Account query method and system, and device
Encrypted queries are initiated to multiple bank systems through an anonymous query method, which solves the problems of low efficiency of bank account query and data leakage, and realizes efficient and secure bank account query.
Patent Information
- Application Number
- PCT/CN2024/142034
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-26
- Filing Date
- 2024-12-24
- Publication Date
- 2025-07-03
AI Technical Summary
The existing bank account query methods are inefficient and are prone to lead to user data leakage. Especially when querying the bank accounts of deceased relatives or elderly relatives, you need to go to the bank one by one to perform identity verification, which is time-consuming and has the risk of privacy data leakage.
An anonymous query method based on key information is adopted, a ciphertext vector is generated through encryption processing and querying multiple background service systems. Homomorphic ciphertext is used to perform account query, and a query report is generated to determine the account association situation and protect user data privacy.
It improves the efficiency of account query, reduces the risk of user data leakage, ensures that the user's key information is not obtained explicitly during the query process, and protects user privacy.
Smart Images

Figure CN2024142034_03072025_PF_FP_ABST
Abstract
Description
Account query method, system and device
[0001] This application claims priority to the Chinese patent application filed with the China Patent Office on December 26, 2023, with application number 202311818852.7 and application name “Account Query Method, System and Device”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of data query technology, and in particular to an account query method, system, and device. Background Art
[0003] With the development and advancement of Internet technology, banks and other financial institutions have made it increasingly convenient for users to open bank accounts, resulting in users opening more and more bank accounts in different banks. However, some bank accounts may be forgotten by users after opening because they are rarely used.
[0004] In daily life, users often need to check which banks they or their relatives have opened bank accounts in. In related solutions, users are usually required to bring their personal identification documents or proof of relationship with their relatives to different banks to inquire one by one. The query efficiency is very low and it is easy to cause user data leakage. Summary of the Invention
[0005] The present application provides an account query method, system and device, which solve the technical problems of low query efficiency and easy leakage of user data in existing account query methods.
[0006] In a first aspect, the present application provides an account query method, the method comprising:
[0007] Obtain key information of the user to be queried, and encrypt the key information to obtain a ciphertext vector corresponding to the key information;
[0008] Sending the ciphertext vector to one or more backend service systems; wherein the backend service systems store an account data set, wherein the account data set includes accounts of multiple users;
[0009] Receiving the homomorphic ciphertext sent by each of the backend service systems respectively; the homomorphic ciphertext is used to indicate whether there is an account associated with the key information in the account data set;
[0010] The homomorphic ciphertext is decrypted, and a query report is generated according to the decryption result, wherein the query report includes whether there is an account associated with the key information in the account data set.
[0011] In a second aspect, the present application provides an account query system, the system comprising:
[0012] An encryption module is used to obtain key information of the user to be queried and encrypt the key information to obtain a ciphertext vector corresponding to the key information;
[0013] a sending module, configured to send the ciphertext vector to one or more backend service systems; wherein the backend service systems store an account data set, wherein the account data set includes accounts of multiple users;
[0014] a receiving module, configured to respectively receive the homomorphic ciphertext sent by each of the backend service systems; the homomorphic ciphertext is used to indicate whether there is an account associated with the key information in the account data set;
[0015] A decryption module is used to decrypt the homomorphic ciphertext and generate a query report based on the decryption result, wherein the query report includes whether there is an account associated with the key information in the account data set.
[0016] In a third aspect, the present application provides an electronic device, comprising: a processor, and a memory and a communication interface communicatively connected to the processor;
[0017] The communication interface is used to communicate with other communication devices;
[0018] The memory is used to store computer-executable instructions;
[0019] The processor is configured to execute the computer-executable instructions stored in the memory to implement the account query method provided in the first aspect.
[0020] In a fourth aspect, the present application provides a computer-readable storage medium storing computer-executable instructions. When the computer-executable instructions are executed by a processor, the account query method provided in the first aspect is implemented.
[0021] In a fifth aspect, the present application provides a computer program product, including a computer program, which, when executed by a processor, implements the account query method provided in the first aspect.
[0022] The account query method, system and device provided in this application can initiate account queries to multiple background service systems at the same time, thereby effectively improving query efficiency; at the same time, by adopting an anonymous query method based on key information, the background service system being queried cannot obtain the key information of the user to be queried and the query results based on the key information in plain text when querying the associated account based on the key information of the user to be queried, thereby effectively protecting the user data of the user to be queried and reducing the risk of user data leakage. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] FIG1 is a schematic diagram of a step flow chart of an account query method provided in an embodiment of the present application;
[0024] FIG2 is a second schematic diagram of a step flow chart of an account query method provided in an embodiment of the present application;
[0025] FIG3 is a schematic diagram of a page of a query report provided in an embodiment of the present application;
[0026] FIG4 is a schematic diagram of another query report page provided in an embodiment of the present application;
[0027] FIG5 is a schematic diagram of a third step flow chart of an account query method provided in an embodiment of the present application;
[0028] FIG6 is a schematic diagram of a program module of an account query system provided in an embodiment of the present application;
[0029] FIG7 is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0030] In order to make the purpose, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application. In addition, although the disclosure in this application is introduced according to one or several exemplary examples, it should be understood that each aspect of these disclosures can also constitute a complete implementation method separately.
