Data right confirmation and ciphertext calculation method and system based on national cryptographic algorithm

By extracting data digests using national cryptographic algorithms and mapping them to homomorphic polynomial bias operators, the problem of lack of constraints on data ownership information in ciphertext computation is solved. This achieves the coupling of ownership features and homomorphic computation, ensuring the security and efficiency of data throughout its entire lifecycle.

CN121967079APending Publication Date: 2026-05-01SHENZHEN GEMDALE BUILDING ENG CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHENZHEN GEMDALE BUILDING ENG CO LTD
Filing Date
2026-03-13
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

In existing technologies, data ownership information lacks mathematical constraints during encrypted computation, leading to the easy loss of ownership features. Static ownership confirmation mechanisms fail in the dynamic computation domain, and communication delays and response bottlenecks become prominent issues.

Method used

Data block digest values ​​are extracted and signed using national cryptographic algorithms, mapped to a bias operator in a homomorphic polynomial space, and injected into the coding equation. A mapping matching relationship between the permission operator and the bias operator is established, the homomorphic noise growth rate is controlled, and a noise injection mechanism is triggered to defend against side-channel attacks.

Benefits of technology

It achieves mathematical coupling between ownership features and homomorphic computation, ensuring the non-repudiation of ownership throughout the entire data lifecycle, reducing communication overhead and response latency in high-concurrency scenarios, and improving throughput efficiency for handling heterogeneous data flow.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121967079A_ABST
    Figure CN121967079A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data security and privacy protection, and discloses a data right confirmation and ciphertext calculation method and system based on a national cryptographic algorithm, and the method comprises the steps: extracting a data abstract value to be confirmed, executing a national cryptographic signature, mapping a signature feature into a bias operator, and injecting the bias operator into a homomorphic coding equation, so as to change the initial distribution of a ciphertext; converting an authority operator based on the operation instruction; verifying a mapping matching relationship between the authority operator and the bias operator; if yes, the noise growth rate is protected and restrained by the hardware security module and is calculated; according to the method disclosed by the present invention, by converting the national cryptographic feature into the ciphertext endogenous constraint, the right confirmation information participates in the construction of the ciphertext spatial distribution, the mathematical coupling of the ownership feature and the computational logic is realized, the implicit defense mechanism based on the noise constraint is constructed, and it is ensured that the ownership is not repudiated in the data life cycle.
Need to check novelty before this filing date? Find Prior Art

Description

A method and system for data ownership confirmation and ciphertext calculation based on national cryptographic algorithms Technical Field

[0001] This invention relates to a data ownership confirmation and ciphertext calculation method and system based on national cryptographic algorithms, belonging to the field of data security and privacy protection technology. Background Technology

[0002] The construction of smart cities currently generates massive amounts of IoT device data and personnel information. Using the national cryptographic SM3 digest algorithm and SM2 signature algorithm to anchor ownership, and combining it with fully homomorphic encryption technology to perform ciphertext computation is the conventional path to achieve secure data interaction. Existing secure multi-party computation schemes adopt a parallel architecture of external ownership mounting and internal data encryption, with ownership confirmation features existing in the form of metadata outside the ciphertext packet.

[0003] Current research and development focuses primarily on physical protection of data acquisition terminals, optimizing processor integration, or improving robustness in complex environments by addressing hardware limitations. However, when the underlying hardware is reliable but the software control methods and processing logic have flaws, data ownership security faces challenges. For example, Chinese invention patent CN111932852B discloses a gas meter reading system and its gas data transmission method based on national cryptographic algorithms. This scheme utilizes SM3 digests and SM1 symmetric encryption to construct a transmission closed loop, enhancing point-to-point anti-theft capabilities. However, the core logic belongs to a parallel architecture externally mounted to ownership; the calculation of ownership features and ciphertext... Being at a mutually decoupled and independent level, since features exist only as metadata outside the ciphertext packet, the fully homomorphic encryption system lacks mathematical constraints on the legality of operators during the ciphertext computation stage. When data blocks undergo splitting, reorganization, or cross-system transfer during the collaborative process, external permission markers are lost in the complex computation chain, leaving the ciphertext logically ownerless. Third parties can maliciously analyze ciphertexts without ownership constraints using homomorphic operators, causing the static ownership confirmation mechanism to fail in the dynamic computation domain. The real-time signature verification process relies on external key management services or certificate servers, resulting in communication delays and response bottlenecks in high-concurrency scenarios.

[0004] Therefore, how to construct an endogenous security system that couples ownership features with homomorphic computation domains, so that ownership information serves as a prerequisite mathematical condition for encrypted computation, is the technical problem that this invention aims to solve. Summary of the Invention

