Multi-party privacy protection risk assessment method and device, and storage medium

Data aggregation between banks through homomorphic encryption technology has been solved, and the problem of inability to communicate between banks has been realized, and a multi-party customer risk assessment is carried out on the premise of protecting privacy, which has improved the early warning capabilities of telecommunications fraud.

CN120372616APending Publication Date: 2025-07-25SHANXI CHINA MOBILE COMM CORP +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410109804.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-25
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

The inability to communicate interbank data leads to the inability to identify telecom fraud customers. The existing technology cannot conduct multiple parties to evaluate customer risks in combination while protecting privacy, and there is a problem of insufficient early warning capabilities.

Method used

Homomorphic encryption technology is adopted to obtain the homomorphic encrypted data of the data node and perform the first homomorphic aggregation process, generate homomorphic decryption shards, and perform the second homomorphic aggregation process to obtain multi-party privacy aggregation data for risk assessment, and use homomorphic operations to combine the privacy data without decryption.

Benefits of technology

It realizes the multi-party evaluation of customer risks while protecting the privacy data of each data node, improves the security and privacy of the data, and supports multi-party risk warning.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120372616A_ABST
    Figure CN120372616A_ABST
Patent Text Reader

Abstract

The invention provides a multi-party privacy risk assessment method and device and a storage medium, and relates to the field of data sharing security, and the method comprises the steps: obtaining homomorphic encryption data of a data node; performing first homomorphic aggregation processing on the homomorphic encrypted data to obtain first homomorphic aggregated data; sending the first homomorphic aggregation data to a data node; obtaining a homomorphic decryption fragment; performing second homomorphic aggregation processing on the homomorphic decryption fragment to obtain second homomorphic aggregation data; acquiring multi-party privacy aggregated data according to the first homomorphic aggregated data and the second homomorphic aggregated data; and performing risk assessment according to the multi-party privacy aggregation data to obtain a risk assessment result. According to the method, the privacy data is aggregated by using homomorphic operation without decryption, and the multi-party privacy aggregated data is obtained for risk assessment, so that the effect of multi-party combination customer risk assessment on the premise of privacy protection is achieved, multi-party combination risk early warning is realized, and the security and privacy of the data are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data sharing security technology, and in particular to a multi-party privacy risk assessment method, device and storage medium. Background Art

[0002] As an institution for transfer transactions, improving the account identification level of telecom fraudsters is the key to combating telecom fraud. Fraudsters often open cards at multiple different banks at the same time. During the card opening review stage, due to customer privacy protection requirements, the data between banks cannot be interoperable and the above situation cannot be identified, resulting in the failure to issue early warnings in a timely manner. In other words, the existing anti-telecom fraud strategies are based on data within the bank and have insufficient early warning capabilities.

[0003] In the existing technology, banks directly query through the user's identity information, which has the risk of leaking the user's identity information. At the same time, without encryption protection or the assistance of a trusted center, it is easy to leak the data of all parties. Therefore, how to establish a security and privacy mechanism under the premise of protecting the privacy of each bank, so that multiple banks can jointly improve the customer identification ability before opening a card, query the number of cards opened by users in multiple banks, and issue early warnings to risky customers to achieve the purpose of enhancing the level of anti-telecom fraud, is an urgent problem to be solved. Summary of the invention

[0004] The present invention provides a multi-party privacy risk assessment method, device and storage medium, which are used to solve the defect in the prior art that banks cannot conduct multi-party combined assessment of customer risks under the premise of protecting privacy.

[0005] The present invention provides a multi-party privacy risk assessment method, which is applied to a querying party and includes:

[0006] Obtaining homomorphically encrypted data of the data node, wherein the homomorphically encrypted data is obtained by encrypting the private data with a combined encryption public key, wherein the combined encryption public key is obtained by combining the public keys of each of the data nodes;

[0007] Performing a first homomorphic aggregation process on the homomorphically encrypted data to obtain first homomorphic aggregated data, wherein the first homomorphic aggregation process is used to combine the private data without decryption;

[0008] Sending the first homomorphic aggregate data to the data node, so that the data node processes the first homomorphic aggregate data based on its own private key shard to generate a homomorphic decryption shard;

[0009] Obtaining the homomorphic decryption fragment;

[0010] Perform a second homomorphic aggregation process on the homomorphic decryption shards to obtain second homomorphic aggregation data. The second homomorphic aggregation process is used to combine the private key shards in the homomorphic decryption shards to form a combined decryption private key;

[0011] Based on the first homomorphic aggregation data and the second homomorphic aggregation data, obtain multi-party privacy aggregation data, where the multi-party privacy aggregation data represents the data formed by combining the privacy data of each of the data nodes;

[0012] Perform a risk assessment based on the multi-party privacy aggregation data to obtain a risk assessment result.