[0031] It should be noted that the brief descriptions of terms in this application are only for the purpose of facilitating the understanding of the embodiments described below, and are not intended to limit the embodiments of this application. Unless otherwise specified, these terms should be understood according to their ordinary and usual meanings.
[0032] In addition, the terms "comprises" and "comprising" and any variations thereof are intended to cover but not exclude inclusion, for example, a product or device comprising a list of components is not necessarily limited to those components expressly listed but may include other components not expressly listed or inherent to such product or device.
[0033] The term "module" used in the embodiments of this application refers to any known or later developed hardware, software, firmware, artificial intelligence, fuzzy logic or combination of hardware and / or software code that can perform the functions associated with the component.
[0034] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0035] The following is an explanation of some of the terms involved in the embodiments of this application:
[0036] Stealth Query, also known as private information retrieval, occurs when the querying party conceals the keywords or customer ID information of the query object. The data service provider provides matching query results, but the specific query object cannot be determined. The Stealth Query protocol is based on cryptographic techniques such as asymmetric encryption and oblivious transmission. The data service provider maintains control of the data resources, while the data requester no longer uses plaintext queries. Adding a random key to the query input significantly improves security compared to plaintext hashing and database collision queries, ensuring that only matching query results are obtained without leaving any trace of the query (query object information or customer ID).
[0037] Oblivious Transfer (OT): A security protocol in cryptography that allows the receiver to obtain certain information input by the sender, but the sender does not know whether the receiver has obtained this information.
[0038] Anonymous query based on oblivious transmission: It mainly uses the n-choose-1 OT protocol, which usually includes the following five steps: (1) The server has n pieces of data, so it generates n RSA public-private key pairs, retains n private keys, and sends n public keys to the client; (2) The user randomly generates a large integer key. It is known that the user wants to retrieve the t-th piece of data, so the user encrypts the large integer key with the received t-th RSA public key and sends the encrypted result s to the client; (3) The server uses the retained n RSA private keys to try to decrypt s at a time and obtain n decryption results (key1, key2, ..., keyn); (4) The server uses a symmetric encryption algorithm (such as the AES algorithm) to encrypt the corresponding message using (key1, key2, ..., keyn) and sends the generated ciphertext message to the user; (5) The user uses the key to symmetrically decrypt the t-th ciphertext and obtains the t-th original plaintext message to be retrieved.
[0039] Anonymous query based on homomorphic encryption: It is implemented based on Paillier semi-homomorphic encryption, that is, it supports homomorphic operations such as addition and multiplication. It usually includes the following steps: (1) The user generates a homomorphic encryption public key; (2) Assuming that the user needs to retrieve the t-th data, an n-dimensional ciphertext vector vector = (v1, ..., vn) is generated, where the t-th item is the ciphertext encrypted with the public key pk after the number 1, and the other items are the ciphertext encrypted with pk after 0. The vector and the public key pk are sent to the server; (3) The server performs a vector inner product operation on the vector and the n plaintext data sets to obtain the ciphertext result, and sends the ciphertext result to the user. Among them, the homomorphic encryption ciphertext calculation result is equal to the plaintext calculation result after decryption; (4) The user uses the private key sk to decrypt the result and obtain the t-th original plaintext message to be retrieved.
[0040] Anonymous query based on hash function: The user side calculates the hash value of the query data and sends the last few bits of the hash value to the server side. The server side calculates the hash value of all data, matches the last few bits of all hash values with the data sent by the client, and returns all matching results to the client.
[0041] With the development and advancement of internet technology, banks and other financial institutions are making it increasingly convenient for users to open bank accounts. This has led to an increasing number of users opening bank accounts in different banks. However, some bank accounts may be forgotten by users due to seldom being used. In daily life, users often want to check which banks they or their relatives have opened bank accounts in. Related solutions usually require users to bring their personal identification documents or proof of relationship with their relatives to visit different banks one by one to check. This query method has the following problems:
[0042] 1. For deceased relatives or elderly relatives, their family members may not know in which banks their bank accounts are opened. Therefore, their family members need to go to multiple banks to check one by one, which will take a lot of time.
[0043] 2. The bank may not have complete storage of bank cards and identity information of deceased relatives or elderly relatives, which may cause identity verification problems during the inquiry process, which will also take a lot of time.
