Management system data privacy protection method and system based on homomorphic encryption

By combining homomorphic encryption technology and identity authentication protocol with the K-means algorithm, the security issue of data privacy protection in the power grid digital management system is solved, ensuring the privacy and security of data during uploading and processing.

CN120654244APending Publication Date: 2025-09-16CHINA ELECTRIC POWER RESEARCH INSTITUTE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410290627.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-03-14
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

Existing data privacy protection methods are fragile and vulnerable to attacks, and their reliance on untrusted third parties leads to low reliability, making the power grid digital management system vulnerable to privacy leaks when uploading data.

Method used

Homomorphic encryption technology is combined with identity authentication protocol and K-means algorithm to ensure data privacy and security through client data entry, application layer identity authentication and cleaning, and server-side data analysis and processing.

Benefits of technology

It realizes the authenticity of client and server identity authentication, removes abnormal data, ensures the confidentiality of data calculation process, and avoids data privacy leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120654244A_ABST
    Figure CN120654244A_ABST
Patent Text Reader

Abstract

The invention discloses a management system data privacy protection method and system based on homomorphic encryption. The method comprises the steps that a client performs data information input; the application layer uses an identity authentication protocol to perform identity authentication on the client access server and cleans the data information after successful authentication to obtain the cleaned data information; the server analyzes and processes the cleaned data information by using a homomorphic encryption technology to obtain a data analysis result and returns the data analysis result to the client; the identity authentication of the client and the server is carried out based on the identity authentication protocol, and the authenticity of the identities of the two communication parties can be ensured; abnormal data can be removed through data cleaning, and the availability of the data is improved; the homomorphic encryption technology can ensure the confidentiality of the data operation process and avoid data privacy leakage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of system data privacy protection, and in particular to a management system data privacy protection method and system based on homomorphic encryption. Background Art

[0002] With the digitalization of power grid services and the implementation of the company's digital transformation strategy, some business processes in areas such as digital services, key task management, and daily work management are still managed manually offline, resulting in low management efficiency and an urgent need to enhance departmental lean management capabilities. To effectively implement the State Grid Corporation's digital transformation strategy, guided by the needs of frontline users and leveraging information and digital technologies, a lean management module was established based on the human resources management system and digital business dispatch cloud. This module will enhance the company's digital and lean management capabilities and promote management and business upgrades.

[0003] While people enjoy the convenience of lean management systems, the massive amounts of user data contained therein also face the risk of privacy leaks. Therefore, the utilization of homomorphic encryption technology is particularly important. Homomorphic encryption is a cryptographic method primarily used in cloud data processing. Compared to traditional encryption methods, it not only performs basic encryption operations but also allows for direct computation on ciphertext. This means that encrypting data and then performing computations on it produces the same result as first performing computations and then decrypting it. This feature is crucial for protecting data privacy and security.

[0004] Existing data privacy protection methods have two shortcomings:

[0005] (1) Most existing data privacy protection methods are based on linear transformation. Although they are simple and efficient, the security of their linear transformation process is fragile and can be easily attacked.

[0006] (2) Most existing solutions are based on a trusted third party, but there is no guarantee that the third party is completely trustworthy. Therefore, they face multiple security threats and have low reliability.

[0007] With the digital transformation and upgrade of the power grid, the emergence of lean management systems has addressed issues such as low management efficiency and a lack of convenient query windows for process flow. This has improved staff efficiency in handling transactions and promoted company management and business upgrades. However, due to business needs, lean management systems collect a large amount of sensitive user information. When the system uploads this data to the server for processing and analysis, an attack could easily lead to data privacy leaks, causing problems for users and the company's business. Summary of the Invention

[0008] In order to solve the problem in the prior art that when system data is uploaded to the server for processing and analysis, it is very easy to cause data privacy leakage due to attacks, the present invention proposes a management system data privacy protection method based on homomorphic encryption, including:

[0009] The client enters data information;

[0010] The application layer uses the identity authentication protocol to authenticate the client access to the server and cleans the data information after the authentication is successful to obtain the cleansed data information;

[0011] The server uses homomorphic encryption technology to analyze and process the cleaned data information, obtains data analysis results and returns them to the client.

