Sensitive data collaborative auditing platform and method based on multi-party network security computing
By hierarchically obfuscating the computing architecture and cross-domain anchoring mechanism, combining Paillier homomorphic encryption, Shamir secret sharing and MPC computing, the security and cross-domain compatibility problems of multi-party secure computing are solved, and efficient and secure collaborative audit of sensitive data is achieved.
Patent Information
- Application Number
- CN202510628733.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-15
- Publication Date
- 2025-07-18
AI Technical Summary
The existing multi-party security computing technology has significant bottlenecks in terms of security, efficiency and cross-domain compatibility, lack of quantum security and rule credibility, and weak cross-domain audit traceability capabilities.
The layered obfuscation computing architecture is adopted, including the data input layer, obfuscation computing layer and audit execution layer. It uses Paillier homomorphic encryption, Shamir secret sharing and MPC computing logic, combined with zero-knowledge proof and cross-domain anchoring mechanism, and through post-quantum encryption algorithm and dynamic threshold adjustment, the data is safely sharded and reasonable transmission is achieved.
It significantly improves the security, efficiency and cross-domain compatibility of multi-party collaborative audits, resists quantum computing attacks, reduces real-time MPC computing, reduces communication complexity, and optimizes storage overhead through Merkle tree and Polkadot XCMP protocols.
Smart Images

Figure CN120342576A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of multi-party secure computing, and more specifically, to a sensitive data collaborative auditing platform and method based on multi-party network security computing. Background Art
[0002] With the surging demand for data collaboration auditing in fields such as finance, healthcare, and government affairs, sensitive data collaborative auditing technology based on multi-party secure computing (MPC) has gradually become a research hotspot. However, the existing technologies still have significant bottlenecks in terms of security, efficiency, and cross-domain compatibility, which are specifically manifested as follows:
[0003] Lack of quantum security and rule credibility: The existing oblivious transfer (OT) protocols rely on RSA or elliptic curve encryption and are vulnerable to quantum computing attacks (such as: Shor's algorithm).
[0004] Weak cross-domain auditing and tracing capabilities: The existing solutions rely on centralized databases or single blockchains to store auditing results, posing a risk of single-point failure. Summary of the Invention
[0005] The purpose of the present invention is to provide a sensitive data collaborative auditing platform and method based on multi-party network security computing to improve the security, efficiency, and cross-domain compatibility of multi-party collaborative auditing in view of the deficiencies in the above-mentioned existing technologies.
[0006] To achieve the above objective, the technical solutions adopted in the embodiments of the present application are as follows:
[0007] In a first aspect, an embodiment of the present application provides a sensitive data collaborative auditing platform based on multi-party network security computing, including: a data input layer for each data holder to obtain original data, standardize the original data to obtain standardized data, perform differential privacy processing on the standardized data to obtain privacy data, encrypt the privacy data using the Paillier homomorphic encryption algorithm to obtain ciphertext, perform fragmentation on the ciphertext using Shamir secret sharing to obtain a plurality of fragmented ciphertexts, and upload the fragmented ciphertexts to a confusion layer; a confusion calculation layer, where the participating nodes of the confusion calculation layer are divided into data layer nodes, a confusion layer node group, and an auditing layer node; the data layer nodes are used to receive the fragmented ciphertexts; the confusion layer node group is used to aggregate the fragmented ciphertexts using the Paillier homomorphic encryption algorithm to obtain an aggregated ciphertext, perform fragmentation on the aggregated ciphertext using Shamir secret sharing to obtain a plurality of fragmented aggregated ciphertexts, and distribute the fragmented aggregated ciphertexts to the auditing layer nodes; the auditing layer nodes are used to perform target calculation on the fragmented aggregated ciphertexts based on the MPC calculation logic; an auditing execution layer, including an auditing rule compiler, where the auditing rule compiler is used to convert auditing rules into the MPC calculation logic.
[0008] In one implementation, the confusion layer node group consists of multiple trusted third-party nodes, and each node runs in a TEE.
[0009] In one implementation, the confusion calculation layer is further used to dynamically adjust the threshold of the Shamir secret sharing according to data tags; the data tags include sensitivity levels.
[0010] In one implementation, the confusion calculation layer is further used to transmit the fragmented aggregated ciphertext between the sender and the receiver among the participating parties based on a post-quantum encryption algorithm.
