Data desensitization and privacy protection method and device, medium and computer program product

By introducing finite field multiplication optimization and dynamic masking techniques into homomorphic encryption, the problem of low efficiency in multiplication operations of homomorphic encryption technology is solved, achieving efficient data desensitization and privacy protection, and improving computing performance and security.

CN121508796APending Publication Date: 2026-02-10CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511848300.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-09
Publication Date
2026-02-10

Smart Images

  • Figure CN121508796A_ABST
    Figure CN121508796A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of information security, and particularly provides a data desensitization and privacy protection method and device, a medium and a computer program product. The method comprises the following steps: encrypting plaintext data to be processed through a homomorphic encryption algorithm to generate an initial ciphertext; mapping the initial ciphertext into a finite field to obtain ciphertext data represented by the finite field; in a finite field, carrying out multiplication operation on the ciphertext data; and mapping a result of completing multiplication back to the homomorphic encrypted ciphertext space from the finite field to obtain a target ciphertext. According to the method and the device, encryption processing is performed through the homomorphic encryption algorithm, and the execution efficiency of multiplication operation in homomorphic encryption is remarkably improved while the ciphertext security is maintained. In addition, the multiplication operation is executed in a finite field, and the algebraic characteristic of the multiplication operation is utilized for optimization, so that the calculation burden of the multiplication operation is remarkably reduced. The problems of high calculation complexity and low efficiency when homomorphic encryption executes multiple multiplication operations are effectively solved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of information security, and particularly relates to a data desensitization and privacy protection method, device, medium and computer program product. BACKGROUND

[0002] With the popularization of cloud computing and big data technology, massive data is entrusted to the cloud for processing, and the privacy information contained therein faces the risk of leakage. Therefore, it is usually necessary to encrypt the privacy data.

[0003] In the related art, homomorphic encryption technology is often used to encrypt the privacy data. Homomorphic encryption technology allows direct arithmetic operations in the ciphertext state, which provides the possibility for cloud data security calculation. However, the fully homomorphic encryption scheme is inefficient and consumes a lot of resources when processing complex operations, and the partial homomorphic encryption scheme, although improved in efficiency, cannot support both addition and multiplication operations at the same time, and the function is limited, which is difficult to meet the demand of complex calculation logic. SUMMARY

[0004] Therefore, the present disclosure exemplary embodiments provide a data desensitization and privacy protection method, device, medium and computer program product to solve the problems in the related art.

[0005] One aspect of the present disclosure exemplary embodiments provides a data desensitization and privacy protection method, which comprises: encrypting the plaintext data to be processed by a homomorphic encryption algorithm to generate an initial ciphertext; mapping the initial ciphertext to a finite field to obtain ciphertext data represented by the finite field; performing multiplication operation on the ciphertext data in the finite field; mapping the result of the multiplication operation from the finite field back to the homomorphic encryption ciphertext space to obtain a target ciphertext.

[0006] Another aspect of the present disclosure exemplary embodiments provides a data desensitization and privacy protection device, which comprises: a data acquisition module configured to encrypt the plaintext data to be processed by a homomorphic encryption algorithm to generate an initial ciphertext; a data processing module configured to map the initial ciphertext to a finite field to obtain ciphertext data represented by the finite field; The data processing module is further configured to perform multiplication operation on the ciphertext data in the finite field. The data processing module is further configured to map the result of the multiplication operation from the finite field back to the homomorphic encryption ciphertext space to obtain a target ciphertext.

[0007] In yet another aspect of the embodiments of the present disclosure, a computer device is provided, which includes a memory, a processor, and a computer program stored in the memory, and the processor executes the computer program to implement the method according to the embodiments of the present disclosure.

[0008] In yet another aspect of the embodiments of the present disclosure, a computer readable storage medium is provided, which stores a computer program / instruction, and the computer program / instruction is executed by a processor to implement the method according to the embodiments of the present disclosure.

[0009] In yet another aspect of the embodiments of the present disclosure, a computer program product is provided, which includes a computer program / instruction, and the computer program / instruction is executed by a processor to implement the method according to the embodiments of the present disclosure.

[0010] As will be described in detail below, according to a data de-sensitization and privacy protection method according to an embodiment of the present disclosure, plaintext data to be processed is encrypted by a homomorphic encryption algorithm to generate initial ciphertext; the initial ciphertext is mapped to a finite field to obtain ciphertext data represented in the finite field; multiplication operation is performed on the ciphertext data in the finite field; and the result of the multiplication operation is mapped back from the finite field to the ciphertext space of the homomorphic encryption to obtain target ciphertext. Therefore, the data de-sensitization and privacy protection method provided by the present disclosure performs encryption processing by a homomorphic encryption algorithm, which significantly improves the execution efficiency of multiplication operation in homomorphic encryption while maintaining the security of ciphertext, effectively solving the problem of low computational efficiency of homomorphic encryption technology in multiplication operation. In addition, by performing multiplication operation in a finite field and optimizing it by using its algebraic properties, the computational burden of multiplication operation is significantly reduced. At the same time, the back mapping mechanism ensures that the operation result is still in the homomorphic encryption system, and by taking advantage of the structure of the finite field, the multiplication operation in homomorphic encryption is strengthened in both security and efficiency. The problem of high computational complexity and low efficiency of homomorphic encryption when performing multiple multiplication operations is effectively solved. BRIEF DESCRIPTION OF DRAWINGS

