Encryption method, decryption method, encryption and decryption method and computer readable storage medium

Through the multiple security protection technology of double-layer encryption, data compression and digital signature, the existing encryption methods are solved inadequate security and improper key management, and efficient and secure file data transmission and storage are achieved.

CN120263395AInactive Publication Date: 2025-07-04BEIJING ZHIQIAN TECH CO LTD

Patent Information

Application Number
CN202510749069.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-06
Publication Date
2025-07-04
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing encryption methods have problems such as insufficient security, missing data integrity verification, non-standard file formats, improper key management, and large computing and storage overhead. It is especially difficult to meet the requirements of high security and high efficiency in data transmission, storage and tamper-proof.

Method used

The two-layer encryption method is adopted. First, AES symmetric encryption is used to generate a random key, then the RSA-OAEP algorithm is used to encrypt the key, and the key ciphertext is added to the file header. The data block is encrypted in blocks using AES-GCM to generate authentication tags. Finally, the data is digitally signed through the RSA-PSS algorithm to ensure data integrity.

Benefits of technology

It realizes efficient and secure encryption processing for the transferred file data, improves data transmission efficiency, enhances key transmission security, provides dual guarantees of data confidentiality and integrity, and prevents tampering and key leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263395A_ABST
    Figure CN120263395A_ABST
Patent Text Reader

Abstract

The invention provides an encryption method, a decryption method, an encryption and decryption method and a computer readable storage medium, and relates to the technical field of information security processing. The encryption method comprises the following steps: reading original file data and compressing the original file data; randomly generating an encryption key by using a first preset encryption method; encrypting the encryption key by using a second preset encryption method; adding the key ciphertext into a file header; performing block encryption on the compressed data block by using an enhancement mode of a first preset encryption method to obtain a ciphertext and an authentication tag; splicing the file header, the ciphertext and the authentication tag; performing digital signature on the spliced data; and sequentially writing the file header, the ciphertext, the authentication tag and the digital signature into the file according to a predefined format to obtain an encrypted data file. Through multiple security protection technologies of double-layer encryption, data compression, label authentication and digital signature, efficient and safe encryption processing on the file data to be transmitted is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of information security processing, and particularly relates to an encryption method, a decryption method, an encryption and decryption method, and a computer-readable storage medium. Background Art

[0002] Existing file encryption technologies mostly adopt a single encryption method, such as a symmetric stream cipher (e.g., RC4) or a block cipher, but there are problems such as insufficient security, lack of data integrity verification, and non-standard file formats. Traditional encryption methods often cannot simultaneously meet the requirements of high security and high efficiency in data transmission, storage, and anti-tampering, including: First, insufficient security: For example, the traditional AES + RSA combined encryption scheme.

[0003] AES (symmetric encryption): Like a "key", it can quickly lock and open a large safe (encrypt a large amount of data). But the problem is how to safely give this key to the other party? RSA (asymmetric encryption): Like a pair of "locks", you have a public lock (public), and the other party has a private lock (confidential). You can lock something with the other party's public lock, but only he can open it with the private lock. However, the disadvantage is that the locking speed is very slow and it is not suitable for locking too many things.

[0004] Example of combined usage: Suppose you want to send a secret message to a friend: Step 1: Generate an AES key. You generate a random AES key (such as a string of random numbers), which can quickly encrypt and decrypt your chat content.

[0005] Step 2: Encrypt the AES key with RSA. You ask your friend for his "public lock" (i.e., his RSA public key), and then use this public lock to lock the AES key in a box (encrypt the AES key with RSA). Even if someone peeks at this box, they cannot open it without your friend's "private lock".

[0006] Step 3: Send the encrypted AES key and the message. Send the box with the AES key locked by RSA to your friend. Encrypt your chat content into ciphertext with the AES key (stuff it into the large safe).

[0007] After the friend receives it: Use his own "private lock" to open the box with the AES key and get the AES key.

[0008] Use the AES key to decrypt the ciphertext and read the message.

[0009] In the traditional AES + RSA combined encryption scheme, RSA is only used to transmit the key because it is efficient in encrypting small data (such as a string of keys). AES is responsible for the actual encryption of the content, which is fast and highly secure. This combination combines the advantages of both encryptions, being both secure and efficient! However, in the traditional AES + RSA combined encryption scheme, the encrypted data itself may be tampered with, and traditional encryption modes (ECB / CBC / CFB) cannot automatically detect tampering. This is like: a user sends a box with a seal (encrypted data), but someone may secretly open the box during transportation, replace the contents inside, and then reseal it. The recipient opens it and finds that the box is still sealed, but the contents inside have been switched! 1. ECB mode (Electronic Codebook): The data is divided into blocks, and each block is encrypted independently (like locking each small box with the same lock). Vulnerability: If the contents of two data blocks are the same, the encrypted ciphertext blocks will also be exactly the same. An attacker can: Copy and paste: For example, tamper with a repeated section in the chat record and replace it with other information.

