Information encryption method, system, equipment and medium

By desensitizing and symmetric encryption of the information to be encrypted in the large language model, the leakage problem of sensitive data during transmission and processing is solved, data privacy is guaranteed and the accuracy of processing results is achieved, and it is suitable for data interaction scenarios containing sensitive information.

CN120358066APending Publication Date: 2025-07-22SHANGHAI DIGITAL SECURITY TECH CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510643125.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-19
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

The prior art cannot ensure that the sensitive data part involved in the processing results of large language model can only be restored and displayed on the user side, while preventing secondary leakage during data transmission and model call.

Method used

By desensitizing the encrypted information, the sensitive information is replaced with the desensitized information, and the encrypted information is generated using a symmetric encryption algorithm, the processing results are received and decrypted to restore the sensitive information. AES and RSA hybrid encryption mechanism is used to identify subjective emotionally sensitive information in combination with the emotion analysis model.

Benefits of technology

Effectively prevent the leakage of sensitive information during transmission and processing, ensure data privacy and security, while recovering semantic and complete processing results, improving encryption efficiency and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358066A_ABST
    Figure CN120358066A_ABST
Patent Text Reader

Abstract

The invention relates to an information encryption method, system and device and a medium. The method comprises the following steps: acquiring to-be-encrypted information, and generating and sending an encryption request; performing desensitization processing on the to-be-encrypted information, and replacing sensitive information in the to-be-encrypted information with desensitization information to obtain processed to-be-encrypted information; receiving a first key, and symmetrically encrypting the processed to-be-encrypted information by using the first key to generate encrypted information; sending the encrypted information; and receiving the processing result, symmetrically decrypting the processing result based on the second key, and replacing the desensitization information in the symmetrically decrypted processing result with the corresponding sensitive information to obtain a final processing result. According to the method, the data security is ensured, and meanwhile, a final processing result which is complete in semantics and contains sensitive information input by a user can be recovered.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security processing, and particularly relates to an information encryption method, system, device, and medium. Background Art

[0002] With the wide application of large language models in fields such as natural language processing, computer vision, and recommendation systems, more and more users embed the invocation of large language models into key business processes in daily office work, business processing, and decision-making support. During the model invocation process, users often need to submit data content containing sensitive information, such as personal identification information, credit card numbers, passwords, etc., to obtain task responses or semantic analysis results generated by the large language model. Such sensitive information plays an important role in ensuring the accuracy of the model output and the effectiveness of context understanding. However, once this information is leaked during transmission or processing, it may cause serious consequences such as economic losses, legal risks, or damaged reputation. Users generally face such a contradiction: on the one hand, they need to submit data containing sensitive fields to the large language model to obtain accurate results; on the other hand, they are worried that these sensitive information will be leaked or misused in the interaction link. In addition, users often also expect the results returned by the large language model to retain content related to the original sensitive information to meet the integrity requirements of the business, thereby further increasing the requirements for the security of large model data transmission. Therefore, an information encryption method, system, device, and medium are needed. Summary of the Invention

[0003] In view of the above disadvantages of the prior art, the purpose of the present invention is to provide an information encryption method, system, device, and medium, which improves the problem that the prior art cannot take into account both ensuring that the sensitive data part involved in the model processing result can only be restored and displayed at the user end, and preventing secondary leakage during data transmission and model invocation.

[0004] To achieve the above and other related purposes, the present invention provides an information encryption method, including: obtaining information to be encrypted, generating and sending an encryption request; performing desensitization processing on the information to be encrypted, replacing sensitive information in the information to be encrypted with desensitized information to obtain the processed information to be encrypted; receiving a first key, and symmetrically encrypting the processed information to be encrypted using the first key to generate encrypted information; wherein the first key is generated by a first server based on the encryption request, returned after being asymmetrically encrypted, and obtained by decrypting through a preset asymmetric private key; sending the encrypted information; receiving a processing result and symmetrically decrypting the processing result based on a second key, and replacing the desensitized information in the symmetrically decrypted processing result with the corresponding sensitive information to obtain the final processing result; wherein the processing result is obtained by a second server invoking a large language model to process the encrypted information, and the second key is the symmetric key of the first key.

[0005] In an embodiment of the present invention, the information to be encrypted is desensitized, and the sensitive information in the information to be encrypted is replaced with desensitized information to obtain the processed information to be encrypted, including: detecting the type of the information to be encrypted: if the information to be encrypted is structured information, sensitive information in the information to be encrypted is identified, and the identified sensitive information is desensitized, and the sensitive information in the information to be encrypted is replaced with the desensitized information after desensitization processing to obtain the processed information to be encrypted; if the information to be encrypted is unstructured information, semantic desensitization processing is performed on the information to be encrypted to replace the sensitive information in the information to be encrypted with desensitized information to obtain the processed information to be encrypted.