[0013] According to a multi-party privacy risk assessment method provided by the present invention, the combined decryption private key is formed by processing the private key shards based on a preset threshold value, and the combined decryption private key is obtained from the private key shards with a quantity greater than or equal to the preset threshold value; the sending of the first homomorphic aggregation data to the data node includes:

[0014] Select data nodes with a quantity greater than or equal to the preset threshold value as decryption nodes;

[0015] Send the first homomorphic aggregation data to the decryption nodes.

[0016] According to a multi-party privacy risk assessment method provided by the present invention, the private key shard is a polynomial value obtained by substituting the unique identification code corresponding to the data node into a global polynomial. The global polynomial is formed by each data node randomly generating a polynomial of degree k - 1 and the combined decryption private key, where k is the preset threshold value. The global polynomial can be determined based on the private key shards with a quantity greater than or equal to the preset threshold value to determine the combined decryption private key.

[0017] According to a multi-party privacy risk assessment method provided by the present invention, the homomorphic encrypted data includes a random term, a privacy encryption term, and a verification term. The first homomorphic aggregation data includes a random aggregation term, a privacy aggregation term, and a verification aggregation term. The random aggregation term is used to enable the decryption node to perform processing to generate the homomorphic decryption shards, the privacy aggregation term is used to decrypt and obtain the multi-party privacy aggregation data, and the verification aggregation term is used to verify whether the homomorphic encrypted data has been tampered with.

[0018] According to a multi-party privacy risk assessment method provided by the present invention, the sending of the first homomorphic aggregation data to the decryption node to obtain the homomorphic decryption shards includes:

[0019] Send the first homomorphic aggregated data and each of the homomorphic encrypted data to the decryption node, so that the decryption node verifies whether the first homomorphic aggregated data is tampered with according to the random aggregation item, the public keys of each data node, and the verification aggregation item, and generates the homomorphic decryption shard when the first homomorphic aggregated data is not tampered with;

[0020] The obtaining the homomorphic decryption shard includes:

[0021] Obtain the homomorphic decryption shards of each decryption node.

[0022] According to a multi-party privacy risk assessment method provided by the present invention, the performing risk assessment according to the multi-party privacy aggregated data to obtain a risk assessment result includes:

[0023] Compare the multi-party privacy aggregated data with a preset risk threshold to obtain a risk assessment result.

[0024] The present invention also provides a multi-party privacy risk assessment method, which is applied to a processing party and includes:

[0025] In response to the data request information of the query party, perform encryption processing on the privacy data based on the combined encryption public key to form homomorphic encrypted data;

[0026] Send the homomorphic encrypted data to the query party;

[0027] In response to the decryption request information of the query party, obtain first homomorphic aggregated data, where the first homomorphic aggregated data is obtained by performing first homomorphic aggregation processing on the homomorphic encrypted data of each data node, and the first homomorphic aggregation processing is used to combine the privacy data without decrypting;

[0028] Process the first homomorphic aggregated data according to the private key shard to generate a homomorphic decryption shard;

[0029] Send the homomorphic decryption shard to the query party;

[0030] Wherein, the homomorphic decryption shard is used to obtain a combined decryption private key, the combined decryption private key represents a key formed by combining the private keys of each data node, and the combined decryption private key is used to decrypt the first homomorphic aggregated data to obtain multi-party privacy aggregated data.

[0031] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, and when the processor executes the program, it implements the multi-party privacy risk assessment method as described in any one of the above.

[0032] The present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements a multi-party privacy risk assessment method as described in any one of the above.

[0033] The present invention also provides a computer program product, including a computer program. When the computer program is executed by a processor, it implements a multi-party privacy risk assessment method as described in any one of the above.

[0034] The multi-party privacy risk assessment method, device and storage medium provided by the present invention have at least the following beneficial effects: The querying party obtains the homomorphic encrypted data of each data node, performs a first homomorphic aggregation process on the homomorphic encrypted data to obtain first homomorphic aggregation data. Utilizing the characteristics of homomorphic operations, the result of combining the first homomorphic aggregation data with the privacy data and then performing encryption processing is the same, enabling the combination of privacy data without decryption. The querying party sends the first homomorphic aggregation data to the decrypted data nodes, allowing the data nodes to use their respective private key shards to process the first homomorphic aggregation data to generate homomorphic decryption shards, which contain the information of the private key shards. The querying party performs a second homomorphic aggregation process on each homomorphic decryption shard to obtain second homomorphic aggregation data containing the combined decryption private key. The combined decryption private key corresponds to the combined encryption public key for encrypting the homomorphic encrypted data, enabling the decryption of the first homomorphic aggregation data, and then obtaining multi-party privacy aggregation data for risk assessment. Thus, by using homomorphic operations, the privacy data is aggregated without decryption, achieving the effect of protecting the privacy data of each data node. The second homomorphic aggregation data is obtained through homomorphic decryption shards to decrypt the first homomorphic aggregation data, and multi-party privacy aggregation data reflecting the combination of the privacy data of each data node is obtained for risk assessment, achieving the effect of multi-party combined assessment of customer risks while protecting privacy, which is conducive to realizing multi-party combined risk warning and improving the security and privacy of data. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0036] Figure 1 FIG. 1 is one of the flow diagrams of a multi-party privacy risk assessment method applied to a querying party provided by the present invention;

