Privacy preserving data homomorphic encryption method and system

By integrating structured and unstructured data and utilizing hardware trust modules and multinomial ring encryption technology, verifiable zero-knowledge proofs are generated. This solves the problems of high computational overhead and poor verifiability of existing fully homomorphic encryption schemes in blockchain environments, and achieves efficient unstructured data processing and transparent auditing.

CN120856304BActive Publication Date: 2025-12-09NANJING YISHENG SAFETY TECH RES INST CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511375336.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-25
Publication Date
2025-12-09
Estimated Expiration
2045-09-25

AI Technical Summary

Technical Problem

Existing fully homomorphic encryption schemes suffer from huge computational overhead and poor real-time performance, making it difficult to support collaborative encryption and verifiable computation of unstructured topological data. They also cannot efficiently generate verifiable zero-knowledge proofs in blockchain environments, thus limiting the application of transparent auditing.

Method used

By fusing structured econometric data with unstructured topological data, a dataset to be encrypted carrying privacy attributes is generated. The physical non-cloning property of the hardware trust module is used to derive clock synchronization factors for data obfuscation and transformation. Combined with polynomial ring encryption and zero-knowledge proof binding tags, an algebraic structure ciphertext block that supports ciphertext arithmetic operations is constructed to generate verification conclusions and anonymized smart contract proofs that can be directly written into the blockchain.

Benefits of technology

Significantly reducing computation and communication overhead and improving real-time response, a verifiable encrypted computation framework applicable to blockchain environments has been constructed, supporting encrypted operations and transparent auditing of unstructured data, thus solving the bottlenecks of existing technologies in terms of efficiency and verifiability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120856304B_ABST
    Figure CN120856304B_ABST
Patent Text Reader

Abstract

The application provides a privacy protection-based data homomorphic encryption method and system, and relates to the fields of data security and blockchain technology. The application fuses multiple source data and derives a clock synchronization factor with the aid of a hardware trust module to drive confusion and nonlinear transformation to generate tamper-resistant data flow. In the main channel, homomorphic encryption based on a polynomial ring is used to generate algebraic structure ciphertext blocks supporting ciphertext calculation. In the auxiliary channel, a zero-knowledge proof label is generated based on a cryptographic digest and a clock factor, and mathematical binding is established through a shared random source. Finally, a blockchain decision network outputs the verification conclusion on the straight-chain and the smart contract proof containing the zero-knowledge audit path according to the binding relationship and the zero-knowledge label, realizing efficient, verifiable and privacy-protected data encryption and blockchain integration. The application can protect data privacy while realizing verifiable, tamper-resistant ciphertext processing and smart contract auditing.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of data security and blockchain technology, and particularly relates to a data homomorphic encryption method and system based on privacy protection. BACKGROUND

[0002] In cloud computing, federated learning and blockchain scenarios, there are a large number of needs to search, count or machine learning model inference on data stored by a third-party platform (such as a cloud server) in a ciphertext state. This requires that the encryption technology not only guarantees the confidentiality of data, but also supports direct calculation on ciphertext, and the calculation result after decryption is consistent with the result of the same calculation on plaintext. Therefore, there is an urgent need for a data homomorphic encryption method that can realize privacy protection and efficient ciphertext calculation, which needs to resist quantum computing attacks in security and meet the constraints of computing power and communication overhead in performance.

[0003] At present, a representative existing scheme for the above-mentioned needs is a full homomorphic encryption scheme based on the RLWE problem. This scheme encodes data on a polynomial ring, uses a lattice difficult problem to realize encryption, and realizes ciphertext calculation of any depth through Bootstrapping technology. The core is that the cloud server can directly perform addition and multiplication operations on the encrypted polynomial coefficients without obtaining the private key, complete calculation tasks such as ciphertext data aggregation and logistic regression, and finally return the result to the data owner for decryption, thereby realizing a complete privacy protection calculation closed loop in theory.

[0004] Although the full homomorphic encryption scheme provides strong security guarantee and complete calculation, it still has significant defects: first, the huge computing overhead and delay brought by Bootstrapping operation make it difficult to meet the requirements of high real-time applications; second, the scheme usually only focuses on arithmetic operations on structured data, lacks collaborative encryption and verification mechanism for unstructured topological data commonly used in distributed systems such as blockchain, and thus the ciphertext generated by the scheme is difficult to efficiently generate verifiable zero-knowledge proof when combined with blockchain technology, and cannot prove the integrity and tamper resistance of the calculation process, thereby limiting its application in scenarios requiring transparent audit and efficient verification. SUMMARY

[0005] The present application aims to provide a data homomorphic encryption method and system based on privacy protection to solve the problems of large computing overhead, poor real-time performance, and difficulty in supporting collaborative encryption and verifiable calculation of unstructured topological data in existing homomorphic encryption schemes, which leads to the inability to efficiently generate verifiable zero-knowledge proof and realize transparent audit in a blockchain environment.

[0006] To solve the above technical problems, in a first aspect, the application provides a data homomorphic encryption method based on privacy protection, comprising:

[0007] Fusing structured measurement data and unstructured topological data to generate a data set to be encrypted carrying privacy attributes;

[0008] A hardware trust module provides a trust root for a blockchain node through its physically unclonable feature, and derives a clock synchronization factor from the trust root to drive a block position confusion and nonlinear transformation on the data set to be encrypted through the clock synchronization factor, generating tamper-resistant blockchain-ready data streams;

[0009] Implementing polynomial ring-based homomorphic encryption on the blockchain-ready data streams in the main encryption channel to construct algebraic structure ciphertext blocks supporting ciphertext arithmetic operations;

[0010] Generating zero-knowledge proof binding tags based on the cryptographic hash of the algebraic structure ciphertext blocks and the clock synchronization factor in the auxiliary verification channel, and establishing a mathematical binding relationship with the main channel through a shared random source;

[0011] Inputting the algebraic structure ciphertext blocks into a decision network composed of blockchain nodes to output verification conclusions that can be directly written to the blockchain and generate anonymized smart contract proofs containing zero-knowledge audit paths through multiple blockchain nodes in the decision network based on the zero-knowledge proof binding tags and the mathematical binding relationship.

[0012] Optionally, the blockchain nodes include a first node, an intermediate node, and a terminal node, comprising:

[0013] The multiple blockchain nodes in the decision network output verification conclusions that can be directly written to the blockchain and generate anonymized smart contract proofs containing zero-knowledge audit paths based on the zero-knowledge proof binding tags and the mathematical binding relationship, comprising:

[0014] The first node in the decision network performs a homomorphic comparison operation on a privacy-sensitive field using the mathematical binding relationship to generate ciphertext with a first-level state marker;

[0015] The intermediate node chain performs multi-level ciphertext state transfer calculations on the ciphertext with the first-level state marker using a reasoning matrix dynamically calibrated by the zero-knowledge proof binding tags to generate ciphertext with a final state marker;

[0016] The terminal node aggregates the ciphertext with the final state marker, adopts a distributed key reconstruction mechanism based on threshold cryptography, and performs collaborative decryption to output verification conclusions that can be directly written to the blockchain and generate anonymized smart contract proofs containing zero-knowledge audit paths.

[0017] Optionally, the homomorphic encryption based on a polynomial ring is implemented on the blockchain-ready data stream in the main encryption channel, and an algebraic structure ciphertext block supporting ciphertext arithmetic operations is constructed, including:

[0018] The blockchain-ready data stream is segmented into fixed-size data blocks in the main encryption channel, and the data blocks are mapped onto a polynomial ring;

[0019] The polynomial ring is selected as an encryption algebraic structure, and a homomorphic encryption key is generated, including a public key for performing encryption operations and a secret key for subsequent decryption operations;

[0020] The data blocks are encrypted using the public key, and plaintext data blocks are converted into ciphertext polynomials through polynomial multiplication and other operations;

[0021] All ciphertext polynomials are combined in sequence into a ciphertext sequence to form an algebraic structure ciphertext block.