[0005] To address the problems raised in the background art, the technical solution of this invention is as follows: A data ownership confirmation and ciphertext calculation method based on the national cryptographic algorithm, comprising the following steps: Step 101, obtaining the data block to be confirmed, extracting the digest value of the data block to be confirmed using the SM3 algorithm, calling a preset SM2 signature certificate to digitally sign the digest value, and extracting the key feature vector in the signature result, mapping the key feature vector to a bias operator in the homomorphic polynomial space; Step 102, performing homomorphic encoding, injecting the bias operator into the encoding equation during the process of encoding the plaintext vector into the homomorphic encryption initial polynomial, so as to change the initial distribution of the ciphertext under the fault-tolerant loop learning problem, and generating initial ciphertext carrying the ownership distribution characteristics as the constraint response of the bias operator; Step 103, receiving... The computation request includes a data permission package. The set of operation permissions encapsulated in the data permission package is parsed, and the operation instructions in the set of operation permissions are extracted and converted into permission operators in the computation domain. Step 104: The mapping matching relationship between the permission operators and the bias operators of the ciphertext to be computed is verified. If the preset mapping matching relationship is satisfied, the permission operators are used to perform homomorphic computation on the initial ciphertext in the hardware security module. The mapping matching result between the permission operators and the bias operators is used to constrain the homomorphic noise growth rate in the computation process to a preset threshold range to ensure the decryption accuracy of the ciphertext produced by the homomorphic computation. Step 105: If the mapping matching relationship is inconsistent, the bias operators are used to trigger noise injection, so that the noise budget corresponding to the initial ciphertext is exhausted and a random number is output.

[0006] Preferably, step 101, which maps the key feature vector to a bias operator in the homomorphic polynomial space, includes: step 201, extracting the key feature vector... 3D eigencomponents ,in, The signature statistical features are normalized; step 202, using a preset basis transformation matrix. right 3D eigencomponents Perform a linear projection transformation to calculate the bias vector in the coefficient field of the homomorphic polynomial. Step 203, the bias vector Transformed into a bias operator for intervening in the learning initial distribution of the fault-tolerant loop. .

[0007] Preferably, step 102, which involves injecting the bias operator into the coding equation, includes: step 301, whereby the original plaintext vector... Mapping to ring polynomials At that time, the bias operator As a translation term superimposed on the ring polynomial In the coefficient term; step 302, using the superposition bias operator The ring polynomial after As the initial sampling center, noise sampling is performed under a discrete Gaussian distribution that conforms to a preset standard deviation, so that the coefficient distribution of the generated ciphertext polynomial is consistent with the bias operator. It satisfies the preset statistical correlation.

[0008] Preferably, step 104, which constrains the homomorphic noise growth rate during the calculation process to a preset threshold range, includes: step 401, calculating the ciphertext noise modulus after performing homomorphic calculation. Step 402: Adjust the noise scaling factor according to the matching degree between the permission operator and the bias operator. Step 403, using the noise scaling factor For ciphertext noise modulus Compensation is performed to ensure that the homomorphic noise growth rate satisfies the following constraints: ,in, The total noise after calculation. and These are the noise values ​​of the two ciphertext items involved in the calculation. This is the noise scaling factor. This is a fixed truncation noise determined based on a preset calculation accuracy.

[0009] Preferably, the step of triggering noise injection in step 105 includes: step 501, monitoring the mapping deviation value between the permission operator and the bias operator; step 502, if the mapping deviation value exceeds the preset tolerance threshold, actively superimposing the random perturbation polynomial derived from the bias operator during the relinearization stage of the homomorphic multiplication operator; step 503, by increasing the modulus dimension of the ciphertext terms, reducing the ciphertext noise budget involved in the calculation to zero in a single iteration.

[0010] Preferably, step 104, which involves performing homomorphic computation on the initial ciphertext using the permission operator within the hardware security module, includes: step 601, loading the permission operator into the trusted execution environment of the hardware security module; step 602, establishing a secure logical isolation zone for ciphertext computation within the trusted execution environment; and step 603, using a hardware accelerator to perform parallel computation on the homomorphic addition operator, homomorphic multiplication operator, and relinearization operator within the secure logical isolation zone.

[0011] Preferably, the method also includes a data ownership confirmation and traceability step: Step 701, after the initial ciphertext undergoes splitting, recombination or aggregation calculation of the ciphertext domain, retain the ownership characteristics of the bias operator in the generated intermediate result ciphertext; Step 702, by extracting the ownership distribution characteristics in the intermediate result ciphertext, the ownership information of the data in the process of multi-party circulation is verified.

[0012] Preferably, step 103, receiving the calculation request containing the data permission package, includes: step 801, obtaining the data permission package through a secure transmission protocol; step 802, verifying the digital signature of the data permission package using the public key corresponding to the SM2 signature certificate; and step 803, if the signature verification passes, extracting the set of operation permissions defined in the data permission package for the data block to be authorized.

[0013] Preferably, step 104, which involves calculating using the mapping and matching results of the permission operator and the bias operator, includes: step 901, presetting a reverse compensation variable in the permission operator based on the distribution offset introduced by the bias operator during the encoding stage; step 902, while performing homomorphic operations on the ciphertext, using the reverse compensation variable to offset the distribution deviation in the initial ciphertext, thereby achieving operator alignment within the ciphertext domain; and also includes a dynamic permission management step: receiving a permission revocation instruction issued by the key management service, updating the permission verification rules within the hardware security module based on the permission revocation instruction, so that permission operators that satisfy the mapping and matching relationship become invalid in the verification rules.

