Business and financial collaboration data security interaction method

By encrypting and processing data on the business side and building a secret index of blockchain, the problem of low data security and interaction efficiency in business finance collaboration is solved, and the security and efficient retrieval of data during transmission, storage and use is achieved.

CN120474754AInactive Publication Date: 2025-08-12GOLDEN NETWORK (BEIJING) E-COMMERCE CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510556313.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-29
Publication Date
2025-08-12
Estimated Expiration
Not applicable · inactive patent

Smart Images

  • Figure CN120474754A_ABST
    Figure CN120474754A_ABST
Patent Text Reader

Abstract

The invention discloses a business and financial collaboration data security interaction method, which belongs to the technical field of data security interaction, can ensure the security of data in transmission, storage and use processes by encrypting data between a business end and a financial end, and then can ensure the security of the data in the transmission, storage and use processes by taking attributes of the business end and the financial end as verification conditions. According to the method, the data can be effectively prevented from being acquired and decrypted by illegal persons, the security of the data in the interaction process is greatly improved, finally, the data can be retrieved in an encrypted state in time by generating the secret index, the security of data interaction is further improved, and the user experience is improved. The technical problem that in the prior art, the data security is low in the business and financial collaboration process is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of data security interaction, and specifically relates to a method for business-finance collaborative data security interaction. Background Art

[0002] Business-Finance Collaboration refers to the close integration of business management and financial management during the operation of an enterprise, and the realization of integrated business and financial operations through information sharing, process integration, data analysis and decision support. With the continuous deepening of enterprise informatization construction, business and financial collaboration has become a key link for enterprises to improve their management level. However, in the existing technology, the following problems exist in the process of business-finance collaboration: Data security issues: Business data and financial data are vulnerable to hacker attacks during transmission and storage, resulting in data leakage. Interaction efficiency issues: The data interaction process between the business system and the financial system is complex, resulting in low efficiency of collaborative work. Usability issues: In the existing technology, the business-finance collaboration system is complex to operate and has high requirements for users. Summary of the Invention

[0003] The present invention provides a method for secure data interaction in business-finance collaboration, which is used to solve the technical problem of low data security in the business-finance collaboration process in the prior art.

[0004] A method for secure data interaction between business and finance collaboration, comprising:

[0005] Initialize security interaction parameters; wherein, the security interaction parameters include system public parameters, the first key pair corresponding to the financial end, the second key pair corresponding to the business end, blockchain transactions, and attribute decryption keys;

[0006] According to the security interaction parameters, the data owner encrypts the interaction data to obtain the encrypted interaction data, constructs the secret index corresponding to the encrypted interaction data, and then publishes the encrypted interaction data and the corresponding secret index to the blockchain;

[0007] A data user generates a search trapdoor, and matches the secret index corresponding to the search trapdoor in the blockchain according to the search trapdoor to obtain a data search result; wherein the data search result indicates a search success or a search failure;

[0008] When the data search result is a successful search, the data user is attribute-verified according to the security interaction parameter and the encrypted interaction data is obtained from the blockchain for semi-decryption to obtain semi-decrypted data;

[0009] After the semi-decrypted data is transmitted to the data user, the semi-decrypted data is decrypted by the data user according to the security interaction parameters to obtain the plaintext data corresponding to the data to be interacted with, thereby realizing the secure interaction of business and financial collaborative data;

[0010] Among them, when the data owner is the business end, the data user is the financial end; when the data owner is the financial end, the data user is the business end.

[0011] In a possible implementation, the method for initializing the system common parameters includes:

[0012] Randomly select the first multiplication cyclic group G and the second multiplication cyclic group G of order p as prime number T ;

[0013] Determine a generator g of the first multiplicative cyclic group G;

[0014] Define a bilinear map is: G×G→G T ;

[0015] Determines the mapping of any string to Z p A first hash function H in , a second hash function H0 that maps the identity identifier to the first multiplication cyclic group G, and a third hash function H3 that maps the attribute to the first multiplication cyclic group G; wherein Z p represents the nonnegative minimal simplified residue system modulo p;

[0016] From Z p Randomly select the first random number γ;

[0017] Scheduling attribute management from Z p Randomly select the second random number α aid and the third random number β aid ;

[0018] The scheduling attribute management party uses the second random number α aid and the third random number β aid , generate the attribute management key as: and SK aid ={α aid , β aid}; Among them, PK aid Indicates the public key corresponding to the attribute manager who manages the attribute, SK aid Indicates the private key corresponding to the attribute manager that manages the attribute;

[0019] According to the prime number p, the first multiplication cyclic group G, the second multiplication cyclic group G T , generator g, bilinear map First random number γ, first hash function H, second hash function H0, third hash function H3, non-negative minimum simplified remainder system Z p , the public key PK corresponding to the attribute manager aid and private key SK aid , get the system common parameters.

