to the data storage user, including:
[0027] Query the public key corresponding to the data storage user;
[0028] Based on the unique identity code corresponding to the data storage user, query the server storing the corresponding private key fragment to obtain the first target server;
[0029] Randomly determine a number of servers greater than K from the first target servers to obtain multiple second target servers;
[0030] Transmit the unique identification code corresponding to the data storage user, the public key corresponding to the data storage user, and the private key fragment transmission instruction to the second target server
[0031] According to the unique identity code corresponding to the data storage user, query the private key fragment corresponding to the data storage user through the second target server to obtain the private key fragment to be sent;
[0032] After encrypting the private key fragments to be sent using the public key corresponding to the data storage user through the second target server, the encrypted private key fragments are obtained;
[0033] According to the unique identification code corresponding to the data storage user, the data receiving address corresponding to the data storage user is queried through the second target server, and the encrypted private key fragments are transmitted to the data storage user according to the data receiving address;
[0034] The association between the unique identification code corresponding to the data storage user and the corresponding data receiving address is obtained during the pre-stored data or the data storage user accessing the data.
[0035] Furthermore, the data storage user recovers the user's private key based on the encrypted private key fragments, including:
[0036] The data storage user constructs an unknown K-order polynomial with a constant term. The unknown K-order polynomial means that the coefficients of each order are unknown.
[0037] The unknown K-order polynomial is decrypted using the dependent variable and independent variable in the private key fragment to obtain the known K-order polynomial, and the constant term of the known K-order polynomial is taken as the user's private key.
[0038] Furthermore, it also includes:
[0039] When a data storage user accesses the stored e-commerce data, the target server storing the e-commerce data is queried based on the unique identity identification code corresponding to the e-commerce order data to be stored, and the target server is scheduled to transmit the encrypted e-commerce order data to be stored to the data storage user, so that the data storage user can complete data decryption based on the user's private key and the encrypted e-commerce order data to be stored, and use the attribute-based encryption algorithm to realize storage access control of the e-commerce data.
[0040] The present invention provides an e-commerce order data storage method, which uses a preset network security detection model to identify real-time network traffic characteristics, obtains the network security status during the data storage process, and controls the data storage process according to the network security status. It can preliminarily ensure the security of the data storage process, and then use an attribute-based encryption algorithm to encrypt the stored e-commerce order data, further improving data security. Only data storage users related to the data can access the data, and then fragment the user's private key, and store the private key fragments in isolation, which greatly enhances the security and anti-loss of the data and ensures the storage security of the e-commerce order data. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.
[0042] Figure 1A flowchart of a method for storing e-commerce order data provided by an embodiment of the present invention.
[0043] The above drawings illustrate specific embodiments of the present invention, which will be described in more detail below. These drawings and the accompanying description are not intended to limit the scope of the present invention in any way, but rather to illustrate the concept of the present invention to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION
[0044] Exemplary embodiments will be described in detail herein, examples of which are illustrated in the accompanying drawings. In the following description, when referring to the drawings, like numbers in different figures represent like or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all possible embodiments consistent with the present invention. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present invention, as detailed in the appended claims.
[0045] The embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
[0046] like Figure 1 As shown, an embodiment of the present invention provides an e-commerce order data storage method, including:
[0047] S1. Obtain the e-commerce order data to be stored, the unique identification code corresponding to the e-commerce order data to be stored, the user attributes corresponding to the e-commerce order data to be stored, and the real-time network traffic characteristics during the data storage process;
[0048] The e-commerce order data to be stored can be data transmitted by users or data from e-commerce platforms, and is the data to be stored in the embodiments of the present invention. The unique identity identification code corresponding to the e-commerce order data to be stored can be used to store and search the data of the data storage user, which can effectively improve the efficiency of data storage. The user attributes corresponding to the e-commerce order data to be stored are mainly used for attribute-based encryption, so that only users with user attributes specified by the access policy can access and decrypt the data, fundamentally improving the security of the data. The real-time network traffic characteristics during the data storage process are used to identify the network security status, thereby identifying the security of the data storage process and the access process, which can effectively ensure data security.
[0049] S2. Using a pre-set network security detection model to identify real-time network traffic characteristics, and obtaining the network security status during data storage; wherein the network security status includes network security or network insecurity;
[0050] The pre-set network security detection model can be a deep learning model trained with historical data sets. This deep learning model often has the ability to identify network traffic characteristics. By identifying real-time network traffic characteristics through the pre-set network security detection model, it can effectively identify network security during data storage or data access, effectively improving data storage security.