[0014] A data ownership confirmation and ciphertext calculation system based on national cryptographic algorithms is disclosed. The system includes an ownership mapping module, a homomorphic encoding module, a permission resolution module, and a ciphertext calculation module. The ownership mapping module acquires the data block to be confirmed, extracts its digest value using the SM3 algorithm, digitally signs the digest value using a pre-set SM2 signature certificate, and extracts key feature vectors from the signature result, mapping these key feature vectors to bias operators in a homomorphic polynomial space. The homomorphic encoding module, connected to the ownership mapping module, encodes the plaintext vector into a homomorphic encryption initial polynomial, injecting the bias operator into the encoding equation during the encoding process to change the initial distribution of the ciphertext under the fault-tolerant loop learning problem, generating initial ciphertext carrying ownership distribution characteristics. The permission resolution module receives data containing... The computation request for the data permission package is parsed, and the set of operation permissions encapsulated within the data permission package is extracted. The operation instructions in the set of operation permissions are then converted into permission operators within the computation domain. The ciphertext computation module is connected to the homomorphic encoding module and the permission parsing module, respectively, to verify the mapping matching relationship between the permission operators and the bias operators of the ciphertext to be computed. If the preset mapping matching relationship is satisfied, the hardware security module is called to perform homomorphic computation on the initial ciphertext using the permission operators. The mapping matching result between the permission operators and the bias operators is used to constrain the homomorphic noise growth rate during the computation process within a preset threshold range to ensure the decryption accuracy of the ciphertext produced by the homomorphic computation. If the mapping matching relationship is inconsistent, the bias operator is used to trigger noise injection, causing the noise budget corresponding to the initial ciphertext to be exhausted.

[0015] Compared with the prior art, the beneficial effects of the present invention are: 1. In the data ownership confirmation and ciphertext calculation method, the national cryptographic signature feature vector is extracted and converted into a homomorphic polynomial space bias operator; the bias operator is injected into the coding equation to change the initial distribution of the ciphertext, so that the ownership feature participates in the construction of the ciphertext polynomial, and ownership verification is used as the mathematical premise of ciphertext calculation, thus solving the technical problem that the authorization verification and calculation logic are independent in the weighted calculation separation architecture.

[0016] 2. Establish a mapping alignment relationship between permission operators and bias operators to constrain the homomorphic noise growth rate; trigger a noise injection mechanism when the calculation instruction does not carry a matching bias operator, exhaust the noise budget to make the ciphertext calculation result appear as a random number, and construct a noise explosion-based implicit defense mechanism to resist side-channel attacks.

[0017] 3. The authentication logic is encapsulated in the phase verification process of the ciphertext operator. The system does not need to call external key management services or certificate servers to perform ciphertext calculations, which reduces communication overhead and response latency in high-concurrency scenarios and improves the throughput efficiency of processing heterogeneous data streams. The bias operator is retained in the result ciphertext as it evolves homomorphically, so that the data after splitting, recombining or aggregating the ciphertext domain carries the ownership feature component, realizing the non-repudiation of ownership throughout the entire data lifecycle and meeting the requirements of fine-grained persistent traceability of ownership information in complex business scenarios. Attached Figure Description

[0018] Figure 1 is a schematic diagram of the dual-path processing logic of data rights confirmation mapping and operator matching verification in this invention; Figure 2 is a performance comparison diagram of typical homomorphic operators under software implementation and hardware acceleration in this invention; Figure 3 is an interaction timing diagram of computation request parsing and permission mapping verification in this invention. Detailed Implementation

[0019] The technical solution proposed by the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be noted that the following embodiments are only used to explain the present invention and do not constitute a limitation on the scope of protection of the present invention.

[0020] This invention proposes a data ownership confirmation and ciphertext calculation method and system based on national cryptographic algorithms to address the technical problem of the disconnect between ownership information and computational logic in smart city data sharing. By transforming national cryptographic signature features into ciphertext spatial distribution constraints, it achieves mathematical coupling between ownership features and homomorphic computation operators. In smart city IoT sensing applications, due to the numerous data transfer stages and complex participating entities, external ownership tags are prone to loss during data splitting or cross-system migration, resulting in ciphertext being ownerless after entering the computation domain. To address this technical challenge, this invention obtains the data block to be confirmed during the data source ownership confirmation stage and utilizes... The algorithm extracts the digest value of the data block to be determined and calls the preset... The signing certificate performs a digital signature on the digest value. The system extracts the key feature vectors from the signature result and converts them into bias operators in a homomorphic polynomial space using the following procedure. When constructing the ownership feature space mapping, the processor extracts key feature vectors. 3D eigencomponents ,in For the normalized signature statistical features, a preset basis transformation matrix is ​​used. Regarding 3D eigencomponents Perform a linear projection transformation to calculate the bias vector in the coefficient field of the homomorphic polynomial. And thus the bias vector Transformed into a problem for intervening in fault-tolerant cycle learning, i.e. Bias operator for initial distribution This mapping process establishes a connection between legal ownership characteristics and the intrinsic mathematical features of the ciphertext, ensuring that ownership information no longer exists merely as external metadata.

