Data privacy protection effect evaluation method and device, storage medium and program product

By simulating the operational characteristics of a fully homomorphic encryption coprocessor and key-data binding deviation reports, a hardware side-channel leakage risk vector and a key management defect score are generated. This solves the problem of evaluating the effectiveness of data privacy protection in fully homomorphic encryption scenarios, achieves multi-dimensional evaluation and quantification, and provides a comprehensive score that is comparable and interpretable.

CN120893067APending Publication Date: 2025-11-04CHINA UNITED NETWORK COMM GRP CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510977442.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-15
Publication Date
2025-11-04

AI Technical Summary

Technical Problem

How to effectively evaluate the data privacy protection effect in fully homomorphic encryption scenarios, especially the ability to resist side-channel attacks and key management vulnerabilities.

Method used

By simulating the operational characteristics of a fully homomorphic encryption coprocessor, a hardware side-channel leakage risk vector and a key-data binding deviation report are generated. Combined with side-channel vulnerability scores and key management defect scores, a multi-dimensional fusion evaluation is performed to generate a comprehensive privacy protection score for the fully homomorphic encryption scenario.

Benefits of technology

It provides a multi-dimensional evaluation method that can accurately assess the data privacy protection effect in fully homomorphic encryption scenarios, identify and quantify the ability to resist side-channel attacks and key management vulnerabilities, and generate a comprehensive score that is comparable and interpretable.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120893067A_ABST
    Figure CN120893067A_ABST
Patent Text Reader

Abstract

The invention provides a data privacy protection effect evaluation method and device, a storage medium and a program product, and relates to the technical field of data analysis. The method comprises the following steps: carrying out simulation attack based on operation characteristics during operation of the fully homomorphic encryption coprocessor, and generating a hardware side channel leakage risk vector; performing association matching based on the key state change event and the ciphertext data survival period, and generating a key-data binding deviation report; based on the hardware side channel leakage risk vector and the key-data binding deviation report, performing quantitative evaluation on the bypass attack resistance and key management vulnerability of the fully homomorphic encryption scheme, and generating a side channel vulnerability score and a key management defect score; and determining a privacy protection comprehensive score of the fully homomorphic encryption scene based on the side channel vulnerability score and the key management defect score. The method is used for effectively evaluating the data privacy protection effect in the fully homomorphic encryption scene.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data analysis, and particularly relates to a data privacy protection effect evaluation method and device, a storage medium and a program product. BACKGROUND

[0002] With the rapid development of digital economy, data has become a key production factor, and the problem of data privacy protection has become increasingly prominent. In terms of classification of data privacy protection technology, according to different protection principles, it is mainly divided into methods based on cryptography (such as fully homomorphic encryption, secure multi-party computation), methods based on perturbation (such as differential privacy, data desensitization), methods based on architecture (such as federated learning, trusted execution environment) and hybrid methods.

[0003] Therefore, how to effectively evaluate the actual effect of privacy protection technology has become a problem that needs to be solved. SUMMARY

[0004] The present application provides a data privacy protection effect evaluation method, device, storage medium and program product, and provides a method for effectively evaluating the data privacy protection effect in the fully homomorphic encryption scenario.

[0005] In a first aspect, the present application provides a data privacy protection effect evaluation method, which comprises: performing simulation attacks based on operation characteristics of a fully homomorphic encryption coprocessor runtime, to generate a hardware side channel leakage risk vector; performing correlation matching based on key state change events and ciphertext data survival periods, to generate a key-data binding bias report; the key-data binding bias report is used to represent the time window difference existing between the key validity period and the ciphertext data survival period; based on the hardware side channel leakage risk vector and the key-data binding bias report, the anti-side channel attack ability and the key management vulnerability of the fully homomorphic encryption scheme are quantitatively evaluated, to generate a side channel vulnerability score and a key management defect score; based on the side channel vulnerability score and the key management defect score, a comprehensive privacy protection score of the fully homomorphic encryption scenario is determined.

[0006] Optionally, a simulated attack is performed based on the operational characteristics of the fully homomorphic encryption coprocessor to generate a hardware side-channel leakage risk vector. This includes: acquiring the operational characteristics of the fully homomorphic encryption coprocessor during runtime and generating a hardware operational characteristic set; the operational characteristics include at least one of the following: memory access timing characteristics, electromagnetic radiation waveform characteristics, and instruction execution cycle characteristics; based on the hardware operational characteristic set, a side-channel attack simulation engine is used to inject multimodal attack vectors of timing correlation attacks, electromagnetic template attacks, and power consumption analysis attacks to generate a potential leakage path pattern cluster; for each potential leakage path in the potential leakage path pattern cluster, correlation parameters and observability parameters are extracted; correlation parameters include the probability of cooperation with other potential leakage paths; observability parameters include signal strength and / or parsing difficulty score; based on correlation parameters, observability parameters, and preset grading rules, the risk level of each potential leakage path is determined; key risk paths with risk levels higher than the level threshold are selected from the potential leakage path pattern cluster; and a hardware side-channel leakage risk vector is generated based on the key risk paths.

[0007] Optionally, based on the hardware side-channel leakage risk vector and key-data binding deviation report, the resistance to side-channel attacks and key management vulnerabilities of the fully homomorphic encryption scheme are quantitatively evaluated, generating a side-channel vulnerability score and a key management defect score. This includes: based on the hardware side-channel leakage risk vector, performing threat modeling on the temporal correlation of memory access patterns and the resolvability of electromagnetic radiation signals to generate a memory access pattern leakage path map and an electromagnetic side-channel threat value; based on the key-data binding deviation report, performing risk probability inference on the overlapping areas of key validity period and ciphertext data lifespan to generate a key access permission overrun risk level; and through a preset fragility mapping rule base, performing multi-factor normalization weighting processing on the memory access pattern leakage path map, electromagnetic side-channel threat value, and key access permission overrun risk level to generate a side-channel vulnerability score and a key management defect score.

[0008] Optionally, based on the key-data binding deviation report, risk probability inference is performed on the overlapping area of ​​key validity period and ciphertext data lifespan to generate a key access control out-of-bounds risk level, including: calculating the key access control out-of-bounds risk level according to the following formula:

[0009]

[0010] Among them, D overlap L represents the maximum or minimum value of cross-over overlap. k W represents the length of the k-th overlapping interval. k V represents the weight of the k-th overlapping interval. k R represents the degree of violation in the k-th interval, m represents the number of overlapping intervals, α and β represent balance factors, and Rrisk denotes the key privilege boundary crossing risk level, O i denotes the survival period of the i th ciphertext data, K i denotes the validity period of the i th key, T total denotes the total time period, P(E i ) denotes the i th boundary crossing event occurrence probability, n denotes the number of ciphertext data-key binding pairs.