[0037] Figure 2 FIG. 2 is another flow diagram of a multi-party privacy risk assessment method applied to a querying party provided by the present invention;

[0038] Figure 3 It is one of the schematic flowcharts of a multi - party privacy risk assessment method provided by the present invention and applied to the processing party;

[0039] Figure 4 It is the schematic structural diagram of the electronic device provided by the present invention. Specific embodiments

[0040] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the present invention will be clearly and completely described below with reference to the accompanying drawings in the present invention. Obviously, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present invention without making creative efforts belong to the scope of protection of the present invention.

[0041] The following combines Figure 1 - Figure 2 Describe a multi - party privacy risk assessment method of the present invention, which is applied to the query party and includes:

[0042] S100: Obtain the homomorphic encrypted data of the data node. The homomorphic encrypted data is obtained by encrypting the privacy data with the combined encryption public key, and the combined encryption public key is obtained by combining the public keys of each data node;

[0043] S110: Perform a first homomorphic aggregation process on the homomorphic encrypted data to obtain first homomorphic aggregation data. The first homomorphic aggregation process is used to combine the privacy data without decrypting;

[0044] S120: Send the first homomorphic aggregation data to the data node so that the data node processes the first homomorphic aggregation data based on its own private key shards to generate homomorphic decryption shards;

[0045] S130: Obtain the homomorphic decryption shards;

[0046] S140: Perform a second homomorphic aggregation process on the homomorphic decryption shards to obtain second homomorphic aggregation data. The second homomorphic aggregation process is used to combine the private key shards in the homomorphic decryption shards to form a combined decryption private key;

[0047] S150: According to the first homomorphic aggregation data and the second homomorphic aggregation data, obtain multi - party privacy aggregation data. The multi - party privacy aggregation data represents the data formed by combining the privacy data of each data node;

[0048] S160: Perform a risk assessment according to the multi - party privacy aggregation data to obtain a risk assessment result.

[0049] The querying party obtains the homomorphically encrypted data of each data node, performs a first homomorphic aggregation process on the homomorphically encrypted data to obtain first homomorphic aggregation data. Utilizing the characteristics of homomorphic operations, the result of combining the first homomorphic aggregation data with the private data and then performing encryption is the same, enabling the combination of private data without decryption. The querying party sends the first homomorphic aggregation data to the decrypted data nodes, allowing the data nodes to use their respective private key shards to process the first homomorphic aggregation data to generate homomorphic decryption shards, which contain information about the private key shards. The querying party performs a second homomorphic aggregation process on each homomorphic decryption shard to obtain second homomorphic aggregation data containing the combined decryption private key. The combined decryption private key corresponds to the combined encryption public key for encrypting the homomorphically encrypted data, enabling the decryption of the first homomorphic aggregation data, and thus obtaining multi-party private aggregation data for risk assessment. In this way, homomorphic operations are used to aggregate private data without decryption, achieving the effect of protecting the private data of each data node. By obtaining the second homomorphic aggregation data through homomorphic decryption shards to decrypt the first homomorphic aggregation data and obtaining multi-party private aggregation data reflecting the combination of the private data of each data node for risk assessment, the effect of multi-party combined assessment of customer risks is achieved under the premise of protecting privacy, which is conducive to realizing multi-party combined risk warning and improving data security and privacy.

[0050] The querying party can be one of the data nodes, and the data nodes can be devices such as the data servers of each bank. The public keys of each data node are public. Therefore, each data node can obtain all the public keys for processing to obtain the same combined encryption public key, and then encrypt the private data based on the combined encryption public key to form homomorphically encrypted data.

[0051] Homomorphic operation refers to the process in which during the first operation on encrypted data, the original data is combined with a second operation of fixed mapping. For example: f(x)·f(y) = f(x + y) or f(x)+f(y) = f(x·y), that is, when performing multiplication and addition operations on the encrypted data f(x) and f(y), the original data x and y are processed with the corresponding addition and multiplication. It can be seen that due to the characteristics of homomorphic operations, the result obtained by performing the first operation on the encrypted data is the same as the result obtained by encrypting the original data after performing the second operation.