[0021] When transforming key eigenvectors into bias operators in homomorphic polynomial space, the basis transformation matrix... The values ​​of each element are pre-defined according to the Gram-Schmidt orthogonalization algorithm. The normalized signature statistical features are mapped to the homomorphic polynomial coefficient domain, and the bias vectors corresponding to different weight subjects are defined. In the model The space is in an orthogonal subspace; the matrix for Order basis transformation matrix, vector for The coefficient vector of the homomorphic polynomial, modulus The modulus of the ciphertext polynomial coefficients, and the bias vector. The components are directly used as coefficients to construct the ring polynomial generation bias operator. Operator To intervene in the bias polynomial of the initial distribution of the fault-tolerant loop learning problem and maintain the initial decryption accuracy, the bias vector is... The infinite norm is restricted to the modulus. Within one-tenth of the original value, a correlation is established between ownership characteristics and the mathematical eigenvalues ​​of the ciphertext, providing a benchmark for subsequent operator alignment. Since homomorphic encryption systems typically lack mathematical constraints on operator validity during the computation phase, the system will bias the operators during homomorphic encoding. Injection coding equation; in specific operations, the original plaintext vector is... Mapping to ring polynomials At that time, the bias operator As a translation term superimposed on the ring polynomial In the coefficient terms, the superposition bias operator is used. The ring polynomial after As the initial sampling center, noise sampling is performed under a discrete Gaussian distribution that meets the preset standard deviation. This step changes the initial distribution of the ciphertext under the fault-tolerant loop learning problem and generates an initial ciphertext carrying the weight distribution characteristics.

[0022] When processing computation requests containing data permission packages, the system needs to address the authentication latency issue under high concurrency scenarios. The permission parsing module parses the set of operation permissions encapsulated within the data permission package, extracts the operation instructions, and converts them into permission operators within the computation domain. The system then verifies that the permission operator matches the bias operator of the ciphertext to be computed. The mapping and matching relationship between them; if the preset mapping and matching relationship is satisfied, then in the hardware security module, i.e. The internal algorithm uses permission operators to perform homomorphic computation on the initial ciphertext, and utilizes permission operators and bias operators during the computation process. The mapping and matching results constrain the homomorphic noise growth rate within a preset threshold range to ensure the decryption accuracy of the ciphertext output by homomorphic computation. Specifically, when performing homomorphic computation within the hardware security module, the permission operator is loaded into the trusted execution environment of the hardware security module, and a secure logical isolation zone for ciphertext computation is established within this environment. The hardware accelerator performs parallel operations on the homomorphic addition operator, homomorphic multiplication operator, and relinearization operator within the secure logical isolation zone. To achieve noise-controlled computation, the system calculates the ciphertext noise modulus after homomorphic computation. Based on the permission operator and the bias operator Matching degree adjustment noise scaling factor And using a noise scaling factor For ciphertext noise modulus Compensation is performed to ensure that the homomorphic noise growth rate satisfies the following constraints: ,in, The total noise after calculation. and These are the noise values ​​of the two ciphertext items involved in the calculation. This is the noise scaling factor. To ensure that the calculation results under legitimate operators are decryptable, a fixed truncation noise is determined based on a preset calculation accuracy.

[0023] If the mapping matching relationship is inconsistent, that is, the computation request does not carry the correct ownership bias information, then the bias operator is used. Noise injection triggering; system monitoring permission operators and bias operators If the mapping deviation between the two exceeds a preset tolerance threshold, the hardware security module will extract the feature value of the permission operator and the built-in bias operator of the ciphertext to be computed before performing homomorphic computation. The Euclidean distance determines the mapping deviation value. Deviation value The deviation value is the matching error between the permission operator and the bias operator in the coefficient space. Exceeding the preset When the tolerance threshold is reached, a noise injection procedure is initiated during the relinearization stage, which calls a hardware true random number generator to generate a random perturbation polynomial. Polynomial To exhaust the noise budget, a random polynomial with coefficients following a discrete Gaussian distribution whose standard deviation is at least three orders of magnitude greater than the initial encrypted noise, the hardware accelerator will... The superposition of these terms onto the coefficients of the ciphertext polynomial enables the calculation of the ciphertext noise modulus. A single iteration exceeds the decryption threshold, exhausting the noise budget; modulus Given the current ciphertext noise value, output a random number. Then, during the relinearization phase of the homomorphic multiplication operator, the bias operator actively superimposes the values. The generated random perturbation polynomial increases the modulus dimension of the ciphertext terms, causing the noise budget of the ciphertext involved in the computation to drop to zero in a single iteration. This results in the exhaustion of the noise budget corresponding to the initial ciphertext and the output of random numbers. This noise explosion mechanism renders illegal computations mathematically invalid.

[0024] To support ownership tracking throughout the entire data lifecycle, the bias operator is still retained in the intermediate ciphertext generated after the initial ciphertext undergoes splitting, recombination, or aggregation calculations of the ciphertext field. The system extracts ownership characteristics from the ciphertext of intermediate results to verify ownership information during the multi-party transfer of data. Furthermore, the system supports dynamic permission management; upon receiving a permission revocation command from the key management service, it updates the permission verification rules within the hardware security module, rendering permission operators that previously satisfied the mapping relationship invalid. This invention also provides a data ownership confirmation and ciphertext calculation system based on national cryptographic algorithms, comprising an ownership mapping module, a homomorphic encoding module, a permission parsing module, and a ciphertext calculation module. The ownership mapping module is used to acquire the data block to be confirmed and generate a bias operator. The homomorphic coding module is used to generate initial ciphertext carrying ownership distribution characteristics, the permission parsing module is used to convert operation instructions into permission operators, and the ciphertext calculation module is used to verify the mapping matching relationship and perform noise-controlled homomorphic calculation or trigger noise injection based on the verification result.