[0006] In an embodiment of the present invention, sensitive information in the information to be encrypted is identified, and the identified sensitive information is desensitized, and the sensitive information in the information to be encrypted is replaced with the desensitized information after desensitization processing to obtain the processed information to be encrypted, including: detecting whether there is preset sensitive information in the information to be encrypted: if there is, the hash value of the sensitive information is calculated based on the hash algorithm, and the hash value is used as the desensitized information to replace the corresponding sensitive information to obtain the processed information to be encrypted; if not, the information to be encrypted is used as the processed information to be encrypted.

[0007] In an embodiment of the present invention, semantic desensitization processing is performed on the information to be encrypted to replace the sensitive information in the information to be encrypted with desensitized information to obtain the processed information to be encrypted, including: performing fuzzy matching between the information to be encrypted and the sentiment words in the sentiment word library to identify the sensitive information with subjective sentiment in the information to be encrypted; extracting the text statement where the sensitive information is located and the corresponding context statement from the information to be encrypted, and inputting each extracted text statement into the sentiment analysis model to obtain the sentiment score of the sensitive information; determining whether the sentiment score is within the preset sentiment intensity range: if so, the sensitive information is retained, and the information to be encrypted is used as the processed information to be encrypted; otherwise, according to the preset vocabulary replacement table, the sensitive information in the information to be encrypted is replaced with the corresponding desensitized information to obtain the processed information to be encrypted.

[0008] In an embodiment of the present invention, receiving a processing result, symmetrically decrypting the processing result based on a second key, and replacing the desensitized information in the symmetrically decrypted processing result with corresponding sensitive information to obtain a final processing result, includes: receiving the processing result and performing symmetric decryption processing on the processing result based on the second key to obtain a decrypted processing result; looking up in a pre-stored mapping table whether there is desensitized information in the decrypted processing result that matches the mapping table: wherein, the mapping table stores the mapping relationship between sensitive information and corresponding desensitized information; if it exists, based on the found mapping relationship between the sensitive information and the corresponding desensitized information, replacing the desensitized information in the decrypted result with the corresponding sensitive information to obtain a final processing result; if it does not exist, directly using the decrypted processing result as the final processing result.

[0009] In an embodiment of the present invention, after obtaining the final processing result, it further includes: performing differential display on the processing result based on the user identification in the information to be encrypted.

[0010] In an embodiment of the present invention, the symmetric encryption is the Advanced Encryption Standard algorithm.

[0011] In an embodiment of the present invention, there is also provided an information encryption system, the system includes: a data acquisition module, configured to acquire information to be encrypted, generate and send an encryption request; a desensitization module, configured to desensitize the information to be encrypted, replace the sensitive information in the information to be encrypted with desensitized information to obtain processed information to be encrypted; an encryption module, configured to receive a first key, and symmetrically encrypt the processed information to be encrypted using the first key to generate encrypted information; wherein, the first key is generated by a first server based on the encryption request, and is returned after asymmetric encryption, and is obtained after being decrypted by a preset asymmetric private key; a sending module, configured to send the encrypted information; a decryption and restoration module, configured to receive a processing result and symmetrically decrypt the processing result based on a second key, and replace the desensitized information in the symmetrically decrypted processing result with corresponding sensitive information to obtain a final processing result; wherein, the processing result is obtained by a second server calling a large language model to process the encrypted information, and the second key is the symmetric key of the first key.

[0012] In an embodiment of the present invention, there is also provided an electronic device, including: one or more processors; a storage device, configured to store one or more programs, when the one or more programs are executed by the one or more processors, enabling the electronic device to implement the information encryption method of any one of the above.

[0013] In an embodiment of the present invention, there is also provided a computer-readable storage medium, on which a computer program is stored, when the computer program is executed by a processor of a computer, enabling the computer to execute the information encryption method of any one of the above.

[0014] As described above, an information encryption method, system, device and medium of the present invention have the following beneficial effects: After obtaining the information to be encrypted, the sensitive information therein is replaced with desensitized information. Through this desensitization process, it can effectively prevent the leakage of sensitive information during the transmission process and subsequent model processing process, thereby ensuring data privacy and security. In addition, by using a symmetric encryption algorithm to perform symmetric encryption on the processed information to be encrypted, it can not only improve the encryption efficiency and security strength, but also ensure that the information sent to the large language model does not contain sensitive content. By decrypting the processing result generated by the large language model and replacing the desensitized information therein with the corresponding sensitive information, while ensuring data security, the final processing result with complete semantics and containing the sensitive information input by the user can be restored. The present invention not only ensures the security of sensitive information throughout the transmission and processing process, but also guarantees the accuracy and readability of the processing result through reverse desensitization processing. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 It is a flowchart showing an information encryption method provided by an embodiment of the present invention;

[0016] Figure 2 It is a block diagram showing the structure of an information encryption system provided by an embodiment of the present invention;

[0017] Figure 3 It is a schematic structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0018] The following specific examples illustrate the implementation manners of the present invention. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific implementation manners. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other.

