Data processing method and data processing device

By using a commitment mechanism based on algebraic one-way functions and a multi-layered encryption structure, the decryption certificate and the key are tightly bound together, solving the problems of resource waste and traceability difficulties caused by loose key binding, and realizing efficient key verification and traceability capabilities.

CN121864475APending Publication Date: 2026-04-14METEOROLOGICAL DEV & PLANNING INST OF CHINA METEOROLOGICAL ADMINISTRATION
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
METEOROLOGICAL DEV & PLANNING INST OF CHINA METEOROLOGICAL ADMINISTRATION
Filing Date
2026-02-14
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

In existing technologies, the binding relationship between keys and decryption credentials is loose, making it impossible to identify and avoid malicious operations. High privileges of internal management personnel lead to trust asymmetry, making it impossible to trace violations and resulting in serious waste of resources.

Method used

By using a commitment mechanism based on algebraic one-way functions, the unsealing certificate and key are tightly bound together, a commitment value is generated and encrypted in multiple layers, and traceability is performed by combining hardware feature parameters and project background parameters. A multi-layer encryption structure is designed to verify the correctness of the key.

Benefits of technology

It enables effective verification of key correctness during decryption, reduces resource waste, improves regulatory capabilities, and supports traceability and accountability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121864475A_ABST
    Figure CN121864475A_ABST
Patent Text Reader

Abstract

The invention provides a data processing method for an encryption party, a data processing method for a decryption party and a data processing device. The data processing method for the encryption party comprises the following steps: symmetrically encrypting a plaintext by using a first secret value to generate a ciphertext; obfuscating the first secret value based on the second secret value; generating a committed value for the second secret value using a first algorithm based on an algebraic one-way function; and encapsulating the obfuscated first secret value and commitment value to generate a data packet; performing asymmetric encryption on the data packet by using the public key; and packaging and sending the ciphertext and the encrypted data packet.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of information security, and more specifically to a data processing method for an encrypting party, a data processing method for a decrypting party, and a data processing apparatus. Background Technology

[0002] In modern cryptography, Key Encapsulation Mechanism (KEM) is a fundamental technology widely used in secure communication and data protection. The traditional KEM process for encrypted big data transmission typically involves the encryptor generating a one-time symmetric key to encrypt the data to be sent, then using a public key to encrypt the symmetric key before transmitting the encrypted data. The decryptor uses their private key to decrypt the data, obtain the symmetric key, and then decrypt the data. The security of this process primarily relies on the encryption protection of the symmetric key. However, in high-security business scenarios such as electronic bidding, judicial evidence preservation, authorized unlocking of critical data, and distribution of corporate secrets, the key decapsulation can be combined with specific external conditions or secret credentials (also known as "decapsulation credentials"), allowing only individuals or entities with decryption qualifications to perform the decryption action.

[0003] However, the above-mentioned mechanisms may have many problems in terms of security management, such as the inability to identify and avoid malicious operations, the high level of authority of internal management personnel leading to trust asymmetry, and the inability to trace violations when disputes occur.

[0004] Therefore, there is a need for an improved key management mechanism that can tightly bind decryption credentials and keys for business scenarios with high information security requirements. Summary of the Invention

[0005] To address the aforementioned issues, this disclosure provides a data processing method for encrypting data, a data processing method for decrypting data, a data processing apparatus, a data processing system, and a computer-readable storage medium.

[0006] According to a first aspect of this disclosure, a data processing method for an encryptor is provided, comprising: symmetrically encrypting plaintext using a first secret value to generate ciphertext; obfuscating the first secret value based on a second secret value; generating a commitment value for the second secret value using a first algorithm based on an algebraic one-way function; encapsulating the obfuscated first secret value and commitment value to generate a data packet; asymmetrically encrypting the data packet using a public key; and packaging and sending the ciphertext and the encrypted data packet together.

[0007] For example, in the data processing method according to this disclosure, packaging and sending ciphertext and encrypted data packets includes: generating a hash digest of the ciphertext and the encrypted data packets; digitally signing the hash digest using the private key of the encryptor to generate a signature value; and packaging and sending the ciphertext, the encrypted data packets, and the signature value.

[0008] By tightly binding the decryption certificate and key through an algebraic structure and designing a multi-layered encryption structure for layered encryption, the correctness of the key can be verified with minimal resources during decryption, thereby avoiding resource waste caused by malicious operations by the decryptor.

[0009] For example, in the data processing method according to this disclosure, the second secret value is generated through the following steps: obtaining traceability parameters, the traceability parameters including hardware characteristic parameters of the device used to generate the second secret value and / or project background parameters associated with the plaintext, wherein the project background parameters associated with the plaintext include a data sensitivity level associated with the plaintext, a project target value associated with the plaintext, and a complexity of the participating entities in the project associated with the plaintext; generating the second secret value based on a random value used to generate the second secret value and the traceability parameters, wherein the data processing method further includes: in response to receiving a decryption request sent by a decryption party, sending the random value and the traceability parameters to the decryption party.

[0010] By generating decryption credentials based on the hardware characteristic parameters of the generating device and / or the project background parameters associated with the plaintext, it is possible to trace the generating device that generates the decryption credentials and / or the business project associated with the plaintext, which helps to improve regulatory capabilities and facilitates subsequent audit investigations.

[0011] For example, in the data processing method according to this disclosure, the step of using a first algorithm based on an algebraic one-way function to generate the commitment value of the second secret value includes: selecting the first algorithm from two or more candidate algorithms based on an algebraic one-way function, wherein the two or more candidate algorithms include: a basic elliptic curve dot product algorithm, a Pedersen commitment algorithm, a threshold secret commitment algorithm, and a lattice-based post-quantum commitment algorithm.

[0012] For example, in the data processing method according to this disclosure, the data processing method further includes, in response to the first algorithm being the Pedersen commitment algorithm: in response to receiving a decryption request from the decryptor, sending an auxiliary random number to the decryptor for generating the commitment value.

[0013] For example, in the data processing method according to this disclosure, selecting the first algorithm from two or more candidate algorithms based on algebraic one-way functions includes: selecting the first algorithm from the two or more candidate algorithms based on one or more decision conditions associated with the plaintext, the decision conditions including: the data sensitivity level associated with the plaintext, the value of the item associated with the plaintext, the complexity of the participants in the item associated with the plaintext, the computing power of the encryption device, and the network communication performance parameters between the encryption device and the decryption device.

[0014] For example, in the data processing method according to this disclosure, selecting the first algorithm from the two or more candidate algorithms based on one or more of the decision conditions includes: selecting a threshold secret commitment algorithm as the first algorithm in response to the complexity of the participating entity being greater than or equal to a first predetermined threshold; and determining whether to exclude a lattice-based post-quantum commitment algorithm from the two or more candidate algorithms based on the device computing power and the network communication performance parameters in response to the complexity of the participating entity being less than the first predetermined threshold.

[0015] For example, in the data processing method according to this disclosure, selecting the first algorithm from the two or more candidate algorithms based on one or more of the decision conditions includes: calculating the security requirement level of the plaintext by weighting the values ​​of one or more of the decision conditions according to the following formula:

[0016]

[0017] in, Data sensitivity level associated with the plaintext The weight, The value of the project object associated with the plaintext. The weight, Complexity of participants in the project associated with the plaintext The weight, Network communication performance parameters between the encrypting party and the decrypting party The weight, The computing power of the encryption device The weights, and among them, The algorithm selects a candidate algorithm from two or more candidate algorithms as the first algorithm based on the security requirement level, including: selecting a lattice-based post-quantum commitment algorithm or a Pedersen commitment algorithm as the first algorithm in response to the security requirement level being greater than or equal to a second predetermined threshold; selecting a Pedersen commitment algorithm as the first algorithm in response to the security requirement level being less than the second predetermined threshold and greater than or equal to a third predetermined threshold; and selecting a basic elliptic curve dot product algorithm as the first algorithm in response to the security requirement level being less than the third predetermined threshold, wherein the second predetermined threshold is greater than the third predetermined threshold.

[0018] For example, in the data processing method according to this disclosure, encapsulating the obfuscated first secret value and the commitment value to generate the data packet includes: generating a header information block, wherein the header information block includes an algorithm identifier indicating the first algorithm and a traceability identifier, the traceability identifier indicating whether the second secret value is generated based on the traceability parameter; and concatenating at least the header information block, the obfuscated first secret value, and the commitment value using a communication protocol format to generate the data packet.