[0011] The above and other objects, features and advantages of the present disclosure will become more apparent from the following detailed description when taken in conjunction with the accompanying drawings in which like reference characters refer to like elements throughout. The accompanying drawings are intended to provide a further understanding of the embodiments of the present disclosure and are incorporated in and constitute a part of this specification, illustrate embodiments of the present disclosure and serve to explain the present disclosure, and do not constitute a limitation of the present disclosure. In the drawings, like reference numerals refer to like elements throughout.

[0012] Figure 1 A flowchart of a data de-sensitization and privacy protection method provided by an embodiment of the present disclosure; Figure 2 A flowchart of a data de-sensitization and privacy protection method provided by an embodiment of the present disclosure; Figure 3 A functional module schematic block diagram of the data desensitization and privacy protection device provided by the embodiments of the present disclosure is shown in FIG. 1. Figure 4 A structural block diagram of the electronic device provided by the embodiments of the present disclosure is shown in FIG. 2. Figure 5 A schematic diagram of the computer program product provided by the embodiments of the present disclosure is shown in FIG. 3. DETAILED DESCRIPTION

[0013] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms, and should not be interpreted as being limited to the embodiments set forth herein, but rather, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes, and are not intended to limit the scope of protection of the present disclosure.

[0014] It should be understood that each step described in the method embodiments of the present disclosure can be executed in different orders and / or in parallel. In addition, the method embodiments can include additional steps and / or omit the execution of the steps shown. The scope of the present disclosure is not limited in this respect.

[0015] The term “comprising” and variations thereof as used herein are open-ended, that is, “including but not limited to”. The term “based on” is “based, at least in part, on”. The term “one embodiment” means “at least one embodiment”; the term “another embodiment” means “at least one additional embodiment”; the term “some embodiments” means “at least some embodiments”. Related definitions are given below in the description of the embodiments. It should be noted that the concepts of “first”, “second”, etc. mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not intended to limit the order or interdependence of the functions performed by these devices, modules or units.

[0016] It should be noted that the modification of “one” or “multiple” mentioned in the present disclosure is illustrative rather than limiting, and those skilled in the art should understand that, unless otherwise explicitly indicated in the context, it should be understood as “one or more”.

[0017] The names of the messages or information exchanged between the multiple devices in the embodiments of the present disclosure are only for illustrative purposes, and are not intended to limit the scope of the messages or information.

[0018] It can be understood that, before using the technical solutions disclosed in the embodiments of the present disclosure, the type of personal information involved in the present disclosure, the scope of use, the use scenario, etc. should be informed to the user and the authorization of the user should be obtained in a proper manner according to relevant laws and regulations.

[0019] With the popularization of cloud computing and big data technology, massive data is entrusted to the cloud for processing, and the privacy information contained therein is at risk of being leaked. Therefore, it is usually necessary to encrypt the privacy data.

[0020] In related technologies, data desensitization and homomorphic encryption technology are often used to encrypt privacy data. Among them, static data desensitization achieves data protection by disguising, replacing or deleting sensitive fields before data storage or transmission, but the data processed by this method is irreversible and cannot support further query and calculation analysis. Dynamic data desensitization performs real-time desensitization during data use according to the access rights of the visitor, which balances data use and security to some extent, but its implementation mechanism is complex and can easily cause system performance bottlenecks in high-concurrency access scenarios, and it is highly dependent on fine-grained permission control strategies. Homomorphic encryption technology allows arithmetic operations to be performed directly on ciphertext, making cloud data security calculation possible. However, the fully homomorphic encryption scheme is inefficient and resource-intensive when processing complex operations, while the partial homomorphic encryption scheme, although improved in efficiency, cannot support both addition and multiplication operations, and its functionality is limited, making it difficult to meet the needs of complex calculation logic.