[0022] Optionally, the physical unclonable feature of the hardware trust module provides a trust root for the blockchain node, and a clock synchronization factor is derived from the trust root to drive the block position confusion and nonlinear transformation of the to-be-encrypted data set through the clock synchronization factor to generate a tamper-resistant blockchain-ready data stream, including:

[0023] A time-dependent sequence value is derived from the trust root as a clock synchronization factor, which is updated synchronously through a hardware clock and a counter;

[0024] The clock synchronization factor is used as a random seed to drive the block position confusion engine to perform block position confusion on the to-be-encrypted data set, adjust the original data layout by rearranging the order of data blocks, and obtain a data stream that has undergone block position confusion;

[0025] The clock synchronization factor is used to initialize a nonlinear transformation function at the same time, and nonlinear substitution and permutation operations are performed on the content of the data blocks to change the distribution of data values, and a data stream that has undergone nonlinear transformation is obtained;

[0026] The data stream that has undergone block position confusion and the data stream that has undergone nonlinear transformation are combined to generate a tamper-resistant blockchain-ready data stream.

[0027] Optionally, the cryptographic hash of the algebraic structure ciphertext block and the clock synchronization factor are used to generate a zero-knowledge proof binding tag in the auxiliary verification channel, and a mathematical binding relationship is established with the main channel through a shared random source, including:

[0028] The cryptographic hash of the algebraic structure ciphertext block is calculated by using a hash function to generate an fixed-length digest value;

[0029] mixing the clock synchronization factor with the digest value to generate a binding seed through XOR operation or other mixing function;

[0030] running a zero-knowledge proof protocol with the binding seed as a randomness parameter, the zero-knowledge proof protocol taking the algebraic structure ciphertext block as a proof object, outputting a proof label that can prove the integrity and does not leak the content thereof as a zero-knowledge proof binding label;

[0031] simultaneously synchronizing the main encryption channel and the auxiliary verification channel from the shared random source to obtain the same random value;

[0032] using the random value to combine the zero-knowledge proof binding label through a mathematical function to establish a mathematical binding relationship between the main encryption channel and the auxiliary verification channel.

[0033] Optionally, the structured measurement data and the unstructured topological data are fused to generate a to-be-encrypted data set carrying privacy attributes, including:

[0034] collecting structured measurement data stored in a table form and unstructured topological data stored in a graph structure or a network form;

[0035] standardizing the fields of the structured measurement data and mapping the nodes and edges in the unstructured topological data into vector representations to convert the structured measurement data and the unstructured topological data into a unified data format;

[0036] associating the converted structured measurement data and the unstructured topological data by fields and connecting through a common identifier;

[0037] labeling the associated data with privacy attributes, adding a privacy label according to the data sensitivity to form a to-be-encrypted data set carrying privacy attributes.

[0038] In a second aspect, the present application provides a data homomorphic encryption system based on privacy protection, including:

[0039] a generating module configured to fuse structured measurement data and unstructured topological data to generate a to-be-encrypted data set carrying privacy attributes;

[0040] a second generating module configured to provide a trust root for a blockchain node through a physical unclonable feature of a hardware trust module, and derive a clock synchronization factor from the trust root to drive a confusion operation to perform block position confusion and nonlinear transformation on the to-be-encrypted data set through the clock synchronization factor, and generate tamper-resistant blockchain-ready data stream;

[0041] The construction module is configured to implement polynomial ring-based homomorphic encryption on the blockchain-ready data stream in a main encryption channel, and construct an algebraic structure ciphertext block supporting ciphertext arithmetic operation;

[0042] The establishment module is configured to generate a zero-knowledge proof binding tag based on a cryptographic digest of the algebraic structure ciphertext block and the clock synchronization factor in a secondary verification channel, and establish a mathematical binding relationship with the main channel through a shared random source;

[0043] The output module is configured to input the algebraic structure ciphertext block into a decision network composed of blockchain nodes, so that a verification conclusion directly writable into a blockchain and an anonymized smart contract proof containing a zero-knowledge audit path are output by a plurality of blockchain nodes in the decision network according to the zero-knowledge proof binding tag and the mathematical binding relationship.

[0044] In a third aspect, the present application provides an electronic device, comprising:

[0045] A memory for storing a computer program;

[0046] A processor for executing the computer program to implement the steps of the privacy protection-based data homomorphic encryption method according to the first aspect.

[0047] In a fourth aspect, the present application provides a computer readable storage medium, wherein the computer readable storage medium stores a computer program, and the computer program is executable by a processor to implement the steps of the privacy protection-based data homomorphic encryption method according to the first aspect.

[0048] The privacy protection-based data homomorphic encryption method provided by the present application maps data into a high-dimensional vector and performs randomized block encryption, thereby reducing the complexity of single ciphertext calculation, introducing a proof chain structure based on a hash commitment, and enabling a third-party platform to generate a non-interactive zero-knowledge proof in a ciphertext calculation process to prove the correctness and integrity of the calculation. This scheme not only significantly reduces the calculation and communication overhead and improves the response real-time performance, but more importantly, it builds a verifiable ciphertext calculation framework applicable to a blockchain environment, effectively supports ciphertext operation and transparent audit on unstructured data without sacrificing data privacy, thereby solving the bottleneck problem of the prior art in terms of efficiency and verifiability. BRIEF DESCRIPTION OF DRAWINGS

[0049] In order to make the technical solutions of the embodiments or prior art of the present application more clear, the drawings needed in the embodiment or prior art description will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application, and those skilled in the art can also obtain other drawings according to these drawings without creative labor.

[0050] Figure 1 A flowchart of a data homomorphic encryption method based on privacy protection provided by an embodiment of the present application;

[0051] Figure 2 A flowchart of a specific implementation of a data homomorphic encryption method based on privacy protection provided by an embodiment of the present application;

[0052] Figure 3 A flowchart of another specific implementation of a data homomorphic encryption method based on privacy protection provided by an embodiment of the present application;

[0053] Figure 4 A structural schematic diagram of a data homomorphic encryption system based on privacy protection provided by an embodiment of the present application. DETAILED DESCRIPTION

[0054] In cloud computing and blockchain applications, although the existing RLWE-based full homomorphic encryption scheme can realize direct calculation of ciphertext and guarantee data privacy, it has two major limitations: the Bootstrapping operation it relies on produces high computational and time overhead, making it difficult to apply to actual scenarios with high real-time requirements; this type of scheme mainly targets arithmetic operations on structured data and lacks native support for unstructured topological data, making it difficult to efficiently generate verifiable computation proof and unable to meet the strong demand for data integrity, tamper resistance and auditability in distributed environments.

[0055] In view of the above defects, the application provides a lightweight homomorphic encryption method supporting verifiable computing. The core innovation of the method is to combine vectorization coding technology with zero-knowledge proof mechanism to realize limited homomorphic operation without Bootstrapping in a lattice cryptography system. Specifically, by mapping data into a high-dimensional vector and performing randomized block encryption, the complexity of single ciphertext calculation is reduced, and a proof chain structure based on a hash commitment is introduced, so that a third-party platform can generate a non-interactive zero-knowledge proof during the ciphertext calculation process to prove the correctness and integrity of the calculation. The scheme not only significantly reduces the calculation and communication overhead and improves the response real-time performance, but more importantly, it builds a verifiable ciphertext computing framework applicable to a blockchain environment. Without sacrificing data privacy, the scheme effectively supports ciphertext operation and transparent auditing of unstructured data, thereby solving the bottleneck problem of the prior art in terms of efficiency and verifiability.