[0019] For example, in the data processing method according to this disclosure, asymmetric encryption of a data packet using a public key includes: in response to the data length of the data packet being less than or equal to a fourth predetermined threshold, asymmetric encryption of the data packet using the public key to generate an encrypted data packet; or in response to the data length of the data packet being greater than the fourth predetermined threshold, symmetric encryption of the data packet using a random temporary transmission key to generate an encrypted data packet, and asymmetric encryption of the random temporary transmission key using the public key, wherein the step of packaging and sending the ciphertext and the encrypted data packet includes sending the encrypted random temporary transmission key together with the encrypted data packet to the decryptor.

[0020] By adaptively selecting the most suitable algorithm for encryption based on the specific business scenario of the project associated with the plaintext, a balance can be struck between data security, computational overhead, and business scenario requirements, thereby improving the resource utilization efficiency of both the encryption and decryption devices.

[0021] According to a second aspect of this disclosure, a data processing method for a decryptor is provided, comprising: receiving ciphertext and an encrypted data packet; performing asymmetric decryption on the encrypted data packet using the decryptor's private key, and determining a commitment value, a first algorithm for generating the commitment value, and an obfuscated first secret value based on the decrypted data packet, wherein the first algorithm is an algorithm based on an algebraic one-way function; obtaining a second secret value, and using the first algorithm to perform commitment verification based on the second secret value and the commitment value; in response to successful commitment verification, restoring the obfuscated first secret value based on the second secret value to determine the first secret value; and performing symmetric decryption on the ciphertext using the first secret value to determine the plaintext.

[0022] For example, in the data processing method according to this disclosure, asymmetric decryption of the encrypted data packet using the decryptor's private key further includes: verifying the signature of the ciphertext and the encrypted data packet using the encryptor's public key; and performing asymmetric decryption in response to successful signature verification, and terminating decryption in response to failed signature verification.

[0023] For example, in the data processing method according to this disclosure, the header information block of the decrypted data packet includes an algorithm identifier indicating the first algorithm and a traceability identifier, the traceability identifier indicating whether the second secret value is generated based on traceability parameters, wherein the traceability parameters include hardware characteristic parameters of the device of the encryptor used to generate the second secret value and / or project background parameters associated with the plaintext, the project background parameters associated with the plaintext including a data sensitivity level associated with the plaintext, a target value associated with the plaintext, and a complexity of the participating entities in the project associated with the plaintext, and wherein obtaining the second secret value includes: in response to the traceability identifier indicating that the second secret value is generated based on the traceability parameters, obtaining the second secret value by the following steps: receiving a random value for generating the second secret value and the traceability parameters; and generating the second secret value based on the random value and the traceability parameters.

[0024] According to a third aspect of this disclosure, a data processing apparatus is provided, comprising: one or more processors; and a memory connected to the one or more processors, having stored thereon instructions executable by the one or more processors, the instructions, when executed, enabling the apparatus to perform the data processing methods according to various aspects of this disclosure.

[0025] According to a fourth aspect of this disclosure, a data processing system is provided, comprising: an encryption device, the encryption device being configured to perform a data processing method of the encryption party according to a first aspect of this disclosure; and a decryption device, the decryption device including a component for performing a data processing method of the decryption party according to a second aspect of this disclosure.

[0026] According to a fifth aspect of this disclosure, a computer-readable storage medium having instructions stored thereon is provided, which, when executed by one or more processors, cause the one or more processors to perform the data processing methods provided in the above aspects. Attached Figure Description

[0027] To more clearly illustrate the technical solutions according to the embodiments of this disclosure, the accompanying drawings used in the description of the embodiments will be briefly introduced below. The accompanying drawings in the following description are merely exemplary embodiments of this disclosure.

[0028] Figure 1 This is an example flowchart illustrating a data processing method of an encryption party according to an embodiment of the present disclosure;

[0029] Figure 2 This is a schematic diagram illustrating an example structure of a data packet encapsulated using a first embodiment according to an embodiment of the present disclosure;

[0030] Figure 3 This is a schematic diagram illustrating an example structure of a data packet encapsulated using a second embodiment according to an embodiment of the present disclosure;

[0031] Figure 4 This is an example flowchart illustrating a data processing method for a decryption method according to an embodiment of the present disclosure;

[0032] Figure 5 This is a schematic diagram illustrating a data processing system according to an embodiment of the present disclosure;

[0033] Figure 6 This is a schematic diagram illustrating a data processing apparatus according to an embodiment of the present disclosure.

[0034] It should be understood that the above-described drawings are provided to further illustrate the embodiments of this disclosure and constitute a part of the specification. They are used together with the embodiments of this disclosure to explain this disclosure, but do not constitute a limitation thereof. Detailed Implementation

[0035] To make the objectives, technical solutions, and advantages of this disclosure more apparent, exemplary embodiments according to this disclosure will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of this disclosure, and not all embodiments of this disclosure, and it should be understood that the exemplary embodiments described herein do not constitute a limitation of this disclosure.

[0036] In this specification and accompanying drawings, operations and elements that are substantially the same or similar are indicated by the same or similar reference numerals, and repeated descriptions of these operations and elements are omitted. Furthermore, in the description of this disclosure, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance or order. Moreover, the technical features involved in the different embodiments of this disclosure described below may be combined with each other as long as they do not conflict with each other.

[0037] As described in the background section, in business scenarios with high information security requirements, decryption credentials can be combined with keys to improve security. For example, a hash function-based commitment mechanism can be used to bind decryption credentials and keys, requiring verification of the decryption credentials before decryption can proceed. However, this binding relationship between decryption credentials and keys is loose, meaning it's impossible to prove a unique binding between them. This loose binding relationship presents numerous problems in terms of supervision and constraint.

[0038] Taking electronic bidding as an example, the encryptor can be the bidder, while the decryptor can be the tendering party or its agent. In the current electronic bidding process, the electronic bid is prepared and encrypted by the bidder before the bidding deadline and uploaded to a unified platform (e.g., a platform designated by the tendering party or its agent). Before the bid opening, the tendering party or its agent cannot know the bidding situation or the specific content of the bid. At the bid opening, the bidder submits the decryption certificate and key to the platform within a specified time for decryption.

[0039] In this process, for example, due to the weak collision resistance of hash functions, there is a possibility of forging decryption credentials to obtain the key and thus learn about the bidding situation and specific bid contents before the bid opening. Alternatively, since the function of decryption credentials in existing technology is mainly to verify whether someone is qualified to decrypt, if an internal staff member of the decryption party obtains the key with authorization, they may bypass this verification step and privately decrypt and view the bid documents before the bid opening.

[0040] For example, because the validity of the decryption certificate and the key are not strongly correlated, if a bidder unintentionally or maliciously submits an incorrect key, the tendering party or tendering agent may spend a significant amount of resources trying to decrypt it until the decryption fails before discovering the error. This leads to a waste of computing resources, and in some large projects involving multiple entities, it may even cause the entire process to be blocked due to the exhaustion of computing resources.

[0041] For example, keys and / or decryption credentials are usually randomly generated random numbers for one-time use. In the event of a dispute due to decryption failure, it may be impossible to trace the source. For instance, in cases of bid rigging or collusion, regulatory authorities may find it difficult to prove whether the keys of multiple entities were generated from the same physical device, resulting in a lack of key technical support for electronic forensics and liability determination.

[0042] Based on the above, this disclosure provides a data processing method, data processing apparatus, system, and computer-readable storage medium for encrypting and decrypting parties. According to embodiments of this disclosure, by using a commitment mechanism based on algebraic one-way functions to bind the decryption credential and the key, a tighter binding relationship can be established between the decryption credential and the key. Furthermore, based on this tight binding relationship, the correctness of the key can be verified with minimal resources during decryption, thereby improving system efficiency and reducing resource waste.

[0043] Figure 1 This is an example flowchart illustrating a data processing method 100 of an encryption method according to an embodiment of the present disclosure. Figure 1 The data processing method 100 shown can be derived from, for example... Figure 5 The data processing system 500 shown or such Figure 6 The data processing apparatus 600 shown is implemented or a computer-readable storage medium. For example... Figure 1 As shown, the data processing method 100 of the encryption party according to the embodiments of this disclosure can start from step S101.