[0021] Therefore, in order to solve the above problems, the exemplary embodiments of the present disclosure provide a data desensitization and privacy protection method. First, the plaintext data is encrypted by homomorphic encryption to generate ciphertext with homomorphic properties. Then, the ciphertext is mapped to a finite field (GF(p)), and the algebraic structure of the finite field is used to perform secure multiplication operations, significantly reducing the computational complexity of multiplication operations in traditional homomorphic encryption. Among them, the multiplication operation is realized by modular operation in the finite field, and the operation result is mapped back to the ciphertext space to maintain the operation properties of homomorphic encryption. To further enhance privacy protection, dynamic masking technology based on finite fields is introduced, which generates a mask through a pseudo random number generator (PRNG) and combines it with encrypted data to achieve desensitization, while authorized users can restore the original data through unmasking operations. In addition, the present embodiment also supports multi-party secure computation (MPC) scenarios, where each participant performs local calculation in an encrypted state, and the center aggregates the results through finite field multiplication and decryption, effectively reducing communication and calculation overhead, and improving the efficiency and security of collaborative calculation.

[0022] Exemplarily, Figure 1 The flowchart of the data desensitization and privacy protection method provided by the embodiments of the present disclosure is shown in Figure 1 As shown in the figure, it can specifically include the following steps: Step S110: Homomorphic encryption multiplication optimization based on finite field mapping.

[0023] In order to solve the technical problem of low efficiency and significant calculation bottleneck of multiplication operation in homomorphic encryption in large-scale data scenarios, the embodiment introduces a secure multiplication in finite field to optimize the multiplication operation in the framework of homomorphic encryption, simplifies the calculation process of multiplication by using the structure of finite field, and significantly improves the operation efficiency under the premise of ensuring the security of ciphertext.

[0024] Exemplarily, the optimization steps of homomorphic encryption in the embodiment can include: First, generate a public key pk and a private key sk by a key generation algorithm, wherein the public key is used for data encryption, and the private key is used for data decryption, and the public key pk and the private key sk can be represented as:

[0025] wherein, represents a security parameter.

[0026] Secondly, use the public key to homomorphically encrypt the input plaintext data m i to generate ciphertext c i :

[0027] The generated ciphertext c i has homomorphic properties and supports addition and multiplication operations in the encrypted state.

[0028] Finally, in order to optimize the multiplication operation in the encrypted state, the ciphertext can be mapped to a finite field GF(p) composed of a large prime number p, and the ciphertext c i is converted to a finite field representation for subsequent multiplication operation in the algebraic structure:

[0029] Based on this, while maintaining the security of the ciphertext, the execution efficiency of the multiplication operation in homomorphic encryption is significantly improved, effectively solving the problem of low calculation efficiency of homomorphic encryption technology in multiplication operation.

[0030] Step S120: secure multiplication in finite field and homomorphic remapping mechanism.

[0031] In order to solve the technical problem of rising calculation complexity and significant efficiency decline caused by multiple multiplication operations in homomorphic encryption, the embodiment optimizes this operation by secure multiplication in finite field, simplifies the calculation process of multiplication by using the mathematical structure of finite field, and enhances the efficiency and security of homomorphic encryption algorithm in complex calculation.

[0032] Exemplarily, after the encrypted data is mapped to the finite field , two encrypted data and The multiplication operation can be expressed as:

[0033] The multiplication operation utilizes the closure and algebraic structure of the finite field to simplify the multiplication process from a mathematical perspective, effectively avoiding the problem of high multiplication complexity in traditional homomorphic encryption.

[0034] After completing the multiplication operation in the finite field, the result is converted back to the homomorphic ciphertext space through the mapping function, obtaining Thus, the overall efficiency of multiplication is significantly improved while ensuring that the homomorphic property is not lost.

[0035] For example, the mapping function can be expressed as:

[0036] Based on this, by performing the multiplication operation in the finite field and optimizing it using its algebraic properties, the computational burden of multiplication is significantly reduced. At the same time, the back-mapping mechanism ensures that the operation result is still within the homomorphic encryption system, and through the structural advantages of the finite field, the multiplication operation in homomorphic encryption is strengthened in both security and efficiency. The problem of high computational complexity and low efficiency of homomorphic encryption when performing multiple multiplication operations is effectively solved.

[0037] Step S130: Finite field dynamic mask generation and reversible de-sensitization mechanism.

[0038] To solve the technical problem of insufficient privacy protection of homomorphic encryption when dealing with side-channel attacks or statistical analysis-based inferences, and to enhance data privacy protection, the present embodiment proposes a dynamic mask de-sensitization mechanism based on finite fields, further improving the security of data de-sensitization.

[0039] Specifically, first, in the finite field GF(p), a pseudo-random number generator PRNG() is used to dynamically generate a random mask value r i for each encrypted data, ensuring unpredictability and randomness:

[0040] Subsequently, the mask is combined with the encrypted data in the finite field through a modulo addition operation to obtain the de-sensitized ciphertext :

[0041] This masking process not only ensures the privacy of data in the encrypted state, but also, through the structural characteristics of the finite field, effectively improves the security of the mask and the original data.

[0042] When the authorized party needs to recover the original data, the known mask r iBy performing a demasking operation and decrypting the ciphertext within the framework of homomorphic encryption, the secure use and restoration of data can be achieved without exposing sensitive information throughout the process.