[0011] In one implementation, the auditing execution layer further includes a zero-knowledge proof generator, where the zero-knowledge proof generator is used to record the input and output values of the circuit gate operations in the target calculation process, and generate a zero-knowledge proof based on a zero-knowledge proof library according to the input and output values of the circuit gate operations.
[0012] In one implementation, the zero-knowledge proof generator is further used to verify the zero-knowledge proof through a publicly available Verification Key.
[0013] In one implementation, the auditing execution layer further includes a dynamic rule updater, where the dynamic rule updater is used to generate an updated circuit and an updated zero-knowledge proof according to the adjusted auditing rules when the auditing rules are adjusted, and obtain the consensus of the majority of nodes through a smart contract voting mechanism.
[0014] In one embodiment, the sensitive data collaborative auditing platform based on multi-party network security computing further includes a cross-domain anchoring layer, which is used to, after each audit is completed, construct the leaf nodes of a Merkle tree for the audit results in chronological order, and then merge them layer by layer upward until the root hash is generated to obtain the Merkle tree.
[0015] In one embodiment, the cross-domain anchoring layer is further used to write the root hash into a heterogeneous chain through the Polkadot XCMP protocol, and when the heterogeneous chain is attacked, recover the root hash of the heterogeneous chain through multi-chain consensus.
[0016] In a second aspect, an embodiment of the present application further provides a sensitive data collaborative auditing method based on multi-party network security computing, including: each data holder obtains the original data, standardizes the original data to obtain standardized data, performs differential privacy processing on the standardized data to obtain private data, encrypts the private data using the Paillier homomorphic encryption algorithm to obtain ciphertext, shards the ciphertext using Shamir secret sharing to obtain several sharded ciphertexts; aggregates the sharded ciphertexts using the Paillier homomorphic encryption algorithm to obtain an aggregated ciphertext, shards the aggregated ciphertext using Shamir secret sharing to obtain several sharded aggregated ciphertexts, converts the audit rules into the MPC calculation logic, and based on the sharded aggregated ciphertexts, performs target calculation on the sharded aggregated ciphertexts using the MPC calculation logic.
[0017] In one embodiment, it further includes: dynamically adjusting the threshold of the Shamir secret sharing according to the data label; the data label includes the sensitivity level.
[0018] In one embodiment, it further includes: transmitting the sharded aggregated ciphertext between the sender and the receiver in each participant based on a post-quantum encryption algorithm.
[0019] In one embodiment, it further includes: recording the input and output values of the circuit gate operations in the target calculation process, and generating a zero-knowledge proof based on the zero-knowledge proof library according to the input and output values of the circuit gate operations.
[0020] In one embodiment, it further includes: verifying the zero-knowledge proof through the publicly available Verification Key.
[0021] In one embodiment, it further includes: when the audit rules are adjusted, generating an updated circuit and an updated zero-knowledge proof according to the adjusted audit rules, and obtaining the consensus of the majority of nodes through the intelligent contract voting mechanism.
[0022] In one embodiment, it further includes: after each audit is completed, constructing the leaf nodes of the Merkle tree from the audit results in chronological order, and then merging them layer by layer upwards until the root hash is generated to obtain the Merkle tree.
[0023] In one embodiment, it further includes: writing the root hash into the heterogeneous chain through the Polkadot XCMP protocol, and when the heterogeneous chain is attacked, restoring the root hash of the heterogeneous chain through multi-chain consensus.
[0024] In a third aspect, an embodiment of the present application provides a computer device, including: a processor, a storage medium, and a bus. The storage medium stores program instructions executable by the processor. When the computer device runs, the processor communicates with the storage medium through the bus, and the processor executes the program instructions to perform the steps of any of the above methods.