[0056] To make the person skilled in the art better understand the scheme of the application, the application will be further described in detail below in combination with the drawings and specific embodiments. Obviously, the described embodiments are only part of the embodiments of the application, not all the embodiments. Based on the embodiments in the application, all other embodiments obtained by a person skilled in the art without creative labor fall within the scope of protection of the application.

[0057] The core of the application is to provide a data homomorphic encryption method based on privacy protection. The flowchart of one specific embodiment is shown in Figure 1 The method comprises the following steps.

[0058] S101, fusion of structured measurement data and unstructured topological data to generate a set of encrypted data carrying privacy attributes;

[0059] Optionally, S101 can specifically include the following steps:

[0060] S1011, collecting structured measurement data stored in a table form and unstructured topological data stored in a graph structure or a network form;

[0061] S1012, standardizing the fields of the structured measurement data, and mapping the nodes and edges in the unstructured topological data into vector representations to convert the structured measurement data and the unstructured topological data into a unified data format;

[0062] S1013, associating the converted structured measurement data and unstructured topological data by fields, and connecting them through a common identifier;

[0063] S1014, label the privacy attribute of the associated data, add a privacy label according to the data sensitivity, and form a to-be-encrypted data set carrying the privacy attribute.

[0064] In the above scheme, the structured metering data is quantified data with fixed fields and explicit format organized in table form; the unstructured topology data is data describing the connection relationship between entities in the form of a graph or network; the privacy attribute is an attribute of data involving personal or organizational sensitive information; the to-be-encrypted data set is a data set that needs to be encrypted and protected after fusion processing and privacy attribute labeling; the table form is a two-dimensional structure with rows representing records and columns representing fields; the graph structure is composed of nodes and edges, where the nodes represent entities and the edges represent relationships; the standardized encoding is to convert data fields according to uniform rules to make different formats of data consistent; the uniform data format is the same or compatible representation form of different types of data after processing; the common identifier is an attribute that can uniquely identify an entity in both types of data; the associated data is a record that combines the two types of data; the data sensitivity is the degree of harm after data leakage; and the privacy label is a label indicating the sensitivity.

[0065] In the embodiment of the application, first, the structured metering data is extracted through the metering automation system interface through S1011, the structured metering data is stored in the form of a database table or an Excel table, and the unstructured topology data is exported through a topology management platform, the unstructured topology data is stored in the form of a graph database file or a.graph format file generated by a network modeling tool; for example, in a certain regional smart energy system, a user electricity data table is extracted from a power utilization information collection system database, and a regional power grid topology graph file is exported from a power grid GIS system.

[0066] Secondly, for the structured metering data, a standardized algorithm (such as Min-Max scaling) is applied to encode the numerical fields, and the numerical conversion is completed through the formula: , for the unstructured topology data, a graph embedding algorithm (such as Node2Vec) is used to map nodes and edges into fixed-dimensional vector representations, after processing, all data are converted into numerical vector format, which is convenient for unified processing; for example, the A department performs Min-Max standardization on the consumption field: assuming that the minimum value of the original power consumption is 0 kWh and the maximum value is 1000 kWh, then the record of power consumption 500 kWh is standardized to 0.5; at the same time, the B system uses Node2Vec to process the topology graph to generate a 128-dimensional vector for each node, such as the vector of node node_001 is [0.1, 0.3, …, -0.2].

[0067] Then, the standardized structured metering data is connected and matched with the vectorized unstructured topology data based on the common identifier through S1013, specifically through a database join operation or a data frame merging operation, according to the mapping relationship between the user identifier and the node identifier, the two types of data are integrated into a unified data set. For example, through the corresponding relationship between user_id and node_id, the power consumption data after standardization processing is associated and merged with the node feature vector data to form a complete data record containing standardized metering value and topology vector.

[0068] Finally, a labeling rule library is established based on the characteristics and content sensitivity of the data fields through S1014, the labeling rule library contains sensitive field identification rules and sensitivity grading standards, then an automatic labeling technology is used to evaluate the sensitivity of each field in the associated data, according to the field type, data content and business scenario to determine the privacy level, finally the privacy label is added as a new metadata field to the data set to form a complete encrypted data set carrying privacy attributes.

[0069] In practical application, in a smart grid data preprocessing project of a certain power department, first, metering data is collected from the internal database system, a data table containing 10000 records is obtained, each record contains user_id, timestamp and consumption fields, an example record is user_id:1001, timestamp:2023-01-0100:00:00, consumption:350kWh; at the same time, topology data is obtained from the power grid management platform, containing 500 nodes and 1000 edges, an example node is node_id:sub_001, type:substation, location:A area. Then the power consumption data is standardized, assuming that the minimum power consumption recorded by the system is 50kWh and the maximum power consumption is 1200kWh, then the standardized value of 350kWh power consumption is obtained after calculation The Node2Vec algorithm is used to generate a 128-dimensional feature vector for the topology node. Then, through the mapping relationship between user_id and node_id, the standardized metering data is associated and integrated with the node vector data. Finally, according to the privacy labeling rules, user_id is marked as "highly sensitive", the standardized power consumption value is marked as "medium sensitive", and the node vector is marked as "low sensitive" to form a complete encrypted data set.

[0070] The overall scheme of S101 above clearly defines the privacy attributes and sensitivity of each part of the fused data, through the label, the data protection requirements are clearer, providing a targeted basis for subsequent encryption processing, which not only ensures the safety of privacy information, but also avoids excessive encryption affecting data use, balancing the needs of data protection and value utilization.

[0071] S102, providing a trust root for the blockchain node through the physically unclonable feature of the hardware trust module, and deriving a clock synchronization factor from the trust root to drive the block position confusion and nonlinear transformation on the to-be-encrypted data set through the clock synchronization factor to generate tamper-resistant blockchain-ready data stream;

[0072] Optionally, S102 can specifically include the following steps:

[0073] S1021, deriving a time-dependent sequence value from the trust root as a clock synchronization factor, which is updated synchronously through a hardware clock and a counter;

[0074] S1022, using the clock synchronization factor as a random seed to drive the confusion engine to perform block position confusion on the to-be-encrypted data set, adjust the original data layout by rearranging the order of data blocks, and obtain a data stream that has undergone block position confusion;

[0075] S1023, simultaneously initializing a nonlinear transformation function using the clock synchronization factor to perform nonlinear substitution and permutation operations on the content of the data block, change the distribution of data values, and obtain a data stream that has undergone nonlinear transformation;

[0076] S1024, combining the data stream that has undergone block position confusion and the data stream that has undergone nonlinear transformation to generate a tamper-resistant blockchain-ready data stream.

[0077] In the above scheme, the hardware trust module refers to a hardware component integrated with a physically unclonable function; the physically unclonable feature refers to a unique feature formed by microscopic differences in the manufacturing process, which can generate a unique and non-reproducible identifier; the blockchain node refers to a computing device participating in the operation, storage and verification of data in a blockchain network; the root of trust refers to an original key or identifier extracted from the physically unclonable feature of the hardware trust module, which can be used as the basis for trust; the clock synchronization factor refers to a sequence value derived from the root of trust and dynamically changing over time; the hardware clock refers to a timing component built into the hardware trust module; the counter refers to a numerical recording component that increments over time; the random seed refers to an initial value used to initialize a random number generator, which determines the direction of the random sequence; the obfuscation engine refers to a functional module that performs data obfuscation operations; the data set to be encrypted refers to a collection of original data that needs to be securely processed; block position obfuscation refers to an operation that changes the data layout by rearranging the order of data blocks; the data block refers to a sub-data unit divided from the data set according to a fixed size; the original data layout refers to the arrangement order of the data block in the original data set; the nonlinear transformation function refers to a mathematical function with a nonlinear relationship between the output and the input, used to change the distribution of data values; the nonlinear replacement refers to an operation of mapping and replacing data values with a nonlinear function; the permutation operation refers to an operation of rearranging the positions of data units; the distribution of data values refers to the frequency and range of different numerical values in the data set; the blockchain-ready data stream refers to a data sequence that meets the storage requirements of the blockchain and has tamper-resistant features after processing.