[0020] In one possible implementation, a method for initializing a first key pair corresponding to the financial end and a second key pair corresponding to the business end includes:

[0021] Scheduling financial end from Z p Randomly select the fourth random number z oid , and generating a first key pair according to the fourth random number: and SK oid =z oid Among them, PK oid Represents the public key in the first key pair, SK oid represents the private key in the first key pair;

[0022] Scheduling business end from Z p Randomly select the fifth random number z uid , and generating a first key pair according to the fourth random number: and SK uid =z uid Among them, PK uid Represents the public key in the second key pair, SK uid Represents the private key in the second key pair.

[0023] In one possible implementation, a method for initializing a blockchain transaction includes:

[0024] Determine the financial end's identity identifier oid and assign the first attribute set S to the financial end oid , the first blockchain transaction is generated as: {oid, S oid , Timetamp oid}; Among them, Timetamp oid Indicates the first timestamp;

[0025] Determine the business side's identity identifier uid and assign the second attribute set S to the financial side uid , generate the second blockchain transaction as: {uid, S uid , Timetamp uid}; Among them, Timetamp uid Indicates the second timestamp;

[0026] Initialization method for attribute decryption key, including:

[0027] Determine the target attribute set S mb ; Among them, the target attribute set S mb Set as the first attribute set S oid Or the second attribute set S uid ;

[0028] Get the target attribute set S mb The corresponding first key parameter and second key parameter are:

[0029]

[0030] in, represents the first key parameter, Represents the second key parameter, t represents the value from Z p The sixth random number randomly selected from the mb Represents the fourth random number z oid or the fifth random number z uid , mb represents the financial side's identity identifier oid or the business side's identity identifier uid, att i Represents the target attribute set S mb The i-th attribute in ;

[0031] According to the first key parameter and the second key parameter, the attribute decryption key is determined to be:

[0032] In a possible implementation, the data owner encrypts the interaction data according to the security interaction parameter to obtain the encrypted interaction data, including:

[0033] According to the non-negative minimum simplified residual coefficient Z in the safe interaction parameter p , define a data access strategy as A; where A represents the non-negative minimum simplified residual system Z p Where is a matrix with l rows and n columns;

[0034] Through the data owner in Z p The first random array is randomly selected as {s,v2,…,v n} and the second random array is {y2, y2,…, y n};

[0035] The first vector is constructed according to the first random array: and the second vector is

[0036] For each row A in data access strategy A i , determine the first secret shard of s in data access policy A as:

[0037]

[0038] For each row A in data access strategy A i , determine the second secret shard of 0 in data access policy A as:

[0039]

[0040] According to the security interaction parameter, the first secret fragment and the second secret fragment, the interaction data is encrypted as follows:

[0041]

[0042] Among them, F represents the plain text of the data to be exchanged, C0 represents the cipher text of the data to be exchanged, and C 1,i Represents the first encryption parameter, C 2,i Represents the second encryption parameter, C 3,i Represents the third encryption parameter, C 4,i represents the fourth encryption parameter, α ρ(i) represents the second random number corresponding to the attribute manager ρ(i), ρ() represents the function that maps a row in the data access policy A to an attribute manager, t i Indicates that from Z p Randomly select the sixth random number, β ρ(i) represents the third random number corresponding to the attribute manager ρ(i), δ() represents the function that maps a row in the data access policy A to an attribute;

[0043] According to the ciphertext C0 of the data to be exchanged, the first encryption parameter C 1,i , the second encryption parameter C 2,i , the third encryption parameter C 3,i and the fourth encryption parameter C 4,i , determine the encrypted interaction data as CT=(C0,{C 1,i ,C 2,i ,C 3,i ,C 4,i} i∈[l] ).

[0044] In one possible implementation, after constructing the secret index corresponding to the encrypted interaction data, publishing the encrypted interaction data and the corresponding secret index to the blockchain includes:

[0045] The data owner extracts a set of keywords KW from the data to be interacted, which is {kw1, kw2, ..., kw d}; where d represents the total number of keywords;

[0046] From Z pRandomly select the seventh random number τ and the eighth random number τ1;

[0047] According to the seventh random number τ and the eighth random number τ1, the index component is constructed as follows:

[0048]

[0049] Where W1 represents the first index component, W2 represents the second index component, W3 represents the third index component, and W j Indicates the index parameter corresponding to the jth keyword; when the data owner is the financial end, z yy Represents the fourth random number z oid ; When the data owner is the business end, z yy Represents the fifth random number z uid ;

[0050] According to the first index component W1, the second index component W2, the third index component W3 and the index parameter W j , the secret index corresponding to the encrypted interaction data is constructed as:

[0051] I dx =(W1, W2, W3, {W j} j∈[d] )

[0052] Among them, I dx Indicates the secret index corresponding to the encrypted interaction data;

[0053] Determine an encrypted hash value of the encrypted interaction data, and jointly publish the encrypted interaction data, the encrypted hash value, and the corresponding secret index to the blockchain.