[0044] 3. Having someone else check your bank account on your behalf requires preparing a large amount of paper materials and the process is relatively cumbersome. In addition, the data of each bank is not interoperable, and the identity verification process must be repeated for each query.
[0045] 4. When family members go to each bank to check the accounts of deceased relatives or elderly relatives, personal privacy data may be leaked, resulting in the illegal use of the private information of the deceased relatives or elderly relatives.
[0046] In addition, some online query solutions still have the following problems:
[0047] 1. Anonymous queries based on oblivious transfer and homomorphic encryption require users to know in advance the location of the data to be queried in the dataset. Therefore, before querying, the user needs to perform a privacy intersection with the server to locate the data. However, in the scenario of one-click card access for deceased individuals, data queries need to be performed on multiple commercial banks. The communication cost of privacy intersection is relatively high, so anonymous queries based on oblivious transfer and homomorphic encryption are not applicable.
[0048] Second, although the performance of anonymous query based on hash function is relatively high, it will expose the privacy of the querying user to a certain extent. The queried bank can obtain the dataset of the query results. If the hash value bits used for the query are long enough, the indistinguishability of this scheme is very low.
[0049] In response to the above technical problems, an account query method is provided in an embodiment of the present application, which can initiate account queries to multiple background service systems at the same time, thereby effectively improving the query efficiency; at the same time, by adopting an anonymous query method based on key information, the background service system being queried cannot obtain the key information of the user to be queried and the query results based on the key information in plain text when querying the associated account based on the key information of the user to be queried, thereby effectively protecting the user data of the user to be queried and reducing the risk of user data leakage.
[0050] The backend service system may be a banking service system.
[0051] The technical solutions shown in this application are described in detail below through specific embodiments. It should be noted that the following embodiments can exist independently or in combination with each other, and the same or similar contents will not be repeated in different embodiments.
[0052] In some implementations, the above-mentioned account query method can be applied to a "one-click card query" scenario, where a user can initiate account query requests to multiple bank service systems simultaneously through a client.
[0053] Optionally, the above account query method can also be applied to the scenario where family members check the account card of deceased relatives or elderly relatives with one click.
[0054] 1 , which is a flowchart illustrating steps of an account query method provided in an embodiment of the present application, in some embodiments of the present application, the account query method includes:
[0055] S101: The client receives the query materials uploaded by the user.
[0056] In some embodiments, the querying user can first perform real-name authentication in the client (such as face recognition authentication, etc.). After completing the real-name authentication, enter the account query program entrance and actively fill in the identity information of the user to be queried, such as one or more of the user to be queried's phone number, name, ID number, front and back photos of the ID card, and other information.
[0057] In some embodiments, if the user to be queried is a deceased relative of the current queried user, it is also necessary to upload information proving the relationship with the user to be queried, as well as one or more of the following information: a scanned document of the death certificate of the user to be queried, telephone number, name, ID number, photos of the front and back of the ID card, etc.
[0058] S102. The client sends the image data in the query material to the middle platform gateway.
[0059] Optionally, the above-mentioned image data may include the front and back photos of the ID card, the scanned document of the deceased certificate, the face photo, etc. in the above-mentioned query materials.
[0060] S103. The middle platform gateway performs image tampering detection.
[0061] In some implementations, the middle platform gateway may perform image tampering detection on the image data to determine whether the image data has been tampered with.
[0062] Image tampering detection refers to the process of detecting and analyzing tampered images. Image tampering detection methods primarily include feature-based and machine learning-based approaches. Feature-based approaches analyze image features such as pixels, color, and texture to extract features that differ from the original image, thereby determining whether the image has been tampered with. Machine learning-based approaches utilize large amounts of training data to train models to identify whether an image has been tampered with.
[0063] S104. The middle platform gateway feeds back the image tampering detection results to the client.
[0064] S105. The client sends the query materials to the review background.
[0065] In some implementations, after the client determines that the image data has not been tampered with, it may send the query materials to the review backend for further review.
[0066] Among them, the audit background can review the authenticity of the above-mentioned query materials.
[0067] In some implementations, the audit backend may verify the identity information and the relationship proof information according to a preset verification process.
[0068] S106. The audit backend sends an external auxiliary inspection request to the external inspection system.
[0069] In some embodiments, the external auxiliary inspection request may include the identity information and the relationship proof information.
[0070] Optionally, the external inspection system may be a local inspection system with legal inspection qualifications.
[0071] In some embodiments, the external verification system may verify the received identity information and the relationship proof information to determine whether they are legitimate, and send the verification results to the review background.
[0072] S107. The audit backend receives the inspection results sent by the external inspection system.
[0073] In some embodiments, when the audit background detects that the above-mentioned identity information and relationship proof information have failed verification, it can feedback the reason for the failure to verify to the client, and the querying user can supplement or modify the query materials according to the reason for the failure to verify.