[0043] For example, the decryption process can be represented as:

[0044] Based on this, by introducing dynamically generated random masks within a finite domain, the privacy protection strength of encrypted data is significantly enhanced, effectively solving the technical problem that homomorphic encryption technology is difficult to defend against side-channel attacks and statistical inference.

[0045] Step S140: Local encryption and centralized aggregation mechanism in multi-party secure computation.

[0046] To meet the needs of multiple untrusted parties to collaborate in multi-party secure computation (MPC) scenarios, this embodiment significantly reduces the computation and communication complexity of the MPC architecture and improves collaborative computation efficiency by integrating homomorphic encryption and finite field multiplication techniques.

[0047] In this mechanism, all parties participate in the distributed computation of encrypted data. First, each party performs homomorphic encryption on its local data and performs local computations such as multiplication within a finite domain. Then, the results of the local computations are uploaded to the trusted center.

[0048] Subsequently, the Trust Center performs homomorphic aggregation of the local computation results of each participant based on finite field operations to obtain the global encrypted computation result, and then generates the final plaintext result through decryption:

[0049] Based on this, secure multi-party computation introduces finite field operations, which significantly reduces the communication burden and collaborative computation complexity among the parties while ensuring that the data of each party is not leaked. This effectively solves the problems of high communication overhead and low computation efficiency caused by frequent interactions and complex protocols in secure multi-party computation.

[0050] One or more technical solutions provided in the exemplary embodiments of this disclosure, by introducing a finite field secure multiplication mechanism, fully utilize the algebraic properties of finite fields and efficient algorithms, significantly reducing the time complexity and resource consumption of multiplication operations. While maintaining end-to-end data encryption, they achieve faster multiplication capabilities.

[0051] Furthermore, by generating a pseudo-random mask in a finite domain and applying it to encrypted data, common privacy inference and side-channel attacks can be effectively resisted. Compared to traditional static desensitization methods, dynamic masks offer greater flexibility and adaptability, allowing the mask strength to be dynamically adjusted according to specific computational needs, thus achieving a higher level of data privacy protection.

[0052] Furthermore, by introducing finite-field secure multiplication into the multi-party secure computation framework, the communication and computational overhead between participants is significantly reduced while ensuring end-to-end data encryption. Leveraging the operational closure of finite fields and the efficient multiplication characteristics, each participant can independently complete local encrypted computations and collaboratively generate a global result in ciphertext through a homomorphic aggregation mechanism, without disclosing any sensitive information throughout the process.

[0053] Therefore, the data desensitization and privacy protection method provided in the exemplary embodiments of this disclosure effectively solves the problems of low computational efficiency, high complexity and insufficient privacy protection in the prior art. It not only significantly improves the processing performance of encrypted data, but also further strengthens the privacy protection capability of data throughout its entire life cycle, while optimizing the secure computation efficiency in multi-party collaboration scenarios.

[0054] Based on the above embodiments, this disclosure also provides a data anonymization and privacy protection method. Figure 2 A flowchart illustrating the data anonymization and privacy protection method provided in this disclosure embodiment is shown below. Figure 2 As shown, the method may include the following steps: Step S210: Encrypt the plaintext data to be processed using a homomorphic encryption algorithm to generate the initial ciphertext.

[0055] For example, the homomorphic encryption step may include: First, a public key pk and a private key sk are generated using a key generation algorithm. The public key is used for data encryption, and the private key is used for data decryption. The public key pk and the private key sk can be represented as follows:

[0056] in, Indicates safety parameters.

[0057] Secondly, use the public key to input plaintext data m i Perform homomorphic encryption to generate the initial ciphertext c. i :

[0058] The generated initial ciphertext c i It possesses homomorphic properties, supporting addition and multiplication operations in an encrypted state.

[0059] Step S220: Map the initial ciphertext to a finite field to obtain the ciphertext data represented by the finite field.

[0060] In this embodiment, to optimize multiplication operations in the encrypted state, the initial ciphertext can be mapped to a finite field GF(p) composed of large prime numbers p, and the initial ciphertext c can be mapped to a finite field GF(p). iTransform to a finite field representation so that subsequent multiplication operations can be performed within this algebraic structure:

[0061] Step S230: Perform multiplication on the ciphertext data within a finite field.

[0062] To address the technical problem of increased computational complexity and significantly reduced efficiency caused by multiple multiplication operations in homomorphic encryption, this embodiment optimizes this operation through finite field secure multiplication. By utilizing the mathematical structure of finite fields, the calculation process of multiplication is simplified, thereby enhancing the efficiency and security of homomorphic encryption algorithms in complex computations.

[0063] Step S240: Map the result of the multiplication operation back from the finite field to the homomorphically encrypted ciphertext space to obtain the target ciphertext.

[0064] In this embodiment, after performing multiplication within a finite field, the result is converted back to the homomorphic ciphertext space using a mapping function to obtain... This significantly improves the overall efficiency of multiplication while ensuring that the homomorphic property is not lost.