[0054] In one possible implementation, generating a search trapdoor by a data user includes:

[0055] The data user determines the keywords of interest as KW'={kw1', kw2',..., kw d ”}; where d' represents the total number of keywords of interest to data users;

[0056] From Z p Randomly select an eighth random number η;

[0057] According to the keyword of interest and the eighth random number η, the search component is generated as:

[0058]

[0059] Among them, T1 represents the first search component, T2 represents the second search component, and T3 represents the third search component. When the data user is the financial end, z syRepresents the fourth random number z oid ; When the data user is the business end, z sy Represents the fifth random number z uid ;kw j ' indicates the jth keyword of interest;

[0060] According to the first search component T1, the second search component T2 and the third search component T3, the search trapdoor is determined to be: Td = {T1, T2, T3}.

[0061] In one possible implementation, the search trapdoor is matched in the blockchain with a secret index corresponding to the search trapdoor, and the data search result is:

[0062] For all secret indices, determine whether the relationship between the secret index and the search trapdoor in the blockchain satisfies If so, the data search result is determined to be a search success, and the secret index that satisfies the relationship is used as the secret index corresponding to the search trapdoor; otherwise, the data search result is determined to be a search failure;

[0063] Among them, PK sy Indicates the public key corresponding to the data user.

[0064] In one possible implementation, when the data search result indicates a successful search, the data user is attribute-verified based on the security interaction parameter and the encrypted interaction data is obtained from the blockchain for semi-decryption to obtain the semi-decrypted data, including:

[0065] When the data search result is a successful search, determine whether the attribute corresponding to the data user meets the data access policy A. If so, determine that the attribute verification is successful, and obtain the encrypted interaction data from the blockchain for semi-decryption. Otherwise, determine that the attribute verification fails and end the data security interaction process;

[0066] Get the encrypted interaction data from the blockchain and semi-decrypt it according to the security interaction parameters:

[0067]

[0068]

[0069] Among them, tct i represents the first intermediate parameter, I represents the attribute set of the data user, sy represents the identity identifier of the data user, tct represents the second intermediate parameter, c i Represents the constant corresponding to the i-th attribute, V 1,i represents the first calculation parameter, and PK syRepresents the public key corresponding to the data user; V 2,i represents the second calculation parameter, and Indicates the first key parameter corresponding to the data user; V 3,i represents the third calculation parameter, V 4,i represents the fourth calculation parameter, Indicates the second key parameter corresponding to the data user;

[0070] According to the second intermediate parameter, the semi-decrypted data is determined to be:

[0071] SCT = {C0, tct}

[0072] Here, SCT represents semi-decrypted data.

[0073] In a possible implementation, according to the security interaction parameter, the data user decrypts the semi-decrypted data to obtain the plaintext data corresponding to the data to be interacted, which is:

[0074]

[0075] Among them, SK sy Indicates the private key corresponding to the data user.

[0076] The present invention provides a method for secure data interaction in business-finance collaboration, which encrypts the data between the business end and the financial end, thereby ensuring the security of the data during transmission, storage and use. Then, by using the attributes of the business end and the financial end as verification conditions, it can effectively prevent the data from being obtained and decrypted by illegal persons, greatly improving the security of the data during the interaction process. Finally, by generating a secret index, the data can be retrieved even in an encrypted state, further improving the security of data interaction, and solving the technical problem of low data security in the business-finance collaboration process. BRIEF DESCRIPTION OF THE DRAWINGS

[0077] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.

[0078] Figure 1 A flowchart of a method for secure business-finance collaborative data interaction provided by an embodiment of the present invention.

[0079] Figure 2 A schematic diagram of an application scenario provided by an embodiment of the present invention.

[0080] The above drawings illustrate specific embodiments of the present invention, which will be described in more detail below. These drawings and the accompanying description are not intended to limit the scope of the present invention in any way, but rather to illustrate the concept of the present invention to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION

[0081] Exemplary embodiments will be described in detail herein, examples of which are illustrated in the accompanying drawings. In the following description, when referring to the drawings, like numbers in different figures represent like or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all possible embodiments consistent with the present invention. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present invention, as detailed in the appended claims.

[0082] The embodiments of the present invention will be described in detail below with reference to the accompanying drawings.

[0083] like Figure 1 As shown, an embodiment of the present invention provides a method for secure data interaction between business and finance collaboration, including:

[0084] S101. Initialize security interaction parameters; wherein the security interaction parameters include system public parameters, a first key pair corresponding to the financial end, a second key pair corresponding to the business end, a blockchain transaction, and an attribute decryption key;

[0085] Initialization is performed through the secure interaction parameters in the entire application scenario, which facilitates subsequent encryption and decryption of data, thereby achieving secure interaction of business and financial collaborative data.