[0074] In some implementations, after receiving the query materials resubmitted by the querying user, the client re-initiates the above-mentioned verification process.
[0075] S108. The review backend sends the key information of the user to be queried to the query backend.
[0076] In some implementations, when the audit backend detects that the identity information and the relationship proof information are verified, the audit backend can obtain key information of the user to be queried from the identity information and send it to the query backend.
[0077] S109: The query backend executes the account query process.
[0078] In some implementations, the query backend may utilize the aforementioned key information to initiate a query to one or more backend service systems, and generate a query report based on the content fed back by the backend service systems.
[0079] The backend service system may be a banking service system.
[0080] S110. The audit backend sends a query report viewing request to the query backend.
[0081] In some implementations, the audit backend may send a query report viewing request to the query backend every preset time period (eg, half an hour).
[0082] S111. The query background feeds back the query report to the audit background.
[0083] In some implementations, after generating a query report, the query backend, upon receiving a query report viewing request sent by the audit backend, feeds back the query report to the audit backend.
[0084] S112. The audit backend feeds back the query report to the client.
[0085] In some implementations, after receiving the query report fed back by the query backend, the audit backend feeds back the query report to the client.
[0086] In some implementations, after the audit backend feeds back the query report to the client, the query status in the client may be updated to "view report".
[0087] S113. The client displays the query report.
[0088] In some implementations, the querying user can browse the report content by clicking "View Report" in the client.
[0089] In some implementations, the content of the query report can be temporarily stored for a certain period of time (eg, 30 days). After the expiration date, the content of the query report will be automatically deleted and cannot be viewed, and the application record will be retained in the historical record.
[0090] It is understood that the aforementioned middleware gateway, audit backend, and query backend all constitute the account query system, and the client is the client corresponding to the aforementioned account query system, which can be installed on a common client computer. Such clients include web browsers used on the World Wide Web and instant messaging client software. Such clients may include network terminals such as mobile terminals, tablet computers, laptop computers, desktop computers, and smart TVs. Such clients may also include apps (applications) and web browsers running on such clients.
[0091] Referring to FIG. 2 , FIG. 2 is a second flow chart illustrating steps of an account query method provided in an embodiment of the present application. In some embodiments of the present application, the account query method includes:
[0092] S201. The account query system obtains key information of the user to be queried, and encrypts the key information to obtain a ciphertext vector corresponding to the key information.
[0093] Optionally, the above key information may be the phone number, ID number, front and back pictures of the ID card, facial photo, etc. of the user to be queried, which is not limited in the embodiments of the present application.
[0094] In some implementations, after obtaining the key information of the user to be queried, the key information may be encrypted using a preset encryption method to protect user privacy and data security.
[0095] S202: The account query system sends the ciphertext vector to one or more backend service systems.
[0096] The background service system stores an account data set, which includes accounts of multiple users.
[0097] Optionally, the one or more backend service systems may be backend service systems selected by the querying user from a plurality of candidate backend service systems. For example, assuming there are n candidate backend service systems, if the querying user wishes to query whether the user to be queried has opened an account in m (m≤n) of these backend service systems, the user may select m of the n candidate backend service systems, and the account query system may send the ciphertext vector to the m backend service systems.
[0098] S203. The backend service system generates homomorphic ciphertext based on the ciphertext vector and the account data set.
[0099] The homomorphic ciphertext is used to indicate whether there is an account associated with the key information in the account data set.
[0100] Homomorphic ciphertext refers to ciphertext that has undergone homomorphic encryption. Homomorphic encryption is a specialized encryption method that allows specific algebraic operations to be performed directly on ciphertext, while still retaining the encrypted data. The advantage of homomorphic encryption is that it allows analysis and retrieval of specific encrypted data even while the data is encrypted, improving data processing efficiency and ensuring secure data transmission. Furthermore, correctly encrypted data will still yield the correct decryption result.
[0101] S204. The backend service system sends the homomorphic ciphertext to the account query system.
[0102] In some implementations, each backend service system may send the generated homomorphic ciphertext to the account query system.
[0103] S205. The account query system decrypts the homomorphic ciphertext and generates a query report based on the decryption result.
[0104] The query report includes whether there is an account associated with the above key information in the above account data set.
[0105] In some embodiments, the applicant's relevant information may be displayed in the report header of the query report, and in the bank account display area, based on the minimum and necessary principles, only a list of bank identifiers with accounts may be displayed without displaying card attributes and other information.
[0106] For example, referring to FIG3 and FIG4 , FIG3 is a page diagram of a query report provided in an embodiment of the present application, and FIG4 is a page diagram of another query report provided in an embodiment of the present application.
[0107] In Figure 3, if it is determined that accounts associated with the above key information exist in the account data sets in the backend service systems corresponding to xx Bank, yy Bank, and zz Bank, only the names of xx Bank, yy Bank, and zz Bank may be displayed in the query report.