[0065] For example, the mapping function can be represented as:

[0066] Based on this, homomorphic encryption is used for encryption processing. While maintaining the security of the ciphertext, the execution efficiency of multiplication operations in homomorphic encryption is significantly improved, effectively solving the problem of low computational efficiency in multiplication operations in homomorphic encryption technology. Furthermore, by placing the multiplication operation within a finite field and optimizing it using its algebraic properties, the computational burden of multiplication operations is significantly reduced. Simultaneously, the back-mapping mechanism ensures that the operation result remains within the homomorphic encryption system. Through the structural advantages of the finite field, a dual enhancement of security and efficiency is achieved in multiplication operations within homomorphic encryption. This effectively solves the problem of high computational complexity and low efficiency in homomorphic encryption when performing multiple multiplication operations.

[0067] Based on the above embodiments, in another embodiment provided in this disclosure, the above data anonymization and privacy protection method may further include: Within a finite field, a mask value is generated for the ciphertext data using a pseudo-random number generator; The encrypted data and the mask value are modulo-added to generate the de-identified encrypted data.

[0068] In this embodiment, in order to address the technical problem of insufficient privacy protection in homomorphic encryption when dealing with side-channel attacks or statistical analysis-type inferences, and to enhance data privacy protection, this embodiment proposes a dynamic masking desensitization mechanism based on finite fields, which further improves the security of data desensitization.

[0069] Specifically, firstly, within the finite field GF(p), a pseudo-random number generator PRNG() is used to dynamically generate a random mask value r for each ciphertext data. i To ensure unpredictability and randomness:

[0070] Subsequently, the mask is combined with the ciphertext data within a finite field, and the de-identified ciphertext data is obtained through modular addition. :

[0071] Based on this, generating a dynamic mask and combining the mask with ciphertext data not only ensures the privacy of the data in the encrypted state, but also effectively improves the security of the mask and the original data through the structural characteristics of finite fields.

[0072] Based on the above embodiments, in another embodiment provided in this disclosure, the above data anonymization and privacy protection method may further include: Upon receiving a demasking instruction, the mask value is used to demask the desensitized ciphertext data to obtain ciphertext data represented by a finite field. The demasking process includes subtracting the mask value from the desensitized ciphertext data and performing a modulo operation on a large prime number.

[0073] In this embodiment, upon receiving a demasking command, the desensitized ciphertext data is first subtracted and moduloed within a finite field to strip the mask and recover the homomorphically encrypted finite-field representation of the ciphertext. Subsequently, this ciphertext data is backmapped back to the original homomorphically encrypted ciphertext space. Finally, the backmapped ciphertext is decrypted using the homomorphically encrypted private key to obtain the original plaintext data. This demasking process ensures that the data remains encrypted or protected throughout the entire process from the desensitized state to plaintext recovery, achieving secure data use and restoration.

[0074] For example, the decryption process can be represented as:

[0075] Based on this, by introducing a reversible demasking mechanism, it is ensured that data that has been dynamically masked and desensitized can still be restored to the original plaintext data, thereby preserving the availability of data while effectively preventing privacy threats such as side-channel attacks and statistical analysis.

[0076] Based on the above embodiments, in another embodiment provided in this disclosure, the multiplication operation on ciphertext data within a finite field may include: Perform multiplication on two ciphertext data and take the modulo of a large prime number in a finite field; the multiplication operation uses either the Montgomery multiplication method or the Karatsuba algorithm.

[0077] In the embodiment, for ciphertext data represented by two finite fields... and Multiplication is defined as calculating the product of two numbers and taking the modulus of the larger prime number p:

[0078] To further improve the efficiency of multiplication operations, Montgomery multiplication or Karatsuba algorithm can be used.

[0079] Among them, the Montgomery multiplication method avoids division operations by transforming the modulus to a more computationally efficient domain, making it suitable for repetitive modular arithmetic scenarios. The Karatsuba algorithm, on the other hand, reduces the computational complexity of large-scale multiplications, thus significantly reducing computational overhead when dealing with ciphertext multiplications generated from large-scale data.

[0080] Based on this, by moving the multiplication operation of encrypted data to a finite field and utilizing the closure property of modular arithmetic and efficient algorithms such as Montgomery multiplication or Karatsuba algorithm, the computational complexity is reduced and the operation speed is improved. This effectively solves the technical problem of high computational complexity and low execution efficiency of multiplication operations in homomorphic encryption, which cannot meet the needs of real-time processing of large-scale data.

[0081] Based on the above embodiments, in another embodiment provided in this disclosure, the above data anonymization and privacy protection method may further include: Multiple participants each perform homomorphic encryption on their local data to generate local ciphertext; Map the local ciphertext to a finite field to obtain the local finite field ciphertext; Perform multiplication on the local finite field ciphertext within a finite field to obtain the local computation result; Send the local computation results to the trusted center.