[0044] In step S101, the plaintext can be symmetrically encrypted using the first secret value to generate ciphertext.

[0045] In this disclosure, the first secret value (denoted in this disclosure as...) The first secret key is a symmetric key used between the encrypting and decrypting parties to symmetrically encrypt plaintext; therefore, it can be interchangeably referred to as a "symmetric encryption key." In embodiments according to this disclosure, as a non-limiting example, the first secret value can be a k-bit random number. The first secret value can be generated randomly using a cryptographically secure function, such as a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG).

[0046] In embodiments according to this disclosure, plaintext (denoted in this disclosure as...) Plaintext can be any unencrypted raw information existing in various forms, such as data, text, strings, bitstreams, voice, and video images—any form that can be used for communication between the encrypting and decrypting parties. For example, in an electronic bidding scenario, plaintext can be the tender document. The tender document may contain various information related to the project being bid on, such as the value and price of the project, the project implementation plan and schedule used for bidding, confidential technical solutions, and a list of partner resources, etc., which are information that needs to be kept confidential.

[0047] In this disclosure, as a non-limiting example, the Advanced Encryption Standard-256 Galois / Counter Mode (AES-256-GCM algorithm) can be selected as the symmetric encryption algorithm. In this disclosure, the ciphertext generated by the symmetric encryption in step S101 can be denoted as... It should be understood that the function algorithm or symmetric encryption algorithm used to generate the first secret value described above can be other suitable algorithms, and this disclosure does not limit this.

[0048] At step S102, the first secret value can be obfuscated based on the second secret value.

[0049] In this disclosure, the second secret value (denoted in this disclosure as...) This can be interchangeably referred to as a "decryption credential," which is an additional secret value generated by the encrypting party in addition to the first secret value described above. In embodiments according to this disclosure, the second secret value may be generated in different ways.

[0050] In this disclosure, as a first generation method, the second secret value can be a randomly selected high-entropy random integer, wherein, ,and It is the order of the generator G on the algebraic group structure E defined over a finite field.

[0051] Therefore, alternatively or in order to enable subsequent traceability of the relevant secret value for regulatory purposes, a second secret value can be further generated based on parameters associated with the device generating the first / second secret value (e.g., an encryption device and / or a decryption device) and / or parameters associated with the background of the plaintext. In embodiments according to this disclosure, the parameters associated with the device generating the relevant secret value and / or the background parameters associated with the plaintext may be referred to as traceability parameters.

[0052] In this disclosure, as a second generation method, the second secret value can be generated based on hardware feature parameters. For example, as a non-limiting example, the second secret value can be generated by the following steps: (i) obtaining the hardware feature parameters of the device used to generate the second secret value; (ii) generating the second secret value based on a random value and the hardware parameters. Generally, since both the first and second secret values ​​are generated by the encryptor, the device used to generate the second secret value can also be the same device used to generate the first secret value.

[0053] Random value (denoted in this disclosure as) () can be a high-entropy random salt value, which can be generated by a random number generator or otherwise.

[0054] Hardware characteristic parameters (referred to in this disclosure as) This can include the CPU serial number of the generating device, the motherboard UUID, or the network card MAC address, etc.

[0055] In embodiments according to this disclosure, hardware characteristic parameters can be... With random values The concatenation is then performed. Next, the concatenated hardware feature parameters are processed using a Key Derivation Function (KDF). With random values Perform the operation and assign the result to the order of the generator G on the algebraic group structure E defined over a finite field. Take the modulo to obtain the second secret value. .

[0056] By generating a second secret value using hardware characteristic parameters, regulatory authorities can trace the device that generated the second secret value in case of disputes in subsequent stages. For example, in cases of bid rigging or collusion, multiple participants in the bidding process may actually be the same entity registering under different names. In such cases, the key may actually have been generated by the same device. In this situation, regulatory authorities can use the hardware characteristic parameters for electronic forensics and liability determination.

[0057] In this disclosure, as a third generation method, a second secret value can be generated based on project background parameters associated with the plaintext. For example, as a non-limiting example, the second secret value can be generated by the following steps: (i) obtaining project background parameters associated with the plaintext; (ii) generating a second secret value based on random values ​​and project background parameters associated with the plaintext.

[0058] In embodiments according to this disclosure, in an electronic bidding scenario, the project background parameters associated with the plaintext (denoted in this disclosure as...) This can include the data sensitivity level, the value of the project target, and the complexity of the participating entities.

[0059] The data sensitivity level associated with plaintext (denoted in this disclosure as) The data sensitivity level (also known as the "data sensitivity rating") indicates the confidentiality of plaintext. In this disclosure, as a non-limiting example, the data sensitivity level can be divided into three levels based on the type of plaintext:

[0060] Level I: This includes plain text documents such as ordinary business documents and public tender notices;

[0061] Level II: Commercial bids and general technical solutions that explicitly involve undisclosed quotations;

[0062] Level III: The text explicitly involves core intellectual property rights (such as core patents), key algorithm code, exclusive formulas, or core trade secrets.

[0063] Specifically, if it belongs to type 1, the parameter is set to 1; if it belongs to type 2, the parameter is set to 5; and if it belongs to type 3, the parameter is set to 10.

[0064] The value of the project object associated with the plaintext (denoted in this disclosure as) The asset value (also referred to as the "asset value") can indicate the asset size of an electronic bidding project associated with plaintext. In this disclosure, as a non-limiting example, the asset value can be quantified to a value within 10 for calculation purposes, such as setting the parameter to 1 if the asset size is <5 million; setting the parameter to 5 if it is between 5 million and 50 million; and setting the parameter to 10 if it is >50 million.

[0065] The complexity of the participants in the project associated with the plaintext (denoted in this disclosure as...) The "participant complexity" parameter (also known as "entity complexity") indicates the participating parties in a project associated with plaintext. If the project involves a single entity, for example, a single entity (e.g., a single company) bidding on the project as the sole responsible party, then each bidding entity can independently encrypt the plaintext as the encryptor. In other words, the relevant secret value can be generated independently by a single entity. However, if the project involves a consortium or multiple entities, for example, two or more entities bidding as a consortium, then all entities / multiple entities in the consortium need to jointly encrypt the plaintext as the encryptor. In other words, the relevant secret value needs to be jointly generated by all entities / multiple entities in the consortium. In this disclosure, as a non-limiting example, the parameter can be set to 1 when the project involves a single entity, and set to 10 when the project involves a consortium and / or multiple entities. Alternatively, the parameter can be set to different corresponding values ​​depending on the number of entities.

[0066] It should be understood that the above-described quantification method for the hierarchical assignment of project background parameters associated with the plaintext is exemplary and not restrictive. Depending on the specific implementation, different quantification methods can be adjusted according to the actual project participation situation, such as adjusting to normalization or choosing other methods. This disclosure does not limit this.

[0067] In embodiments according to this disclosure, the aforementioned project background parameters associated with the plaintext (i.e., data sensitivity level, project target value, and complexity of participating entities) can be serialized and then combined with random values. Concatenation. Similar to the second generation method, random values. This can be a high-entropy random salt value generated by a random number generator or otherwise. Then, the concatenated project background parameters associated with the plaintext are processed using a key derivation function. and random values Perform common operations and assign the results to the order of the generator G on the algebraic group structure E defined over a finite field. Take the modulo to obtain the second secret value. .

[0068] By generating a second secret value using project background parameters associated with plaintext, disputes in subsequent stages can be traced back to specific bidding projects through analysis of these parameters, avoiding the need to search through massive amounts of project data. For example, regulatory authorities may receive a report of irregularities in a project. If the unsealing certificate (i.e., the second secret value) embeds background parameters associated with that project, the regulatory authorities can directly and accurately match the reported bidding project using these parameters, without having to search through massive amounts of project data one by one, thus improving the efficiency of tracing the source. Simultaneously, the project background parameters associated with plaintext can also serve as key clues in electronic evidence collection, proving the correspondence between the unsealing certificate and a specific project, enhancing the relevance and verifiability of electronic evidence, and providing technical support for dispute resolution and liability determination.