[0108] In FIG4 , if no account associated with the key information mentioned above exists in the account data sets in the above-mentioned respective backend service systems, then only “no relevant account found” may be displayed in the query report.
[0109] The account query method provided in this application can initiate account queries to multiple background service systems at the same time, thereby effectively improving query efficiency; at the same time, by adopting an anonymous query method based on key information, the background service system being queried cannot obtain the key information of the user to be queried and the query results based on the key information in plain text when querying the associated account based on the key information of the user to be queried, thereby effectively protecting the user data of the user to be queried and reducing the risk of user data leakage.
[0110] Based on the contents described in the above embodiments, referring to FIG5 , FIG5 is a schematic diagram of a third step flow chart of an account query method provided in an embodiment of the present application. In some embodiments of the present application, the account query method includes:
[0111] S501. The backend service system generates a Lagrange interpolation polynomial H(x) and an identification polynomial F(x).
[0112] In some implementations, assume that an account dataset (ki, vi) is stored in each backend service system, and that the account dataset (ki, vi) includes accounts of n users. For example, the account dataset may be ((k1, v1), (k2, v2), ..., (kn, vn)), where ki represents the key information of the i-th user, and vi represents the accounts associated with the key information of the i-th user.
[0113] In some embodiments, the backend service system may pre-generate an identification polynomial F(x) corresponding to the dataset, and pre-generate a Lagrange interpolation polynomial H(x) corresponding to the dataset based on a Lagrange polynomial interpolation method. Wherein, a value of 0 in the identification polynomial F(x) indicates the existence of a related account, and a value of 1 indicates the absence of a related account.
[0114] In some embodiments:
[0115] H(X)=a_0+a_1x+a_2x^2+...+a_n x^n;
[0116] F(x)=(x-k_1)(x-k_2)...(x-k_n)=c_0+c_1x+c_2x^2+...+c_n x^n;
[0117] Among them, H(k_1)=v_1, H(k_2)=v_2,..., H(k_n)=v_n, F(k_1)=F(k_2)=...=F(k_n)=0.
[0118] S502. The account query system generates a homomorphically encrypted public key PK and a homomorphically encrypted private key SK.
[0119] There is no order between step S501 and step S502.
[0120] S503 : The account query system uses the homomorphic encryption public key PK to encrypt the key information of the user to be queried, and obtains a ciphertext vector E(vector).
[0121] In some embodiments, assuming that the key information of the user to be queried is kt, the account query system can obtain a pre-generated homomorphic encryption public key PK, and use the homomorphic encryption public key PK to encrypt the key information kt to the power of 1 to the power of n respectively, to obtain the ciphertext vector E(vector) corresponding to the key information kt; where n is a positive integer and n≥2; E(vector)=(E(k_t), E(k_t^2), ..., E(k_t^n)).
[0122] S504: The account query system sends the ciphertext vector E(vector) to one or more backend service systems.
[0123] S505 . The backend service system determines the homomorphic ciphertext E(F(vector)) and E(H(vector)).
[0124] In some implementations, the backend service system may generate homomorphic ciphertext based on the ciphertext vector E(vector), and the Lagrange interpolation polynomial H(x) and identification polynomial F(x) corresponding to the above account data set.
[0125] In some embodiments, the backend service system may input the ciphertext vector E(vector) into the Lagrange interpolation polynomial H(x) and the identification polynomial F(x), and then generate the ciphertext vector E(vector) based on the value of the identification polynomial F(x) and the value of the Lagrange interpolation polynomial H(x). The value of the identification polynomial F(x) indicates whether an account associated with the key information exists in the account data set; and the value of the Lagrange interpolation polynomial H(x) indicates the account associated with the key information.
[0126] Specifically, the ciphertext vector E(vector) can be substituted into the function identification polynomial F(x) and the Lagrange interpolation polynomial H(x), and the value E(F(vector)) of the identification polynomial F(x) and the value E(H(vector)) of the Lagrange interpolation polynomial H(x) are used as the above-mentioned homomorphic ciphertext.
[0127] S506 . The backend service system sends the homomorphic ciphertext E(F(vector)) and E(H(vector)) to the account query system.
[0128] S507. The account query system uses the homomorphic encryption private key SK to decrypt the homomorphic ciphertext E(F(vector)) and E(H(vector)) to obtain the plaintext values F(vector) and H(vector).
[0129] In some embodiments, the account query system can obtain a pre-generated homomorphic encryption private key SK that matches the above-mentioned homomorphic encryption public key PK; use the homomorphic encryption private key SK to decrypt the above-mentioned homomorphic ciphertext to obtain the plaintext value H(vector) of the Lagrange interpolation polynomial and the plaintext value F(vector) of the identification polynomial.
[0130] S508. The account query system generates a query report based on F(vector) and H(vector).