[0010] Replay attack: Intercept a piece of encrypted data and send it directly repeatedly (such as repeated deductions).

[0011] Example: You send the message "Transfer 100 yuan" twice, and after encryption, it may become two identical ciphertexts. An attacker can delete one of them, causing the other party to only receive one transfer.

[0012] 2. CBC mode (Cipher Block Chaining): When each data block is encrypted, it is mixed with the ciphertext of the previous block (like a chain of links). Vulnerabilities: Although it solves the repetition problem of ECB, there are two risks: Initial Vector (IV) leakage: If the IV is predicted or reused, an attacker can forge part of the data.

[0013] Intermediate tampering: An attacker can modify a ciphertext block, causing all subsequent decrypted data to be incorrect, but the recipient may not be able to detect the tampering (unless additional integrity verification is performed).

[0014] Example: You and your friend agree to transmit messages using a chain of ciphertext blocks, but an attacker tampers with one of the intermediate ciphertext blocks, causing the decrypted chat content to become garbled, but the recipient may mistake it for a normal error rather than tampering.

[0015] 3. Cipher Feedback (CFB) mode: Similar to CBC, but the data stream is encrypted bit by bit (suitable for real-time communication). Vulnerability: Similar to CBC, there is no built-in integrity protection. An attacker can modify a single bit in the ciphertext, resulting in a predictable change in the corresponding bit of the decrypted plaintext (such as modifying the last bit of the transfer amount).

[0016] Inserting or deleting data: Since the mode depends on the previous ciphertext block, an attacker may disrupt the entire decryption process by inserting invalid data, but it is difficult for the receiver to locate the problem.

[0017] It can be seen that in the traditional AES + RSA combination, the ECB, CBC, or CFB mode only focuses on encryption and does not care about verification. Data may be tampered with but cannot be detected, and there are certain vulnerabilities in data integrity verification and anti-tampering capabilities. An attacker may use replay attacks, padding attacks, or ciphertext adjustment attacks to infer part of the original data content.

[0018] Second, improper key management: Many existing solutions only use RSA to encrypt the symmetric key, but do not effectively manage the use of the key, resulting in the key being stolen and used to decrypt all historical data, with low security. Some solutions use fixed keys or change keys irregularly, lacking a flexible key update mechanism and being vulnerable to long-term attacks.

[0019] Third, high computational and storage overhead: Due to the high computational complexity of RSA encryption and decryption operations, large computational overhead will be generated when processing large files, affecting performance.

[0020] Fourth, insufficient anti-tampering ability: Existing solutions usually only rely on the authentication tag of symmetric encryption (such as the TAG of AES-GCM), and do not further combine RSA signatures for anti-tampering verification. An attacker may still use the unencrypted file header to tamper. Some encryption solutions only provide basic hash checks (such as CRC32 or SHA256), but these methods are vulnerable to collision attacks and cannot truly ensure data integrity. Summary of the Invention

[0021] The purpose of the present invention is to overcome the above technical deficiencies and provide an encryption method, a decryption method, an encryption and decryption method, and a computer-readable storage medium to solve the problem of low security of the encryption and decryption methods in related technologies.

[0022] To achieve the above technical objectives, the present invention adopts the following technical solutions: According to the first aspect of the present invention, an encryption method applicable to a data source is provided, including: Read the original file data and compress it to obtain a compressed data block; Use a first preset encryption method to randomly generate an encryption key; Encrypt the encryption key using a second preset encryption method to obtain a ciphertext of the key; Add the ciphertext of the key to the file header; Use the enhanced mode of the first preset encryption method to perform block encryption on the compressed data block to obtain ciphertext and an authentication tag; Concatenate the file header, ciphertext, and authentication tag; Use a third preset encryption method to perform a digital signature on the concatenated data; Write the file header, ciphertext, authentication tag, and digital signature into a file in a predefined format in sequence to obtain an encrypted data file.

[0023] Preferably, when using the first preset encryption method to randomly generate an encryption key, specifically: Use the AES symmetric encryption method to randomly generate an AES symmetric encryption key with a preset number of bits.