[0086] S102. Encrypting the interaction data by the data owner according to the security interaction parameter to obtain encrypted interaction data, constructing a secret index corresponding to the encrypted interaction data, and publishing the encrypted interaction data and the corresponding secret index to the blockchain;

[0087] The embodiment of the present invention can effectively improve the security of the data interaction process by encrypting the interaction data by the data owner, and at the same time construct a secret index corresponding to the encrypted interaction data, so that the data can be retrieved even in an encrypted state, so that the data is in a ciphertext state during transmission and retrieval, further improving the security of the data interaction process.

[0088] S103: Generate a search trapdoor by the data user, and match the secret index corresponding to the search trapdoor in the blockchain according to the search trapdoor to obtain a data search result; wherein the data search result indicates a search success or a search failure;

[0089] By generating a search trap by the data user, a match can be achieved with the secret index. If the match is successful, it can be determined that the corresponding data exists and the data can be decrypted according to the security interaction parameters. If the match fails, it can be determined that the corresponding data does not exist, and an empty message should be returned or the business-finance collaborative data security interaction process should be terminated directly.

[0090] S104. When the data search result indicates that the search is successful, the attribute of the data user is verified according to the security interaction parameter, and the encrypted interaction data is obtained from the blockchain and semi-decrypted to obtain semi-decrypted data;

[0091] By semi-decrypting the data in advance and then transmitting it to the data user for final decryption, not only can the security of the decryption parameters be effectively guaranteed, but the data processing pressure of the data user can also be effectively reduced, and the efficiency of data security interaction can be improved.

[0092] S105. After transmitting the semi-decrypted data to the data user, the data user decrypts the semi-decrypted data according to the security interaction parameter to obtain the plaintext data corresponding to the data to be interacted with, thereby achieving secure interaction of business-finance collaborative data.

[0093] Among them, when the data owner is the business end, the data user is the financial end; when the data owner is the financial end, the data user is the business end.

[0094] The present invention provides a method for secure data interaction in business-finance collaboration, which encrypts the data between the business end and the financial end, thereby ensuring the security of the data during transmission, storage and use. Then, by using the attributes of the business end and the financial end as verification conditions, it can effectively prevent the data from being obtained and decrypted by illegal persons, greatly improving the security of the data during the interaction process. Finally, by generating a secret index, the data can be retrieved even in an encrypted state, further improving the security of data interaction, and solving the technical problem of low data security in the business-finance collaboration process.

[0095] like Figure 2As shown, in order for those skilled in the art to better understand the technical solutions described in the embodiments of the present invention, the application scenarios involved in the present invention are introduced, which may include: attribute managers, cloud servers, data users, data owners, and blockchains; attribute managers, cloud servers, data users, and data owners can publish their own data on the blockchain or obtain data from the blockchain, and attribute managers are only accessed and controlled by cloud servers, thereby customizing attributes and access policies for data users and data owners. There can be multiple attribute managers to further manage attributes. A method for secure interaction of business and financial collaborative data described in an embodiment of the present invention can be run through a cloud server, thereby achieving secure interaction of data.

[0096] In a possible implementation, the method for initializing the system common parameters includes:

[0097] Randomly select the first multiplication cyclic group G and the second multiplication cyclic group G of order p as prime number T ;

[0098] Determine a generator g of the first multiplicative cyclic group G;

[0099] Define a bilinear map is: G×G→G T ;

[0100] Determines the mapping of any string to Z p A first hash function H in , a second hash function H0 that maps the identity identifier to the first multiplication cyclic group G, and a third hash function H3 that maps the attribute to the first multiplication cyclic group G; wherein Z p represents the nonnegative minimal simplified residue system modulo p;

[0101] From Z p Randomly select the first random number γ;

[0102] Scheduling attribute management from Z p Randomly select the second random number α aid and the third random number β aid ;

[0103] The scheduling attribute management party uses the second random number α aid and the third random number β aid , generate the attribute management key as: and SK aid ={α aid , β aid}; Among them, PK aid Indicates the public key corresponding to the attribute manager who manages the attribute, SK aid Indicates the private key corresponding to the attribute manager that manages the attribute;

[0104] According to the prime number p, the first multiplication cyclic group G, the second multiplication cyclic group G T , generator g, bilinear map First random number γ, first hash function H, second hash function H0, third hash function H3, non-negative minimum simplified remainder system Z p , the public key PK corresponding to the attribute manager aid and private key SK aid , get the system common parameters.

[0105] In one possible implementation, a method for initializing a first key pair corresponding to the financial end and a second key pair corresponding to the business end includes:

[0106] Scheduling financial end from Z p Randomly select the fourth random number z oid , and generating a first key pair according to the fourth random number: and SK oid =z oid Among them, PK oid Represents the public key in the first key pair, SK oid represents the private key in the first key pair;

[0107] Scheduling business end from Z p Randomly select the fifth random number z uid , and generating a first key pair according to the fourth random number: and SK uid =z uid Among them, PK uid Represents the public key in the second key pair, SK uid Represents the private key in the second key pair.