[0131] In some embodiments, when the plaintext value F(vector) of the identification polynomial is equal to a preset value (e.g., equal to 0), it is determined that an account associated with the key information exists in the account data set, and the plaintext value H(vector) of the Lagrange interpolation polynomial is determined to be the account associated with the key information. When the plaintext value F(vector) of the identification polynomial is not equal to the preset value (e.g., equal to 1), it is determined that an account associated with the key information does not exist in the account data set. The key information-based anonymous query scheme uses the Lagrange interpolation polynomial to hash the data set and uses the identification polynomial to determine whether the data exists.
[0132] Based on the content described in the above embodiments, in some embodiments of the present application, after obtaining the ciphertext vector corresponding to the key information, the account query system can further detect whether each candidate backend service system supports the anonymous query, and select the first candidate backend service system that supports the anonymous query as the backend service system. That is, after obtaining the ciphertext vector corresponding to the key information, the account query system can only send the ciphertext vector to the backend service system that supports the anonymous query, and not send the ciphertext vector to the backend service system that does not support the anonymous query, thereby further preventing the leakage of user data.
[0133] In some embodiments of the present application, the query report generated by the account query system may also include the bank identifier corresponding to the second candidate backend service system that does not support the above-mentioned anonymous query, thereby prompting the querying user which banks the current query operation has ignored. The user can choose other query methods based on the bank identifier corresponding to the second candidate backend service system that does not support the above-mentioned anonymous query in the query report to inquire whether the account of the user to be queried is opened in the above-mentioned second candidate backend service system, thereby preventing some accounts from being missed.
[0134] In some embodiments of the present application, the account query system may send an upgrade reminder message to the second candidate backend service system, prompting it to upgrade its system so that it supports anonymous query. In other words, in some implementations, the account query system may promptly remind certain backend service systems that do not support anonymous query to complete their service upgrades promptly, thereby providing more comprehensive query services to users.
[0135] Based on the content described in the above embodiments, an account query system is further provided in the embodiments of the present application. Referring to FIG. 6 , FIG. 6 is a schematic diagram of program modules of an account query system provided in the embodiments of the present application. In some embodiments, the account query system 60 includes:
[0136] The encryption module 601 is used to obtain key information of the user to be queried, and encrypt the key information to obtain a ciphertext vector corresponding to the key information.
[0137] The sending module 602 is configured to send the ciphertext vector to one or more backend service systems; the backend service systems store an account data set, wherein the account data set includes accounts of multiple users.
[0138] The receiving module 603 is used to respectively receive the homomorphic ciphertext sent by each of the backend service systems; the homomorphic ciphertext is used to indicate whether there is an account associated with the key information in the account data set.
[0139] The decryption module 604 is configured to decrypt the homomorphic ciphertext and generate a query report based on the decryption result. The query report includes information on whether there is an account associated with the key information in the account data set.
[0140] The account query system provided by this application can initiate account queries to multiple background service systems at the same time, thereby effectively improving query efficiency; at the same time, by adopting an anonymous query method based on key information, the background service system being queried cannot obtain the key information of the user to be queried and the query results based on the key information in plain text when querying the associated account based on the key information of the user to be queried, thereby effectively protecting the user data of the user to be queried and reducing the risk of user data leakage.
[0141] In some embodiments, the encryption module 601 is configured to:
[0142] Get the pre-generated homomorphic encryption public key;
[0143] Use the homomorphic encryption public key to encrypt the key information from the 1st power to the nth power respectively to obtain the ciphertext vector corresponding to the key information; where n is a positive integer and n≥2.
[0144] In some embodiments, the homomorphic ciphertext is generated by the background service system according to the ciphertext vector and the Lagrange interpolation polynomial and identification polynomial corresponding to the account data set.
[0145] In some embodiments, the homomorphic ciphertext is generated by the backend service system according to the value of the identification polynomial and the value of the Lagrange interpolation polynomial after the backend service system inputs the ciphertext vector into the Lagrange interpolation polynomial and the identification polynomial;
[0146] The value of the identification polynomial is used to indicate whether there is an account associated with the key information in the account data set; and the value of the Lagrange interpolation polynomial is used to indicate the account associated with the key information.
[0147] In some embodiments, the decryption module 604 is configured to:
[0148] Obtaining a pre-generated homomorphic encryption private key that matches the homomorphic encryption public key;
[0149] Decrypting the homomorphic ciphertext using the homomorphic encryption private key to obtain the plaintext value of the Lagrange interpolation polynomial and the plaintext value of the identification polynomial;
[0150] When the plaintext value of the identification polynomial is equal to a preset value, determining that an account associated with the key information exists in the account data set, and determining the plaintext value of the Lagrange interpolation polynomial as the account associated with the key information;
[0151] When the plain text value of the identification polynomial is not equal to the preset value, it is determined that no account associated with the key information exists in the account data set.