[0025] Example 1: In a smart city government data cross-departmental collaborative processing scenario, the municipal data center needs to aggregate individual payment records from the social security department and treatment frequency data from the medical department to calculate quantitative health risk indicators for specific groups. When data blocks from different departments undergo cross-system transfer, splitting, and reorganization, traditional external ownership markers are easily lost, resulting in the encrypted data being ownerless after entering the fully homomorphic encryption computation domain. This poses a technical risk of unauthorized third parties using homomorphic operators to perform malicious analysis. To address this challenge, the system invokes an ownership mapping procedure to process the input de-identified data blocks using... The algorithm extracts the digest value and calls... Digital signatures are extracted from signature certificates. 3D eigencomponents The system utilizes a preset basis transformation matrix. right Perform a linear projection transformation to generate a bias vector in the coefficient field of the homomorphic polynomial. And convert it into a bias operator. During the homomorphic coding phase, this bias operator As a translation term, it is added to the initial polynomial. In the coefficient term, the generated initial ciphertext carries specific weighted phase characteristics under the fault-tolerant loop learning problem. When the medical department initiates a joint risk calculation instruction and submits a request containing a data permission package, the permission resolution module utilizes... The certificate's public key verifies the signature and translates the operation instructions into permission operators within the computing domain.

[0026] During the ciphertext computation phase, the system verifies the permission operator against the bias operator built into the ciphertext to be computed. The mapping alignment relationship; when the two phases are aligned, the hardware security module adjusts the noise scaling factor using the permission operator during the execution of the homomorphic addition operator. This makes the calculated total noise satisfy Constraint rules, among which and These are the noise values ​​of the data items involved in the calculation; this mechanism enables... The authorization feature and the homomorphic computation operator are mathematically coupled. The authorization verification result directly serves as a prerequisite for subsequent noise-controlled computation. If an unauthorized third party attempts to perform an illegal aggregation operation on the ciphertext and fails to provide a matching authorization operator, the system detects the authorization operator and the bias operator. If the mapping deviation between the two exceeds the preset tolerance threshold, the system actively superimposes the bias operator during the relinearization stage of the homomorphic multiplication operator. The generated random perturbation polynomial reduces the ciphertext noise budget involved in the calculation to zero in a single iteration by increasing the modulus dimension of the ciphertext terms. This process results in the ciphertext decryption result being a meaningless pseudo-random number, and the homomorphic noise explosion mechanism is used to achieve implicit defense against illegal calculation instructions.

[0027] Example 2: In a test environment simulating cross-departmental ownership confirmation and encrypted aggregation calculation of government data in a smart city, the permission operator and bias operator based on the national cryptographic algorithm are verified. The effectiveness of the image matching mechanism in resisting unauthorized computation instructions was tested on a computing cluster consisting of a processor, memory, and a hardware security module simulator. The test data sourced from IoT sensing signals generated using Monte Carlo simulation. The simulation employed a discrete Gaussian distribution model to simulate additive noise interference and followed... The mathematical framework of the problem; the core control parameter set in the experiment is the homomorphic noise scaling factor. The decision logic chain for this parameter setting identifies the factors affecting the parameter value as the permission operator, and the built-in bias operator in the ciphertext to be computed. The mapping deviation value between them, the essence of the technical trade-off lies in balancing the decryption accuracy of the computational output with the sensitivity of triggering noise bombs for illegal requests. The decision rule is set so that when the mapping deviation value is within a certain range... To ensure the validity of the decryption results, when the noise scaling factor is within the preset tolerance threshold, the noise scaling factor is adjusted accordingly. It tends towards the lower limit of the value range, i.e. To limit the growth of homomorphic noise, adjustments are made when the deviation exceeds this threshold. Increase the noise compensation ratio until the noise budget is exhausted; at an input signal-to-noise ratio of And injection Noise scaling factor under typical operating conditions of power frequency interference noise sources Anchored as This allows for mathematical constraints on ownership characteristics while ensuring computational efficiency.

[0028] After the test procedure is initiated, the sample of this invention will carry out the test... and The algorithm-generated matching permission operator's calculation request is input into the system, while the control group uses a random operator without ownership phase features to perform homomorphic addition and multiplication operations. The observed data trends show that the noise modulus of the ciphertext under legitimate instructions in the trusted execution environment of the hardware security module is... The growth was controlled, while the control group experienced a nonlinear explosion of noise after the superposition of random perturbation polynomials during the relinearization stage; see Table 1.

[0029] Table 1: Comparative Data on the Impact of Operator Matching State on Cipher Noise Budget

[0030] The noise growth curve and constraint rules obtained by the experimental group This aligns with theoretical expectations. The total noise after calculation. and These are the noise values ​​of the two ciphertext items involved in the calculation. This is the noise scaling factor. This is a fixed truncation noise determined based on a preset calculation precision; experimental results confirm that the noise in the national cryptographic signature results... 3D eigencomponents Convert to bias operator The method of injecting homomorphic coding equations can realize the active verification of the legality of operators in the computation domain, and the mathematical coupling mechanism between the obtained associated data proof ownership characteristics and computation logic ensures that the ownership of data is irrefutable throughout its life cycle, thus solving the technical problem of using ownership information as a prerequisite mathematical condition for encrypted computation.