[0019] It should be noted that the diagrams provided in the following embodiments only illustrate the basic concept of the present invention in a schematic manner. Therefore, only the components related to the present invention are shown in the diagrams, rather than being drawn according to the number, shape and size of the components in actual implementation. The type, quantity and proportion of each component in actual implementation can be arbitrarily changed, and the component layout type may also be more complex.

[0020] In the following description, a large number of details are explored to provide a more thorough explanation of the embodiments of the present invention. However, it is obvious to those skilled in the art that the embodiments of the present invention can be implemented without these specific details. In other embodiments, well-known structures and devices are shown in the form of block diagrams rather than in detail to avoid making the embodiments of the present invention difficult to understand.

[0021] The present invention provides an information encryption method. After obtaining the information to be encrypted, the sensitive information therein is replaced with desensitized information. Through this desensitization process, it can effectively prevent information leakage of sensitive information during the transmission process and subsequent model processing process, thereby ensuring data privacy and security. In addition, the processed information to be encrypted is symmetrically encrypted by a symmetric encryption algorithm, which can not only improve the encryption efficiency and security strength, but also ensure that the information sent to the large language model does not contain sensitive content. By decrypting the processing result generated by the large language model and replacing the desensitized information therein with the corresponding sensitive information, while ensuring data security, the final processing result with complete semantics and containing the sensitive information input by the user can be restored. The present invention not only ensures the security of sensitive information throughout the transmission and processing process, but also guarantees the accuracy and readability of the processing result through reverse desensitization processing. It is applicable to data interaction scenarios containing sensitive information, especially suitable for the security call requirements of large language models.

[0022] As Figure 1 shown, the information encryption method is applied to the client and includes the following steps:

[0023] S11. Obtain the information to be encrypted, generate and send an encryption request.

[0024] When users need to analyze user behavior records, generate summaries of business texts, judge instruction intentions, or extract key information, etc., they often call large language models to perform the required semantic processing tasks. To achieve the above calls, users need to submit the information to be encrypted through the client. Since the information to be encrypted may contain sensitive data, to prevent data leakage, the client needs to perform desensitization processing on the information to be encrypted before sending and complete the information encryption operation based on the key mechanism to ensure privacy and security during data transmission and processing. In addition, after receiving the information to be encrypted, the client will generate an encryption request and send the encryption request to the first server to obtain the first key for encryption.

[0025] S12. Perform desensitization processing on the information to be encrypted, replace the sensitive information in the information to be encrypted with desensitized information, and obtain the processed information to be encrypted.

[0026] To prevent the leakage of sensitive information during data transmission and semantic processing, it is necessary to desensitize the information to be encrypted. Specifically, the sensitive information in the information to be encrypted can be identified through preset sensitive information types or relevant recognition models, and the identified sensitive information can be replaced with corresponding desensitized information to form the processed information to be encrypted.

[0027] Specifically, step S12 includes the following processing procedures:

[0028] First, detect the type of the information to be encrypted: If the information to be encrypted is structured information, identify the sensitive information in the information to be encrypted and desensitize the identified sensitive information, replacing the sensitive information in the information to be encrypted with the desensitized information after desensitization processing to obtain the processed information to be encrypted; if the information to be encrypted is unstructured information, perform semantic desensitization processing on the information to be encrypted to replace the sensitive information in the information to be encrypted with desensitized information to obtain the processed information to be encrypted.

[0029] Structured information refers to data with a fixed format that can be clearly defined by fields or tags, usually existing in the form of database tables, JSON, key-value pairs, etc. Unstructured information refers to free text or natural language content without a fixed field format, commonly found in user inputs, emails, conversation logs, comments, etc., and information needs to be extracted through semantic recognition. In the present invention, in order to effectively identify and desensitize sensitive information in different types of information, the client will detect the type of the information to be encrypted proposed by the user. If the information to be encrypted is structured information such as database content or JSON, the client will analyze various types of data contained therein based on preset sensitive information recognition rules, identify the sensitive information therein, and desensitize the identified sensitive information to obtain desensitized information. On the contrary, if the information to be encrypted is unstructured information such as customer service chat records or email text, the client will identify the sensitive information in the information to be encrypted through the context semantic recognition method and perform desensitization replacement on the sensitive information in a semantic-preserving manner to obtain the processed information to be encrypted. It can be understood that for any information to be encrypted, it can contain one sensitive information or multiple sensitive information. The number of sensitive information identified from the information to be encrypted is not limited, and the information to be encrypted can be structured information, such as database records and form data; it can also be unstructured information, such as natural language text and user input content; it can also be a mixture of structured and unstructured information. When the information to be encrypted is a mixture of structured and unstructured information, the client respectively adopts corresponding recognition and desensitization strategies for the structured part and the unstructured part therein, and after completing the desensitization processing, combines them to obtain the complete processed information to be encrypted.