[0078] In the embodiments of the present application, as shown in Figure 2 First, the root of trust is generated by using the physically unclonable feature of the hardware trust module through S1021, and then a dynamic sequence is extracted from the root of trust by using a key derivation algorithm, and a time-dependent clock synchronization factor is generated by combining the timestamp provided by the hardware clock and the incremental value of the counter. The factor changes with the update of the hardware clock and the counter; for example, in the A blockchain system, the root of trust of the B hardware trust module is a fixed key K, the current timestamp of the hardware clock is T=1620000000000ms, and the counter value C=100. By mixing and calculating K, T and C through the HKDF algorithm, a clock synchronization factor S=0x7a3f9d (hexadecimal sequence) is generated. After 10 milliseconds, T is updated to 1620000000010ms and C=101, and a new S=0x2b8e4c is calculated.

[0079] Secondly, the data set to be encrypted is divided into a plurality of continuous data blocks by S1022 according to a preset size, forming a sequence of original data blocks; the clock synchronization factor is directly input into a random number generation unit of the confusion engine, and the confusion engine is started by taking the clock synchronization factor as a random seed, and the confusion engine generates a set of non-repeating random permutation sequences based on the seed, and then performs a position rearrangement operation on the sequence of original data blocks according to the set of sequences, that is, each data block is recombined according to the index order of the random permutation sequence, and finally integrated to form a data stream subjected to block position confusion.

[0080] Next, the clock synchronization factor is input into a nonlinear transformation function to complete initialization by S1023, and the nonlinear transformation function determines a replacement mapping table and a permutation rule according to the clock synchronization factor; then, for each data block divided from the original data set to be encrypted, nonlinear replacement is performed according to the mapping table, and then permutation operation is performed on the replaced bytes according to the permutation rule; finally, all processed data blocks are spliced in turn to form a data stream subjected to nonlinear transformation; for example, in the A blockchain system, the nonlinear transformation function is initialized with S=0x7a3f9d, and the original data blocks [D1, D2, D3, D4] are processed respectively: D1 becomes D1' after replacement and permutation, D2 becomes D2', D3 becomes D3', and D4 becomes D4', and the nonlinear transformation data stream "D1'D2'D3'D4'" is spliced.

[0081] Finally, the data stream subjected to block position confusion and the nonlinear transformation data stream are combined by S1024 using a data stream interleaving algorithm in a fixed length unit, corresponding units in the two data streams are alternately extracted and spliced in turn to form an integrated data sequence containing position confusion and content transformation characteristics, which is a tamper-resistant blockchain ready data stream; for example, in the A blockchain system, the block position confusion data stream is "D2D4D1D3", the nonlinear transformation data stream is "D1'D2'D3'D4'", and the blockchain ready data stream "D2D1'D4D2'D1D3'D3D4'" is obtained by alternately combining each block of data.

[0082] In practical applications, in the smart grid data preprocessing project of a certain power department, first, a trust root is generated from a hardware trust module, combined with a timestamp T = 1630000000000 and a counter C = 200, a clock synchronization factor S = 0x5c7d2f is generated through the HKDF algorithm; then, 8 pieces of electric metering data [E1, E2, E3, E4, E5, E6, E7, E8] (each piece is 2KB, and each piece contains a plurality of user_id, timestamp, and consumption field records) are divided into original sequences, S drives the confusion engine to generate an arrangement sequence [5, 1, 7, 3, 8, 2, 6, 4], and after rearrangement, it is spliced into block position confusion data stream "E5E1E7E3E8E2E6E4"; at the same time, S is used to initialize the nonlinear transformation function, and the original 8 pieces of electric metering data are replaced and transposed to obtain [E1', E2', E3', E4', E5', E6', E7', E8'], which are spliced into nonlinear transformation data stream "E1'E2'E3'E4'E5'E6'E7'E8'"; finally, the block position confusion data stream and the nonlinear transformation data stream are alternately combined in the manner of "E5E1'E1E2'E7E3'E3E4'E8E5'E2E6'E6E7'E4E8'", to generate a smart grid ready data stream, which can be directly used for subsequent association and integration with topology data.

[0083] The overall scheme of S102 realizes the cooperative processing of block position confusion and nonlinear transformation through the trusted basis provided by the hardware trust module combined with the clock synchronization factor, ensures the consistency and timeliness of data processing, breaks the original data layout through block position confusion, changes the data content distribution through nonlinear transformation, and the combination of the two greatly improves the anti-tampering ability of the data. The finally generated blockchain ready data stream has double confusion features of position and content, which can meet the storage specification of the blockchain and effectively resist tampering, providing reliable protection for the security and credibility of the blockchain data.

[0084] S103, implementing homomorphic encryption based on a polynomial ring on the blockchain ready data stream in a main encryption channel, constructing an algebraic structure ciphertext block supporting ciphertext arithmetic operation;

[0085] Optionally, S103 can specifically include the following steps:

[0086] S1031, dividing the blockchain ready data stream into data blocks of a fixed size in the main encryption channel, and mapping the data blocks to a polynomial ring;

[0087] S1032, selecting the polynomial ring as an encryption algebraic structure, generating a homomorphic encryption key, including a public key for performing encryption operation and a secret key for subsequent decryption operation;

[0088] S1033, encrypting the data block using the public key, converting the plaintext data block to a ciphertext polynomial through polynomial multiplication and other operations;

[0089] S1034, combining all ciphertext polynomials into a ciphertext sequence in sequence to form an algebraic structure ciphertext block.

[0090] In the above scheme, the main encryption channel refers to a special communication or calculation channel specially used for performing encryption processing on data with high security requirements; the blockchain-ready data stream refers to an anti-tampering data sequence that has undergone previous confusion processing and meets the storage format requirements of the blockchain; the fixed-size data block refers to a sub-data unit formed by dividing the blockchain-ready data stream into a preset uniform length; the polynomial ring refers to a set of polynomials whose coefficients are taken from a specific set of integers, whose variable degree does not exceed a preset value, and which satisfy the "polynomial modulo specific polynomial" operation rule, and is the core algebraic structure of homomorphic encryption; the homomorphic encryption based on the polynomial ring refers to an encryption technology that realizes the decryption of ciphertext after performing arithmetic operations on the ciphertext, and the result is consistent with the plaintext after the operation and then encryption; the low Hamming weight refers to the fact that most of the coefficients in the polynomial are 0, and only a few are non-zero values, which is convenient for subsequent operations; the homomorphic encryption key refers to a key pair used to perform homomorphic encryption and decryption operations, including a public key and a secret key; the public key refers to a key that is publicly disclosed and used to perform encryption operations on data; the secret key refers to a key that is not publicly disclosed and is used to perform decryption operations on ciphertext; the plaintext data block refers to a fixed-size data block that has not been encrypted; the ciphertext polynomial refers to the ciphertext represented in the form of a polynomial after homomorphic encryption of the plaintext data block; the ciphertext sequence refers to a continuous ciphertext unit formed by arranging a plurality of ciphertext polynomials in the order of the original data block; and the algebraic structure ciphertext block refers to an overall ciphertext unit composed of a ciphertext sequence and having algebraic properties supporting arithmetic operations on ciphertext.