[0031] Example 3: This example, in conjunction with Figures 1 to 3, describes a data ownership confirmation and ciphertext calculation method and system based on the national cryptographic algorithm. As shown in Figure 1, the data processing path on the left begins by acquiring the data block to be confirmed and extracting the original plaintext data. It then enters the national cryptographic feature extraction and mapping stage, extracting features through SM3 digest and SM2 signature technology, and mapping key feature vectors to bias operators. Subsequently, homomorphic encoding and injection steps are performed to inject the bias operators into the encoding equation to change the distribution and generate an initial ciphertext stream carrying ownership features. The request processing path on the right responds to the calculation request containing the data permission package. After permission parsing and transformation steps, the operation permission set is parsed, and the operation instructions are transformed into a permission operator stream. The two paths converge at the mapping matching relationship verification stage, comparing the permission operators and the bias operators. If the match is successful, the homomorphic calculation process of the hardware security module is entered. The calculation is performed using the permission operators, and the homomorphic noise growth rate is constrained within a preset range. Finally, the calculation result ciphertext that guarantees decryption accuracy is output. If the match fails, the noise injection mechanism is triggered to exhaust the noise budget using the bias operators, making the defense mechanism effective. Finally, a random number is output.

[0032] As shown in Figure 2, the vertical axis represents the computation time in milliseconds (ms), and the horizontal axis lists the three key operations: homomorphic addition, homomorphic multiplication, and relinearization. The legend distinguishes between the traditional software implementation data with horizontal bars and the hardware security module accelerated data with diagonal bars. In the homomorphic addition stage, the time difference between the two is small. However, in the homomorphic multiplication and relinearization stages, which have higher computational complexity, the computation time accelerated by the hardware security module shows a decreasing trend. Especially in the homomorphic multiplication stage, its time is much lower than the 250ms level of the traditional software implementation.

[0033] As shown in Figure 3, this diagram covers five main participants: the computation requester, the secure transport layer, the permission parsing module, the verification module, and the ciphertext to be computed. The interaction process begins with the computation requester sending a computation request containing a data permission packet through the secure transport layer. After receiving and transmitting the data permission packet, the permission parsing module verifies the digital signature using the SM2 public key. In the logical branch where the signature verification is successful, the system sequentially executes the steps of extracting the operation permission set, extracting the operation instructions, and converting them into permission operators. The generated permission operators are then passed to the verification module, which subsequently obtains the bias operator from the ciphertext to be computed. For permission operators and bias operators The system verifies the mapping relationship and returns the verification result. In the logical branch where the signature verification fails, the system rejects the request operation, thus forming a closed loop of security verification and data flow sequence.

[0034] Example 4: In a scenario where multiple medical institutions jointly calculate disease incidence rates using fully homomorphic encryption technology, each participant completes encrypted aggregation calculations without disclosing the original medical records. Because the medical record data blocks have strong ownership attributes, the system addresses the technical challenge of implementing mathematical-level constraints on ownership characteristics during homomorphic operator operations to prevent unauthorized aggregation. The system obtains the medical record data blocks to be assigned ownership and utilizes... The algorithm extracts the digest value and calls... The length of the digital signature extraction result is The processor divides the feature vector into 1 bit features. each feature component ,in The polynomial ring dimension of homomorphic encryption schemes Maintaining the proportional relationship, using a preset basis transformation matrix right Perform a linear projection transformation to obtain the bias vector The processor will The elements in the polynomial are used as coefficients of the ring polynomial, and the modulus of the polynomial coefficients is... Perform bit-width alignment within the space to ensure that each coefficient distribution is within the specified range. The bias operator is obtained in the central region. During the homomorphic coding phase, the processor will use the bias operator. The ring polynomial superimposed as a translation term onto the plaintext mapping In this process, by adjusting the sampling center of the discrete Gaussian distribution, the generated initial ciphertext is made to exhibit a shape in the coefficient domain determined by the bias vector. The determined frequency domain distribution characteristics.

[0035] The computing node receives a statistics request. The permission parsing module extracts operation instructions from the data permission packet and converts them into permission operators. This conversion process is performed within the trusted execution environment of the hardware security module. The steps include mapping the read or sum operation instructions to operator feature values ​​in the computation domain using a linear congruence generator. The system verifies that the permission operator matches the bias operator built into the ciphertext to be computed. The mapping matching relationship allows the hardware accelerator to perform ciphertext summation operations in parallel within the logical isolation zone of the hardware security module when a match is found, and adjusts the noise scaling factor according to the operator alignment result. To compensate for the noise increment caused by coefficient shift, the noise modulus of the final calculation result is made to meet the requirements. Constraints, where, The total noise after calculation. and These are the noise values ​​of the two ciphertext items involved in the calculation. This is the noise scaling factor. This is a fixed truncated noise determined based on a preset calculation precision; if an unauthorized third party attempts to illegally invoke the aggregation operator, the system detects the permission operator feature value and the bias operator. The mapping deviation value exceeds The calibration threshold is then used in the relinearization stage, where the bias operator is actively superimposed. The generated random perturbation polynomial reduces the ciphertext noise budget involved in the computation to zero by increasing the modulus dimension of the ciphertext terms.

[0036] Example 5: In the initial deployment of a cross-departmental government data aggregation and computing system, the system executes the feature projection matrix. Offline calibration procedures are used to determine the dimensions in the polynomial ring. Based on the frequency domain distribution characteristics, this calibration procedure uses a statistically representative de-identified original dataset as a sample to extract the frequency domain distribution characteristics within a controlled hardware security module simulation environment. Signature feature vector The normalized components are calculated, and projection mapping is performed. The computational unit calculates the normalized components of each sample in the polynomial coefficient modulus. The projection variance in space, and the deviation of the coefficient distribution center, and based on the projected bias vector. The matrix is ​​iteratively corrected based on the degree of overlap with the target weight phase features. The values ​​of each element are chosen to ensure that the initial distribution of the generated ciphertext in the fault-tolerant loop learning problem satisfies the preset statistical correlation index.