[0051] S3. When the network security status is unsafe, the data storage process of the e-commerce order data is terminated, network security is managed and controlled, and abnormal information is fed back to the data storage user;
[0052] When the network security status is network insecurity, it indicates that the current data storage user may be attacking the data storage server cluster and the data storage security is threatened. Therefore, network security can be managed and controlled to ensure the security of the data storage server cluster.
[0053] S4. When the network security status is network security, encrypt the e-commerce order data to be stored using an attribute-based encryption algorithm based on the user attributes corresponding to the e-commerce order data to be stored, and obtain the encrypted e-commerce order data to be stored and the user private key;
[0054] When the network security status is network security, it indicates that the current data access process is normal. When the account and password of the data storage user match correctly, data storage or data access can be performed for the user. The use of attribute-based encryption algorithm to encrypt the stored e-commerce order data can greatly improve data security.
[0055] S5. After associating the encrypted e-commerce order data to be stored with the unique identification code corresponding to the e-commerce order data to be stored, the data is transmitted to any server in the data storage server cluster for storage;
[0056] Optionally, the associated data mirrors can be stored on different servers in the data storage server cluster, thereby achieving multiple backup storage and improving the data loss resistance.
[0057] S6. Fragment the user private key to obtain multiple private key fragments, and transmit the multiple private key fragments to different servers in the data storage server cluster for storage, thereby completing the storage process of the e-commerce order data.
[0058] The user private key is fragmented to obtain multiple private key fragments, and the multiple private key fragments are transmitted to different servers in the data storage server cluster for storage. Even if an illegal data acquirer obtains some of the private key fragments, he or she will not be able to decrypt the data, further improving data security.
[0059] The present invention provides an e-commerce order data storage method, which uses a preset network security detection model to identify real-time network traffic characteristics, obtains the network security status during the data storage process, and controls the data storage process according to the network security status. It can preliminarily ensure the security of the data storage process, and then use an attribute-based encryption algorithm to encrypt the stored e-commerce order data, further improving data security. Only data storage users related to the data can access the data, and then fragment the user's private key, and store the private key fragments in isolation, which greatly enhances the security and anti-loss of the data and ensures the storage security of the e-commerce order data.
[0060] In an embodiment of the present invention, a preset network security detection model is used to identify real-time network traffic characteristics and obtain the network security status during data storage, including:
[0061] The real-time network traffic features are constructed as data vectors or data matrices to obtain the data to be identified. For example, assuming that the pre-set network security detection model is set to a convolutional neural network, the real-time network traffic features should be constructed as a data matrix, which can be constructed by referring to the existing methods.
[0062] The data to be identified is used as the input of a preset network security detection model, the output of the preset network security detection model is obtained, and the state category with the highest probability in the output is used as the network security state during the data storage process.
[0063] In the embodiments of the present invention, the pre-set network security detection model is configured as a convolutional neural network or a recurrent neural network. However, it is worth noting that the above two neural networks are merely preferred embodiments of the present invention, and other neural networks can also be used as network security detection models to implement network security detection.
[0064] In an embodiment of the present invention, the method for presetting the network security detection model includes:
[0065] After optimizing the hyperparameters of the network security detection model using an intelligent optimization algorithm, the final hyperparameters of the network security detection model are determined, and the network security detection model is deployed according to the final hyperparameters of the network security detection model to complete the pre-setting of the network security detection model.
[0066] Optionally, an embodiment of the present invention provides an intelligent optimization algorithm to improve the accuracy of network security detection, which may include:
[0067] Randomly initialize the hyperparameters of the network security detection model (e.g., randomly initialize between the upper and lower limits of the hyperparameters), encode the initialized hyperparameters into a vector, obtain the parameter vector, and repeatedly obtain multiple different parameter vectors;
[0068] Use an existing training dataset (such as the KDD99 dataset) to obtain the loss function value (such as the root mean square loss function value) corresponding to each parameter vector;
[0069] According to the loss function values corresponding to all parameter vectors, the parameter vector with the largest loss function value is determined as the optimal parameter vector;
[0070] Based on the optimal parameter vector, an adaptive learning mechanism is used to perform social learning on each parameter vector to obtain a parameter vector after social learning;
[0071] For the parameter vector after social learning, a local adjustment mechanism is used to adjust the local position of the parameter vector to obtain the parameter vector after local position adjustment;
[0072] For the parameter vector after local position adjustment, a global adjustment mechanism is used to perform global position adjustment on the parameter vector to obtain the parameter vector after global position adjustment;
[0073] The adaptive learning mechanism, local adjustment mechanism, and global adjustment mechanism are repeatedly executed until the maximum number of training times is reached. The optimal parameter vector is re-determined based on the parameter vector after global position adjustment during the last training process, and the hyperparameters in the optimal parameter vector are used as the final hyperparameters to complete the training.