[0108] In one possible implementation, a method for initializing a blockchain transaction includes:

[0109] Determine the financial end's identity identifier oid and assign the first attribute set S to the financial end oid , the first blockchain transaction is generated as: {oid, S oid , Timetamp oid}; Among them, Timetamp oid Indicates the first timestamp;

[0110] Determine the business side's identity identifier uid and assign the second attribute set S to the financial side uid , generate the second blockchain transaction as: {uid, S uid , Timetamp uid}; Among them, Timetampuid Indicates the second timestamp;

[0111] In this embodiment, by setting the first timestamp and the second timestamp, the creation time of the first blockchain transaction and the second blockchain transaction can be determined. Therefore, an effective time can also be set. When the second timestamp exceeds the effective time, it can be deemed invalid and the attributes should be reallocated, thereby dynamically performing data security protection, thereby further improving the security of data interaction.

[0112] Initialization method for attribute decryption key, including:

[0113] Determine the target attribute set S mb ; Among them, the target attribute set S mb Set as the first attribute set S oid Or the second attribute set S uid ;

[0114] Get the target attribute set S mb The corresponding first key parameter and second key parameter are:

[0115]

[0116] in, represents the first key parameter, Represents the second key parameter, t represents the value from Z p The sixth random number randomly selected from the mb Represents the fourth random number z oid or the fifth random number z uid , mb represents the financial side's identity identifier oid or the business side's identity identifier uid, att i Represents the target attribute set S mb The i-th attribute in ;

[0117] According to the first key parameter and the second key parameter, the attribute decryption key is determined to be:

[0118] In a possible implementation, the data owner encrypts the interaction data according to the security interaction parameter to obtain the encrypted interaction data, including:

[0119] According to the non-negative minimum simplified residual coefficient Z in the safe interaction parameter p , define a data access strategy as A; where A represents the non-negative minimum simplified residual system Z p Where is a matrix with l rows and n columns;

[0120] Through the data owner in Z pThe first random array is randomly selected as {s,v2,…,v n} and the second random array is {y2, y2,…, y n};

[0121] The first vector is constructed according to the first random array: and the second vector is

[0122] For each row A in data access strategy A i , determine the first secret shard of s in data access policy A as:

[0123]

[0124] For each row A in data access strategy A i , determine the second secret shard of 0 in data access policy A as:

[0125]

[0126] According to the security interaction parameter, the first secret fragment and the second secret fragment, the interaction data is encrypted as follows:

[0127]

[0128] Among them, F represents the plain text of the data to be exchanged, C0 represents the cipher text of the data to be exchanged, and C 1,i Represents the first encryption parameter, C 2,i Represents the second encryption parameter, C 3,i Represents the third encryption parameter, C 4,i represents the fourth encryption parameter, α ρ(i) represents the second random number corresponding to the attribute manager ρ(i), ρ() represents the function that maps a row in the data access policy A to an attribute manager, t i Indicates that from Z p Randomly select the sixth random number, β ρ(i) represents the third random number corresponding to the attribute manager ρ(i), δ() represents the function that maps a row in the data access policy A to an attribute;

[0129] According to the ciphertext C0 of the data to be exchanged, the first encryption parameter C 1,i , the second encryption parameter C 2,i , the third encryption parameter C 3,i and the fourth encryption parameter C 4,i , determine the encrypted interaction data as CT=(C0,{C 1,i ,C 2,i ,C 3,i ,C4,i} i∈[l] ).

[0130] This embodiment encrypts the interaction data and uploads it to the blockchain to facilitate data acquisition by all parties while preventing data tampering, thereby effectively improving the security of data during the interaction process.

[0131] In one possible implementation, after constructing the secret index corresponding to the encrypted interaction data, publishing the encrypted interaction data and the corresponding secret index to the blockchain includes:

[0132] The data owner extracts a set of keywords KW from the data to be interacted, which is {kw1, kw2, ..., kw d}; where d represents the total number of keywords;

[0133] From Z p Randomly select the seventh random number τ and the eighth random number τ1;

[0134] According to the seventh random number τ and the eighth random number τ1, the index component is constructed as follows:

[0135]

[0136] Where W1 represents the first index component, W2 represents the second index component, W3 represents the third index component, and W j Indicates the index parameter corresponding to the jth keyword; when the data owner is the financial end, z yy Represents the fourth random number z oid ; When the data owner is the business end, z yy Represents the fifth random number z uid ;

[0137] According to the first index component W1, the second index component W2, the third index component W3 and the index parameter W j , the secret index corresponding to the encrypted interaction data is constructed as:

[0138] I dx =(W1, W2, W3, {W j} j∈[d] )

[0139] Among them, I dx Indicates the secret index corresponding to the encrypted interaction data;

[0140] Determine an encrypted hash value of the encrypted interaction data, and jointly publish the encrypted interaction data, the encrypted hash value, and the corresponding secret index to the blockchain.