[0011] Optionally, based on the key-data binding deviation report, the risk probability inference is performed on the cross-overlapping area of the key validity period and the ciphertext data survival period to generate the key privilege boundary crossing risk level, including: based on the key state change sequence in the key-data binding deviation report and the data survival period label, the time window of the key validity period and the ciphertext data survival period is dynamically segmented to generate a cross-overlapping time slice set; using the following formula, the operation path that can still access the corresponding ciphertext data after the key failure in the cross-overlapping time slice set is processed by the Bayesian network model to generate a key privilege boundary crossing risk probability value:

[0012]

[0013] wherein Z denotes the key privilege boundary crossing risk probability value, β i denotes the risk coefficient of the i th operation path, D i denotes the amount of ciphertext data, S i denotes the security threshold, γ i denotes the time sensitivity coefficient, t i denotes the operation duration, and m denotes the number of operation paths; based on the current business scenario and the preset scenario weight corresponding relationship, the key privilege boundary crossing risk probability value is weighted and matched to determine the key privilege boundary crossing risk level.

[0014] Optionally, based on the side channel vulnerability score and the key management defect score, a privacy protection comprehensive score of the fully homomorphic encryption scene is determined, including: the side channel vulnerability score and the key management defect score are hierarchically weighted and aggregated to generate a hierarchical fusion intermediate vector; based on a predefined score quantization mapping table, the hierarchical fusion intermediate vector is processed by cross-dimension normalization conversion to generate a privacy protection comprehensive score of the fully homomorphic encryption scene.

[0015] The data privacy protection effect evaluation method provided in the application can simulate attacks based on operation characteristics of a full homomorphic encryption coprocessor runtime to generate a hardware side channel leakage risk vector; perform associated matching based on key state change events and ciphertext data survival periods to generate a key-data binding deviation report; the key-data binding deviation report is used to represent a time window difference existing between a key validity period and a ciphertext data survival period; based on the hardware side channel leakage risk vector and the key-data binding deviation report, the anti-side channel attack capability and key management vulnerabilities of a full homomorphic encryption scheme are quantitatively evaluated to generate a side channel vulnerability score and a key management defect score; and based on the side channel vulnerability score and the key management defect score, a privacy protection comprehensive score of a full homomorphic encryption scene is determined. In this way, through multi-dimensional fusion processing of the side channel vulnerability score and the key management defect score, the data privacy protection effect in a full homomorphic encryption scene can be effectively evaluated from multiple dimensions, thereby providing a method for effectively evaluating the data privacy protection effect in a full homomorphic encryption scene.

[0016] In a second aspect, the application provides a data privacy protection effect evaluation device, which comprises various functional modules for the method in the first aspect.

[0017] In a third aspect, the application provides a computer program product, which comprises computer instructions; when the computer instructions are run on an electronic device, the electronic device implements the method in the first aspect.

[0018] In a fourth aspect, the application provides an electronic device, which comprises a processor and a memory; the memory stores instructions executable by the processor; and the processor is configured to execute the instructions to cause the electronic device to implement the method in the first aspect.

[0019] In a fifth aspect, the application provides a readable storage medium, which comprises software instructions; when the software instructions are run on an electronic device, the electronic device implements the method in the first aspect.

[0020] The advantages of the second aspect to the fifth aspect are as described in the first aspect, and will not be described again. BRIEF DESCRIPTION OF DRAWINGS

[0021] In order to more clearly illustrate the technical solutions in the embodiments of the application or the prior art, the following will briefly introduce the drawings needed in the embodiments or the prior art description. Obviously, the drawings in the following description only some embodiments of the application, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of these drawings.

[0022] Figure 1A flowchart of a data privacy protection effect evaluation method provided by an embodiment of the present application is shown in FIG. 1.

[0023] Figure 2 A flowchart of another data privacy protection effect evaluation method provided by an embodiment of the present application is shown in FIG. 2.

[0024] Figure 3 A flowchart of still another data privacy protection effect evaluation method provided by an embodiment of the present application is shown in FIG. 3.

[0025] Figure 4 A flowchart of still another data privacy protection effect evaluation method provided by an embodiment of the present application is shown in FIG. 4.

[0026] Figure 5 A flowchart of still another data privacy protection effect evaluation method provided by an embodiment of the present application is shown in FIG. 5.

[0027] Figure 6 A flowchart of still another data privacy protection effect evaluation method provided by an embodiment of the present application is shown in FIG. 6.

[0028] Figure 7 A composition diagram of a data privacy protection effect evaluation device provided by an embodiment of the present application is shown in FIG. 7.

[0029] Figure 8 A composition diagram of an electronic device provided by an embodiment of the present application is shown in FIG. 8. DETAILED DESCRIPTION

[0030] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of protection of the present application.

[0031] It should be noted that the words “exemplarily” or “for example” in the embodiments of the present application are used to represent as an example, illustration or explanation. Any embodiment or design scheme described as “exemplarily” or “for example” in the embodiments of the present application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. In fact, the words “exemplarily” or “for example” are used to present the relevant concepts in a specific way.

[0032] In order to clearly describe the technical solutions in the embodiments of the present application, in the embodiments of the present application, the words “first”, “second” and the like are used to distinguish the same or similar items or items with basically the same function and role. Those skilled in the art can understand that the words “first”, “second” and the like are not used to limit the quantity and execution order.

[0033] With the rapid development of digital economy, data has become a key production factor, and data privacy protection issues have become increasingly prominent. In terms of classification of data privacy protection technology, according to different protection principles, it is mainly divided into methods based on cryptography (such as fully homomorphic encryption, secure multi-party computation), methods based on perturbation (such as differential privacy, data desensitization), methods based on architecture (such as federated learning, trusted execution environment) and hybrid methods.

[0034] Therefore, how to effectively evaluate the actual effect of privacy protection technology has become a problem that needs to be solved.

[0035] Based on this, the embodiment of the application provides a data privacy protection effect evaluation method, device, storage medium and program product, which can accurately and effectively evaluate the data privacy protection effect in the fully homomorphic encryption scenario.

[0036] The execution subject of the data privacy protection effect evaluation method provided by the embodiment of the application is a data privacy protection effect evaluation device, which can be a computer or a server or other electronic devices with computing processing function; or the data privacy protection effect evaluation device can also be a processor (such as a central processing unit (CPU)) in the foregoing electronic device; or the data privacy protection effect evaluation device can also be a platform or software system deployed in the foregoing electronic device; or the data privacy protection effect evaluation device is also a functional module for executing the data privacy protection effect evaluation method in the foregoing electronic device. The embodiment of the application does not make any limitation.

[0037] For the sake of simplicity, the execution subject of the data privacy protection effect evaluation method provided by the embodiment of the application is taken as an example to introduce the data privacy protection effect evaluation device.