[0082] In this embodiment, in the context of multi-party secure computation, in order to achieve collaborative computation while protecting the data privacy of all parties, this embodiment combines homomorphic encryption and finite field multiplication techniques to meet the needs of multiple untrusted participants to collaboratively complete the computation.

[0083] First, each participant uses a unified homomorphic encryption algorithm and public key to encrypt their local data, generating local ciphertext with homomorphic properties. Then, each participant maps this local ciphertext to a finite field defined by a large prime number p, obtaining local finite-field ciphertext. Within this finite field, each participant can independently perform multiplication operations on their own ciphertext data, generating local computation results. Finally, each party only needs to send the processed local computation results to the trusted center, without transmitting any original data or encryption private keys.

[0084] Based on this, by pre-processing multiplication operations locally on each participant's machine, and independently performing data anonymization within a finite domain using an optimization algorithm, the number of real-time communication rounds and data transmission volume between participants is significantly reduced. This effectively solves the technical problems in multi-party secure computation protocols, such as huge communication overhead, high computational latency, and poor system scalability caused by frequent interactions between participants.

[0085] Based on the above embodiments, in another embodiment provided in this disclosure, the above data anonymization and privacy protection method may further include: The trusted center receives the local computation results sent by each participant; Within a finite domain, homomorphic aggregation is performed on all local computation results to obtain the aggregated result; The aggregation result is backmapped to a homomorphic encryption space and decrypted using a private key to obtain the target plaintext result.

[0086] In this embodiment, the trusted center receives local computation results uploaded by all participants. Then, an aggregation operation is performed within a finite field. Based on finite field operations, the local computation results of each participant are homomorphically aggregated to obtain a global encrypted computation result, which is then decrypted to generate the target plaintext result. The homomorphic aggregation process fully utilizes the multiplicative homomorphic properties of homomorphic encryption and the closure property of finite field operations, ensuring that no individual participant's data needs to be decrypted during the aggregation process. After aggregation, the obtained aggregation result is backmapped from the finite field to the homomorphically encrypted ciphertext space. Finally, the trusted center uses its securely held homomorphic encryption private key to decrypt the aggregated ciphertext, thus obtaining the target plaintext result of the global computation.

[0087] For example, the Trust Center performs homomorphic aggregation of the local computation results of each participant based on finite field operations to obtain a global encrypted computation result, and generates the target plaintext result through decryption, which can be represented as:

[0088] Based on this, by having a trusted center perform non-interactive ciphertext aggregation within a limited domain, the complex multi-party secure computation protocol is simplified into a one-time centralized process, greatly reducing the communication complexity and computational latency of the entire system. Simultaneously, since the aggregation and decryption processes are performed only on the local computation results, and the private key is independently managed by the trusted center, the correctness of the final result is ensured while preventing the leakage of sensitive information that may occur during the aggregation process, achieving an ideal balance between security and efficiency.

[0089] One or more technical solutions provided in the exemplary embodiments of this disclosure, by introducing a finite field secure multiplication mechanism, fully utilize the algebraic properties of finite fields and efficient algorithms, significantly reducing the time complexity and resource consumption of multiplication operations. While maintaining end-to-end data encryption, they achieve faster multiplication capabilities.

[0090] Furthermore, by generating a pseudo-random mask in a finite domain and applying it to encrypted data, common privacy inference and side-channel attacks can be effectively resisted. Compared to traditional static desensitization methods, dynamic masks offer greater flexibility and adaptability, allowing the mask strength to be dynamically adjusted according to specific computational needs, thus achieving a higher level of data privacy protection.

[0091] Furthermore, by introducing finite-field secure multiplication into the multi-party secure computation framework, the communication and computational overhead between participants is significantly reduced while ensuring end-to-end data encryption. Leveraging the operational closure of finite fields and the efficient multiplication characteristics, each participant can independently complete local encrypted computations and collaboratively generate a global result in ciphertext through a homomorphic aggregation mechanism, without disclosing any sensitive information throughout the process.

[0092] Therefore, the data desensitization and privacy protection method provided in the exemplary embodiments of this disclosure effectively solves the problems of low computational efficiency, high complexity and insufficient privacy protection in the prior art. It not only significantly improves the processing performance of encrypted data, but also further strengthens the privacy protection capability of data throughout its entire life cycle, while optimizing the secure computation efficiency in multi-party collaboration scenarios.

[0093] The foregoing primarily describes the solutions provided by exemplary embodiments of this disclosure. It is understood that, in order to achieve the above functions, the electronic device includes corresponding hardware structures and / or software modules for performing each function. Those skilled in the art should readily recognize that, based on the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein, this disclosure can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this disclosure.