[0024] Preferably, when using the second preset encryption method to encrypt the encryption key to obtain a ciphertext of the key, specifically: Use the RSA-OAEP algorithm to encrypt the encryption key to generate a ciphertext of the key.

[0025] Preferably, the step of adding the ciphertext of the key to the file header includes: Generate a preset number of random bytes nonce and a timestamp, and construct a file header, which includes: a fixed magic number, the ciphertext of the key, nonce, and timestamp.

[0026] Preferably, when using the enhanced mode of the first preset encryption method to perform block encryption on the compressed data block to obtain ciphertext and an authentication tag, specifically: Use the AES-GCM algorithm to perform block encryption on the compressed data block to obtain ciphertext and an authentication tag.

[0027] Preferably, when using the third preset encryption method to perform a digital signature on the concatenated data, specifically: Use the RSA-PSS algorithm in combination with the SHA256 hash function to perform a digital signature on the concatenated data.

[0028] According to the second aspect of the present invention, a decryption method applicable to a receiving end is provided, including: Parse the file header, ciphertext, authentication tag, and digital signature from the encrypted data file; Using the third preset encryption method, perform signature verification on the data obtained by concatenating the file header, ciphertext, and authentication tag. If the verification passes, determine that the received data file is complete and has not been tampered with, and comes from the expected source; otherwise, discard the received data file. Extract the key ciphertext from the file header, and use the second preset encryption method to decrypt the encryption key from the key ciphertext. Use the enhanced mode of the first preset encryption method and the encryption key to decrypt the ciphertext and verify the authentication tag. If the verification passes, determine that the received data file is complete and has not been tampered with; otherwise, discard the received data file. Decompress the decrypted data file to obtain the restored original file.

[0029] Preferably, the first preset encryption method is: the AES symmetric encryption method. The enhanced mode of the first preset encryption method is: using the AES-GCM algorithm. The second preset encryption method is: the RSA-OAEP algorithm. The third preset encryption method is: the RSA-PSS algorithm.

[0030] According to the third aspect of the present invention, there is provided an encryption and decryption method, including: The above encryption method and the above decryption method.

[0031] According to the fourth aspect of the present invention, there is provided a computer-readable storage medium storing computer-executable instructions for executing the above encryption method or the above decryption method.

[0032] The technical solutions provided by the embodiments of the present invention may include the following beneficial effects: The technical solution provided by the present invention reads the original file data and compresses it to obtain a compressed data block, which improves the data transmission efficiency, increases the difficulty of data confusion, reduces the file size, and increases the difficulty of side-channel attacks.

[0033] By using the first preset encryption method to randomly generate an encryption key and using the second preset encryption method to encrypt the encryption key to obtain a key ciphertext, the security of key transmission is ensured, and key leakage and cracking attacks are effectively prevented.

[0034] Use the enhanced mode of the first preset encryption method to perform block encryption on the compressed data block to obtain a ciphertext and an authentication tag, and through the built-in authentication mechanism provided by the enhanced mode of the first preset encryption method, double guarantees of data confidentiality and integrity are achieved.

[0035] Using the third preset encryption method, perform a digital signature on the spliced data. Through the authentication tag and digital signature, ensure the integrity of the data during transmission and storage, and have non-repudiation.

[0036] It can be seen that the technical solution provided by the present invention realizes efficient and secure encryption processing of the file data to be transmitted through multiple security protection technologies such as double-layer encryption, data compression, authentication tags, and digital signatures, and solves the problems of low security of the encryption method in the prior art, improper key management, large computational storage overhead of the encryption algorithm, and insufficient anti-tampering ability. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] Figure 1 is a flowchart of an encryption method shown according to an exemplary embodiment; Figure 2 is a flowchart of a decryption method shown according to an exemplary embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0038] In order to enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0039] Embodiment 1 Figure 1 is a flowchart of an encryption method shown according to an exemplary embodiment, applicable to a data source. Refer to Figure 1 , the encryption method includes: Step S11: Read the original file data and compress it to obtain a compressed data block; Step S12: Use the first preset encryption method to randomly generate an encryption key; Step S13: Use the second preset encryption method to encrypt the encryption key to obtain a key ciphertext; Step S14: Add the key ciphertext to the file header; Step S15: Use the enhanced mode of the first preset encryption method to perform block encryption on the compressed data block to obtain a ciphertext and an authentication tag; Step S16: Splice the file header, ciphertext, and authentication tag; Step S17: Use the third preset encryption method to perform a digital signature on the spliced data; Step S18: Write the file header, ciphertext, authentication tag, and digital signature into the file in the predefined format in sequence to obtain the encrypted data file.