[0030] In an alternative embodiment of the present invention, sensitive information in the information to be encrypted is identified, and the identified sensitive information is desensitized. The sensitive information in the information to be encrypted is replaced with the desensitized information after desensitization processing to obtain the processed information to be encrypted, including the following processing procedures: Detect whether there is preset sensitive information in the information to be encrypted. If it exists, calculate the hash value of the sensitive information based on the hash algorithm, use the hash value as the desensitized information, and replace the corresponding sensitive information to obtain the processed information to be encrypted. If it does not exist, use the information to be encrypted as the processed information to be encrypted.

[0031] When the information to be encrypted is structured information, the client will compare each data item in the information to be encrypted one by one based on the preset sensitive information identification rules to determine whether it contains sensitive information. Among them, the sensitive information identification rules can be keyword matching, data format identification, regular expression verification, or a sensitive information dictionary, etc. Those skilled in the art can flexibly configure the specific identification rules according to the actual application scenario and will not be elaborated here. If the identification result shows that there is sensitive information, the following process is executed for each sensitive information: Calculate the hash value of the sensitive information based on the hash algorithm, and use the calculated hash value as the desensitized information to replace the original sensitive information, thereby generating the processed information to be encrypted. Exemplarily, if a structured information contains data items such as "Phone: 138********" or "ID number: 4201**************", it can be determined as sensitive information according to the mobile phone number format or ID number format rules, and hash replacement processing is performed on it. Conversely, if no sensitive information is detected, no desensitization processing is required, and the information to be encrypted can be directly used as the processed information to be encrypted for the subsequent encryption process.

[0032] In an alternative embodiment of the present invention, semantic desensitization processing is performed on the information to be encrypted to replace the sensitive information in the information to be encrypted with desensitized information, obtaining the processed information to be encrypted, including the following process: Perform fuzzy matching between the information to be encrypted and the emotional words in the emotional word library to identify the sensitive information with subjective emotions in the information to be encrypted. Extract the text statement where the sensitive information is located and the corresponding context statement from the information to be encrypted, and input each extracted text statement into the sentiment analysis model to obtain the sentiment score of the sensitive information. Determine whether the sentiment score is within the preset sentiment intensity range. If so, retain the sensitive information and use the information to be encrypted as the processed information to be encrypted. Otherwise, according to the preset vocabulary replacement table, replace the sensitive information in the information to be encrypted with the corresponding desensitized information to obtain the processed information to be encrypted.

[0033] When the information to be encrypted is unstructured information, in order to identify sensitive content that may carry subjective judgments or subjective tendencies in the information to be encrypted, the client performs fuzzy matching between the information to be encrypted and the sentiment words in the preset sentiment word library to identify sensitive information with subjective emotion expressions. Then, the text statements containing the sensitive information and the text statements of their contexts are extracted from the information to be encrypted, and these text statements are input into a sentiment analysis model for sentiment tendency analysis to obtain the sentiment score of the sensitive information. Among them, the sentiment analysis model includes, but is not limited to, BERT, BiLSTM, or TextCNN, etc. Any natural language processing model that can effectively identify the sentiment tendency in text statements can be applicable, and no limitation is made here. If the sentiment score is within the preset sentiment intensity range, it indicates that the emotion expression is relatively neutral. In this case, the sensitive information will be retained, and the current information to be encrypted will be directly used as the processed information to be encrypted. On the contrary, if the sentiment score is not within the sentiment intensity range, it indicates that the sentiment tendency is relatively obvious, and it can be considered that there is a subjective emotion. In this case, the client will perform replacement processing on the sensitive information according to the preset vocabulary replacement table. For example, "bearish on a certain stock" will be replaced with "please analyze a certain stock" to perform desensitization replacement while maintaining semantic integrity, and generate the final processed information to be encrypted. It can be understood that the sensitive information identified can be searched in the vocabulary replacement table for corresponding items through methods such as exact matching, fuzzy matching, synonym comparison, or regular rule matching. If there is a corresponding item, the corresponding neutral replacement word will be extracted for desensitization processing.

[0034] Exemplarily, the information to be encrypted input by the user is "It is recommended to buy COSCO Shipping (601919), bearish on Seres (601127), please give me the latest market value analysis of these two stocks". Based on fuzzy matching with the sentiment word library, the word with subjective tendency "bearish" is quickly matched, and then the text statement where the word is located and its context are input into the sentiment analysis model for scoring. Suppose the sentiment score of "bearish" is -0.56, which exceeds the preset sentiment intensity range and belongs to a relatively strong negative emotion, and it is determined as a subjective expression. Accordingly, the client replaces "bearish" with the sentiment-neutral word "analyze" to obtain the desensitized content "Please give me the latest market value analysis of COSCO Shipping (601919) and Seres (601127)". This processing removes subjective judgments while retaining the semantics and is suitable for secure transmission to an open large language model for processing.