[0052] First, the private data is protected by encrypting it. The homomorphically encrypted data does not disclose the private data. The homomorphically encrypted data and the first homomorphic aggregation process utilize the characteristics of homomorphic operations, making the first homomorphic aggregation data equivalent to the result of encrypting the combined private data of each individual. Therefore, the combined private data, i.e., multi-party private aggregation data, can be obtained by decrypting the first homomorphic aggregation data using the decryption method corresponding to the encryption method for generating the homomorphically encrypted data.

[0053] It should be emphasized that in general encryption and decryption methods, the encryption object is the same as the object obtained after decryption. However, the present invention utilizes the characteristics of homomorphic operations to achieve the effect that the encryption object is different from the object obtained after decryption by using a single encryption and decryption method. That is, the encryption object is private data, while the object obtained after decryption is the combined data of multiple parties' privacy. Thus, on the basis of not revealing privacy, the effect of obtaining the combined data of multiple parties is achieved.

[0054] Through the second homomorphic aggregation process on the homomorphic decryption shards, the private key shards included in the homomorphic decryption shards are combined to form the second homomorphic aggregation data. Similar to the principle of the first homomorphic aggregation process, the second homomorphic aggregation process also utilizes the characteristics of homomorphic operations. The result of processing the first homomorphic data by each private key shard is the same as the result of processing the first homomorphic data after combining each private key shard, both of which are the second homomorphic aggregation data. That is, the second homomorphic aggregation data can be understood as containing the information of the combined decryption private key formed by combining each private key shard.

[0055] It should be noted that the process of a private key shard processing the first homomorphic data is not a step of decrypting and restoring the data, but rather a process that enables the homomorphic decryption shard to contain the information of the private key shard. In another way of understanding, it can be considered that the homomorphic decryption shard is the data formed after encrypting the private key shard, so that the homomorphic decryption shard contains the information of the private key shard.

[0056] Through the method provided by the present invention, the requirements for risk assessment of customers in the bank card opening scenario can be met. For example, the private data is the number of bank cards opened by a customer in each bank, and the combined data of multiple parties' privacy corresponds to the total number of bank cards opened in each bank. It is possible to obtain the total number of bank cards opened while not revealing the specific number of bank cards opened by each bank, protecting the privacy of the number of bank cards opened by each bank and being able to obtain the total number of bank cards opened for risk assessment of the customer. When the total number of bank cards opened by the customer is greater than the risk threshold, a risk warning is issued for the customer.

[0057] For the convenience of subsequent understanding, the combined encryption public key and the combined decryption private key are first described. In some embodiments of the present invention: there are N data nodes, and the private key of each data node is x i , then the combined decryption private key can be X = ∑x i , that is, the sum of the private keys of each data node is the combined decryption private key, and the public key of each node is then the combined encryption public key can be that is, the result of multiplying the public keys of each data node is the combined encryption public key.

[0058] The above is only an illustrative description and does not limit specific implementations. For example, the combined decryption private key can also be obtained by multiplying the private keys of each data node, and the combined encryption public key can also be the sum of each data node, or obtained by other operations. Subsequently, it is defaulted that the combined decryption private key is obtained by the above accumulation and the combined encryption public key is obtained by multiplication.

[0059] Reference Figure 2 , in some embodiments of a multi-party privacy risk assessment method where the present invention is applied to a querying party, the combined decryption private key is processed based on a preset threshold value to form the private key shards, and the combined decryption private key is obtained from the private key shards with a quantity greater than or equal to the preset threshold value; the S120 includes:

[0060] S121: Select the data nodes with a quantity greater than or equal to the preset threshold value as decryption nodes;

[0061] S122: Send the first homomorphic aggregated data to the decryption nodes.

[0062] Since the combined decryption private key only needs to be determined by the private key shards with a quantity greater than the preset threshold value, therefore, select the data nodes with a quantity greater than or equal to the preset threshold value as decryption nodes, obtain the homomorphic decryption shards from the decryption nodes, meet the quantity requirements corresponding to the preset threshold value, and then obtain the second homomorphic aggregated data containing the combined decryption private key based on the homomorphic decryption shards. In this way, it is not necessary to obtain the homomorphic decryption shards of all data nodes, and only the homomorphic decryption shards with a quantity greater than or equal to the preset threshold value need to be obtained, which is beneficial to avoid the situation where decryption cannot be performed when one data node fails, making the decryption more flexible.

[0063] It should be noted that each data node can be regarded as a group. When one data node fails, the public key and private key of the group will not change, that is, the combined encryption public key and the combined decryption private key will not change. By setting the preset threshold value, the data nodes required to obtain the combined decryption private key can be flexibly adjusted, that is, the number of homomorphic decryption shards required. In this way, the security and risk resistance can be balanced. The larger the preset threshold value, the more data nodes are required to participate in decryption and the higher the security. The smaller the preset threshold value, the lower the requirements for the data nodes participating in decryption and the more the number of faulty data nodes that can be resisted, that is, the stronger the risk resistance.