[0025] The beneficial effects of the present application are:
[0026] (1) Through the hierarchical obfuscation computing architecture, dynamic threshold adjustment, zero-knowledge verification, and cross-domain anchoring mechanism, the security, efficiency, and cross-domain compatibility of multi-party collaborative auditing are significantly improved;
[0027] (2) By separating the roles of the data input layer, obfuscation computing layer, and audit execution layer, the difficulty of collusion is greatly increased (for example: nodes in the data layer cannot access the audit logic, and nodes in the obfuscation layer cannot obtain the original data);
[0028] (3) By optimizing the traditional OT through the NTRU algorithm to resist quantum computing attacks, and at the same time reducing the communication complexity through the batch expansion technology (the complexity is reduced from O(n) to O(logn));
[0029] (4) Through the Paillier homomorphic encryption in the obfuscation layer to pre-aggregate data shards, the real-time MPC calculation amount can be reduced. Experiments show that the real-time calculation delay of million-level data is reduced by more than 40%;
[0030] (5) By aggregating hashes through the Merkle tree and writing them into multiple chains through the Polkadot cross-chain protocol, the storage overhead is only 1 / 10 of the traditional blockchain solution (only the root hash needs to be stored, rather than the full amount of data). BRIEF DESCRIPTION OF THE DRAWINGS
[0031] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required in the embodiments. It should be understood that the following drawings only show some embodiments of the present invention, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.
[0032] Figure 1 A structural schematic diagram of a sensitive data collaborative auditing platform based on multi-party network security computing provided by an embodiment of the present application;
[0033] Figure 2 A flowchart of a sensitive data collaborative auditing method based on multi-party network security computing provided by an embodiment of the present application;
[0034] Figure 3 A structural schematic diagram of a computer device provided by an embodiment of the present application. Detailed implementation manners
[0035] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some but not all of the embodiments of the present invention.
[0036] Therefore, the detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the present application claimed, but merely represents selected embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the scope of protection of the present application.
[0037] In the description of the present application, it should be noted that if terms such as "upper", "lower", etc. indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, or the orientation or positional relationship in which the product of this application is usually placed during use, it is only for the convenience of describing the present application and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the present application.
[0038] In addition, terms such as "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0039] It should be noted that the features in the embodiments of the present application can be combined with each other without conflict.
[0040] Figure 1 This is a schematic flowchart of a sensitive data collaborative auditing platform 100 provided by an embodiment of the present application; as Figure 1 shown, the platform includes:
[0041] A data input layer 110, which is used for each data holder to obtain original data, standardize the original data to obtain standardized data, perform differential privacy processing on the standardized data to obtain private data, encrypt the private data using the Paillier homomorphic encryption algorithm to obtain ciphertext, perform sharding on the ciphertext using Shamir secret sharing to obtain several sharded ciphertexts, and upload the sharded ciphertexts to the confusion layer.
[0042] Among them, the original data includes structured data and unstructured data. For structured data, fields (such as user ID, transaction amount) can be extracted through an SQL parser, converted into a numerical tensor (such as a floating-point matrix), and then encapsulated into a standardized data packet (such as a JSON Schema), including metadata tags (such as PII, financial transaction), to obtain standardized data. For unstructured data, key entities (such as IP address, timestamp) can be extracted using NLP tools (such as regular expressions, named entity recognition), mapped into a scalar or vector format, and then encapsulated into a standardized data packet (such as a JSON Schema), including metadata tags (such as PII, financial transaction), to obtain standardized data.
[0043] The differential privacy processing is specifically that the data holder adds noise locally using the Laplace Mechanism, where the privacy budget can be dynamically configured.
[0044] Homomorphic encryption is a special encryption algorithm that allows specific operations to be performed on encrypted data, and these operations are equivalent to performing the same operations on the original plaintext data after decryption. This feature enables homomorphic encryption to protect data privacy while also performing necessary calculations and analyses. The Paillier homomorphic encryption algorithm is an algorithm whose operation on ciphertext is equivalent to performing an addition operation on plaintext. Specifically, it is a public-key encryption algorithm that uses a pair of keys: a public key and a private key. The public key is used to encrypt data, and the private key is used to decrypt data. The Paillier homomorphic encryption algorithm is as follows: First, generate keys: The key generation process of the Paillier algorithm includes selecting two large prime numbers (p and q), calculating n in the public key and the private key, then selecting a random number g that satisfies certain conditions, and finally generating the public key (n, g) and the private key; Second, the encryption process: Given the plaintext and the public key, the encryption process selects a random number and calculates the ciphertext according to the public key and the random number; Finally, the decryption process: Given the ciphertext and the private key, decrypt according to the private key.
[0045] Secret Sharing is a technique used to protect sensitive data (such as encryption keys). It divides a secret into multiple parts and distributes these parts to multiple participants. Only when the parts are combined together can the original secret be recovered. It spreads the risk among multiple parties, thereby improving the security of the system.