[0012] Preferably, the application layer uses an identity authentication protocol to authenticate the client access to the server and cleans the data information after the authentication is successful, to obtain the cleansed data information, including:

[0013] The application layer uses the identity authentication protocol to authenticate the client access to the server;

[0014] The application layer uses the K-means algorithm to clean the data information to remove abnormal data and obtain cleaned data information.

[0015] Preferably, the application layer uses an identity authentication protocol to authenticate the client access to the server, specifically including:

[0016] After receiving the first request from the client, the authentication center performs authentication based on whether the client name and client IP exist in the database. If not, the authentication fails; otherwise, the authentication succeeds and returns the first response information to the client.

[0017] The client decrypts the first response information in combination with the client key to obtain the first timestamp, TGS related information and the key CTGS_SK, and compares the first timestamp with the time interval. If the time interval is greater than the set time, the authentication fails; otherwise, the authentication succeeds and the client sends a second request to the TGS.

[0018] After receiving the second request, the TGS verifies whether the server IP exists in the database. If not, the authentication fails. Otherwise, the authentication succeeds and the encrypted GT is decrypted to obtain the second timestamp.

[0019] The TGS compares the second timestamp with the communication time interval. If it is greater than the set time, the authentication fails. Otherwise, the TGS decrypts the first response message using the key CTGS_SK and compares it with the client information in the GT before sending the second response message to the client.

[0020] The client receives the second response information and decrypts it using the key CTGS_SK to obtain a third timestamp and compares it with the time interval. If it is greater than the set time, the authentication fails; otherwise, the client extracts the key CS_SK and sends a third request to the server.

[0021] After receiving the third request, the server decrypts the obtained fourth timestamp and compares it with the time interval. If it is greater than the set time, the authentication fails. Otherwise, the server uses the key CS_SK to obtain the authenticated client information and compares it with the client information in ST. After the comparison is successful, the server sends a third response message to the client.

[0022] Among them, the application layer includes: authorization and authentication center, database, and TGS.

[0023] Preferably, the application layer uses a K-means algorithm to clean the data information to remove abnormal data, and obtains cleaned data information, including:

[0024] The application layer randomly selects part of the data as the initial cluster center based on the data information;

[0025] The application layer calculates the Euclidean distance of the remaining data to the initial cluster center based on the initial cluster center, and performs clustering to obtain a clustered set;

[0026] The application layer calculates the sample mean based on the clustered set, selects a new cluster center for clustering, and deletes abnormal data to obtain cleaned data information.

[0027] Preferably, the server uses homomorphic encryption technology to analyze and process the cleaned data information, obtains data analysis results and returns them to the client, including:

[0028] The server generates public and private keys based on the key generation function;

[0029] The server encrypts the plaintext data based on the public key combined with the encryption function to obtain ciphertext data;

[0030] The server decrypts the ciphertext data based on the private key in combination with the decryption function, obtains the plaintext data and returns it to the client.

[0031] Based on the same inventive concept, the present invention also proposes a management system data privacy protection system based on homomorphic encryption, comprising:

[0032] Client, used for data information entry;

[0033] The application layer is used to authenticate the client access to the server using the identity authentication protocol and clean the data information after successful authentication to obtain the cleaned data information;

[0034] The server is used to analyze and process the cleaned data information using homomorphic encryption technology, obtain data analysis results and return them to the client.

[0035] Preferably, the application layer includes:

[0036] The identity authentication submodule is used to authenticate the client access to the server using the identity authentication protocol;

[0037] The data cleaning submodule is used to clean the data information by using the K-means algorithm to remove abnormal data and obtain cleaned data information.

[0038] Preferably, the identity authentication submodule is specifically used to:

[0039] After receiving the first request from the client, the authentication center performs authentication based on whether the client name and client IP exist in the database. If not, the authentication fails; otherwise, the authentication succeeds and returns the first response information to the client.

[0040] The client decrypts the first response information in combination with the client key to obtain the first timestamp, TGS related information and the key CTGS_SK, and compares the first timestamp with the time interval. If the time interval is greater than the set time, the authentication fails; otherwise, the authentication succeeds and the client sends a second request to the TGS.