[0064] In some embodiments of a multi-party privacy risk assessment method where the present invention is applied to a querying party, the private key shards are polynomial values obtained by substituting the unique identification codes corresponding to the data nodes into a global polynomial, and the global polynomial is formed by each of the data nodes randomly generating a polynomial of degree k - 1 and the combined decryption private key, where k is the preset threshold value. The combined decryption private key can be determined based on the private key shards whose quantity is greater than or equal to the preset threshold value to determine the global polynomial.

[0065] The combined decryption private key can be determined by private key shards whose quantity is greater than or equal to the preset threshold value. Therefore, the querying party performs a second homomorphic aggregation process by obtaining homomorphic decryption shards whose quantity is greater than or equal to the preset threshold value to obtain second homomorphic aggregation data. Since the second homomorphic aggregation data contains private key shard information whose quantity is greater than or equal to the preset threshold value, the combined decryption private key can be determined based on this, and then the first homomorphic aggregation data is decrypted based on the second homomorphic aggregation data. In this way, taking advantage of the characteristics of homomorphic operations, homomorphic operations are carried out with homomorphic decryption shards as the carrier to combine the private key shards, which can, under the condition of ensuring that the private key shards are not disclosed, obtain private key shards whose quantity is greater than or equal to the preset threshold value for combination, meet the determination conditions of the combined decryption private key, and obtain the combined decryption private key.

[0066] By having each data node randomly generate a polynomial of degree k - 1 respectively and combining the private keys of each data node, a global polynomial containing combined decryption private key information is formed, that is, the global polynomial can determine the combined decryption private key. In this way, the obtained global polynomial is randomly generated by each data node, which is beneficial to improving security.

[0067] Based on the uniqueness theorem of interpolation polynomials, that is, a polynomial of degree k - 1 requires more than k numerical points to be determined, the preset threshold value is k, and the second homomorphic aggregation data contains private key shard (corresponding to k numerical points) information whose quantity is greater than or equal to the threshold value k, which can determine the global polynomial, and then determine the combined decryption private key. In this way, through the method of each data node randomly generating polynomials to form a global polynomial, the function that more than or equal to the corresponding quantity of homomorphic decryption shards of the preset threshold value is required to determine the combined decryption private key is realized.

[0068] For the sake of easy understanding, an example is given to illustrate the global polynomial. In some embodiments of the present invention, there are n data nodes, and each data node randomly generates a polynomial of degree k - 1, D i (x), based on all the random polynomials and the combined decryption private key, the global polynomial is obtained:

[0069]

[0070] where F(x) is the global polynomial, A is the coefficient, and C is the constant term.

[0071] Suppose that if we want to combine the decryption private key with the value of the polynomial when the independent variable is 0, we can adjust the constant term so that the global polynomial satisfies:

[0072] F(0) = C = ∑x i

[0073] where x i is the private key of each data node. Similarly, by adjusting the constant term, we can set the value of the polynomial when the independent variable is other values to the combined decryption private key. Subsequently, it is defaulted that the value of the polynomial when the independent variable is 0 is the combined decryption private key.

[0074] Generate private key shards according to the unique identification code of each data node:

[0075] sk i = F(ID i )

[0076] where sk i is the private key shard, and ID i is the unique identification code of the data node. It can be understood that other values associated with the data node can also be used to generate the corresponding private key shards.

[0077] Based on the above situation, according to the uniqueness theorem of interpolation polynomials, the following expression can be obtained:

[0078]

[0079]

[0080] Similarly, through the method of interpolation, the global polynomial F(x) is restored and determined based on k private key shards. Since each private key shard is generated by the same global polynomial F(x), as long as the preset threshold value is satisfied, even if different private key shards are used, the same global polynomial F(x) will be restored and obtained. Further, substituting the independent variable x = 0, we can obtain F(0) = ∑x i , that is, the combined decryption private key.

[0081] The above is the principle explanation for determining the combined decryption private key based on private key shards with a quantity greater than or equal to the threshold value. It can be understood that the homomorphic decryption shards are subjected to the second homomorphic aggregation process to obtain the second homomorphic aggregation data. During this process, no private key information is leaked. Utilizing the characteristics of homomorphic operations and the above principle, the second homomorphic aggregation data contains the information of the combined decryption private key.

[0082] In some embodiments of a multi-party privacy risk assessment method where the present invention is applied to a querying party, the homomorphic encrypted data includes a random term, a privacy encrypted term, and a verification term. The first homomorphic aggregated data includes a random aggregated term, a privacy aggregated term, and a verification aggregated term. The random aggregated term is used for the decryption node to process to generate the homomorphic decryption shard. The privacy aggregated term is used to decrypt and obtain the multi-party privacy aggregated data. The verification aggregated term is used to verify whether the homomorphic encrypted data has been tampered with.