[0091] In the embodiments of the present application, first, the data segmentation algorithm is called in the main encryption channel through S1031 to divide the blockchain-ready data stream into a plurality of continuous data blocks according to a preset fixed size; then a numerical mapping algorithm is used to map the byte values of each data block to the coefficients of a polynomial in the polynomial ring in sequence, and the variable degree of the polynomial is incremented from 0, thereby converting each data block to a polynomial on the polynomial ring and completing the mapping of the data block to the polynomial ring; for example, when the A blockchain system processes the blockchain-ready data stream of a B type sensor, the total length of the data stream is 1024 bytes, and after being divided according to 128 bytes / block, 8 data blocks (Block1-Block8) are obtained; taking Block1 as an example, its byte sequence is [0x12, 0x34, 0x56,..., 0xab] (a total of 128 bytes), and each byte value is taken as a coefficient to generate a polynomial on the polynomial ring The remaining 7 data blocks are similarly mapped to... .

[0092] Secondly, based on the parameter requirements of the homomorphic encryption algorithm, S1032 selects a suitable polynomial ring as the encryption algebra structure. This polynomial ring is typically represented as follows: ,in It is the set of integers modulo q (q is a preset large prime number used to control the range of coefficients). It is an ideal generator; then the key generation algorithm is called to generate a homomorphic encryption key on the polynomial ring: first, a low Hamming weight polynomial is randomly selected. , as the secret key; then select a random polynomial and small error polynomial Through formula The polynomial is calculated. Finally As a public key Used as a secret key, key pair generation is completed; for example, choosing a polynomial ring. (q=2048, n=128), randomly generate secret key Random selection Small error polynomial Substitute into the formula to calculate After expanding, combine like terms to obtain The final public key is The secret key is .

[0093] Next, the encryption module of the homomorphic encryption algorithm is called via S1033 to directly perform encryption operations on the data block using the public key, selecting a small polynomial. and small error polynomial Then through the formula and Two ciphertext polynomials were calculated. ,Will As the corresponding data block The encrypted polynomial.

[0094] Finally, through S1034, the ciphertext combination algorithm is invoked to arrange the ciphertext polynomials sequentially according to the original segmentation order of their corresponding plaintext data blocks, forming a continuous ciphertext sequence; then, a structured identifier is added to the ciphertext sequence, integrating it into a whole unit with a unified format and algebraic operation characteristics, serving as an algebraic structure ciphertext block that supports ciphertext arithmetic operations.

[0095] In practical applications, a certain power department performs encryption processing on smart grid ready data stream in a smart grid data preprocessing project. First, in the main encryption channel, the 1024-byte smart grid ready data stream is divided into 8 data blocks according to 128 bytes / block, and the byte value of each data block is converted into a polynomial coefficient through a numerical mapping algorithm. For example, the byte sequence [0x23, 0x45,..., 0xcd] of Block3 is mapped into a polynomial Secondly, the polynomial ring is selected as the encryption structure, and the secret key and the public key are generated, where , , Then, each plaintext polynomial is encrypted, and is taken as an example. The polynomial , , is substituted into the formula to generate the ciphertext polynomial , Finally, the 8 ciphertext polynomials are arranged in the original block order, and data start markers, length information and end markers are added to integrate the smart grid algebraic structure ciphertext block. The overall scheme of S103 ensures the security of the blockchain ready data stream encryption process through the main encryption channel, avoiding external interference of the encryption operation. The homomorphic encryption technology of the polynomial ring enables the generated algebraic structure ciphertext block to support ciphertext arithmetic operation, and subsequent operations on the ciphertext can be performed without decryption, reducing the risk of key exposure. The data block segmentation and polynomial mapping ensure the standardization and batch processing efficiency of the encryption process, and the algebraic design of key generation and encryption operation improves the encryption strength. Finally, the algebraic structure ciphertext block not only meets the storage requirements of the blockchain, but also supports flexible ciphertext processing while ensuring data security, providing technical support for the secure storage and efficient operation of the blockchain data.

[0096] S104, based on the cryptographic digest of the algebraic structure ciphertext block and the clock synchronization factor, generates a zero-knowledge proof binding tag, and synchronously establishes a mathematical binding relationship with the main channel through a shared random source.

[0097]

[0098] Optionally, S104 can specifically include the following steps:

[0099] S1041, a cryptographic digest of the algebraic structure ciphertext block is calculated by using a hash function to generate an fixed-length digest value;

[0100] ​S1042, mixing the clock synchronization factor and the digest value to generate a binding seed through XOR operation or other mixing function;

[0101] S1043, running a zero-knowledge proof protocol with the binding seed as a randomness parameter, the zero-knowledge proof protocol taking the algebraic structure ciphertext block as a proof object, outputting a proof label that can prove the integrity and does not leak the content thereof as a zero-knowledge proof binding label;

[0102] S1044, simultaneously synchronizing the main encryption channel and the auxiliary verification channel from the shared random source to obtain the same random value;

[0103] S1045, using the random value to combine the zero-knowledge proof binding label through a mathematical function to establish a mathematical binding relationship between the main encryption channel and the auxiliary verification channel.

[0104] In the above scheme, the auxiliary verification channel refers to a parallel channel for auxiliary verification of the main encryption channel processing result and ensuring data integrity; the algebraic structure ciphertext block refers to an overall ciphertext unit generated by the main encryption channel, which supports ciphertext arithmetic operation; the cryptographic digest refers to a fixed-length numerical value calculated by a hash function on data; the hash function refers to a function that maps arbitrary length data to a fixed length output; the clock synchronization factor refers to a sequence value derived from a trusted root and dynamically changing with time, used to ensure the time correlation of the operation; the mixing operation refers to the process of combining two or more data units into a new data unit according to a specific rule; the XOR operation refers to the logical operation of "same as 0, different as 1" on the corresponding bits of two binary numbers; the mixing function refers to other combination rules other than XOR; the binding seed refers to a randomness parameter for initializing zero-knowledge proof generated by mixing the clock synchronization factor and the digest value; the zero-knowledge proof protocol refers to a cryptographic protocol in which the prover can prove to the verifier that a statement is true without leaking information; the proof object refers to the algebraic structure ciphertext block targeted by the zero-knowledge proof; the proof label refers to the identification output by the zero-knowledge proof for proving data integrity; the zero-knowledge proof binding label refers to the proof label combined with the clock synchronization factor and the digest value, which has the functions of time correlation and integrity proof; the shared random source refers to a trusted source that provides the same random value for the main encryption channel and the auxiliary verification channel; the random value refers to a random number obtained from the shared random source, used to establish the correlation between the channels; the mathematical binding relationship refers to the correlation of the processing results of the two channels through a mathematical function.

[0105] In the embodiments of the present application, first, in the auxiliary verification channel, the binary data of the algebraic structure ciphertext block is taken as input, compressed and iteratively processed by a hash function, and then a fixed-length cryptographic digest is output. For example, in a certain blockchain system, the algebraic structure ciphertext block generated by the main channel is "CB001...FF" (binary data), and the digest value "H=0x7a3f9d...2b8e" (256-bit hexadecimal number) is obtained after SHA-256 calculation.

[0106] Secondly, the clock synchronization factor and the cryptographic digest are mixed by S1042: if the exclusive OR operation is used, the binary corresponding bits of the two are calculated bit by bit, and the calculation result is taken as the binding seed; if other mixing functions are used, the two are regarded as polynomial coefficients after addition and then taken modulo to generate the binding seed; for example, in the scene, the exclusive OR operation is used, the binary of S is "1010...0110", the binary of H is "1100...1001", and the binding seed "0110...1111" (256 bits) is obtained after exclusive OR.

[0107] Then, the zero-knowledge proof protocol is initialized by S1043 with the binding seed as the randomness parameter, the auxiliary verification channel takes the algebraic structure ciphertext block as the proof object, generates a random challenge value using the binding seed, and generates a proof label through the interaction steps of the protocol. The proof label can prove to the verifier that the ciphertext block has not been tampered with, but does not disclose the specific content of the ciphertext block. The proof label is taken as the zero-knowledge proof binding label.

[0108] Then, the main encryption channel and the auxiliary verification channel use the "timestamp alignment + identity authentication + value verification" synchronization acquisition mechanism by S1044 to obtain the same random value from a shared random source.