[0037] When the system is deployed in a heterogeneous hardware security module environment, a pre-deployment calibration procedure is performed to calibrate the noise scaling factor. Within the baseline operating range, the calibration module initiates the chain of homomorphic addition and multiplication operators in a trusted execution environment and monitors the computation time and homomorphic noise modulus of the hardware accelerator. The growth rate is adjusted by the calibration unit via a discrete step-by-step method. The value of makes from Increment to The calculation results and decryption accuracy at each step point are recorded, and the value taken at the moment before the slope of the noise growth rate curve changes abruptly is taken as the initial calibration value under this hardware environment.

[0038] Example 6: In the continuous operation of a high-concurrency IoT sensing data aggregation and computing system, the system executes a dynamic noise budget benchmark calibration procedure to address the objective challenges of hardware environmental temperature rise and electronic component aging. The calibration module monitors the hardware safety module in real time during processing. The instruction cycle time and transient power consumption during signature feature mapping operations are used to obtain the energy consumption benchmark value of the hardware accelerator when performing homomorphic polynomial operations. The calibration unit starts a preset benchmark homomorphic task in a trusted execution environment and extracts the polynomial coefficient modulus. The initial signal-to-noise ratio distribution characteristics within the space are used to adjust the feature projection matrix via a feedback loop when a shift in the operating frequency of the computing core is detected. The feature component weights in the equation enable the generated bias operator. To maintain statistical distribution characteristics under different workloads, the processor calculates the noise scaling factor in the current operating environment by comparing the variance of the polynomial coefficients after mapping the baseline plaintext vector. The correction factor.

[0039] When the system encounters initial signature statistical feature offsets caused by batch differences in IoT sensing terminals, it executes an adaptive alignment procedure for the ownership phase features to correct the bias operator. The initial translation components are used to extract the current batch of terminals according to the alignment procedure. The statistical median component of the signature is obtained and a projection mapping is performed. The calculated phase correction value is then superimposed onto the homomorphic polynomial coefficient modulus. At the center of the domain, the mapping deviation value during the permission operator verification process is continuously monitored to ensure it remains stable. The feature alignment status is determined within the preset calibration value.

[0040] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.

[0041] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.

Claims

1. A method for data ownership confirmation and ciphertext calculation based on national cryptographic algorithms, characterized in that, Includes the following steps: Step 101: Obtain the data block to be confirmed, extract the digest value of the data block to be confirmed using the SM3 algorithm, call the preset SM2 signature certificate to digitally sign the digest value, and extract the key feature vector in the signature result, and map the key feature vector into a bias operator in the homomorphic polynomial space. Step 102: Perform homomorphic encoding. In the process of encoding the plaintext vector into the homomorphic encryption initial polynomial, the bias operator is injected into the encoding equation to change the initial distribution of the ciphertext under the fault-tolerant loop learning problem and generate the initial ciphertext carrying the weight distribution characteristics as the constraint response of the bias operator. Step 103: Receive a computation request containing a data permission package, parse the set of operation permissions encapsulated in the data permission package, extract the operation instructions in the set of operation permissions and convert them into permission operators in the computation domain; Step 104: Verify the mapping matching relationship between the permission operators and the bias operators of the ciphertext to be computed. If the preset mapping matching relationship is satisfied, perform homomorphic computation on the initial ciphertext using the permission operators in the hardware security module, and use the mapping matching result between the permission operators and the bias operators to constrain the homomorphic noise growth rate in the computation process to a preset threshold range, so as to ensure the decryption accuracy of the ciphertext of the computation result produced by the homomorphic computation. Step 105: If the mapping matching relationship is inconsistent, the bias operator is used to trigger noise injection, so that the noise budget corresponding to the initial ciphertext is exhausted and a random number is output.

2. The data ownership confirmation and ciphertext calculation method based on the national cryptographic algorithm according to claim 1, characterized in that, Step 101, which maps the key feature vectors to bias operators in the homomorphic polynomial space, includes: Step 201, extracting the key feature vectors from... 3D eigencomponents ,in, The signature statistical features are normalized; step 202, using a preset basis transformation matrix. right 3D eigencomponents Perform a linear projection transformation to calculate the bias vector in the coefficient field of the homomorphic polynomial. Step 203, the bias vector Transformed into a bias operator for intervening in the learning initial distribution of the fault-tolerant loop. 。 3. The data ownership confirmation and ciphertext calculation method based on the national cryptographic algorithm according to claim 1, characterized in that, Step 102, which involves injecting the bias operator into the coding equation, includes: Step 301, in the original plaintext vector... Mapping to ring polynomials At that time, the bias operator As a translation term superimposed on the ring polynomial In the coefficient terms; step 302, using the superposition bias operator The ring polynomial after As the initial sampling center, noise sampling is performed under a discrete Gaussian distribution that conforms to a preset standard deviation, so that the coefficient distribution of the generated ciphertext polynomial is consistent with the bias operator. It satisfies the preset statistical correlation.