[0041] After receiving the second request, the TGS verifies whether the server IP exists in the database. If not, the authentication fails. Otherwise, the authentication succeeds and the encrypted GT is decrypted to obtain the second timestamp.

[0042] The TGS compares the second timestamp with the communication time interval. If it is greater than the set time, the authentication fails. Otherwise, the TGS decrypts the first response message using the key CTGS_SK and compares it with the client information in the GT before sending the second response message to the client.

[0043] The client receives the second response information and decrypts it using the key CTGS_SK to obtain a third timestamp and compares it with the time interval. If it is greater than the set time, the authentication fails; otherwise, the client extracts the key CS_SK and sends a third request to the server.

[0044] After receiving the third request, the server decrypts the obtained fourth timestamp and compares it with the time interval. If it is greater than the set time, the authentication fails. Otherwise, the server uses the key CS_SK to obtain the authenticated client information and compares it with the client information in ST. After the comparison is successful, the server sends a third response message to the client.

[0045] Among them, the application layer includes: authorization and authentication center, database, and TGS.

[0046] Preferably, the data cleaning submodule is specifically used to:

[0047] Randomly selecting part of the data as initial cluster centers based on the data information;

[0048] Calculating the Euclidean distance between the remaining data and the initial cluster center based on the initial cluster center, and performing clustering to obtain a clustered set;

[0049] The sample mean is calculated based on the clustered set, a new cluster center is selected for clustering, and abnormal data is deleted to obtain cleaned data information.

[0050] Preferably, the server is specifically used to:

[0051] Generate public key and private key according to the key generation function;

[0052] Encrypting the plaintext data based on the public key in combination with the encryption function to obtain ciphertext data;

[0053] The ciphertext data is decrypted based on the private key in combination with a decryption function to obtain the plaintext data and return it to the client.

[0054] Compared with the prior art, the present invention has the following beneficial effects:

[0055] A data privacy protection method and system for a management system based on homomorphic encryption, comprising: a client entering data information; an application layer authenticating the client's access to a server using an identity authentication protocol and cleaning the data information after successful authentication to obtain cleansed data information; the server analyzing and processing the cleansed data information using homomorphic encryption technology to obtain data analysis results and return them to the client; the present invention performs identity authentication on the client and server based on the identity authentication protocol, thereby ensuring the authenticity of the identities of both communicating parties; data cleaning can remove abnormal data and improve data availability; homomorphic encryption technology can ensure the confidentiality of the data operation process and avoid data privacy leakage. BRIEF DESCRIPTION OF THE DRAWINGS

[0056] Figure 1 This is a flow chart of a data privacy protection method for a management system based on homomorphic encryption according to the present invention;

[0057] Figure 2 This is a privacy protection model diagram of the present invention;

[0058] Figure 3 This is the identity authentication flow chart of the present invention;

[0059] Figure 4This is a data cleaning flow chart of the present invention. DETAILED DESCRIPTION

[0060] The present invention application proposes a data privacy protection method for a management system based on homomorphic encryption, constructs a three-layer architecture of "client-application layer-server", and proposes an identity authentication protocol based on this architecture to complete the identity authentication between the client and the server; then, the data information is cleaned based on an improved algorithm based on k-means at the application layer; finally, based on homomorphic encryption technology, the data that needs to be analyzed and processed in the system is encrypted and analyzed at the server, and the results are returned to the client after processing; in order to better understand the present invention, the contents of the present invention are further explained below in conjunction with the drawings and embodiments of the specification.

[0061] Example 1:

[0062] A data privacy protection method for management systems based on homomorphic encryption. The specific process is as follows: Figure 1 As shown, including:

[0063] Step 1: The client enters data information;

[0064] Step 2: The application layer uses an identity authentication protocol to authenticate the client access to the server and cleans the data information after the authentication is successful to obtain cleansed data information;

[0065] In step 3, the server uses homomorphic encryption technology to analyze and process the cleaned data information, obtains the data analysis results and returns them to the client.