[0040] It should be noted that in this embodiment, the "information source" refers to the sender of information, that is, the generator of the original data or the initiator of encryption. The "information sink" refers to the receiver of information, that is, the decryptor of the ciphertext and the user of the final data. The information source is the starting point of encryption, and the information sink is the ending point of decryption. The two together form a closed loop of encrypted communication. In the encryption and decryption method, the information source and the information sink respectively refer to the two ends of encryption and decryption. For example, in the HTTPS protocol, the client (information source) encrypts the request and sends it to the server (information sink). The server decrypts it, processes it, and returns an encrypted response. The client then decrypts the response content.

[0041] In specific practice, the technical solution provided in this embodiment can be applied to scenarios such as file storage, transmission, and evidence preservation that need to balance performance and security, such as enterprise data protection, cloud security, end-to-end communication, etc. Including but not limited to: 1. High-security file storage, for example: local encrypted storage of enterprise sensitive files (such as financial data, contracts). Advantages: Symmetric encryption (AES) efficiently processes large files.

[0042] Asymmetric encryption (RSA) protects the symmetric key to prevent leakage.

[0043] Digital signature (RSA-PSS) ensures that the file has not been tampered with and its source is trustworthy.

[0044] 2. Secure cloud storage and transmission, for example: uploading encrypted files to the cloud disk or sending them via email. Advantages: Compression reduces storage and transmission costs.

[0045] The key is protected by asymmetric encryption to avoid the risk of leakage in the cloud.

[0046] Digital signature prevents data from being tampered with during transmission.

[0047] 3. End-to-end encrypted communication, for example: file transmission in an instant messaging tool. Advantages: Symmetric encryption quickly processes the message content.

[0048] Asymmetric encryption exchanges the session key to ensure that only the recipient can decrypt.

[0049] Digital signature verifies the identity of the sender.

[0050] 4. Blockchain and data evidence preservation, for example: storing the hash value of the encrypted file in the blockchain to ensure that the data cannot be tampered with. Advantages: Digital signature binds the file to the user identity.

[0051] Authentication tags (such as AES - GCM) prevent data forgery.

[0052] In specific practice, in step S11, reading the original file data and compressing it to obtain a compressed data block can be specifically: Read the original file data and compress it using the zlib algorithm to obtain a compressed data block.

[0053] It can be understood that most of the existing solutions do not compress and store the data files to be transmitted, resulting in a significant increase in the volume of the encrypted files, wasting storage resources and affecting the transmission efficiency.

[0054] Zlib is a widely used compression library mainly for data compression rather than encryption. Although compression and encryption are sometimes used together, their purposes are different. The technical solution provided in this embodiment compresses the original data before encryption, improving the transmission efficiency, increasing the difficulty of data obfuscation, and at the same time reducing the file volume.

[0055] It can be understood that the technical solution provided in this embodiment reads the original file data and compresses it to obtain a compressed data block, improving the data transmission efficiency, increasing the difficulty of data obfuscation, reducing the file volume, and increasing the difficulty of side - channel attacks.

[0056] By using the first preset encryption method to randomly generate an encryption key and using the second preset encryption method to encrypt the encryption key to obtain a key ciphertext, the security of key transmission is ensured, effectively preventing key leakage and cracking attacks.

[0057] Use the enhanced mode of the first preset encryption method to encrypt the compressed data block in chunks to obtain ciphertext and an authentication tag. Through the built - in authentication mechanism provided by the enhanced mode of the first preset encryption method, double - guarantee of data confidentiality and integrity is achieved.

[0058] Use the third preset encryption method to perform a digital signature on the concatenated data. Through the authentication tag and digital signature, the integrity of the data during transmission and storage is ensured, and non - repudiation is provided.

[0059] It can be seen that the technical solution provided in this embodiment realizes efficient and secure encryption processing of the file data to be transmitted through multiple security protection technologies such as double - layer encryption, data compression, authentication tags, and digital signatures, solving the problems of low security of encryption methods, improper key management, large computational and storage overheads of encryption algorithms, and insufficient anti - tampering ability in the prior art.

[0060] In specific practice, in step S12, using the first preset encryption method to randomly generate an encryption key is specifically: Use the AES symmetric encryption method to randomly generate an AES symmetric encryption key of a preset number of bits.