[0046] The obfuscated computing layer 120, the participating nodes of the obfuscated computing layer are divided into data layer nodes, obfuscated layer node groups, and audit layer nodes; the data layer nodes are used to receive sharded ciphertexts; the obfuscated layer node groups are used to aggregate the sharded ciphertexts using the Paillier homomorphic encryption algorithm to obtain aggregated ciphertexts, and to shard the aggregated ciphertexts using Shamir secret sharing to obtain a number of sharded aggregated ciphertexts, and distribute the sharded aggregated ciphertexts to the audit layer nodes; the audit layer nodes are used to perform target calculations on the sharded aggregated ciphertexts based on the sharded aggregated ciphertexts using MPC computing logic.
[0047] The aggregated ciphertext is obtained according to the following formula (1):
[0048]
[0049] Among them, C sum is the aggregate ciphertext; n is the dimension of the polynomial ring; C i is a single shard ciphertext; Q is the modulus chain, Q = q1×q2×…×q L , q1, q2, q L is a set of gradually decreasing moduli.
[0050] In actual operation, you can run the above aggregation ciphertext process by configuring the parameters; Example, scenario: Gradient aggregation in federated learning
[0051] 1. Demand
[0052] Security: 128-bit post-quantum security
[0053] Calculation: Supports 100 additions + 10 multiplications
[0054] Efficiency: single addition time < 1ms, ciphertext size < 500KB
[0055] 2. Parameter configuration
[0056] Ring dimension n = 2 16
[0057] Modulus chain Q = q1 × q2 × ... × q 12
[0058] Noise distribution χ, discrete Gaussian distribution σ=8
[0059] Delayed rescaling frequency: Rescale every 3 multiplications
[0060] Ciphertext compression: 8-bit quantization + Huffman coding.
[0061] Secure Multi-Party Computation (MPC) is a technology that allows multiple parties to jointly compute a function without revealing their respective data. Each party inputs its own private data. After the computation is completed, each party can only obtain its own computation result and cannot know the input data of other parties.
[0062] The MPC computation logic is obtained by the audit execution layer transforming the audit rules.
[0063] The target computation is generally a relatively complex computation, such as statistics, aggregation, etc.
[0064] Furthermore, the obfuscation layer node group consists of multiple trusted third-party nodes, and each node runs in a TEE.
[0065] Among them, the TEE can be Intel SGX, which is responsible for executing the generation of aggregated ciphertext.
[0066] The obfuscation computation layer is also used to dynamically adjust the threshold of Shamir secret sharing according to the data label.
[0067] Among them, the data label includes the sensitivity level.
[0068] Exemplarily, for ordinary data, the threshold is (3, 5), that is, at least 3 shards can recover the data; for highly sensitive data, the threshold is adjusted to (4, 7), and at least 4 shards are required to participate in the computation.
[0069] In actual operation, the threshold adjustment rule can be predefined by a smart contract and synchronized to all nodes in real time.
[0070] Furthermore, the obfuscation computation layer is also used to transmit the sharded aggregated ciphertext between the sender and the receiver among the participating parties based on a post-quantum encryption algorithm.
[0071] Among them, the post-quantum encryption algorithm can be the NTRU algorithm; specifically, this step can be implemented through the following process: First, the Receiver generates an NTRU key pair (public key PK, private key SK) and sends the PK to the Sender; Second, the Sender uses the PK to encrypt two messages (m0, m1) to generate ciphertexts C0 = Enc(PK, m0), C1 = Enc(PK, m1); Third, the Receiver selects a bit b ∈ {0, 1}, generates a random parameter related to the selected bit (for example: a random number r), and constructs a request message to send to the Sender; Finally, the Sender returns the encryption result, and the Receiver uses the SK to decrypt the selected message m b , and it is impossible to obtain the other message m 1-b . In this way, the receiver can only decrypt the specified shard and cannot obtain the content of other shards. In addition, by dynamically distributing the threshold value, it can ensure that the nodes process the shards according to the latest rules. For example: adjusting the threshold value from (3, 5) to (4, 7).
[0072] Furthermore, the OT rounds can be optimized. Specifically, it can be implemented through the following process: First, execute a small number (for example: k times) of basic OT protocols to generate an initial key seed; Second, use a pseudo-random generator (PRG) and a hash function (for example: SHA-3) to expand the seed into keys for n OT instances; For example: based on the KOS protocol (Kilian-Osborne-Savani), O(n) OT is achieved through O(k) basic OT, where K << n. In this way, through the batch OT expansion technology, the OT instances of a single interaction are expanded into multiple instances, which can reduce the communication complexity (from O(n) to O(logn)).