[0069] In this disclosure, as a fourth generation method, a second secret value can be generated by simultaneously using hardware characteristic parameters and project background parameters associated with the plaintext, thereby achieving better traceability and supervision. For example, as a non-limiting example, the second secret value can be generated by the following steps: (i) obtaining the hardware characteristic parameters of the device used to generate the second secret value. and project background parameters associated with the plaintext (ii) Based on random values Hardware characteristic parameters and project background parameters associated with the plaintext Generate a second secret value.

[0070] Specifically, in embodiments according to this disclosure, the project background parameters (i.e., data sensitivity level, project value, and complexity of participating entities) associated with the plaintext can be serialized and then linked to hardware feature parameters. and random values Concatenate the data. Then, use a key derivation function to process the concatenated project background parameters associated with the plaintext. Hardware characteristic parameters and random values Perform common operations and assign the results to the order of the generator G on the algebraic group structure E defined over a finite field. Take the modulo to obtain the second secret value. .

[0071] It should be understood that in the above-mentioned second secret value generation method, the key derivation function can be selected as either the HMAC-based Key Derivation Function (HKDF) or the Password-Based Key Derivation Function 2 (PBKDF2) algorithm.

[0072] Furthermore, the aforementioned traceability parameters can be stored as credentials in the device used to generate the secret value, and sent to the decryptor during the subsequent decryption process to generate a second secret value for verification. For example, in an embodiment according to this disclosure, the data processing method 100 may further include: in response to receiving a decryption request from the decryptor, sending a random value and traceability parameters to the decryptor. Alternatively, in response to the traceability parameters including only project background parameters associated with the plaintext... The traceability parameters may not need to be sent separately when a decryption request is received from the decryptor, which will be explained in detail in the second implementation section on generating data packets.

[0073] Next, after obtaining the second secret value, the first secret value can be obfuscated using this second secret value. In embodiments according to this disclosure, as a non-limiting example, a hash digest of the second secret value can be calculated. Then, using the calculated results As a mask, the first secret value is processed by stream cipher operations (such as bitwise XOR). Obfuscation is performed to obtain the obfuscated first secret value. .

[0074] At step S103, the commitment value of the second secret value can be generated using a first algorithm based on an algebraic one-way function. The algebraic one-way function (denoted as...) () refers to a class defined in a finite field The mapping function of the algebraic group structure on the domain has computational one-wayness and algebraic homomorphism. Therefore, using the first algorithm based on the algebraic one-way function to generate the commitment value of the second secret value can ensure that the second secret value cannot be derived from the commitment value. Preferably, in this disclosure, the algebraic one-way function can be an elliptic curve over the prime field, whose equation is... ,in To define this prime number field Large prime numbers, and among them and To determine the coefficients for the shape of the elliptic curve, satisfying... This ensures the curve is non-singular. As a non-limiting example, the elliptic curve can be chosen as the standard curve secp256r1 (NIST P-256) or secp256k1.

[0075] Step S103 may further include selecting a first algorithm from two or more candidate algorithms based on algebraic one-way functions. In embodiments according to this disclosure, the two or more candidate algorithms based on algebraic one-way functions may include: a basic elliptic curve dot product algorithm, a Pedersen commitment algorithm, a threshold secret commitment algorithm, and a lattice-based post-quantum commitment algorithm. After selecting the first algorithm from the candidate algorithms, it can be used to generate a commitment value for a second secret value. Specifically, in embodiments according to this disclosure:

[0076] In response to selecting the basic elliptic curve dot product algorithm as the first algorithm, the second secret value can be... As a scalar, it is multiplied by an elliptic curve scalar with the previously defined generator G to obtain the commitment value. .

[0077] In response to the selection of the Pedersen commitment algorithm as the first algorithm, the second secret value can be... In addition, a high-entropy auxiliary random number r is introduced. Another generator is selected on an elliptic curve E defined over a finite field. And it requires that the generator cannot be computed. The discrete logarithmic relationship between the generator H and G and the previously defined generator G allows the calculation of the commitment value based on the generators H and G. In this scenario, the auxiliary random number r can be sent separately by the user through a secure channel to the decryptor after the decryptor issues a decryption request, for use in commitment verification.

[0078] In response to the choice of the threshold secret commitment algorithm as the first algorithm, the second secret value is not used directly. Instead, it constructs a polynomial. Then, for each coefficient of the polynomial, a commitment is calculated to obtain a set of commitment values. Assuming there are t individuals collaborating to bid on the project, each individual participating in the project needs to obtain their corresponding shard. (in It serves as the unique identifier for the individual and holds the corresponding commitment value for the shard.

[0079] In response to the selection of a lattice-based post-quantum commitment algorithm as the first algorithm, a matrix can be constructed. and error vector And calculate the second secret value. Commitment value .

[0080] By using the commitment algorithm based on algebraic one-way functions to bind the unsealing certificate and the key, a stronger collision-resistant binding relationship can be established between the unsealing certificate and the key, thereby reducing the possibility that the unsealing certificate can be forged to obtain the key and thus know the bidding situation and specific bid content in advance before the bid opening.

[0081] In a first embodiment according to this disclosure, the first algorithm may be configured manually (by staff of the tendering party or tendering agent).

[0082] Preferably, in the second embodiment of this disclosure, the first algorithm can automatically select from the two or more candidate algorithms. For example, it can automatically determine and notify each bidding participant to encrypt the corresponding algorithm based on the parameter values ​​of a specific scenario, so as to automatically adapt to different reliability confidentiality purposes in different scenarios. For example, in an embodiment of this disclosure, selecting the first algorithm from two or more candidate algorithms based on algebraic one-way functions may include selecting the first algorithm from two or more candidate algorithms based on one or more decision conditions associated with the plaintext. The decision conditions may include: the data sensitivity level associated with the plaintext, the value of the project associated with the plaintext, the complexity of the participating entities of the project associated with the plaintext, the computing power of the encrypting party's device, and the network communication performance parameters between the encrypting party and the decrypting party.

[0083] In this disclosure, the selection of the algorithm used for commitment calculation is primarily determined by considering both business context and computing resources. Regarding the business context, the data sensitivity level, target value, and complexity of participating entities in the aforementioned decision conditions have already been described in the section on the optional generation methods of the second secret value in step S102, and will not be repeated here for the sake of brevity. Regarding computing resources, this disclosure primarily considers the device's computing power and network communication performance parameters. In this disclosure, these decision conditions can also be referred to as "contextual environment parameters" and can be sent along with auxiliary information.

[0084] Network communication performance parameters between the encryptor and decryptor (denoted in this disclosure as) Network communication performance parameters (also referred to as "network communication performance parameters") can indicate the communication network environment between a client and a server. In embodiments according to this disclosure, as a non-limiting example, network communication performance parameters... The network communication performance parameters can be determined based on the communication network environment when the data processing method 100 is executed. In response to detecting a weak network environment (e.g., the current network type is below 4G or network latency and packet loss rate exceed a certain threshold), the network communication performance parameters can be adjusted. It can be set to 1; in response to detecting that the communication network environment is a 4G or broadband network, the network communication performance parameters... It can be set to 5; in response to detecting that the communication network environment is a leased network (such as an enterprise leased network), the network communication performance parameters... It can be set to 10.

[0085] The computing power of the encryption device (referred to in this disclosure as) This (also known as "device computing power") indicates the computing power of an encrypted device, and it can be determined based on the type of encrypted device. For example, as a non-limiting example, if the encrypted device is identified as a mobile device or IoT device, its computing power can be considered limited and... Set to 1; if the encrypted device is identified as a personal computer (e.g., it can include a desktop computer), then the computing power can be considered normal and... Set to 5; if the encrypted device is identified as a high-performance server cluster, then it can be assumed that the computing power is sufficient to support complex calculations and will Set it to 10.

[0086] The following describes a specific algorithm selection strategy according to embodiments of this disclosure. In this disclosure, business compliance may be given priority. For example, when a project involves a consortium or multiple entities, in embodiments according to this disclosure, a threshold secret commitment algorithm may be selected as the first algorithm in response to the complexity of the participating entities being greater than or equal to a first predetermined threshold. As a non-limiting example, the first predetermined threshold may be set to 10. It should be understood that the first predetermined threshold may be set to different values ​​depending on different quantification methods for the complexity of the participating entities, and this disclosure does not impose any limitations on this.