[0074] Optionally, based on the optimal parameter vector, an adaptive learning mechanism is used to perform social learning on each parameter vector to obtain a parameter vector after social learning, which may include:
[0075]
[0076]
[0077] in, represents the adaptive inertia weight, represents pi, t Indicates the current number of training times, T indicates the preset maximum number of training times, Indicates the t During the training i parameter vector, i =1,2,…,I, I represents the total number of parameter vectors, represents the first constant factor, represents the first learning parameter, represents the optimal parameter vector, represents the second constant factor, represents the second learning parameter, represents the optimal parameter vector in the t-1th training process, that is, the optimal parameter vector in the previous training process, represents the third learning parameter, represents the parameter vector after social learning .
[0078] The adaptive learning mechanism provided by the embodiment of the present invention can give the algorithm a greater weight in the early stage of iteration, so that the parameter vector can be searched widely in the search space, which is conducive to improving the global search performance of the algorithm. Then, by searching the optimal position in different training processes, the search in the optimal direction can be effectively realized, with a certain volatility, which can avoid falling into the local optimum too early to a certain extent.
[0079] Optionally, for the parameter vector after social learning, a local adjustment mechanism is used to adjust the local position of the parameter vector, and the parameter vector after local position adjustment is obtained as follows:
[0080]
[0081] in, represents the parameter vector after the mth social learning during the tth training process, Represents the parameter vector after local position adjustment , represents the worst parameter vector (i.e. the parameter vector with the largest loss function value), represents the optimal parameter vector, represents the first learning rate, and is a random number uniformly distributed between [0,1]; represents the second learning rate, and is a random number uniformly distributed between [0,1]; Represents a random adjustment factor between (0,1).
[0082] The local adjustment mechanism provided by the embodiment of the present invention searches the local area based on the worst position and the optimal position, thereby searching more local unfamiliar areas and improving the ability of the algorithm to escape from the local optimal solution to a certain extent.
[0083] Optionally, for the parameter vector after the local position adjustment, a global adjustment mechanism is used to perform global position adjustment on the parameter vector, and the parameter vector after the global position adjustment is obtained as follows:
[0084]
[0085]
[0086] in, Indicates the j The parameter vector after local position adjustment, j =1,2,…,I, Represents the parameter vector The corresponding first random parameter vector, Represents the parameter vector The corresponding second random evolution parameter vector, Represents the parameter vector after global position adjustment , represents the first random number between (0,1), represents the second random number between (0,1), represents the third random number between (0,1), represents the fourth random number between (0,1), represents the fifth random number between (0,1), represents the global search coefficient, represents a natural constant, T represents the maximum number of training times, Represents pi.
[0087] The global adjustment mechanism provided by the present invention allows the global search coefficient to decrease slowly, which can enable the algorithm to have a larger global jump ability in the early and middle stages, thereby effectively preventing the algorithm from falling into local optimality, thereby improving the global search ability of the algorithm. In the later stage of the algorithm, the global search coefficient will decrease sharply, which can effectively ensure the convergence ability of the algorithm.
[0088] The intelligent optimization algorithm provided by the embodiment of the present invention can enable the trained neural network to better learn the data relationships in the data set, thereby better identifying network security and ensuring the storage security of e-commerce order data.
[0089] In an embodiment of the present invention, when the network security status is unsafe, the data storage process of the e-commerce order data is terminated, network security is managed and controlled, and abnormal information is fed back to the data storage user, including:
[0090] When the network status is unsafe, the data storage process of the e-commerce order data is terminated;
[0091] Restrict data storage users' access (such as prohibiting the user's access for a certain period of time or blacklisting the user) to implement network security management and control, and generate access prohibition exception information to the data storage user.
[0092] In an embodiment of the present invention, fragmenting the user private key to obtain multiple private key fragments includes:
[0093] Construct a known K-order polynomial with a constant term. The constant term in the known K-order polynomial is set to the user's private key. If the user's private key is not a decimal number, the private key is first converted to a decimal number, so that it can be applied to various encryption systems. A known K-order polynomial means that the coefficients of each order are known.
[0094] Randomly generate 2K independent variables, input the independent variables into a known K-order polynomial, obtain the dependent variable output by the known K-order polynomial, and obtain the dependent variable corresponding to each independent variable;
[0095] The dependent variables corresponding to any dependent variable and the independent variable are combined into a private key fragment. After traversing all dependent variables, multiple private key fragments are obtained.