[0035] Compared with the existing static desensitization technology, such as desensitization through simple mechanical replacement (such as desensitizing "credit card number 6214..." to "[PAYMENT] number XXXX"), it is easy to cause semantic loss, resulting in the inability of the large language model to identify the specific card type. It is also difficult to deal with new risk scenarios, such as sudden leakage of sensitive information in conversations. This solution uses a context-aware algorithm to perform sentiment recognition on sensitive content in encrypted information, and can identify highly sensitive information related to code logic, business rules or subjective judgments, thereby avoiding possible misjudgments based on traditional keyword matching methods. In addition, this solution can also effectively shield expressions such as traders' subjective judgments to prevent them from being leaked during the use of large language models, reducing the compliance or regulatory risks caused by them.

[0036] S13. Receive the first key, and use the first key to symmetrically encrypt the processed information to be encrypted to generate encrypted information; wherein the first key is generated by the first server based on the encryption request, and is returned after asymmetrical encryption, and is obtained after decryption using a preset asymmetric private key.

[0037] After the client completes the desensitization of the information to be encrypted, it receives the encryption key returned by the first server, wherein the encryption key is a symmetric encryption key dynamically generated by the first server according to the encryption request, and is returned after encryption by the first server using a preset asymmetric encryption public key. The client uses the locally pre-stored asymmetric encryption private key to decrypt the encryption key, thereby obtaining the first key in plain text. After obtaining the first key, the client uses the first key to encrypt the desensitized information to be encrypted. Specifically, a symmetric encryption algorithm can be used, combined with an initialization vector and encryption parameters, to convert the processed information to be encrypted into ciphertext form to form encrypted information for subsequent secure transmission and remote processing calls.

[0038] In an optional embodiment of the present invention, the symmetric encryption is the Advanced Encryption Standard (AES) algorithm, and the asymmetric encryption is the RSA (Rivest–Shamir–Adleman) algorithm. The AES algorithm has the advantages of fast encryption speed, low resource usage, and suitability for large-scale data encryption, and is suitable for rapid processing of encrypted information. The RSA algorithm is used to encrypt symmetric keys, and has the advantages of high key exchange security and strong resistance to man-in-the-middle attacks. This hybrid encryption mechanism not only ensures the privacy of sensitive data, but also takes into account the processing efficiency and flexibility of key management. It is suitable for use in cross-system or non-trusted communication environments, and ensures the integrity and security of encrypted data during transmission and decryption.

[0039] It should be noted that after receiving the encryption request sent by the client, the first server generates a temporary symmetric encryption key according to the context of the current task or the request identifier, which serves as the first key for subsequent data encryption. The first key can be generated by a high-strength random number generation algorithm, and has uniqueness and unpredictability, thus ensuring the security and timeliness of the first key. To prevent the key from being stolen or tampered with during transmission, the first server encrypts the generated first key using a preset asymmetric encryption public key to form a key ciphertext, and returns it to the client. After the client decrypts the key ciphertext returned by the first server using the locally stored asymmetric encryption private key, the first key is obtained. This method can effectively avoid the exposure of the plaintext key in the network and achieve secure key negotiation.

[0040] S14. Send the encrypted information.

[0041] After the client symmetrically encrypts the information to be encrypted using the first key, the encrypted information is generated and sent to the second server. The second server symmetrically decrypts the encrypted information using the symmetric encryption key stored locally to obtain the plaintext service data. The decrypted information is input into the large language model to perform corresponding semantic processing tasks, and the processing result is obtained. Then, the second server encrypts the processing result and sends it to the client in the form of ciphertext.

[0042] S15. Receive the processing result, symmetrically decrypt the processing result based on the second key, and replace the desensitized information in the symmetrically decrypted processing result with the corresponding sensitive information to obtain the final processing result; wherein, the processing result is obtained by the second server calling the large language model to process the encrypted information, and the second key is the symmetric key of the first key.

[0043] After the client receives the encrypted processing result returned by the second server, it symmetrically decrypts the processing result using the second key stored locally to obtain the plaintext processing result containing desensitized information. Among them, the second key is the same symmetric key as the first key previously used by the client or its valid copy, which is used to ensure the end-to-end consistency of the data processing process. To restore the final readable result, the client will perform reverse replacement on the desensitized information in the decrypted processing result to generate the final processing result with complete semantics containing the original sensitive information.

[0044] In an optional embodiment of the present invention, step S15 includes the following process:

[0045] First, receive the processing result and perform symmetric decryption processing on the processing result based on the second key to obtain the decrypted processing result.