[0073] The audit execution layer 130 includes an audit rule compiler, which is used to convert audit rules into MPC calculation logic.
[0074] Among them, this step can be implemented through the following process: First, use a syntax parser (for example: ANTLR) to convert the audit rule (for example: count the number of users with more than 100 daily transactions) into an intermediate representation (IR); Second, compile the IR into an MPC-compatible boolean circuit or arithmetic circuit; For example: the conditional judgment (transaction count > 100) is converted into a comparison circuit (Greater-Than Gate), and the statistical count is converted into an addition circuit; Finally, the circuit can be logically simplified (for example: constant folding, gate merging) to reduce the MPC calculation amount.
[0075] Furthermore, the audit execution layer further includes a zero-knowledge proof generator, which is used to record the input and output values of circuit gate operations in the target calculation process, and generate zero-knowledge proofs based on the zero-knowledge proof library according to the input and output values of circuit gate operations.
[0076] Specifically, this step can be achieved through the following process: First, generate public parameters (Proving Key, Verification Key) to ensure the initial credibility of the rule logic; Second, during the MPC calculation process, record the input and output values of all circuit gate operations, and use the zk-SNARKs library (such as: libsnark) to generate proofs to prove that the calculation process strictly follows the predetermined rules.
[0077] Furthermore, the zero-knowledge proof generator is also used to verify the zero-knowledge proof through the publicly available Verification Key.
[0078] Specifically, this step is used for third-party verifiers to verify the proof through the Verification Key to ensure that the audit rules have not been tampered with.
[0079] Furthermore, the audit execution layer further includes a dynamic rule updater, which is used to generate updated circuits and updated zero-knowledge proofs according to the adjusted audit rules when the audit rules are adjusted, and obtain the consensus of the majority of nodes through the smart contract voting mechanism.
[0080] Specifically, when the audit rules need to be adjusted (such as: changes in compliance policies), it is necessary to regenerate the circuits and zero-knowledge proofs, and obtain the consensus of the majority of nodes through the smart contract voting mechanism.
[0081] In actual operation, the sensitive data collaborative audit platform based on multi-party network security computing may further include a cross-domain anchoring layer, which is used to construct the leaf nodes of the Merkle tree in chronological order for the audit results after each audit, and then merge them layer by layer upward until the root hash is generated to obtain the Merkle tree.
[0082] Specifically, the audit results can be the metadata of the audit results, such as: time range, list of participants. Further, in actual operation, after the audit is completed, the participants can generate a data hash (such as: SHA-3) for the metadata of the audit results, construct the leaf nodes of the Merkle tree in chronological order, and then perform hash merging layer by layer upward to obtain the Merkle tree.
[0083] Furthermore, the cross-domain anchoring layer is also used to write the root hash into the heterogeneous chain through the Polkadot XCMP protocol, and when the heterogeneous chain is attacked, recover the root hash of the heterogeneous chain through multi-chain consensus.
[0084] This step can ensure the credibility of audit traceability.
[0085] The sensitive data collaborative audit platform based on multi-party network security computing provided by the embodiments of the present application includes: a data input layer, which is used for each data holder to obtain original data, standardize the original data to obtain standardized data, perform differential privacy processing on the standardized data to obtain privacy data, encrypt the privacy data using the Paillier homomorphic encryption algorithm to obtain ciphertext, perform fragmentation on the ciphertext using Shamir secret sharing to obtain several fragmented ciphertexts, and upload the fragmented ciphertexts to the confusion layer; a confusion calculation layer, where the participating nodes of the confusion calculation layer are divided into data layer nodes, a confusion layer node group, and audit layer nodes; the data layer nodes are used to receive the fragmented ciphertexts; the confusion layer node group is used to aggregate the fragmented ciphertexts using the Paillier homomorphic encryption algorithm to obtain an aggregated ciphertext, perform fragmentation on the aggregated ciphertext using Shamir secret sharing to obtain several fragmented aggregated ciphertexts, and distribute the fragmented aggregated ciphertexts to the audit layer nodes; the audit layer nodes are used to perform target calculations on the fragmented aggregated ciphertexts based on the fragmented aggregated ciphertexts using the MPC calculation logic; an audit execution layer, including an audit rule compiler, which is used to convert audit rules into MPC calculation logic. In this way, through a hierarchical confusion calculation architecture, dynamic threshold adjustment, zero-knowledge verification, and cross-domain anchoring mechanism, the security, efficiency, and cross-domain compatibility of multi-party collaborative auditing are significantly improved.