[0152] In some embodiments, the account query system further includes a detection module for:
[0153] Check whether each candidate backend service system supports anonymous query;
[0154] The first candidate background service system that supports the anonymous query is used as the background service system.
[0155] In some embodiments, the query report also includes a bank identifier corresponding to a second candidate backend service system that does not support the anonymous query.
[0156] In some embodiments, the sending module 602 is further configured to:
[0157] An upgrade reminder message is sent to the second candidate background service system, where the upgrade reminder message is used to remind the second candidate background service system to perform a system upgrade so that the second candidate background service system supports the anonymous query.
[0158] In some embodiments, the account query system further includes a verification module for:
[0159] Receive the identity information of the user to be queried and the relationship certification information between the user to be queried and the current applicant;
[0160] The identity information and the relationship proof information are verified according to a preset verification process; wherein the verification process includes sending the identity information and the relationship proof information to an external verification system for verification.
[0161] The encryption module 601 is used to:
[0162] When it is detected that the identity information and the relationship proof information are verified, the key information is obtained from the identity information.
[0163] It should be noted that the specific execution contents of the encryption module 601, the sending module 602, the receiving module 603 and the decryption module 604 in the embodiment of the present application can refer to the various steps in the account query method described in the above embodiment, and will not be repeated here.
[0164] Furthermore, based on the contents described in the above embodiments, an electronic device is also provided in an embodiment of the present application, which includes at least one processor, and a communication interface and a memory to which the processor is communicatively connected; wherein the communication interface is used to communicate with other communication devices, and the memory stores computer-executable instructions; the above at least one processor executes the computer-executable instructions stored in the memory to implement the various steps in the account query method described in the above embodiments.
[0165] For a better understanding of the embodiments of the present application, refer to FIG. 7 , which is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present application.
[0166] As shown in FIG7 , the electronic device 70 of this embodiment includes: a processor 701 , a memory 702 , and a communication interface 704 ; wherein:
[0167] Memory 702, for storing computer-executable instructions;
[0168] The communication interface 704 is used to communicate with other communication devices;
[0169] The processor 701 is configured to execute computer-executable instructions stored in the memory to implement the various steps of the query optimization method described in the above embodiment.
[0170] Optionally, the memory 702 may be independent or integrated with the processor 701 .
[0171] When the memory 702 is independently provided, the device further includes a bus 703 for connecting the memory 702 , the communication interface 704 and the processor 701 .
[0172] An embodiment of the present application provides a computer-readable storage medium having computer-executable instructions stored therein. When a processor executes the computer-executable instructions, the steps of the account query method described in the above embodiment are implemented.
[0173] An embodiment of the present application provides a computer program product, including a computer program. When the computer program is executed by a processor, the computer program implements the various steps of the account query method described in the above embodiment.
[0174] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules is merely a logical function division. In actual implementation, there may be other division methods, such as multiple modules can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interface, device or module, which can be electrical, mechanical or other forms.
[0175] The modules described as separate components may or may not be physically separate, and the components shown as modules may or may not be physical units, that is, they may be located in one place or distributed across multiple network elements. Some or all of the modules may be selected to achieve the purpose of the solution of this embodiment according to actual needs.
[0176] In addition, the functional modules in the various embodiments of the present application may be integrated into a single processing unit, or each module may exist physically separately, or two or more modules may be integrated into a single unit. The above-mentioned modules may be implemented in the form of hardware or hardware plus software functional units.
[0177] The above-mentioned integrated module implemented in the form of a software functional module can be stored in a computer-readable storage medium. The above-mentioned software functional module is stored in a storage medium and includes a number of instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) or a processor to perform some steps of the method described in each embodiment of the present application.
[0178] It should be understood that the processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), etc. A general-purpose processor may be a microprocessor or any conventional processor. The steps of the method disclosed in the application may be directly implemented by a hardware processor or implemented by a combination of hardware and software modules in the processor.
[0179] The memory may include high-speed memory and may also include non-volatile storage, such as at least one disk memory, and may also be a USB flash drive, a mobile hard disk, a read-only memory, a magnetic disk or an optical disk.
[0180] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. Buses can be classified into address buses, data buses, and control buses. For ease of illustration, the buses in the drawings of this application are not limited to just one bus or just one type of bus.
[0181] The storage medium may be implemented by any type of volatile or non-volatile memory device, or a combination thereof, such as static random access memory, electrically erasable programmable read-only memory, erasable programmable read-only memory, programmable read-only memory, read-only memory, magnetic storage, flash memory, magnetic disk, or optical disk. The storage medium may be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0182] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some or all of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of the present application.