[0109] Finally, the random value is used to combine the zero-knowledge proof binding label Proof by S1045 through mathematical functions: if a hash function is used, Hash(R||Proof) is calculated; if polynomial multiplication is used, the two are regarded as polynomial coefficients and multiplied. The combination result is associated with the algebraic structure ciphertext block of the main encryption channel and the zero-knowledge proof label of the auxiliary verification channel, so that the main encryption channel and the auxiliary verification channel form an inseparable mathematical binding relationship.

[0110] In practical applications, in the smart grid data preprocessing project of a certain power department, when processing the metering encrypted data of the electric meter, first, the algebraic structure ciphertext block CB123...789 generated by the main channel is calculated by SHA-256 to obtain a cryptographic digest H = 0x2d5f...8a1b; second, the clock synchronization factor S = 0x6e3a...4c9d is XORed with H to obtain the binding seed Seed = 0x4b65...c687; then, the Schnorr protocol is initialized with Seed, the ciphertext block is taken as the proof object, and the zero-knowledge proof binding tag Proof = 0x7c9f...3d2e is generated; at the same time, the main and auxiliary channels obtain the random value R = 0x5a8b...6e1d from the shared random source; finally, R and Proof are spliced and calculated by SHA-256 to obtain Hash(R||Proof) = 0x9b3e...8f4c, and the mathematical binding relationship of the two channels is established to ensure the consistency of the ciphertext block and the proof tag.

[0111] The overall scheme of S104 realizes the unique identification of the algebraic structure ciphertext block through the cryptographic digest generated by the auxiliary verification channel, ensures the data integrity verifiable; the mixed operation of the clock synchronization factor and the digest makes the zero-knowledge proof binding tag have time correlation, preventing replay attacks; through the establishment of the shared random source and the mathematical binding relationship, the consistency of the main encryption channel and the auxiliary verification channel is ensured, avoiding separation or individual tampering; the overall process enhances the security and credibility of data processing, and provides reliable support for the verification of blockchain data.

[0112] S105, inputting the algebraic structure ciphertext block into a decision network composed of blockchain nodes, so as to output a verification conclusion that can be directly written into a blockchain and generate an anonymized smart contract proof containing a zero-knowledge audit path through a plurality of blockchain nodes in the decision network according to the zero-knowledge proof binding tag and the mathematical binding relationship.

[0113] Optionally, S105 can specifically include the following steps:

[0114] S1051, performing a homomorphic comparison operation on a privacy-sensitive field by a first node in the decision network using the mathematical binding relationship to generate a ciphertext with a first-level state marker;

[0115] S1052, performing a multi-level ciphertext state transition calculation on the ciphertext with the first-level state marker by an intermediate node chain using a reasoning matrix dynamically calibrated by the zero-knowledge proof binding tag to generate a ciphertext with a final state marker;

[0116] S1053, aggregating the ciphertexts marked with the final state label by the terminal node, performing collaborative decryption using a distributed key reconstruction mechanism based on threshold cryptography, outputting a verification conclusion that can be directly written into a blockchain, and generating an anonymized smart contract proof containing a zero-knowledge audit path.

[0117] In the above scheme, the mathematical binding relationship refers to the correlation between data elements established through mathematical functions; the privacy-sensitive field refers to a data field containing personal identity or health information; the homomorphic comparison operation is an encryption calculation technology; the first-level state label refers to an encrypted Boolean result generated through homomorphic comparison; the zero-knowledge proof binding label refers to a verification label generated through zero-knowledge proof technology; the reasoning matrix refers to a dynamically adjusted mathematical matrix; the multi-level ciphertext state transition calculation refers to state conversion through encryption calculation steps; the final state label refers to an encrypted aggregation result after multi-level verification; the terminal node refers to the last blockchain node of the decision network; the distributed key reconstruction mechanism based on threshold cryptography refers to a security protocol that requires multiple nodes to collaborate in decryption; collaborative decryption refers to the use of private key shares by nodes to decrypt data; the verification conclusion refers to the readable result after decryption; the zero-knowledge audit path refers to an audit track generated through zero-knowledge proof technology; and the anonymized smart contract proof refers to an encryption proof that ensures the privacy protection of a smart contract.

[0118] In the embodiments of the present application, as shown in Figure 3 First, the first node in the decision network is extracted to extract the encrypted field and the encrypted threshold value, and a homomorphic encryption algorithm is applied to the encrypted field and the encrypted threshold value to generate an encrypted Boolean value, which is used as the first-level state label.

[0119] Second, each intermediate node verifies the validity of the zero-knowledge proof binding label first to ensure that the sensor data source is trusted and has not been tampered with, then dynamically adjusts the parameters of the reasoning matrix according to the information provided by the zero-knowledge proof binding label, and finally performs homomorphic calculation on the encrypted state label using the calibrated reasoning matrix to realize state transition. For example, in a certain temperature monitoring scenario, after the first intermediate node verifies the zero-knowledge proof label, it adjusts the weight parameter of the reasoning matrix from E(0.6) to E(0.8) according to the label indication, and then calculates E(true) x E(0.8) + E(humidity reading) x E(0.2) = E(0.86); the second node continues to calibrate and calculate, and finally generates the final encrypted state label E(alert_status) after multi-level processing.

[0120] Finally, all encrypted state markers are aggregated by the terminal node S1053, multiple encrypted markers are combined into a comprehensive ciphertext by homomorphic addition operation, then a distributed key reconstruction mechanism based on threshold cryptography is adopted, requiring at least 3 nodes to jointly participate in the decryption process, the nodes provide private key fragments through Shamir secret sharing algorithm, and the complete decryption key is reconstructed; then the reconstructed complete decryption key is used to perform collaborative decryption on the comprehensive ciphertext, and the plaintext value is obtained; the plaintext value is converted into a readable verification conclusion according to a preset rule; combined with the readable verification conclusion, an anonymous smart contract proof containing a zero-knowledge audit path is generated by zero-knowledge proof technology such as zk-SNARKs.

[0121] In practical applications, in a certain power department smart grid blockchain management system, for the algebraic structure ciphertext block (CB123...789, containing 8 electricity metering data encryption polynomials) of the smart grid, the zero-knowledge proof binding label (Proof=0x7c9f...3d2e) and the mathematical binding relationship (Hash(R||Proof)=0x9b3e...8f4c, R=0x5a8b...6e1d), a decision network operation is composed of 5 blockchain nodes (Node1 is the first node, Node2-3 is the intermediate node, and Node4-5 is the terminal node): first, Node1 extracts the encryption polynomials corresponding to the 8 electricity meters and E(2) (electricity data security threshold based on the polynomial ring encryption) from the algebraic structure ciphertext block, verifies the binding validity, and generates the first level state marker ciphertext through homomorphic comparison; then Node2 compares the binding seed Seed=0x4b65...c687, verifies the zero-knowledge proof binding label using the Schnorr protocol, adjusts the weight according to the electricity meter data credibility calibration reasoning matrix, and calculates the intermediate state marker, Node3 verifies Proof and combines the clock synchronization factor S to adjust the weight, and generates the final state marker ciphertext; finally, Node4-5 combines the final marker into a comprehensive ciphertext E(5.745) (corresponding to the standardized electricity data mean value), and Node2 reconstructs the secret key and collaboratively decrypts to get plaintext 5.745, outputs the verification conclusion "overall consistent with the power grid electricity standard", and then generates the zero-knowledge audit path through zk-SNARKs, embeds the smart contract to generate the anonymous proof (address 0x8e9d...3c2a), which can be directly written into the blockchain for power grid data security audit.