[0066] This embodiment builds a three-tier architecture of "client-application layer-server", where the client enters data information, the application layer cleans the data and completes the identity authentication between the client and the server, and the server analyzes and processes the data; Figure 2 This embodiment is described in detail.

[0067] In step 1, the client enters data information, including:

[0068] Data information is entered based on the client.

[0069] In step 2, the application layer uses the identity authentication protocol to authenticate the client access to the server and cleans the data information after the authentication is successful to obtain the cleansed data information, specifically including:

[0070] When the client applies to access the server, in order to avoid data privacy leakage caused by false device access, an identity authentication protocol is proposed. The identity authentication process is as follows: Figure 3 As shown:

[0071] (1) The client initiates the first request to the authentication center of the application layer in plain text. The request contains: client name, client IP and current timestamp.

[0072] After receiving the first request from the client, the authentication center searches the application layer database for relevant information to determine whether the client exists. If not, authentication fails and the service ends. If relevant information about the client exists, the authentication center returns a first response to the client. This response consists of two parts:

[0073] The first part is called the Token Grant Ticket (GT), which contains: the validity period of the GT, the client name, the client IP address, the current timestamp, the name of the Token Grant Service (TGS) to be accessed, and the key CTGS_SK (Client Ticket Grant Service_Session Key) used for communication between the client and TGS. The entire GT is encrypted with the TGS key and cannot be decrypted by the client.

[0074] The second part is encrypted with the client's key and contains: the GT's validity period, the current timestamp, the name of the TGS to be accessed, and the communication key CTGS_SK between the client and the TGS. This part is encrypted with the client's key, and since the fake client does not have this key, the client's identity can be authenticated.

[0075] (2) The client uses its own key to decrypt the second part of the content in (1) and obtain the timestamp, information about the TGS to be accessed, and the key CTGS_SK used to communicate with the TGS. First, based on the timestamp obtained from decrypting the second part of the content, it determines whether the time interval between the client and the request it sent is greater than 3 minutes. If so, the authentication fails; otherwise, the client prepares to send a second request to the TGS.

[0076] The client further sends a request to TGS. The request information mainly includes two parts: the first part is the client name, client IP, and current timestamp encrypted with the key CTGS_SK; the second part is the server IP and GT to be accessed.

[0077] After receiving the second request from the client, TGS first searches the database for the server's IP address to see if the server exists. If not, the authentication fails and the service ends. If the authentication succeeds, TGS decrypts the encrypted GT with its own key and determines whether the communication time interval exceeds 3 minutes based on the timestamp obtained. If not, TGS decrypts the first part of the information mentioned above using CTGS_SK and compares it with the client information in the GT. If all are the same, the client identity is considered correct.

[0078] At this point, TGS returns a second response message to the client, which contains two parts:

[0079] The first part is the service token ST (Service Ticket) required by the client to access the server. The ST has been encrypted with the server key. The ST information includes: client name, client IP, server IP to be accessed, ST validity period, timestamp, and the key CS_SK (Client Service Session Key) used for communication between the client and the server.

[0080] The second part contains: CS_SK, timestamp and ST validity period, which is encrypted using CTGS_SK.

[0081] (3) The client receives the second response from the TGS and decrypts the second part of the content mentioned above using the locally cached CTGS_SK. It then determines whether the time interval between the timestamp and the request is more than three minutes. If it is more than three minutes, the authentication fails and the service ends. If it is less than three minutes, the client extracts the CS_SK and prepares to send a third request to the server:

[0082] The third request sent by the client to the server contains two parts: the first part is the client name, client IP and timestamp; the second part is ST.

[0083] After receiving the third request, the server uses its own key to decrypt ST and checks the timestamp to determine whether the time interval exceeds 3 minutes. If it exceeds 3 minutes, the authentication fails and the service ends. Otherwise, it takes out CS_SK and uses CS_SK to decrypt the first part of the content mentioned in step (3), thereby obtaining the client information after GT authentication. At this time, this part of information is compared with the second part of information mentioned in step (3). If the two information are consistent, it is finally confirmed that the client identity is correct.