[0086] After introducing the sensitive data collaborative audit platform based on multi-party network security computing in the exemplary embodiments of the present disclosure, next, refer to Figure 2 to describe the sensitive data collaborative audit method based on multi-party network security computing in the exemplary embodiments of the present disclosure.
[0087] Refer to Figure 2 , the sensitive data collaborative audit method based on multi-party network security computing includes: Step 210, each data holder obtains original data, standardizes the original data to obtain standardized data, performs differential privacy processing on the standardized data to obtain privacy data, encrypts the privacy data using the Paillier homomorphic encryption algorithm to obtain ciphertext, and performs fragmentation on the ciphertext using Shamir secret sharing to obtain several fragmented ciphertexts; Step 220, aggregates the fragmented ciphertexts using the Paillier homomorphic encryption algorithm to obtain an aggregated ciphertext, and performs fragmentation on the aggregated ciphertext using Shamir secret sharing to obtain several fragmented aggregated ciphertexts; Step 230, converts the audit rules into MPC calculation logic, and performs target calculations on the fragmented aggregated ciphertexts based on the fragmented aggregated ciphertexts using the MPC calculation logic.
[0088] In one embodiment, it further includes: dynamically adjusting the threshold of Shamir secret sharing according to data tags; the data tags include sensitivity levels.
[0089] In one embodiment, it further includes: transmitting the sharded aggregated ciphertext between the sender and the receiver among the participating parties based on a post-quantum encryption algorithm.
[0090] In one embodiment, it further includes: recording the input and output values of circuit gate operations in the target calculation process, and generating a zero-knowledge proof based on the input and output values of the circuit gate operations according to a zero-knowledge proof library.
[0091] In one embodiment, it further includes: verifying the zero-knowledge proof through a publicly available Verification Key.
[0092] In one embodiment, it further includes: when the audit rule is adjusted, generating an updated circuit and an updated zero-knowledge proof according to the adjusted audit rule, and obtaining the consensus of the majority of nodes through an intelligent contract voting mechanism.
[0093] In one embodiment, it further includes: after each audit is completed, constructing the leaf nodes of a Merkle tree for the audit results in chronological order, and then merging them layer by layer upwards until the root hash is generated to obtain the Merkle tree.
[0094] In one embodiment, it further includes: writing the root hash into a heterogeneous chain through the Polkadot XCMP protocol, and when the heterogeneous chain is attacked, restoring the root hash of the heterogeneous chain through multi-chain consensus.
[0095] The above modules can be one or more integrated circuits configured to implement the above methods, for example: one or more application-specific integrated circuits (ASICs), or, one or more microprocessors, or, one or more field programmable gate arrays (FPGAs), etc. Again, when a certain above module is implemented in the form of a processing element scheduling program code, the processing element can be a general-purpose processor, such as a central processing unit (CPU) or other processors that can call program code. Again, these modules can be integrated together and implemented in the form of a system-on-a-chip (SOC).
[0096] Figure 3Schematic diagram of the computer device provided by the embodiments of the present application. This device can be integrated into a terminal device or a chip of a terminal device, and the terminal can be a computing device with data processing capabilities.
[0097] The device includes: a processor 301, a storage medium 302, and a bus 303.
[0098] The storage medium 302 stores program instructions executable by the processor 301. When the computer device 300 runs, the processor 301 communicates with the storage medium 302 through the bus 303, and the processor 301 executes the program instructions to execute the above method embodiments. The specific implementation manners and technical effects are similar and will not be elaborated here.
[0099] Optionally, the present invention further provides a program product, such as a computer-readable storage medium, including a program that is used to execute the above method embodiments when executed by a processor.
[0100] In several embodiments provided by the present invention, it should be understood that the disclosed apparatus and method can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of the apparatus or unit can be in an electrical, mechanical or other form.
[0101] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or they can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0102] In addition, each functional unit in various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated unit can be implemented in the form of hardware, or in the form of a combination of hardware and software functional units.