[0122] The overall scheme of S105 realizes the whole-process protection of the privacy-sensitive field through homomorphic comparison, ciphertext transfer and threshold decryption, relies on multi-layer verification to ensure data credibility, and finally generates a compliant blockchain verification conclusion and anonymization proof. In addition, the layered logic of primary node verification-intermediate node calibration-terminal node decryption balances data privacy security, processing reliability and blockchain compliance, and adapts to data management needs.

[0123] The following is a complete example for steps 101-105. In a certain power department smart grid data preprocessing project, first, 10,000 records of electric meter data (containing user_id, timestamp, consumption fields) are collected from the internal database, 500 nodes and 1000 edges of topological data are obtained from the power grid management platform, and the clock synchronization factor S=0x5c7d2f is generated by the HKDF algorithm through the hardware trust module combined with the timestamp T=1630000000000 and the counter C=200.

[0124] Then the electric meter data is standardized, and the Node2Vec algorithm is used to generate a 128-dimensional feature vector of the topological node. Then 8 blocks of electric meter data are divided into original sequences, and the block position obfuscation data stream is generated by driving the obfuscation engine with the clock synchronization factor S. Meanwhile, the original data is processed to generate a nonlinear transformation data stream by initializing a nonlinear transformation function with the clock synchronization factor S. The smart grid ready data stream is obtained by alternately combining the two data streams in a specific way.

[0125] Next, the ready data stream is divided into 8 data blocks with 128 bytes per block. After being converted into polynomial coefficients, the polynomial ring A key pair is generated, and a ciphertext polynomial is generated by encrypting each plaintext polynomial. After arranging and adding a marker, an algebraic structure ciphertext block is integrated. Then, the ciphertext block digest H is calculated using SHA-256. The clock synchronization factor S is XORed with the ciphertext block digest H to obtain the binding seed Seed. The Seed is used to initialize the Schnorr protocol to generate a zero-knowledge proof binding label Proof. Random values R are obtained synchronously through the main and auxiliary channels. The Hash value is calculated by concatenating R and Proof to establish a mathematical binding relationship.

[0126] Finally, a decision network is formed by 5 blockchain nodes. The primary node extracts the encrypted polynomial and the security threshold from the ciphertext block, generates a ciphertext with a first-level state marker through homomorphic comparison, and the intermediate node chain dynamically adjusts the weight and generates a ciphertext with a final state marker using Proof to dynamically calibrate the reasoning matrix. The terminal node aggregates the ciphertext, reconstructs the key using threshold cryptography, and cooperatively decrypts to output the verification conclusion "overall compliance with the power consumption standard". Then, a zero-knowledge audit path is generated using zk-SNARKs, an anonymization proof is generated by embedding a smart contract, and is directly written into the blockchain.

[0127] Figure 4 A structural schematic diagram of a specific embodiment of a data homomorphic encryption system based on privacy protection provided by the embodiment is shown in FIG. 1. Figure 4 The system can include:

[0128] A generation module 41 is configured to fuse structured metering data and unstructured topological data to generate a data set to be encrypted carrying privacy attributes.

[0129] A second generation module 42 is configured to provide a trust root for a blockchain node through a physically unclonable feature of a hardware trust module, and derive a clock synchronization factor from the trust root to drive a block position confusion and a nonlinear transformation on the data set to be encrypted through the clock synchronization factor to generate tamper-resistant blockchain-ready data stream.

[0130] A construction module 43 is configured to implement polynomial ring-based homomorphic encryption on the blockchain-ready data stream in a main encryption channel to construct an algebraic structure ciphertext block supporting ciphertext arithmetic operations.

[0131] An establishment module 44 is configured to generate a zero-knowledge proof binding tag based on a cryptographic digest of the algebraic structure ciphertext block and the clock synchronization factor in a secondary verification channel, and simultaneously establish a mathematical binding relationship with the main channel through a shared random source.

[0132] An output module 45 is configured to input the algebraic structure ciphertext block into a decision network composed of blockchain nodes to output a verification conclusion that can be directly written into a blockchain and generate an anonymized smart contract proof containing a zero-knowledge audit path through a plurality of blockchain nodes in the decision network according to the zero-knowledge proof binding tag and the mathematical binding relationship.

[0133] The data homomorphic encryption system based on privacy protection of the embodiment is used to implement the aforementioned data homomorphic encryption method based on privacy protection, and thus the specific embodiments in the data homomorphic encryption system based on privacy protection can refer to the embodiment part of the data homomorphic encryption method based on privacy protection in the foregoing, and the specific embodiments can refer to the description of the respective embodiment parts, which will not be repeated here.

[0134] The application further provides an electronic device, including a memory for storing a computer program, and a processor for executing the computer program to implement the steps of the data homomorphic encryption method based on privacy protection.

[0135] The application further provides a computer readable storage medium, and the computer readable storage medium stores a computer program.

[0136] In an example embodiment, the computer readable storage medium can include, but is not limited to, a U disk, a read-only memory, a random access memory, a mobile hard disk, a magnetic disk or an optical disk, and various media capable of storing a computer program.

[0137] The embodiments of the application further provide a computer program product, and the computer program product includes a computer program, and the computer program is executed by a processor to implement the steps in the privacy protection based data homomorphic encryption method.

[0138] The skilled person can further realize that the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein can be realized by electronic hardware, computer software or a combination of both. In order to clearly illustrate the interchangeability of hardware and software, the components and steps of the examples have been described in the above description in general terms. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. The skilled person can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the application.

[0139] The above describes in detail the privacy protection based data homomorphic encryption method and system provided by the application. The principles and implementation manners of the application are described by using specific examples in this paper, and the above example description is only used to help understand the method of the application and its core idea. It should be pointed out that for ordinary skilled person in the art, without departing from the principles of the application, the application can be improved and modified in several ways, and these improvements and modifications also fall within the protection scope of the application.

Claims

1. A privacy-preserving homomorphic encryption method for data, characterized in that, include: By fusing structured econometric data with unstructured topological data, a dataset to be encrypted with privacy attributes is generated. The physical non-cloning property of the hardware trust module provides a root of trust for the blockchain node, and a clock synchronization factor is derived from the root of trust to drive the obfuscation operation to perform block position obfuscation and nonlinear transformation on the dataset to be encrypted, thereby generating a tamper-resistant blockchain-ready data stream. Homomorphic encryption based on polynomial rings is implemented on the blockchain-ready data stream in the main encryption channel to construct an algebraic structure ciphertext block that supports ciphertext arithmetic operations. In the auxiliary verification channel, a zero-knowledge proof binding label is generated based on the cryptographic digest of the algebraic structure ciphertext block and the clock synchronization factor. Simultaneously, a mathematical binding relationship is established with the main channel through a shared random source. The auxiliary verification channel refers to a parallel channel used to assist in verifying the processing results of the main encryption channel and ensure data integrity. The mathematical binding relationship refers to linking the processing results of the two channels through a mathematical function. The algebraic structure ciphertext block is input into a decision network composed of blockchain nodes, so that multiple blockchain nodes in the decision network can output a verification conclusion that can be directly written into the blockchain and generate an anonymous smart contract proof containing a zero-knowledge audit path based on the zero-knowledge proof binding label and the mathematical binding relationship. The blockchain nodes include a head node, intermediate nodes, and a terminal node, including: The process of generating an anonymous smart contract proof containing a zero-knowledge audit path by having multiple blockchain nodes in the decision network output a verification conclusion that can be directly written into the blockchain based on the zero-knowledge proof binding label and the mathematical binding relationship includes: The first node in the decision network performs a homomorphic comparison operation on the privacy-sensitive field using the mathematical binding relationship to generate ciphertext with a first-level state tag. By using the zero-knowledge proof-bound tag-dynamically calibrated inference matrix through the intermediate node chain, multi-level ciphertext state transition calculations are performed on the ciphertext with the first-level state tag to generate ciphertext with the final state tag. The ciphertext with the final state marker is aggregated by the terminal node, and a distributed key reconstruction mechanism based on threshold cryptography is adopted to perform collaborative decryption. The output is a verification conclusion that can be directly written into the blockchain and an anonymized smart contract proof containing a zero-knowledge audit path is generated.