[0038] Figure 1 A flowchart of a data privacy protection effect evaluation method provided by the embodiment of the application. As shown in the figure, the method comprises the following steps: Figure 1

[0039] S101, simulate attacks based on the operation characteristics of the fully homomorphic encryption coprocessor runtime, and generate a hardware side channel leakage risk vector.

[0040] ​For example, the data privacy protection effect evaluation device can first capture the memory access timing, electromagnetic radiation waveform, instruction execution period and other operation characteristics of the full homomorphic encryption coprocessor runtime in real time to form a hardware operation characteristic set. Then, the side channel attack simulation engine simulates the multi-modal attack vectors such as timing correlation attack, electromagnetic template attack and power analysis attack based on the set to generate a potential leakage path pattern cluster. Then, the risk pattern clustering engine performs dynamic threshold segmentation according to the correlation and observability of the potential leakage path pattern cluster to generate a hardware side channel leakage risk vector that labels each side channel leakage point and risk level, providing a hardware level risk basis for subsequent security evaluation of the full homomorphic encryption scheme.

[0041] In some embodiments, Figure 2 Another data privacy protection effect evaluation method provided by the embodiments of the present application is shown in the flowchart. As shown in Figure 2 The S101 can specifically include the following steps:

[0042] S1011, obtaining operation characteristics of the full homomorphic encryption coprocessor runtime to generate a hardware operation characteristic set.

[0043] The operation characteristics include at least one of the following: memory access timing characteristics, electromagnetic radiation waveform characteristics, and instruction execution period characteristics.

[0044] As an example, the data privacy protection effect evaluation device can capture multiple runtime operation characteristics of the full homomorphic encryption coprocessor in real time through the hardware behavior monitoring module. The memory access timing characteristics, i.e. the time sequence and frequency information of the coprocessor when accessing the memory, help to find out whether the memory operation has a regular pattern; at the same time, the electromagnetic radiation waveform characteristics, i.e. the strength, frequency and waveform change of the electromagnetic radiation signal generated by the coprocessor when running; in addition, the instruction execution period characteristics, i.e. the time period consumed by the coprocessor to execute different instructions. The above captured characteristics are integrated into a complete hardware operation characteristic set. Based on the hardware operation characteristic set, the side channel attack simulation engine is used to inject multiple multi-modal attack vectors. The simulation engine will simulate timing correlation attack in turn, find out the time regularity related to the key by analyzing the time interval and execution order between the operation steps.

[0045] S1012, based on the hardware operation characteristic set, using the side channel attack simulation engine to inject multi-modal attack vectors of timing correlation attack, electromagnetic template attack and power analysis attack, and generate a potential leakage path pattern cluster.

[0046] Exemplarily, for the simulation of electromagnetic template attack part, the data privacy protection effect evaluation device can compare the pre-constructed electromagnetic radiation feature template with the actually captured electromagnetic radiation signal to see if there is a pattern that can be exploited to infer the key; for the simulation of power analysis attack part, the data privacy protection effect evaluation device can analyze the power consumption changes of the fully homomorphic encryption coprocessor at different operation stages to explore whether the power consumption fluctuation is related to the key operation, thereby generating a potential leakage path pattern cluster. Then, through the risk pattern clustering engine, the correlation and observability of the potential leakage path pattern cluster are dynamically threshold segmented. The risk pattern clustering engine will analyze and screen the potential leakage path pattern cluster according to the set dynamic threshold, identify the paths with strong correlation and high observability, and generate a hardware side channel leakage risk vector to quantify the leakage risk degree of the fully homomorphic encryption coprocessor in the hardware side channel.

[0047] S1013, for each potential leakage path in the potential leakage path pattern cluster, extract the correlation parameter and the observability parameter of each potential leakage path.

[0048] As an example, the correlation parameter can include the cooperative probability with other potential leakage paths; the observability parameter can include the signal strength and / or the analysis difficulty score.

[0049] S1014, based on the correlation parameter and the observability parameter and the preset grading rule, determine the risk level of each potential leakage path.

[0050] S1015, select a key risk path with a risk level higher than a threshold from the potential leakage path pattern cluster.

[0051] S1016, generate a hardware side channel leakage risk vector based on the key risk path.

[0052] As an example, the hardware side channel leakage risk vector can be understood as a structured representation of the side channel risk of the fully homomorphic encryption coprocessor. For example, the hardware side channel leakage risk vector can include the specific location of each leakage path (such as the timing correlation path of memory address 0x1234), the corresponding risk level (such as “high risk: 8 points”), and the associated path information (such as “cooperatively leaked with electromagnetic radiation path P5”) and the like.

[0053] S102, based on the key state change event and the ciphertext data survival period, perform correlation matching to generate a key-data binding deviation report.

[0054] The key-data binding deviation report is used to represent the time window difference between the key validity period and the ciphertext data survival period. For example, the key-data binding deviation report can include a key state change sequence and a data survival period label.

[0055] For example, the data privacy protection effect evaluation device can monitor key state change events through a key life cycle tracking system, record the complete course of the key from generation to destruction, including the state change information of each stage such as generation, distribution, use, update, revocation, etc. The data privacy protection effect evaluation device can analyze the survival period of the ciphertext data through the data life cycle parser, and clearly understand the different stages and time ranges of the data from creation to final destruction. When performing timing alignment processing, the key state change event is associated and matched with the survival period of the ciphertext data to determine the correspondence between the two in time, identify the time window difference between the key validity period and the data survival period, that is, the inconsistent state that the data still survives after the key expires or the data has been destroyed but the key is still valid, and generate a key-data binding deviation report to provide a basis for subsequent evaluation of key management vulnerabilities in the fully homomorphic encryption scheme.

[0056] S103, based on the hardware side channel leakage risk vector and the key-data binding deviation report, quantitatively evaluate the anti-side channel attack ability and key management vulnerability of the fully homomorphic encryption scheme, and generate a side channel vulnerability score and a key management defect score.

[0057] For example, the data privacy protection effect evaluation device can analyze the timing correlation of the memory access mode, observe the regularity that can be exploited by side channel attacks, such as the association of the time interval and execution order between specific operation steps with key information, and thus construct a memory access mode leakage path map. At the same time, the resolvability of the electromagnetic radiation signal is evaluated to determine the degree to which the electromagnetic radiation signal is easily resolved to obtain sensitive information of internal operations, and thus determine the electromagnetic side channel threat value. Then, according to the key-data binding deviation report, the Bayesian network model is used to infer the risk probability of the overlapping interval of the data survival period within the key validity period. By analyzing the key state change sequence and the data survival period label, the time window of the key validity period and the data survival period is dynamically divided to generate a set of cross-overlapping time slices. Based on the set, the operation path that can still access the corresponding ciphertext data after the key is invalid is deduced, the privilege boundary risk probability value is calculated, and the key privilege boundary risk level is generated by weighted matching combined with the criticality label of the business scenario. Then, with the help of a pre-set vulnerability mapping rule library, the memory access mode leakage path map, the electromagnetic side channel threat value, and the key privilege boundary risk level are subjected to multi-factor normalization and weighted processing, thereby generating a side channel vulnerability score and a key management defect score.