[0141] The present invention facilitates tamper-proof verification of encrypted interaction data by constructing an encrypted hash value, making it easier to find the corresponding data. By establishing a secret search, data can be retrieved even in an encrypted state. From the moment the data is encrypted and uploaded, it is guaranteed to be tamper-proof and unreachable, greatly improving the security of data interaction.

[0142] In one possible implementation, generating a search trapdoor by a data user includes:

[0143] The data user determines the keywords of interest as KW'={kw1', kw2',..., kw d ”}; where d' represents the total number of keywords of interest to data users;

[0144] From Z p Randomly select an eighth random number η;

[0145] According to the keyword of interest and the eighth random number η, the search component is generated as:

[0146]

[0147] Among them, T1 represents the first search component, T2 represents the second search component, and T3 represents the third search component. When the data user is the financial end, z sy Represents the fourth random number z oid ; When the data user is the business end, z sy Represents the fifth random number z uid ;kw j ' indicates the jth keyword of interest;

[0148] According to the first search component T1, the second search component T2 and the third search component T3, the search trapdoor is determined to be: Td = {T1, T2, T3}.

[0149] In one possible implementation, the search trapdoor is matched in the blockchain with a secret index corresponding to the search trapdoor, and the data search result is:

[0150] For all secret indices, determine whether the relationship between the secret index and the search trapdoor in the blockchain satisfies If so, the data search result is determined to be a search success, and the secret index that satisfies the relationship is used as the secret index corresponding to the search trapdoor; otherwise, the data search result is determined to be a search failure;

[0151] Among them, PK sy Indicates the public key corresponding to the data user.

[0152] In one possible implementation, when the data search result indicates a successful search, the data user is attribute-verified based on the security interaction parameter and the encrypted interaction data is obtained from the blockchain for semi-decryption to obtain the semi-decrypted data, including:

[0153] When the data search result is a successful search, determine whether the attribute corresponding to the data user meets the data access policy A. If so, determine that the attribute verification is successful, and obtain the encrypted interaction data from the blockchain for semi-decryption. Otherwise, determine that the attribute verification fails and end the data security interaction process;

[0154] Get the encrypted interaction data from the blockchain and semi-decrypt it according to the security interaction parameters:

[0155]

[0156] Among them, tct i represents the first intermediate parameter, I represents the attribute set of the data user, sy represents the identity identifier of the data user, tct represents the second intermediate parameter, c i Represents the constant corresponding to the i-th attribute, V 1,i represents the first calculation parameter, and PK sy Represents the public key corresponding to the data user; V 2,i represents the second calculation parameter, and Indicates the first key parameter corresponding to the data user; V 3,i represents the third calculation parameter, V 4,i represents the fourth calculation parameter, Indicates the second key parameter corresponding to the data user;

[0157] According to the second intermediate parameter, the semi-decrypted data is determined to be:

[0158] SCT = {C0, tct}

[0159] Here, SCT represents semi-decrypted data.

[0160] By semi-decrypting the data in advance and then transmitting it to the data user for final decryption, not only can the security of the decryption parameters be effectively guaranteed, but the data processing pressure of the data user can also be effectively reduced, and the efficiency of data security interaction can be improved.

[0161] In a possible implementation, according to the security interaction parameter, the data user decrypts the semi-decrypted data to obtain the plaintext data corresponding to the data to be interacted, which is:

[0162]

[0163] Among them, SK sy Indicates the private key corresponding to the data user.

[0164] From the above operation process, it can be found that data users only need to perform simple calculations, which can effectively improve the efficiency of data decryption and reduce the computing performance requirements for data users.

[0165] It will be understood by those skilled in the art that the embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code. The solutions in the embodiments of the present invention may be implemented in various computer languages, for example, the object-oriented programming language Java and the interpreted scripting language JavaScript.

[0166] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0167] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0168] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps for the function specified in one or more boxes.

[0169] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.

[0170] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.

Claims

1. A method for secure data interaction between business and finance, characterized in that: include: Initialize security interaction parameters; wherein, the security interaction parameters include system public parameters, the first key pair corresponding to the financial end, the second key pair corresponding to the business end, blockchain transactions, and attribute decryption keys; According to the security interaction parameters, the data owner encrypts the interaction data to obtain the encrypted interaction data, constructs the secret index corresponding to the encrypted interaction data, and then publishes the encrypted interaction data and the corresponding secret index to the blockchain; A data user generates a search trapdoor, and matches the secret index corresponding to the search trapdoor in the blockchain according to the search trapdoor to obtain a data search result; wherein the data search result indicates a search success or a search failure; When the data search result is a successful search, the data user is attribute-verified according to the security interaction parameter and the encrypted interaction data is obtained from the blockchain for semi-decryption to obtain semi-decrypted data; After the semi-decrypted data is transmitted to the data user, the semi-decrypted data is decrypted by the data user according to the security interaction parameters to obtain the plaintext data corresponding to the data to be interacted with, thereby realizing the secure interaction of business and financial collaborative data; Among them, when the data owner is the business end, the data user is the financial end; when the data owner is the financial end, the data user is the business end.