[0096] In an embodiment of the present invention, the following further comprises:
[0097] When a data storage user accesses the stored e-commerce data, different servers use the public key published by the data storage user to encrypt the private key fragments, and then transmit the encrypted private key fragments to the data storage user, so that the data storage user can restore the user's private key based on the encrypted private key fragments, thereby realizing the storage security control of the e-commerce data.
[0098] In an embodiment of the present invention, different servers encrypt private key fragments using a public key published by a data storage user, and then transmit the encrypted private key fragments to the data storage user, including:
[0099] Query the public key corresponding to the data storage user;
[0100] Based on the unique identity code corresponding to the data storage user, query the server storing the corresponding private key fragment to obtain the first target server;
[0101] Randomly determine a number of servers greater than K from the first target servers to obtain multiple second target servers;
[0102] Transmit the unique identification code corresponding to the data storage user, the public key corresponding to the data storage user, and the private key fragment transmission instruction to the second target server
[0103] According to the unique identity code corresponding to the data storage user, query the private key fragment corresponding to the data storage user through the second target server to obtain the private key fragment to be sent;
[0104] After encrypting the private key fragments to be sent using the public key corresponding to the data storage user through the second target server, the encrypted private key fragments are obtained;
[0105] According to the unique identification code corresponding to the data storage user, the data receiving address corresponding to the data storage user is queried through the second target server, and the encrypted private key fragments are transmitted to the data storage user according to the data receiving address;
[0106] The association between the unique identification code corresponding to the data storage user and the corresponding data receiving address is obtained during the pre-stored data or the data storage user accessing the data.
[0107] In an embodiment of the present invention, the data storage user recovers the user private key based on the encrypted private key fragments, including:
[0108] The data storage user constructs an unknown K-order polynomial with a constant term. The unknown K-order polynomial means that the coefficients of each order are unknown.
[0109] The unknown K-order polynomial is decrypted using the dependent variable and independent variable in the private key fragment to obtain the known K-order polynomial, and the constant term of the known K-order polynomial is taken as the user's private key.
[0110] The user private key fragmentation process provided by the embodiment of the present invention can effectively prevent data from being unable to be decrypted or being decrypted by illegal persons due to the loss of user private keys, greatly increasing the storage security of e-commerce order data.
[0111] In an embodiment of the present invention, the following further comprises:
[0112] When a data storage user accesses the stored e-commerce data, the target server storing the e-commerce data is queried based on the unique identity identification code corresponding to the e-commerce order data to be stored, and the target server is scheduled to transmit the encrypted e-commerce order data to be stored to the data storage user, so that the data storage user can complete data decryption based on the user's private key and the encrypted e-commerce order data to be stored, and use the attribute-based encryption algorithm to realize storage access control of the e-commerce data.
[0113] Those skilled in the art will readily appreciate other embodiments of the present invention after considering the specification and practicing the invention disclosed herein. The present invention is intended to cover any variations, uses, or adaptations of the present invention that follow the general principles of the present invention and include common knowledge or customary techniques in the art not disclosed herein. It should be understood that the present invention is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and variations can be made without departing from the scope thereof. The scope of the present invention is limited only by the appended claims.
Claims
1. A method for storing e-commerce order data, characterized in that: include: Obtaining the e-commerce order data to be stored, the unique identification code corresponding to the e-commerce order data to be stored, the user attributes corresponding to the e-commerce order data to be stored, and the real-time network traffic characteristics during the data storage process; Using a pre-set network security detection model to identify real-time network traffic characteristics, and obtain the network security status during data storage; the network security status includes network security or network insecurity; When the network security status is unsafe, the data storage process of the e-commerce order data is terminated, the network security is managed and controlled, and abnormal information is fed back to the data storage user; When the network security status is network security, the e-commerce order data to be stored is encrypted using an attribute-based encryption algorithm based on the user attributes corresponding to the e-commerce order data to be stored, and the encrypted e-commerce order data to be stored and the user private key are obtained; After associating the encrypted e-commerce order data to be stored with the unique identification code corresponding to the e-commerce order data to be stored, the data is transmitted to any server in the data storage server cluster for storage; The user private key is fragmented to obtain multiple private key fragments, and the multiple private key fragments are respectively transmitted to different servers in the data storage server cluster for storage, thereby completing the storage process of the e-commerce order data.