[0058] In some embodiments, Figure 3 A flowchart of another method for evaluating the data privacy protection effect is provided in some embodiments of the application. As shown in Figure 3 S103 can include the following steps:

[0059] S1031, threat modeling the timing correlation of the memory access pattern and the resolvability of the electromagnetic radiation signal based on the hardware side channel leakage risk vector, to generate a memory access pattern leakage path atlas and an electromagnetic side channel threat value.

[0060] S1032, risk probability inference on the cross-overlapping area of the key validity period and the ciphertext data survival period based on the key-data binding bias report, to generate a key permission boundary risk level.

[0061] As an example, S1032 can specifically include calculating the key permission boundary risk level according to the following formula:

[0062]

[0063] In formula (1) and formula (2), D overlap represents the maximum value of the cross-overlapping degree, L k represents the length of the kth overlapping interval, W k represents the weight of the kth overlapping interval, V k represents the violation degree of the kth interval, m represents the number of overlapping intervals, and a and β represent balance factors, R risk represents the key permission boundary risk level, O i represents the survival period of the ith ciphertext data, K i represents the validity period of the ith key, T total represents the total time period, P(E i ) represents the probability of the occurrence of the ith boundary event, and n represents the number of ciphertext data-key binding pairs.

[0064] It should be noted that based on the hardware side channel leakage risk vector, the timing correlation of the memory access mode and the resolvability of the electromagnetic radiation signal are threat modeled. The timing correlation analysis of the memory access mode mainly focuses on the time interval and execution order of the memory read and write operations, and judges whether there is a rule related to the key-related information. The resolvability evaluation of the electromagnetic radiation signal focuses on whether the electromagnetic radiation signal generated by the coprocessor during operation can be easily resolved to obtain sensitive information of internal operation, and then determines the electromagnetic side channel threat value. Then, based on the key-data binding deviation report, the risk probability inference processing is performed on the cross-overlapping interval of the data survival period within the key validity period. By analyzing the key state change sequence and the data survival period label, the time window of the key validity period and the data survival period is dynamically divided, and a cross-overlapping time slice set is generated. Then, using the Bayesian network model, the operation path that can still access the corresponding ciphertext data after the key is invalid in the cross-overlapping time slice set is probabilistically deduced, and the key authority boundary risk level is generated by weighted matching processing combined with the criticality label of the business scenario.

[0065] Then, through the preset vulnerability mapping rule library, the memory access mode leakage path map, the electromagnetic side channel threat value and the key authority boundary risk level are subjected to multi-factor normalization weighting processing to generate a side channel vulnerability score and a key management defect score. In this process, the importance weight of different factors is fully considered, and each risk factor is normalized to eliminate the dimensional difference and numerical range difference that may exist between different evaluation dimensions, so that the generated score is more comparable and interpretable.

[0066] As another example, Figure 4 A flowchart of another data privacy protection effect evaluation method provided by an embodiment of the present application is shown in FIG. 10. As shown in FIG. 10, Figure 4 The above S1032 can specifically include the following steps:

[0067] S10321, based on the key state change sequence and the data survival period label in the key-data binding deviation report, the time window of the key validity period and the ciphertext data survival period is dynamically divided to generate a cross-overlapping time slice set.

[0068] S10322, through the Bayesian network model, the operation path that can still access the corresponding ciphertext data after the key is invalid in the cross-overlapping time slice set is probabilistically deduced to generate a key authority boundary risk probability value.

[0069] As an example, the data privacy protection effect evaluation device can calculate the key authority boundary risk probability value by the following formula:

[0070]

[0071] In formula (3), Z represents the key permission boundary risk probability value, β i represents the risk coefficient of the i-th operation path, D i represents the amount of ciphertext data, S i represents the security threshold, γ i represents the time sensitivity coefficient, t i represents the operation duration, and m represents the number of operation paths.

[0072] S10323, based on the current business scenario and the preset scenario weight correspondence relationship, the key permission boundary risk probability value is weighted and matched, and the key permission boundary risk level is determined.

[0073] It should be noted that, according to the key state change sequence in the key-data binding deviation report and the data survival period label, the time window of the key validity period and the data survival period is dynamically segmented, and the above process will subdivide the key validity period and the data survival period into multiple time segments, generate a cross-overlapping time slice set, in order to more accurately locate the overlapping relationship of the key and the data in time. Then, the Bayesian network model is used to perform probability inference processing on the operation path that can still access the corresponding ciphertext data after the key is invalid in the cross-overlapping time slice set. Among them, the Bayesian network model will analyze the possibility of different operation paths still being able to access the ciphertext data after the key is invalid according to the existing prior knowledge and the collected data. In this process, the risk coefficient of the operation path, the amount of ciphertext data, the security threshold, the time sensitivity coefficient and the operation duration and other factors are considered, and the permission boundary risk probability value is calculated by probability.

[0074] Then, based on the preset scene dynamic weight table, the permission boundary risk probability value and the criticality label of the business scenario are weighted and matched. Different business scenarios have different tolerance and sensitivity to key permission boundary risk, and the scene dynamic weight table allocates weights to different risk factors according to the criticality of the business scenario. By weighted matching, the permission boundary risk probability value and the criticality of the business scenario are combined to generate a key permission boundary risk level. The risk level can provide an important basis for subsequent security decision and privacy protection strategy formulation.

[0075] S1033, through the preset fragility mapping rule library, the memory access mode leakage path map, the electromagnetic side channel threat value and the key permission boundary risk level are multi-factor normalized and weighted to generate a side channel vulnerability score and a key management defect score.

[0076] For example, the data privacy protection effect evaluation device can perform threat modeling processing on the time correlation of the memory access mode and the resolvability of the electromagnetic radiation signal based on the hardware side channel leakage risk vector. The time correlation analysis of the memory access mode mainly focuses on the time interval and execution order of the memory read-write operation, and judges whether there is a rule related to the key-related information. The resolvability evaluation of the electromagnetic radiation signal focuses on whether the electromagnetic radiation signal generated by the coprocessor during operation can be easily resolved to obtain sensitive information of internal operation, and then determines the electromagnetic side channel threat value. Then, based on the key-data binding deviation report, the risk probability inference processing is performed on the cross-overlapping interval of the data survival period within the key validity period. By analyzing the key state change sequence and the data survival period label, the time window of the key validity period and the data survival period is dynamically divided, and a cross-overlapping time slice set is generated. Then, using the Bayesian network model, the operation path that can still access the corresponding ciphertext data after the key is invalid in the cross-overlapping time slice set is probabilistically deduced, and the key permission boundary risk level is generated by combining the key label of the business scenario for weighted matching processing.