[0084] Subsequently, the server returns a third response message encrypted with the CTGS_Sk key to the client. After the client decrypts it using the locally cached CTGS_Sk key, it can also confirm the identity of the server, and the two can then communicate over the network.

[0085] After the identity authentication is passed, the client sends the data to be analyzed and processed to the database of the application layer, and performs data cleaning based on the improved K-means algorithm to remove abnormal data. The data cleaning process is as follows: Figure 4 As shown:

[0086] S1: Randomly select some data as the initial cluster center;

[0087] S2: For the initialized cluster center, calculate the Euclidean distance of all remaining data to each center, and then classify them into the cluster with the closest cluster;

[0088] S3: Calculate the mean of the samples in each cluster after clustering as the center of the new cluster;

[0089] S4: Then repeat steps (2) and (3) until the clustering result no longer changes;

[0090] S5: At this point, the isolated points, that is, the abnormal data, are deleted, and the entire clustering process, that is, the data cleaning process, is completed.

[0091] In step 3, the server uses homomorphic encryption technology to analyze and process the cleaned data information, obtains data analysis results and returns them to the client, specifically including:

[0092] After data cleaning is completed, the data is sent to the server for data analysis and processing. Here, the data is encrypted based on homomorphic encryption technology. The processing process is as follows:

[0093] (1) Key generation: KeyGen()→(pk,sk)

[0094] Randomly select two prime numbers p and q, and satisfy gcd(pq, (p-1)(q-1)) = 1;

[0095] Calculate n = pq, λ = lcm(p-1,q-1), and define the decryption function

[0096] Randomly select a positive integer g <n 2 , and calculate μ=(L(g λ mod n 2 )) -1 mod n;

[0097] The public key pk is (n, g); the private key sk is (λ, μ).

[0098] Among them, KeyGen() is the key generation function, pk is the public key, sk is the private key, gcd() is the function that returns the greatest common divisor, lcm() is the function that returns the least common multiple, and L() is the decryption function.

[0099] (2) Encryption: Enc(pk,m)→c

[0100] Randomly select an integer r that satisfies 0 <r<n, That is, r in n 2 There exists a multiplicative inverse under the residue system of , and a sufficient condition is that r and n are relatively prime;

[0101] Calculate the ciphertext c=g m r n mod n 2 .

[0102] Among them, Enc() is the encryption function, pk is the public key, m is the plaintext data, c is the ciphertext data, Z represents an integer, and the subscript represents the number of elements in the integer set.

[0103] After encryption is completed, the data is analyzed and processed according to the calculation requirements, and the encrypted results are decrypted after processing. The decryption steps are as follows:

[0104] Decryption: Dec(sk,c)→m

[0105] Calculate the plaintext m=L(c λ mod n 2 )*μmod n.

[0106] Where Dec() is the decryption function, sk is the private key generated by the key generation function KeyGen(), c is the ciphertext data, m is the plaintext data, and L() is the decryption function. This embodiment, from the perspective of preventing possible privacy leaks during data communication and calculation, mutually authenticates the identities of the client and server according to the proposed identity authentication protocol to ensure the authenticity of the identities of both communicating parties; then uses a modified k-means algorithm to clean the data, remove abnormal data, and improve data availability; finally, encrypts the data based on homomorphic encryption technology to ensure the confidentiality of the data during the calculation process.

[0107] Example 2:

[0108] A management system data privacy protection system based on homomorphic encryption, comprising:

[0109] Client, used for data information entry;

[0110] The application layer is used to authenticate the client access to the server using the identity authentication protocol and clean the data information after successful authentication to obtain the cleaned data information;

[0111] The server is used to analyze and process the cleaned data information using homomorphic encryption technology, obtain data analysis results and return them to the client.

[0112] Application layer, including:

[0113] The identity authentication submodule is used to authenticate the client access to the server using the identity authentication protocol;

[0114] The data cleaning submodule is used to clean the data information by using the K-means algorithm to remove abnormal data and obtain cleaned data information.