[0103] The integrated unit implemented in the form of software functional units can be stored in a computer-readable storage medium. The above-mentioned software functional units are stored in a storage medium and include several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) or a processor (English: processor) to execute some steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (English: Read-Only Memory, abbreviated as: ROM), random access memories (English: Random Access Memory, abbreviated as: RAM), magnetic disks, or optical discs.
[0104] The above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.
Claims
1. A sensitive data collaborative auditing platform based on multi-party network security computing, characterized in that Comprising: A data input layer for each data holder to obtain original data, standardize the original data to obtain standardized data, perform differential privacy processing on the standardized data to obtain privacy data, encrypt the privacy data using the Paillier homomorphic encryption algorithm to obtain ciphertext, perform fragmentation on the ciphertext using Shamir secret sharing to obtain a number of fragmented ciphertexts, and upload the fragmented ciphertexts to the obfuscation layer; An obfuscation calculation layer, where the participating nodes of the obfuscation calculation layer are divided into data layer nodes, obfuscation layer node groups, and audit layer nodes; the data layer nodes are used to receive the fragmented ciphertexts; the obfuscation layer node groups are used to aggregate the fragmented ciphertexts using the Paillier homomorphic encryption algorithm to obtain aggregated ciphertexts, perform fragmentation on the aggregated ciphertexts using Shamir secret sharing to obtain a number of fragmented aggregated ciphertexts, and distribute the fragmented aggregated ciphertexts to the audit layer nodes; the audit layer nodes are used to perform target calculations on the fragmented aggregated ciphertexts based on the MPC calculation logic; An audit execution layer, including an audit rule compiler, which is used to convert audit rules into the MPC calculation logic.
2. The platform according to claim 1, wherein The obfuscation layer node group consists of multiple trusted third-party nodes, and each node runs in a TEE.
3. The platform according to claim 1, wherein The obfuscation calculation layer is also used to dynamically adjust the threshold of the Shamir secret sharing according to data tags; the data tags include sensitivity levels.
4. The platform according to claim 1, characterized in that, The obfuscation calculation layer is also used to transmit the fragmented aggregated ciphertexts between the sender and the receiver among the participating parties based on a post-quantum encryption algorithm.
5. The platform according to claim 1, characterized in that, The audit execution layer also includes a zero-knowledge proof generator, which is used to record the input and output values of the circuit gate operations during the target calculation process, and generate a zero-knowledge proof based on the zero-knowledge proof library according to the input and output values of the circuit gate operations.
6. The platform according to claim 5, characterized in that, The zero-knowledge proof generator is also used to verify the zero-knowledge proof through the publicly available Verification Key.
7. The platform according to claim 5, characterized in that, The audit execution layer also includes a dynamic rule updater, which is used to generate an updated circuit and an updated zero-knowledge proof according to the adjusted audit rules when the audit rules are adjusted, and obtain the consensus of the majority of nodes through the smart contract voting mechanism.
8. The platform according to claim 1, wherein The sensitive data collaborative audit platform based on multi-party network security calculation further includes a cross-domain anchoring layer, which is used to construct the leaf nodes of a Merkle tree for the audit results in chronological order after each audit, and then merge them layer by layer upward until the root hash is generated to obtain the Merkle tree.
9. The platform according to claim 8, wherein The cross-domain anchoring layer is also used to write the root hash into a heterogeneous chain through the Polkadot XCMP protocol, and when the heterogeneous chain is attacked, recover the root hash of the heterogeneous chain through multi-chain consensus.
10. A sensitive data collaborative auditing method based on multi-party network security computing, characterized in that, Comprising: Each data holder obtains the original data, standardizes the original data to obtain standardized data, performs differential privacy processing on the standardized data to obtain private data, encrypts the private data using the Paillier homomorphic encryption algorithm to obtain ciphertext, and fragments the ciphertext using Shamir secret sharing to obtain a number of fragmented ciphertexts; The fragmented ciphertexts are aggregated using the Paillier homomorphic encryption algorithm to obtain an aggregated ciphertext, the aggregated ciphertext is fragmented using Shamir secret sharing to obtain a number of fragmented aggregated ciphertexts, the audit rules are converted into the MPC calculation logic, and based on the fragmented aggregated ciphertexts, the fragmented aggregated ciphertexts are subjected to target calculation using the MPC calculation logic.
Citation Information
Cited By
Audit data processing method, device and product based on block chain and privacy calculation
CN122222759A