[0077] Then, through the preset vulnerability mapping rule library, the memory access mode leakage path map, the electromagnetic side channel threat value and the key permission boundary risk level are subjected to multi-factor normalization weighting processing to generate a side channel vulnerability score and a key management defect score. In this process, the importance weight of different factors is fully considered, and each risk factor is normalized to eliminate the dimensional difference and numerical range difference that may exist between different evaluation dimensions, so that the generated score is more comparable and interpretable.

[0078] S104, based on the side channel vulnerability score and the key management defect score, determine the privacy protection comprehensive score of the fully homomorphic encryption scene.

[0079] For example, the data privacy protection effect evaluation device can perform dynamic weight coefficient allocation processing on the evaluation dimensions of the side channel vulnerability score and the key management defect score based on the security policy label of the fully homomorphic encryption scenario, to generate a multi-dimensional evaluation weight parameter. The above process fully considers the importance of each evaluation dimension under different security policies. For example, in some scenarios that require high real-time performance, the vulnerability of side channel attacks may have a higher weight; while in scenarios that focus more on key security, the weight of key management defects may be greater. Through the multi-rule library driven fusion engine, the side channel vulnerability score, the key management defect score, and the multi-dimensional evaluation weight parameter are subjected to hierarchical weighted aggregation processing to generate a hierarchical fusion intermediate vector. In this stage, a plurality of pre-set rule libraries are used to perform weighted calculation on each score according to different rules, so as to ensure that the fused intermediate vector can more comprehensively and accurately reflect the comprehensive influence of each evaluation dimension. This step involves multiple levels of processing to fully integrate information from different dimensions. Then, based on a pre-defined score quantization mapping table, the hierarchical fusion intermediate vector is subjected to cross-dimension normalization conversion processing to generate a privacy protection comprehensive score of the fully homomorphic encryption scenario. The conversion process maps the values of each hierarchical fusion intermediate vector to a unified score quantization range, ensuring that the scores of different dimensions can be compared and integrated on a common scale. Through the above method, the dimensional differences and numerical range differences between different evaluation dimensions can be eliminated, making the generated privacy protection comprehensive score more comparable and interpretable.

[0080] In some possible embodiments, Figure 5 Another flowchart of a data privacy protection effect evaluation method is provided for the embodiments of the present application. As shown in Figure 5 The S104 can specifically include the following steps:

[0081] S1041, performing hierarchical weighted aggregation processing on the side channel vulnerability score and the key management defect score to generate a hierarchical fusion intermediate vector.

[0082] S1042, based on a pre-defined score quantization mapping table, performing cross-dimension normalization conversion processing on the hierarchical fusion intermediate vector to generate a privacy protection comprehensive score of the fully homomorphic encryption scenario.

[0083] For example, the data privacy protection effect evaluation device can perform dynamic weight coefficient allocation processing on the evaluation dimensions of the side channel vulnerability score and the key management defect score according to the security policy label of the homomorphic encryption scene, and generate a multi-dimensional evaluation weight parameter. The importance of each dimension is different in different scenarios. Through the security policy label, the key degree of the side channel attack risk and the key management vulnerability in the current scenario can be determined, and corresponding weights are assigned to each evaluation dimension to ensure that subsequent calculations focus on key risk points. With the help of a fusion engine driven by multiple rule libraries, the side channel vulnerability score, the key management defect score, and the multi-dimensional evaluation weight parameter are subjected to hierarchical weighted aggregation processing to generate a hierarchical fusion intermediate vector. The multiple rule libraries cover risk evaluation rules in different scenarios, and the fusion engine performs hierarchical calculation on each score and its weight according to these rules. The hierarchical weighted aggregation processing is used to integrate risk information in different dimensions and to preserve the hierarchical relationship and relative importance of each dimension in the integration process. The generated hierarchical fusion intermediate vector is the basis for subsequent conversion processing.

[0084] According to the predefined score quantization mapping table, the hierarchical fusion intermediate vector is subjected to cross-dimension normalization conversion processing to generate a privacy protection comprehensive score of the homomorphic encryption scene. The predefined score quantization mapping table provides a mapping relationship for converting the hierarchical fusion intermediate vector into a comprehensive score. Through cross-dimension normalization conversion processing, the dimensional and numerical range differences between the evaluation dimensions are eliminated, so that the scores in different dimensions can be integrated on the same scale to obtain a comprehensive score reflecting the privacy protection effect of the homomorphic encryption scene.

[0085] Optionally, Figure 6 A flowchart of another data privacy protection effect evaluation method provided by an embodiment of the present application is shown in FIG. 10B. As shown in FIG. 10B, the method can include the following steps: Figure 6

[0086] S10421, based on the dimension distribution characteristics of the hierarchical fusion intermediate vector, performing dynamic adjustment processing on the quantization threshold in the predefined score quantization mapping table to generate a dynamically adapted quantization mapping table.

[0087] S10422, through a multi-dimensional coupling engine, performing dependency analysis processing on the hierarchical fusion intermediate vector and the dynamically adapted quantization mapping table to generate a cross-dimension coupled normalized vector.

[0088] S10423, based on a preset privacy protection level mapping rule, performing scale alignment processing on the cross-dimension coupled normalized vector to generate a privacy protection comprehensive score of the homomorphic encryption scene.

[0089] ​It should be noted that the data privacy protection effect evaluation device can understand the distribution of each dimension in the intermediate vector and its importance by analyzing the dimension distribution characteristics of the hierarchical fusion intermediate vector. According to the above characteristics, the quantization threshold in the pre-defined scoring quantization mapping table is dynamically adjusted and processed to generate a dynamically adapted quantization mapping table. This step aims to make the quantization mapping table fit the characteristics of the hierarchical fusion intermediate vector, and better reflect the risk level of each dimension. Then, through the multi-dimensional coupling engine, the dependency relationship between the hierarchical fusion intermediate vector and the dynamically adapted quantization mapping table is analyzed and processed. The multi-dimensional coupling engine can identify the complex association between the intermediate vector and the quantization mapping table, and analyze how each dimension affects each other and how it corresponds to the quantization threshold, thereby generating a normalized vector after cross-dimensional coupling. The generation process of the normalized vector ensures that the risks of different dimensions can be compared and integrated on a unified scale. Then, based on the pre-set privacy protection level mapping rule, the normalized vector after cross-dimensional coupling is processed for scale alignment. The pre-set privacy protection level mapping rule defines the corresponding relationship between different risk levels and privacy protection levels. The scale alignment processing converts the risk values in the normalized vector into the corresponding privacy protection levels to generate the privacy protection comprehensive score in the fully homomorphic encryption scenario. This step completes the conversion from technical risk evaluation to privacy protection effect measurement, providing decision-makers with an intuitive privacy protection effect evaluation result.