[0083] The homomorphic encrypted data includes a triple data of a random term, a privacy encrypted term, and a verification term. When performing the first homomorphic aggregation process, the triple data are respectively aggregated to form a random aggregated term, a privacy aggregated term, and a verification aggregated term, that is, the first homomorphic aggregated data. The verification term is used to verify whether the homomorphic encrypted data has been tampered with. Similarly, the verification aggregated term is used to verify whether there is a tampered part in the aggregated first homomorphic data. In this way, it is beneficial to improve the security of the data.

[0084] It should be noted that the privacy encrypted term is formed by encrypting privacy data, combined encryption public key, and a random factor. When decrypting, the random factor and the combined decryption private key need to be determined. The random factor is randomly generated by each node, which is beneficial to dynamically change the encryption process and improve security. The random term is also formed by the random factor. The random aggregated term aggregates the random factors of each data node. The random aggregated term is used to generate the homomorphic decryption shard, that is, while carrying the private key shard information back to each decryption node, it also plays the role of eliminating the random factor in the privacy aggregated term during decryption.

[0085] In some embodiments of the present invention, the homomorphic encrypted data can be expressed as:

[0086]

[0087] The homomorphic aggregation process of the homomorphic encrypted data to obtain the first homomorphic aggregated data is achieved through the following formula:

[0088]

[0089]

[0090] where E(m i ) is the homomorphic encrypted data, i is the serial number of the data node, g is a preset value, is the random term, is the privacy encrypted term, s i is the verification term, m i is the privacy data, Y is the combined encryption public key, r i is the random factor of the i-th data node, E(∑m i) is the first homomorphic aggregation data, is a random aggregation item, is a privacy aggregation item, ∑s i is a verification aggregation item.

[0091] In some embodiments of a multi-party privacy risk assessment method where the present invention is applied to a querying party, the S122 includes:

[0092] Send the first homomorphic aggregation data and each of the homomorphic encrypted data to the decryption node, so that the decryption node verifies whether the first homomorphic aggregation data has been tampered with according to the random aggregation item, the public keys of each data node, and the verification aggregation item, and generates the homomorphic decryption shard when the first homomorphic aggregation data has not been tampered with;

[0093] The S130 includes:

[0094] Obtain the homomorphic decryption shards of each decryption node.

[0095] Each decryption node verifies based on the random aggregation item, the public keys of each data node, and the verification aggregation item to ensure that the part of the obtained first homomorphic aggregation data that has not been tampered with. After determining that the first homomorphic aggregation data has not been tampered with, that is, it is truly generated by each data node, further process the first homomorphic aggregation data to generate the homomorphic decryption shard, and send the homomorphic decryption shard back to the querying party. In this way, it is beneficial to timely discover forged and tampered data and improve the security of the data.

[0096] It can be understood that the public keys of each data node are public and can be obtained arbitrarily.

[0097] In some embodiments of the present invention, the expression of the verification item is:

[0098] s i = r i + e i · xi

[0099]

[0100] Verify the authenticity of the first homomorphic aggregation data, that is, whether it has been tampered with. When the following expression is satisfied, it has not been tampered with:

[0101]

[0102] Among them, g is a preset value, ∑s i is the verification aggregation item, is the random aggregation item, r i is the random factor of the i-th data node, n is the total number of data nodes, Y iis the public key of the i-th data node, s i is the verification item, x i is the private key of the i-th data node, and Hash is the hashing operation.

[0103] The verification item s i is formed by the random factor, private key, and public key of the data node, and where e i is obtained by processing the random factor and public key through the hashing operation. Utilizing the non-tamperability of the hashing operation, it is ensured that the verification item cannot be tampered with, and then the entire homomorphic encrypted data is ensured not to be tampered with using the verification item.

[0104] In some embodiments of the present invention, the homomorphic decryption shard is obtained through the following formula:

[0105]

[0106] where, H i is the homomorphic decryption shard, g is a preset value, is the random aggregation item, sk i is the private key shard.

[0107] In some embodiments of the present invention, obtaining the multi-party privacy aggregation data based on the first homomorphic aggregation data and the second homomorphic aggregation data is achieved through the following expression:

[0108]

[0109]

[0110]

[0111]

[0112] where, T is the second homomorphic aggregation data, H i is the homomorphic decryption shard, sk i is the private key shard, ID i is the unique identification code of the data node, Y is the combined encryption public key, ∑x i is the combined decryption private key, is the privacy aggregation item, is the multi-party privacy aggregation data. Reference may be made to the description part above regarding the determination of the combined decryption private key based on the private key shards with a quantity greater than or equal to the threshold value.

[0113] Obtaining the second homomorphic aggregation data by calculating based on the homomorphic decryption shard Combining the privacy aggregation item in the first homomorphic aggregation data Enables the acquisition of the multi-party privacy aggregation data From the multi-party privacy-aggregated data, ∑m can be extracted i , that is, the sum of the privacy data of each data node, for risk assessment.