2. The method for secure business-finance collaborative data interaction according to claim 1, characterized in that: The method for initializing the common parameters of the system includes: Randomly select the first multiplication cyclic group G and the second multiplication cyclic group G of order p as prime number T ; Determine a generator g of the first multiplicative cyclic group G; Define a bilinear map is: G×G→G T ; Determines the mapping of any string to Z p A first hash function H in , a second hash function H0 that maps the identity identifier to the first multiplication cyclic group G, and a third hash function H3 that maps the attribute to the first multiplication cyclic group G; wherein Z p represents the nonnegative minimal simplified residue system modulo p; From Z p Randomly select the first random number γ; Scheduling attribute management from Z p Randomly select the second random number α aid and the third random number β aid ; The scheduling attribute management party uses the second random number α aid and the third random number β aid , generate the attribute management key as: and SK aid ={α aid , β aid }; Among them, PK aid Indicates the public key corresponding to the attribute manager who manages the attribute, SK aid Indicates the private key corresponding to the attribute manager that manages the attribute; According to the prime number p, the first multiplication cyclic group G, the second multiplication cyclic group G T , generator g, bilinear map First random number γ, first hash function H, second hash function H0, third hash function H3, non-negative minimum simplified remainder system Z p , the public key PK corresponding to the attribute manager aid and private key SK aid , get the system common parameters.

3. The method for secure business-finance collaborative data interaction according to claim 2, characterized in that: The method for initializing the first key pair corresponding to the financial end and the second key pair corresponding to the business end includes: Scheduling financial end from Z p Randomly select the fourth random number z oid , and generating a first key pair according to the fourth random number: and SK oid =z oid Among them, PK oid Represents the public key in the first key pair, SK oid represents the private key in the first key pair; Scheduling business end from Z p Randomly select the fifth random number z uid , and generating a first key pair according to the fourth random number: and SK uid =z uid Among them, PK uid Represents the public key in the second key pair, SK uid Represents the private key in the second key pair.

4. The method for secure business-finance collaborative data interaction according to claim 3 is characterized in that: The initialization method of blockchain transactions includes: Determine the financial end's identity identifier oid and assign the first attribute set S to the financial end oid , the first blockchain transaction is generated as: {oid, S oid , Timetamp oid }; Among them, Timetamp oid Indicates the first timestamp; Determine the business side's identity identifier uid and assign the second attribute set S to the financial side uid , generate the second blockchain transaction as: {uid, S uid , Timetamp uid }; Among them, Timetamp uid Indicates the second timestamp; Initialization method for attribute decryption key, including: Determine the target attribute set S mb ; Among them, the target attribute set S mb Set as the first attribute set S oid Or the second attribute set S uid ; Get the target attribute set S mb The corresponding first key parameter and second key parameter are: in, represents the first key parameter, Represents the second key parameter, t represents the value from Z p The sixth random number randomly selected from the mb Represents the fourth random number z oid or the fifth random number z uid , mb represents the financial side's identity identifier oid or the business side's identity identifier uid, att i Represents the target attribute set S mb The i-th attribute in ; According to the first key parameter and the second key parameter, the attribute decryption key is determined to be:

5. The method for secure business-finance collaborative data interaction according to claim 4 is characterized in that: According to the security interaction parameters, the data owner encrypts the interaction data to obtain encrypted interaction data, including: According to the non-negative minimum simplified residual coefficient Z in the safe interaction parameter p , define a data access strategy as A; where A represents the non-negative minimum simplified residual system Z p Where is a matrix with l rows and n columns; Through the data owner in Z p The first random array is randomly selected as {s,v2,…,v n } and the second random array is {y2, y2,…, y n }; The first vector is constructed according to the first random array: and the second vector is For each row A in data access strategy A i , determine the first secret shard of s in data access policy A as: For each row A in data access strategy A i , determine the second secret shard of 0 in data access policy A as: According to the security interaction parameter, the first secret fragment and the second secret fragment, the interaction data is encrypted as follows: Among them, F represents the plain text of the data to be exchanged, C0 represents the cipher text of the data to be exchanged, and C 1,i Represents the first encryption parameter, C 2,i Represents the second encryption parameter, C 3,i Represents the third encryption parameter, C 4,i represents the fourth encryption parameter, α ρ(i) represents the second random number corresponding to the attribute manager ρ(i), ρ() represents the function that maps a row in the data access policy A to an attribute manager, t i Indicates that from Z p Randomly select the sixth random number, β ρ(i) represents the third random number corresponding to the attribute manager ρ(i), δ() represents the function that maps a row in the data access policy A to an attribute; According to the ciphertext C0 of the data to be exchanged, the first encryption parameter C 1,i , the second encryption parameter C 2,i , the third encryption parameter C 3,i and the fourth encryption parameter C 4,i , determine the encrypted interaction data as CT=(C0,{C 1,i ,C 2,i ,C 3,i ,C 4,i } i∈[l] ).