[0090] The data privacy protection effect evaluation method provided by the embodiments of the present application can simulate attacks based on the operation characteristics of the fully homomorphic encryption coprocessor runtime to generate a hardware side channel leakage risk vector; perform association matching based on key state change events and ciphertext data survival periods to generate a key-data binding bias report; the key-data binding bias report is used to represent the time window difference between the key validity period and the ciphertext data survival period; based on the hardware side channel leakage risk vector and the key-data binding bias report, the side channel vulnerability score and the key management defect score are generated by quantitatively evaluating the anti-side channel attack ability and key management vulnerabilities of the fully homomorphic encryption scheme; based on the side channel vulnerability score and the key management defect score, the privacy protection comprehensive score of the fully homomorphic encryption scenario is determined. In this way, by performing multi-dimensional fusion processing on the side channel vulnerability score and the key management defect score, the data privacy protection effect in the fully homomorphic encryption scenario can be effectively evaluated from multiple dimensions, thereby providing a method for effectively evaluating the data privacy protection effect in the fully homomorphic encryption scenario.

[0091] In some embodiments, after generating the privacy protection comprehensive score of the fully homomorphic encryption scenario, the method can further include: based on the privacy protection comprehensive score, performing root cause positioning processing on hardware abstraction layer design defects and key rotation strategies to generate a privacy protection optimization suggestion list.

[0092] For example, the data privacy protection effect evaluation device can perform pattern matching processing on the time sequence behavior characteristics of the hardware abstraction layer design defects and the rule conflict characteristics of the key rotation strategy according to the privacy protection comprehensive score, to generate a defect feature vector set containing multi-dimensional feature information. On this basis, the joint query engine of the defect mode library and the strategy rule library is used to perform multi-dimensional associated path backtracking processing on each feature in the defect feature vector set. Among them, by comparing the defect feature vector with the known mode in the defect mode library and with the rules in the strategy rule library, the root path of the defect is traced back, thereby generating a clear hardware defect root path map and a key strategy conflict chain. Then, based on the preset optimization rule template library, the hardware defect root path map and the key strategy conflict chain are prioritized and repaired strategy mapping processing, according to the matching result of the optimization rule template, the priority order is determined, and the corresponding repair strategy is matched for each problem, and then a privacy protection optimization suggestion list is generated, which provides specific and feasible improvement suggestions for improving the privacy protection effect.

[0093] The above mainly introduces the scheme provided by the embodiments of the application from the perspective of method. In order to realize the above functions, the data privacy protection effect evaluation device comprises the corresponding hardware structure and / or software modules for executing each function. Those skilled in the art should easily realize that, in combination with the units and algorithm steps of each example described in the embodiments disclosed in the present application, the application can be realized in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed by hardware or computer software driven hardware depends on the specific application and design constraints of the technical solution. Professional technical target can use different methods to realize the described function for each specific application, but this implementation should not be considered beyond the scope of the application.

[0094] In an exemplary embodiment, the embodiments of the application also provide a data privacy protection effect evaluation device. Figure 7 The composition schematic diagram of the data privacy protection effect evaluation device provided by the embodiments of the application is shown in FIG. 7. As shown in the figure, the device comprises a processing module 701. Figure 7

[0095] ​The processing module 701 is configured to simulate attacks based on operation characteristics of the homomorphic encryption coprocessor runtime to generate a hardware side channel leakage risk vector; perform correlation matching based on key state change events and ciphertext data survival periods to generate a key-data binding deviation report; the key-data binding deviation report is used to represent a time window difference between a key validity period and a ciphertext data survival period; based on the hardware side channel leakage risk vector and the key-data binding deviation report, the anti-side channel attack capability and the key management vulnerability of the homomorphic encryption scheme are quantitatively evaluated to generate a side channel vulnerability score and a key management defect score; and based on the side channel vulnerability score and the key management defect score, a privacy protection comprehensive score of the homomorphic encryption scene is determined.

[0096] In some possible embodiments, the processing module 701 is specifically configured to obtain operation characteristics of the homomorphic encryption coprocessor runtime to generate a hardware operation characteristic set; the operation characteristics include at least one of the following: memory access timing characteristics, electromagnetic radiation waveform characteristics, and instruction execution period characteristics; based on the hardware operation characteristic set, a multi-modal attack vector of a timing correlation attack, an electromagnetic template attack, and a power analysis attack is injected by using a side channel attack simulation engine to generate a potential leakage path mode cluster; for each potential leakage path in the potential leakage path mode cluster, an association parameter and an observability parameter of each potential leakage path are extracted; the association parameter includes a cooperation probability with other potential leakage paths; the observability parameter includes a signal strength and / or a resolution difficulty score; based on the association parameter, the observability parameter, and a preset grading rule, a risk level of each potential leakage path is determined; from the potential leakage path mode cluster, a key risk path with a risk level higher than a threshold level is selected; and based on the key risk path, a hardware side channel leakage risk vector is generated.

[0097] In some possible embodiments, the processing module 701 is specifically configured to, based on the hardware side channel leakage risk vector, perform threat modeling processing on timing correlation of a memory access mode and resolvability of an electromagnetic radiation signal to generate a memory access mode leakage path map and an electromagnetic side channel threat value; based on the key-data binding deviation report, perform risk probability reasoning on an overlapping area of a key validity period and a ciphertext data survival period to generate a key permission boundary crossing risk level; and through a preset fragility mapping rule library, the memory access mode leakage path map, the electromagnetic side channel threat value, and the key permission boundary crossing risk level are subjected to multi-factor normalization and weighting processing to generate a side channel vulnerability score and a key management defect score.

[0098] In some possible embodiments, the processing module 701 is specifically configured to calculate the key permission boundary crossing risk level according to the following formula:

[0099]

[0100] wherein D overlap denotes the cross-overlapping degree maximum value, L k denotes the kth overlapping interval length, W k denotes the kth overlapping interval weight, V k denotes the kth interval violation degree, m denotes the number of overlapping intervals, a and b denote the balance factors, R risk denotes the key permission out-of-bound risk level, O i denotes the survival period of the ith ciphertext data, K i denotes the validity period of the ith key, T total denotes the total time period, P(E i ) denotes the occurrence probability of the ith out-of-bound event, and n denotes the number of ciphertext data-key binding pairs.