[0061] It should be noted that AES (Advanced Encryption Standard) is a symmetric encryption algorithm (the same key is used for encryption and decryption), which is constructed based on the Substitution-Permutation Network (SPN), and supports key lengths of 128 / 192 / 256 bits and a data block length of 128 bits. It is currently the most widely used encryption standard globally, replacing the earlier DES algorithm. Preferably, in this embodiment, a 256-bit AES symmetric encryption key is randomly generated.

[0062] The disadvantage of the AES symmetric encryption algorithm is that symmetric encryption requires pre-sharing of keys, and key distribution and storage in large-scale systems may be complex (which needs to be solved in combination with asymmetric encryption).

[0063] Compared with RSA (Rivest-Shamir-Adleman, an asymmetric encryption algorithm), AES is faster and suitable for encrypting large amounts of data; RSA asymmetric encryption is slower and is used for key exchange or digital signatures.

[0064] In specific practice, in step S13, the second preset encryption method is used to encrypt the encryption key to obtain a key ciphertext, specifically: Use the RSA-OAEP algorithm to encrypt the encryption key to generate a key ciphertext.

[0065] It should be noted that the RSA-OAEP algorithm (RSA with Optimal Asymmetric Encryption Padding) is an enhanced version of the RSA algorithm. By introducing random numbers and hash functions (such as SHA-1 / SHA-256) to pad the plaintext, the security is improved. Simply put, the RSA-OAEP algorithm = RSA algorithm + OAEP padding rule.

[0066] For example, to send a secret message to a friend, the RSA-OAEP algorithm: 1) Add a layer of "garbled code wrapping": First add a string of random numbers (such as a birthday, weather) to the message, and then generate an "anti-counterfeiting label" through a certain mathematical operation (such as a hash function).

[0067] 2) Lock it in a safe: Encrypt this "tagged garbled message" with the friend's public key, just like putting a letter in a locked box; 3) Sending: After the friend receives it, use the private key to unlock the lock, and then remove the "anti-counterfeiting label" and the random number according to the previous rules to restore the original message.

[0068] It can be understood that in step S12, a 256-bit AES symmetric encryption key is randomly generated, and in step S13, the RSA-OAEP algorithm is used to encrypt the key to generate a key ciphertext of 256 bytes.

[0069] In a specific implementation, in step S14, the key ciphertext is added to the file header, including: Generate a preset number of bytes of random number nonce and a timestamp, and construct a file header, which includes: a fixed magic number, a key ciphertext, a nonce, and a timestamp.

[0070] It should be noted that the fixed magic number, key ciphertext, nonce, and timestamp in the file header are common components in encrypted files or protocols, each performing different functions.

[0071] Preferably, in this embodiment, a 12-byte random nonce and an 8-byte timestamp are generated, and a file header is constructed.

[0072] 1) Fixed magic number: A fixed binary or hexadecimal value (such as 0xDEADBEEF), used to identify the type or format of the file; functions include: quick verification: telling the system or program "this file is a legitimate encrypted file" to prevent misoperations (such as trying to open a binary file with a text editor); anti-tampering detection: if the file is accidentally modified, the magic number may not match, and the system will prompt that the file is damaged.

[0073] 2) Key ciphertext: The symmetric key (or other key) encrypted with the recipient's public key.

[0074] 3) Nonce (one-time random number): A randomly generated number used only in one encryption operation.

[0075] 4) Timestamp: Records the time when the file is generated or encrypted (accurate to milliseconds or seconds). Functions include: timeliness verification: preventing the file from being used after expiration (for example, in financial transactions, old transactions may be invalid); preventing replay attacks: attackers cannot use old ciphertext to impersonate new requests (if the timestamp has expired, it will be rejected); audit trail: facilitating the retrospective of the operation time of the file afterwards.

[0076] In a specific implementation, in step S15, the enhanced mode of the first preset encryption method is used to perform block encryption on the compressed data block to obtain a ciphertext and an authentication tag. Specifically: Use the AES-GCM algorithm to perform block encryption on the compressed data block to obtain a ciphertext and an authentication tag.

[0077] Preferably, in this embodiment, an authentication tag tag of 16 bytes is generated.

[0078] It should be noted that the AES-GCM algorithm, AES-GCM can be understood as a "combination technology of encryption + stamping", which can not only ensure data confidentiality (encryption), but also verify whether the data has been tampered with (authentication). It is a working mode of the AES encryption method, and GCM in the name represents Galois / Counter Mode (Galois counter mode).