[0046] After the client receives the encrypted processing result returned by the second server, it calls the second key symmetric to the first key to perform a symmetric decryption operation on the ciphertext content to restore the processing result in the plaintext form after model processing. Since the second key and the first key are the same key or keys that can be inferred from each other, it can be ensured that the ciphertext is accurately restored to the original data after decryption, thus achieving the consistency and integrity of data processing.

[0047] Then, from the pre-stored mapping table, it is checked whether there is matching desensitized information in the decrypted processing result: Among them, the mapping table stores the mapping relationship between sensitive information and the corresponding desensitized information: If there is a match, based on the found mapping relationship between the sensitive information and the corresponding desensitized information, the desensitized information in the decrypted result is replaced with the corresponding sensitive information to obtain the final processing result. Conversely, if there is no match, the decrypted processing result is directly used as the final processing result.

[0048] To achieve the restoration of desensitized information, after the client decrypts the processing result, it also performs content matching on the decrypted processing result to determine whether it contains the desensitized information registered in the preset mapping table. Among them, the mapping table is pre-stored locally on the client, and when performing the aforementioned desensitization processing, the mapping relationship between the sensitive information and the corresponding desensitized information is stored in the mapping table. If the client identifies matching desensitized information in the decrypted processing result in the mapping table, the desensitized information is replaced with its corresponding original sensitive information based on the mapping relationship, thus restoring the processing result with accurate semantics containing the original sensitive information. Conversely, if no desensitized information is matched, it indicates that the processing result does not involve content that needs to be restored. At this time, the decrypted result can be directly output as the final processing result without further replacement operations. Thus, the secure replacement, transmission, and local real result restoration of sensitive values are achieved, ensuring that user privacy data is not leaked while still being able to obtain and display accurate analysis results.

[0049] Exemplarily, the user's original input is a request to calculate the total monthly operating income of a certain company in the first half of last year. To prevent the plaintext numbers from being directly sent to the large language model, the client adopts a dynamic numerical replacement strategy to convert the original operating income data into forged secure data (such as replacing 23.4 in January with 76.6 in January), and then inputs the desensitized data into the large language model to obtain the aggregated value. The result returned by the large language model is 295.0. The client performs reverse restoration and correction on this result and finally obtains the real business result of 155.0. This example performs numerical desensitization and restoration based on the defined formula F(n) = 100 - 10×N - V(n), where N is the position where the data appears and V(n) is the actual value.

[0050] In an alternative embodiment of the present invention, after obtaining the final processing result, it further includes: performing differential display on the processing result based on the user identifier in the information to be encrypted. After the client obtains the final processing result through the above operations, it can also identify the user's identity through the user identifier, search for the corresponding preset permission policy according to the user's identity, and combine the results of historical interaction data analysis, and use the policy engine to dynamically determine the data range and display method visible to the current user. Among them, the user's identity includes but is not limited to developers, auditors, business operators, etc. Exemplarily, for information content marked with a relatively high sensitivity level, the client can keep it in a desensitized state (such as using hash values, pseudonyms, or mask processing) when facing ordinary business users, while it can be partially or fully restored to the real sensitive information when facing users with auditing permissions. The policy engine can automatically adjust the desensitization intensity or display granularity of the fields based on multi-dimensional features such as access frequency, field sensitivity, and historical query behavior, so as to achieve personalized and secure presentation of the processing result, and improve data controllability and privacy compliance.

[0051] As Figure 2 shown, the information encryption system 200 includes: a data acquisition module 210, a desensitization module 220, an encryption / decryption module 230, a sending module 240, and a decryption and restoration module 250. The above-mentioned data acquisition module 210 is used to acquire the information to be encrypted, generate and send an encryption request. The desensitization module 220 is used to perform desensitization processing on the information to be encrypted, replace the sensitive information in the information to be encrypted with desensitized information, and obtain the processed information to be encrypted. The encryption module 230 is used to receive the first key and perform symmetric encryption on the processed information to be encrypted using the first key to generate encrypted information; wherein, the first key is generated by the first server based on the encryption request, returned after being asymmetrically encrypted, and obtained after being decrypted by the preset asymmetric private key. The sending module 240 is used to send the encrypted information. The decryption and restoration module 250 is used to receive the processing result and perform symmetric decryption on the processing result based on the second key, and replace the desensitized information in the symmetrically decrypted processing result with the corresponding sensitive information to obtain the final processing result; wherein, the processing result is obtained by the second server calling the large language model to process the encrypted information, and the second key is the symmetric key of the first key.

[0052] For the specific limitations of the information encryption system, reference can be made to the limitations on the information encryption method in the above text, which will not be elaborated here. Each module in the above information encryption system can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor of the computer device in hardware format or independent of it, or stored in the memory of the computer device in software format, so that the processor can call the corresponding operations of the above modules.