[0101] In some possible embodiments, the processing module 701 is specifically configured to perform dynamic segmentation processing on the time window of the key validity period and the ciphertext data survival period based on the key state change sequence in the key-data binding deviation report and the data survival period label, to generate a cross-overlapping time slice set; and perform probability inference processing on the operation path that can still access the corresponding ciphertext data after the key is disabled in the cross-overlapping time slice set by using a Bayesian network model, to generate a key permission out-of-bound risk probability value, by using the following formula:

[0102]

[0103] wherein Z denotes the key permission out-of-bound risk probability value, b i denotes the risk coefficient of the ith operation path, D i denotes the amount of ciphertext data, S i denotes the security threshold, g i denotes the time sensitivity coefficient, t i denotes the operation duration, and m denotes the number of operation paths; and the key permission out-of-bound risk level is determined by performing weighted matching processing on the key permission out-of-bound risk probability value based on the current business scenario and a preset scenario weight corresponding relationship.

[0104] In some possible embodiments, the processing module 701 is specifically configured to perform hierarchical weighted aggregation processing on the side channel vulnerability score and the key management defect score, to generate a hierarchical fusion intermediate vector; and perform cross-dimension normalization conversion processing on the hierarchical fusion intermediate vector based on a predefined score quantization mapping table, to generate a privacy protection comprehensive score in a fully homomorphic encryption scenario.

[0105] It should be noted that, Figure 7The division of the modules is illustrative, and is only logical functional division. In actual implementation, another division manner can be used. For example, two or more functions can be integrated in one processing module. The integrated module can be implemented in the form of hardware or in the form of a software function module.

[0106] In the example embodiment, the data privacy protection effect evaluation apparatus can be a computer or a service electronic device with a computing processing function, as described above. In this case, the embodiment of the present application further provides an electronic device, Figure 8 The composition of the electronic device provided by the embodiment of the present application is shown in the figure. As shown in the figure, the electronic device includes a processor 10, a memory 20, a communication line 30, a communication interface 40, and an input / output interface 50. Figure 8

[0107] The processor 10, the memory 20, the communication interface 40, and the input / output interface 50 can be connected through the communication line 30.

[0108] The processor 10 is configured to execute instructions stored in the memory 20 to implement the data privacy protection effect evaluation method provided by the above-mentioned embodiments of the present application. The processor 10 can be a CPU, a general processor network processor (NP), a digital signal processing (DSP), a microprocessor, a micro control unit (MCU) / single-chip microcomputer / single-chip microcomputer, a programmable logic device (PLD), or any combination thereof. The processor 10 can also be any other device with processing function, such as a circuit, a device, or a software module, and the embodiments of the present application do not limit this. In an example, the processor 10 can include one or more CPUs, such as CPU0 and CPU1 in Figure 8 As an optional implementation manner, the electronic device can include multiple processors, for example, in addition to the processor 10, the electronic device can further include a processor 60 (illustrated by a dashed line in Figure 8 ).

[0109] ​A memory 20 is configured to store instructions. For example, the instructions can be a computer program. Optionally, the memory 20 can be a read-only memory (ROM) or another type of static storage device that can store static information and / or instructions that are not to be changed by the device. Alternatively, or additionally, the memory 20 can be a random access memory (RAM) or another type of dynamic storage device that can store information and / or instructions that are to be changed by the device. The memory 20 can also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or another type of optical storage, a magnetic disk storage or another type of storage device that can store information and / or instructions that are to be changed by the device. The embodiments of the present application are not limited in this regard.

[0110] It is to be noted that the memory 20 can be independent of the processor 10 or integrated with the processor 10. The memory 20 can be located within the electronic device or outside the electronic device. The embodiments of the present application are not limited in this regard.

[0111] A communication line 30 is configured to transmit information between components included in the electronic device.

[0112] A communication interface 40 is configured to communicate with other devices or other communication networks. The other communication networks can be an Ethernet, a radio access network (RAN), a wireless local area network (WLAN), or the like. The communication interface 40 can be a module, a circuit, a transceiver, or any device capable of implementing communication.

[0113] An input / output interface 50 is configured to implement human-machine interaction between a user and the electronic device. For example, the input / output interface 50 can implement action interaction or information interaction between the user and the electronic device.

[0114] For example, the input / output interface 50 can be a mouse, a keyboard, a display screen, or a touch display screen, or the like. Through the mouse, the keyboard, the display screen, or the touch display screen, the action interaction or the information interaction between the user and the electronic device can be implemented.

[0115] It is to be noted that the above-described structure does not constitute a limitation on the electronic device, and the electronic device can include more or fewer components than those shown in the figure, or a combination of some components, or a different arrangement of components. Figure 8 The embodiments of the present application are not limited in this regard. Figure 8 The electronic device can include more or fewer components than those shown in the figure, or a combination of some components, or a different arrangement of components.

[0116] In an example embodiment, the embodiments of the present application further provide a computer program product, which comprises computer instructions, and when the computer instructions are executed in an electronic device, the electronic device implements the method in the foregoing method embodiments.

[0117] In an example embodiment, the embodiments of the present application further provide a computer readable storage medium, which comprises software instructions, and when the software instructions are executed in an electronic device, the electronic device implements the method in the foregoing method embodiments. The computer readable storage medium can be a non-transitory computer readable storage medium, for example, the non-transitory computer readable storage medium can be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, and an optical data storage device, etc.

[0118] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware, or any combination thereof. When implemented by using a software program, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product comprises one or more computer executable instructions. When the computer executable instructions are loaded and executed on a computer, all or part of the processes or functions according to the embodiments of the present application are generated. The computer can be a general purpose computer, a special purpose computer, a computer network, or other programmable apparatus. The computer executable instructions can be stored in a computer readable storage medium, or transmitted from one computer readable storage medium to another computer readable storage medium, for example, the computer executable instructions can be transmitted from one website site, computer, server or data center to another website site, computer, server or data center through a wired (for example, coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (for example, infrared, wireless, microwave, etc.) manner.

[0119] Although the present application is described herein in conjunction with various embodiments, other variations of the disclosed embodiments can be understood and effected by those skilled in the art in practicing the claimed application, from the appended claims, the disclosure, and the accompanying drawings. In the claims, the word “comprising” does not exclude other components or steps, and the indefinite articles “a” or “an” do not exclude a plurality. A single processor or other unit can fulfill the functions of several items recited in the claims. The mere fact that certain measures are recited in mutually different dependent claims does not indicate that a combination of these measures cannot be used to advantage.

[0120] Although the present application has been described in connection with specific embodiments thereof, it will be evident that many modifications and changes can be made thereto without departing from the spirit and scope of the application. Accordingly, it is intended to cover all modifications and changes as fall within the true spirit and scope of the application, and it is intended to include all such modifications and changes in the scope of the claims and their equivalents. Obviously, many modifications and variations of this application are possible in light of the above teachings. It is, therefore, to be understood that within the scope of the claims and their equivalents, the application can be practiced otherwise than as specifically described.