Claims
1. An account query method, characterized in that, The method includes: Obtaining key information of a user to be queried, and performing encryption processing on the key information to obtain a ciphertext vector corresponding to the key information; Sending the ciphertext vector to one or more backend service systems; an account dataset is stored in the backend service system, and the account dataset includes accounts of multiple users; Receiving homomorphic ciphertexts sent by each of the backend service systems respectively; the homomorphic ciphertexts are used to indicate whether there is an account associated with the key information in the account dataset; Performing decryption processing on the homomorphic ciphertexts, and generating a query report according to the decryption result, where the query report includes whether there is an account associated with the key information in the account dataset.
2. The method according to claim 1, wherein The performing encryption processing on the key information to obtain a ciphertext vector corresponding to the key information includes: Obtaining a pre-generated homomorphic encryption public key; Using the homomorphic encryption public key to perform encryption processing on the 1st power to the nth power of the key information respectively to obtain a ciphertext vector corresponding to the key information; where n is a positive integer and n≥2.
3. The method according to claim 1, wherein The homomorphic ciphertext is generated by the backend service system according to the ciphertext vector, and a Lagrange interpolation polynomial and an identification polynomial corresponding to the account dataset.
4. The method according to claim 3, wherein The homomorphic ciphertext is generated by the backend service system after inputting the ciphertext vector into the Lagrange interpolation polynomial and the identification polynomial, and according to the value of the identification polynomial and the value of the Lagrange interpolation polynomial; wherein, the value of the identification polynomial is used to indicate whether there is an account associated with the key information in the account dataset; the value of the Lagrange interpolation polynomial is used to indicate the account associated with the key information.
5. The method according to claim 4, wherein The performing decryption processing on the homomorphic ciphertexts and generating a query report according to the decryption result includes: Obtaining a pre-generated homomorphic encryption private key that matches the homomorphic encryption public key; Using the homomorphic encryption private key to perform decryption processing on the homomorphic ciphertexts to obtain the plaintext value of the Lagrange interpolation polynomial and the plaintext value of the identification polynomial; When the plaintext value of the identification polynomial is equal to a preset value, determining that there is an account associated with the key information in the account dataset, and determining the plaintext value of the Lagrange interpolation polynomial as the account associated with the key information; When the plaintext value of the identification polynomial is not equal to the preset value, determining that there is no account associated with the key information in the account dataset.
6. The method according to claim 1, characterized in that, The method further includes: Detecting whether each candidate backend service system supports stealth query; Using a first candidate backend service system that supports the stealth query as the backend service system.
7. The method according to claim 6, characterized in that, The query report further includes bank identifiers corresponding to second candidate backend service systems that do not support the stealth query.
8. The method according to claim 7, wherein The method further includes: Sending an upgrade reminder message to the second candidate backend service system, where the upgrade reminder message is used to remind the second candidate backend service system to perform system upgrade so that the second candidate backend service system supports the stealth query.
9. The method according to any one of claims 1 to 8, characterized in that The method further includes: Receive the identity information of the user to be queried and the relationship proof information between the user to be queried and the current applicant user; Verify the identity information and the relationship proof information according to a preset verification process; wherein, the verification process includes sending the identity information and the relationship proof information to an external inspection system for inspection; The obtaining of the key information of the user to be queried includes: When it is detected that the identity information and the relationship proof information pass the verification, obtain the key information from the identity information.
10. An account query system, characterized in that, The account query system includes: An encryption module, configured to obtain the key information of the user to be queried and perform encryption processing on the key information to obtain a ciphertext vector corresponding to the key information; A sending module, configured to send the ciphertext vector to one or more background service systems; the background service systems store an account data set, and the account data set includes the accounts of multiple users; A receiving module, configured to respectively receive the homomorphic ciphertext sent by each of the background service systems; the homomorphic ciphertext is used to indicate whether there is an account associated with the key information in the account data set; A decryption module, configured to perform decryption processing on the homomorphic ciphertext and generate a query report according to the decryption result, and the query report includes whether there is an account associated with the key information in the account data set.
11. An electronic device, characterized in that, Includes: A processor, as well as a memory and a communication interface communicatively connected to the processor; The communication interface is used to communicate with other communication devices; The memory is used to store computer execution instructions; The processor is used to execute the computer execution instructions stored in the memory to implement the account query method according to any one of claims 1-9.
12. A computer-readable storage medium, characterized in that, Computer execution instructions are stored in the computer-readable storage medium, and when the computer execution instructions are executed by a processor, the account query method according to any one of claims 1-9 is implemented.
13. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, the account query method according to any one of claims 1-9 is implemented.
Citation Information
Patent Citations
Electronic accounting method and device and terminal equipment
CN104700277A
Data processing method and related equipment
CN113051590A
Data anonymous trace query method and device, storage medium and electronic equipment
CN116680324A
Account query method, system and equipment
CN117951173A
Computer-Implemented System And Method For Providing Secure Data Processing In A Cloud Using Discrete Homomorphic Encryption
US20150244517A1