[0079] Simply put, AES-GCM = encrypt data + generate anti-counterfeiting label. Among them, block encryption (similar to block locking): cut the compressed data into small pieces (for example, each 16 bytes as a piece), and encrypt each piece with the AES algorithm. GCM uses a "counter" (Counter) to generate a key stream, and each data block is encrypted with a different counter value to avoid repetition. It is similar to assigning different "keys" to each data block. Even if an attacker obtains the ciphertext of a certain block, they cannot infer the content of other blocks.

[0080] After the encryption is completed, GCM will generate an authentication tag of a fixed length. This Tag is generated through mathematical operations on all data blocks and the encryption process, which is equivalent to "stamping an anti-counterfeiting seal" on the entire file. When the recipient decrypts, the Tag will be recalculated. If it is inconsistent with the received Tag, it means that the file has been tampered with (for example, modified or damaged during the process).

[0081] In specific practice, in step S17, the third preset encryption method is used to perform a digital signature on the spliced data. Specifically: Use the RSA-PSS algorithm in cooperation with the SHA256 hash function to perform a digital signature on the spliced data.

[0082] Preferably, in this embodiment, for the data spliced from the file header, ciphertext, and authentication tag tag, a digital signature is generated using the RSA-PSS algorithm in cooperation with SHA256 hash, generating a 256-byte signature.

[0083] It should be noted that the RSA-PSS algorithm, RSA-PSS is a modern padding scheme of the RSA encryption method, with the full name of RSA Probabilistic Signature Scheme, RSA probabilistic signature scheme. Its core features are probabilistic and anti-tampering, and it is mainly used in digital signature scenarios (such as verifying the file source or identity). Simply put, by introducing random numbers and hash functions, each signature is different, thus preventing attackers from forging signatures. Through dynamic random numbers and hash functions, the signature is unpredictable and tamper-proof, and it is the mainstream scheme for current digital signatures.

[0084] For example: Sign a contract using RSA-PSS and send it to a friend.

[0085] Signature process: Contract content → Hash value (such as SHA-256).

[0086] Generate a random salt → Mix the hash and the salt → Encrypt with the private key → Generate a signature.

[0087] Verification process: The friend receives the contract and the signature → Decrypt the signature with the public key to obtain the salt and the hash value → Recalculate the contract hash value → Compare whether they are the same. If they are the same → The contract has not been tampered with, and it was indeed signed by you! In step S18, write the file header, ciphertext, authentication tag, and digital signature into the file in a predefined format in sequence to obtain an encrypted data file.

[0088] The final generated file format is: Encrypted file = Magic number (8 bytes) + RSA-encrypted AES key (256 bytes) + nonce (12 bytes) + Timestamp (8 bytes) + Ciphertext + AES-GCM authentication tag tag (16 bytes) + Digital signature (256 bytes).

[0089] In summary, for the technical solution provided in this embodiment, first, by compressing the data before encryption, the data transmission efficiency is improved, the data confusion difficulty is increased, the file size is reduced, and the difficulty of side-channel attacks is increased.

[0090] Secondly, use RSA-OAEP to encrypt the symmetric encryption key AES key to ensure the security of symmetric key transmission and effectively prevent key leakage and cracking attacks; use symmetric encryption AES-GCM to encrypt the file data and provide a built-in authentication mechanism at the same time to achieve double protection of data confidentiality and integrity.

[0091] In addition, by embedding a file header in a custom format in the file, including metadata such as a fixed magic number, RSA-encrypted AES key, random nonce, timestamp, etc., it is convenient for subsequent processing and expansion. The timestamp embedded in the file header can be used to record the generation time, which can prevent replay attacks and provide a basis for subsequent timeliness verification.

[0092] Finally, introduce a built-in data integrity authentication mechanism (AES-GCM authentication tag) and digital signature (RSA-PSS signature) to ensure the integrity of the data during transmission and storage and have non-repudiation.

[0093] It can be seen that the technical solution provided in this embodiment realizes efficient and secure encryption processing of the file data to be transmitted through multiple security protection technologies such as double-layer encryption, data compression, embedding time stamps, and digital signatures, and solves the problems of low security, improper key management, large computational storage overhead of encryption algorithms, and insufficient anti-tampering ability in the existing encryption methods.