[0121] The above description is only specific embodiments of the present application, but the protection scope of the present application is not limited thereto, and any change or replacement within the technical scope disclosed in the present application should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method for evaluating the effectiveness of data privacy protection, characterized in that, The method includes: Simulated attacks are performed based on the operational characteristics of the fully homomorphic encryption coprocessor during runtime to generate a hardware side-channel leakage risk vector. The key-data binding deviation report is generated by associating and matching key state change events and ciphertext data lifespan; the key-data binding deviation report is used to indicate the time window difference between the key validity period and the ciphertext data lifespan. Based on the hardware side-channel leakage risk vector and the key-data binding deviation report, the resistance to side-channel attacks and key management vulnerabilities of the fully homomorphic encryption scheme are quantitatively evaluated, and a side-channel vulnerability score and a key management defect score are generated. Based on the side-channel vulnerability score and the key management defect score, a comprehensive privacy protection score for the fully homomorphic encryption scenario is determined.

2. The method according to claim 1, characterized in that, The simulation attack based on the operational characteristics of the fully homomorphic encryption coprocessor during runtime generates a hardware side-channel leakage risk vector, including: The operational characteristics of the fully homomorphic encryption coprocessor during operation are obtained to generate a hardware operation characteristic set; the operation characteristics include at least one of the following: memory access timing characteristics, electromagnetic radiation waveform characteristics, and instruction execution cycle characteristics. Based on the aforementioned hardware operation feature set, a side-channel attack simulation engine is used to inject multimodal attack vectors of timing correlation attacks, electromagnetic template attacks, and power analysis attacks to generate a cluster of potential leakage path patterns. For each potential leakage path in the potential leakage path pattern cluster, the correlation parameter and observability parameter of each potential leakage path are extracted; the correlation parameter includes the probability of cooperation with other potential leakage paths; the observability parameter includes signal strength and / or parsing difficulty score; Based on the correlation parameters, the observability parameters, and the preset grading rules, the risk level of each potential leakage path is determined; Select key risk paths with risk levels higher than the level threshold from the cluster of potential leakage path patterns; The hardware-side channel leakage risk vector is generated based on the key risk path.

3. The method according to claim 1, characterized in that, The method, based on the hardware side-channel leakage risk vector and the key-data binding deviation report, quantitatively evaluates the side-channel attack resistance and key management vulnerabilities of the fully homomorphic encryption scheme, generating a side-channel vulnerability score and a key management defect score, including: Based on the hardware-side channel leakage risk vector, threat modeling is performed on the temporal correlation of memory access patterns and the resolvability of electromagnetic radiation signals to generate a memory access pattern leakage path map and electromagnetic side channel threat value. Based on the key-data binding deviation report, risk probability inference is performed on the overlapping area of ​​key validity period and ciphertext data lifespan to generate key permission overstepping risk level; By using a pre-defined fragile mapping rule base, the memory access pattern leakage path map, the electromagnetic side channel threat value, and the key permission overstepping risk level are processed by multi-factor normalization weighting to generate the side channel vulnerability score and the key management defect score.

4. The method according to claim 3, characterized in that, Based on the key-data binding deviation report, the risk probability inference is performed on the overlapping area of ​​the key validity period and the ciphertext data lifespan to generate a key permission violation risk level, including: Calculate the key access violation risk level using the following formula: Among them, D overlap L represents the maximum or minimum value of cross-over overlap. k W represents the length of the k-th overlapping interval. k V represents the weight of the k-th overlapping interval. k R represents the degree of violation in the k-th interval, m represents the number of overlapping intervals, α and β represent balance factors, and R risk Indicates the risk level of key access exceeding limits, O i K represents the lifespan of the i-th ciphertext data. i T represents the validity period of the i-th key. total P(E) represents the total time period. i ) represents the probability of the i-th out-of-bounds event occurring, and n represents the number of ciphertext data-key binding pairs.

5. The method according to claim 3, characterized in that, Based on the key-data binding deviation report, the risk probability inference is performed on the overlapping area of ​​the key validity period and the ciphertext data lifespan to generate a key permission violation risk level, including: Based on the key status change sequence and data lifecycle label in the key-data binding deviation report, the time window of key validity period and ciphertext data lifecycle is dynamically segmented to generate a set of overlapping time slices. Using the following formula, a Bayesian network model is used to perform probabilistic extrapolation on the operation paths that can still access the corresponding ciphertext data after the key expires in the set of overlapping time slices, generating a key access violation risk probability value: Where Z represents the probability value of key access violation risk, β i D represents the risk coefficient of the i-th operation path. i S represents the amount of ciphertext data. i Indicates the safety threshold, γ i The time sensitivity coefficient, t i The duration of the operation is represented by m, and the number of operation paths is represented by m. Based on the current business scenario and the preset scenario weight correspondence, the probability value of the key permission out-of-bounds risk is weighted and matched to determine the key permission out-of-bounds risk level.

6. The method according to claim 1, characterized in that, The determination of a comprehensive privacy protection score for a fully homomorphic encryption scenario based on the side-channel vulnerability score and the key management defect score includes: The side channel vulnerability score and the key management defect score are subjected to hierarchical weighted aggregation processing to generate a hierarchical fusion intermediate vector; Based on a predefined scoring quantization mapping table, the hierarchical fusion intermediate vector is subjected to cross-dimensional normalization transformation to generate a comprehensive privacy protection score for the fully homomorphic encryption scenario.

7. A data privacy protection effectiveness evaluation device, characterized in that, include: Processing module; The processing module is used to simulate attacks based on the operational characteristics of the fully homomorphic encryption coprocessor during runtime, and generate a hardware side-channel leakage risk vector. Based on the correlation and matching of key state change events and ciphertext data lifespan, a key-data binding deviation report is generated. The key-data binding deviation report is used to represent the time window difference between the key validity period and the ciphertext data lifespan. Based on the hardware side-channel leakage risk vector and the key-data binding deviation report, the resistance to side-channel attacks and key management vulnerabilities of the fully homomorphic encryption scheme are quantitatively evaluated, generating a side-channel vulnerability score and a key management defect score. Based on the side-channel vulnerability score and the key management defect score, a comprehensive privacy protection score for the fully homomorphic encryption scenario is determined.

8. An electronic device, characterized in that, include: Processor and memory; The memory stores instructions that the processor can execute; When the processor is configured to execute the instructions, the electronic device performs the method as described in any one of claims 1-6.

9. A readable storage medium, characterized in that, include: Software instructions; When the software instructions are executed in an electronic device, the electronic device causes the electronic device to perform the method as described in any one of claims 1-6.

10. A computer program product, characterized in that, include: Computer instructions; When the computer instructions are executed in an electronic device, the electronic device causes the electronic device to perform the method as described in any one of claims 1-6.