2. The e-commerce order data storage method according to claim 1, characterized in that: Use pre-set network security detection models to identify real-time network traffic characteristics and obtain network security status during data storage, including: Construct real-time network traffic features into data vectors or data matrices to obtain the data to be identified; The data to be identified is used as the input of a preset network security detection model, the output of the preset network security detection model is obtained, and the state category with the highest probability in the output is used as the network security state during the data storage process.
3. The e-commerce order data storage method according to claim 2, characterized in that: The pre-set network security detection model is set to: convolutional neural network or recurrent neural network.
4. The e-commerce order data storage method according to claim 3, characterized in that: The method for presetting the network security detection model includes: After optimizing the hyperparameters of the network security detection model using an intelligent optimization algorithm, the final hyperparameters of the network security detection model are determined, and the network security detection model is deployed according to the final hyperparameters of the network security detection model to complete the pre-setting of the network security detection model.
5. The e-commerce order data storage method according to claim 1, characterized in that: When the network security status is unsafe, the data storage process of the e-commerce order data is terminated, network security is managed and controlled, and abnormal information is fed back to the data storage user, including: When the network status is unsafe, the data storage process of the e-commerce order data is terminated; Limit the access of data storage users to achieve network security management and control, and generate access-prohibited exception information to data storage users.
6. The e-commerce order data storage method according to claim 1, characterized in that: The user private key is fragmented to obtain multiple private key fragments, including: Construct a known K-order polynomial with a constant term. The constant term in the known K-order polynomial is set to the user's private key. If the user's private key is not a decimal number, first convert the private key to a decimal number. A known K-order polynomial means that the coefficients of each order are known. Randomly generate 2K independent variables, input the independent variables into a known K-order polynomial, obtain the dependent variable output by the known K-order polynomial, and obtain the dependent variable corresponding to each independent variable; The dependent variables corresponding to any dependent variable and the independent variable are combined into a private key fragment. After traversing all dependent variables, multiple private key fragments are obtained.
7. The e-commerce order data storage method according to claim 1, characterized in that: Also includes: When a data storage user accesses the stored e-commerce data, different servers use the public key published by the data storage user to encrypt the private key fragments, and then transmit the encrypted private key fragments to the data storage user, so that the data storage user can restore the user's private key based on the encrypted private key fragments, thereby realizing the storage security control of the e-commerce data.
8. The e-commerce order data storage method according to claim 7, characterized in that: Different servers encrypt the private key fragments using the public key published by the data storage user, and then transmit the encrypted private key fragments to the data storage user, including: Query the public key corresponding to the data storage user; Based on the unique identity code corresponding to the data storage user, query the server storing the corresponding private key fragment to obtain the first target server; Randomly determine a number of servers greater than K from the first target servers to obtain multiple second target servers; Transmit the unique identification code corresponding to the data storage user, the public key corresponding to the data storage user, and the private key fragment transmission instruction to the second target server According to the unique identity code corresponding to the data storage user, query the private key fragment corresponding to the data storage user through the second target server to obtain the private key fragment to be sent; After encrypting the private key fragments to be sent using the public key corresponding to the data storage user through the second target server, the encrypted private key fragments are obtained; According to the unique identification code corresponding to the data storage user, the data receiving address corresponding to the data storage user is queried through the second target server, and the encrypted private key fragments are transmitted to the data storage user according to the data receiving address; The association between the unique identification code corresponding to the data storage user and the corresponding data receiving address is obtained during the pre-stored data or the data storage user accessing the data.
9. The e-commerce order data storage method according to claim 8, characterized in that: The data storage user recovers the user's private key based on the encrypted private key fragments, including: The data storage user constructs an unknown K-order polynomial with a constant term. The unknown K-order polynomial means that the coefficients of each order are unknown. The unknown K-order polynomial is decrypted using the dependent variable and independent variable in the private key fragment to obtain the known K-order polynomial, and the constant term of the known K-order polynomial is taken as the user's private key.
10. The e-commerce order data storage method according to claim 1, characterized in that: Also includes: When a data storage user accesses the stored e-commerce data, the target server storing the e-commerce data is queried based on the unique identity identification code corresponding to the e-commerce order data to be stored, and the target server is scheduled to transmit the encrypted e-commerce order data to be stored to the data storage user, so that the data storage user can complete data decryption based on the user's private key and the encrypted e-commerce order data to be stored, and use the attribute-based encryption algorithm to realize storage access control of the e-commerce data.
Citation Information
Patent Citations
Key management system and method, electronic equipment and computer readable storage medium
CN116264505A
Efficient attribute-based encryption method for proxy re-encryption by using edge controller
CN116318874A