[0114] Based on the multi-party privacy-aggregated data It can be by combining a preset mapping table to obtain the specific value of the privacy sum and data ∑m i In computer data processing, it is difficult to perform logarithmic log processing. When the specific value of g is known, by exponentiating g x to construct ∑m i and the mapping table can facilitate subsequent based on obtaining ∑m i .

[0115] In some embodiments of a multi-party privacy risk assessment method of the present invention applied to a querying party, the S160 includes:

[0116] Comparing the multi-party privacy-aggregated data with a preset risk threshold to obtain a risk assessment result.

[0117] After obtaining the multi-party privacy-aggregated data Determine the specific value of the privacy sum and data ∑m i After that, compare the privacy sum and data ∑m i with a preset risk threshold. When the privacy sum and data ∑m i is greater than the risk threshold, take the existence of risk as the risk assessment result. When the privacy sum and data ∑m i is less than or equal to the risk threshold, take no risk as the risk assessment result.

[0118] The privacy data m i can be the number of bank cards opened. Then ∑m i is the total number of bank cards opened by each bank. Through the method of the present invention, without disclosing the number of bank cards opened by each bank m i , the total number of bank cards opened by each bank ∑m i can be obtained, meeting the need for risk assessment of customers in the bank card opening scenario, protecting the privacy of the number of bank cards opened by each bank and being able to obtain the total number of opened cards for risk assessment of customers.

[0119] Refer to Figure 3 , the present invention also provides a multi-party privacy risk assessment method, applied to a processing party, including:

[0120] S200: In response to the data request information of the querying party, encrypt the privacy data based on the combined encryption public key to form homomorphic encrypted data;

[0121] S210: Send the homomorphic encrypted data to the querying party;

[0122] S220: In response to the decryption request information of the querying party, obtain first homomorphic aggregated data, where the first homomorphic aggregated data is obtained by performing a first homomorphic aggregation process on the homomorphic encrypted data of each data node, and the first homomorphic aggregation process is used to combine the private data without decrypting;

[0123] S230: Process the first homomorphic aggregated data according to the private key shards to generate homomorphic decryption shards;

[0124] S240: Send the homomorphic decryption shards to the querying party;

[0125] Among them, the homomorphic decryption shards are used to obtain a combined decryption key, and the combined decryption key represents a key formed by combining the private keys of each data node, and the combined decryption key is used to decrypt the first homomorphic aggregated data to obtain multi-party private aggregated data.

[0126] When the processing party receives the data request information of the querying party, according to the data request information, determine the target private data, and encrypt the private data based on the combined encryption public key to form homomorphic encrypted data and return it to the querying party. The querying party processes the homomorphic encrypted data to form first homomorphic aggregated data, and sends decryption request information to the processing party. The processing party receives the decryption request information of the querying party, obtains the first homomorphic aggregated data for processing, generates homomorphic decryption shards and returns them to the querying party. The querying party processes the homomorphic decryption shards to form second homomorphic aggregated data, and based on the first homomorphic aggregated data and the second homomorphic aggregated data, obtains multi-party private aggregated data for risk assessment.

[0127] The processing party can be a data node. Further, in the case where a preset threshold value is set, it can be used as a decryption node to process the first homomorphic aggregated data according to the private key shards to generate homomorphic decryption shards.

[0128] A multi-party private risk assessment method applied to the processing party of the present invention can be referred to in conjunction with a multi-party private risk assessment method applied to the querying party as described above, and will not be elaborated here.

[0129] The querying party can send data request information to the processing party in a way of anonymous query, etc.

[0130] Figure 4 Illustrates a schematic diagram of the physical structure of an electronic device, such as Figure 4As shown in the figure, the electronic device may include: a processor 810, a communications interface 820, a memory 830, and a communication bus 840. Among them, the processor 810, the communications interface 820, and the memory 830 communicate with each other through the communication bus 840. The processor 810 may call the logic instructions in the memory 830 to execute the above-mentioned multi-party privacy risk assessment method.

[0131] The electronic device provided by the present invention can be used as a data node, and further can be used as a querying party or a processing party.

[0132] In addition, when the logic instructions in the above-mentioned memory 830 are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs, etc., which can store program codes.

[0133] On the other hand, the present invention also provides a computer program product. The computer program product includes a computer program. The computer program can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute a multi-party privacy risk assessment method provided by the above-mentioned various methods.

[0134] On another aspect, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it is implemented to execute a multi-party privacy risk assessment method provided by the above-mentioned various methods.

[0135] In the description of the present invention, it should be understood that the terms "first" and "second" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one of such features. In the description of the present invention, "a plurality" means at least two, such as two, three, etc., unless otherwise specifically defined.