[0115] Identity authentication submodule, specifically used for:

[0116] After receiving the first request sent by the client, the authorization authentication center performs authentication based on whether the client Name and client IP exist in the database. If not, the authentication fails; otherwise, the authentication succeeds and returns a first response information to the client;

[0117] The client decrypts the first response information in combination with the client key to obtain the first timestamp, TGS related information and the key CTGS_SK, and compares the first timestamp with the time interval. If the time interval is greater than the set time, the authentication fails; otherwise, the authentication succeeds and the client sends a second request to the TGS.

[0118] After receiving the second request, the TGS verifies whether the server IP exists in the database. If not, the authentication fails. Otherwise, the authentication succeeds and the encrypted GT is decrypted to obtain the second timestamp.

[0119] The TGS compares the second timestamp with the communication time interval. If it is greater than the set time, the authentication fails. Otherwise, the TGS decrypts the first response message using the key CTGS_SK and compares it with the client information in the GT before sending the second response message to the client.

[0120] The client receives the second response information and decrypts it using the key CTGS_SK to obtain a third timestamp and compares it with the time interval. If it is greater than the set time, the authentication fails; otherwise, the client extracts the key CS_SK and sends a third request to the server.

[0121] After receiving the third request, the server decrypts the obtained fourth timestamp and compares it with the time interval. If it is greater than the set time, the authentication fails. Otherwise, the server uses the key CS_SK to obtain the authenticated client information and compares it with the client information in ST. After the comparison is successful, the server sends a third response message to the client.

[0122] Among them, the application layer includes: authorization and authentication center, database, and TGS.

[0123] The data cleaning submodule is specifically used for:

[0124] Randomly selecting part of the data as initial cluster centers based on the data information;

[0125] Calculating the Euclidean distance between the remaining data and the initial cluster center based on the initial cluster center, and performing clustering to obtain a clustered set;

[0126] The sample mean is calculated based on the clustered set, a new cluster center is selected for clustering, and abnormal data is deleted to obtain cleaned data information.

[0127] The server is specifically used for:

[0128] Generate public key and private key according to the key generation function;

[0129] Encrypting the plaintext data based on the public key in combination with the encryption function to obtain ciphertext data;

[0130] The ciphertext data is decrypted based on the private key in combination with a decryption function to obtain the plaintext data and return it to the client.

[0131] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0132] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0133] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0134] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0135] The above are merely embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention are included in the scope of the claims of the present invention to be approved.

Claims

1. A data privacy protection method for a management system based on homomorphic encryption, characterized in that: include: The client enters data information; The application layer uses the identity authentication protocol to authenticate the client access to the server and cleans the data information after the authentication is successful to obtain the cleansed data information; The server uses homomorphic encryption technology to analyze and process the cleaned data information, obtains data analysis results and returns them to the client.

2. The method according to claim 1, characterized in that The application layer uses the identity authentication protocol to authenticate the client access to the server and cleans the data information after the authentication is successful, obtaining the cleaned data information, including: The application layer uses the identity authentication protocol to authenticate the client access to the server; The application layer uses the K-means algorithm to clean the data information to remove abnormal data and obtain cleaned data information.

3. The method according to claim 2, characterized in that The application layer uses the identity authentication protocol to authenticate the client access to the server, specifically including: After receiving the first request from the client, the authentication center performs authentication based on whether the client name and client IP exist in the database. If not, the authentication fails; otherwise, the authentication succeeds and returns the first response information to the client. The client decrypts the first response information in combination with the client key to obtain the first timestamp, TGS related information and the key CTGS_SK, and compares the first timestamp with the time interval. If the time interval is greater than the set time, the authentication fails; otherwise, the authentication succeeds and the client sends a second request to the TGS. After receiving the second request, the TGS verifies whether the server IP exists in the database. If not, the authentication fails. Otherwise, the authentication succeeds and the encrypted GT is decrypted to obtain the second timestamp. The TGS compares the second timestamp with the communication time interval. If it is greater than the set time, the authentication fails. Otherwise, the TGS decrypts the first response message using the key CTGS_SK and compares it with the client information in the GT before sending the second response message to the client. The client receives the second response information and decrypts it using the key CTGS_SK to obtain a third timestamp and compares it with the time interval. If it is greater than the set time, the authentication fails; otherwise, the client extracts the key CS_SK and sends a third request to the server. After receiving the third request, the server decrypts the obtained fourth timestamp and compares it with the time interval. If it is greater than the set time, the authentication fails. Otherwise, the server uses the key CS_SK to obtain the authenticated client information and compares it with the client information in ST. After the comparison is successful, the server sends a third response message to the client. Among them, the application layer includes: authorization and authentication center, database, and TGS.