4. The data ownership confirmation and ciphertext calculation method based on the national cryptographic algorithm according to claim 1, characterized in that, Step 104, which constrains the homomorphic noise growth rate during the calculation process to a preset threshold range, includes: Step 401, calculating the ciphertext noise modulus after performing homomorphic calculation. Step 402: Adjust the noise scaling factor according to the matching degree between the permission operator and the bias operator. Step 403, using the noise scaling factor For ciphertext noise modulus Compensation is performed to ensure that the homomorphic noise growth rate satisfies the following constraints: ,in, The total noise after calculation. and These are the noise values ​​of the two ciphertext items involved in the calculation. This is the noise scaling factor. This is a fixed truncation noise determined based on a preset calculation accuracy.

5. The data ownership confirmation and ciphertext calculation method based on the national cryptographic algorithm according to claim 1, characterized in that, The step of triggering noise injection in step 105 includes: step 501, monitoring the mapping deviation value between the permission operator and the bias operator; step 502, if the mapping deviation value exceeds the preset tolerance threshold, actively superimposing the random perturbation polynomial derived from the bias operator during the relinearization stage of the homomorphic multiplication operator; step 503, by increasing the modulus dimension of the ciphertext terms, reducing the ciphertext noise budget involved in the calculation to zero in a single iteration.

6. The data ownership confirmation and ciphertext calculation method based on the national cryptographic algorithm according to claim 1, characterized in that, Step 104, which involves performing homomorphic computation on the initial ciphertext using the permission operator within the hardware security module, includes: Step 601, loading the permission operator into the trusted execution environment of the hardware security module; Step 602, establishing a secure logical isolation zone for ciphertext computation within the trusted execution environment; and Step 603, using a hardware accelerator to perform parallel computation on the homomorphic addition operator, homomorphic multiplication operator, and relinearization operator within the secure logical isolation zone.

7. The data ownership confirmation and ciphertext calculation method based on the national cryptographic algorithm according to claim 1, characterized in that, It also includes a data ownership confirmation and traceability step: Step 701, after the initial ciphertext undergoes splitting, recombination or aggregation calculation of the ciphertext field, the ownership characteristics of the bias operator are retained in the generated intermediate result ciphertext; Step 702: By extracting the ownership distribution characteristics from the encrypted intermediate results, the ownership information of the data during the multi-party transfer process is verified.

8. The data ownership confirmation and ciphertext calculation method based on the national cryptographic algorithm according to claim 1, characterized in that, The step of receiving the calculation request containing the data permission package in step 103 includes: step 801, obtaining the data permission package through a secure transmission protocol; step 802, verifying the digital signature of the data permission package using the public key corresponding to the SM2 signature certificate; step 803, if the signature verification passes, extracting the set of operation permissions defined in the data permission package for the data block to be authorized.

9. The data ownership confirmation and ciphertext calculation method based on the national cryptographic algorithm according to claim 1, characterized in that, The step 104, which uses the mapping matching result of the permission operator and the bias operator for calculation, includes: Step 901, presetting a reverse compensation variable in the permission operator based on the distribution offset introduced by the bias operator during the encoding stage; Step 902, while performing homomorphic operation on the ciphertext, using the reverse compensation variable to offset the distribution deviation in the initial ciphertext to achieve operator alignment within the ciphertext domain, and also includes a dynamic permission management step: receiving a permission revocation instruction issued by the key management service, updating the permission verification rules in the hardware security module based on the permission revocation instruction, so that the permission operators that satisfy the mapping matching relationship are invalidated in the verification rules.

10. A data ownership confirmation and ciphertext calculation system based on the national cryptographic algorithm, used to implement the data ownership confirmation and ciphertext calculation method based on the national cryptographic algorithm as described in claim 1, characterized in that, The system includes an ownership mapping module, a homomorphic encoding module, an access control parsing module, and a ciphertext calculation module: The ownership mapping module is used to obtain the data block to be confirmed, extract the digest value of the data block to be confirmed using the SM3 algorithm, call the preset SM2 signature certificate to digitally sign the digest value, and extract the key feature vector in the signature result, and map the key feature vector into a bias operator in the homomorphic polynomial space. The homomorphic coding module, connected to the weight mapping module, is used to encode the plaintext vector into a homomorphic encryption initial polynomial. During the encoding process, a bias operator is injected into the encoding equation to change the initial distribution of the ciphertext under the fault-tolerant loop learning problem and generate an initial ciphertext carrying the weight distribution characteristics. The permission parsing module is used to receive a calculation request containing a data permission package, parse the set of operation permissions encapsulated in the data permission package, extract the operation instructions in the set of operation permissions and convert them into permission operators in the calculation domain; The ciphertext calculation module is connected to the homomorphic encoding module and the permission parsing module respectively. It is used to verify the mapping matching relationship between the permission operator and the bias operator of the ciphertext to be calculated. If the preset mapping matching relationship is satisfied, the hardware security module is called to perform homomorphic calculation on the initial ciphertext using the permission operator. The mapping matching result between the permission operator and the bias operator is used to constrain the homomorphic noise growth rate in the calculation process within a preset threshold range to ensure the decryption accuracy of the ciphertext produced by the homomorphic calculation. If the mapping matching relationship is inconsistent, the bias operator is used to trigger noise injection, which depletes the noise budget corresponding to the initial ciphertext.

Citation Information

Patent Citations

  • A gas meter reading system based on national cryptographic algorithms and its gas data transmission method

    CN111932852B