[0087] Furthermore, while lattice-based post-quantum commitment algorithms offer higher security, they generate large ciphertext sizes and involve complex matrix operations, thus placing high demands on communication networks and computing resources. Therefore, in embodiments according to this disclosure, the decision to exclude lattice-based post-quantum commitment algorithms from a pool of candidate algorithms can be based on computing power and network communication performance parameters. For example, in response to network communication performance parameters... Or device computing power This allows lattice-based post-quantum commitment algorithms to be eliminated from multiple candidate algorithms.

[0088] Next, in embodiments according to this disclosure, the decision conditions can be weighted to calculate the security requirement level of the plaintext, and a corresponding candidate algorithm can be selected from the two or more candidate algorithms as the first algorithm based on the security requirement level. For example, as a non-limiting example, each decision condition (i.e., data sensitivity level) can be weighted. The value of the project target Complexity of participating entities Network communication performance parameters Equipment computing power The security requirement level is obtained by weighting and applying the following expression. :

[0089]

[0090] In embodiments according to this disclosure, as described above, the priority of the decision conditions considered can be the weights of the data sensitivity levels. =Weight of the project's target value Weights based on the complexity of participating entities Weights of network communication performance parameters =Weight of device computing power For example, as a non-limiting example, the weight coefficients of each decision condition in this disclosure can be set to... =0.3, =0.3, =0.2, =0.1, =0.1. This is because: In electronic bidding scenarios, data sensitivity and project value are core factors for bidding security considerations. The higher the data sensitivity level and the larger the project value, the more severe the consequences of leakage. Therefore, when selecting an algorithm strategy, both need to be set as equally important and given the highest priority. Secondly, if the bidding process involves multiple parties, the time and complexity of the key distribution and decryption processes may increase, correspondingly increasing the risk of key leakage and tampering. However, if many parties are involved but the actual data sensitivity level and project value are not high, using complex algorithms for encryption (such as lattice-based post-quantum commitment algorithms) may lead to over-encryption, making the bidding process too lengthy and wasting computational resources. Therefore, the complexity of participating parties can be set as the second priority. Finally, device computing power and network communication performance parameters are operating environment conditions and are not core factors for electronic bidding. As long as it is ensured that both the encryptor and decryptor can run the selected algorithm normally, it is sufficient.

[0091] After calculating the security requirement level of the plaintext, in embodiments according to this disclosure, in response to the security requirement level being greater than or equal to a second predetermined threshold, a lattice-based post-quantum commitment algorithm or a Pedersen commitment algorithm may be selected as the first algorithm; in response to the security requirement level being less than the second predetermined threshold and greater than or equal to a third predetermined threshold, a Pedersen commitment algorithm may be selected as the first algorithm; and in response to the security requirement level being less than the third predetermined threshold, a basic elliptic curve dot product algorithm may be selected as the first algorithm, wherein the second predetermined threshold is greater than the third predetermined threshold. It should be understood that, depending on the quantification method of the decision conditions used in a specific implementation, the second and third predetermined thresholds may be set to different values, and this disclosure does not limit this.

[0092] For example, following the quantification method described above for the aforementioned decision-making conditions, as a non-limiting example, in response to the plaintext security requirement level... This can indicate high data sensitivity, high value, a consortium, or multiple entities, thus allowing a lattice-based post-quantum commitment algorithm to be chosen as the first algorithm. However, if computational and network limitations exist (e.g., insufficient computational resources due to the need to use internal servers for compliance requirements), the lattice-based post-quantum commitment algorithm can be excluded from the multiple candidate algorithms as described above. In this case, the Pedersen commitment algorithm can be chosen as the first algorithm.

[0093] The security requirement level in response to plaintext is It can indicate scenarios with moderate data sensitivity, moderate value, and conventional network and computing resources, and the Pedersen commitment algorithm can be selected as the first algorithm.

[0094] The security requirement level in response to plaintext is It can indicate that the project does not involve complex scenarios with high data sensitivity, high value, or complex consortiums, so the basic elliptic curve dot product algorithm with the fastest computation speed and the least storage can be selected as the first algorithm.

[0095] In this way, computational efficiency can be optimized for different scenarios, dynamically reducing redundant overhead. For example, when the complexity of the participating entities... Greater than a predetermined threshold (e.g.) (≥ 10) Choosing a threshold secret commitment algorithm can support multi-party collaborative key recovery to meet compliance requirements, but the computational overhead will increase by approximately 30%. (If the device's computing power...) Low or network bandwidth The shortcomings of lattice-based post-quantum algorithms can be ruled out, and instead, the computationally faster and more resource-intensive basic elliptic curve multiplication (ECM) algorithm or the Pedersen commitment algorithm can be chosen. For example, in terms of computation time, the computation time of the basic ECM algorithm or the Pedersen commitment algorithm can be only 1 / 5 that of the lattice-based post-quantum algorithm, and the communication time can be reduced by about 60%; in terms of storage, the commitment value of the basic ECM algorithm or the Pedersen commitment algorithm, after compression, only requires 33 bytes, while the commitment value of the lattice-based post-quantum algorithm is much longer and variable. Therefore, when the security requirements are low (e.g., when S is less than a third predetermined threshold), choosing the basic ECM algorithm can reduce communication overhead and unnecessary bandwidth consumption.

[0096] Taking the bidding process for a large-scale national infrastructure project as an example, this project has high data sensitivity ( =10), the project target has high value ( =10), with over 200 participating entities ( =10), sufficient network bandwidth ( =10), but the tenderer needs to use internally deployed physical servers (e.g., for compliance requirements), resulting in limited computing resources ( =3). Based on the adaptive strategy described in embodiments of this disclosure, the security requirement level corresponding to the project can be calculated in response to the algorithm. The Pedersen commitment algorithm was chosen due to computational resource constraints. In the case of manual / fixed configuration algorithms, the tendering party might, without considering or understanding the computational resource limitations, use a lattice-based post-quantum commitment algorithm for large-scale national infrastructure projects to ensure encryption security. This could lead to high server resource consumption, and multiple entities might simultaneously encrypt and upload tender documents / conduct bid opening and decryption at the last minute, causing server crashes and preventing normal encryption or decryption.

[0097] Furthermore, when multiple projects are conducted simultaneously on the same bidding platform, manual configuration of algorithms may lead to errors due to factors such as concentrated deadlines and complex parameter configurations, which could result in process disputes or the risk of information leakage.

[0098] As described above, by calculating the security requirement level of plaintext based on the specific business scenario, network, and device capabilities of the project associated with the plaintext according to the embodiments of this disclosure, and adaptively selecting the most suitable algorithm for commitment encryption under different circumstances, a balance can be struck between data security, computational overhead, and business scenario requirements. This not only improves the resource utilization efficiency of both the encryption and decryption devices, but also avoids the problems of over-encryption / insufficient protection levels or cumbersome and error-prone manual configuration due to the pursuit of uniform configuration.

[0099] In step S104, the obfuscated first secret value and commitment value can be encapsulated to generate a data packet. The following will combine... Figure 2 and Figure 3 The specific implementation method of the encapsulation is described in detail.

[0100] Figure 2 This is a schematic diagram illustrating an example structure of a data packet 200 encapsulated using a first embodiment according to an embodiment of the present disclosure. Figure 2 As shown, the fields of data packet 200 may include a header information block, a commitment field, and a first secret value field.

[0101] The header information block is used to instruct the decryptor of the received data packet 200 how to parse the subsequent payload. For example... Figure 2 As shown, the fields in the header information block may include protocol identifier, protocol version number, algorithm identifier, traceability identifier, and flag bits.

[0102] The protocol identifier is used to identify the type of data packet 200. In embodiments according to this disclosure, the protocol identifier can be a 3-byte field. As a non-limiting example, the protocol identifier can be configured as the hexadecimal number 0x4B454D to indicate that data packet 200 is a data packet generated through a key encapsulation mechanism.

[0103] The protocol version number is used to ensure backward compatibility of the protocol. In embodiments according to this disclosure, it can be a 1-byte field. For example, in electronic bidding scenarios, encryption / decryption protocols may be upgraded iteratively with business needs, but historical bid documents usually need to be retained for long-term auditing and regulatory traceability. Therefore, in the new version, the corresponding decryption logic of the old version can be automatically switched by recognizing this field, thereby ensuring that bid documents encrypted with the old version can still be decrypted normally, avoiding the risk that historical data cannot be verified due to protocol upgrades.