[0136] In the description of this specification, the descriptions referring to terms such as "one embodiment", "some embodiments", "examples", "specific examples", or "some examples", etc., mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic descriptions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.

[0137] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A multi-party privacy risk assessment method, characterized in that, Applied to the querying party, including: Obtain the homomorphic encrypted data of the data nodes, where the homomorphic encrypted data is obtained by encrypting the private data with the combined encryption public key, and the combined encryption public key is obtained by combining the public keys of each data node; Perform a first homomorphic aggregation process on the homomorphic encrypted data to obtain first homomorphic aggregation data, where the first homomorphic aggregation process is used to combine the private data without decrypting; Send the first homomorphic aggregation data to the data nodes so that the data nodes process the first homomorphic aggregation data based on their own private key shards to generate homomorphic decryption shards; Obtain the homomorphic decryption shards; Perform a second homomorphic aggregation process on the homomorphic decryption shards to obtain second homomorphic aggregation data, where the second homomorphic aggregation process is used to combine the private key shards in the homomorphic decryption shards to form a combined decryption private key; Obtain multi-party private aggregation data based on the first homomorphic aggregation data and the second homomorphic aggregation data, where the multi-party private aggregation data represents the data formed by combining the private data of each data node; Perform a risk assessment based on the multi-party private aggregation data to obtain a risk assessment result.

2. The multi-party privacy risk assessment method according to claim 1, wherein The combined decryption private key is processed based on a preset threshold value to form the private key shards, and the combined decryption private key is obtained from the private key shards with a quantity greater than or equal to the preset threshold value; The sending the first homomorphic aggregation data to the data nodes includes: Select a quantity of data nodes greater than or equal to the preset threshold value as decryption nodes; Send the first homomorphic aggregation data to the decryption nodes.

3. The multi-party privacy risk assessment method according to claim 2, characterized in that, The private key shards are polynomial values obtained by substituting the unique identification codes corresponding to the data nodes into the global polynomial, and the global polynomial is formed by randomly generating a polynomial of degree k - 1 by each data node and the combined decryption private key, where k is the preset threshold value, and the global polynomial can be determined based on the private key shards with a quantity greater than or equal to the preset threshold value to determine the combined decryption private key.

4. The multi-party privacy risk assessment method according to claim 3, wherein, The homomorphic encrypted data includes a random term, a private encrypted term, and a verification term, the first homomorphic aggregation data includes a random aggregation term, a private aggregation term, and a verification aggregation term, the random aggregation term is used to let the decryption nodes process to generate the homomorphic decryption shards, the private aggregation term is used to decrypt to obtain the multi-party private aggregation data, and the verification aggregation term is used to verify whether the homomorphic encrypted data has been tampered with.

5. The multi-party privacy risk assessment method according to claim 4, wherein The sending the first homomorphic aggregation data to the decryption nodes to obtain the homomorphic decryption shards includes: Send the first homomorphic aggregation data and each homomorphic encrypted data to the decryption nodes so that the decryption nodes verify whether the first homomorphic aggregation data has been tampered with based on the random aggregation term, the public keys of each data node, and the verification aggregation term, and generate the homomorphic decryption shards when the first homomorphic aggregation data has not been tampered with; The obtaining the homomorphic decryption shards includes: Obtain the homomorphic decryption shards of each decryption node.

6. The multi-party privacy risk assessment method according to claim 1, characterized in that, Performing risk assessment based on the multi-party privacy aggregated data to obtain a risk assessment result, including: Comparing the multi-party privacy aggregated data with a preset risk threshold to obtain a risk assessment result.

7. A multi-party privacy risk assessment method, characterized in that Applied to the processing party, including: In response to the data request information of the query party, encrypting the privacy data based on the combined encryption public key to form homomorphic encrypted data; Sending the homomorphic encrypted data to the query party; In response to the decryption request information of the query party, obtaining first homomorphic aggregated data, where the first homomorphic aggregated data is obtained by performing a first homomorphic aggregation process on the homomorphic encrypted data of each data node, and the first homomorphic aggregation process is used to combine the privacy data without decrypting; Processing the first homomorphic aggregated data according to the private key shards to generate homomorphic decryption shards; Sending the homomorphic decryption shards to the query party; Wherein, the homomorphic decryption shards are used to obtain a combined decryption private key, the combined decryption private key represents a key formed by combining the private keys of each of the data nodes, and the combined decryption private key is used to decrypt the first homomorphic aggregated data to obtain multi-party privacy aggregated data.

8. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements a multi-party privacy risk assessment method according to any one of claims 1 to 7.

9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements a multi-party privacy risk assessment method according to any one of claims 1 to 7.

10. A computer program product, the computer program product comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements a multi-party privacy risk assessment method according to any one of claims 1 to 7.