[0053] It should be noted that, in order to highlight the innovative part of the present invention, modules that are not closely related to solving the technical problems proposed by the present invention are not introduced in this embodiment, but this does not mean that there are no other modules in this embodiment.

[0054] As Figure 3 shown, the electronic device 3 may include a memory 31, a processor 32, and a bus, and may also include a computer program stored in the memory 31 and executable on the processor 32, such as an information encryption program.

[0055] Among them, the memory 31 includes at least one type of readable storage medium. The readable storage medium includes flash memory, mobile hard disk, multimedia card, card-type memory (such as SD or DX memory, etc.), magnetic memory, magnetic disk, optical disk, etc. The memory 31 may be an internal storage unit of the electronic device 3 in some embodiments, such as the mobile hard disk of the electronic device 3. The memory 31 may also be an external storage device of the electronic device 3 in other embodiments, such as a plug-in mobile hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc. equipped on the electronic device 3. Further, the memory 31 may include both an internal storage unit and an external storage device of the electronic device 3. The memory 31 can be used not only to store application software installed in the electronic device 3 and various types of data, such as the code for information encryption, etc., but also to temporarily store data that has been output or will be output.

[0056] The processor 32 may be composed of integrated circuits in some embodiments. For example, it may be composed of a single packaged integrated circuit, or may be composed of multiple integrated circuits with the same or different functions, including a combination of one or more Central Processing Units (CPUs), microprocessors, digital processing chips, graphics processors, and various control chips. The processor 32 is the control core (Control Unit) of the electronic device 3, connecting various components of the entire electronic device 3 through various interfaces and circuits, and by running or executing programs or modules (such as information encryption programs, etc.) stored in the memory 31, and calling data stored in the memory 31, to perform various functions of the electronic device 3 and process data.

[0057] The processor 32 executes the operating system of the electronic device 3 and various installed application programs. The processor 32 executes the application programs to implement the steps in the above information encryption method.

[0058] Exemplarily, a computer program can be divided into one or more modules. One or more modules are stored in the memory 31 and executed by the processor 32 to complete the present application. One or more modules can be a series of computer program instruction segments capable of completing specific functions, and the instruction segments are used to describe the execution process of the computer program in the electronic device 3. For example, the computer program can be divided into a data acquisition module 210, a desensitization module 220, an encryption / decryption module 230, a sending module 240, and a decryption and restoration module 250.

[0059] The integrated units implemented in the form of software function modules as described above can be stored in a computer-readable storage medium. The computer-readable storage medium can be non-volatile or volatile. The above software function modules are stored in a storage medium and include several instructions for causing a computer device (which can be a personal computer, a computer device, or a network device, etc.) or a processor to execute part of the functions of the information encryption method according to various embodiments of the present application.

[0060] In summary, for an information encryption method, system, device, and medium disclosed by the present invention, after obtaining the information to be encrypted, the sensitive information therein is replaced with desensitized information. Through this desensitization process, it is possible to effectively prevent the leakage of sensitive information during the transmission process and subsequent model processing process, thereby ensuring data privacy and security. In addition, the processed information to be encrypted is symmetrically encrypted through a symmetric encryption algorithm, which can not only improve the encryption efficiency and security strength, but also ensure that the information sent to the large language model does not contain sensitive content. By decrypting the processing result generated by the large language model and replacing the desensitized information therein with the corresponding sensitive information, while ensuring data security, the final processing result with complete semantics and containing the sensitive information input by the user can be restored. The present invention not only ensures the security of sensitive information throughout the transmission and processing processes, but also guarantees the accuracy and readability of the processing result through reverse desensitization. Therefore, the present invention effectively overcomes various disadvantages in the prior art and has high industrial utilization value.

[0061] The above embodiments are only illustrative of the principles and effects of the present invention and are not intended to limit the present invention. Any person familiar with this technology can modify or change the above embodiments without departing from the spirit and scope of the present invention. Therefore, all equivalent modifications or changes completed by those with ordinary knowledge in the technical field without departing from the spirit and technical ideas disclosed by the present invention should still be covered by the claims of the present invention.

Claims

1. An information encryption method, characterized in that, The method includes: Obtain the information to be encrypted, generate and send an encryption request; Perform desensitization processing on the information to be encrypted, replace the sensitive information in the information to be encrypted with desensitized information, and obtain the processed information to be encrypted; Receive the first key, and use the first key to perform symmetric encryption on the processed information to be encrypted to generate encrypted information; wherein, the first key is generated by the first server based on the encryption request, returned after asymmetric encryption, and obtained after decryption with a preset asymmetric private key; Send the encrypted information; Receive the processing result and perform symmetric decryption on the processing result based on the second key, and replace the desensitized information in the symmetrically decrypted processing result with the corresponding sensitive information to obtain the final processing result; wherein, the processing result is obtained by the second server calling a large language model to process the encrypted information, and the second key is the symmetric key of the first key.