[0094] The exemplary embodiments of this disclosure can divide the electronic device into functional units according to the above method examples. For example, each function can be divided into a separate functional module, or two or more functions can be integrated into a single processing module. The integrated module can be implemented in hardware or as a software functional module. It should be noted that the module division in the exemplary embodiments of this disclosure is illustrative and only represents one logical functional division; other division methods may be used in actual implementation.

[0095] By dividing each functional module according to its corresponding function, an exemplary embodiment of this disclosure provides a data anonymization and privacy protection device, which can be a server or a chip applied to a server. Figure 3 This is a schematic block diagram illustrating the functional modules of the data anonymization and privacy protection device provided in the embodiments of this disclosure. Figure 3 As shown, the data anonymization and privacy protection device 300 includes: The data acquisition module 310 is used to encrypt the plaintext data to be processed using a homomorphic encryption algorithm to generate initial ciphertext; Data processing module 320 is used to map the initial ciphertext to a finite field to obtain ciphertext data represented by the finite field; The data processing module 320 is also used to perform multiplication operations on the ciphertext data within the finite field; The data processing module 320 is further configured to backmap the result of the multiplication operation from the finite field to the homomorphically encrypted ciphertext space to obtain the target ciphertext.

[0096] In another embodiment provided in this disclosure, the data processing module 320 is further configured to generate a mask value for the ciphertext data by means of a pseudo-random number generator within the finite domain; and to perform a modulo addition operation on the ciphertext data and the mask value to generate desensitized ciphertext data.

[0097] In another embodiment provided in this disclosure, the data processing module 320 is further configured to, upon receiving a demasking instruction, use the mask value to perform demasking processing on the desensitized ciphertext data to obtain the ciphertext data represented by the finite field; the demasking processing includes: subtracting the mask value from the desensitized ciphertext data and performing a modulo operation on a large prime number.

[0098] In another embodiment provided in this disclosure, the data processing module 320 is further configured to perform a multiplication operation on two ciphertext data and take the modulus of a large prime number in the finite field; wherein the multiplication operation employs Montgomery multiplication or Karatsuba algorithm.

[0099] In another embodiment provided in this disclosure, the data processing module 320 is further configured to: encrypt local data homomorphically by multiple participants to generate local ciphertext; map the local ciphertext to a finite field to obtain local finite field ciphertext; perform multiplication operations on the local finite field ciphertext within the finite field to obtain a local calculation result; and send the local calculation result to a trusted center.

[0100] In another embodiment provided in this disclosure, the data processing module 320 is further configured to receive local computation results sent by each participating party in the trusted center; perform homomorphic aggregation on all local computation results within the finite domain to obtain an aggregation result; backmap the aggregation result to a homomorphic encryption space and decrypt it using a private key to obtain the target plaintext result.

[0101] Exemplary embodiments of this disclosure also provide an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor. The memory stores a computer program executable by the at least one processor, the computer program being executed by the at least one processor to cause the electronic device to perform a method according to an embodiment of this disclosure.

[0102] Exemplary embodiments of this disclosure also provide a non-transitory computer-readable storage medium storing a computer program, wherein the computer program, when executed by a computer's processor, is used to cause the computer to perform a method according to embodiments of this disclosure.

[0103] Figure 4 The structural block diagram of the electronic device provided in the embodiments of this disclosure will now be described as follows: An electronic device 400 that can serve as a server or client of this disclosure is an example of a hardware device that can be applied to various aspects of this disclosure. The electronic device is intended to represent various forms of digital electronic computer devices, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the disclosure described and / or claimed herein.

[0104] like Figure 4As shown, the electronic device 400 includes a computing unit 401, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 402 or a computer program loaded from a storage unit 408 into a random access memory (RAM) 403. The RAM 403 may also store various programs and data required for the operation of the electronic device 400. The computing unit 401, ROM 402, and RAM 403 are interconnected via a bus 404. An input / output (I / O) interface 405 is also connected to the bus 404.

[0105] Multiple components in electronic device 400 are connected to I / O interface 405, including: input unit 406, output unit 407, storage unit 408, and communication unit 409. Input unit 406 can be any type of device capable of inputting information to electronic device 400. Input unit 406 can receive input digital or character information and generate key signal inputs related to user settings and / or function control of electronic device. Output unit 407 can be any type of device capable of presenting information and may include, but is not limited to, a display, speaker, video / audio output terminal, vibrator, and / or printer. Storage unit 408 may include, but is not limited to, disks and optical discs. Communication unit 409 allows electronic device 400 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks, and may include, but is not limited to, modems, network cards, infrared communication devices, wireless communication transceivers, and / or chipsets, such as Bluetooth™ devices, WiFi devices, WiMax devices, cellular communication devices, and / or the like.

[0106] The computing unit 401 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 401 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 401 performs the various methods and processes described above. The various methods described above can all be implemented as computer software programs, which are tangibly contained in a machine-readable medium, such as storage unit 408. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 400 via ROM 402 and / or communication unit 409.