[0094] Embodiment 2 Figure 2 is a flowchart of a decryption method shown according to an exemplary embodiment, which is applicable to the receiving end. Refer to Figure 2 , and the decryption method includes: Step S21: Parse the file header, ciphertext, authentication tag, and digital signature from the encrypted data file; Step S22: Use the third preset encryption method to verify the digital signature of the data after splicing the file header, ciphertext, and authentication tag. If the verification passes, it is determined that the received data file is complete and has not been tampered with, and comes from the expected source; otherwise, discard the received data file; Step S23: Extract the key ciphertext from the file header, and use the second preset encryption method to decrypt the encryption key from the key ciphertext; Step S24: Use the enhanced mode of the first preset encryption method and the encryption key to decrypt the ciphertext, and verify the authentication tag. If the verification passes, it is determined that the received data file is complete and has not been tampered with; otherwise, discard the received data file; Step S25: Decompress the decrypted data file to obtain the restored original file.

[0095] It should be noted that the "source" in this embodiment refers to the information sender, that is, the generator of the original data or the initiator of encryption. The "receiving end" refers to the information receiver, that is, the decryptor of the ciphertext and the user of the final data. The source is the starting point of encryption, and the receiving end is the end point of decryption. The two together form a closed loop of encrypted communication. In the encryption and decryption methods, the source and the receiving end refer to the two ends of encryption and decryption respectively. For example, in the HTTPS protocol, the client (source) encrypts the request and sends it to the server (receiving end). The server decrypts it, processes it, and returns an encrypted response. The client then decrypts the response content.

[0096] The technical solution provided in this embodiment has the same application scenario as that in Embodiment 1, and will not be elaborated in this embodiment.

[0097] In specific practice, preferably, the first preset encryption method is: AES symmetric encryption method; The enhanced mode of the first preset encryption method is: using the AES-GCM algorithm; The second preset encryption method is: RSA-OAEP algorithm; The third preset encryption method is: RSA-PSS algorithm.

[0098] For the specific content and implementation mechanism of the above encryption algorithms, please refer to the relevant introduction in Embodiment 1, which will not be elaborated in this embodiment.

[0099] The technical solution provided in this embodiment is used in conjunction with the encryption algorithm provided in Embodiment 1. The encryption algorithm provided in Embodiment 1 realizes efficient and secure encryption processing of the file data to be transmitted through multiple security protection technologies such as double-layer encryption, data compression, embedding time stamps, and digital signatures. In cooperation with the decryption algorithm provided in this embodiment, it solves the problems of low security, improper key management, large computational storage overhead of encryption and decryption algorithms, and insufficient anti-tampering ability in the prior art.

[0100] Embodiment 3 A encryption and decryption method shown according to an exemplary embodiment includes: The encryption method described in the above Embodiment 1, and / or, the decryption method described in the above Embodiment 2.

[0101] The application scenario of the technical solution provided in this embodiment is the same as that in Embodiment 1, which will not be elaborated in this embodiment.

[0102] The technical solution provided in this embodiment includes the encryption algorithm provided in Embodiment 1 and the decryption algorithm provided in Embodiment 2. Among them, the encryption algorithm provided in Embodiment 1 realizes efficient and secure encryption processing of the file data to be transmitted through multiple security protection technologies such as double-layer encryption, data compression, embedding time stamps, and digital signatures. In cooperation with the decryption algorithm provided in Embodiment 2, it solves the problems of low security, improper key management, large computational storage overhead of encryption and decryption algorithms, and insufficient anti-tampering ability in the prior art.

[0103] Embodiment 4 A computer-readable storage medium shown according to an exemplary embodiment stores computer-executable instructions for executing the above encryption method or the above decryption method.

[0104] The technical solution provided in this embodiment includes the encryption algorithm provided in Embodiment 1 and the decryption algorithm provided in Embodiment 2. Among them, the encryption algorithm provided in Embodiment 1 realizes efficient and secure encryption processing of the file data to be transmitted through multiple security protection technologies such as double-layer encryption, data compression, embedding time stamps, and digital signatures. In cooperation with the decryption algorithm provided in Embodiment 2, it solves the problems of low security, improper key management, large computational storage overhead of encryption and decryption algorithms, and insufficient anti-tampering ability in the prior art.

[0105] The serial numbers of the embodiments of the present application above are only for description and do not represent the superiority or inferiority of the embodiments.

[0106] If the integrated units in the above embodiments are implemented in the form of software functional units and sold or used as independent products, they can be stored in the above computer-readable storage media. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing one or more computer devices (which can be personal computers, servers, or network devices, etc.) to execute all or part of the steps of the methods described in various embodiments of the present application.

[0107] In the above embodiments of the present application, the descriptions of the various embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0108] In the several embodiments provided by the present application, it should be understood that the disclosed client can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of the units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of units or modules can be in an electrical or other form.