2. The information encryption method according to claim 1, wherein The performing desensitization processing on the information to be encrypted, replacing the sensitive information in the information to be encrypted with desensitized information, and obtaining the processed information to be encrypted includes: Detect the type of the information to be encrypted: If the information to be encrypted is structured information, perform sensitive information identification on the information to be encrypted, perform desensitization processing on the identified sensitive information, replace the sensitive information in the information to be encrypted with the desensitized information after desensitization processing, and obtain the processed information to be encrypted; If the information to be encrypted is unstructured information, perform semantic desensitization processing on the information to be encrypted to replace the sensitive information in the information to be encrypted with desensitized information, and obtain the processed information to be encrypted.

3. The information encryption method according to claim 2, wherein The performing sensitive information identification on the information to be encrypted, performing desensitization processing on the identified sensitive information, replacing the sensitive information in the information to be encrypted with the desensitized information after desensitization processing, and obtaining the processed information to be encrypted includes: Detect whether there is preset sensitive information in the information to be encrypted: If it exists, calculate the hash value of the sensitive information based on the hash algorithm, use the hash value as the desensitized information, replace the corresponding sensitive information, and obtain the processed information to be encrypted; If it does not exist, use the information to be encrypted as the processed information to be encrypted.

4. The information encryption method according to claim 2, characterized in that, The performing semantic desensitization processing on the information to be encrypted to replace the sensitive information in the information to be encrypted with desensitized information, and obtaining the processed information to be encrypted includes: Perform fuzzy matching between the information to be encrypted and the sentiment words in the sentiment word library to identify the sensitive information with subjective sentiment in the information to be encrypted; Extract the text statement where the sensitive information is located and the corresponding context statement from the information to be encrypted, and input each extracted text statement into a sentiment analysis model to obtain the sentiment score of the sensitive information; Judge whether the sentiment score is within a preset sentiment intensity range: If so, retain the sensitive information and use the information to be encrypted as the processed information to be encrypted; Otherwise, according to a preset vocabulary replacement table, replace the sensitive information in the information to be encrypted with the corresponding desensitized information to obtain the processed information to be encrypted.

5. The information encryption method according to claim 1, wherein Receiving the processing result, symmetrically decrypting the processing result based on the second key, and replacing the desensitized information in the symmetrically decrypted processing result with the corresponding sensitive information to obtain the final processing result, including: Receiving the processing result and performing symmetric decryption processing on the processing result based on the second key to obtain the decrypted processing result; Checking from the pre-stored mapping table whether there is desensitized information in the decrypted processing result that matches the mapping table: wherein, the mapping table stores the mapping relationship between sensitive information and the corresponding desensitized information; If it exists, based on the mapping relationship between the found sensitive information and the corresponding desensitized information, replacing the desensitized information in the decrypted result with the corresponding sensitive information to obtain the final processing result; If it does not exist, directly using the decrypted processing result as the final processing result.

6. The information encryption method according to claim 1, wherein After obtaining the final processing result, it further includes: performing differential display on the processing result based on the user identifier in the information to be encrypted.

7. The information encryption method according to claim 1, wherein The symmetric encryption is the Advanced Encryption Standard algorithm.

8. An information encryption system, characterized in that, The system includes: A data acquisition module, configured to acquire the information to be encrypted, generate and send an encryption request; A desensitization module, configured to desensitize the information to be encrypted, replace the sensitive information in the information to be encrypted with desensitized information, and obtain the processed information to be encrypted; An encryption module, configured to receive the first key and perform symmetric encryption on the processed information to be encrypted using the first key to generate encrypted information; wherein, the first key is generated by the first server based on the encryption request, returned after being asymmetrically encrypted, and obtained after being decrypted by the preset asymmetric private key; A sending module, configured to send the encrypted information; A decryption and restoration module, configured to receive the processing result, symmetrically decrypt the processing result based on the second key, and replace the desensitized information in the symmetrically decrypted processing result with the corresponding sensitive information to obtain the final processing result; wherein, the processing result is obtained by the second server calling a large language model to process the encrypted information, and the second key is the symmetric key of the first key.

9. An electronic device, characterized in that, The electronic device includes: One or more processors; A storage device, configured to store one or more programs, which, when executed by the one or more processors, cause the electronic device to implement the information encryption method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, A computer program is stored thereon, which, when executed by a processor of the computer, causes the computer to execute the information encryption method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Method for detecting network sensitive information based on content and emotion

    CN113590738A

  • Encryption and desensitization system and method for personal biological characteristic sensitive data

    CN115766148A

  • Data encryption method and device based on classification identification and storage medium

    CN117556447A

  • Large model data protection method, system and equipment based on data grid

    CN119475425A

  • Large model reasoning method and device based on sensitive information protection and related equipment

    CN119623648A