6. The method for secure business-finance collaborative data interaction according to claim 5, characterized in that: After constructing the secret index corresponding to the encrypted interaction data, the encrypted interaction data and the corresponding secret index are published to the blockchain, including: The data owner extracts a set of keywords KW from the data to be interacted, which is {kw1, kw2, ..., kw d }; where d represents the total number of keywords; From Z p Randomly select the seventh random number τ and the eighth random number τ1; According to the seventh random number τ and the eighth random number τ1, the index component is constructed as follows: Where W1 represents the first index component, W2 represents the second index component, W3 represents the third index component, and W j Indicates the index parameter corresponding to the jth keyword; when the data owner is the financial end, z yy Represents the fourth random number z oid ; When the data owner is the business end, z yy Represents the fifth random number z uid ; According to the first index component W1, the second index component W2, the third index component W3 and the index parameter W j , the secret index corresponding to the encrypted interaction data is constructed as: I dx =(W1,W2,W3,{W j } j∈[d] ) Among them, I dx Indicates the secret index corresponding to the encrypted interaction data; Determine an encrypted hash value of the encrypted interaction data, and jointly publish the encrypted interaction data, the encrypted hash value, and the corresponding secret index to the blockchain.

7. The method for secure business-finance collaborative data interaction according to claim 6, characterized in that: Generate search trapdoors through data users, including: The data user determines the keywords of interest as KW'={kw1', kw2',..., kw d' '}; where d' represents the total number of keywords of interest to data users; From Z p Randomly select an eighth random number η; According to the keyword of interest and the eighth random number η, the search component is generated as: Among them, T1 represents the first search component, T2 represents the second search component, and T3 represents the third search component. When the data user is the financial end, z sy Represents the fourth random number z oid ; When the data user is the business end, z sy Represents the fifth random number z uid ;kw j ' indicates the jth keyword of interest; According to the first search component T1, the second search component T2 and the third search component T3, the search trapdoor is determined to be: Td = {T1, T2, T3}.

8. The method for secure business-finance collaborative data interaction according to claim 7, characterized in that: According to the search trapdoor, the secret index corresponding to the search trapdoor is matched in the blockchain, and the data search result is obtained as follows: For all secret indices, determine whether the relationship between the secret index and the search trapdoor in the blockchain satisfies If so, the data search result is determined to be a search success, and the secret index that satisfies the relationship is used as the secret index corresponding to the search trapdoor; otherwise, the data search result is determined to be a search failure; Among them, PK sy Indicates the public key corresponding to the data user.

9. The method for secure business-finance collaborative data interaction according to claim 8, characterized in that: When the data search result is a successful search, the data user is attribute-verified according to the security interaction parameters and the encrypted interaction data is obtained from the blockchain for semi-decryption to obtain semi-decrypted data, including: When the data search result is a successful search, determine whether the attribute corresponding to the data user meets the data access policy A. If so, determine that the attribute verification is successful, and obtain the encrypted interaction data from the blockchain for semi-decryption. Otherwise, determine that the attribute verification fails and end the data security interaction process; Get the encrypted interaction data from the blockchain and semi-decrypt it according to the security interaction parameters: Among them, tct i represents the first intermediate parameter, I represents the attribute set of the data user, sy represents the identity identifier of the data user, tct represents the second intermediate parameter, c i Represents the constant corresponding to the i-th attribute, V 1,i represents the first calculation parameter, and PK sy Represents the public key corresponding to the data user; V 2,i represents the second calculation parameter, and Indicates the first key parameter corresponding to the data user; V 3,i represents the third calculation parameter, V 4,i represents the fourth calculation parameter, Indicates the second key parameter corresponding to the data user; According to the second intermediate parameter, the semi-decrypted data is determined to be: SCT = {C0, tct} Here, SCT represents semi-decrypted data.

10. The method for secure business-finance collaborative data interaction according to claim 9, characterized in that: According to the security interaction parameters, the semi-decrypted data is decrypted by the data user to obtain the plaintext data corresponding to the data to be interacted, which is: Among them, SK sy Indicates the private key corresponding to the data user.

Citation Information

Patent Citations

  • Ciphertext data sharing method and system based on collaborative searchable

    CN115694974A

  • Internet of Things data sharing method for block chain assisted search

    CN117494221A

  • Anti-framing searchable Internet of Things data sharing method and system

    CN117640255A

  • Fund security risk monitoring system

    CN118446823A

  • Block chain-based business and financial data interaction management system and method

    CN119441357A