4. The method according to claim 2, characterized in that The application layer uses the K-means algorithm to clean the data information to remove abnormal data, and obtains cleaned data information, including: The application layer randomly selects part of the data as the initial cluster center based on the data information; The application layer calculates the Euclidean distance of the remaining data to the initial cluster center based on the initial cluster center, and performs clustering to obtain a clustered set; The application layer calculates the sample mean based on the clustered set, selects a new cluster center for clustering, and deletes abnormal data to obtain cleaned data information.

5. The method according to claim 1, characterized in that: The server analyzes and processes the cleaned data information using homomorphic encryption technology, obtains data analysis results and returns them to the client, including: The server generates public and private keys based on the key generation function; The server encrypts the plaintext data based on the public key combined with the encryption function to obtain ciphertext data; The server decrypts the ciphertext data based on the private key in combination with the decryption function, obtains the plaintext data and returns it to the client.

6. A management system data privacy protection system based on homomorphic encryption, characterized in that: include: Client, used for data information entry; The application layer is used to authenticate the client access to the server using the identity authentication protocol and clean the data information after successful authentication to obtain the cleaned data information; The server is used to analyze and process the cleaned data information using homomorphic encryption technology, obtain data analysis results and return them to the client.

7. The system according to claim 6, characterized in that The application layer includes: The identity authentication submodule is used to authenticate the client access to the server using the identity authentication protocol; The data cleaning submodule is used to clean the data information by using the K-means algorithm to remove abnormal data and obtain cleaned data information.

8. The system according to claim 7, characterized in that: The identity authentication submodule is specifically used to: After receiving the first request from the client, the authentication center performs authentication based on whether the client name and client IP exist in the database. If not, the authentication fails; otherwise, the authentication succeeds and returns the first response information to the client. The client decrypts the first response information in combination with the client key to obtain the first timestamp, TGS related information and the key CTGS_SK, and compares the first timestamp with the time interval. If the time interval is greater than the set time, the authentication fails. Otherwise, the authentication succeeds and a second request is sent to the TGS; After receiving the second request, the TGS verifies whether the server IP exists in the database. If not, the authentication fails. Otherwise, the authentication succeeds and the encrypted GT is decrypted to obtain the second timestamp. The TGS compares the second timestamp with the communication time interval, and if it is greater than the set time, the authentication fails; Otherwise, the first response message is decrypted using the key CTGS_SK and compared with the client information in GT before sending the second response message to the client; The client receives the second response information and decrypts it using the key CTGS_SK to obtain a third timestamp and compares it with the time interval. If it is greater than the set time, the authentication fails. Otherwise, extract the key CS_SK and send a third request to the server; After receiving the third request, the server decrypts the obtained fourth timestamp and compares it with the time interval. If it is greater than the set time, the authentication fails. Otherwise, the server uses the key CS_SK to obtain the authenticated client information and compares it with the client information in ST. After the comparison is successful, the server sends a third response message to the client. Among them, the application layer includes: authorization and authentication center, database, and TGS.

9. The system according to claim 7, characterized in that: The data cleaning submodule is specifically used to: Randomly selecting part of the data as initial cluster centers based on the data information; Calculating the Euclidean distance between the remaining data and the initial cluster center based on the initial cluster center, and performing clustering to obtain a clustered set; The sample mean is calculated based on the clustered set, a new cluster center is selected for clustering, and abnormal data is deleted to obtain cleaned data information.

10. The system according to claim 6, characterized in that: The server is specifically used for: Generate public key and private key according to the key generation function; Encrypting the plaintext data based on the public key in combination with the encryption function to obtain ciphertext data; The ciphertext data is decrypted based on the private key in combination with a decryption function to obtain the plaintext data and return it to the client.