[0104] An algorithm identifier is used to identify the first algorithm, enabling the decryptor to know which algorithm was used for commitment verification. In embodiments according to this disclosure, as a non-limiting example, the algorithm identifier may be a 1-byte field, wherein setting the algorithm identifier to 0x01 indicates a basic elliptic curve dot product algorithm, setting it to 0x02 indicates a Pedersen commitment algorithm, setting it to 0x03 indicates a threshold secret commitment algorithm, and setting it to 0x04 indicates a lattice-based post-quantum commitment algorithm.

[0105] The traceability capability identifier is used to indicate the specific method of generating the second secret value, enabling the decrypting party to know how to obtain the second secret value for commitment verification. In embodiments according to this disclosure, as a non-limiting example, the traceability capability identifier may be a 1-byte field.

[0106] As a non-limiting example, when the second secret value is generated using the first generation method as described above (i.e., a high-entropy random integer), the traceability identifier is set to 0x01, indicating that the decryptor can directly request and receive the second secret value during decryption.

[0107] When the second secret value is generated using the second generation method described above (i.e., based on hardware characteristic parameters), the traceability capability identifier is set to 0x02, indicating the hardware characteristic parameters of the device used to generate the second secret value that the decryptor needs during decryption. and random values To generate the second secret value.

[0108] When the second secret value is generated using the third generation method described above (i.e., based on the project background parameters associated with the plaintext), the traceability identifier is set to 0x03, indicating that the decryptor needs the project background parameters associated with the plaintext to generate the second secret value during decryption. and random values To generate the second secret value.

[0109] When the second secret value is generated using the fourth generation method described above (i.e., based on hardware characteristic parameters and project background parameters associated with the plaintext), the traceability identifier is set to 0x04, indicating the hardware characteristic parameters of the device used to generate the second secret value that the decryptor needs during decryption. and project background parameters associated with the plaintext and random values To generate the second secret value.

[0110] A flag bit can indicate whether the commitment value is compressed. As a non-limiting example, the flag bit can be 1 bit, set to 1 when it is determined that the commitment value is compressed, and 0 otherwise. Specifically, in embodiments according to this disclosure, the commitment value can be compressed to further reduce transmission bandwidth. For example, as a non-limiting example, if the first algorithm is a basic elliptic curve dot product algorithm or a Pedersen commitment algorithm, the commitment value can be compressed using a standard compression format (Standards for Efficient Cryptography 1, SEC1) by storing only the parity bits of the X and Y coordinates. It should be noted that for threshold secret commitment algorithms or lattice-based post-quantum commitment algorithms, the commitment value may not be compressed. This is because: firstly, there is no universal standard for compression of these two algorithms, and inconsistencies in parsing can easily occur after compression, making the commitment value unverifiable; secondly, when these two algorithms are selected as the first algorithm according to the commitment algorithm selection strategy of this disclosure, their applicable scenarios have been considered to be scenarios involving consortia or projects with high security requirements, and suitable network communication environments and computing resources are available.

[0111] The commitment field in data packet 200 may include two subfields: commitment value length and commitment value data. In embodiments of this disclosure, the commitment value length indicates the data length of the commitment value, which may be a 2-byte field. For the basic elliptic curve dot product algorithm or the Pedersen commitment algorithm, it is typically 33 bytes (compressed) or 65 bytes (uncompressed); for lattice ciphers or threshold schemes, the length is variable.

[0112] The first secret value field in data packet 200 is an obfuscated first secret value.

[0113] Next, in embodiments according to this disclosure, the header information block, commitment field, and first secret value field can be encoded using a communication protocol format. For example, the DER encoding rules defined by the ASN.1 (Abstract Syntax Notation One) standard can be used, or the TLV (Tag-Length-Value) compact binary format can be used. Then, the encoded header information block, commitment field, and first secret value field are concatenated into a continuous binary file according to the protocol-specified order and big-endian byte order, and encapsulation is completed to obtain data packet 200.

[0114] In this disclosure, as an optional second implementation, context parameters can be included in the data packet for encapsulation. Figure 3 This is a schematic diagram illustrating an example structure of a data packet 300 encapsulated using a second embodiment according to an embodiment of the present disclosure.

[0115] Compared to Figure 2 The structure of data packet 200 shown is as follows: Figure 3 The fields of data packet 300 shown can additionally include context parameters. This is because context parameters can represent the temporary state at the time of encryption, and therefore can be encapsulated and packaged with the data packet for subsequent tracing and auditing.

[0116] like Figure 3 As shown, the context parameter field may include the values ​​of the aforementioned parameter items. Data sensitivity level Complexity of participating entities Network communication performance parameters and device computing power As subfields, each subfield is 1 byte long. As mentioned earlier, the value of the target parameter, the data sensitivity level, and the complexity of the participating entities can be sent to the decryption party as traceability parameters to verify the commitment. Network communication performance parameters and device computing power can also be additionally sent to the decryption party for monitoring traceability and auditing.

[0117] Since the encrypting party may not send network communication performance parameters and device computing capabilities, the flag bit can be increased by 1 bit to indicate the validity of the subfields "Network Communication Performance Parameters" and "Device Computing Capabilities" in the context environment parameters field. For example, as... Figure 3 As shown, the flag bit can include two bits, where Bit_0 indicates whether the commitment value is compressed, and Bit_1 indicates whether the subfields of network communication performance parameters and device computing power in the context environment parameter field are valid. Specifically, when Bit_1 is set to 0, it indicates that these two subfields are invalid, and when Bit_1 is set to 1, it indicates that they are valid.

[0118] return Figure 1 After obtaining the data packet, in step S105, the data packet can be asymmetricly encrypted using the public key. In this disclosure, either the RSA-Optimal Asymmetric Encryption Padding (RSA-OAEP) algorithm or the Elliptic Curve Integrated Encryption Scheme (ECIES) algorithm can be selected as the asymmetric encryption algorithm. It should be understood that other suitable algorithms can be selected as the asymmetric encryption algorithm, and this disclosure does not limit this selection.

[0119] In this disclosure, to improve efficiency, different asymmetric encryption methods can be adaptively selected based on the length of the data packet. For example, the data packet may be large when using a lattice-based post-quantum commitment algorithm. For instance, in embodiments according to this disclosure, asymmetric encryption of the data packet using a public key may include: in response to the data length of the data packet being less than or equal to a fourth predetermined threshold, asymmetric encryption of the data packet using the public key to generate an encrypted data packet; or in response to the data length of the data packet being greater than the fourth predetermined threshold, symmetric encryption of the data packet using a random temporary transmission key to generate an encrypted data packet, and asymmetric encryption of the random temporary transmission key using the public key, wherein sending the ciphertext and the encrypted data packet together includes sending the encrypted random temporary transmission key along with the encrypted data packet to the decryptor. As a non-limiting example, the fourth predetermined threshold may be set to a plaintext length limit for the asymmetric algorithm, such as the plaintext length limit for the RSA-OAEP algorithm or the ECIES algorithm. It should be understood that, depending on the different asymmetric encryption algorithms selected, the fourth predetermined threshold may be set to other suitable values, and this disclosure does not limit this.

[0120] Finally, in step S106, the ciphertext and the encrypted data packet can be packaged and sent. In this disclosure, the encrypted data packet can be denoted as... That is, the transmission structure of the data packet ultimately sent to the decryptor can be... .

[0121] Optionally, to prevent tampering, in embodiments according to this disclosure, packaging and sending the ciphertext and encrypted data packet may include: generating a hash digest of the ciphertext and the encrypted data packet; digitally signing the hash digest using the encryptor's private key to generate a signature value; and packaging and sending the ciphertext, the encrypted data packet, and the signature value. In this disclosure, the signature value of the hash digest of both the ciphertext and the encrypted data packet can be denoted as... That is, in the case of digital signatures, the transmission structure of the data packet ultimately sent to the decryptor can be... It should be understood that any suitable digital signature algorithm can be used in the embodiments according to this disclosure, and this disclosure is not limited thereto.