2. The method according to claim 1, characterized in that, The process involves aggregating the ciphertext with the final state marker through terminal nodes, employing a threshold cryptography-based distributed key reconstruction mechanism and performing collaborative decryption, outputting a verification conclusion that can be directly written into the blockchain, and generating an anonymous smart contract proof containing a zero-knowledge audit path, including: Ciphertext with final state markers is collected through terminal nodes and combined sequentially into aggregated ciphertext blocks; The terminal node initiates a key reconstruction request for the secret key in the homomorphic encryption key to multiple blockchain nodes in the decision network. The blockchain nodes hold a key portion of the secret key and send the key portion to the terminal node through a secure channel. The key portion received by the terminal node that reaches a preset threshold number is reconstructed into a complete decryption key using a polynomial interpolation method. The aggregated ciphertext block is decrypted using the complete decryption key to obtain a verification conclusion in plaintext form. Based on the verification conclusion and the zero-knowledge proof binding tag, a zero-knowledge audit path is generated. The zero-knowledge audit path links all operation steps through a hash chain without disclosing sensitive information. The verification conclusion and the zero-knowledge audit path are encapsulated into a smart contract, and the smart contract is anonymized by removing all node identity information to generate an anonymized smart contract proof.

3. The method according to claim 1, characterized in that, Homomorphic encryption based on a polynomial ring is performed on the blockchain-ready data stream in the main encryption channel to construct an algebraic structure ciphertext block that supports ciphertext arithmetic operations, including: The blockchain-ready data stream is divided into fixed-size data blocks in the main cryptographic channel, and the data blocks are mapped onto a polynomial ring. The polynomial ring is selected as the cryptographic algebra structure to generate a homomorphic encryption key, including a public key for performing encryption operations and a secret key for subsequent decryption operations. The data block is encrypted using the public key, and the plaintext data block is converted into a ciphertext polynomial through polynomial multiplication and other operations. All ciphertext polynomials are combined sequentially into a ciphertext sequence, forming an algebraic structure ciphertext block.

4. The method according to claim 1, characterized in that, The process involves using the physical non-cloning property of the hardware trust module to provide a root of trust for blockchain nodes, and deriving a clock synchronization factor based on the root of trust to drive obfuscation operations and perform block position obfuscation and nonlinear transformation on the dataset to be encrypted, generating a tamper-resistant blockchain-ready data stream, including: A time-dependent sequence value is derived from the root of trust as a clock synchronization factor, which is updated synchronously by a hardware clock and a counter. Using the clock synchronization factor as a random seed, the obfuscation engine is driven to obfuscate the block positions of the dataset to be encrypted. By rearranging the order of the data blocks, the original data layout is adjusted to obtain a data stream with obfuscated block positions. Simultaneously, the clock synchronization factor is used to initialize the nonlinear transformation function, and nonlinear replacement and permutation operations are performed on the contents of the data block to change the distribution of data values ​​and obtain a data stream after nonlinear transformation. By combining the data stream that has undergone block location obfuscation and the data stream that has undergone non-linear transformation, a tamper-resistant blockchain-ready data stream is generated.

5. The method according to claim 1, characterized in that, In the secondary verification channel, a zero-knowledge proof binding label is generated based on the cryptographic digest of the algebraic structure ciphertext block and the clock synchronization factor, and a mathematical binding relationship is simultaneously established with the main channel through a shared random source, including: A fixed-length digest value is generated by computing the cryptographic digest of the algebraic structure ciphertext block using a hash function. The clock synchronization factor and the digest value are mixed, and a binding seed is generated through XOR operation or other mixing functions; The zero-knowledge proof protocol is run with the binding seed as a randomness parameter. The zero-knowledge proof protocol takes the algebraic structure ciphertext block as the proof object and outputs a proof label that can prove its integrity without revealing its content, which serves as the zero-knowledge proof binding label. Simultaneously, the main encryption channel and the auxiliary verification channel synchronously obtain the same random value from the shared random source; The random value is combined with the zero-knowledge proof binding tag through a mathematical function to establish a mathematical binding relationship between the main encryption channel and the secondary verification channel.

6. The method according to claim 1, characterized in that, By fusing structured econometric data with unstructured topological data, a dataset to be encrypted with privacy attributes is generated, including: Collect structured econometric data stored in tabular form and unstructured topological data stored in graph or network form; The fields of the structured measurement data are standardized and encoded, and the nodes and edges in the unstructured topological data are mapped to vector representations to convert the structured measurement data and unstructured topological data into a unified data format. The converted structured measurement data and the unstructured topology data are associated by field and connected by a common identifier; The associated data is labeled with privacy attributes, and privacy tags are added according to the sensitivity of the data to form a dataset to be encrypted carrying privacy attributes.

7. A privacy-preserving homomorphic encryption system for data, characterized in that, include: The generation module is used to merge structured econometric data and unstructured topological data to generate a dataset to be encrypted carrying privacy attributes; The second generation module is used to provide a root of trust for blockchain nodes through the physical non-cloning characteristics of the hardware trust module, and derive a clock synchronization factor based on the root of trust to drive the obfuscation operation to perform block position obfuscation and nonlinear transformation on the dataset to be encrypted, thereby generating a tamper-resistant blockchain ready data stream. A construction module is used to implement homomorphic encryption based on polynomial rings on the blockchain-ready data stream in the main encryption channel, and to construct an algebraic structure ciphertext block that supports ciphertext arithmetic operations. A module is established to generate a zero-knowledge proof binding label in the auxiliary verification channel based on the cryptographic digest of the algebraic structure ciphertext block and the clock synchronization factor, and synchronously establish a mathematical binding relationship with the main channel through a shared random source. The auxiliary verification channel refers to a parallel channel used to assist in verifying the processing results of the main encryption channel and ensure data integrity. The mathematical binding relationship refers to associating the processing results of the two channels through a mathematical function. The output module is used to input the algebraic structure ciphertext block into a decision network composed of blockchain nodes, so that multiple blockchain nodes in the decision network can output a verification conclusion that can be directly written into the blockchain and generate an anonymous smart contract proof containing a zero-knowledge audit path based on the zero-knowledge proof binding label and the mathematical binding relationship. The blockchain nodes include a head node, intermediate nodes, and a terminal node, including: The process of generating an anonymous smart contract proof containing a zero-knowledge audit path by having multiple blockchain nodes in the decision network output a verification conclusion that can be directly written into the blockchain based on the zero-knowledge proof binding label and the mathematical binding relationship includes: The first node in the decision network performs a homomorphic comparison operation on the privacy-sensitive field using the mathematical binding relationship to generate ciphertext with a first-level state tag. By using the zero-knowledge proof-bound tag-dynamically calibrated inference matrix through the intermediate node chain, multi-level ciphertext state transition calculations are performed on the ciphertext with the first-level state tag to generate ciphertext with the final state tag. The ciphertext with the final state marker is aggregated by the terminal node, and a distributed key reconstruction mechanism based on threshold cryptography is adopted to perform collaborative decryption. The output is a verification conclusion that can be directly written into the blockchain and an anonymized smart contract proof containing a zero-knowledge audit path is generated.

8. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor, configured to implement the steps of the privacy-preserving homomorphic data encryption method as described in any one of claims 1 to 6 when executing the computer program.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, enables the implementation of the privacy-preserving homomorphic encryption method for data as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Homomorphic encryption system and homomorphic encryption execution method based on reconfigurable technology

    CN113660076A

  • Homomorphic encryption-based block chain supervisible zero-knowledge proof verification method

    CN116502266A