[0107] Figure 5The diagram illustrates a computer program product provided in an embodiment of this disclosure. An exemplary embodiment of this disclosure also provides a computer program product 500, including a computer program 501, wherein the computer program 501, when executed by a computer's processor, is used to cause the computer to perform a method according to an embodiment of this disclosure.

[0108] The program code used to implement the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0109] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0110] As used in this disclosure, the terms "machine-readable medium" and "computer-readable medium" refer to any computer program product, device, and / or apparatus (e.g., disk, optical disk, memory, programmable logic device (PLD)) for providing machine instructions and / or data to a programmable processor, including machine-readable media that receive machine instructions as machine-readable signals. The term "machine-readable signal" refers to any signal for providing machine instructions and / or data to a programmable processor.

[0111] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0112] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as a data server), or computing systems that include middleware components (e.g., an application server), or computing systems that include frontend components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., a communication network). Examples of communication networks include local area networks (LANs), wide area networks (WANs), and the Internet.

[0113] Computer systems can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. Client-server relationships are created by computer programs running on the respective computers and having a client-server relationship with each other.

[0114] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of this disclosure are performed, in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a terminal, a user equipment, or other programmable device. The computer program or instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program or instructions can be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center integrating one or more available media. The available medium can be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; it can also be an optical medium, such as a digital video disc (DVD); or it can be a semiconductor medium, such as a solid-state drive (SSD).

[0115] Although this disclosure has been described in conjunction with specific features and embodiments, it will be apparent that various modifications and combinations can be made therein without departing from the spirit and scope of this disclosure. Accordingly, this specification and drawings are merely exemplary illustrations of the disclosure as defined by the appended claims and are to be considered as covering any and all modifications, variations, combinations, or equivalents within the scope of this disclosure. It is obvious that those skilled in the art can make various alterations and modifications to this disclosure without departing from its spirit and scope. Thus, this disclosure is also intended to include any such modifications and modifications that fall within the scope of the claims of this disclosure and their equivalents.

Claims

1. A method for data anonymization and privacy protection, characterized in that, The method includes: The plaintext data to be processed is encrypted using a homomorphic encryption algorithm to generate the initial ciphertext; The initial ciphertext is mapped to a finite field to obtain ciphertext data represented by the finite field. Perform multiplication operations on the ciphertext data within the finite field; The result of the multiplication operation is backmapped from the finite field to the homomorphically encrypted ciphertext space to obtain the target ciphertext.

2. The method according to claim 1, characterized in that, The method further includes: Within the finite field, a mask value is generated for the ciphertext data using a pseudo-random number generator; The encrypted data and the mask value are added modulowise to generate the de-identified encrypted data.

3. The method according to claim 2, characterized in that, The method further includes: Upon receiving a demasking instruction, the mask value is used to perform demasking processing on the desensitized ciphertext data to obtain the ciphertext data represented by the finite field; the demasking processing includes: subtracting the mask value from the desensitized ciphertext data and performing a modulo operation on a large prime number.

4. The method according to claim 1, characterized in that, The multiplication operation on the ciphertext data within the finite field includes: Perform a multiplication operation on two ciphertext data and take the modulus of a large prime number in the finite field; wherein the multiplication operation adopts the Montgomery multiplication method or the Karatsuba algorithm.

5. The method according to claim 1, characterized in that, The method further includes: Multiple participants each perform homomorphic encryption on their local data to generate local ciphertext; Map the local ciphertext to a finite field to obtain the local finite field ciphertext; Perform multiplication operations on the local finite field ciphertext within the finite field to obtain the local calculation result; The local computation results are sent to the trusted center.

6. The method according to claim 5, characterized in that, The method further includes: The trusted center receives the local calculation results sent by each participating party; Within the finite domain, homomorphic aggregation is performed on all local computation results to obtain the aggregated result; The aggregation result is backmapped to a homomorphic encryption space and decrypted using a private key to obtain the target plaintext result.

7. A data anonymization and privacy protection device, characterized in that, The device includes: The data acquisition module is used to encrypt the plaintext data to be processed using a homomorphic encryption algorithm to generate the initial ciphertext; The data processing module is used to map the initial ciphertext to a finite field to obtain ciphertext data represented by the finite field. The data processing module is also used to perform multiplication operations on the ciphertext data within the finite domain; The data processing module is also used to backmap the result of the multiplication operation from the finite field to the homomorphically encrypted ciphertext space to obtain the target ciphertext.

8. A computer device, comprising a memory, a processor, and a computer program stored in the memory, characterized in that, The processor executes the computer program to implement the method of claim 1.

9. A computer-readable storage medium having a computer program / instructions stored thereon, characterized in that, When the computer program / instruction is executed by the processor, it implements the method of claim 1.

10. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instruction is executed by the processor, it implements the method of claim 1.