[0122] Figure 4 This is an example flowchart illustrating a data processing method for decryption according to an embodiment of the present disclosure. Figure 4 The data processing method 400 shown can be derived from, for example... Figure 5 The data processing system 500 shown or such Figure 6 The data processing apparatus 600 shown is implemented or a computer-readable storage medium. For example... Figure 4As shown, the data processing method 400 of the decryption party according to the embodiments of this disclosure can start from step S401.

[0123] At step S401, ciphertext and encrypted data packets can be received. Then, at step S402, the encrypted data packets can be asymmetrically decrypted using the decryptor's private key, and a commitment value, a first algorithm for generating the commitment value, and a confused first secret value can be determined based on the decrypted data packets, wherein the first algorithm is an algorithm based on an algebraic one-way function.

[0124] If the final data packet sent by the encryptor to the decryptor is signed (i.e., the transmission structure of the received data packet is...), then... Before performing asymmetric decryption, signature verification is required. If signature verification fails, it indicates that the data has been tampered with or the identity of the data packet sender is questionable (e.g., the data packet sender is not the corresponding encryptor). In this case, data processing method 400 will terminate directly without performing any decryption operation. Therefore, in step S401, performing asymmetric decryption of the encrypted data packet using the decryptor's private key may also include: verifying the signature of the ciphertext and the encrypted data packet using the encryptor's public key; and performing asymmetric decryption in response to successful signature verification, and terminating decryption in response to signature verification failure.

[0125] The transmission structure in response to successful signature verification or received data packets is It can perform asymmetric decryption of encrypted data packets and obtain algorithm identifiers and traceability identifiers from the header information blocks of decrypted data packets.

[0126] In embodiments according to this disclosure, a first algorithm for generating commitment values ​​can be determined based on an algorithm identifier. For example, as a non-limiting example, the algorithm identifier can be a 1-byte field, wherein setting the algorithm identifier to 0x01 indicates a basic elliptic curve dot product algorithm, setting it to 0x02 indicates a Pedersen commitment algorithm, setting it to 0x03 indicates a threshold secret commitment algorithm, and setting it to 0x04 indicates a lattice-based post-quantum commitment algorithm.

[0127] When the algorithm identifier indicates that the Pedersen commitment algorithm is the first algorithm, the data processing method 400 may include issuing a decryption request to the packet sender to request it to send an auxiliary random number r for generating the commitment value.

[0128] Since the threshold secret commitment algorithm requires all participants to submit a valid fragment before the second secret value can be recovered from the fragment, when the algorithm identifier indicates that the threshold secret commitment algorithm is the first algorithm, the data processing method 400 may include indicating that it is necessary to wait for t fragments to be collected. Only then can commitment verification be carried out.

[0129] At step S403, a second secret value can be obtained, and a first algorithm can be used to perform commitment verification based on the second secret value and the commitment value.

[0130] In embodiments according to this disclosure, the method of obtaining the second secret value can be determined based on a traceability identifier included in the header information block of the decrypted data packet. The traceability identifier can be a 1-byte field that indicates whether the second secret value was generated based on traceability parameters. In response to the traceability identifier indicating that the second secret value was not generated based on traceability parameters, the data processing method 400 may include directly requesting and receiving the second secret value from the data packet sender. For example, as a non-limiting example, a traceability identifier of 0x01 indicates that the decryptor can directly request and receive the second secret value.

[0131] Accordingly, in response to the traceability capability identifier indicating that the second secret value is generated based on traceability parameters, the second secret value can be obtained through the following steps: receiving a random value and traceability parameters from a device used to generate the second secret value; and generating the second secret value based on the random value and traceability parameters, wherein the traceability parameters include hardware characteristic parameters of the device used to generate the second secret value and / or project background parameters associated with the plaintext. The second secret value can then be regenerated at the decryption point by the decryption device using the random value and traceability parameters.

[0132] For example, as a non-limiting example, a traceability capability identifier of 0x02 indicates that the decryptor needs to request the hardware characteristic parameters of the device used to generate the second secret value during decryption. and random values Then, the decryption device can recalculate the second secret value, for example... .

[0133] Similarly, when the traceability capability identifier is 0x03, it indicates that during decryption, the decryptor needs to request the project background parameters associated with the plaintext used to generate the second secret value. and random values Then, the decryption device can recalculate the second secret value, for example... .

[0134] When the traceability identifier is 0x04, it indicates that the decryptor needs to request the hardware characteristic parameters of the device used to generate the second secret value during decryption. and project background parameters associated with the plaintext and random values Then, the decryption device can recalculate the second secret value, for example... .

[0135] Next, a first algorithm can be used to perform commitment verification based on the second secret value and the commitment value in the decrypted data packet. Specifically, in embodiments according to this disclosure, the first algorithm can be used to generate the commitment value of the second secret value (denoted in this disclosure as ). Then, the generated commitment value can be determined. and the commitment value in the decrypted data packet Whether they are consistent. When If successful, the verification is confirmed; otherwise, if verification fails, the decryption process is terminated.

[0136] At step S404, in response to successful commitment verification, the obfuscated first secret value can be restored based on the second secret value to determine the first secret value. In embodiments according to this disclosure, a hash digest of the second secret value can be calculated. Then, stream cipher operations (such as bitwise XOR) are performed on the obfuscated first secret value. Perform the restoration to obtain the first secret value. .

[0137] Finally, at step 405, the ciphertext can be symmetrically decrypted using the first secret value to determine the plaintext. Optionally, in embodiments according to this disclosure, sensitive data, such as the first and second secret values, can be removed from the decryption device after the plaintext is obtained. Data such as tracing parameters and contextual parameters can be archived for subsequent review and oversight. For example, if a dispute arises after decryption is terminated, the tracing parameters and / or contextual parameters can be retrieved for investigation and accountability.

[0138] The data processing method 400 according to embodiments of this disclosure first verifies the digital signature to ensure the data source is correct and has not been tampered with; secondly, it performs commitment verification to ensure the key is correct; and only then does it perform key recovery and decryption. Through this multi-layered verification system, the correctness of the key can be verified with minimal resources, thereby avoiding resource waste.

[0139] Figure 5 This is a schematic diagram illustrating a data processing system 500 according to an embodiment of the present disclosure. The data processing system 500 can be implemented by an electronic device or apparatus by running a computer program including instructions; that is, it can be a software system or an electronic system.

[0140] like Figure 5 As shown, the data processing system 500 may include an encryption device 501 and a decryption device 502. The encryption device can act as the encryptor and may include components for performing operations according to... Figures 1 to 3The components of the data processing method 100 for an encrypting party according to embodiments of the present disclosure are described, and the decryption device can act as the decrypting party and may include components for performing the data processing according to the present disclosure. Figure 4 The components of a data processing method 400 for decryption according to embodiments of the present disclosure are described.

[0141] Figure 6 This is a schematic diagram illustrating a data processing apparatus 600 according to an embodiment of the present disclosure. Figure 6 As shown, the data processing device 600 may include one or more processors 601 and a memory 602 connected to the one or more processors 601. The memory 602 stores instructions executable by the one or more processors 601. When the instructions are executed by the instructions executable by the one or more processors 601, the device 600 is enabled to perform the following operations: Figures 1 to 4 The data processing method according to embodiments of the present disclosure is described herein.

[0142] The processor 601 may be any processing-capable device capable of implementing the functions according to embodiments of the present disclosure, such as a general-purpose processor, digital signal processor (DSP), ASIC, field programmable gate array (FPGA) or other programmable logic device (PLD), discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein.

[0143] The memory 602 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) and / or cache memory, or other removable / non-removable, volatile / non-volatile computer system memory, such as hard disk drives, CD-ROMs, DVD-ROMs, or other optical storage media.

[0144] The data processing methods, data processing systems, and apparatus according to embodiments of this disclosure can also be implemented by providing a computer program product containing program code implementing the methods, systems, and apparatus, or by any storage medium storing such a computer program product.