[0109] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0110] In addition, the functional units in each embodiment of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0111] The above is only the preferred embodiment of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can still be made, and these improvements and refinements should also be regarded as the protection scope of the present application.

Claims

1. A cryptographic method applicable to a source, characterized in that, It includes: Read the original file data and compress it to obtain a compressed data block; Use the first preset encryption method to randomly generate an encryption key; Use the second preset encryption method to encrypt the encryption key to obtain a ciphertext of the key; Add the ciphertext of the key to the file header; Use the enhanced mode of the first preset encryption method to perform block encryption on the compressed data block to obtain ciphertext and an authentication tag; Concatenate the file header, ciphertext, and authentication tag; Use the third preset encryption method to perform a digital signature on the concatenated data; Write the file header, ciphertext, authentication tag, and digital signature into a file in the predefined format in sequence to obtain an encrypted data file.

2. The encryption method according to claim 1, wherein The step of using the first preset encryption method to randomly generate an encryption key specifically is: Use the AES symmetric encryption method to randomly generate an AES symmetric encryption key with a preset number of bits.

3. The encryption method according to claim 1, characterized in that, The step of using the second preset encryption method to encrypt the encryption key to obtain a ciphertext of the key specifically is: Use the RSA-OAEP algorithm to encrypt the encryption key to generate a ciphertext of the key.

4. The encryption method according to claim 1, wherein The step of adding the ciphertext of the key to the file header includes: Generate a preset-byte random number nonce and a timestamp, and construct a file header, where the file header includes: a fixed magic number, the ciphertext of the key, nonce, and timestamp.

5. The encryption method according to claim 2, wherein The step of using the enhanced mode of the first preset encryption method to perform block encryption on the compressed data block to obtain ciphertext and an authentication tag specifically is: Use the AES-GCM algorithm to perform block encryption on the compressed data block to obtain ciphertext and an authentication tag.

6. The encryption method according to claim 1, characterized in that The step of using the third preset encryption method to perform a digital signature on the concatenated data specifically is: Use the RSA-PSS algorithm in cooperation with the SHA256 hash function to perform a digital signature on the concatenated data.

7. A decryption method, applicable to the destination, characterized in that, It includes: Parse the file header, ciphertext, authentication tag, and digital signature from the encrypted data file; Use the third preset encryption method to perform signature verification on the data obtained by concatenating the file header, ciphertext, and authentication tag. If the verification passes, it is determined that the received data file is complete and has not been tampered with, and it comes from the expected source; Otherwise, discard the received data file; Extract the ciphertext of the key from the file header, and use the second preset encryption method to decrypt the encryption key from the ciphertext of the key; Use the enhanced mode of the first preset encryption method and the encryption key to decrypt the ciphertext, and verify the authentication tag. If the verification passes, it is determined that the received data file is complete and has not been tampered with; otherwise, discard the received data file; Decompress the decrypted data file to obtain the restored original file.

8. According to the decryption method described in claim 7, characterized in that The first preset encryption method is: the AES symmetric encryption method; The enhanced mode of the first preset encryption method is: using the AES-GCM algorithm; The second preset encryption method is: the RSA-OAEP algorithm; The third preset encryption method is: the RSA-PSS algorithm.

9. A method for encryption and decryption, characterized in that, It includes: The encryption method according to any one of claims 1 to 6, and the decryption method according to any one of claims 7 to 8.

10. A computer-readable storage medium storing computer-executable instructions, characterized in that, The computer-executable instructions are used to execute the encryption method according to any one of claims 1 to 6, and / or execute the decryption method according to any one of claims 7 to 8.

Citation Information

Patent Citations

  • File encryption method and apparatus, encrypted file reading method and apparatus and terminal

    CN105095783A

  • Encryption method and decryption method for file, and encryption and decryption system

    CN105187204A

  • Novel symmetric key algorithm for high speed encryption

    CN106656475A

  • Decentralized data verification and data security transaction system and method

    CN109347878A

  • Embedded Euler system access control method, device and equipment and storage medium

    CN118734333A

Cited By

  • Intelligent Internet of Things equipment storage data transmission system and method based on block chain

    CN121036946A

  • Secure data packet generation method with file header signature and data body signature separated

    CN121841861A

  • A secure data packet generation method with file header signature separated from data body signature

    CN121841861B

  • DNA information double-layer encryption method and system based on gradient fluorescent nucleotide and application of DNA information double-layer encryption method and system

    CN122226416A