[0145] According to embodiments of this disclosure, a computer-readable storage medium having instructions stored thereon, which, when executed by one or more processors, cause the one or more processors to perform a reference... Figures 1 to 4The data processing methods according to embodiments of the present disclosure are described herein. In embodiments of the present disclosure, the computer-readable storage medium may be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. Non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory may be random access memory (RAM), which serves as an external cache. By way of example, but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct memory bus random access memory (DR RAM). It should be noted that the memory of the methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0146] It should be noted that the flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. Each block in a flowchart or block diagram may represent a module, segment, or portion of code, which contains one or more executable instructions for implementing a specified logical function. It should be noted that in some alternative embodiments, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0147] In general, the various exemplary embodiments of this disclosure can be implemented in hardware or dedicated circuitry, software, firmware, logic, or any combination thereof. Some aspects can be implemented in hardware, while others can be implemented in firmware or software that can be executed by a controller, microprocessor, or other computing device. When aspects of embodiments of this disclosure are illustrated or described as block diagrams, flowcharts, or using some other graphical representation, it will be understood that the blocks, apparatuses, systems, techniques, or methods described herein can be implemented as non-limiting examples in hardware, software, firmware, dedicated circuitry or logic, general-purpose hardware or controllers or other computing devices, or some combination thereof.

[0148] The exemplary embodiments described above according to this disclosure are merely illustrative and not restrictive. Those skilled in the art will understand that various modifications and combinations of these embodiments or their features can be made without departing from the principles and spirit of this disclosure, and such modifications should fall within the scope of this disclosure.

Claims

1. A data processing method for an encryptor, comprising: The plaintext is symmetrically encrypted using the first secret value to generate ciphertext; The first secret value is obfuscated based on the second secret value; The commitment value of the second secret value is generated using a first algorithm based on algebraic one-way functions; The obfuscated first secret value and the promised value are encapsulated to generate a data packet; The data packet is asymmetrically encrypted using a public key; as well as The ciphertext and encrypted data packets are packaged and sent.

2. The data processing method of claim 1, wherein, The second secret value is generated through the following steps: Obtain tracing parameters, which include hardware feature parameters of the device used to generate the second secret value and / or project background parameters associated with the plaintext, wherein the project background parameters associated with the plaintext include the data sensitivity level associated with the plaintext, the value of the project associated with the plaintext, and the complexity of the participating entities in the project associated with the plaintext; The second secret value is generated based on the random value used to generate the second secret value and the tracing parameter. The data processing method further includes: In response to receiving a decryption request from the decryptor, the random value and the tracing parameter are sent to the decryptor.

3. The data processing method of claim 1, wherein, The step of using a first algorithm based on algebraic one-way functions to generate the commitment value of the second secret value includes: The first algorithm is selected from two or more candidate algorithms based on algebraic one-way functions, wherein the two or more candidate algorithms include: basic elliptic curve dot product algorithm, Pedersen commitment algorithm, threshold secret commitment algorithm, and lattice-based post-quantum commitment algorithm.

4. The data processing method of claim 3, wherein, The data processing method further includes a response to the first algorithm being the Pedersen commitment algorithm: In response to receiving a decryption request from the decryptor, an auxiliary random number for generating the commitment value is sent to the decryptor.

5. The data processing method of claim 3, wherein, The step of selecting the first algorithm from the two or more candidate algorithms based on algebraic one-way functions includes: The first algorithm is selected from two or more candidate algorithms based on one or more of the decision conditions associated with the plaintext, the decision conditions including: The data sensitivity level associated with the plaintext, the value of the project associated with the plaintext, the complexity of the participating entities in the project associated with the plaintext, the computing power of the encrypting party's device, and the network communication performance parameters between the encrypting party and the decrypting party.

6. The data processing method as described in claim 5, wherein, The step of selecting the first algorithm from two or more candidate algorithms based on one or more of the decision conditions includes: In response to the fact that the complexity of the participating entity is greater than or equal to a first predetermined threshold, a threshold secret commitment algorithm is selected as the first algorithm. In response to the fact that the complexity of the participating entity is less than the first predetermined threshold, a determination is made based on the device's computing power and the network communication performance parameters to exclude lattice-based post-quantum commitment algorithms from the two or more candidate algorithms.

7. The data processing method as described in claim 6, wherein, Selecting the first algorithm from the two or more candidate algorithms based on one or more of the decision conditions includes: The security requirement level of the plaintext is calculated by weighting the values ​​of one or more of the decision conditions according to the following formula: in, Data sensitivity level associated with the plaintext The weight, The value of the project object associated with the plaintext. The weight, Complexity of participants in the project associated with the plaintext The weight, Network communication performance parameters between the encrypting party and the decrypting party The weight, The computing power of the encryption device The weights, and among them, ;as well as Selecting a candidate algorithm as the first algorithm from two or more candidate algorithms based on the security requirement level includes: In response to the security requirement level being greater than or equal to a second predetermined threshold, either the lattice-based post-quantum commitment algorithm or the Pedersen commitment algorithm is selected as the first algorithm. In response to the security requirement level being less than the second predetermined threshold and greater than or equal to the third predetermined threshold, the Pedersen commitment algorithm is selected as the first algorithm; and In response to the security requirement level being less than the third predetermined threshold, the basic elliptic curve dot product algorithm is selected as the first algorithm, wherein the second predetermined threshold is greater than the third predetermined threshold.

8. The data processing method as described in claim 2, wherein, Encapsulating the obfuscated first secret value and the commitment value to generate the data packet includes: Generate a header information block, wherein the header information block includes an algorithm identifier indicating the first algorithm and a traceability identifier, the traceability identifier indicating whether the second secret value is generated based on the traceability parameters; The data packet is generated by concatenating at least the header information block, the obfuscated first secret value, and the commitment value using a communication protocol format.

9. The data processing method as described in claim 1, wherein, The step of using the public key to perform asymmetric encryption on the data packet includes: In response to the data length of the data packet being less than or equal to a fourth predetermined threshold, the data packet is asymmetrically encrypted using the public key to generate an encrypted data packet; or In response to the data length of the data packet being greater than the fourth predetermined threshold, the data packet is symmetrically encrypted using a random temporary transmission key to generate an encrypted data packet, and the random temporary transmission key is asymmetrically encrypted using the public key, wherein the step of packaging and sending the ciphertext and the encrypted data packet includes sending the encrypted random temporary transmission key together with the encrypted data packet to the decryptor.

10. The data processing method as described in claim 1, wherein, The step of packaging and sending the ciphertext and the encrypted data packet includes: Generate a hash digest of the ciphertext and the encrypted data packet; Using the private key of the cryptographer, digitally sign the hash digest to generate a signature value; and The ciphertext, the encrypted data packet, and the signature value are packaged and sent.

11. A data processing method for decryption, comprising: Receive ciphertext and encrypted data packets; The encrypted data packet is asymmetrically decrypted using the private key of the decryptor, and a commitment value, a first algorithm for generating the commitment value, and a first obfuscated secret value are determined based on the decrypted data packet, wherein the first algorithm is an algorithm based on an algebraic one-way function. Obtain a second secret value, and use the first algorithm to perform commitment verification based on the second secret value and the commitment value; In response to successful commitment verification, the obfuscated first secret value is restored based on the second secret value to determine the first secret value; and The ciphertext is symmetrically decrypted using the first secret value to determine the plaintext.

12. The data processing method as described in claim 11, wherein, The step of using the private key of the decryptor to perform asymmetric decryption of the encrypted data packet includes: The ciphertext and the encrypted data packet are signed and verified using the encryptor's public key; and In response to successful signature verification, the asymmetric decryption is performed; in response to failed signature verification, the decryption is terminated.

13. The data processing method as described in claim 11, wherein, The header information block of the decrypted data packet includes an algorithm identifier indicating the first algorithm and a traceability identifier. The traceability identifier indicates whether the second secret value was generated based on traceability parameters. These traceability parameters include hardware characteristic parameters of the device used to generate the second secret value and / or project background parameters associated with the plaintext. The project background parameters associated with the plaintext include the data sensitivity level associated with the plaintext, the value of the project associated with the plaintext, and the complexity of the participating entities in the project associated with the plaintext. The process of obtaining the second secret value includes: In response to the traceability capability identifier indicating that the second secret value is generated based on the traceability parameters, the second secret value is obtained through the following steps: Receive the random value used to generate the second secret value and the tracing parameter; and The second secret value is generated based on the random value and the tracing parameter.

14. A data processing apparatus, comprising: One or more processors; A memory connected to the one or more processors stores instructions executable by the one or more processors, which, when executed, enable the apparatus to perform the data processing method as described in any one of claims 1 to 13.